Trojan - trošku urychleně , díky Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Trojan - trošku urychleně , díky

Příspěvekod jaojao » 16 led 2013 11:57

Mrkněte na to někdo, díky.
Známý koukal, něco odkliknul a, a pak už jen čučel - Trojan.Ransom.Gen :D
Objevil jsem mu ho až v Mbamu viz níže.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:00, on 16.1.2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Expert\Downloads\Teplota procesoru\CoreTemp32\Core Temp.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\Expert\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... spire_7530
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... spire_7530
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... spire_7530
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE Systemboot
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Core Temp] "C:\Users\Expert\Downloads\Teplota procesoru\CoreTemp32\Core Temp.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2375729464-1652811455-3684655677-1002\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-2375729464-1652811455-3684655677-1002\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-2375729464-1652811455-3684655677-1002\..\RunOnce: [AcerScrSav] C:\Windows\Acer\run_NB.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{692C7F80-CB10-40F7-B994-0011FC12904D}: NameServer = 62.240.178.250
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - - C:\Windows\system32\lxcgcoms.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7768 bytes
-----------------------------------------------------------------------------------------------------------------------------
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
http://www.malwarebytes.org

Verze: v2013.01.16.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Expert :: EXPERT-PC [administrátor]

Ochrana: Povolena

16.1.2013 10:45:27
MBAM-log-2013-01-16 (10-53-25).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 224415
Uplynulý čas: 7 minut, 29 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 1
C:\Users\Expert\13976472.exe (Trojan.Ransom.Gen) -> Nebyla provedena žádná instrukce.

(konec)
----------------------------------------------------------------------------------------------------------------------------------------
nová kontrola po smazání s restartem - čistá, našel jsem to válet se v karanténě tak sem to vykopnul i odtama

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
http://www.malwarebytes.org

Verze: v2013.01.16.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Expert :: EXPERT-PC [administrátor]

Ochrana: Povolena

16.1.2013 11:02:40
mbam-log-2013-01-16 (11-02-40).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 224440
Uplynulý čas: 8 minut, 2 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)
-------------------------------------------------------------
Vypadá to čistě, nevím ....
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Reklama
Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod Žbeky » 16 led 2013 13:48

Fixni:

Kód: Vybrat vše

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... spire_7530
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... spire_7530
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... spire_7530
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-21-2375729464-1652811455-3684655677-1002\..\RunOnce: [AcerScrSav] C:\Windows\Acer\run_NB.exe (User 'UpdatusUser')
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod jaojao » 16 led 2013 14:11

