Kontrola HJT - nákaza v MBAM Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Kontrola HJT - nákaza v MBAM

Příspěvekod CZechBoY » 02 zář 2013 10:14

Zdravím,
inspirován pár tématy předemnou, taky jsem si rozjel rychlý sken s tušením, že něco možná nebude v pořádku.
Už asi před 2 týdny jsem zase někde vzal ten vir bitcoin generator, řekl bych, že je zavirovaný fraps na uložto :(

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:14:37, on 2. 9. 2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Program Files (x86)\FeedDemon\FeedDemon.exe
D:\Program Files (x86)\QIP Infium\infium.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\czech_000\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
D:\Program Files (x86)\Opera\16.0.1196.62\opera.exe
D:\Program Files (x86)\Opera\16.0.1196.62\opera_crashreporter.exe
D:\Program Files (x86)\Opera\16.0.1196.62\opera.exe
D:\Program Files (x86)\Opera\16.0.1196.62\opera.exe
D:\Program Files (x86)\Opera\16.0.1196.62\opera.exe
D:\Program Files (x86)\Opera\16.0.1196.62\opera.exe
D:\Program Files (x86)\Opera\16.0.1196.62\opera.exe
D:\Program Files (x86)\Opera\16.0.1196.62\opera.exe
D:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: DebugBar BHO - {69FC0024-10EB-480A-BBF2-3BF4E78E17B1} - D:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: DebugBar (Toolbar) - {3E1201F4-1707-409F-BB45-A5F192381DA0} - D:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O8 - Extra context menu item: Inspect Element with DebugBar - res://D:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.dll/247
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.co ... 5.15.0.cab
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll
O23 - Service: Acunetix WVS Scheduler v8 (AcuWVSSchedulerv8) - Unknown owner - D:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - D:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel® Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - D:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Unknown owner - C:\Windows\system32\sfrem01.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto Launcher Service (SolutoLauncherService) - Soluto - D:\Program Files\Soluto\SolutoLauncherService.exe
O23 - Service: Soluto Remote Service (SolutoRemoteService) - GlavSoft LLC. - D:\Program Files\Soluto\SolutoRemoteService.exe
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - D:\Program Files\Soluto\SolutoService.exe
O23 - Service: Glasovne poruke (Speechsrv) - Unknown owner - D:\Program Files (x86)\LAN Voice Chat\Speechs.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Aktivátor Správce výběru OS Acronis (Správce výběru OS) - Unknown owner - D:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - D:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - D:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - D:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 10316 bytes




MBAM:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.09.02.01

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16660
czech_000 :: NTB [administrátor]

2. 9. 2013 10:07:55
MBAM-log-2013-09-02 (10-12-02).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 245065
Uplynulý čas: 3 minut, 53 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 2
C:\Windows\Inf\ntvdm.vbe (Malware.Trace) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\ntvdm.inf (Malware.Trace) -> Nebyla provedena žádná instrukce.

(konec)
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod jaro3 » 02 zář 2013 18:57

Oba soubory dej na virustotal.

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: DebugBar (Toolbar) - {3E1201F4-1707-409F-BB45-A5F192381DA0} - D:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.dll
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin


Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod CZechBoY » 02 zář 2013 20:32

ATF cleaner je nějakej nepoužitelnej, ačkoliv mám všechny běžné prohlížeče instalované tak jsou záložky Firefox a Chrome zašedlé :(

Adw:
# AdwCleaner v3.002 - Report created 02/09/2013 at 20:23:17
# Updated 01/09/2013 by Xplode
# Operating System : Windows 8 Pro (64 bits)
# Username : czech_000 - NTB
# Running from : D:\download\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found : C:\Users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\Extensions\{79b8e308-95a2-4044-932d-80e833a863cc}
Folder Found C:\Program Files (x86)\Conduit
Folder Found C:\Users\czech_000\AppData\Local\Conduit
Folder Found C:\Users\czech_000\AppData\Local\cre
Folder Found C:\Users\czech_000\AppData\LocalLow\Conduit
Folder Found C:\Users\czech_000\AppData\Roaming\DriverCure
Folder Found C:\Users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\CT3282722
Folder Found C:\Users\czech_000\AppData\Roaming\ParetoLogic

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\Software\Conduit

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16537


-\\ Mozilla Firefox v23.0.1 (cs)

[ File : C:\Users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\prefs.js ]

