Prosím o kontrolu logu - pomalé nabíhání Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 14 pro 2012 10:01

Dobrý den, prosím o kontrolu logu.
Počítač je vcelku rychlý, všechno v pohodě, jen při zapnutí pc a nabíhání windowsu - po zobrazení obrazovky "Přihlášování..." se místo plochy objeví černé pozadí a vidím jen myš - zhruba 30 vteřin, poté se plocha zobrazí a vše naběhne. Nevím proč, proto prosím o kontrolu logu :?

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:53:29, on 14.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Users\Samec\Desktop\HiJackThis (1).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser

Configuration Utility\AddressBarSearch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat

\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin

\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program

Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin

\jp2ssv.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Exetender_298] "C:\Program Files (x86)\Frag Games\GPlayer.exe" /runonstartup (User 'LOCAL

SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Exetender_298] "C:\Program Files (x86)\Frag Games\GPlayer.exe" /runonstartup (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Exetender_298] "C:\Program Files (x86)\Frag Games\GPlayer.exe" /runonstartup (User 'Default

user')
O4 - Startup: SpeedFan.lnk = C:\Program Files (x86)\SpeedFan\speedfan.exe
O4 - Startup: TeamViewer 7.lnk = C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:

\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files

(x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files

(x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files

(x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program

Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Broken Internet access because of LSP provider 'c:\program files (x86)\vmware\vmware server\vsocklib.dll' missing
O17 - HKLM\System\CCS\Services\Tcpip\..\{23C2C53C-60B8-4D02-A942-0DDBB5C3FF73}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E3EDCCB-FE8E-4E23-9F5C-FF58C761CDBF}: NameServer = 127.0.0.1
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft

Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis

\Schedule2\schedul2.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files

(x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows

\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP

\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.13\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS

\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM

\Browser Configuration Utility\BCUService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file

missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file

missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update

\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update

\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel

\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware

\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla

Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file

missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe

(file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file

missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file

missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file

missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file

missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file

missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis

\SyncAgent\syncagentsrv.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer

\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe

(file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file

missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat

\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe

(file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem

\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files

(x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10299 bytes

Reklama
Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod Žbeky » 14 pro 2012 12:02

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 14 pro 2012 12:46

Malwarebytes Anti-Malware (PRO) 1.65.1.1000
www.malwarebytes.org

Verze databáze: v2012.12.14.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Samec :: SAMEK-PC [administrátor]

Ochrana: Zakázána

14.12.2012 12:42:33
mbam-log-2012-12-14 (12-42-33).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 210493
Uplynulý čas: 2 minut, 58 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod Žbeky » 14 pro 2012 13:10

