Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 07 črc 2013 15:17

Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "

- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje "Smazání- Finished "
- Klikni na "Zprávy " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Reklama
Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Dokyxxx » 21 srp 2013 17:05

RogueKiller V8.6.2 [Jul 5 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Standard [Práva správce]
Mód : Odebrat -- Datum : 08/21/2013 16:58:07
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 10 ¤¤¤
[HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ POL] HKLM\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NAHRAZENO (1)
[HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> NAHRAZENO (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: Hitachi HDP725050GLA360 +++++
--- User ---
[MBR] f94e5c6f135d9eb42300792488926020
[BSP] 81191be59324ccb175303064e16cb832 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 474938 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 972675072 | Size: 2000 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_08212013_165807.txt >>
RKreport[0]_S_07072013_134903.txt;RKreport[0]_S_08212013_165739.txt

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 21 srp 2013 17:05

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Dokyxxx » 21 srp 2013 17:06

16:59:41.0387 5580 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
16:59:42.0807 5580 ============================================================
16:59:42.0807 5580 Current date / time: 2013/08/21 16:59:42.0807
16:59:42.0807 5580 SystemInfo:
16:59:42.0807 5580
16:59:42.0807 5580 OS Version: 6.0.6002 ServicePack: 2.0
16:59:42.0807 5580 Product type: Workstation
16:59:42.0807 5580 ComputerName: STANDARD-PC
16:59:42.0807 5580 UserName: Standard
16:59:42.0807 5580 Windows directory: C:\Windows
16:59:42.0807 5580 System windows directory: C:\Windows
16:59:42.0807 5580 Processor architecture: Intel x86
16:59:42.0807 5580 Number of processors: 4
16:59:42.0807 5580 Page size: 0x1000
16:59:42.0807 5580 Boot type: Normal boot
16:59:42.0807 5580 ============================================================
16:59:43.0259 5580 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:59:43.0306 5580 ============================================================
16:59:43.0306 5580 \Device\Harddisk0\DR0:
16:59:43.0322 5580 MBR partitions:
16:59:43.0322 5580 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x39F9D000
16:59:43.0322 5580 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x39F9D800, BlocksNum 0x3E8000
16:59:43.0322 5580 ============================================================
16:59:43.0368 5580 C: <-> \Device\Harddisk0\DR0\Partition1
16:59:43.0446 5580 D: <-> \Device\Harddisk0\DR0\Partition2
16:59:43.0446 5580 ============================================================
16:59:43.0446 5580 Initialize success
16:59:43.0446 5580 ============================================================
16:59:48.0438 2500 ============================================================
16:59:48.0438 2500 Scan started
16:59:48.0438 2500 Mode: Manual;
16:59:48.0438 2500 ============================================================
16:59:49.0250 2500 ================ Scan system memory ========================
16:59:49.0250 2500 System memory - ok
16:59:49.0250 2500 ================ Scan services =============================
16:59:49.0546 2500 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
16:59:49.0546 2500 ACPI - ok
16:59:49.0686 2500 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
16:59:49.0686 2500 AdobeFlashPlayerUpdateSvc - ok
16:59:49.0952 2500 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
16:59:49.0952 2500 adp94xx - ok
16:59:50.0076 2500 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
16:59:50.0076 2500 adpahci - ok
16:59:50.0123 2500 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
16:59:50.0123 2500 adpu160m - ok
16:59:50.0201 2500 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
16:59:50.0201 2500 adpu320 - ok
16:59:50.0248 2500 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
16:59:50.0264 2500 AeLookupSvc - ok
16:59:50.0279 2500 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
16:59:50.0279 2500 AFD - ok
16:59:50.0326 2500 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
16:59:50.0326 2500 agp440 - ok
16:59:50.0388 2500 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
16:59:50.0388 2500 aic78xx - ok
16:59:50.0404 2500 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
16:59:50.0420 2500 ALG - ok
16:59:50.0420 2500 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
16:59:50.0420 2500 aliide - ok
16:59:50.0482 2500 [ C4232FADFA9691B85DDA0A7B636C5F6D ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
16:59:50.0482 2500 AMD External Events Utility - ok
16:59:50.0513 2500 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
16:59:50.0513 2500 amdagp - ok
16:59:50.0560 2500 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
16:59:50.0560 2500 amdide - ok
16:59:50.0591 2500 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
16:59:50.0591 2500 AmdK7 - ok
16:59:50.0607 2500 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
16:59:50.0607 2500 AmdK8 - ok
16:59:51.0668 2500 [ 10D681E635E81C253FC5DD1A5048B0E9 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
16:59:51.0714 2500 amdkmdag - ok
16:59:51.0792 2500 [ 112A7F24C6535DBD2E90AEF34ECB57A4 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
16:59:51.0808 2500 amdkmdap - ok
16:59:51.0886 2500 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
16:59:51.0886 2500 Appinfo - ok
16:59:51.0917 2500 [ 0FE769CAE5855B53C90E23F85E7E89FF ] AppMgmt C:\Windows\System32\appmgmts.dll
16:59:51.0917 2500 AppMgmt - ok
16:59:51.0948 2500 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
16:59:51.0948 2500 arc - ok
16:59:51.0964 2500 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
16:59:51.0964 2500 arcsas - ok
16:59:52.0011 2500 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
16:59:52.0011 2500 AsyncMac - ok
16:59:52.0026 2500 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
16:59:52.0026 2500 atapi - ok
16:59:52.0073 2500 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
16:59:52.0073 2500 AudioEndpointBuilder - ok
16:59:52.0089 2500 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
16:59:52.0089 2500 Audiosrv - ok
16:59:52.0167 2500 [ 8DCD8B53E5935D9AF52CB62FD2B965B5 ] avgtp C:\Windows\system32\drivers\avgtpx86.sys
16:59:52.0167 2500 avgtp - ok
16:59:52.0198 2500 [ 502F1C30BD50B32D00CE4DCAECC3D3C7 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
16:59:52.0214 2500 b57nd60x - ok
16:59:52.0323 2500 [ 6163664C7E9CD110AF70180C126C3FDC ] BcmSqlStartupSvc C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
16:59:52.0323 2500 BcmSqlStartupSvc - ok
16:59:52.0354 2500 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
16:59:52.0354 2500 Beep - ok
16:59:52.0370 2500 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
16:59:52.0385 2500 BFE - ok