Line Found : user_pref("CT3282722.FF19Solved", "true");
Line Found : user_pref("CT3282722.UserID", "UN17474402554071154");
Line Found : user_pref("CT3282722.addressUrlXPETakeover", "true");
Line Found : user_pref("CT3282722.autoDisableScopes", -1);
Line Found : user_pref("CT3282722.fullUserID", "UN17474402554071154.IN.20130827034044");
Line Found : user_pref("CT3282722.installDate", "27/08/2013 03:40:44");
Line Found : user_pref("CT3282722.installSessionId", "-1");
Line Found : user_pref("CT3282722.installSp", "TRUE");
Line Found : user_pref("CT3282722.installerVersion", "1.5.4.5");
Line Found : user_pref("CT3282722.keyword", "true");
Line Found : user_pref("CT3282722.originalSearchAddressUrl", "");
Line Found : user_pref("CT3282722.searchRevert", "FALSE");
Line Found : user_pref("CT3282722.searchUserMode", "3");
Line Found : user_pref("CT3282722.versionFromInstaller", "10.16.9.6");
Line Found : user_pref("CT3282722.xpeMode", "3");
Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Line Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3282722&SearchSource=2&CUI=UN17474402554071154&UM=3&q=");
Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT3282722");
Line Found : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3282722&SearchSource=2&CUI=UN17474402554071154&UM=3&q=");
Line Found : user_pref("smartbar.machineId", "0QADMJTCUI2KO6KH7RHOAWULGOKDMJKWBMQT+PEBLX63Y8QPKZXS2N1QL7D4FPOXEVTWJ2UJPV64N7ZUW2OSGG");

-\\ Google Chrome v29.0.1547.62

[ File : C:\Users\czech_000\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [3200 octets] - [02/09/2013 20:23:17]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3260 octets] ##########




Rogue:
RogueKiller V8.6.8 _x64_ [Sep 2 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : czech_000 [Práva správce]
Mód : Kontrola -- Datum : 09/02/2013 20:29:39
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> NALEZENO
[HJ DESK] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
[HID SVC][Skrytý od API] HKLM\[...]\CCSet\[...]\Services : S () -> NALEZENO
[HID SVC][Skrytý od API] HKLM\[...]\CS001\[...]\Services : S () -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] af2d5d26254f379ef01a9d18b0ba1e96
[BSP] e5564d3a591cf8403f708aa9e7a52e9a : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 350 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 718848 | Size: 150775 Mo
2 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 309506048 | Size: 1500 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 312578048 | Size: 801242 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_09022013_202939.txt >>




koukám, že avast je jediný co pozná bitcion miner :D
https://www.virustotal.com/cs/file/9dd2 ... 378146663/
https://www.virustotal.com/cs/file/8e45 ... 378146698/
utoho druhého jsem musel dát rescan, minulý výsledek 10/46
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod jaro3 » 03 zář 2013 10:11

tak to smaž..oboje.

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.

Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "

- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje "Smazání skončeno "
- Klikni na "Zprávy " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod CZechBoY » 03 zář 2013 13:35

no status box ukazuje "Mazání dokončeno" a tlačítko se jmenuje "Zpráva" ;)
RogueKiller V8.6.9 _x64_ [Sep 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : czech_000 [Práva správce]
Mód : Odebrat -- Datum : 09/03/2013 13:33:05
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> NAHRAZENO (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[HID SVC][Skrytý od API] HKLM\[...]\CCSet\[...]\Services : S () -> [0x3] Systém nemůže nalézt uvedenou cestu.
[HID SVC][Skrytý od API] HKLM\[...]\CS001\[...]\Services : S () -> [0x3] Systém nemůže nalézt uvedenou cestu.

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] af2d5d26254f379ef01a9d18b0ba1e96
[BSP] e5564d3a591cf8403f708aa9e7a52e9a : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 350 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 718848 | Size: 150775 Mo
2 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 309506048 | Size: 1500 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 312578048 | Size: 801242 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_09032013_133305.txt >>
RKreport[0]_S_09022013_202939.txt;RKreport[0]_S_09032013_133253.txt