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 14 pro 2012 13:52

13:50:42.0526 1800 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
13:50:42.0526 1800 UEFI system
13:50:44.0528 1800 ============================================================
13:50:44.0528 1800 Current date / time: 2012/12/14 13:50:44.0528
13:50:44.0529 1800 SystemInfo:
13:50:44.0529 1800
13:50:44.0529 1800 OS Version: 6.1.7601 ServicePack: 1.0
13:50:44.0529 1800 Product type: Workstation
13:50:44.0529 1800 ComputerName: SAMEK-PC
13:50:44.0529 1800 UserName: Samec
13:50:44.0529 1800 Windows directory: C:\Windows
13:50:44.0529 1800 System windows directory: C:\Windows
13:50:44.0529 1800 Running under WOW64
13:50:44.0529 1800 Processor architecture: Intel x64
13:50:44.0529 1800 Number of processors: 4
13:50:44.0529 1800 Page size: 0x1000
13:50:44.0529 1800 Boot type: Normal boot
13:50:44.0529 1800 ============================================================
13:50:45.0767 1800 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:50:45.0773 1800 ============================================================
13:50:45.0773 1800 \Device\Harddisk0\DR0:
13:50:45.0773 1800 GPT partitions:
13:50:45.0774 1800 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {846056EE-0584-448B-A725-68846BFC52AE}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x32000
13:50:45.0774 1800 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {2AD09120-E6C5-4796-9A1D-846534292785}, Name: Microsoft reserved partition, StartLBA 0x32800, BlocksNum 0x40000
13:50:45.0774 1800 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {0DB30D72-C304-4BF4-B53B-8B2BE66935FD}, Name: Basic data partition, StartLBA 0x72800, BlocksNum 0x32056000
13:50:45.0774 1800 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {D0B02ABE-CB5C-45AA-95E7-E3ED494B252F}, Name: Basic data partition, StartLBA 0x320C8800, BlocksNum 0x4263E000
13:50:45.0774 1800 MBR partitions:
13:50:45.0774 1800 ============================================================
13:50:45.0798 1800 C: <-> \Device\Harddisk0\DR0\Partition4
13:50:45.0833 1800 D: <-> \Device\Harddisk0\DR0\Partition3
13:50:45.0833 1800 ============================================================
13:50:45.0833 1800 Initialize success
13:50:45.0833 1800 ============================================================
13:50:47.0003 0544 ============================================================
13:50:47.0003 0544 Scan started
13:50:47.0003 0544 Mode: Manual;
13:50:47.0003 0544 ============================================================
13:50:47.0300 0544 ================ Scan system memory ========================
13:50:47.0300 0544 System memory - ok
13:50:47.0300 0544 ================ Scan services =============================
13:50:47.0642 0544 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
13:50:47.0645 0544 1394ohci - ok
13:50:47.0660 0544 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
13:50:47.0664 0544 ACPI - ok
13:50:47.0685 0544 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
13:50:47.0686 0544 AcpiPmi - ok
13:50:47.0773 0544 [ F578ABFF32E9E3B9518CD59C3A931A3E ] AcrSch2Svc C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
13:50:47.0782 0544 AcrSch2Svc - ok
13:50:47.0817 0544 [ B1EA9681502EE57F87DB71D726288A5B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13:50:47.0818 0544 AdobeARMservice - ok
13:50:47.0968 0544 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:50:47.0971 0544 AdobeFlashPlayerUpdateSvc - ok
13:50:48.0019 0544 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:50:48.0027 0544 adp94xx - ok
13:50:48.0060 0544 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:50:48.0067 0544 adpahci - ok
13:50:48.0090 0544 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:50:48.0232 0544 adpu320 - ok
13:50:48.0256 0544 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:50:48.0257 0544 AeLookupSvc - ok
13:50:48.0286 0544 [ 0517E1670A58213E3F206066CD209273 ] AF15BDA C:\Windows\system32\DRIVERS\AF15BDA.sys
13:50:48.0293 0544 AF15BDA - ok
13:50:48.0341 0544 [ 6CCD1135320109D6B219F1A6E04AD9F6 ] Afc C:\Windows\syswow64\drivers\Afc.sys
13:50:48.0342 0544 Afc - ok
13:50:48.0375 0544 [ ABCF9C80EAACE03021BB7F450EB8993F ] afcdp C:\Windows\system32\DRIVERS\afcdp.sys
13:50:48.0378 0544 afcdp - ok
13:50:48.0464 0544 [ 37D739F9CD9D3E99F5E824C91E62200D ] afcdpsrv C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
13:50:48.0490 0544 afcdpsrv - ok
13:50:48.0547 0544 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
13:50:48.0553 0544 AFD - ok
13:50:48.0565 0544 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:50:48.0567 0544 agp440 - ok
13:50:48.0587 0544 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
13:50:48.0590 0544 ALG - ok
13:50:48.0607 0544 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
13:50:48.0608 0544 aliide - ok
13:50:48.0633 0544 [ 4C1E3649C89C7D542CD18ECC5210099D ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
13:50:48.0650 0544 AMD External Events Utility - ok
13:50:48.0659 0544 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
13:50:48.0661 0544 amdide - ok
13:50:48.0664 0544 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:50:48.0666 0544 AmdK8 - ok
13:50:48.0882 0544 [ A3C0A15B39F979E8F3EABA901D72ECD7 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
13:50:49.0048 0544 amdkmdag - ok
13:50:49.0084 0544 [ 20F3CD38B107C1BD747C0EA37D450165 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
13:50:49.0086 0544 amdkmdap - ok
13:50:49.0089 0544 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
13:50:49.0090 0544 AmdPPM - ok
13:50:49.0104 0544 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
13:50:49.0106 0544 amdsata - ok
13:50:49.0115 0544 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
13:50:49.0118 0544 amdsbs - ok
13:50:49.0120 0544 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
13:50:49.0121 0544 amdxata - ok
13:50:49.0151 0544 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
13:50:49.0169 0544 AppID - ok
13:50:49.0180 0544 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
13:50:49.0182 0544 AppIDSvc - ok
13:50:49.0196 0544 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
13:50:49.0199 0544 Appinfo - ok
13:50:49.0234 0544 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
13:50:49.0240 0544 arc - ok
13:50:49.0244 0544 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:50:49.0247 0544 arcsas - ok
13:50:49.0307 0544 [ FB03A917C1294D3E6D671F24722E1BA3 ] asComSvc C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
13:50:49.0314 0544 asComSvc - ok
13:50:49.0343 0544 [ A63173897EA1A73A75D0E65036DE5B15 ] asHmComSvc C:\Program Files (x86)\ASUS\AAHM\1.00.13\aaHMSvc.exe
13:50:49.0350 0544 asHmComSvc - ok
13:50:49.0374 0544 [ FEF9DD9EA587F8886ADE43C1BEFBDAFE ] AsIO C:\Windows\syswow64\drivers\AsIO.sys
13:50:49.0375 0544 AsIO - ok
13:50:49.0394 0544 [ 718692FFF22D6AF47EBA0A741A924921 ] asmthub3 C:\Windows\system32\DRIVERS\asmthub3.sys
13:50:49.0396 0544 asmthub3 - ok
13:50:49.0404 0544 [ BAD70A5AC534C108F680A33C654BC626 ] asmtxhci C:\Windows\system32\DRIVERS\asmtxhci.sys
13:50:49.0407 0544 asmtxhci - ok
13:50:49.0475 0544 [ 108FB6DDB69E537A2EA53F425363FAE5 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
13:50:49.0477 0544 aspnet_state - ok
13:50:49.0488 0544 [ 5C31DFB196CB3A488A041881634D86D2 ] AsSysCtrlService C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
13:50:49.0493 0544 AsSysCtrlService - ok
13:50:49.0513 0544 [ 1392B92179B07B672720763D9B1028A5 ] AsUpIO C:\Windows\syswow64\drivers\AsUpIO.sys
13:50:49.0514 0544 AsUpIO - ok
13:50:49.0541 0544 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:50:49.0542 0544 AsyncMac - ok
13:50:49.0555 0544 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
13:50:49.0555 0544 atapi - ok
13:50:49.0625 0544 [ 36322190763845975E0D001E90687BF2 ] athur C:\Windows\system32\DRIVERS\athurx.sys
13:50:49.0682 0544 athur - ok
13:50:49.0756 0544 [ B0790FF0E25B7A2674296052F2162C1A ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
13:50:49.0757 0544 AtiHDAudioService - ok
13:50:49.0792 0544 [ 54494B93BB5AD74C807100144EC30D64 ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys
13:50:49.0795 0544 atksgt - ok
13:50:49.0843 0544 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:50:49.0852 0544 AudioEndpointBuilder - ok
13:50:49.0863 0544 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
13:50:49.0868 0544 AudioSrv - ok
13:50:49.0894 0544 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
13:50:49.0896 0544 AxInstSV - ok
13:50:49.0913 0544 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
13:50:49.0919 0544 b06bdrv - ok
13:50:49.0926 0544 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
13:50:49.0930 0544 b57nd60a - ok
13:50:49.0972 0544 [ 328E794278CC30CA7C06E346A18B1ABC ] BCUService C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
13:50:49.0974 0544 BCUService - ok
13:50:49.0989 0544 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
13:50:49.0992 0544 BDESVC - ok
13:50:50.0009 0544 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
13:50:50.0010 0544 Beep - ok
13:50:50.0051 0544 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
13:50:50.0060 0544 BFE - ok
13:50:50.0101 0544 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
13:50:50.0110 0544 BITS - ok
13:50:50.0129 0544 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
13:50:50.0131 0544 blbdrive - ok
13:50:50.0141 0544 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:50:50.0143 0544 bowser - ok
13:50:50.0147 0544 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
13:50:50.0148 0544 BrFiltLo - ok
13:50:50.0174 0544 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
13:50:50.0175 0544 BrFiltUp - ok
13:50:50.0194 0544 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
13:50:50.0214 0544 BridgeMP - ok
13:50:50.0248 0544 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
13:50:50.0250 0544 Browser - ok
13:50:50.0257 0544 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
13:50:50.0262 0544 Brserid - ok
13:50:50.0266 0544 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
13:50:50.0268 0544 BrSerWdm - ok
13:50:50.0271 0544 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
13:50:50.0273 0544 BrUsbMdm - ok
13:50:50.0276 0544 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
13:50:50.0277 0544 BrUsbSer - ok
13:50:50.0300 0544 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
13:50:50.0302 0544 BthEnum - ok
13:50:50.0305 0544 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
13:50:50.0308 0544 BTHMODEM - ok
13:50:50.0328 0544 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
13:50:50.0341 0544 BthPan - ok
13:50:50.0380 0544 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
13:50:50.0397 0544 BTHPORT - ok
13:50:50.0438 0544 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
13:50:50.0440 0544 bthserv - ok
13:50:50.0451 0544 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
13:50:50.0452 0544 BTHUSB - ok
13:50:50.0462 0544 catchme - ok
13:50:50.0472 0544 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:50:50.0487 0544 cdfs - ok
13:50:50.0498 0544 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:50:50.0500 0544 cdrom - ok
13:50:50.0520 0544 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
13:50:50.0522 0544 CertPropSvc - ok
13:50:50.0524 0544 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
13:50:50.0540 0544 circlass - ok
13:50:50.0557 0544 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
13:50:50.0562 0544 CLFS - ok
13:50:50.0618 0544 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:50:50.0619 0544 clr_optimization_v2.0.50727_32 - ok
13:50:50.0651 0544 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:50:50.0652 0544 clr_optimization_v2.0.50727_64 - ok
13:50:50.0705 0544 [ 6D7C8A951AF6AD6835C029B3CB88D333 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:50:50.0706 0544 clr_optimization_v4.0.30319_32 - ok
13:50:50.0716 0544 [ 86329C35FF23CFEF0FB6C0023BA06BCE ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:50:50.0718 0544 clr_optimization_v4.0.30319_64 - ok
13:50:50.0721 0544 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
13:50:50.0723 0544 CmBatt - ok
13:50:50.0727 0544 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:50:50.0728 0544 cmdide - ok
13:50:50.0765 0544 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
13:50:50.0772 0544 CNG - ok
13:50:50.0776 0544 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
13:50:50.0778 0544 Compbatt - ok
13:50:50.0792 0544 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
13:50:50.0794 0544 CompositeBus - ok
13:50:50.0797 0544 COMSysApp - ok
13:50:50.0802 0544 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:50:50.0804 0544 crcdisk - ok
13:50:50.0836 0544 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:50:50.0838 0544 CryptSvc - ok
13:50:50.0863 0544 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:50:50.0867 0544 DcomLaunch - ok
13:50:50.0887 0544 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
13:50:50.0891 0544 defragsvc - ok
13:50:50.0909 0544 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:50:50.0910 0544 DfsC - ok
13:50:50.0921 0544 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
13:50:50.0925 0544 Dhcp - ok
13:50:50.0940 0544 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
13:50:50.0940 0544 discache - ok
13:50:50.0949 0544 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
13:50:50.0950 0544 Disk - ok
13:50:50.0980 0544 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:50:50.0983 0544 Dnscache - ok
13:50:51.0010 0544 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
13:50:51.0013 0544 dot3svc - ok
13:50:51.0017 0544 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
13:50:51.0019 0544 DPS - ok
13:50:51.0054 0544 [ 4CCE2C5FD3F4805AA2052AABF48C5DE6 ] DRIVER_B C:\Windows\system32\Drivers\DRIVER_BIN64
13:50:51.0067 0544 Suspicious file (Forged): C:\Windows\system32\Drivers\DRIVER_BIN64. Real md5: 4CCE2C5FD3F4805AA2052AABF48C5DE6, Fake md5: DE3CDAD1E847546111D2F3FA9944C831
13:50:51.0067 0544 DRIVER_B ( ForgedFile.Multi.Generic ) - warning
13:50:51.0067 0544 DRIVER_B - detected ForgedFile.Multi.Generic (1)
13:50:51.0103 0544 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:50:51.0105 0544 drmkaud - ok
13:50:51.0144 0544 dump_wmimmc - ok
13:50:51.0177 0544 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:50:51.0190 0544 DXGKrnl - ok
13:50:51.0210 0544 [ D00EAE9C735A7DEE8049E50D73D25434 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
13:50:51.0224 0544 eamonm - ok
13:50:51.0237 0544 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
13:50:51.0240 0544 EapHost - ok
13:50:51.0280 0544 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
13:50:51.0308 0544 ebdrv - ok
13:50:51.0341 0544 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
13:50:51.0342 0544 EFS - ok
13:50:51.0378 0544 [ E5EDDE3C8158DD0CBC5812F201DCDED0 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
13:50:51.0380 0544 ehdrv - ok
13:50:51.0442 0544 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:50:51.0452 0544 ehRecvr - ok
13:50:51.0510 0544 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
13:50:51.0513 0544 ehSched - ok
13:50:51.0590 0544 [ AD4FAADE819E0DA9933BEA7C01D2C763 ] ekrn C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
13:50:51.0597 0544 ekrn - ok
13:50:51.0607 0544 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:50:51.0613 0544 elxstor - ok
13:50:51.0617 0544 [ 587F0F4145A1536A6E37EFD769B7665F ] epfw C:\Windows\system32\DRIVERS\epfw.sys
13:50:51.0628 0544 epfw - ok
13:50:51.0632 0544 [ D2F812358EE8EE23CBB5C4DAFFB5B819 ] EpfwLWF C:\Windows\system32\DRIVERS\EpfwLWF.sys
13:50:51.0657 0544 EpfwLWF - ok
13:50:51.0660 0544 [ 34BF55D69AB74D14C7E7A17259CB7DF8 ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
13:50:51.0661 0544 epfwwfp - ok
13:50:51.0663 0544 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:50:51.0664 0544 ErrDev - ok
13:50:51.0699 0544 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
13:50:51.0701 0544 EventSystem - ok
13:50:51.0713 0544 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
13:50:51.0730 0544 exfat - ok
13:50:51.0742 0544 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:50:51.0744 0544 fastfat - ok
13:50:51.0776 0544 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
13:50:51.0782 0544 Fax - ok
13:50:51.0786 0544 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
13:50:51.0787 0544 fdc - ok
13:50:51.0820 0544 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
13:50:51.0822 0544 fdPHost - ok
13:50:51.0831 0544 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
13:50:51.0833 0544 FDResPub - ok
13:50:51.0845 0544 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:50:51.0847 0544 FileInfo - ok
13:50:51.0898 0544 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:50:51.0926 0544 Filetrace - ok
13:50:51.0929 0544 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
13:50:51.0930 0544 flpydisk - ok
13:50:51.0945 0544 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:50:51.0949 0544 FltMgr - ok
13:50:51.0968 0544 [ F0CC1A9106F9FB0F704F6ED95622B43E ] fltsrv C:\Windows\system32\DRIVERS\fltsrv.sys
13:50:51.0969 0544 fltsrv - ok
13:50:52.0008 0544 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
13:50:52.0022 0544 FontCache - ok
13:50:52.0076 0544 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:50:52.0078 0544 FontCache3.0.0.0 - ok
13:50:52.0086 0544 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
13:50:52.0105 0544 FsDepends - ok
13:50:52.0130 0544 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:50:52.0132 0544 Fs_Rec - ok
13:50:52.0150 0544 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