16:59:52.0463 2500 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
16:59:52.0479 2500 BITS - ok
16:59:52.0510 2500 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
16:59:52.0526 2500 blbdrive - ok
16:59:52.0588 2500 [ 0A5F1B94396C2757F1354881D5266CC1 ] Blfp C:\Windows\system32\DRIVERS\basp.sys
16:59:52.0588 2500 Blfp - ok
16:59:52.0619 2500 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
16:59:52.0619 2500 bowser - ok
16:59:52.0806 2500 [ FA5A8C83E3683A0A811F8C8CA9D0D9CC ] BrcmMgmtAgent C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
16:59:52.0806 2500 BrcmMgmtAgent - ok
16:59:52.0900 2500 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
16:59:52.0900 2500 BrFiltLo - ok
16:59:52.0947 2500 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
16:59:52.0947 2500 BrFiltUp - ok
16:59:53.0009 2500 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
16:59:53.0009 2500 Browser - ok
16:59:53.0040 2500 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
16:59:53.0040 2500 Brserid - ok
16:59:53.0087 2500 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
16:59:53.0087 2500 BrSerWdm - ok
16:59:53.0134 2500 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
16:59:53.0134 2500 BrUsbMdm - ok
16:59:53.0212 2500 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
16:59:53.0212 2500 BrUsbSer - ok
16:59:53.0243 2500 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
16:59:53.0243 2500 BTHMODEM - ok
16:59:53.0274 2500 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
16:59:53.0274 2500 cdfs - ok
16:59:53.0290 2500 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
16:59:53.0306 2500 cdrom - ok
16:59:53.0368 2500 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
16:59:53.0368 2500 CertPropSvc - ok
16:59:53.0384 2500 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
16:59:53.0384 2500 circlass - ok
16:59:53.0399 2500 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
16:59:53.0399 2500 CLFS - ok
16:59:53.0446 2500 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:59:53.0446 2500 clr_optimization_v2.0.50727_32 - ok
16:59:53.0493 2500 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:59:53.0493 2500 clr_optimization_v4.0.30319_32 - ok
16:59:53.0571 2500 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
16:59:53.0571 2500 cmdide - ok
16:59:53.0618 2500 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\drivers\compbatt.sys
16:59:53.0618 2500 Compbatt - ok
16:59:53.0618 2500 COMSysApp - ok
16:59:53.0633 2500 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
16:59:53.0633 2500 crcdisk - ok
16:59:53.0664 2500 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
16:59:53.0664 2500 Crusoe - ok
16:59:53.0742 2500 [ 684C130BBC6DB681BAD4920A4C944AA5 ] CryptSvc C:\Windows\system32\cryptsvc.dll
16:59:53.0742 2500 CryptSvc - ok
16:59:53.0774 2500 [ 9BDB2E89BE8D0EF37B1F25C3D3FC192C ] CSC C:\Windows\system32\drivers\csc.sys
16:59:53.0774 2500 CSC - ok
16:59:53.0883 2500 [ 0A2095F92F6AE4FE6484D911B0C21E95 ] CscService C:\Windows\System32\cscsvc.dll
16:59:53.0898 2500 CscService - ok
16:59:53.0976 2500 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
16:59:53.0992 2500 DcomLaunch - ok
16:59:54.0054 2500 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
16:59:54.0054 2500 DfsC - ok
16:59:54.0460 2500 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
16:59:54.0476 2500 DFSR - ok
16:59:54.0522 2500 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
16:59:54.0522 2500 Dhcp - ok
16:59:54.0616 2500 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
16:59:54.0616 2500 disk - ok
16:59:54.0678 2500 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
16:59:54.0678 2500 Dnscache - ok
16:59:54.0725 2500 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
16:59:54.0741 2500 dot3svc - ok
16:59:54.0803 2500 [ 4F59C172C094E1A1D46463A8DC061CBD ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys
16:59:54.0803 2500 Dot4 - ok
16:59:54.0819 2500 [ 80BF3BA09F6F2523C8F6B7CC6DBF7BD5 ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys
16:59:54.0834 2500 Dot4Print - ok
16:59:54.0881 2500 [ C55004CA6B419B6695970DFE849B122F ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys
16:59:54.0881 2500 dot4usb - ok
16:59:54.0912 2500 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
16:59:54.0912 2500 DPS - ok
16:59:54.0975 2500 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
16:59:54.0975 2500 drmkaud - ok
16:59:55.0037 2500 [ FB38473835476A6FB272215A1D972AF9 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
16:59:55.0037 2500 dtsoftbus01 - ok
16:59:55.0100 2500 [ 5DE0FAEC9E5D1AAE74F8568897891A01 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
16:59:55.0100 2500 DXGKrnl - ok
16:59:55.0178 2500 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
16:59:55.0178 2500 E1G60 - ok
16:59:55.0224 2500 [ 668819862FFDE09028B975B74D376030 ] e1yexpress C:\Windows\system32\DRIVERS\e1y6032.sys
16:59:55.0224 2500 e1yexpress - ok
16:59:55.0318 2500 [ 16FF05BE2BD95824B487B1476862A84B ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
16:59:55.0318 2500 eamonm - ok
16:59:55.0349 2500 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
16:59:55.0349 2500 EapHost - ok
16:59:55.0380 2500 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
16:59:55.0380 2500 Ecache - ok
16:59:55.0458 2500 [ 366369746D1818FDD8589D1F2C8A6D03 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
16:59:55.0458 2500 ehdrv - ok
16:59:55.0630 2500 [ 7FE34FD5652C54BDA8D2DF8AC92E833A ] ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
16:59:55.0630 2500 ekrn - ok
16:59:55.0724 2500 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
16:59:55.0724 2500 elxstor - ok
16:59:55.0786 2500 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
16:59:55.0786 2500 EMDMgmt - ok
16:59:55.0880 2500 [ E38CABC8881DBE278BDA5E131CFF74AC ] epfwwfpr C:\Windows\system32\DRIVERS\epfwwfpr.sys
16:59:55.0880 2500 epfwwfpr - ok
16:59:55.0926 2500 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
16:59:55.0926 2500 ErrDev - ok
16:59:56.0004 2500 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
16:59:56.0004 2500 EventSystem - ok
16:59:56.0129 2500 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
16:59:56.0129 2500 exfat - ok
16:59:56.0192 2500 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
16:59:56.0192 2500 fastfat - ok
16:59:56.0441 2500 [ DFBA0F60FA301E5B1BFB1403A93EE23E ] Fax C:\Windows\system32\fxssvc.exe
16:59:56.0472 2500 Fax - ok
16:59:56.0519 2500 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
16:59:56.0519 2500 fdc - ok
16:59:56.0535 2500 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
16:59:56.0535 2500 fdPHost - ok
16:59:56.0566 2500 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
16:59:56.0566 2500 FDResPub - ok
16:59:56.0597 2500 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
16:59:56.0597 2500 FileInfo - ok
16:59:56.0613 2500 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
16:59:56.0613 2500 Filetrace - ok
16:59:56.0675 2500 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