14:06:02.0831 4800 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
14:06:03.0049 4800 ============================================================
14:06:03.0049 4800 Current date / time: 2013/01/16 14:06:03.0049
14:06:03.0049 4800 SystemInfo:
14:06:03.0049 4800
14:06:03.0049 4800 OS Version: 6.0.6002 ServicePack: 2.0
14:06:03.0049 4800 Product type: Workstation
14:06:03.0049 4800 ComputerName: EXPERT-PC
14:06:03.0049 4800 UserName: Expert
14:06:03.0049 4800 Windows directory: C:\Windows
14:06:03.0049 4800 System windows directory: C:\Windows
14:06:03.0049 4800 Processor architecture: Intel x86
14:06:03.0049 4800 Number of processors: 2
14:06:03.0049 4800 Page size: 0x1000
14:06:03.0049 4800 Boot type: Normal boot
14:06:03.0049 4800 ============================================================
14:06:04.0469 4800 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
14:06:04.0469 4800 ============================================================
14:06:04.0469 4800 \Device\Harddisk0\DR0:
14:06:04.0469 4800 MBR partitions:
14:06:04.0469 4800 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1400800, BlocksNum 0x12016800
14:06:04.0469 4800 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x13417000, BlocksNum 0x12017000
14:06:04.0469 4800 ============================================================
14:06:04.0516 4800 C: <-> \Device\Harddisk0\DR0\Partition1
14:06:04.0563 4800 D: <-> \Device\Harddisk0\DR0\Partition2
14:06:04.0563 4800 ============================================================
14:06:04.0563 4800 Initialize success
14:06:04.0563 4800 ============================================================
14:06:06.0029 4956 ============================================================
14:06:06.0029 4956 Scan started
14:06:06.0029 4956 Mode: Manual;
14:06:06.0029 4956 ============================================================
14:06:07.0090 4956 ================ Scan system memory ========================
14:06:07.0090 4956 System memory - ok
14:06:07.0090 4956 ================ Scan services =============================
14:06:07.0683 4956 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
14:06:07.0683 4956 ACPI - ok
14:06:07.0745 4956 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
14:06:07.0776 4956 adp94xx - ok
14:06:07.0823 4956 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
14:06:07.0839 4956 adpahci - ok
14:06:07.0854 4956 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
14:06:07.0854 4956 adpu160m - ok
14:06:07.0885 4956 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
14:06:07.0885 4956 adpu320 - ok
14:06:07.0932 4956 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
14:06:07.0932 4956 AeLookupSvc - ok
14:06:07.0995 4956 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
14:06:07.0995 4956 AFD - ok
14:06:08.0057 4956 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
14:06:08.0057 4956 agp440 - ok
14:06:08.0104 4956 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
14:06:08.0119 4956 aic78xx - ok
14:06:08.0166 4956 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
14:06:08.0166 4956 ALG - ok
14:06:08.0182 4956 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
14:06:08.0182 4956 aliide - ok
14:06:08.0275 4956 ALSysIO - ok
14:06:08.0307 4956 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
14:06:08.0307 4956 amdagp - ok
14:06:08.0322 4956 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
14:06:08.0322 4956 amdide - ok
14:06:08.0353 4956 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
14:06:08.0353 4956 AmdK7 - ok
14:06:08.0385 4956 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
14:06:08.0385 4956 AmdK8 - ok
14:06:08.0447 4956 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
14:06:08.0447 4956 Appinfo - ok
14:06:08.0478 4956 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
14:06:08.0478 4956 arc - ok
14:06:08.0509 4956 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
14:06:08.0509 4956 arcsas - ok
14:06:08.0556 4956 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
14:06:08.0556 4956 aswFsBlk - ok
14:06:08.0603 4956 [ 62F9DCEC95F91B8E0203E85D344A7E65 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
14:06:08.0603 4956 aswMonFlt - ok
14:06:08.0634 4956 [ 7C9F0A2AB17D52261A9252A2EB320884 ] AswRdr C:\Windows\system32\drivers\AswRdr.sys
14:06:08.0634 4956 AswRdr - ok
14:06:08.0681 4956 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
14:06:08.0712 4956 aswSnx - ok
14:06:08.0728 4956 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\Windows\system32\drivers\aswSP.sys
14:06:08.0743 4956 aswSP - ok
14:06:08.0806 4956 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
14:06:08.0806 4956 aswTdi - ok
14:06:08.0837 4956 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
14:06:08.0837 4956 AsyncMac - ok
14:06:08.0853 4956 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
14:06:08.0868 4956 atapi - ok
14:06:08.0993 4956 [ 044DCFC10B9144725B0E59AC319759E3 ] athr C:\Windows\system32\DRIVERS\athr.sys
14:06:09.0009 4956 athr - ok
14:06:09.0071 4956 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:06:09.0071 4956 AudioEndpointBuilder - ok
14:06:09.0087 4956 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
14:06:09.0102 4956 Audiosrv - ok
14:06:09.0289 4956 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
14:06:09.0289 4956 avast! Antivirus - ok
14:06:09.0367 4956 [ 744663C3183CE5A11308F20C7B90C63E ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
14:06:09.0367 4956 b57nd60x - ok
14:06:09.0445 4956 [ C38077D14ADF896EE1E1DBBCBCF77E14 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
14:06:09.0461 4956 BCM43XX - ok
14:06:09.0508 4956 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
14:06:09.0508 4956 Beep - ok
14:06:09.0570 4956 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
14:06:09.0586 4956 BFE - ok
14:06:09.0726 4956 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
14:06:09.0742 4956 BITS - ok
14:06:09.0773 4956 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
14:06:09.0773 4956 blbdrive - ok
14:06:09.0820 4956 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
14:06:09.0820 4956 bowser - ok
14:06:09.0851 4956 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
14:06:09.0851 4956 BrFiltLo - ok
14:06:09.0898 4956 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
14:06:09.0913 4956 BrFiltUp - ok
14:06:09.0929 4956 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
14:06:09.0945 4956 Browser - ok
14:06:09.0960 4956 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
14:06:09.0960 4956 Brserid - ok
14:06:09.0976 4956 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
14:06:09.0976 4956 BrSerWdm - ok
14:06:09.0991 4956 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
14:06:09.0991 4956 BrUsbMdm - ok
14:06:10.0023 4956 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
14:06:10.0023 4956 BrUsbSer - ok
14:06:10.0054 4956 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
14:06:10.0054 4956 BTHMODEM - ok
14:06:10.0132 4956 [ 09E6AFFAE6C0E9158BF05C7D08D0107A ] BUNAgentSvc C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
14:06:10.0132 4956 BUNAgentSvc - ok
14:06:10.0194 4956 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
14:06:10.0194 4956 cdfs - ok
14:06:10.0241 4956 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
14:06:10.0241 4956 cdrom - ok
14:06:10.0288 4956 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
14:06:10.0303 4956 CertPropSvc - ok
14:06:10.0335 4956 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\DRIVERS\circlass.sys
14:06:10.0350 4956 circlass - ok
14:06:10.0397 4956 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
14:06:10.0397 4956 CLFS - ok
14:06:10.0584 4956 [ 5CA9B1062C0C3E3AE19C23AD9D8A5048 ] CLHNService C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
14:06:10.0584 4956 CLHNService - ok
14:06:10.0740 4956 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:06:10.0740 4956 clr_optimization_v2.0.50727_32 - ok
14:06:10.0849 4956 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:06:10.0849 4956 clr_optimization_v4.0.30319_32 - ok
14:06:10.0896 4956 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
14:06:10.0896 4956 CmBatt - ok
14:06:10.0927 4956 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
14:06:10.0927 4956 cmdide - ok
14:06:10.0974 4956 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
14:06:10.0974 4956 Compbatt - ok
14:06:10.0990 4956 COMSysApp - ok
14:06:11.0005 4956 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
14:06:11.0005 4956 crcdisk - ok
14:06:11.0037 4956 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
14:06:11.0037 4956 Crusoe - ok
14:06:11.0099 4956 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
14:06:11.0099 4956 CryptSvc - ok
14:06:11.0161 4956 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
14:06:11.0193 4956 DcomLaunch - ok
14:06:11.0224 4956 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
14:06:11.0224 4956 DfsC - ok
14:06:11.0364 4956 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
14:06:11.0427 4956 DFSR - ok
14:06:11.0473 4956 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
14:06:11.0489 4956 Dhcp - ok
14:06:11.0520 4956 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
14:06:11.0536 4956 disk - ok