13:50:52.0153 0544 fvevol - ok
13:50:52.0185 0544 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:50:52.0188 0544 gagp30kx - ok
13:50:52.0219 0544 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
13:50:52.0230 0544 gpsvc - ok
13:50:52.0281 0544 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:50:52.0282 0544 gupdate - ok
13:50:52.0291 0544 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:50:52.0292 0544 gupdatem - ok
13:50:52.0315 0544 [ F8F0851D336C3B88DBD7232B6348E09A ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
13:50:52.0316 0544 hamachi - ok
13:50:52.0329 0544 [ EDB09F2DF76C352B7AF56D0B473049D6 ] hcmon C:\Windows\system32\drivers\hcmon.sys
13:50:52.0330 0544 hcmon - ok
13:50:52.0334 0544 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
13:50:52.0336 0544 hcw85cir - ok
13:50:52.0363 0544 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:50:52.0368 0544 HdAudAddService - ok
13:50:52.0389 0544 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:50:52.0391 0544 HDAudBus - ok
13:50:52.0395 0544 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
13:50:52.0396 0544 HidBatt - ok
13:50:52.0402 0544 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:50:52.0404 0544 HidBth - ok
13:50:52.0409 0544 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
13:50:52.0411 0544 HidIr - ok
13:50:52.0427 0544 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
13:50:52.0430 0544 hidserv - ok
13:50:52.0457 0544 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:50:52.0458 0544 HidUsb - ok
13:50:52.0488 0544 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:50:52.0491 0544 hkmsvc - ok
13:50:52.0505 0544 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:50:52.0509 0544 HomeGroupListener - ok
13:50:52.0536 0544 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:50:52.0540 0544 HomeGroupProvider - ok
13:50:52.0545 0544 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
13:50:52.0547 0544 HpSAMD - ok
13:50:52.0570 0544 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:50:52.0579 0544 HTTP - ok
13:50:52.0583 0544 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
13:50:52.0584 0544 hwpolicy - ok
13:50:52.0588 0544 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
13:50:52.0591 0544 i8042prt - ok
13:50:52.0622 0544 [ D7921D5A870B11CC1ADAB198A519D50A ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
13:50:52.0626 0544 iaStor - ok
13:50:52.0664 0544 [ 8FFF9083252C16FE3960173722605E9E ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
13:50:52.0666 0544 IAStorDataMgrSvc - ok
13:50:52.0680 0544 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
13:50:52.0693 0544 iaStorV - ok
13:50:52.0703 0544 [ C1010ADD3DDAE1196ED21057AF7B2AAE ] ICCWDT C:\Windows\system32\DRIVERS\ICCWDT.sys
13:50:52.0704 0544 ICCWDT - ok
13:50:52.0745 0544 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:50:52.0756 0544 idsvc - ok
13:50:52.0760 0544 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:50:52.0762 0544 iirsp - ok
13:50:52.0814 0544 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
13:50:52.0825 0544 IKEEXT - ok
13:50:52.0900 0544 [ CAA8BC6737DFA3BF1A50175CFB226788 ] InputFilter_Hid_FlexDef2b C:\Windows\system32\DRIVERS\InputFilter_FlexDef2b.sys
13:50:52.0901 0544 InputFilter_Hid_FlexDef2b - ok
13:50:52.0976 0544 [ 589B94A9B73A0E819FF873743A480834 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
13:50:53.0008 0544 IntcAzAudAddService - ok
13:50:53.0012 0544 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
13:50:53.0014 0544 intelide - ok
13:50:53.0020 0544 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:50:53.0021 0544 intelppm - ok
13:50:53.0031 0544 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:50:53.0033 0544 IPBusEnum - ok
13:50:53.0047 0544 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:50:53.0049 0544 IpFilterDriver - ok
13:50:53.0077 0544 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:50:53.0082 0544 iphlpsvc - ok
13:50:53.0084 0544 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
13:50:53.0086 0544 IPMIDRV - ok
13:50:53.0122 0544 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
13:50:53.0142 0544 IPNAT - ok
13:50:53.0155 0544 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:50:53.0156 0544 IRENUM - ok
13:50:53.0159 0544 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:50:53.0160 0544 isapnp - ok
13:50:53.0165 0544 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
13:50:53.0169 0544 iScsiPrt - ok
13:50:53.0180 0544 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:50:53.0181 0544 kbdclass - ok
13:50:53.0184 0544 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:50:53.0185 0544 kbdhid - ok
13:50:53.0208 0544 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
13:50:53.0209 0544 KeyIso - ok
13:50:53.0235 0544 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:50:53.0237 0544 KSecDD - ok
13:50:53.0251 0544 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
13:50:53.0254 0544 KSecPkg - ok
13:50:53.0272 0544 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
13:50:53.0274 0544 ksthunk - ok
13:50:53.0303 0544 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
13:50:53.0309 0544 KtmRm - ok
13:50:53.0347 0544 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
13:50:53.0352 0544 LanmanServer - ok
13:50:53.0362 0544 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:50:53.0366 0544 LanmanWorkstation - ok
13:50:53.0396 0544 [ 8E4CA9AFD55EF6B509C80A8715ABF8C6 ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
13:50:53.0398 0544 lirsgt - ok
13:50:53.0433 0544 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:50:53.0451 0544 lltdio - ok
13:50:53.0480 0544 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:50:53.0500 0544 lltdsvc - ok
13:50:53.0505 0544 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:50:53.0507 0544 lmhosts - ok
13:50:53.0516 0544 lmimirr - ok
13:50:53.0523 0544 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:50:53.0526 0544 LSI_FC - ok
13:50:53.0530 0544 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:50:53.0531 0544 LSI_SAS - ok
13:50:53.0535 0544 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
13:50:53.0536 0544 LSI_SAS2 - ok
13:50:53.0539 0544 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:50:53.0540 0544 LSI_SCSI - ok
13:50:53.0543 0544 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
13:50:53.0545 0544 luafv - ok
13:50:53.0598 0544 [ 024DA28053D57E9E32BEE52600576BBB ] MarvinBus C:\Windows\system32\DRIVERS\MarvinBus64.sys
13:50:53.0602 0544 MarvinBus - ok
13:50:53.0639 0544 [ A8FE8F2783B2929B56F5370A89356CE9 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
13:50:53.0640 0544 MBAMProtector - ok
13:50:53.0704 0544 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
13:50:53.0707 0544 MBAMScheduler - ok
13:50:53.0760 0544 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
13:50:53.0766 0544 MBAMService - ok
13:50:53.0787 0544 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:50:53.0790 0544 Mcx2Svc - ok
13:50:53.0793 0544 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
13:50:53.0795 0544 megasas - ok
13:50:53.0800 0544 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
13:50:53.0804 0544 MegaSR - ok
13:50:53.0833 0544 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
13:50:53.0842 0544 MEIx64 - ok
13:50:53.0881 0544 Microsoft SharePoint Workspace Audit Service - ok
13:50:53.0890 0544 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
13:50:53.0893 0544 MMCSS - ok
13:50:53.0902 0544 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
13:50:53.0903 0544 Modem - ok
13:50:53.0916 0544 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:50:53.0916 0544 monitor - ok
13:50:53.0920 0544 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:50:53.0921 0544 mouclass - ok
13:50:53.0936 0544 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:50:53.0938 0544 mouhid - ok
13:50:53.0941 0544 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
13:50:53.0943 0544 mountmgr - ok
13:50:53.0994 0544 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
13:50:53.0997 0544 MozillaMaintenance - ok
13:50:54.0003 0544 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
13:50:54.0006 0544 mpio - ok
13:50:54.0015 0544 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:50:54.0017 0544 mpsdrv - ok
13:50:54.0041 0544 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
13:50:54.0052 0544 MpsSvc - ok
13:50:54.0086 0544 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:50:54.0090 0544 MRxDAV - ok
13:50:54.0103 0544 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:50:54.0106 0544 mrxsmb - ok
13:50:54.0134 0544 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:50:54.0139 0544 mrxsmb10 - ok
13:50:54.0144 0544 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:50:54.0147 0544 mrxsmb20 - ok
13:50:54.0151 0544 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
13:50:54.0152 0544 msahci - ok
13:50:54.0157 0544 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:50:54.0160 0544 msdsm - ok
13:50:54.0194 0544 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
13:50:54.0198 0544 MSDTC - ok
13:50:54.0205 0544 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:50:54.0207 0544 Msfs - ok
13:50:54.0224 0544 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
13:50:54.0225 0544 mshidkmdf - ok
13:50:54.0228 0544 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:50:54.0229 0544 msisadrv - ok
13:50:54.0248 0544 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:50:54.0259 0544 MSiSCSI - ok
13:50:54.0262 0544 msiserver - ok
13:50:54.0279 0544 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:50:54.0280 0544 MSKSSRV - ok
13:50:54.0300 0544 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:50:54.0302 0544 MSPCLOCK - ok
13:50:54.0313 0544 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:50:54.0315 0544 MSPQM - ok
13:50:54.0328 0544 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:50:54.0332 0544 MsRPC - ok
13:50:54.0374 0544 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:50:54.0374 0544 mssmbios - ok
13:50:54.0443 0544 MSSQL$SQLEXPRESS - ok
13:50:54.0498 0544 [ 7A2A8C975356858EB38466A6B1592E8D ] MSSQLServerADHelper100 c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
13:50:54.0500 0544 MSSQLServerADHelper100 - ok
13:50:54.0502 0544 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:50:54.0503 0544 MSTEE - ok
13:50:54.0505 0544 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
13:50:54.0506 0544 MTConfig - ok
13:50:54.0522 0544 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
13:50:54.0524 0544 Mup - ok
13:50:54.0553 0544 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
13:50:54.0561 0544 napagent - ok
13:50:54.0626 0544 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:50:54.0670 0544 NativeWifiP - ok
13:50:54.0738 0544 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:50:54.0745 0544 NDIS - ok
13:50:54.0762 0544 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
13:50:54.0764 0544 NdisCap - ok
13:50:54.0784 0544 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:50:54.0787 0544 NdisTapi - ok
13:50:54.0795 0544 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:50:54.0811 0544 Ndisuio - ok
13:50:54.0816 0544 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:50:54.0835 0544 NdisWan - ok
13:50:54.0844 0544 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:50:54.0846 0544 NDProxy - ok
13:50:54.0849 0544 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:50:54.0851 0544 NetBIOS - ok
13:50:54.0863 0544 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
13:50:54.0867 0544 NetBT - ok
13:50:54.0875 0544 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
13:50:54.0877 0544 Netlogon - ok
13:50:54.0901 0544 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
13:50:54.0905 0544 Netman - ok
13:50:54.0950 0544 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:50:54.0954 0544 NetMsmqActivator - ok
13:50:54.0958 0544 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:50:54.0960 0544 NetPipeActivator - ok
13:50:54.0981 0544 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
13:50:54.0988 0544 netprofm - ok
13:50:55.0048 0544 [ 618C55B392238B9467F9113E13525C49 ] netr28ux C:\Windows\system32\DRIVERS\netr28ux.sys
13:50:55.0059 0544 netr28ux - ok
13:50:55.0062 0544 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:50:55.0064 0544 NetTcpActivator - ok
13:50:55.0067 0544 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:50:55.0068 0544 NetTcpPortSharing - ok
13:50:55.0086 0544 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:50:55.0087 0544 nfrd960 - ok
13:50:55.0114 0544 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:50:55.0121 0544 NlaSvc - ok
13:50:55.0148 0544 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:50:55.0150 0544 Npfs - ok
13:50:55.0185 0544 npggsvc - ok
13:50:55.0189 0544 NPPTNT2 - ok
13:50:55.0193 0544 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
13:50:55.0196 0544 nsi - ok
13:50:55.0229 0544 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:50:55.0230 0544 nsiproxy - ok
13:50:55.0299 0544 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:50:55.0308 0544 Ntfs - ok
13:50:55.0321 0544 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
13:50:55.0321 0544 Null - ok
13:50:55.0350 0544 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:50:55.0352 0544 nvraid - ok
13:50:55.0357 0544 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:50:55.0369 0544 nvstor - ok
13:50:55.0378 0544 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:50:55.0380 0544 nv_agp - ok
13:50:55.0383 0544 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
13:50:55.0384 0544 ohci1394 - ok
13:50:55.0491 0544 [ C07B3ACBDDF9BCFDA8779A3B6D4414C3 ] OODefragAgent C:\Program Files\OO Software\Defrag\oodag.exe
13:50:55.0509 0544 OODefragAgent - ok
13:50:55.0561 0544 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:50:55.0565 0544 ose64 - ok
13:50:55.0720 0544 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
13:50:55.0738 0544 osppsvc - ok
13:50:55.0771 0544 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
13:50:55.0774 0544 p2pimsvc - ok
13:50:55.0795 0544 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
13:50:55.0799 0544 p2psvc - ok
13:50:55.0802 0544 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
13:50:55.0804 0544 Parport - ok
13:50:55.0833 0544 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:50:55.0848 0544 partmgr - ok
13:50:55.0861 0544 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
13:50:55.0863 0544 PcaSvc - ok
13:50:55.0877 0544 [ 3FDE033DFB0D07F8B7D5C9A3044AA121 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
13:50:55.0916 0544 pccsmcfd - ok
13:50:55.0920 0544 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
13:50:55.0921 0544 pci - ok
13:50:55.0923 0544 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
13:50:55.0924 0544 pciide - ok
13:50:55.0928 0544 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:50:55.0931 0544 pcmcia - ok
13:50:55.0933 0544 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
13:50:55.0934 0544 pcw - ok
13:50:55.0952 0544 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:50:55.0958 0544 PEAUTH - ok
13:50:56.0068 0544 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
13:50:56.0071 0544 PerfHost - ok
13:50:56.0111 0544 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
13:50:56.0124 0544 pla - ok
13:50:56.0181 0544 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:50:56.0191 0544 PlugPlay - ok
13:50:56.0203 0544 PnkBstrA - ok
13:50:56.0213 0544 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
13:50:56.0215 0544 PNRPAutoReg - ok
13:50:56.0222 0544 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
13:50:56.0226 0544 PNRPsvc - ok
13:50:56.0263 0544 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:50:56.0268 0544 PolicyAgent - ok
13:50:56.0287 0544 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
13:50:56.0289 0544 Power - ok
13:50:56.0300 0544 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:50:56.0301 0544 PptpMiniport - ok
13:50:56.0304 0544 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
13:50:56.0305 0544 Processor - ok
13:50:56.0339 0544 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
13:50:56.0342 0544 ProfSvc - ok
13:50:56.0353 0544 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:50:56.0354 0544 ProtectedStorage - ok
13:50:56.0381 0544 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
13:50:56.0383 0544 Psched - ok
13:50:56.0425 0544 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:50:56.0467 0544 ql2300 - ok
13:50:56.0472 0544 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:50:56.0489 0544 ql40xx - ok
13:50:56.0504 0544 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
13:50:56.0510 0544 QWAVE - ok
13:50:56.0519 0544 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:50:56.0537 0544 QWAVEdrv - ok
13:50:56.0548 0544 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:50:56.0550 0544 RasAcd - ok
13:50:56.0583 0544 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
13:50:56.0585 0544 RasAgileVpn - ok
13:50:56.0602 0544 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
13:50:56.0606 0544 RasAuto - ok
13:50:56.0611 0544 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:50:56.0645 0544 Rasl2tp - ok
13:50:56.0690 0544 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
13:50:56.0696 0544 RasMan - ok
13:50:56.0702 0544 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:50:56.0741 0544 RasPppoe - ok
13:50:56.0751 0544 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
...