16:59:56.0675 2500 flpydisk - ok
16:59:56.0784 2500 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
16:59:56.0784 2500 FltMgr - ok
16:59:57.0034 2500 [ 119ACA7CADCA75BEA6B38E999443BAA6 ] FontCache C:\Windows\system32\FntCache.dll
16:59:57.0050 2500 FontCache - ok
16:59:57.0128 2500 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
16:59:57.0128 2500 FontCache3.0.0.0 - ok
16:59:57.0206 2500 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
16:59:57.0206 2500 Fs_Rec - ok
16:59:57.0252 2500 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
16:59:57.0252 2500 gagp30kx - ok
16:59:57.0315 2500 [ 007AEA2E06E7CEF7372E40C277163959 ] ggflt C:\Windows\system32\DRIVERS\ggflt.sys
16:59:57.0315 2500 ggflt - ok
16:59:57.0346 2500 [ C73DE35960CA75C5AB4AE636B127C64E ] ggsemc C:\Windows\system32\DRIVERS\ggsemc.sys
16:59:57.0346 2500 ggsemc - ok
16:59:57.0424 2500 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
16:59:57.0440 2500 gpsvc - ok
16:59:57.0518 2500 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
16:59:57.0518 2500 HdAudAddService - ok
16:59:57.0549 2500 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
16:59:57.0549 2500 HDAudBus - ok
16:59:57.0627 2500 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
16:59:57.0627 2500 HidBth - ok
16:59:57.0642 2500 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
16:59:57.0642 2500 HidIr - ok
16:59:57.0736 2500 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
16:59:57.0736 2500 hidserv - ok
16:59:57.0767 2500 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
16:59:57.0767 2500 HidUsb - ok
16:59:57.0783 2500 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
16:59:57.0783 2500 hkmsvc - ok
16:59:57.0798 2500 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
16:59:57.0814 2500 HpCISSs - ok
16:59:58.0204 2500 [ FCB563B0A23643E5F80B6FF1E60F610F ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
16:59:58.0204 2500 hpqcxs08 - ok
16:59:58.0220 2500 [ 25E443E27165C652723A92D9BDFD4649 ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
16:59:58.0220 2500 hpqddsvc - ok
16:59:58.0251 2500 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
16:59:58.0251 2500 HTTP - ok
16:59:58.0344 2500 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
16:59:58.0344 2500 i2omp - ok
16:59:58.0376 2500 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
16:59:58.0376 2500 i8042prt - ok
16:59:58.0454 2500 [ 42BE6406094936A23280D68D9AEC33D0 ] iaStor C:\Windows\system32\drivers\iastor.sys
16:59:58.0454 2500 iaStor - ok
16:59:58.0485 2500 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
16:59:58.0485 2500 iaStorV - ok
16:59:58.0625 2500 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
16:59:58.0641 2500 idsvc - ok
16:59:59.0234 2500 [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
16:59:59.0280 2500 igfx - ok
16:59:59.0312 2500 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
16:59:59.0312 2500 iirsp - ok
16:59:59.0343 2500 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
16:59:59.0343 2500 IKEEXT - ok
16:59:59.0390 2500 [ 0E70E4485F0ED782248E26353A08D312 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
16:59:59.0405 2500 IntcAzAudAddService - ok
16:59:59.0436 2500 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
16:59:59.0436 2500 intelide - ok
16:59:59.0452 2500 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
16:59:59.0452 2500 intelppm - ok
16:59:59.0468 2500 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
16:59:59.0483 2500 IPBusEnum - ok
16:59:59.0499 2500 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:59:59.0499 2500 IpFilterDriver - ok
16:59:59.0530 2500 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
16:59:59.0546 2500 iphlpsvc - ok
16:59:59.0592 2500 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
16:59:59.0592 2500 IPMIDRV - ok
16:59:59.0624 2500 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
16:59:59.0624 2500 IPNAT - ok
16:59:59.0655 2500 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
16:59:59.0655 2500 IRENUM - ok
16:59:59.0670 2500 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
16:59:59.0670 2500 isapnp - ok
16:59:59.0686 2500 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
16:59:59.0686 2500 iScsiPrt - ok
16:59:59.0780 2500 [ 76F9267AB1223A5EA5230625A0031BDC ] IT9135BDA C:\Windows\system32\Drivers\IT9135BDA.sys
16:59:59.0780 2500 IT9135BDA - ok
16:59:59.0795 2500 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
16:59:59.0795 2500 iteatapi - ok
16:59:59.0842 2500 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
16:59:59.0842 2500 iteraid - ok
16:59:59.0858 2500 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
16:59:59.0858 2500 kbdclass - ok
16:59:59.0873 2500 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
16:59:59.0873 2500 kbdhid - ok
16:59:59.0920 2500 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
16:59:59.0920 2500 KeyIso - ok
16:59:59.0951 2500 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
16:59:59.0951 2500 KSecDD - ok
16:59:59.0982 2500 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
16:59:59.0982 2500 KtmRm - ok
17:00:00.0045 2500 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
17:00:00.0045 2500 LanmanServer - ok
17:00:00.0076 2500 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:00:00.0076 2500 LanmanWorkstation - ok
17:00:00.0201 2500 [ C34411A244029F1C08687F7C752C4563 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
17:00:00.0201 2500 LightScribeService - ok
17:00:00.0232 2500 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:00:00.0248 2500 lltdio - ok
17:00:00.0263 2500 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:00:00.0263 2500 lltdsvc - ok
17:00:00.0279 2500 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
17:00:00.0279 2500 lmhosts - ok
17:00:00.0310 2500 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
17:00:00.0310 2500 LSI_FC - ok
17:00:00.0326 2500 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
17:00:00.0326 2500 LSI_SAS - ok
17:00:00.0341 2500 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
17:00:00.0341 2500 LSI_SCSI - ok
17:00:00.0372 2500 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
17:00:00.0372 2500 luafv - ok
17:00:00.0435 2500 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
17:00:00.0435 2500 MBAMProtector - ok
17:00:00.0528 2500 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:00:00.0528 2500 MBAMScheduler - ok
17:00:00.0591 2500 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:00:00.0591 2500 MBAMService - ok
17:00:00.0653 2500 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
17:00:00.0653 2500 megasas - ok
17:00:00.0684 2500 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
17:00:00.0684 2500 MegaSR - ok
17:00:00.0731 2500 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
17:00:00.0731 2500 MMCSS - ok
17:00:00.0747 2500 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
17:00:00.0747 2500 Modem - ok
17:00:00.0778 2500 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:00:00.0778 2500 monitor - ok