14:06:11.0567 4956 [ 73BAF270D24FE726B9CD7F80BB17A23D ] DKbFltr C:\Windows\system32\DRIVERS\DKbFltr.sys
14:06:11.0567 4956 DKbFltr - ok
14:06:11.0614 4956 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
14:06:11.0614 4956 Dnscache - ok
14:06:11.0661 4956 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
14:06:11.0676 4956 dot3svc - ok
14:06:11.0707 4956 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
14:06:11.0707 4956 DPS - ok
14:06:11.0739 4956 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
14:06:11.0739 4956 drmkaud - ok
14:06:11.0848 4956 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
14:06:11.0863 4956 DXGKrnl - ok
14:06:11.0910 4956 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
14:06:11.0910 4956 E1G60 - ok
14:06:11.0926 4956 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
14:06:11.0941 4956 EapHost - ok
14:06:11.0988 4956 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
14:06:12.0004 4956 Ecache - ok
14:06:12.0097 4956 [ 2CE2DDCB1A41ED4488A2A8B98D286B3D ] eDataSecurity Service C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
14:06:12.0113 4956 eDataSecurity Service - ok
14:06:12.0175 4956 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
14:06:12.0175 4956 ehRecvr - ok
14:06:12.0207 4956 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
14:06:12.0207 4956 ehSched - ok
14:06:12.0238 4956 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
14:06:12.0238 4956 ehstart - ok
14:06:12.0269 4956 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
14:06:12.0285 4956 elxstor - ok
14:06:12.0409 4956 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
14:06:12.0409 4956 EMDMgmt - ok
14:06:12.0487 4956 [ EDCE64430652F6A0BBCCC348E2713FC3 ] epfwwfpr C:\Windows\system32\DRIVERS\epfwwfpr.sys
14:06:12.0487 4956 epfwwfpr - ok
14:06:12.0565 4956 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
14:06:12.0565 4956 ErrDev - ok
14:06:12.0612 4956 [ A51FD9DF23720485991F56741BBEFCFB ] ETService C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
14:06:12.0612 4956 ETService - ok
14:06:12.0721 4956 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
14:06:12.0737 4956 EventSystem - ok
14:06:12.0799 4956 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
14:06:12.0815 4956 exfat - ok
14:06:12.0893 4956 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
14:06:12.0893 4956 fastfat - ok
14:06:12.0940 4956 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
14:06:12.0940 4956 fdc - ok
14:06:13.0018 4956 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
14:06:13.0033 4956 fdPHost - ok
14:06:13.0080 4956 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
14:06:13.0080 4956 FDResPub - ok
14:06:13.0158 4956 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
14:06:13.0158 4956 FileInfo - ok
14:06:13.0205 4956 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
14:06:13.0221 4956 Filetrace - ok
14:06:13.0252 4956 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
14:06:13.0252 4956 flpydisk - ok
14:06:13.0299 4956 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
14:06:13.0299 4956 FltMgr - ok
14:06:13.0361 4956 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
14:06:13.0377 4956 FontCache - ok
14:06:13.0595 4956 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
14:06:13.0657 4956 FontCache3.0.0.0 - ok
14:06:13.0704 4956 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
14:06:13.0704 4956 Fs_Rec - ok
14:06:13.0735 4956 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
14:06:13.0735 4956 gagp30kx - ok
14:06:13.0798 4956 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
14:06:13.0829 4956 gpsvc - ok
14:06:13.0954 4956 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
14:06:13.0969 4956 gupdate - ok
14:06:13.0985 4956 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
14:06:13.0985 4956 gupdatem - ok
14:06:14.0016 4956 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:06:14.0032 4956 HdAudAddService - ok
14:06:14.0079 4956 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
14:06:14.0094 4956 HDAudBus - ok
14:06:14.0157 4956 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
14:06:14.0235 4956 HidBth - ok
14:06:14.0266 4956 [ D8DF3722D5E961BAA1292AA2F12827E2 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
14:06:14.0266 4956 HidIr - ok
14:06:14.0359 4956 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
14:06:14.0359 4956 hidserv - ok
14:06:14.0422 4956 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
14:06:14.0422 4956 HidUsb - ok
14:06:14.0531 4956 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
14:06:14.0547 4956 hkmsvc - ok
14:06:14.0578 4956 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
14:06:14.0578 4956 HpCISSs - ok
14:06:14.0656 4956 [ 46D67209550973257601A533E2AC5785 ] HSFHWAZL C:\Windows\system32\DRIVERS\VSTAZL3.SYS
14:06:14.0656 4956 HSFHWAZL - ok
14:06:14.0796 4956 [ FADD7095163CB3CB4073793EBB50FE75 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
14:06:14.0812 4956 HSF_DPV - ok
14:06:14.0859 4956 [ 058783BEDD17615D1FECE09F77960436 ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
14:06:14.0859 4956 HSXHWAZL - ok
14:06:14.0905 4956 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
14:06:14.0921 4956 HTTP - ok
14:06:14.0968 4956 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
14:06:14.0968 4956 i2omp - ok
14:06:15.0015 4956 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
14:06:15.0015 4956 i8042prt - ok
14:06:15.0046 4956 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
14:06:15.0061 4956 iaStorV - ok
14:06:15.0280 4956 [ EB969035824A1A364DC5140B8621A75B ] IconMan_R C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
14:06:15.0311 4956 IconMan_R - ok
14:06:15.0436 4956 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:06:15.0467 4956 idsvc - ok
14:06:15.0498 4956 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
14:06:15.0514 4956 iirsp - ok
14:06:15.0670 4956 [ A06EFD4965F8A3F97A8C9A291D032678 ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
14:06:15.0670 4956 IJPLMSVC - ok
14:06:15.0841 4956 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
14:06:15.0857 4956 IKEEXT - ok
14:06:15.0888 4956 [ C6E5276C00EBDEB096BB5EF4B797D1B6 ] int15 C:\Windows\system32\drivers\int15.sys
14:06:15.0888 4956 int15 - ok
14:06:16.0185 4956 [ C4667E9AB717B71D3C1B7635ACC60E6B ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
14:06:16.0278 4956 IntcAzAudAddService - ok
14:06:16.0356 4956 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
14:06:16.0356 4956 intelide - ok
14:06:16.0387 4956 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
14:06:16.0387 4956 intelppm - ok
14:06:16.0419 4956 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
14:06:16.0419 4956 IPBusEnum - ok
14:06:16.0450 4956 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:06:16.0450 4956 IpFilterDriver - ok
14:06:16.0528 4956 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
14:06:16.0528 4956 iphlpsvc - ok
14:06:16.0543 4956 IpInIp - ok
14:06:16.0575 4956 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
14:06:16.0590 4956 IPMIDRV - ok
14:06:16.0621 4956 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
14:06:16.0621 4956 IPNAT - ok
14:06:16.0653 4956 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
14:06:16.0668 4956 IRENUM - ok
14:06:16.0684 4956 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
14:06:16.0684 4956 isapnp - ok
14:06:16.0731 4956 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
14:06:16.0746 4956 iScsiPrt - ok
14:06:16.0762 4956 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
14:06:16.0762 4956 iteatapi - ok
14:06:16.0777 4956 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
14:06:16.0777 4956 iteraid - ok
14:06:16.0824 4956 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
14:06:16.0824 4956 kbdclass - ok
14:06:16.0855 4956 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
14:06:16.0855 4956 kbdhid - ok
14:06:16.0918 4956 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
14:06:16.0918 4956 KeyIso - ok
14:06:16.0980 4956 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
14:06:16.0996 4956 KSecDD - ok
14:06:17.0058 4956 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
14:06:17.0074 4956 KtmRm - ok
14:06:17.0105 4956 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll
14:06:17.0121 4956 LanmanServer - ok
14:06:17.0167 4956 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:06:17.0183 4956 LanmanWorkstation - ok
14:06:17.0230 4956 [ 793FF718477345CD5D232C50BED1E452 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
14:06:17.0230 4956 LightScribeService - ok
14:06:17.0261 4956 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
14:06:17.0261 4956 lltdio - ok
14:06:17.0308 4956 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
14:06:17.0308 4956 lltdsvc - ok
14:06:17.0339 4956 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
14:06:17.0339 4956 lmhosts - ok
14:06:17.0370 4956 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
14:06:17.0386 4956 LSI_FC - ok
14:06:17.0401 4956 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
14:06:17.0417 4956 LSI_SAS - ok
14:06:17.0433 4956 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
14:06:17.0433 4956 LSI_SCSI - ok
14:06:17.0479 4956 [ 9BC81FCB5AB1253927B60C0AD815445D ] Ltn_stk7070P C:\Windows\system32\DRIVERS\Ltn_stk7070P.sys