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 14 pro 2012 13:52

...
13:50:56.0770 0544 RasSstp - ok
13:50:56.0820 0544 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:50:56.0825 0544 rdbss - ok
13:50:56.0829 0544 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
13:50:56.0830 0544 rdpbus - ok
13:50:56.0878 0544 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:50:56.0879 0544 RDPCDD - ok
13:50:56.0885 0544 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:50:56.0885 0544 RDPENCDD - ok
13:50:56.0890 0544 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
13:50:56.0890 0544 RDPREFMP - ok
13:50:56.0915 0544 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
13:50:56.0916 0544 RdpVideoMiniport - ok
13:50:56.0935 0544 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:50:56.0949 0544 RDPWD - ok
13:50:56.0954 0544 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
13:50:56.0957 0544 rdyboost - ok
13:50:56.0990 0544 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:50:56.0993 0544 RemoteAccess - ok
13:50:57.0013 0544 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:50:57.0016 0544 RemoteRegistry - ok
13:50:57.0034 0544 [ 9C3AC71A9934B884FAC567A8807E9C4D ] Revoflt C:\Windows\system32\DRIVERS\revoflt.sys
13:50:57.0036 0544 Revoflt - ok
13:50:57.0051 0544 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
13:50:57.0093 0544 RFCOMM - ok
13:50:57.0133 0544 [ CAF88D6573D21CD2AA27001DDBFDC74D ] RMCAST C:\Windows\system32\DRIVERS\RMCAST.sys
13:50:57.0136 0544 RMCAST - ok
13:50:57.0153 0544 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
13:50:57.0156 0544 RpcEptMapper - ok
13:50:57.0187 0544 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
13:50:57.0189 0544 RpcLocator - ok
13:50:57.0209 0544 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
13:50:57.0214 0544 RpcSs - ok
13:50:57.0267 0544 [ CD553B8633466A6D1C115812F2619F1F ] RsFx0103 C:\Windows\system32\DRIVERS\RsFx0103.sys
13:50:57.0272 0544 RsFx0103 - ok
13:50:57.0276 0544 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:50:57.0294 0544 rspndr - ok
13:50:57.0373 0544 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
13:50:57.0378 0544 RTL8167 - ok
13:50:57.0406 0544 [ 0031DD0C5D4446DA0A3E02617DC6D642 ] s1039bus C:\Windows\system32\DRIVERS\s1039bus.sys
13:50:57.0409 0544 s1039bus - ok
13:50:57.0434 0544 [ 98C7DBE2290D8CB0235E9528F6A1A53D ] s1039mdfl C:\Windows\system32\DRIVERS\s1039mdfl.sys
13:50:57.0436 0544 s1039mdfl - ok
13:50:57.0442 0544 [ 7EF052A067D862ECD2A2335914611074 ] s1039mdm C:\Windows\system32\DRIVERS\s1039mdm.sys
13:50:57.0445 0544 s1039mdm - ok
13:50:57.0450 0544 [ BCC3F31F1FE1E78A5BA2CD6A0E44BA64 ] s1039mgmt C:\Windows\system32\DRIVERS\s1039mgmt.sys
13:50:57.0453 0544 s1039mgmt - ok
13:50:57.0457 0544 [ A0CF11BFFA41176CCD54E701CEB68921 ] s1039nd5 C:\Windows\system32\DRIVERS\s1039nd5.sys
13:50:57.0459 0544 s1039nd5 - ok
13:50:57.0589 0544 [ BD2DA968C5DCEF51BA8014FBAC7A0B6A ] s1039obex C:\Windows\system32\DRIVERS\s1039obex.sys
13:50:57.0592 0544 s1039obex - ok
13:50:57.0598 0544 [ 96B4051B65C1974258A8A33A03C0B082 ] s1039unic C:\Windows\system32\DRIVERS\s1039unic.sys
13:50:57.0601 0544 s1039unic - ok
13:50:57.0608 0544 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
13:50:57.0610 0544 SamSs - ok
13:50:57.0614 0544 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:50:57.0633 0544 sbp2port - ok
13:50:57.0649 0544 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:50:57.0652 0544 SCardSvr - ok
13:50:57.0662 0544 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
13:50:57.0664 0544 scfilter - ok
13:50:57.0686 0544 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
13:50:57.0691 0544 Schedule - ok
13:50:57.0710 0544 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
13:50:57.0711 0544 SCPolicySvc - ok
13:50:57.0726 0544 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:50:57.0730 0544 SDRSVC - ok
13:50:57.0744 0544 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:50:57.0745 0544 secdrv - ok
13:50:57.0762 0544 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
13:50:57.0764 0544 seclogon - ok
13:50:57.0770 0544 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
13:50:57.0773 0544 SENS - ok
13:50:57.0783 0544 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
13:50:57.0785 0544 SensrSvc - ok
13:50:57.0798 0544 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
13:50:57.0800 0544 Serenum - ok
13:50:57.0816 0544 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
13:50:57.0818 0544 Serial - ok
13:50:57.0825 0544 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:50:57.0827 0544 sermouse - ok
13:50:57.0846 0544 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
13:50:57.0850 0544 SessionEnv - ok
13:50:57.0852 0544 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:50:57.0853 0544 sffdisk - ok
13:50:57.0856 0544 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:50:57.0857 0544 sffp_mmc - ok
13:50:57.0859 0544 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:50:57.0861 0544 sffp_sd - ok
13:50:57.0864 0544 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
13:50:57.0865 0544 sfloppy - ok
13:50:57.0910 0544 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:50:57.0916 0544 SharedAccess - ok
13:50:57.0936 0544 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:50:57.0940 0544 ShellHWDetection - ok
13:50:57.0942 0544 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
13:50:57.0944 0544 SiSRaid2 - ok
13:50:57.0948 0544 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:50:57.0960 0544 SiSRaid4 - ok
13:50:57.0981 0544 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:50:57.0983 0544 Smb - ok
13:50:58.0012 0544 [ FDB6E127DF739D4911319F0C8D339CAF ] snapman C:\Windows\system32\DRIVERS\snapman.sys
13:50:58.0015 0544 snapman - ok
13:50:58.0038 0544 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:50:58.0040 0544 SNMPTRAP - ok
13:50:58.0099 0544 [ 12583AF6CBE0050651EAF2723B3AD7B3 ] speedfan C:\Windows\syswow64\speedfan.sys
13:50:58.0102 0544 speedfan - ok
13:50:58.0106 0544 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
13:50:58.0118 0544 spldr - ok
13:50:58.0152 0544 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
13:50:58.0158 0544 Spooler - ok
13:50:58.0245 0544 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
13:50:58.0264 0544 sppsvc - ok
13:50:58.0275 0544 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
13:50:58.0278 0544 sppuinotify - ok
13:50:58.0312 0544 [ 602884696850C86434530790B110E8EB ] sptd C:\Windows\system32\Drivers\sptd.sys
13:50:58.0313 0544 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850C86434530790B110E8EB
13:50:58.0313 0544 sptd ( LockedFile.Multi.Generic ) - warning
13:50:58.0313 0544 sptd - detected LockedFile.Multi.Generic (1)
13:50:58.0347 0544 [ 12E6D95CDE974B131DEFAA44BAB8B056 ] SQLAgent$SQLEXPRESS c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
13:50:58.0351 0544 SQLAgent$SQLEXPRESS - ok
13:50:58.0367 0544 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
13:50:58.0371 0544 srv - ok
13:50:58.0390 0544 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:50:58.0394 0544 srv2 - ok
13:50:58.0397 0544 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:50:58.0399 0544 srvnet - ok
13:50:58.0414 0544 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:50:58.0416 0544 SSDPSRV - ok
13:50:58.0433 0544 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:50:58.0435 0544 SstpSvc - ok
13:50:58.0477 0544 Steam Client Service - ok
13:50:58.0480 0544 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
13:50:58.0482 0544 stexstor - ok
13:50:58.0505 0544 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
13:50:58.0512 0544 stisvc - ok
13:50:58.0525 0544 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:50:58.0526 0544 swenum - ok
13:50:58.0550 0544 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
13:50:58.0566 0544 swprv - ok
13:50:58.0724 0544 [ 4BF999638D299447F02477237D171CA5 ] syncagentsrv C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
13:50:58.0748 0544 syncagentsrv - ok
13:50:58.0790 0544 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
13:50:58.0828 0544 SysMain - ok
13:50:58.0847 0544 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:50:58.0850 0544 TabletInputService - ok
13:50:58.0880 0544 [ F9BE29D5E097F03F81D3CD12B794CB66 ] tap0901 C:\Windows\system32\DRIVERS\tap0901.sys
13:50:58.0880 0544 tap0901 - ok
13:50:58.0903 0544 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:50:58.0906 0544 TapiSrv - ok
13:50:58.0924 0544 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
13:50:58.0926 0544 TBS - ok
13:50:58.0972 0544 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:50:58.0980 0544 Tcpip - ok
13:50:59.0033 0544 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
13:50:59.0047 0544 TCPIP6 - ok
13:50:59.0068 0544 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:50:59.0069 0544 tcpipreg - ok
13:50:59.0076 0544 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:50:59.0078 0544 TDPIPE - ok
13:50:59.0117 0544 [ 843DAFC2CD4ED5D57FA40FD2000C6296 ] tdrpman C:\Windows\system32\DRIVERS\tdrpman.sys
13:50:59.0132 0544 tdrpman - ok
13:50:59.0158 0544 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:50:59.0192 0544 TDTCP - ok
13:50:59.0204 0544 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:50:59.0206 0544 tdx - ok
13:50:59.0363 0544 [ 851C5080261DFC1FCDC21DF0E5EA3BCB ] TeamViewer8 C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
13:50:59.0383 0544 TeamViewer8 - ok
13:50:59.0395 0544 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:50:59.0396 0544 TermDD - ok
13:50:59.0420 0544 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
13:50:59.0423 0544 TermService - ok
13:50:59.0434 0544 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
13:50:59.0435 0544 Themes - ok
13:50:59.0456 0544 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
13:50:59.0457 0544 THREADORDER - ok
13:50:59.0478 0544 [ 31C9790525705B292F3B30F6676873CD ] tib_mounter C:\Windows\system32\DRIVERS\tib_mounter.sys
13:50:59.0490 0544 tib_mounter - ok
13:50:59.0498 0544 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
13:50:59.0501 0544 TrkWks - ok
13:50:59.0536 0544 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:50:59.0538 0544 TrustedInstaller - ok
13:50:59.0549 0544 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:50:59.0552 0544 tssecsrv - ok
13:50:59.0580 0544 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
13:50:59.0582 0544 TsUsbFlt - ok
13:50:59.0612 0544 [ AD64450A4ABE076F5CB34CC08EEACB07 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
13:50:59.0614 0544 TsUsbGD - ok
13:50:59.0655 0544 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:50:59.0674 0544 tunnel - ok
13:50:59.0691 0544 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:50:59.0694 0544 uagp35 - ok
13:50:59.0711 0544 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:50:59.0725 0544 udfs - ok
13:50:59.0739 0544 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:50:59.0742 0544 UI0Detect - ok
13:50:59.0756 0544 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:50:59.0759 0544 uliagpkx - ok
13:50:59.0775 0544 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:50:59.0777 0544 umbus - ok
13:50:59.0793 0544 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
13:50:59.0795 0544 UmPass - ok
13:50:59.0818 0544 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
13:50:59.0824 0544 upnphost - ok
13:50:59.0843 0544 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:50:59.0846 0544 usbccgp - ok
13:50:59.0849 0544 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:50:59.0852 0544 usbcir - ok
13:50:59.0867 0544 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
13:50:59.0889 0544 usbehci - ok
13:50:59.0900 0544 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:50:59.0917 0544 usbhub - ok
13:50:59.0920 0544 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
13:50:59.0921 0544 usbohci - ok
13:50:59.0933 0544 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:50:59.0939 0544 usbprint - ok
13:50:59.0976 0544 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:50:59.0979 0544 usbscan - ok
13:50:59.0997 0544 [ 4ACEE387FA8FD39F83564FCD2FC234F2 ] usbser C:\Windows\system32\drivers\usbser.sys
13:50:59.0999 0544 usbser - ok
13:51:00.0004 0544 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:51:00.0006 0544 USBSTOR - ok
13:51:00.0009 0544 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
13:51:00.0011 0544 usbuhci - ok
13:51:00.0041 0544 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:51:00.0045 0544 usbvideo - ok
13:51:00.0061 0544 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
13:51:00.0065 0544 UxSms - ok
13:51:00.0075 0544 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
13:51:00.0076 0544 VaultSvc - ok
13:51:00.0102 0544 [ 58E2365E7FD880624F648C63C5D22009 ] VBoxNetAdp C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
13:51:00.0106 0544 VBoxNetAdp - ok
13:51:00.0109 0544 VBoxNetFlt - ok
13:51:00.0114 0544 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
13:51:00.0117 0544 vdrvroot - ok
13:51:00.0250 0544 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
13:51:00.0259 0544 vds - ok
13:51:00.0263 0544 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:51:00.0265 0544 vga - ok
13:51:00.0277 0544 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
13:51:00.0278 0544 VgaSave - ok
13:51:00.0291 0544 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
13:51:00.0320 0544 vhdmp - ok
13:51:00.0331 0544 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
13:51:00.0333 0544 viaide - ok
13:51:00.0338 0544 [ 927CBC96C4635F235301411E530FB56E ] vididr C:\Windows\system32\DRIVERS\vididr.sys
13:51:00.0340 0544 vididr - ok
13:51:00.0343 0544 [ 88B4E5C396003BCF479CA4D9BE851D57 ] vidsflt C:\Windows\system32\DRIVERS\vidsflt.sys
13:51:00.0345 0544 vidsflt - ok
13:51:00.0383 0544 [ 69F38919FF1510560D67F9A0B2375B01 ] vmci C:\Windows\system32\drivers\vmci.sys
13:51:00.0394 0544 vmci - ok
13:51:00.0411 0544 [ 3C37A81C995AEE1802C9D8DD9EA0E835 ] VMnetAdapter C:\Windows\system32\DRIVERS\vmnetadapter.sys
13:51:00.0412 0544 VMnetAdapter - ok
13:51:00.0415 0544 VMnetDHCP - ok
13:51:00.0440 0544 [ EA48BEF5BC53D6CB5FEC8F9BE088B337 ] VMnetuserif C:\Windows\system32\drivers\vmnetuserif.sys
13:51:00.0441 0544 VMnetuserif - ok
13:51:00.0445 0544 VMware NAT Service - ok
13:51:00.0462 0544 [ 1286147733E31FE4E40237EB289CD7A8 ] vmx86 C:\Windows\system32\drivers\vmx86.sys
13:51:00.0464 0544 vmx86 - ok
13:51:00.0468 0544 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:51:00.0471 0544 volmgr - ok
13:51:00.0479 0544 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:51:00.0484 0544 volmgrx - ok
13:51:00.0496 0544 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:51:00.0499 0544 volsnap - ok
13:51:00.0503 0544 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:51:00.0513 0544 vsmraid - ok
13:51:00.0546 0544 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
13:51:00.0560 0544 VSS - ok
13:51:00.0576 0544 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
13:51:00.0577 0544 vwifibus - ok
13:51:00.0602 0544 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
13:51:00.0605 0544 vwififlt - ok
13:51:00.0627 0544 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
13:51:00.0628 0544 vwifimp - ok
13:51:00.0642 0544 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
13:51:00.0649 0544 W32Time - ok
13:51:00.0655 0544 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:51:00.0657 0544 WacomPen - ok
13:51:00.0669 0544 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
13:51:00.0670 0544 WANARP - ok
13:51:00.0673 0544 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:51:00.0674 0544 Wanarpv6 - ok
13:51:00.0715 0544 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
13:51:00.0726 0544 WatAdminSvc - ok
13:51:00.0765 0544 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
13:51:00.0777 0544 wbengine - ok
13:51:00.0790 0544 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
13:51:00.0793 0544 WbioSrvc - ok
13:51:00.0805 0544 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:51:00.0809 0544 wcncsvc - ok
13:51:00.0818 0544 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:51:00.0820 0544 WcsPlugInService - ok
13:51:00.0822 0544 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
13:51:00.0823 0544 Wd - ok
13:51:00.0853 0544 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:51:00.0880 0544 Wdf01000 - ok
13:51:00.0929 0544 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:51:00.0931 0544 WdiServiceHost - ok
13:51:00.0934 0544 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:51:00.0935 0544 WdiSystemHost - ok
13:51:00.0953 0544 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
13:51:00.0965 0544 WebClient - ok
13:51:00.0979 0544 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:51:00.0985 0544 Wecsvc - ok
13:51:01.0005 0544 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:51:01.0009 0544 wercplsupport - ok
13:51:01.0040 0544 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
13:51:01.0044 0544 WerSvc - ok
13:51:01.0056 0544 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
13:51:01.0057 0544 WfpLwf - ok
13:51:01.0060 0544 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
13:51:01.0062 0544 WIMMount - ok
13:51:01.0084 0544 WinDefend - ok
13:51:01.0088 0544 WinHttpAutoProxySvc - ok
13:51:01.0144 0544 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:51:01.0148 0544 Winmgmt - ok
13:51:01.0202 0544 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
13:51:01.0254 0544 WinRM - ok
13:51:01.0298 0544 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
13:51:01.0314 0544 WinUsb - ok
13:51:01.0364 0544 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
13:51:01.0376 0544 Wlansvc - ok
13:51:01.0462 0544 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:51:01.0479 0544 wlidsvc - ok
13:51:01.0491 0544 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
13:51:01.0492 0544 WmiAcpi - ok
13:51:01.0510 0544 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:51:01.0512 0544 wmiApSrv - ok
13:51:01.0519 0544 WMPNetworkSvc - ok
13:51:01.0542 0544 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:51:01.0545 0544 WPCSvc - ok
13:51:01.0556 0544 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:51:01.0560 0544 WPDBusEnum - ok
13:51:01.0564 0544 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:51:01.0576 0544 ws2ifsl - ok
13:51:01.0593 0544 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
13:51:01.0595 0544 wscsvc - ok
13:51:01.0597 0544 WSearch - ok
13:51:01.0662 0544 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
13:51:01.0715 0544 wuauserv - ok
13:51:01.0734 0544 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
13:51:01.0743 0544 WudfPf - ok
13:51:01.0768 0544 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:51:01.0783 0544 WUDFRd - ok
13:51:01.0806 0544 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:51:01.0810 0544 wudfsvc - ok
13:51:01.0823 0544 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
13:51:01.0827 0544 WwanSvc - ok
13:51:01.0851 0544 xpvcom - ok
13:51:01.0911 0544 ================ Scan global ===============================
13:51:01.0932 0544 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
13:51:01.0949 0544 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
13:51:01.0957 0544 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
13:51:01.0971 0544 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
13:51:02.0002 0544 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
13:51:02.0007 0544 [Global] - ok
13:51:02.0007 0544 ================ Scan MBR ==================================
13:51:02.0023 0544 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
13:51:02.0030 0544 \Device\Harddisk0\DR0 - ok
13:51:02.0030 0544 ================ Scan VBR ==================================
13:51:02.0033 0544 [ 3F002AD76AC5F39DBA2033CE15851CC1 ] \Device\Harddisk0\DR0\Partition1
13:51:02.0034 0544 \Device\Harddisk0\DR0\Partition1 - ok
13:51:02.0043 0544 [ A1A1CC4BA4AE1C51FC0245E9B1587FFB ] \Device\Harddisk0\DR0\Partition2
13:51:02.0043 0544 \Device\Harddisk0\DR0\Partition2 - ok
13:51:02.0053 0544 [ 669379BCC8D2D469627DC615FF69537C ] \Device\Harddisk0\DR0\Partition3
13:51:02.0055 0544 \Device\Harddisk0\DR0\Partition3 - ok
13:51:02.0077 0544 [ 985799308AC34A0CF3BD42B091BEC98E ] \Device\Harddisk0\DR0\Partition4
13:51:02.0078 0544 \Device\Harddisk0\DR0\Partition4 - ok
13:51:02.0079 0544 ============================================================
13:51:02.0079 0544 Scan finished
13:51:02.0079 0544 ============================================================
13:51:02.0087 4640 Detected object count: 2
13:51:02.0087 4640 Actual detected object count: 2
13:51:03.0553 4640 DRIVER_B ( ForgedFile.Multi.Generic ) - skipped by user
13:51:03.0553 4640 DRIVER_B ( ForgedFile.Multi.Generic ) - User select action: Skip
13:51:03.0554 4640 sptd ( LockedFile.Multi.Generic ) - skipped by user
13:51:03.0554 4640 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 14 pro 2012 13:53