17:00:00.0794 2500 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:00:00.0794 2500 mouclass - ok
17:00:00.0794 2500 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:00:00.0794 2500 mouhid - ok
17:00:00.0809 2500 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
17:00:00.0809 2500 MountMgr - ok
17:00:00.0903 2500 [ A35576A433F4AEB0D48976A004657CB6 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
17:00:00.0903 2500 MozillaMaintenance - ok
17:00:00.0934 2500 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
17:00:00.0934 2500 mpio - ok
17:00:00.0950 2500 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:00:00.0950 2500 mpsdrv - ok
17:00:01.0028 2500 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
17:00:01.0043 2500 MpsSvc - ok
17:00:01.0059 2500 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
17:00:01.0059 2500 Mraid35x - ok
17:00:01.0090 2500 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:00:01.0090 2500 MRxDAV - ok
17:00:01.0106 2500 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:00:01.0106 2500 mrxsmb - ok
17:00:01.0121 2500 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:00:01.0121 2500 mrxsmb10 - ok
17:00:01.0137 2500 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:00:01.0137 2500 mrxsmb20 - ok
17:00:01.0168 2500 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
17:00:01.0168 2500 msahci - ok
17:00:01.0184 2500 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:00:01.0184 2500 msdsm - ok
17:00:01.0230 2500 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
17:00:01.0246 2500 MSDTC - ok
17:00:01.0277 2500 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:00:01.0277 2500 Msfs - ok
17:00:01.0293 2500 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:00:01.0293 2500 msisadrv - ok
17:00:01.0340 2500 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:00:01.0340 2500 MSiSCSI - ok
17:00:01.0355 2500 msiserver - ok
17:00:01.0386 2500 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:00:01.0386 2500 MSKSSRV - ok
17:00:01.0402 2500 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:00:01.0402 2500 MSPCLOCK - ok
17:00:01.0402 2500 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:00:01.0402 2500 MSPQM - ok
17:00:01.0418 2500 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:00:01.0418 2500 MsRPC - ok
17:00:01.0449 2500 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
17:00:01.0449 2500 mssmbios - ok
17:00:01.0511 2500 MSSQL$MSSMLBIZ - ok
17:00:01.0605 2500 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
17:00:01.0620 2500 MSSQLServerADHelper - ok
17:00:01.0652 2500 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:00:01.0652 2500 MSTEE - ok
17:00:01.0667 2500 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
17:00:01.0667 2500 Mup - ok
17:00:01.0730 2500 [ 428C611928DF3E96538A482117E659F7 ] NAL C:\Windows\system32\Drivers\iqvw32.sys
17:00:01.0730 2500 NAL - ok
17:00:01.0901 2500 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
17:00:01.0932 2500 napagent - ok
17:00:01.0979 2500 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:00:01.0979 2500 NativeWifiP - ok
17:00:02.0213 2500 [ 6D8FCDD5BB3B676EF58FA234073492C6 ] NBService C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
17:00:02.0229 2500 NBService - ok
17:00:02.0291 2500 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:00:02.0291 2500 NDIS - ok
17:00:02.0307 2500 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:00:02.0307 2500 NdisTapi - ok
17:00:02.0338 2500 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:00:02.0338 2500 Ndisuio - ok
17:00:02.0354 2500 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:00:02.0369 2500 NdisWan - ok
17:00:02.0416 2500 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:00:02.0416 2500 NDProxy - ok
17:00:02.0478 2500 [ 51C6D8BFBD4EA5B62A1BA7F4469250D3 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
17:00:02.0478 2500 Net Driver HPZ12 - ok
17:00:02.0494 2500 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:00:02.0494 2500 NetBIOS - ok
17:00:02.0510 2500 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
17:00:02.0510 2500 netbt - ok
17:00:02.0541 2500 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
17:00:02.0541 2500 Netlogon - ok
17:00:02.0588 2500 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
17:00:02.0588 2500 Netman - ok
17:00:02.0603 2500 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
17:00:02.0603 2500 netprofm - ok
17:00:02.0712 2500 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:00:02.0744 2500 NetTcpPortSharing - ok
17:00:02.0790 2500 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
17:00:02.0790 2500 nfrd960 - ok
17:00:02.0822 2500 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:00:02.0837 2500 NlaSvc - ok
17:00:03.0102 2500 [ E32686B4E27D11F83E3F2844E104C66C ] NMIndexingService C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
17:00:03.0102 2500 NMIndexingService - ok
17:00:03.0134 2500 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:00:03.0134 2500 Npfs - ok
17:00:03.0149 2500 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
17:00:03.0165 2500 nsi - ok
17:00:03.0165 2500 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:00:03.0165 2500 nsiproxy - ok
17:00:03.0399 2500 [ 2C1121F2B87E9A6B12485DF53CD848C7 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:00:03.0399 2500 Ntfs - ok
17:00:03.0492 2500 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
17:00:03.0492 2500 ntrigdigi - ok
17:00:03.0524 2500 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
17:00:03.0524 2500 Null - ok
17:00:03.0586 2500 [ 77F9F9A199B87FE3F852E12F5419240B ] NVHDA C:\Windows\system32\drivers\nvhda32v.sys
17:00:03.0586 2500 NVHDA - ok
17:00:04.0538 2500 [ B69E6F70CE1151C8D62ABC9DEF64DFBE ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:00:04.0584 2500 nvlddmkm - ok
17:00:04.0631 2500 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:00:04.0631 2500 nvraid - ok
17:00:04.0662 2500 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:00:04.0662 2500 nvstor - ok
17:00:04.0709 2500 [ E4284FCF99FEA13A7E1836F87AE356F6 ] nvsvc C:\Windows\system32\nvvsvc.exe
17:00:04.0709 2500 nvsvc - ok
17:00:04.0803 2500 [ 03E60E0BFA53ED15DC984FA34B44BB0F ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
17:00:04.0818 2500 nvUpdatusService - ok
17:00:04.0850 2500 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:00:04.0850 2500 nv_agp - ok
17:00:04.0959 2500 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
17:00:04.0959 2500 odserv - ok
17:00:04.0974 2500 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
17:00:04.0990 2500 ohci1394 - ok
17:00:05.0021 2500 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:00:05.0021 2500 ose - ok
17:00:05.0068 2500 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
17:00:05.0084 2500 p2pimsvc - ok
17:00:05.0084 2500 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
17:00:05.0084 2500 p2psvc - ok
17:00:05.0130 2500 [ 8A79FDF04A73428597E2CAF9D0D67850 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:00:05.0130 2500 Parport - ok