14:06:17.0495 4956 Ltn_stk7070P - ok
14:06:17.0511 4956 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
14:06:17.0511 4956 luafv - ok
14:06:17.0526 4956 lxcg_device - ok
14:06:17.0589 4956 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
14:06:17.0604 4956 Mcx2Svc - ok
14:06:17.0667 4956 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
14:06:17.0682 4956 MDM - ok
14:06:17.0713 4956 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
14:06:17.0713 4956 mdmxsdk - ok
14:06:17.0745 4956 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
14:06:17.0745 4956 megasas - ok
14:06:17.0791 4956 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
14:06:17.0807 4956 MegaSR - ok
14:06:17.0838 4956 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
14:06:17.0854 4956 MMCSS - ok
14:06:17.0885 4956 MobilityService - ok
14:06:17.0916 4956 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
14:06:17.0916 4956 Modem - ok
14:06:17.0947 4956 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
14:06:17.0947 4956 monitor - ok
14:06:17.0994 4956 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
14:06:17.0994 4956 mouclass - ok
14:06:18.0025 4956 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
14:06:18.0041 4956 mouhid - ok
14:06:18.0057 4956 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
14:06:18.0072 4956 MountMgr - ok
14:06:18.0088 4956 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
14:06:18.0088 4956 mpio - ok
14:06:18.0119 4956 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
14:06:18.0119 4956 mpsdrv - ok
14:06:18.0181 4956 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
14:06:18.0197 4956 MpsSvc - ok
14:06:18.0213 4956 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
14:06:18.0228 4956 Mraid35x - ok
14:06:18.0275 4956 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
14:06:18.0275 4956 MRxDAV - ok
14:06:18.0337 4956 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
14:06:18.0353 4956 mrxsmb - ok
14:06:18.0369 4956 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:06:18.0384 4956 mrxsmb10 - ok
14:06:18.0415 4956 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:06:18.0415 4956 mrxsmb20 - ok
14:06:18.0447 4956 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
14:06:18.0462 4956 msahci - ok
14:06:18.0478 4956 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
14:06:18.0478 4956 msdsm - ok
14:06:18.0509 4956 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
14:06:18.0509 4956 MSDTC - ok
14:06:18.0556 4956 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
14:06:18.0556 4956 Msfs - ok
14:06:18.0587 4956 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
14:06:18.0587 4956 msisadrv - ok
14:06:18.0634 4956 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
14:06:18.0634 4956 MSiSCSI - ok
14:06:18.0649 4956 msiserver - ok
14:06:18.0681 4956 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
14:06:18.0681 4956 MSKSSRV - ok
14:06:18.0727 4956 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
14:06:18.0727 4956 MSPCLOCK - ok
14:06:18.0759 4956 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
14:06:18.0774 4956 MSPQM - ok
14:06:18.0821 4956 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
14:06:18.0821 4956 MsRPC - ok
14:06:18.0868 4956 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
14:06:18.0868 4956 mssmbios - ok
14:06:18.0883 4956 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
14:06:18.0883 4956 MSTEE - ok
14:06:18.0915 4956 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
14:06:18.0915 4956 Mup - ok
14:06:18.0946 4956 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
14:06:18.0961 4956 napagent - ok
14:06:18.0993 4956 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
14:06:19.0008 4956 NativeWifiP - ok
14:06:19.0117 4956 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
14:06:19.0258 4956 NDIS - ok
14:06:19.0305 4956 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
14:06:19.0320 4956 NdisTapi - ok
14:06:19.0336 4956 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
14:06:19.0336 4956 Ndisuio - ok
14:06:19.0414 4956 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
14:06:19.0429 4956 NdisWan - ok
14:06:19.0445 4956 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
14:06:19.0445 4956 NDProxy - ok
14:06:19.0476 4956 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
14:06:19.0476 4956 NetBIOS - ok
14:06:19.0523 4956 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
14:06:19.0523 4956 netbt - ok
14:06:19.0554 4956 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
14:06:19.0554 4956 Netlogon - ok
14:06:19.0601 4956 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
14:06:19.0617 4956 Netman - ok
14:06:19.0648 4956 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
14:06:19.0663 4956 netprofm - ok
14:06:19.0695 4956 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:06:19.0710 4956 NetTcpPortSharing - ok
14:06:19.0741 4956 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
14:06:19.0741 4956 nfrd960 - ok
14:06:19.0773 4956 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
14:06:19.0788 4956 NlaSvc - ok
14:06:19.0819 4956 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
14:06:19.0819 4956 Npfs - ok
14:06:19.0835 4956 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
14:06:19.0851 4956 nsi - ok
14:06:19.0882 4956 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
14:06:19.0882 4956 nsiproxy - ok
14:06:19.0975 4956 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
14:06:19.0991 4956 Ntfs - ok
14:06:20.0022 4956 [ A2B6583A5652A385DFF5E4F49AD48761 ] NTIBackupSvc C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
14:06:20.0022 4956 NTIBackupSvc - ok
14:06:20.0053 4956 [ 2757D2BA59AEE155209E24942AB127C9 ] NTIDrvr C:\Windows\system32\DRIVERS\NTIDrvr.sys
14:06:20.0053 4956 NTIDrvr - ok
14:06:20.0085 4956 [ 547BFA3591C70674B0BFC99354AB78B3 ] NTIPPKernel C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys
14:06:20.0085 4956 NTIPPKernel - ok
14:06:20.0131 4956 [ 40B87FE8A1A9A5AC9E5A91D96F212BCD ] NTISchedulerSvc C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
14:06:20.0131 4956 NTISchedulerSvc - ok
14:06:20.0147 4956 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
14:06:20.0147 4956 ntrigdigi - ok
14:06:20.0178 4956 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
14:06:20.0178 4956 Null - ok
14:06:20.0241 4956 [ 0E616537F3E12D4C9FB71181C2F21BD5 ] NVHDA C:\Windows\system32\drivers\nvhda32v.sys
14:06:20.0256 4956 NVHDA - ok
14:06:20.0646 4956 [ 4152708C0C24E30DAE7FA87D5AFE1D7B ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
14:06:20.0787 4956 nvlddmkm - ok
14:06:20.0833 4956 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
14:06:20.0849 4956 nvraid - ok
14:06:20.0880 4956 [ 02A9F366BCB94B286E34825B2094CB38 ] nvsmu C:\Windows\system32\DRIVERS\nvsmu.sys
14:06:20.0880 4956 nvsmu - ok
14:06:20.0927 4956 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
14:06:20.0927 4956 nvstor - ok
14:06:20.0974 4956 [ 3FF57A9A657C9690ECBC8B1E3B6E3979 ] nvstor32 C:\Windows\system32\DRIVERS\nvstor32.sys
14:06:20.0974 4956 nvstor32 - ok
14:06:21.0052 4956 [ 26DB28B32E8D2F57CB5065A4A053801A ] nvsvc C:\Windows\system32\nvvsvc.exe
14:06:21.0067 4956 nvsvc - ok
14:06:21.0208 4956 [ A19BBE1E3E3FEF50B94CA07DCC0FB776 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
14:06:21.0239 4956 nvUpdatusService - ok
14:06:21.0286 4956 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
14:06:21.0301 4956 nv_agp - ok
14:06:21.0301 4956 NwlnkFlt - ok
14:06:21.0317 4956 NwlnkFwd - ok
14:06:21.0348 4956 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
14:06:21.0364 4956 ohci1394 - ok
14:06:21.0395 4956 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:06:21.0395 4956 ose - ok
14:06:21.0457 4956 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
14:06:21.0473 4956 p2pimsvc - ok
14:06:21.0504 4956 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
14:06:21.0520 4956 p2psvc - ok
14:06:21.0567 4956 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
14:06:21.0567 4956 Parport - ok
14:06:21.0598 4956 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
14:06:21.0613 4956 partmgr - ok
14:06:21.0629 4956 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
14:06:21.0629 4956 Parvdm - ok
14:06:21.0660 4956 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
14:06:21.0676 4956 PcaSvc - ok
14:06:21.0707 4956 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
14:06:21.0707 4956 pci - ok
14:06:21.0723 4956 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
14:06:21.0738 4956 pciide - ok
14:06:21.0769 4956 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
14:06:21.0769 4956 pcmcia - ok
14:06:21.0816 4956 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
14:06:21.0832 4956 PEAUTH - ok
14:06:21.0972 4956 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
14:06:22.0003 4956 pla - ok
14:06:22.0050 4956 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
14:06:22.0066 4956 PlugPlay - ok
14:06:22.0113 4956 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
14:06:22.0128 4956 PNRPAutoReg - ok
14:06:22.0144 4956 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
14:06:22.0159 4956 PNRPsvc - ok
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod jaojao » 16 led 2013 14:12