Combofix
ComboFix 12-12-13.02 - Samec 14.12.2012 13:37:14.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.8173.6557 [GMT 1:00]
Spuštěný z: c:\users\Samec\Desktop\ComboFix.exe
AV: ESET Smart Security 5.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\643A039E65.sys
c:\users\Samec\AppData\Local\Temp\sfamcc00001.dll
c:\users\Samec\AppData\Local\Temp\sfareca00001.dll
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-14 do 2012-12-14 )))))))))))))))))))))))))))))))
.
.
2012-12-14 11:39 . 2012-12-14 11:39 -------- d-----w- c:\users\Samec\AppData\Local\ATI
2012-12-14 11:39 . 2012-12-14 11:39 -------- d-----w- c:\users\Samec\AppData\Local\Apps
2012-12-13 10:56 . 2012-12-13 10:56 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2012-12-13 10:56 . 2012-12-13 10:56 -------- d-----w- c:\program files (x86)\Hamachi
2012-12-12 17:53 . 2012-12-12 17:53 -------- d-----w- c:\programdata\RELOADED
2012-12-12 17:50 . 2012-12-12 17:50 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-12-12 16:53 . 2012-12-12 16:53 367200 ----a-w- c:\windows\system32\drivers\afcdp.sys
2012-12-12 16:53 . 2012-12-12 16:53 1340040 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2012-12-12 16:53 . 2012-12-12 16:53 1093256 ----a-w- c:\windows\system32\drivers\tib_mounter.sys
2012-12-12 16:53 . 2012-12-12 16:53 228488 ----a-w- c:\windows\system32\drivers\vididr.sys
2012-12-12 16:53 . 2012-12-12 16:53 166024 ----a-w- c:\windows\system32\drivers\vidsflt.sys
2012-12-12 16:53 . 2012-12-12 16:53 340104 ----a-w- c:\windows\system32\drivers\snapman.sys
2012-12-12 16:52 . 2012-12-12 16:52 155272 ----a-w- c:\windows\system32\drivers\fltsrv.sys
2012-12-12 16:52 . 2012-12-12 16:53 -------- d-----w- c:\program files (x86)\Common Files\Acronis
2012-12-12 16:52 . 2012-12-12 16:52 -------- d-----w- c:\program files (x86)\Acronis
2012-12-12 16:03 . 2012-10-04 17:45 215040 ----a-w- c:\windows\system32\winsrv.dll
2012-12-09 19:41 . 2012-12-09 19:41 96224 ----a-w- c:\program files (x86)\Mozilla Firefox\updated\webapprt-stub.exe
2012-12-09 00:04 . 2012-12-09 00:04 -------- d-----w- c:\program files\ESET
2012-12-08 23:54 . 2010-11-20 05:27 680960 ----a-w- c:\windows\SysWow64\termsrv.dll
2012-12-08 23:54 . 2010-11-20 05:25 210944 ----a-w- c:\windows\SysWow64\rdpclip.exe
2012-12-03 20:05 . 2012-12-08 23:04 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared
2012-12-03 19:13 . 2012-12-08 23:06 -------- d-----w- c:\programdata\Norton
2012-12-03 19:13 . 2012-12-06 18:26 -------- d-----w- c:\program files (x86)\NortonInstaller
2012-11-29 19:43 . 2012-11-29 19:43 -------- d-----w- c:\program files (x86)\Microsoft WSE
2012-11-28 15:24 . 2012-11-28 15:24 -------- d-----w- c:\program files (x86)\Minecraft PC Gamer Demo
2012-11-28 15:21 . 2012-11-29 17:44 -------- d-----w- c:\users\Samec\AppData\Roaming\.minecraft
2012-11-19 17:13 . 2012-11-19 17:13 -------- d-----w- c:\program files (x86)\GNU
2012-11-19 16:53 . 2012-07-26 07:40 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wdf01000.sys.mui
2012-11-19 16:53 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-19 16:53 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-19 16:53 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-19 16:47 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-19 16:47 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-19 16:47 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-19 16:47 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-19 16:47 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-19 16:47 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-19 16:47 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-19 16:10 . 2012-09-25 22:47 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2012-11-19 16:10 . 2012-09-25 22:46 95744 ----a-w- c:\windows\system32\synceng.dll
2012-11-14 18:19 . 2012-11-14 18:19 -------- d-----w- C:\$AVG
2012-11-14 18:11 . 2012-11-14 18:11 -------- d--h--w- c:\programdata\Common Files
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-12 23:19 . 2011-06-24 12:43 67413224 ----a-w- c:\windows\system32\MRT.exe
2012-12-12 11:12 . 2012-10-27 22:10 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-12 11:12 . 2012-10-27 22:10 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-28 18:51 . 2012-10-28 18:51 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-27 23:00 . 2012-10-27 23:00 15823872 ----a-w- c:\users\Samec\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe
2012-10-27 23:00 . 2012-10-27 23:00 107008 ----a-w- c:\users\Samec\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
2012-10-27 22:59 . 2012-10-27 22:59 786492 ----a-w- c:\users\Samec\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe
2012-10-27 22:57 . 2012-10-27 22:57 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-10-27 22:56 . 2012-05-22 11:23 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-10-27 22:56 . 2011-06-24 13:31 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-10-16 08:38 . 2012-11-28 07:58 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 07:58 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 07:58 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-10-04 16:40 . 2012-12-12 16:03 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-10-02 13:41 . 2012-10-02 13:41 4873072 ----a-w- c:\windows\system32\ooscrsav.scr
2012-10-02 13:41 . 2012-10-02 13:41 256368 ----a-w- c:\windows\system32\oodbs.exe
2012-10-02 13:41 . 2012-10-02 13:41 537456 ----a-w- c:\windows\system32\oodssrs.dll
2012-10-02 13:40 . 2012-10-02 13:40 10096 ----a-w- c:\windows\system32\oodbsrs.dll
2012-09-29 17:54 . 2011-06-24 14:18 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-28 14:37 . 2012-09-28 14:37 221696 ----a-w- c:\windows\system32\clinfo.exe
2012-09-28 14:36 . 2012-09-28 14:36 75776 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-09-28 14:36 . 2012-09-28 14:36 65536 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-09-28 14:36 . 2012-09-28 14:36 63488 ----a-w- c:\windows\system32\OVDecode64.dll
2012-09-28 14:36 . 2012-09-28 14:36 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-09-28 14:36 . 2012-09-28 14:36 32635904 ----a-w- c:\windows\system32\amdocl64.dll
2012-09-28 14:32 . 2012-09-28 14:32 27341824 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-09-28 02:23 . 2012-04-06 01:34 5557928 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-09-28 02:21 . 2012-09-28 02:21 10697216 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-09-28 02:05 . 2012-09-28 02:05 70144 ----a-w- c:\windows\system32\coinst_9.002.dll
2012-09-28 02:03 . 2012-09-28 02:03 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-09-28 02:02 . 2012-09-28 02:02 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-09-28 02:02 . 2012-09-28 02:02 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-09-28 02:02 . 2012-09-28 02:02 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-09-28 02:02 . 2012-09-28 02:02 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-09-28 02:02 . 2012-09-28 02:02 16082432 ----a-w- c:\windows\system32\aticaldd64.dll
2012-09-28 01:59 . 2012-09-28 01:59 23825920 ----a-w- c:\windows\system32\atio6axx.dll
2012-09-28 01:57 . 2012-09-28 01:57 13703168 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-09-28 01:43 . 2011-03-09 04:56 935424 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-09-28 01:41 . 2011-03-09 04:55 1120768 ----a-w- c:\windows\system32\aticfx64.dll
2012-09-28 01:41 . 2012-09-28 01:41 19624960 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-09-28 01:39 . 2012-09-28 01:39 6536192 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-09-28 01:39 . 2012-09-28 01:39 442368 ----a-w- c:\windows\system32\atidemgy.dll
2012-09-28 01:39 . 2012-09-28 01:39 538112 ----a-w- c:\windows\system32\atieclxx.exe
2012-09-28 01:38 . 2012-09-28 01:38 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2012-09-28 01:36 . 2012-09-28 01:36 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-09-28 01:36 . 2012-09-28 01:36 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-09-28 01:36 . 2012-09-28 01:36 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-09-28 01:36 . 2012-09-28 01:36 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-09-28 01:31 . 2012-09-28 01:31 3127296 ----a-w- c:\windows\system32\atiumd6a.dll
2012-09-28 01:25 . 2012-09-28 01:25 6704640 ----a-w- c:\windows\system32\atiumd64.dll
2012-09-28 01:22 . 2011-03-09 04:40 7167488 ----a-w- c:\windows\system32\atidxx64.dll
2012-09-28 01:22 . 2012-04-06 01:22 2691584 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-09-28 01:13 . 2012-09-28 01:13 595456 ----a-w- c:\windows\system32\atiadlxx.dll
2012-09-28 01:13 . 2011-12-06 02:12 405504 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-09-28 01:13 . 2012-09-28 01:13 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-09-28 01:13 . 2012-09-28 01:13 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-09-28 01:13 . 2012-09-28 01:13 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-09-28 01:13 . 2012-09-28 01:13 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-09-28 01:13 . 2012-09-28 01:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-09-28 01:12 . 2012-09-28 01:12 56320 ----a-w- c:\windows\system32\atimpc64.dll
2012-09-28 01:12 . 2012-09-28 01:12 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2012-09-28 01:12 . 2012-09-28 01:12 460288 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-09-28 01:12 . 2012-09-28 01:12 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-09-28 01:12 . 2012-09-28 01:12 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-09-28 01:11 . 2011-03-09 04:17 129536 ----a-w- c:\windows\system32\atiuxp64.dll
2012-09-28 01:11 . 2012-09-28 01:11 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-09-28 01:11 . 2012-09-28 01:11 103424 ----a-w- c:\windows\system32\atiu9p64.dll
2012-09-28 01:10 . 2012-03-09 03:56 82944 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-09-28 01:09 . 2012-09-28 01:09 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-09-19 15:57 . 2012-09-19 15:57 17896 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2011-05-17 21:22 . 2011-05-17 21:20 98816 ----a-w- c:\program files (x86)\euroloader.exe
2011-05-13 13:01 . 2011-05-17 21:20 131584 ----a-w- c:\program files (x86)\gproxy.exe
2011-05-13 09:33 . 2011-05-17 21:20 3336 ----a-w- c:\program files (x86)\eurobattle.reg
2011-04-23 23:30 . 2011-05-17 21:20 68608 ----a-w- c:\program files (x86)\w3lh.dll
2003-04-10 15:56 . 2011-05-17 21:20 351744 ----a-w- c:\program files (x86)\winmpq.exe
2003-04-10 15:18 . 2011-05-17 21:20 184320 ----a-w- c:\program files (x86)\SFmpq.dll
1996-11-08 01:17 . 2011-05-17 21:20 721168 ----a-w- c:\program files (x86)\VB40032.DLL
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-09-28 642728]
.
c:\users\Samec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SpeedFan.lnk - c:\program files (x86)\SpeedFan\speedfan.exe [2012-3-26 4656632]
TeamViewer 7.lnk - c:\program files (x86)\TeamViewer\Version7\TeamViewer.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0oodbs
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936]
R3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
R3 DRIVER_B;DRIVER_B;c:\windows\system32\Drivers\DRIVER_BIN64 [2011-08-17 26424]
R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\EA Sports\FIFA Online 2\GameGuard\dump_wmimmc.sys [x]
R3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service;c:\windows\system32\DRIVERS\InputFilter_FlexDef2b.sys [2010-06-18 17920]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 31800]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [2010-03-15 127600]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 19568]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 161904]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 141424]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 34416]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [2010-03-15 137328]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [2010-03-15 158320]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-06-05 147288]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-24 1255736]
R3 xpvcom;XPVCOM Port;c:\windows\system32\Drivers\xpvcom.sys [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2012-03-14 62496]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys [2012-12-12 155272]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-06-24 834544]
S0 tib_mounter;Acronis TIB Mounter;c:\windows\system32\DRIVERS\tib_mounter.sys [2012-12-12 1093256]
S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys [2012-12-12 228488]
S0 vidsflt;Acronis Disk Storage Filter;c:\windows\system32\DRIVERS\vidsflt.sys [2012-12-12 166024]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2012-03-14 209768]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2012-03-14 148528]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2012-03-14 38288]
S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-12-12 3692536]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-09-28 239616]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.13\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2012-03-07 913144]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2012-10-02 2552176]
S2 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2012-09-14 7024712]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-11-29 3463080]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2009-10-20 65072]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2012-12-12 367200]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2011-01-27 125416]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2011-01-27 385512]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896]
S3 ICCWDT;Intel(R) Watchdog Timer Driver (Intel(R) WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [2010-08-17 26136]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-27 11:12]
.
2012-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-21 18:41]
.
2012-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-21 18:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncError]
@="{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}"
[HKEY_CLASSES_ROOT\CLSID\{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}]
2012-09-24 16:43 2737888 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncInProgress]
@="{00F848DC-B1D4-4892-9C25-CAADC86A215D}"
[HKEY_CLASSES_ROOT\CLSID\{00F848DC-B1D4-4892-9C25-CAADC86A215D}]
2012-09-24 16:43 2737888 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncOk]
@="{71573297-552E-46fc-BE3D-3DFAF88D47B7}"
[HKEY_CLASSES_ROOT\CLSID\{71573297-552E-46fc-BE3D-3DFAF88D47B7}]
2012-09-24 16:43 2737888 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 4081008]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: Interfaces\{23C2C53C-60B8-4D02-A942-0DDBB5C3FF73}: NameServer = 127.0.0.1
TCP: Interfaces\{8E3EDCCB-FE8E-4E23-9F5C-FF58C761CDBF}: NameServer = 127.0.0.1
FF - ProfilePath - c:\users\Samec\AppData\Roaming\Mozilla\Firefox\Profiles\7pxfj3vr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: network.proxy.type - 4
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-Run-Exetender_298 - c:\program files (x86)\Frag Games\GPlayer.exe
ShellIconOverlayIdentifiers-{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} - (no file)
ShellIconOverlayIdentifiers-{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} - (no file)
ShellIconOverlayIdentifiers-{A759AFF6-5851-457D-A540-F4ECED148351} - (no file)
ShellIconOverlayIdentifiers-{1574C9EF-7D58-488F-B358-8B78C1538F51} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DRIVER_B]
"ImagePath"="\??\c:\windows\system32\Drivers\DRIVER_BIN64"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.032"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.abr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ani"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.apd"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.arw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bay"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bmp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cr2"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.crw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cs1"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cur"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dcr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dcx"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dib"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.djv"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.djvu"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dng"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.emf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.eps"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.erf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.fff"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.fpx"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.gif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.hdr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.icl"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.icn"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.iff"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ilbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.int"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.inta"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.iw4"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.j2c"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.j2k"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jbr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jfif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jp2"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpc"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpe"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpeg"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpg"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpk"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpx"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.kdc"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.lbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mef"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mos"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mrw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.nef"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.nrw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.orf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pbr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pcd"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pct"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pcx"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pef"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pgm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pic"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pict"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pix"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.png"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ppm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.psd"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.psp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pspbrush"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pspimage"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.raf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ras"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.raw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rgb"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rgba"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rle"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rsb"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rw2"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rwl"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.sgi"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.sr2"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.srf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tga"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.thm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tiff"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ttc"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ttf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30po\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30po"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30pp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30pp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30ppf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30ppf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wbmp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wmf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xmp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xpm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:22,09,db,54,44,49,6a,6a,6e,0b,e1,f6,2c,bf,05,82,06,75,11,b6,f5,ed,6f,
6e,06,58,db,39,88,a6,9b,56,62,e0,ef,62,4a,92,26,91,ad,85,9b,60,4d,c3,a0,78,\
"??"=hex:23,e1,36,fe,fd,ef,7e,0d,55,91,d8,81,b5,7b,35,54
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\SecuROM\License information*]
"datasecu"=hex:66,0b,b3,06,4a,01,1b,7b,61,48,bf,c8,3b,4d,d3,5e,dc,1d,fa,a3,c9,
ca,74,38,ba,aa,92,a4,91,9b,85,24,24,c4,0c,71,b0,65,a3,fa,68,20,d0,81,cf,ec,\
"rkeysecu"=hex:c8,53,e3,8b,b6,3f,36,8f,fb,c3,f7,a8,db,dd,b9,6e
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="4E4F432CE939A5B13AF76087DEF1335D3CD7BFFB3EDEA2FE62C5C878BD45DC25106F7D719A310902CDDECB62088D4134699F37DE82C82227666A4738DE0D28F440644E2BB707DAE8776C002726BA4A82F57CD3A0C7E75998BC96B9EE19085E7AE4C01FC31D4C0BB37215C1AAD73AAC4EEFE5D69D914F34B166617FA5F6B6198E15DA890EF9928054891187A611D1B9407A91B3983A141176FB2628C5D521E3AA7ECF5BBBD07391DD9F5D7CB71B4AB9A6CA7F9438ECCEC28B2880F9206851BDEFFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98088EDD5E5BE2F6E6675D575E7D6A3B98085D575E7D6A3B98082A2E67CE728862D912C5AAFEAFAEF9120993F429A25CCCB6BFA4B4CBF3A57AD241D3F8CF9FF0378CD97A68AA8FB1A50C5FAE060E00AC83F73E8F42AEBB4C277DD9286313A40DCC6F3D58377808ECAC6A1DD91AC5CBF7F1932747490A665BEEE4A1C00893A48D2D81DE189490C101C724790DECC0D5F29C1C67A361B80738C1525C767BB6982857E575AF327EBB17A3D73F84EB543F547CC5003FD4F8064906B2DE668640CC18BFE24E60F4314657DFC3D0BD393880D87E69087DA4EB9E7C961A147124DCE3194C64C62CF5FB08728FCB21FC2C886240040526000415DFC2C0BCF9BD079AD06ED878D2D88396FA1ABCF7B9C84F4684CC62379930D8DF3011C675A33492695DDCB3D1796E209DEB04E074B46CE056DA4762463339C01944DFDDC1B581DE2326AD9F48D63E7F8D7E6DEE9045F6D2002A7A409A570C8A7228A9B143EB95B9809B2FD35719D88BCB261248412DBBCD6F8F37ADC201DBB9803E725F401429A19F83B37C1C831563A02EB6461D46D12A3777CFD06DBBA106BDB8BC79A290314E83F48F37DA6F0CD635342135E0FB957649251D40F0A919D9869E9284F8D76EA4925E1D17F8461D6B9AA99CD36CCE23777F317A0B450043D59C4CFEFC7374DFC3967FB9A40306695CC3D3F6D744536021168547B18887E3CDA572134EE803CAFABE6D47D9A645D71507CE03E70FB1F31F2C5F6628791F8248AA14E4DC5437B84F1E10AA25B7A89138A10597A099A5485048D2C05900366C019A080C7C5157F779A8A6CE692D6C069BB1BA8F92D2808DC65147C1A0A2D230E8447C247824BD97653A3F21002160E6483B0449C0CFA536C81476D8508F8E23A15EEECF0FB1576EB392BF92B2D2E62A7B254CA7A3470DF8D0C0EEF9AC17965C840334B1F082A8143A516198BE257809A6BB5011A716C3510E6C931DEE2EAAB99A2FF3744647C5677FFEB0AED91F1E84702D23702C3C6BFEE28E9DBC446D23DA2543294427CFDA08C0068E4F296BF85B318DA8B3855DB505E50494584C9266A29706A5D0A292A45CEFB22E0048593C96F7D39A4EFBC0"
"OODEFRAG16.00.00.01PROFESSIONAL"="772FF01F0188454BB14E2A6939430DC5AC88B55123C90BD97597D5519565995D51DAE95F76F4DD20259E15EC50BE5432AF72C0712FD03C2C9111E60056E7499FA4D82D76BA7828FEA7CA5435573451A2B2AAF06BCEACB3DF841DFB72D7039F2413632D347DA1162E7EA0A5293690534B422F7062BED03A2E3E08CC23C8C786CD93B9CB8D83C4CE5A46ED39D6E30BDDBF3D7F5CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6171C11EC38DE3DA6A0AC4980AC79338EDD5E5BE2F6E667DD02BFC5E9317CB957B3A95D185DFE272D564996AE430D0D6061B51BD5ED77AD79CF563A19D395D13CECEFBC645458047B743D0B9A7DEE9DEA07291DB7267F228FE203C57E5771EDB700D2C1C2013D2F0563B31EB4075537095BC76BC6969E12ECF630C7214F76762EDD1FA8223D467F69E8F90A711FAB3E329B7FDD2280310E7FDC0B50672391C8A88C665FD3B2104068DF203B2CD45E88009681FB4E7A93195D7889A99E8C31B5D3A4F98B8C623C2CE9367C51248DE0E1B3AFC50432ED2A2C3DC0614B779A4A037F537584659FEE78F5ECA6A2F90226882F5E06E619175A33F9C48D650531D36823DB32D3DD92CFCABC9BFC36363F29B0F8AC3F4BB2898F0E9522CE59C0054915D690D0BAD5370C3B8EEC20C8C1A568803CBA350A92AAB810338EA53F07A2A92856DC36AD12DB5659E19EF54B6A696514C83C6C312FB4C7029A525B5F19E6F9B6033D0BD0BD255F26CF8327E1649424F88F783002E3B4B2203748FAB99887424AE1C3B903E48CE3991700A06545832FB2A8C90F71F00CF51A99E2530210880C609B94F3D1795A1E1C99119361876614B84E9FD9A87A710F947525F69B6C47E8E87E69AC82D031CE8BDCC275980943E5F561FEA60706ED01A62227BCA37CEF6CC9F80F9D0B24843B3A8A387FFC0DF038C862FC529C8060525C9C164168F5072CDBA2E7C117111AACEEF1272EB9399DA505F9C5F62FB7F98DB505B0636A6FE1466C326859869810ED6383DB4329184ACB7171977A3961C0C1A71D4D4562672D593B069A686DA0D4D144D4B1435C984B4C49394880E5130D021ACF52CE3BBDE5097F9E1A3792F12DAA36221D78188C494C3B633C731AC80E63E7A53DAA9036DFFC609F1BD271BB2F534D46A3EF55ABC0766A26F08268E0458162D19EC8B7F7C1E07BD3DF0A3A0D492793C56079BF0E8378EC5E741F9CA088FBCC25985BB59206E362A7C2F1505DB807084480ABB7343503D089EA80322E01F25F9A665A4674FA3B192B31634A8392581C0EC55E53FE4F4B11CA0B1FDC952E8F46CBD101D672459C19142D7875BF3E03B58F8730D9369E8D24691F3A00C6DF7BA1F8BCCD0AC4D9C44FBACA12CFB077F2AFDA30804703C204EECF08D33693"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\vmnat.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe
c:\program files (x86)\TeamViewer\Version8\tv_w32.exe
.
**************************************************************************
.
Celkový čas: 2012-12-14 13:49:21 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-12-14 12:49
.
Před spuštěním: Volných bajtů: 455 901 601 792
Po spuštění: Volných bajtů: 456 188 755 968
.
- - End Of File - - E070257838A7A783CF2586AEBE32B213