17:00:05.0177 2500 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:00:05.0177 2500 partmgr - ok
17:00:05.0177 2500 [ 6C580025C81CAF3AE9E3617C22CAD00E ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:00:05.0177 2500 Parvdm - ok
17:00:05.0208 2500 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
17:00:05.0208 2500 PcaSvc - ok
17:00:05.0224 2500 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
17:00:05.0240 2500 pci - ok
17:00:05.0255 2500 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
17:00:05.0255 2500 pciide - ok
17:00:05.0271 2500 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
17:00:05.0271 2500 pcmcia - ok
17:00:05.0302 2500 pdfcDispatcher - ok
17:00:05.0333 2500 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:00:05.0333 2500 PEAUTH - ok
17:00:05.0380 2500 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
17:00:05.0396 2500 pla - ok
17:00:05.0411 2500 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:00:05.0427 2500 PlugPlay - ok
17:00:05.0474 2500 [ 79834AA2FBF9FE81EEBB229024F6F7FC ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
17:00:05.0474 2500 Pml Driver HPZ12 - ok
17:00:05.0536 2500 [ 831883B107684301F48ACE752C963984 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
17:00:05.0536 2500 PnkBstrA - ok
17:00:05.0583 2500 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
17:00:05.0583 2500 PNRPAutoReg - ok
17:00:05.0583 2500 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
17:00:05.0598 2500 PNRPsvc - ok
17:00:05.0661 2500 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:00:05.0661 2500 PolicyAgent - ok
17:00:05.0676 2500 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:00:05.0692 2500 PptpMiniport - ok
17:00:05.0708 2500 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
17:00:05.0708 2500 Processor - ok
17:00:05.0723 2500 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
17:00:05.0739 2500 ProfSvc - ok
17:00:05.0739 2500 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
17:00:05.0739 2500 ProtectedStorage - ok
17:00:05.0801 2500 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
17:00:05.0801 2500 PSched - ok
17:00:05.0848 2500 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
17:00:05.0848 2500 ql2300 - ok
17:00:05.0864 2500 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
17:00:05.0864 2500 ql40xx - ok
17:00:05.0910 2500 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
17:00:05.0910 2500 QWAVE - ok
17:00:05.0926 2500 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:00:05.0926 2500 QWAVEdrv - ok
17:00:05.0942 2500 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:00:05.0942 2500 RasAcd - ok
17:00:05.0942 2500 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
17:00:05.0957 2500 RasAuto - ok
17:00:05.0957 2500 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:00:05.0957 2500 Rasl2tp - ok
17:00:05.0973 2500 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
17:00:05.0988 2500 RasMan - ok
17:00:06.0004 2500 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:00:06.0004 2500 RasPppoe - ok
17:00:06.0020 2500 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:00:06.0020 2500 RasSstp - ok
17:00:06.0020 2500 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:00:06.0020 2500 rdbss - ok
17:00:06.0035 2500 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:00:06.0035 2500 RDPCDD - ok
17:00:06.0035 2500 [ 943B18305EAE3935598A9B4A3D560B4C ] rdpdr C:\Windows\system32\DRIVERS\rdpdr.sys
17:00:06.0035 2500 rdpdr - ok
17:00:06.0035 2500 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:00:06.0035 2500 RDPENCDD - ok
17:00:06.0066 2500 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:00:06.0066 2500 RDPWD - ok
17:00:06.0144 2500 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
17:00:06.0144 2500 RemoteAccess - ok
17:00:06.0160 2500 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:00:06.0160 2500 RemoteRegistry - ok
17:00:06.0160 2500 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
17:00:06.0176 2500 RpcLocator - ok
17:00:06.0191 2500 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\System32\rpcss.dll
17:00:06.0191 2500 RpcSs - ok
17:00:06.0207 2500 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:00:06.0222 2500 rspndr - ok
17:00:06.0222 2500 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
17:00:06.0222 2500 SamSs - ok
17:00:06.0238 2500 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:00:06.0238 2500 sbp2port - ok
17:00:06.0269 2500 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:00:06.0269 2500 SCardSvr - ok
17:00:06.0300 2500 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
17:00:06.0300 2500 Schedule - ok
17:00:06.0316 2500 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
17:00:06.0316 2500 SCPolicySvc - ok
17:00:06.0332 2500 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:00:06.0332 2500 SDRSVC - ok
17:00:06.0347 2500 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:00:06.0347 2500 secdrv - ok
17:00:06.0363 2500 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
17:00:06.0363 2500 seclogon - ok
17:00:06.0363 2500 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
17:00:06.0363 2500 SENS - ok
17:00:06.0410 2500 [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:00:06.0410 2500 Serenum - ok
17:00:06.0441 2500 [ 6D663022DB3E7058907784AE14B69898 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:00:06.0441 2500 Serial - ok
17:00:06.0472 2500 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
17:00:06.0472 2500 sermouse - ok
17:00:06.0519 2500 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
17:00:06.0519 2500 SessionEnv - ok
17:00:06.0534 2500 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:00:06.0534 2500 sffdisk - ok
17:00:06.0534 2500 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:00:06.0534 2500 sffp_mmc - ok
17:00:06.0534 2500 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:00:06.0550 2500 sffp_sd - ok
17:00:06.0550 2500 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
17:00:06.0550 2500 sfloppy - ok
17:00:06.0628 2500 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:00:06.0628 2500 SharedAccess - ok
17:00:06.0722 2500 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:00:06.0722 2500 ShellHWDetection - ok
17:00:06.0753 2500 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:00:06.0753 2500 sisagp - ok
17:00:06.0768 2500 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
17:00:06.0768 2500 SiSRaid2 - ok
17:00:06.0784 2500 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
17:00:06.0784 2500 SiSRaid4 - ok
17:00:06.0862 2500 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
17:00:06.0878 2500 slsvc - ok
17:00:06.0878 2500 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
17:00:06.0893 2500 SLUINotify - ok
17:00:06.0909 2500 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:00:06.0909 2500 Smb - ok
17:00:06.0924 2500 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:00:06.0940 2500 SNMPTRAP - ok
17:00:06.0956 2500 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