14:06:22.0237 4956 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
14:06:22.0237 4956 PolicyAgent - ok
14:06:22.0284 4956 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
14:06:22.0284 4956 PptpMiniport - ok
14:06:22.0315 4956 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\DRIVERS\processr.sys
14:06:22.0315 4956 Processor - ok
14:06:22.0331 4956 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
14:06:22.0347 4956 ProfSvc - ok
14:06:22.0378 4956 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
14:06:22.0378 4956 ProtectedStorage - ok
14:06:22.0409 4956 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
14:06:22.0409 4956 PSched - ok
14:06:22.0440 4956 [ 1DCBB35090CC4B2BD3D661E6089523C6 ] PSDFilter C:\Windows\system32\DRIVERS\psdfilter.sys
14:06:22.0440 4956 PSDFilter - ok
14:06:22.0456 4956 [ E26E46D619469964AC3609620F443867 ] PSDNServ C:\Windows\system32\DRIVERS\PSDNServ.sys
14:06:22.0471 4956 PSDNServ - ok
14:06:22.0503 4956 [ 3E1D134AF2806867D06047C4CC33CC65 ] psdvdisk C:\Windows\system32\DRIVERS\PSDVdisk.sys
14:06:22.0503 4956 psdvdisk - ok
14:06:22.0596 4956 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
14:06:22.0627 4956 ql2300 - ok
14:06:22.0643 4956 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
14:06:22.0659 4956 ql40xx - ok
14:06:22.0690 4956 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
14:06:22.0705 4956 QWAVE - ok
14:06:22.0721 4956 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
14:06:22.0737 4956 QWAVEdrv - ok
14:06:22.0752 4956 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
14:06:22.0768 4956 RasAcd - ok
14:06:22.0783 4956 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
14:06:22.0799 4956 RasAuto - ok
14:06:22.0815 4956 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
14:06:22.0815 4956 Rasl2tp - ok
14:06:22.0877 4956 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
14:06:22.0893 4956 RasMan - ok
14:06:22.0924 4956 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
14:06:22.0924 4956 RasPppoe - ok
14:06:22.0955 4956 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
14:06:22.0955 4956 RasSstp - ok
14:06:22.0986 4956 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
14:06:23.0002 4956 rdbss - ok
14:06:23.0017 4956 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
14:06:23.0017 4956 RDPCDD - ok
14:06:23.0080 4956 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
14:06:23.0080 4956 rdpdr - ok
14:06:23.0095 4956 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
14:06:23.0095 4956 RDPENCDD - ok
14:06:23.0142 4956 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
14:06:23.0142 4956 RDPWD - ok
14:06:23.0205 4956 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
14:06:23.0220 4956 RemoteAccess - ok
14:06:23.0251 4956 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
14:06:23.0267 4956 RemoteRegistry - ok
14:06:23.0345 4956 [ 17E0BEF5CA5C9CE52CC8082AC6EBC449 ] RichVideo C:\Program Files\Cyberlink\Shared files\RichVideo.exe
14:06:23.0345 4956 RichVideo - ok
14:06:23.0376 4956 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
14:06:23.0392 4956 RpcLocator - ok
14:06:23.0423 4956 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
14:06:23.0439 4956 RpcSs - ok
14:06:23.0485 4956 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
14:06:23.0485 4956 rspndr - ok
14:06:23.0548 4956 [ 772A6EC587CB8826DF055762E872412F ] RSUSBSTOR C:\Windows\system32\Drivers\RtsUStor.sys
14:06:23.0548 4956 RSUSBSTOR - ok
14:06:23.0595 4956 [ D1FB9A678BD6C2B1129FCB09D5FEB6DD ] RTSTOR C:\Windows\system32\drivers\RTSTOR.SYS
14:06:23.0595 4956 RTSTOR - ok
14:06:23.0610 4956 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
14:06:23.0626 4956 SamSs - ok
14:06:23.0673 4956 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
14:06:23.0688 4956 sbp2port - ok
14:06:23.0751 4956 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
14:06:23.0766 4956 SCardSvr - ok
14:06:23.0813 4956 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
14:06:23.0829 4956 Schedule - ok
14:06:23.0860 4956 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
14:06:23.0860 4956 SCPolicySvc - ok
14:06:23.0891 4956 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
14:06:23.0907 4956 SDRSVC - ok
14:06:23.0938 4956 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
14:06:23.0953 4956 secdrv - ok
14:06:23.0985 4956 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
14:06:24.0000 4956 seclogon - ok
14:06:24.0047 4956 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
14:06:24.0047 4956 SENS - ok
14:06:24.0078 4956 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
14:06:24.0094 4956 Serenum - ok
14:06:24.0125 4956 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
14:06:24.0125 4956 Serial - ok
14:06:24.0156 4956 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
14:06:24.0156 4956 sermouse - ok
14:06:24.0203 4956 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
14:06:24.0203 4956 SessionEnv - ok
14:06:24.0234 4956 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
14:06:24.0234 4956 sffdisk - ok
14:06:24.0250 4956 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
14:06:24.0250 4956 sffp_mmc - ok
14:06:24.0265 4956 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
14:06:24.0265 4956 sffp_sd - ok
14:06:24.0281 4956 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
14:06:24.0281 4956 sfloppy - ok
14:06:24.0328 4956 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
14:06:24.0343 4956 SharedAccess - ok
14:06:24.0390 4956 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:06:24.0406 4956 ShellHWDetection - ok
14:06:24.0421 4956 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
14:06:24.0437 4956 sisagp - ok
14:06:24.0453 4956 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
14:06:24.0453 4956 SiSRaid2 - ok
14:06:24.0484 4956 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
14:06:24.0484 4956 SiSRaid4 - ok
14:06:24.0531 4956 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
14:06:24.0531 4956 SkypeUpdate - ok
14:06:24.0671 4956 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
14:06:24.0780 4956 slsvc - ok
14:06:24.0827 4956 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
14:06:24.0843 4956 SLUINotify - ok
14:06:24.0874 4956 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
14:06:24.0874 4956 Smb - ok
14:06:24.0921 4956 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
14:06:24.0936 4956 SNMPTRAP - ok
14:06:24.0983 4956 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
14:06:24.0983 4956 spldr - ok
14:06:25.0030 4956 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
14:06:25.0030 4956 Spooler - ok
14:06:25.0092 4956 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
14:06:25.0092 4956 srv - ok
14:06:25.0139 4956 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
14:06:25.0139 4956 srv2 - ok
14:06:25.0155 4956 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
14:06:25.0170 4956 srvnet - ok
14:06:25.0201 4956 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
14:06:25.0217 4956 SSDPSRV - ok
14:06:25.0248 4956 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
14:06:25.0264 4956 SstpSvc - ok
14:06:25.0311 4956 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
14:06:25.0326 4956 stisvc - ok
14:06:25.0357 4956 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
14:06:25.0373 4956 swenum - ok
14:06:25.0420 4956 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
14:06:25.0435 4956 swprv - ok
14:06:25.0451 4956 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
14:06:25.0467 4956 Symc8xx - ok
14:06:25.0482 4956 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
14:06:25.0482 4956 Sym_hi - ok
14:06:25.0498 4956 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
14:06:25.0498 4956 Sym_u3 - ok
14:06:25.0545 4956 [ 219AA9FF531490C51E766BD0D3E481CB ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
14:06:25.0545 4956 SynTP - ok
14:06:25.0591 4956 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
14:06:25.0607 4956 SysMain - ok
14:06:25.0654 4956 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
14:06:25.0654 4956 TabletInputService - ok
14:06:25.0701 4956 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
14:06:25.0716 4956 TapiSrv - ok
14:06:25.0747 4956 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
14:06:25.0763 4956 TBS - ok
14:06:25.0825 4956 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
14:06:25.0825 4956 Tcpip - ok
14:06:25.0872 4956 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
14:06:25.0888 4956 Tcpip6 - ok
14:06:25.0919 4956 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
14:06:25.0919 4956 tcpipreg - ok
14:06:25.0981 4956 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
14:06:25.0981 4956 TDPIPE - ok
14:06:26.0013 4956 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
14:06:26.0013 4956 TDTCP - ok
14:06:26.0059 4956 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
14:06:26.0059 4956 tdx - ok
14:06:26.0091 4956 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
14:06:26.0091 4956 TermDD - ok
14:06:26.0169 4956 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
14:06:26.0184 4956 TermService - ok
14:06:26.0215 4956 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
14:06:26.0231 4956 Themes - ok
14:06:26.0247 4956 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