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 14 pro 2012 20:27

Co dál? Díky :-)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod jaro3 » 14 pro 2012 22:26

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Folder::
c:\program files (x86)\Common Files\Symantec Shared
c:\programdata\Norton
c:\program files (x86)\NortonInstaller
C:\$AVG
c:\program files (x86)\Google\Update

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]



Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\users\Samec\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
c:\users\Samec\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe
c:\windows\system32\ooscrsav.scr
c:\windows\system32\oodbs.exe
c:\windows\system32\oodssrs.dll
c:\windows\system32\oodbsrs.dll
c:\program files (x86)\euroloader.exe

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 15 pro 2012 00:38

ComboFix 12-12-14.01 - Samec 15.12.2012 0:24.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.8173.6583 [GMT 1:00]
Spuštěný z: c:\users\Samec\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Samec\Desktop\CFScript.txt
AV: ESET Smart Security 5.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\$AVG
c:\program files (x86)\Common Files\Symantec Shared
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.124\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.124\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.124\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.124\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.124\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.21.124\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.124\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.124\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.124\psuser.dll
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.125\GoogleUpdateB6998767.exe
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\23.0.1271.97\23.0.1271.97_23.0.1271.95_chrome_updater.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\NortonInstaller
c:\programdata\Norton
c:\programdata\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963}\LC.INI
c:\programdata\Norton\{B7B64E4E-97E8-48AA-AF62-F11B5FF9819D}\90011CA09AB108BC8F7CC66FF5D9E1EA\shared_1.0.dat
c:\programdata\Norton\{B7B64E4E-97E8-48AA-AF62-F11B5FF9819D}\common.dat
c:\programdata\Norton\{NM32019-ESD-FSD31014}-S-1-5-18.dat
c:\programdata\Norton\00000082\0000012a\0000065a\cltLMS1.dat
c:\programdata\Norton\00000082\0000012a\0000065a\cltLMS2.dat
c:\programdata\Norton\URLS-{NM32019-ESD-FSD31014}-S-1-5-18.txt
c:\users\Samec\AppData\Local\Temp\sfamcc00001.dll
c:\users\Samec\AppData\Local\Temp\sfareca00001.dll
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-14 do 2012-12-14 )))))))))))))))))))))))))))))))
.
.
2012-12-14 11:39 . 2012-12-14 11:39 -------- d-----w- c:\users\Samec\AppData\Local\ATI
2012-12-14 11:39 . 2012-12-14 11:39 -------- d-----w- c:\users\Samec\AppData\Local\Apps
2012-12-13 10:56 . 2012-12-13 10:56 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2012-12-13 10:56 . 2012-12-13 10:56 -------- d-----w- c:\program files (x86)\Hamachi
2012-12-12 17:53 . 2012-12-12 17:53 -------- d-----w- c:\programdata\RELOADED
2012-12-12 17:50 . 2012-12-12 17:50 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-12-12 16:53 . 2012-12-12 16:53 367200 ----a-w- c:\windows\system32\drivers\afcdp.sys
2012-12-12 16:53 . 2012-12-12 16:53 1340040 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2012-12-12 16:53 . 2012-12-12 16:53 1093256 ----a-w- c:\windows\system32\drivers\tib_mounter.sys
2012-12-12 16:53 . 2012-12-12 16:53 228488 ----a-w- c:\windows\system32\drivers\vididr.sys
2012-12-12 16:53 . 2012-12-12 16:53 166024 ----a-w- c:\windows\system32\drivers\vidsflt.sys
2012-12-12 16:53 . 2012-12-12 16:53 340104 ----a-w- c:\windows\system32\drivers\snapman.sys
2012-12-12 16:52 . 2012-12-12 16:52 155272 ----a-w- c:\windows\system32\drivers\fltsrv.sys
2012-12-12 16:52 . 2012-12-12 16:53 -------- d-----w- c:\program files (x86)\Common Files\Acronis
2012-12-12 16:52 . 2012-12-12 16:52 -------- d-----w- c:\program files (x86)\Acronis
2012-12-12 16:03 . 2012-10-04 17:45 215040 ----a-w- c:\windows\system32\winsrv.dll
2012-12-09 19:41 . 2012-12-09 19:41 96224 ----a-w- c:\program files (x86)\Mozilla Firefox\updated\webapprt-stub.exe
2012-12-09 00:04 . 2012-12-09 00:04 -------- d-----w- c:\program files\ESET
2012-12-08 23:54 . 2010-11-20 05:27 680960 ----a-w- c:\windows\SysWow64\termsrv.dll
2012-12-08 23:54 . 2010-11-20 05:25 210944 ----a-w- c:\windows\SysWow64\rdpclip.exe
2012-12-03 19:13 . 2012-12-03 19:26 -------- d-----w- c:\programdata\NortonInstaller
2012-11-29 19:43 . 2012-11-29 19:43 -------- d-----w- c:\program files (x86)\Microsoft WSE
2012-11-28 15:24 . 2012-11-28 15:24 -------- d-----w- c:\program files (x86)\Minecraft PC Gamer Demo
2012-11-28 15:21 . 2012-11-29 17:44 -------- d-----w- c:\users\Samec\AppData\Roaming\.minecraft
2012-11-19 17:13 . 2012-11-19 17:13 -------- d-----w- c:\program files (x86)\GNU
2012-11-19 16:53 . 2012-07-26 07:40 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wdf01000.sys.mui
2012-11-19 16:53 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-19 16:53 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-19 16:53 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-19 16:47 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-19 16:47 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-19 16:47 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-19 16:47 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-19 16:47 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-19 16:47 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-19 16:47 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-19 16:10 . 2012-09-25 22:47 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2012-11-19 16:10 . 2012-09-25 22:46 95744 ----a-w- c:\windows\system32\synceng.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-12 23:19 . 2011-06-24 12:43 67413224 ----a-w- c:\windows\system32\MRT.exe
2012-12-12 11:12 . 2012-10-27 22:10 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-12 11:12 . 2012-10-27 22:10 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-28 18:51 . 2012-10-28 18:51 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-27 23:00 . 2012-10-27 23:00 15823872 ----a-w- c:\users\Samec\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe
2012-10-27 23:00 . 2012-10-27 23:00 107008 ----a-w- c:\users\Samec\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
2012-10-27 22:59 . 2012-10-27 22:59 786492 ----a-w- c:\users\Samec\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe
2012-10-27 22:57 . 2012-10-27 22:57 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-10-27 22:56 . 2012-05-22 11:23 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-10-27 22:56 . 2011-06-24 13:31 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-10-16 08:38 . 2012-11-28 07:58 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 07:58 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 07:58 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-10-04 16:40 . 2012-12-12 16:03 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-10-02 13:41 . 2012-10-02 13:41 4873072 ----a-w- c:\windows\system32\ooscrsav.scr
2012-10-02 13:41 . 2012-10-02 13:41 256368 ----a-w- c:\windows\system32\oodbs.exe
2012-10-02 13:41 . 2012-10-02 13:41 537456 ----a-w- c:\windows\system32\oodssrs.dll
2012-10-02 13:40 . 2012-10-02 13:40 10096 ----a-w- c:\windows\system32\oodbsrs.dll
2012-09-29 17:54 . 2011-06-24 14:18 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-28 14:37 . 2012-09-28 14:37 221696 ----a-w- c:\windows\system32\clinfo.exe
2012-09-28 14:36 . 2012-09-28 14:36 75776 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-09-28 14:36 . 2012-09-28 14:36 65536 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-09-28 14:36 . 2012-09-28 14:36 63488 ----a-w- c:\windows\system32\OVDecode64.dll
2012-09-28 14:36 . 2012-09-28 14:36 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-09-28 14:36 . 2012-09-28 14:36 32635904 ----a-w- c:\windows\system32\amdocl64.dll
2012-09-28 14:32 . 2012-09-28 14:32 27341824 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-09-28 02:23 . 2012-04-06 01:34 5557928 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-09-28 02:21 . 2012-09-28 02:21 10697216 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-09-28 02:05 . 2012-09-28 02:05 70144 ----a-w- c:\windows\system32\coinst_9.002.dll
2012-09-28 02:03 . 2012-09-28 02:03 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-09-28 02:02 . 2012-09-28 02:02 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-09-28 02:02 . 2012-09-28 02:02 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-09-28 02:02 . 2012-09-28 02:02 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-09-28 02:02 . 2012-09-28 02:02 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-09-28 02:02 . 2012-09-28 02:02 16082432 ----a-w- c:\windows\system32\aticaldd64.dll
2012-09-28 01:59 . 2012-09-28 01:59 23825920 ----a-w- c:\windows\system32\atio6axx.dll
2012-09-28 01:57 . 2012-09-28 01:57 13703168 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-09-28 01:43 . 2011-03-09 04:56 935424 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-09-28 01:41 . 2011-03-09 04:55 1120768 ----a-w- c:\windows\system32\aticfx64.dll
2012-09-28 01:41 . 2012-09-28 01:41 19624960 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-09-28 01:39 . 2012-09-28 01:39 6536192 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-09-28 01:39 . 2012-09-28 01:39 442368 ----a-w- c:\windows\system32\atidemgy.dll
2012-09-28 01:39 . 2012-09-28 01:39 538112 ----a-w- c:\windows\system32\atieclxx.exe
2012-09-28 01:38 . 2012-09-28 01:38 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2012-09-28 01:36 . 2012-09-28 01:36 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-09-28 01:36 . 2012-09-28 01:36 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-09-28 01:36 . 2012-09-28 01:36 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-09-28 01:36 . 2012-09-28 01:36 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-09-28 01:31 . 2012-09-28 01:31 3127296 ----a-w- c:\windows\system32\atiumd6a.dll
2012-09-28 01:25 . 2012-09-28 01:25 6704640 ----a-w- c:\windows\system32\atiumd64.dll
2012-09-28 01:22 . 2011-03-09 04:40 7167488 ----a-w- c:\windows\system32\atidxx64.dll
2012-09-28 01:22 . 2012-04-06 01:22 2691584 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-09-28 01:13 . 2012-09-28 01:13 595456 ----a-w- c:\windows\system32\atiadlxx.dll
2012-09-28 01:13 . 2011-12-06 02:12 405504 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-09-28 01:13 . 2012-09-28 01:13 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-09-28 01:13 . 2012-09-28 01:13 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-09-28 01:13 . 2012-09-28 01:13 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-09-28 01:13 . 2012-09-28 01:13 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-09-28 01:13 . 2012-09-28 01:13 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-09-28 01:12 . 2012-09-28 01:12 56320 ----a-w- c:\windows\system32\atimpc64.dll
2012-09-28 01:12 . 2012-09-28 01:12 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2012-09-28 01:12 . 2012-09-28 01:12 460288 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-09-28 01:12 . 2012-09-28 01:12 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-09-28 01:12 . 2012-09-28 01:12 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2012-09-28 01:11 . 2011-03-09 04:17 129536 ----a-w- c:\windows\system32\atiuxp64.dll
2012-09-28 01:11 . 2012-09-28 01:11 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-09-28 01:11 . 2012-09-28 01:11 103424 ----a-w- c:\windows\system32\atiu9p64.dll
2012-09-28 01:10 . 2012-03-09 03:56 82944 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-09-28 01:09 . 2012-09-28 01:09 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-09-19 15:57 . 2012-09-19 15:57 17896 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2011-05-17 21:22 . 2011-05-17 21:20 98816 ----a-w- c:\program files (x86)\euroloader.exe
2011-05-13 13:01 . 2011-05-17 21:20 131584 ----a-w- c:\program files (x86)\gproxy.exe
2011-05-13 09:33 . 2011-05-17 21:20 3336 ----a-w- c:\program files (x86)\eurobattle.reg
2011-04-23 23:30 . 2011-05-17 21:20 68608 ----a-w- c:\program files (x86)\w3lh.dll
2003-04-10 15:56 . 2011-05-17 21:20 351744 ----a-w- c:\program files (x86)\winmpq.exe
2003-04-10 15:18 . 2011-05-17 21:20 184320 ----a-w- c:\program files (x86)\SFmpq.dll
1996-11-08 01:17 . 2011-05-17 21:20 721168 ----a-w- c:\program files (x86)\VB40032.DLL
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2011-03-08 393216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-09-28 642728]
.
c:\users\Samec\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SpeedFan.lnk - c:\program files (x86)\SpeedFan\speedfan.exe [2012-3-26 4656632]
TeamViewer 7.lnk - c:\program files (x86)\TeamViewer\Version7\TeamViewer.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0oodbs
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936]
R3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
R3 DRIVER_B;DRIVER_B;c:\windows\system32\Drivers\DRIVER_BIN64 [2011-08-17 26424]
R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\EA Sports\FIFA Online 2\GameGuard\dump_wmimmc.sys [x]
R3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service;c:\windows\system32\DRIVERS\InputFilter_FlexDef2b.sys [2010-06-18 17920]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 31800]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [2010-03-15 127600]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 19568]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 161904]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 141424]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 34416]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [2010-03-15 137328]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [2010-03-15 158320]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-06-05 147288]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-24 1255736]