17:00:06.0956 2500 spldr - ok
17:00:06.0971 2500 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
17:00:06.0987 2500 Spooler - ok
17:00:07.0002 2500 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
17:00:07.0002 2500 SQLBrowser - ok
17:00:07.0018 2500 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
17:00:07.0018 2500 SQLWriter - ok
17:00:07.0049 2500 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:00:07.0049 2500 srv - ok
17:00:07.0065 2500 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:00:07.0065 2500 srv2 - ok
17:00:07.0127 2500 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:00:07.0127 2500 srvnet - ok
17:00:07.0143 2500 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:00:07.0158 2500 SSDPSRV - ok
17:00:07.0158 2500 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:00:07.0174 2500 SstpSvc - ok
17:00:07.0283 2500 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
17:00:07.0283 2500 Stereo Service - ok
17:00:07.0346 2500 [ EF70B3D22B4BFFDA6EA851ECB063EFAA ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
17:00:07.0346 2500 StillCam - ok
17:00:07.0361 2500 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
17:00:07.0377 2500 stisvc - ok
17:00:07.0392 2500 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
17:00:07.0392 2500 swenum - ok
17:00:07.0424 2500 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
17:00:07.0424 2500 swprv - ok
17:00:07.0470 2500 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
17:00:07.0470 2500 Symc8xx - ok
17:00:07.0486 2500 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
17:00:07.0486 2500 Sym_hi - ok
17:00:07.0517 2500 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
17:00:07.0517 2500 Sym_u3 - ok
17:00:07.0548 2500 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
17:00:07.0548 2500 SysMain - ok
17:00:07.0626 2500 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:00:07.0626 2500 TabletInputService - ok
17:00:07.0642 2500 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
17:00:07.0658 2500 TapiSrv - ok
17:00:07.0673 2500 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
17:00:07.0673 2500 TBS - ok
17:00:07.0720 2500 [ D18D53974FD715D50FC76F9FFE1C830D ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:00:07.0720 2500 Tcpip - ok
17:00:07.0736 2500 [ D18D53974FD715D50FC76F9FFE1C830D ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
17:00:07.0736 2500 Tcpip6 - ok
17:00:07.0767 2500 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:00:07.0782 2500 tcpipreg - ok
17:00:07.0814 2500 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:00:07.0814 2500 TDPIPE - ok
17:00:07.0829 2500 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:00:07.0829 2500 TDTCP - ok
17:00:07.0876 2500 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:00:07.0876 2500 tdx - ok
17:00:07.0892 2500 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
17:00:07.0892 2500 TermDD - ok
17:00:07.0923 2500 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
17:00:07.0923 2500 TermService - ok
17:00:07.0938 2500 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
17:00:07.0938 2500 Themes - ok
17:00:07.0954 2500 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
17:00:07.0954 2500 THREADORDER - ok
17:00:07.0985 2500 [ CB258C2F726F1BE73C507022BE33EBB3 ] TPM C:\Windows\system32\drivers\tpm.sys
17:00:07.0985 2500 TPM - ok
17:00:08.0016 2500 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
17:00:08.0016 2500 TrkWks - ok
17:00:08.0048 2500 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:00:08.0048 2500 TrustedInstaller - ok
17:00:08.0079 2500 [ F4EAA7ECBCB25DE901C9B7F2CDCDA0B3 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:00:08.0079 2500 tssecsrv - ok
17:00:08.0110 2500 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
17:00:08.0110 2500 tunmp - ok
17:00:08.0157 2500 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:00:08.0157 2500 tunnel - ok
17:00:08.0188 2500 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
17:00:08.0188 2500 uagp35 - ok
17:00:08.0235 2500 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:00:08.0235 2500 udfs - ok
17:00:08.0250 2500 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:00:08.0250 2500 UI0Detect - ok
17:00:08.0282 2500 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:00:08.0282 2500 uliagpkx - ok
17:00:08.0313 2500 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
17:00:08.0313 2500 uliahci - ok
17:00:08.0328 2500 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
17:00:08.0328 2500 UlSata - ok
17:00:08.0360 2500 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
17:00:08.0360 2500 ulsata2 - ok
17:00:08.0375 2500 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
17:00:08.0375 2500 umbus - ok
17:00:08.0391 2500 [ 8A66360F38F81E960E2367B428CBD5D9 ] UmRdpService C:\Windows\System32\umrdp.dll
17:00:08.0391 2500 UmRdpService - ok
17:00:08.0422 2500 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
17:00:08.0422 2500 upnphost - ok
17:00:08.0438 2500 [ 32DB9517628FF0D070682AAB61E688F0 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
17:00:08.0438 2500 usbaudio - ok
17:00:08.0469 2500 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:00:08.0469 2500 usbccgp - ok
17:00:08.0500 2500 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:00:08.0500 2500 usbcir - ok
17:00:08.0531 2500 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:00:08.0531 2500 usbehci - ok
17:00:08.0547 2500 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:00:08.0547 2500 usbhub - ok
17:00:08.0578 2500 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
17:00:08.0578 2500 usbohci - ok
17:00:08.0625 2500 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:00:08.0625 2500 usbprint - ok
17:00:08.0672 2500 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
17:00:08.0672 2500 usbscan - ok
17:00:08.0703 2500 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:00:08.0703 2500 USBSTOR - ok
17:00:08.0718 2500 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
17:00:08.0718 2500 usbuhci - ok
17:00:08.0734 2500 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
17:00:08.0734 2500 usbvideo - ok
17:00:08.0796 2500 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
17:00:08.0796 2500 UxSms - ok
17:00:08.0828 2500 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
17:00:08.0828 2500 vds - ok
17:00:08.0859 2500 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:00:08.0859 2500 vga - ok
17:00:08.0874 2500 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
17:00:08.0874 2500 VgaSave - ok
17:00:08.0890 2500 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:00:08.0890 2500 viaagp - ok
17:00:08.0906 2500 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
17:00:08.0906 2500 ViaC7 - ok
17:00:08.0937 2500 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
17:00:08.0937 2500 viaide - ok
17:00:08.0952 2500 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:00:08.0952 2500 volmgr - ok
17:00:08.0968 2500 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:00:08.0968 2500 volmgrx - ok