14:06:26.0262 4956 THREADORDER - ok
14:06:26.0293 4956 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
14:06:26.0309 4956 TrkWks - ok
14:06:26.0356 4956 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:06:26.0356 4956 TrustedInstaller - ok
14:06:26.0387 4956 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
14:06:26.0387 4956 tssecsrv - ok
14:06:26.0418 4956 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
14:06:26.0418 4956 tunmp - ok
14:06:26.0449 4956 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
14:06:26.0465 4956 tunnel - ok
14:06:26.0481 4956 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
14:06:26.0481 4956 uagp35 - ok
14:06:26.0512 4956 [ F763E070843EE2803DE1395002B42938 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys
14:06:26.0512 4956 UBHelper - ok
14:06:26.0559 4956 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
14:06:26.0559 4956 udfs - ok
14:06:26.0605 4956 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
14:06:26.0621 4956 UI0Detect - ok
14:06:26.0652 4956 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
14:06:26.0652 4956 uliagpkx - ok
14:06:26.0683 4956 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
14:06:26.0699 4956 uliahci - ok
14:06:26.0715 4956 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
14:06:26.0715 4956 UlSata - ok
14:06:26.0746 4956 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
14:06:26.0746 4956 ulsata2 - ok
14:06:26.0761 4956 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
14:06:26.0761 4956 umbus - ok
14:06:26.0793 4956 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
14:06:26.0808 4956 upnphost - ok
14:06:26.0871 4956 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
14:06:26.0871 4956 usbccgp - ok
14:06:26.0902 4956 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
14:06:26.0902 4956 usbcir - ok
14:06:26.0933 4956 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
14:06:26.0933 4956 usbehci - ok
14:06:26.0995 4956 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
14:06:26.0995 4956 usbhub - ok
14:06:27.0011 4956 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
14:06:27.0011 4956 usbohci - ok
14:06:27.0058 4956 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
14:06:27.0058 4956 usbprint - ok
14:06:27.0089 4956 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
14:06:27.0089 4956 usbscan - ok
14:06:27.0136 4956 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:06:27.0136 4956 USBSTOR - ok
14:06:27.0151 4956 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
14:06:27.0151 4956 usbuhci - ok
14:06:27.0307 4956 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
14:06:27.0385 4956 usbvideo - ok
14:06:27.0432 4956 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
14:06:27.0448 4956 UxSms - ok
14:06:27.0495 4956 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
14:06:27.0510 4956 vds - ok
14:06:27.0526 4956 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
14:06:27.0541 4956 vga - ok
14:06:27.0557 4956 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
14:06:27.0557 4956 VgaSave - ok
14:06:27.0588 4956 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
14:06:27.0588 4956 viaagp - ok
14:06:27.0619 4956 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
14:06:27.0619 4956 ViaC7 - ok
14:06:27.0635 4956 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
14:06:27.0651 4956 viaide - ok
14:06:27.0666 4956 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
14:06:27.0666 4956 volmgr - ok
14:06:27.0713 4956 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
14:06:27.0729 4956 volmgrx - ok
14:06:27.0760 4956 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
14:06:27.0760 4956 volsnap - ok
14:06:27.0807 4956 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
14:06:27.0807 4956 vsmraid - ok
14:06:27.0869 4956 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
14:06:27.0900 4956 VSS - ok
14:06:27.0916 4956 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
14:06:27.0931 4956 W32Time - ok
14:06:27.0978 4956 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
14:06:27.0978 4956 WacomPen - ok
14:06:28.0009 4956 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
14:06:28.0025 4956 Wanarp - ok
14:06:28.0025 4956 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
14:06:28.0025 4956 Wanarpv6 - ok
14:06:28.0087 4956 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
14:06:28.0103 4956 wcncsvc - ok
14:06:28.0134 4956 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:06:28.0150 4956 WcsPlugInService - ok
14:06:28.0165 4956 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
14:06:28.0165 4956 Wd - ok
14:06:28.0212 4956 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
14:06:28.0228 4956 Wdf01000 - ok
14:06:28.0275 4956 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
14:06:28.0290 4956 WdiServiceHost - ok
14:06:28.0290 4956 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
14:06:28.0306 4956 WdiSystemHost - ok
14:06:28.0353 4956 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
14:06:28.0384 4956 WebClient - ok
14:06:28.0446 4956 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
14:06:28.0462 4956 Wecsvc - ok
14:06:28.0493 4956 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
14:06:28.0509 4956 wercplsupport - ok
14:06:28.0571 4956 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
14:06:28.0587 4956 WerSvc - ok
14:06:28.0618 4956 [ BB9CBAF6AC20452B245C324F1F50EE81 ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
14:06:28.0633 4956 winachsf - ok
14:06:28.0665 4956 [ 3FA87D56769838AAC82FAFC3E78FC732 ] winbondcir C:\Windows\system32\DRIVERS\winbondcir.sys
14:06:28.0665 4956 winbondcir - ok
14:06:28.0711 4956 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
14:06:28.0727 4956 WinDefend - ok
14:06:28.0743 4956 WinHttpAutoProxySvc - ok
14:06:28.0805 4956 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
14:06:28.0821 4956 Winmgmt - ok
14:06:28.0883 4956 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
14:06:28.0914 4956 WinRM - ok
14:06:28.0992 4956 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
14:06:29.0008 4956 Wlansvc - ok
14:06:29.0117 4956 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
14:06:29.0164 4956 wlidsvc - ok
14:06:29.0195 4956 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
14:06:29.0195 4956 WmiAcpi - ok
14:06:29.0242 4956 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
14:06:29.0242 4956 wmiApSrv - ok
14:06:29.0304 4956 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
14:06:29.0320 4956 WMPNetworkSvc - ok
14:06:29.0382 4956 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
14:06:29.0398 4956 WPCSvc - ok
14:06:29.0429 4956 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
14:06:29.0445 4956 WPDBusEnum - ok
14:06:29.0601 4956 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
14:06:29.0632 4956 WPFFontCache_v0400 - ok
14:06:29.0632 4956 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
14:06:29.0647 4956 ws2ifsl - ok
14:06:29.0679 4956 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll
14:06:29.0694 4956 wscsvc - ok
14:06:29.0710 4956 WSearch - ok
14:06:29.0819 4956 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
14:06:29.0881 4956 wuauserv - ok
14:06:29.0928 4956 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
14:06:29.0928 4956 WudfPf - ok
14:06:29.0975 4956 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
14:06:29.0975 4956 WUDFRd - ok
14:06:30.0006 4956 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
14:06:30.0022 4956 wudfsvc - ok
14:06:30.0053 4956 [ DAB33CFA9DD24251AAA389FF36B64D4B ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
14:06:30.0053 4956 XAudio - ok
14:06:30.0084 4956 [ CD5F291A1161F15896D1A4D63DAFF5DF ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
14:06:30.0100 4956 XAudioService - ok
14:06:30.0178 4956 [ 4D840C6AF3C020ED3A35EFBA9025CF4A ] {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl
14:06:30.0178 4956 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} - ok
14:06:30.0193 4956 ================ Scan global ===============================
14:06:30.0225 4956 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
14:06:30.0271 4956 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
14:06:30.0303 4956 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
14:06:30.0349 4956 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
14:06:30.0365 4956 [Global] - ok
14:06:30.0365 4956 ================ Scan MBR ==================================
14:06:30.0381 4956 [ 7BA4C7EA1EF33A92F5F01BE63EDACB6A ] \Device\Harddisk0\DR0
14:06:36.0215 4956 \Device\Harddisk0\DR0 - ok
14:06:36.0215 4956 ================ Scan VBR ==================================
14:06:36.0246 4956 [ 3A12A388242DC6E1C1B6D05AA9E5B840 ] \Device\Harddisk0\DR0\Partition1
14:06:36.0246 4956 \Device\Harddisk0\DR0\Partition1 - ok
14:06:36.0262 4956 [ D2B01B1568222F1146088619F2C715D6 ] \Device\Harddisk0\DR0\Partition2
14:06:36.0262 4956 \Device\Harddisk0\DR0\Partition2 - ok
14:06:36.0277 4956 ============================================================
14:06:36.0277 4956 Scan finished
14:06:36.0277 4956 ============================================================
14:06:36.0309 5532 Detected object count: 0
14:06:36.0309 5532 Actual detected object count: 0
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod memphisto » 16 led 2013 14:30