R3 xpvcom;XPVCOM Port;c:\windows\system32\Drivers\xpvcom.sys [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2012-03-14 62496]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys [2012-12-12 155272]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-06-24 834544]
S0 tib_mounter;Acronis TIB Mounter;c:\windows\system32\DRIVERS\tib_mounter.sys [2012-12-12 1093256]
S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys [2012-12-12 228488]
S0 vidsflt;Acronis Disk Storage Filter;c:\windows\system32\DRIVERS\vidsflt.sys [2012-12-12 166024]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2012-03-14 209768]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2012-03-14 148528]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2012-03-14 38288]
S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-12-12 3692536]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-09-28 239616]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.13\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2012-03-07 913144]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2012-10-02 2552176]
S2 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2012-09-14 7024712]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-11-29 3463080]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2009-10-20 65072]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2012-12-12 367200]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2011-01-27 125416]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2011-01-27 385512]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896]
S3 ICCWDT;Intel(R) Watchdog Timer Driver (Intel(R) WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [2010-08-17 26136]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-27 11:12]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncError]
@="{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}"
[HKEY_CLASSES_ROOT\CLSID\{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}]
2012-09-24 16:43 2737888 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncInProgress]
@="{00F848DC-B1D4-4892-9C25-CAADC86A215D}"
[HKEY_CLASSES_ROOT\CLSID\{00F848DC-B1D4-4892-9C25-CAADC86A215D}]
2012-09-24 16:43 2737888 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncOk]
@="{71573297-552E-46fc-BE3D-3DFAF88D47B7}"
[HKEY_CLASSES_ROOT\CLSID\{71573297-552E-46fc-BE3D-3DFAF88D47B7}]
2012-09-24 16:43 2737888 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 4081008]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: Interfaces\{23C2C53C-60B8-4D02-A942-0DDBB5C3FF73}: NameServer = 127.0.0.1
TCP: Interfaces\{8E3EDCCB-FE8E-4E23-9F5C-FF58C761CDBF}: NameServer = 127.0.0.1
FF - ProfilePath - c:\users\Samec\AppData\Roaming\Mozilla\Firefox\Profiles\7pxfj3vr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: network.proxy.type - 4
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} - (no file)
ShellIconOverlayIdentifiers-{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} - (no file)
ShellIconOverlayIdentifiers-{A759AFF6-5851-457D-A540-F4ECED148351} - (no file)
ShellIconOverlayIdentifiers-{1574C9EF-7D58-488F-B358-8B78C1538F51} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DRIVER_B]
"ImagePath"="\??\c:\windows\system32\Drivers\DRIVER_BIN64"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.032"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.abr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ani"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.apd"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.arw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bay"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bmp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.bw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cr2"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.crw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cs1"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.cur"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dcr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dcx"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dib"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.djv"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.djvu"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.dng"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.emf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.eps"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.erf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.fff"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.fpx"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.gif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.hdr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.icl"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.icn"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.iff"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ilbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.int"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.inta"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.iw4"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.j2c"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.j2k"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jbr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jfif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jp2"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpc"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpe"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpeg"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpg"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpk"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.jpx"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.kdc"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.lbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mef"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mos"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.mrw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.nef"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.nrw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.orf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pbr"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pcd"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pct"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pcx"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pef"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pgm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pic"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pict"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pix"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.png"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ppm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.psd"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.psp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pspbrush"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.pspimage"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.raf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ras"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.raw"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rgb"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rgba"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rle"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rsb"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rw2"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.rwl"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.sgi"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.sr2"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.srf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tga"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.thm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.tiff"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ttc"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.ttf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30po\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30po"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30pp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30pp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30ppf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.v30ppf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wbmp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.wmf"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xbm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xif"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xmp"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 12.xpm"
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:22,09,db,54,44,49,6a,6a,6e,0b,e1,f6,2c,bf,05,82,06,75,11,b6,f5,ed,6f,
6e,06,58,db,39,88,a6,9b,56,62,e0,ef,62,4a,92,26,91,ad,85,9b,60,4d,c3,a0,78,\
"??"=hex:23,e1,36,fe,fd,ef,7e,0d,55,91,d8,81,b5,7b,35,54
.
[HKEY_USERS\S-1-5-21-781265752-978899382-4182636110-1001\Software\SecuROM\License information*]
"datasecu"=hex:66,0b,b3,06,4a,01,1b,7b,61,48,bf,c8,3b,4d,d3,5e,dc,1d,fa,a3,c9,
ca,74,38,ba,aa,92,a4,91,9b,85,24,24,c4,0c,71,b0,65,a3,fa,68,20,d0,81,cf,ec,\
"rkeysecu"=hex:c8,53,e3,8b,b6,3f,36,8f,fb,c3,f7,a8,db,dd,b9,6e
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="4E4F432CE939A5B13AF76087DEF1335D3CD7BFFB3EDEA2FE62C5C878BD45DC25106F7D719A310902CDDECB62088D4134699F37DE82C82227666A4738DE0D28F440644E2BB707DAE8776C002726BA4A82F57CD3A0C7E75998BC96B9EE19085E7AE4C01FC31D4C0BB37215C1AAD73AAC4EEFE5D69D914F34B166617FA5F6B6198E15DA890EF9928054891187A611D1B9407A91B3983A141176FB2628C5D521E3AA7ECF5BBBD07391DD9F5D7CB71B4AB9A6CA7F9438ECCEC28B2880F9206851BDEFFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98088EDD5E5BE2F6E6675D575E7D6A3B98085D575E7D6A3B98082A2E67CE728862D912C5AAFEAFAEF9120993F429A25CCCB6BFA4B4CBF3A57AD241D3F8CF9FF0378CD97A68AA8FB1A50C5FAE060E00AC83F73E8F42AEBB4C277DD9286313A40DCC6F3D58377808ECAC6A1DD91AC5CBF7F1932747490A665BEEE4A1C00893A48D2D81DE189490C101C724790DECC0D5F29C1C67A361B80738C1525C767BB6982857E575AF327EBB17A3D73F84EB543F547CC5003FD4F8064906B2DE668640CC18BFE24E60F4314657DFC3D0BD393880D87E69087DA4EB9E7C961A147124DCE3194C64C62CF5FB08728FCB21FC2C886240040526000415DFC2C0BCF9BD079AD06ED878D2D88396FA1ABCF7B9C84F4684CC62379930D8DF3011C675A33492695DDCB3D1796E209DEB04E074B46CE056DA4762463339C01944DFDDC1B581DE2326AD9F48D63E7F8D7E6DEE9045F6D2002A7A409A570C8A7228A9B143EB95B9809B2FD35719D88BCB261248412DBBCD6F8F37ADC201DBB9803E725F401429A19F83B37C1C831563A02EB6461D46D12A3777CFD06DBBA106BDB8BC79A290314E83F48F37DA6F0CD635342135E0FB957649251D40F0A919D9869E9284F8D76EA4925E1D17F8461D6B9AA99CD36CCE23777F317A0B450043D59C4CFEFC7374DFC3967FB9A40306695CC3D3F6D744536021168547B18887E3CDA572134EE803CAFABE6D47D9A645D71507CE03E70FB1F31F2C5F6628791F8248AA14E4DC5437B84F1E10AA25B7A89138A10597A099A5485048D2C05900366C019A080C7C5157F779A8A6CE692D6C069BB1BA8F92D2808DC65147C1A0A2D230E8447C247824BD97653A3F21002160E6483B0449C0CFA536C81476D8508F8E23A15EEECF0FB1576EB392BF92B2D2E62A7B254CA7A3470DF8D0C0EEF9AC17965C840334B1F082A8143A516198BE257809A6BB5011A716C3510E6C931DEE2EAAB99A2FF3744647C5677FFEB0AED91F1E84702D23702C3C6BFEE28E9DBC446D23DA2543294427CFDA08C0068E4F296BF85B318DA8B3855DB505E50494584C9266A29706A5D0A292A45CEFB22E0048593C96F7D39A4EFBC0"
"OODEFRAG16.00.00.01PROFESSIONAL"="772FF01F0188454BB14E2A6939430DC5AC88B55123C90BD97597D5519565995D51DAE95F76F4DD20259E15EC50BE5432AF72C0712FD03C2C9111E60056E7499FA4D82D76BA7828FEA7CA5435573451A2B2AAF06BCEACB3DF841DFB72D7039F2413632D347DA1162E7EA0A5293690534B422F7062BED03A2E3E08CC23C8C786CD93B9CB8D83C4CE5A46ED39D6E30BDDBF3D7F5CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6171C11EC38DE3DA6A0AC4980AC79338EDD5E5BE2F6E667DD02BFC5E9317CB957B3A95D185DFE272D564996AE430D0D6061B51BD5ED77AD79CF563A19D395D13CECEFBC645458047B743D0B9A7DEE9DEA07291DB7267F228FE203C57E5771EDB700D2C1C2013D2F0563B31EB4075537095BC76BC6969E12ECF630C7214F76762EDD1FA8223D467F69E8F90A711FAB3E329B7FDD2280310E7FDC0B50672391C8A88C665FD3B2104068DF203B2CD45E88009681FB4E7A93195D7889A99E8C31B5D3A4F98B8C623C2CE9367C51248DE0E1B3AFC50432ED2A2C3DC0614B779A4A037F537584659FEE78F5ECA6A2F90226882F5E06E619175A33F9C48D650531D36823DB32D3DD92CFCABC9BFC36363F29B0F8AC3F4BB2898F0E9522CE59C0054915D690D0BAD5370C3B8EEC20C8C1A568803CBA350A92AAB810338EA53F07A2A92856DC36AD12DB5659E19EF54B6A696514C83C6C312FB4C7029A525B5F19E6F9B6033D0BD0BD255F26CF8327E1649424F88F783002E3B4B2203748FAB99887424AE1C3B903E48CE3991700A06545832FB2A8C90F71F00CF51A99E2530210880C609B94F3D1795A1E1C99119361876614B84E9FD9A87A710F947525F69B6C47E8E87E69AC82D031CE8BDCC275980943E5F561FEA60706ED01A62227BCA37CEF6CC9F80F9D0B24843B3A8A387FFC0DF038C862FC529C8060525C9C164168F5072CDBA2E7C117111AACEEF1272EB9399DA505F9C5F62FB7F98DB505B0636A6FE1466C326859869810ED6383DB4329184ACB7171977A3961C0C1A71D4D4562672D593B069A686DA0D4D144D4B1435C984B4C49394880E5130D021ACF52CE3BBDE5097F9E1A3792F12DAA36221D78188C494C3B633C731AC80E63E7A53DAA9036DFFC609F1BD271BB2F534D46A3EF55ABC0766A26F08268E0458162D19EC8B7F7C1E07BD3DF0A3A0D492793C56079BF0E8378EC5E741F9CA088FBCC25985BB59206E362A7C2F1505DB807084480ABB7343503D089EA80322E01F25F9A665A4674FA3B192B31634A8392581C0EC55E53FE4F4B11CA0B1FDC952E8F46CBD101D672459C19142D7875BF3E03B58F8730D9369E8D24691F3A00C6DF7BA1F8BCCD0AC4D9C44FBACA12CFB077F2AFDA30804703C204EECF08D33693"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\vmnat.exe
c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\program files (x86)\TeamViewer\Version8\tv_w32.exe
.
**************************************************************************
.
Celkový čas: 2012-12-15 00:36:36 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-12-14 23:36
ComboFix2.txt 2012-12-14 12:49
.
Před spuštěním: Volných bajtů: 452 380 442 624
Po spuštění: Volných bajtů: 452 616 089 600
.
- - End Of File - - 916A5CBACAA9485FA2D822153ED0207D