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Dokyxxx » 21 srp 2013 17:07

17:00:09.0046 2500 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:00:09.0046 2500 volsnap - ok
17:00:09.0077 2500 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
17:00:09.0077 2500 vsmraid - ok
17:00:09.0108 2500 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
17:00:09.0124 2500 VSS - ok
17:00:09.0233 2500 [ 654D358F8DC18167F31A01166B4CA9D6 ] vToolbarUpdater15.3.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
17:00:09.0233 2500 vToolbarUpdater15.3.0 - ok
17:00:09.0280 2500 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
17:00:09.0280 2500 W32Time - ok
17:00:09.0296 2500 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
17:00:09.0296 2500 WacomPen - ok
17:00:09.0327 2500 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
17:00:09.0327 2500 Wanarp - ok
17:00:09.0327 2500 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:00:09.0327 2500 Wanarpv6 - ok
17:00:09.0358 2500 [ 20B23332885DFB93FE0185362EE811E9 ] wbengine C:\Windows\system32\wbengine.exe
17:00:09.0374 2500 wbengine - ok
17:00:09.0389 2500 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:00:09.0389 2500 wcncsvc - ok
17:00:09.0405 2500 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:00:09.0420 2500 WcsPlugInService - ok
17:00:09.0436 2500 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
17:00:09.0436 2500 Wd - ok
17:00:09.0483 2500 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:00:09.0498 2500 Wdf01000 - ok
17:00:09.0514 2500 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:00:09.0530 2500 WdiServiceHost - ok
17:00:09.0530 2500 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:00:09.0530 2500 WdiSystemHost - ok
17:00:09.0545 2500 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
17:00:09.0545 2500 WebClient - ok
17:00:09.0623 2500 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:00:09.0623 2500 Wecsvc - ok
17:00:09.0686 2500 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:00:09.0686 2500 wercplsupport - ok
17:00:09.0701 2500 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
17:00:09.0701 2500 WerSvc - ok
17:00:09.0732 2500 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:00:09.0732 2500 WinDefend - ok
17:00:09.0732 2500 WinHttpAutoProxySvc - ok
17:00:09.0779 2500 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:00:09.0779 2500 Winmgmt - ok
17:00:09.0810 2500 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
17:00:09.0826 2500 WinRM - ok
17:00:09.0904 2500 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:00:09.0920 2500 Wlansvc - ok
17:00:09.0935 2500 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
17:00:09.0935 2500 WmiAcpi - ok
17:00:09.0951 2500 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:00:09.0951 2500 wmiApSrv - ok
17:00:09.0998 2500 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:00:10.0013 2500 WMPNetworkSvc - ok
17:00:10.0044 2500 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:00:10.0044 2500 WPDBusEnum - ok
17:00:10.0122 2500 [ B800EEC15851597405784126C407188C ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
17:00:10.0122 2500 WPFFontCache_v0400 - ok
17:00:10.0154 2500 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:00:10.0154 2500 ws2ifsl - ok
17:00:10.0185 2500 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
17:00:10.0185 2500 wscsvc - ok
17:00:10.0185 2500 WSearch - ok
17:00:10.0247 2500 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:00:10.0278 2500 wuauserv - ok
17:00:10.0341 2500 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:00:10.0356 2500 WudfPf - ok
17:00:10.0372 2500 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:00:10.0372 2500 WUDFRd - ok
17:00:10.0388 2500 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:00:10.0403 2500 wudfsvc - ok
17:00:10.0450 2500 ================ Scan global ===============================
17:00:10.0497 2500 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
17:00:10.0544 2500 [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
17:00:10.0559 2500 [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
17:00:10.0575 2500 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
17:00:10.0590 2500 [Global] - ok
17:00:10.0590 2500 ================ Scan MBR ==================================
17:00:10.0590 2500 [ 92A0110A64C3262C5F5DF2032E989DCE ] \Device\Harddisk0\DR0
17:00:10.0778 2500 \Device\Harddisk0\DR0 - ok
17:00:10.0778 2500 ================ Scan VBR ==================================
17:00:10.0793 2500 [ 4348B0676D9527DAC5368AFE0D679CC0 ] \Device\Harddisk0\DR0\Partition1
17:00:10.0793 2500 \Device\Harddisk0\DR0\Partition1 - ok
17:00:10.0809 2500 [ D4781209DAD0F5096D9B6E6CAEC44566 ] \Device\Harddisk0\DR0\Partition2
17:00:10.0809 2500 \Device\Harddisk0\DR0\Partition2 - ok
17:00:10.0809 2500 ============================================================
17:00:10.0809 2500 Scan finished
17:00:10.0809 2500 ============================================================
17:00:10.0824 4132 Detected object count: 0
17:00:10.0824 4132 Actual detected object count: 0
17:00:18.0312 5448 Deinitialize success

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Dokyxxx » 21 srp 2013 17:37

ComboFix 13-08-20.01 - Standard 21.08.2013 17:22:40.2.4 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.420.1029.18.3326.2292 [GMT 2:00]
Spuštěný z: c:\users\Standard\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\update
c:\windows\system32\update\diablo121016.cl
c:\windows\system32\update\diakgcn121016.cl
c:\windows\system32\update\igfxupdate.exe
c:\windows\system32\update\libcurl-4.dll
c:\windows\system32\update\libeay32.dll
c:\windows\system32\update\libidn-11.dll
c:\windows\system32\update\libusb-1.0.dll
c:\windows\system32\update\phatk121016.cl
c:\windows\system32\update\poclbm121016.cl
c:\windows\system32\update\poclbm121016GeForce 210v1w256l4.bin
c:\windows\system32\update\pthreadGC2.dll
c:\windows\system32\update\scrypt121016.cl
c:\windows\system32\update\ssleay32.dll
c:\windows\system32\update\zlib1.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-07-21 do 2013-08-21 )))))))))))))))))))))))))))))))
.
.
2013-08-21 14:14 . 2013-07-02 06:54 7143960 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AC661763-6E51-410C-A670-C7E9C1EF5DEB}\mpengine.dll
2013-08-16 10:57 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2013-08-16 10:57 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-16 10:57 . 2013-07-05 04:53 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-16 10:57 . 2013-07-17 19:41 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-16 10:57 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-16 10:57 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2013-08-16 10:57 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-16 10:57 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-16 10:57 . 2013-07-08 04:16 992768 ----a-w- c:\windows\system32\crypt32.dll
2013-08-16 10:57 . 2013-07-08 04:20 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-08-16 10:57 . 2013-07-08 04:16 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-16 10:57 . 2013-07-08 04:16 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-03 18:22 . 2013-08-03 18:22 5842 ----a-w- c:\windows\system32\PerfStringBackup.TMP
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-07 09:36 . 2013-07-07 09:34 115 ----a-w- c:\windows\DeleteOnReboot.bat
2013-07-06 19:52 . 2013-07-06 19:52 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-06-23 12:14 . 2013-06-23 12:14 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-06-04 01:50 . 2013-07-10 16:58 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-06-03 15:06 . 2012-10-28 05:30 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-03 15:06 . 2011-11-26 13:07 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-01 04:06 . 2013-07-10 16:58 505344 ----a-w- c:\windows\system32\qedit.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 08:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-11-10 09:17 3514176 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2010-08-25 18:45 171032 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-10 20:52 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
2008-04-07 05:10 318488 ----a-w- c:\program files\PDF Complete\pdfsty.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2010-08-25 18:45 170520 ----a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2008-11-14 13:35 305064 ----a-r- c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2012-07-04 01:03 641704 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2012-03-27 11:20 742264 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-626282612-4174701310-2186174446-1003]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
SearchIndexer
SearchIndexer
SearchIndexer
SearchIndexer
SearchIndexer
SearchIndexer
SearchIndexer
SearchIndexer
SearchIndexer
SearchIndexer
SearchIndexer
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-06-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-28 15:06]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\
FF - prefs.js: browser.startup.homepage - www.seznam.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-08-21 17:34
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-626282612-4174701310-2186174446-1003\Software\SecuROM\License information*]
"datasecu"=hex:f7,b3,82,3d,2f,f2,f7,bb,b2,7d,fe,a4,4a,46,7e,5c,ba,31,27,cf,0e,
8d,15,c8,0d,78,e7,44,80,84,a5,22,63,c9,c9,32,6d,b2,43,a1,eb,fd,0e,03,63,99,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
Celkový čas: 2013-08-21 17:36:50
ComboFix-quarantined-files.txt 2013-08-21 15:36
.
Před spuštěním: Volných bajtů: 150 838 779 904
Po spuštění: Volných bajtů: 150 905 806 848
.
- - End Of File - - 004224447861A0C6389673913B0E2B5D
92A0110A64C3262C5F5DF2032E989DCE