Ještě ten Combofix
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod jaojao » 16 led 2013 14:53

ComboFix 13-01-15.02 - Expert 16.01.2013 14:20:50.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2813.1758 [GMT 1:00]
Spuštěný z: c:\users\Expert\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Expert\AppData\Roaming\.#
c:\users\Expert\AppData\Roaming\skype.ini
c:\windows\system32\roboot.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-16 do 2013-01-16 )))))))))))))))))))))))))))))))
.
.
2013-01-09 15:21 . 2012-11-23 01:35 2048000 ----a-w- c:\windows\system32\win32k.sys
2013-01-09 15:20 . 2012-11-20 04:22 204288 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-09 15:20 . 2012-11-02 10:19 1400832 ----a-w- c:\windows\system32\msxml6.dll
2012-12-29 06:06 . 2013-01-16 13:02 -------- d-----w- C:\HijackThis
2012-12-28 22:24 . 2011-12-07 18:32 216064 ----a-w- c:\windows\system32\lagarith.dll
2012-12-28 22:24 . 2011-06-24 15:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2012-12-28 22:24 . 2011-06-24 15:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
2012-12-28 22:24 . 2012-06-09 18:21 178688 ----a-w- c:\windows\system32\unrar.dll
2012-12-28 22:24 . 2011-12-21 18:14 151552 ----a-w- c:\windows\system32\ac3acm.acm
2012-12-28 22:24 . 2012-12-10 18:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2012-12-28 22:24 . 2012-12-28 22:24 -------- d-----w- c:\program files\K-Lite Codec Pack
2012-12-28 20:22 . 2012-12-28 20:22 -------- d-----w- C:\Trend Micro
2012-12-28 15:07 . 2012-12-28 15:07 -------- d-----w- c:\users\Expert\AppData\Local\Apps
2012-12-28 13:29 . 2012-12-28 13:29 -------- d-----w- c:\users\Expert\AppData\Local\Macromedia
2012-12-28 13:29 . 2012-12-28 13:29 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-28 08:06 . 2012-12-28 08:06 -------- d-----w- c:\users\Expert\Tracing
2012-12-28 08:05 . 2012-12-28 08:05 -------- d-----w- c:\windows\cs
2012-12-28 07:57 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2012-12-28 07:57 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2012-12-28 07:57 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2012-12-28 07:53 . 2012-12-28 07:53 89944 ----a-w- c:\program files\Common Files\Windows Live\.cache\751778b01cde4d00b\DSETUP.dll
2012-12-28 07:53 . 2012-12-28 07:53 537432 ----a-w- c:\program files\Common Files\Windows Live\.cache\751778b01cde4d00b\DXSETUP.exe
2012-12-28 07:53 . 2012-12-28 07:53 1801048 ----a-w- c:\program files\Common Files\Windows Live\.cache\751778b01cde4d00b\dsetup32.dll
2012-12-28 07:53 . 2012-12-28 07:53 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\70d2e1901cde4d00a\DSETUP.dll
2012-12-28 07:53 . 2012-12-28 07:53 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\70d2e1901cde4d00a\DXSETUP.exe
2012-12-28 07:53 . 2012-12-28 07:53 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\70d2e1901cde4d00a\dsetup32.dll
2012-12-28 07:53 . 2012-12-28 07:53 6260088 ----a-w- c:\program files\Common Files\Windows Live\.cache\6b64be901cde4d009\Silverlight.4.0.exe
2012-12-28 07:51 . 2012-12-28 14:50 -------- d-----w- c:\users\Expert\AppData\Local\Windows Live
2012-12-28 07:25 . 2012-12-28 07:25 -------- d-----w- c:\users\Expert\AppData\Roaming\DriverCure
2012-12-28 07:25 . 2012-12-28 07:25 -------- d-----w- c:\users\Expert\AppData\Roaming\ParetoLogic
2012-12-28 07:24 . 2012-12-28 07:33 -------- d-----w- c:\programdata\ParetoLogic
2012-12-27 18:07 . 2012-12-27 18:07 -------- d-----w- c:\users\Expert\AppData\Roaming\Reviversoft
2012-12-24 16:41 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4A900E3D-B2F4-42D0-9C4E-C414AF8AACE2}\mpengine.dll
2012-12-22 08:55 . 2012-12-16 13:12 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-22 08:55 . 2012-12-16 10:50 293376 ----a-w- c:\windows\system32\atmfd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-16 12:19 . 2008-01-21 02:24 1036800 ----a-w- c:\windows\system32\d3d8.dll
2012-12-28 13:29 . 2011-12-03 17:19 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-28 07:58 . 2011-03-28 17:36 19696 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-11-13 01:29 . 2012-12-06 02:12 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-02 10:18 . 2012-12-06 02:13 376320 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26 . 2012-12-06 02:13 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2012-10-30 22:51 . 2012-10-12 16:55 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-30 22:51 . 2012-10-12 16:55 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-30 22:51 . 2012-10-12 16:55 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-30 22:51 . 2012-10-12 16:55 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-30 22:51 . 2012-10-12 16:55 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-30 22:51 . 2012-10-12 16:55 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-30 22:51 . 2012-10-12 16:54 41224 ----a-w- c:\windows\avastSS.scr
2012-10-30 22:50 . 2012-10-12 16:54 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-01-16 11:40 . 2013-01-16 11:40 262704 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-14 16:05 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Core Temp"="c:\users\Expert\Downloads\Teplota procesoru\CoreTemp32\Core Temp.exe" [2009-08-04 378384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-14 526896]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-05-30 544768]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-05-09 397312]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2012-03-01 2333968]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-07-16 821768]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-08-30 11672208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 01:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-25 20:36 28672 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-03-24 02:00 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-18 01:40 767312 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-05-12 20:11 167936 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-08-03 11:50 111208 ----a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2009-11-25 18:42 54672 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
2008-05-12 15:28 167936 ------w- c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2375729464-1652811455-3684655677-1000]
"EnableNotificationsRef"=dword:00000001
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 76682189
*NewlyCreated* - ALSYSIO
*Deregistered* - 76682189
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2013-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 20:53]
.
2013-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 20:53]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xportovat do aplikace Microsoft Excel
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{692C7F80-CB10-40F7-B994-0011FC12904D}: NameServer = 62.240.178.250
FF - ProfilePath - c:\users\Expert\AppData\Roaming\Mozilla\Firefox\Profiles\82cm6gpa.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2012-12-28 16:37; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Expert\AppData\Roaming\Mozilla\Firefox\Profiles\82cm6gpa.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-16 14:39
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2013-01-16 14:44:22
ComboFix-quarantined-files.txt 2013-01-16 13:44
.
Před spuštěním: Volných bajtů: 87 834 525 696
Po spuštění: Volných bajtů: 87 727 820 800
.
- - End Of File - - ECC83D5D90BAFD7F90D9EFCE4E80C34E
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod jaojao » 16 led 2013 15:01