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 15 pro 2012 00:39

HJT
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:37:23, on 15.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Users\Samec\Desktop\HiJackThis (1).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - Startup: SpeedFan.lnk = C:\Program Files (x86)\SpeedFan\speedfan.exe
O4 - Startup: TeamViewer 7.lnk = C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{23C2C53C-60B8-4D02-A942-0DDBB5C3FF73}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E3EDCCB-FE8E-4E23-9F5C-FF58C761CDBF}: NameServer = 127.0.0.1
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.13\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9493 bytes

sam7
Level 1.5
Level 1.5
Příspěvky: 126
Registrován: prosinec 10
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalé nabíhání

Příspěvekod sam7 » 15 pro 2012 00:53

https://www.virustotal.com/file/a1ced01 ... 355528615/ - Torrant.exe
https://www.virustotal.com/file/6855c21 ... 355528769/ - cryptedcybertoirrent.exe
ooscrsav.scr - nenalezen v pc
oodbs.exe - nenalezen v pc
oodssrs.dll - nenalezen v pc
oodbsrs.dll - nenalezen v pc
https://www.virustotal.com/file/cc7bbae ... 355529034/ - euroloader.exe

Log - aswMBR

aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-15 00:55:45
-----------------------------
00:55:45.737 OS Version: Windows x64 6.1.7601 Service Pack 1
00:55:45.737 Number of processors: 4 586 0x2A07
00:55:45.738 ComputerName: SAMEK-PC UserName: Samec
00:55:45.783 Initialze error 1
00:55:55.420 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
00:55:55.423 Disk 0 Vendor: WDC_WD10 80.0 Size: 953869MB BusType: 3
00:55:55.426 Disk 0 MBR read successfully
00:55:55.428 Disk 0 MBR scan
00:55:55.431 Disk 0 unknown MBR code
00:55:55.433 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
00:55:55.437 Disk 0 scanning C:\Windows\system32\drivers
00:55:55.440 Service scanning
00:55:56.033 Modules scanning
00:55:56.037 Disk 0 trace - called modules:
00:55:56.044 ntoskrnl.exe fltsrv.sys tdrpman.sys CLASSPNP.SYS disk.sys vidsflt.sys iaStor.sys spxm.sys hal.dll
00:55:56.048 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8009759060]
00:55:56.053 3 CLASSPNP.SYS[fffff880017b843f] -> nt!IofCallDriver -> [0xfffffa80095bee10]
00:55:56.057 5 vidsflt.sys[fffff88000f2b5cd] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007b5f050]
00:55:56.063 Scan finished successfully
00:56:03.162 Disk 0 MBR has been saved successfully to "C:\Users\Samec\Desktop\MBR.dat"
00:56:03.166 The log file has been saved successfully to "C:\Users\Samec\Desktop\aswMBR.txt"


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 109 hostů