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 22 srp 2013 10:22

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
c:\windows\system32\drivers\avgtpx86.sys

Driver::
SearchIndexer
avgtpx86

NetSvcs::
SearchIndexer


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Dokyxxx » 26 srp 2013 17:28

ComboFix 13-08-25.01 - Standard 26.08.2013 17:14:27.2.4 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.420.1029.18.3326.2144 [GMT 2:00]
Spuštěný z: c:\users\Standard\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Standard\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-07-26 do 2013-08-26 )))))))))))))))))))))))))))))))
.
.
2013-08-26 15:20 . 2013-08-26 15:20 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-08-26 15:20 . 2013-08-26 15:20 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-08-26 15:20 . 2013-08-26 15:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-23 15:13 . 2013-08-23 15:13 -------- d-----w- c:\programdata\HPSSUPPLY
2013-08-23 12:07 . 2010-04-05 20:00 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2013-08-23 11:52 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FA53E104-E2FC-44EC-B947-32151C565C21}\mpengine.dll
2013-08-22 15:38 . 2013-08-23 12:24 -------- d-----w- c:\program files\SmartTweak
2013-08-16 10:57 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2013-08-16 10:57 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-16 10:57 . 2013-07-05 03:20 914880 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-16 10:57 . 2013-07-05 01:43 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-08-16 10:57 . 2013-07-17 19:41 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-16 10:57 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-16 10:57 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2013-08-16 10:57 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-16 10:57 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-16 10:57 . 2013-07-08 04:16 992768 ----a-w- c:\windows\system32\crypt32.dll
2013-08-16 10:57 . 2013-07-08 04:20 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-08-16 10:57 . 2013-07-08 04:16 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-16 10:57 . 2013-07-08 04:16 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-03 18:22 . 2013-08-26 14:34 5842 ----a-w- c:\windows\system32\PerfStringBackup.TMP
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-07 09:36 . 2013-07-07 09:34 115 ----a-w- c:\windows\DeleteOnReboot.bat
2013-07-06 19:52 . 2013-07-06 19:52 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-06-23 12:14 . 2013-06-23 12:14 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-06-04 01:50 . 2013-07-10 16:58 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-06-03 15:06 . 2012-10-28 05:30 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-03 15:06 . 2011-11-26 13:07 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-01 04:06 . 2013-07-10 16:58 505344 ----a-w- c:\windows\system32\qedit.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 08:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-11-10 09:17 3514176 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2010-08-25 18:45 171032 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-10 20:52 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
2008-04-07 05:10 318488 ----a-w- c:\program files\PDF Complete\pdfsty.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2010-08-25 18:45 170520 ----a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2008-11-14 13:35 305064 ----a-r- c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2012-07-04 01:03 641704 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2012-03-27 11:20 742264 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-626282612-4174701310-2186174446-1003]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-06-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-28 15:06]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\
FF - prefs.js: browser.startup.homepage - www.seznam.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-UpdateMyDrivers.exe - c:\program files\SmartTweak\UpdateMyDrivers\UpdateMyDrivers.exe
HKCU-Run-UpdateMyDrivers - c:\program files\SmartTweak\UpdateMyDrivers\UpdateMyDrivers.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-08-26 17:22
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-626282612-4174701310-2186174446-1003\Software\SecuROM\License information*]
"datasecu"=hex:f7,b3,82,3d,2f,f2,f7,bb,b2,7d,fe,a4,4a,46,7e,5c,ba,31,27,cf,0e,
8d,15,c8,0d,78,e7,44,80,84,a5,22,63,c9,c9,32,6d,b2,43,a1,eb,fd,0e,03,63,99,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\windows\system32\atiesrxx.exe
c:\windows\system32\atieclxx.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\PDF Complete\pdfsvc.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
c:\windows\System32\WUDFHost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
.
**************************************************************************
.
Celkový čas: 2013-08-26 17:27:57 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-08-26 15:27
ComboFix2.txt 2013-08-21 15:36
.
Před spuštěním: Volných bajtů: 159 635 255 296
Po spuštění: Volných bajtů: 161 864 663 040
.
- - End Of File - - 89736899EE553B4D1703747C9AFB7B71
92A0110A64C3262C5F5DF2032E989DCE

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 26 srp 2013 18:18

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

vyčisti systém CCleanerem

Stáhni si OTC

na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.

+ Nový log z HJT
+ aswMBR

Jak se chová PC?
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Dokyxxx » 26 srp 2013 19:01

aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-08-26 19:00:15
-----------------------------
19:00:15.826 OS Version: Windows 6.0.6002 Service Pack 2
19:00:15.826 Number of processors: 4 586 0x170A
19:00:15.826 ComputerName: STANDARD-PC UserName: Standard
19:00:18.010 Initialize success
19:00:22.027 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:00:22.027 Disk 0 Vendor: Hitachi_ GM4O Size: 476940MB BusType: 3
19:00:22.183 Disk 0 MBR read successfully
19:00:22.198 Disk 0 MBR scan
19:00:22.198 Disk 0 Windows VISTA default MBR code
19:00:22.198 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 474938 MB offset 2048
19:00:22.230 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 2000 MB offset 972675072
19:00:22.230 Disk 0 scanning sectors +976771072
19:00:22.292 Disk 0 scanning C:\Windows\system32\drivers
19:00:29.156 Service scanning
19:00:51.932 Modules scanning
19:01:16.315 Disk 0 trace - called modules:
19:01:16.393 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
19:01:16.408 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8dd68a18]
19:01:16.908 3 CLASSPNP.SYS[923a28b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8cb68028]
19:01:16.908 Scan finished successfully
19:01:29.091 Disk 0 MBR has been saved successfully to "C:\Users\Standard\Desktop\MBR.dat"
19:01:29.091 The log file has been saved successfully to "C:\Users\Standard\Desktop\aswMBR.txt"

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 26 srp 2013 21:06

nový HJT a info o stavu PC
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Dokyxxx » 27 srp 2013 17:33

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:31:41, on 27.8.2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Users\Standard\Downloads\Programy\HiJackThis.exe
C:\Windows\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Broadcom Management Agent (BrcmMgmtAgent) - Broadcom Corporation - C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: vToolbarUpdater15.3.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe

--
End of file - 4645 bytes


a jinak pc nabíhá rychleji,a práce v prohlížeči také..takže pokud v logu nic nenajdete je to vše ok :)


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 56 hostů