Projel jsem to i TFC i AdwCleanerem,..
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod Žbeky » 16 led 2013 17:35

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Folder::
c:\program files\Google\Update

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2375729464-1652811455-3684655677-1000]
"EnableNotificationsRef"=dword:00000000

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

RegNull::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
Obrázek

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod jaojao » 16 led 2013 18:19

ComboFix 13-01-16.01 - Expert 16.01.2013 17:51:26.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2813.1660 [GMT 1:00]
Spuštěný z: c:\users\Expert\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Expert\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))

.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.124\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.124\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.124\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.124\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.124\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.124\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.124\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.124\goopdate.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.124\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.124\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.124\psmachine.dll
c:\program files\Google\Update\1.3.21.124\psuser.dll
c:\program files\Google\Update\Download\{0B92FC40-EFD8-47BD-A088-2E16CCD7D84C}\GoogleToolbarInstaller_updater_signed.exe
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.125\GoogleUpdateB6998767.exe
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\23.0.1271.97\23.0.1271.97_23.0.1271.95_chrome_updater.exe
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\23.0.1271.97\23.0.1271.97_chrome_installer.exe
c:\program files\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\23.0.1271.97\23.0.1271.97_chrome_installer.exe
c:\program files\Google\Update\Download\{AA45CB3B-6AC8-4403-A345-2B75246ECBB3}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\7.4.3230.2052\GoogleToolbarInstaller_updater_signed.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_gupdate
-------\Legacy_gupdatem
-------\Legacy_gupdate
-------\Legacy_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-16 do 2013-01-16 )))))))))))))))))))))))))))))))
.
.
2013-01-16 17:10 . 2013-01-16 17:12 -------- d-----w- c:\users\Expert\AppData\Local\temp
2013-01-16 17:10 . 2013-01-16 17:10 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-16 17:10 . 2013-01-16 17:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-16 14:41 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{23CACEDA-34F6-42CE-9E47-364FAC62A165}\mpengine.dll
2013-01-09 15:21 . 2012-11-23 01:35 2048000 ----a-w- c:\windows\system32\win32k.sys
2013-01-09 15:20 . 2012-11-20 04:22 204288 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-09 15:20 . 2012-11-02 10:19 1400832 ----a-w- c:\windows\system32\msxml6.dll
2012-12-29 06:06 . 2013-01-16 14:03 -------- d-----w- C:\HijackThis
2012-12-28 22:24 . 2011-12-07 18:32 216064 ----a-w- c:\windows\system32\lagarith.dll
2012-12-28 22:24 . 2011-06-24 15:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2012-12-28 22:24 . 2011-06-24 15:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
2012-12-28 22:24 . 2012-06-09 18:21 178688 ----a-w- c:\windows\system32\unrar.dll
2012-12-28 22:24 . 2011-12-21 18:14 151552 ----a-w- c:\windows\system32\ac3acm.acm
2012-12-28 22:24 . 2012-12-10 18:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2012-12-28 22:24 . 2012-12-28 22:24 -------- d-----w- c:\program files\K-Lite Codec Pack
2012-12-28 20:22 . 2012-12-28 20:22 -------- d-----w- C:\Trend Micro
2012-12-28 15:07 . 2012-12-28 15:07 -------- d-----w- c:\users\Expert\AppData\Local\Apps
2012-12-28 13:29 . 2012-12-28 13:29 -------- d-----w- c:\users\Expert\AppData\Local\Macromedia
2012-12-28 13:29 . 2012-12-28 13:29 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-28 08:06 . 2012-12-28 08:06 -------- d-----w- c:\users\Expert\Tracing
2012-12-28 08:05 . 2012-12-28 08:05 -------- d-----w- c:\windows\cs
2012-12-28 07:57 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2012-12-28 07:57 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2012-12-28 07:57 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2012-12-28 07:53 . 2012-12-28 07:53 89944 ----a-w- c:\program files\Common Files\Windows Live\.cache\751778b01cde4d00b\DSETUP.dll
2012-12-28 07:53 . 2012-12-28 07:53 537432 ----a-w- c:\program files\Common Files\Windows Live\.cache\751778b01cde4d00b\DXSETUP.exe
2012-12-28 07:53 . 2012-12-28 07:53 1801048 ----a-w- c:\program files\Common Files\Windows Live\.cache\751778b01cde4d00b\dsetup32.dll
2012-12-28 07:53 . 2012-12-28 07:53 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\70d2e1901cde4d00a\DSETUP.dll
2012-12-28 07:53 . 2012-12-28 07:53 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\70d2e1901cde4d00a\DXSETUP.exe
2012-12-28 07:53 . 2012-12-28 07:53 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\70d2e1901cde4d00a\dsetup32.dll
2012-12-28 07:53 . 2012-12-28 07:53 6260088 ----a-w- c:\program files\Common Files\Windows Live\.cache\6b64be901cde4d009\Silverlight.4.0.exe
2012-12-28 07:51 . 2012-12-28 14:50 -------- d-----w- c:\users\Expert\AppData\Local\Windows Live
2012-12-28 07:25 . 2012-12-28 07:25 -------- d-----w- c:\users\Expert\AppData\Roaming\DriverCure
2012-12-28 07:25 . 2012-12-28 07:25 -------- d-----w- c:\users\Expert\AppData\Roaming\ParetoLogic
2012-12-28 07:24 . 2012-12-28 07:33 -------- d-----w- c:\programdata\ParetoLogic
2012-12-27 18:07 . 2012-12-27 18:07 -------- d-----w- c:\users\Expert\AppData\Roaming\Reviversoft
2012-12-22 08:55 . 2012-12-16 13:12 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-22 08:55 . 2012-12-16 10:50 293376 ----a-w- c:\windows\system32\atmfd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-16 12:19 . 2008-01-21 02:24 1036800 ----a-w- c:\windows\system32\d3d8.dll
2012-12-28 13:29 . 2011-12-03 17:19 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-28 07:58 . 2011-03-28 17:36 19696 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-11-13 01:29 . 2012-12-06 02:12 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-02 10:18 . 2012-12-06 02:13 376320 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26 . 2012-12-06 02:13 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2012-10-30 22:51 . 2012-10-12 16:55 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-30 22:51 . 2012-10-12 16:55 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-30 22:51 . 2012-10-12 16:55 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-30 22:51 . 2012-10-12 16:55 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-30 22:51 . 2012-10-12 16:55 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-30 22:51 . 2012-10-12 16:55 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-30 22:51 . 2012-10-12 16:54 41224 ----a-w- c:\windows\avastSS.scr
2012-10-30 22:50 . 2012-10-12 16:54 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-01-16 11:40 . 2013-01-16 11:40 262704 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-14 16:05 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Core Temp"="c:\users\Expert\Downloads\Teplota procesoru\CoreTemp32\Core Temp.exe" [2009-08-04 378384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-14 526896]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-05-30 544768]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-05-09 397312]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2012-03-01 2333968]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-07-16 821768]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-08-30 11672208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 01:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-25 20:36 28672 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-03-24 02:00 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-18 01:40 767312 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-05-12 20:11 167936 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-08-03 11:50 111208 ----a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2009-11-25 18:42 54672 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
2008-05-12 15:28 167936 ------w- c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2375729464-1652811455-3684655677-1000]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xportovat do aplikace Microsoft Excel
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{692C7F80-CB10-40F7-B994-0011FC12904D}: NameServer = 62.240.178.250,10.0.0.1
FF - ProfilePath - c:\users\Expert\AppData\Roaming\Mozilla\Firefox\Profiles\82cm6gpa.default\
FF - prefs.js: browser.search.selectedEngine - Vyhledávání videí ve službě YouTube
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2012-12-28 16:37; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Expert\AppData\Roaming\Mozilla\Firefox\Profiles\82cm6gpa.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-16 18:12
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(588)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\System32\SysHook.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\conime.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lxcgcoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\acer\Mobility Center\MobilityService.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Launch Manager\QtZgAcer.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\users\Expert\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
c:\program files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-01-16 18:18:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-16 17:18
ComboFix2.txt 2013-01-16 13:44
.
Před spuštěním: Volných bajtů: 87 669 129 216
Po spuštění: Volných bajtů: 87 218 458 624
.
- - End Of File - - B0D4D27E11894C591B4DFACDFFCE6807
----------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------
OK, na ty google updatejoby jsem se koukal, zřejmě je tam nacpal s chrome, bylo to ve složce google i s googleEarth (a tento využívá), tak jsem nevěděl jestli se snažit to dostat ven.
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod jaojao » 16 led 2013 20:06

Pokud je to vše tak díky.
(combo jsem odinstaloval a vyčistil T-cleanerem)
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Trojan - trošku urychleně , díky

Příspěvekod memphisto » 16 led 2013 22:12

Jsi docela zbrklý... V tomto případě se to nemusí vyplatit. Jinak je to ok. Pokud nejsou problémy, tak je to vše.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Trojan - trošku urychleně , díky  Vyřešeno

Příspěvekod jaojao » 17 led 2013 06:58

Většinou jsem kapku rychlejší :smile: , ne nic jiného krom předchozích problémů s teplotou tam nemá, no jen nefunkční mechanika, ale k tomu ho dokopu až to bude zase blbnout s teplotama. :wc:

Díky :clap:
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 109 hostů