13:35:20.0487 1104 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
13:35:20.0700 1104 ============================================================
13:35:20.0700 1104 Current date / time: 2013/09/03 13:35:20.0700
13:35:20.0700 1104 SystemInfo:
13:35:20.0700 1104
13:35:20.0700 1104 OS Version: 6.2.9200 ServicePack: 0.0
13:35:20.0700 1104 Product type: Workstation
13:35:20.0700 1104 ComputerName: NTB
13:35:20.0700 1104 UserName: czech_000
13:35:20.0700 1104 Windows directory: C:\Windows
13:35:20.0700 1104 System windows directory: C:\Windows
13:35:20.0700 1104 Running under WOW64
13:35:20.0700 1104 Processor architecture: Intel x64
13:35:20.0700 1104 Number of processors: 4
13:35:20.0700 1104 Page size: 0x1000
13:35:20.0700 1104 Boot type: Normal boot
13:35:20.0700 1104 ============================================================
13:35:20.0971 1104 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:35:20.0974 1104 ============================================================
13:35:20.0974 1104 \Device\Harddisk0\DR0:
13:35:20.0974 1104 MBR partitions:
13:35:20.0974 1104 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAF000
13:35:20.0974 1104 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xAF800, BlocksNum 0x1267B800
13:35:20.0974 1104 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x12A19000, BlocksNum 0x61CED000
13:35:20.0974 1104 ============================================================
13:35:20.0992 1104 C: <-> \Device\Harddisk0\DR0\Partition2
13:35:21.0034 1104 D: <-> \Device\Harddisk0\DR0\Partition3
13:35:21.0034 1104 ============================================================
13:35:21.0034 1104 Initialize success
13:35:21.0034 1104 ============================================================
13:35:37.0404 5080 ============================================================
13:35:37.0404 5080 Scan started
13:35:37.0404 5080 Mode: Manual;
13:35:37.0404 5080 ============================================================
13:35:37.0751 5080 ================ Scan system memory ========================
13:35:37.0751 5080 System memory - ok
13:35:37.0751 5080 ================ Scan services =============================
13:35:37.0941 5080 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
13:35:37.0943 5080 1394ohci - ok
13:35:37.0972 5080 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys
13:35:37.0972 5080 3ware - ok
13:35:37.0999 5080 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys
13:35:38.0002 5080 ACPI - ok
13:35:38.0028 5080 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys
13:35:38.0029 5080 acpiex - ok
13:35:38.0052 5080 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
13:35:38.0053 5080 acpipagr - ok
13:35:38.0084 5080 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
13:35:38.0085 5080 AcpiPmi - ok
13:35:38.0112 5080 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys
13:35:38.0112 5080 acpitime - ok
13:35:38.0145 5080 [ 3B42D95D20CD2AACDB0564471AE43ED7 ] ACPIVPC C:\Windows\System32\drivers\AcpiVpc.sys
13:35:38.0146 5080 ACPIVPC - ok
13:35:38.0254 5080 [ 00268E392FDAB9D494CA6D4B979E94BB ] AcuWVSSchedulerv8 D:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe
13:35:38.0264 5080 AcuWVSSchedulerv8 - ok
13:35:38.0335 5080 [ 476BB014F3F68C0C15EDDD5B444DA8FF ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:35:38.0337 5080 AdobeFlashPlayerUpdateSvc - ok
13:35:38.0390 5080 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:35:38.0393 5080 adp94xx - ok
13:35:38.0422 5080 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:35:38.0424 5080 adpahci - ok
13:35:38.0457 5080 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:35:38.0458 5080 adpu320 - ok
13:35:38.0494 5080 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:35:38.0497 5080 AeLookupSvc - ok
13:35:38.0539 5080 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD C:\Windows\system32\drivers\afd.sys
13:35:38.0543 5080 AFD - ok
13:35:38.0562 5080 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:35:38.0563 5080 agp440 - ok
13:35:38.0604 5080 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe
13:35:38.0606 5080 ALG - ok
13:35:38.0649 5080 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
13:35:38.0650 5080 AllUserInstallAgent - ok
13:35:38.0693 5080 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
13:35:38.0694 5080 AmdK8 - ok
13:35:38.0699 5080 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
13:35:38.0700 5080 AmdPPM - ok
13:35:38.0705 5080 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys
13:35:38.0706 5080 amdsata - ok
13:35:38.0735 5080 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
13:35:38.0737 5080 amdsbs - ok
13:35:38.0750 5080 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys
13:35:38.0751 5080 amdxata - ok
13:35:38.0783 5080 [ E71711D37C48AC40FD3E2866A5ABBA51 ] anvsnddrv C:\Windows\system32\drivers\anvsnddrv.sys
13:35:38.0784 5080 anvsnddrv - ok
13:35:38.0789 5080 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys
13:35:38.0789 5080 AppID - ok
13:35:38.0802 5080 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll
13:35:38.0802 5080 AppIDSvc - ok
13:35:38.0833 5080 [ 4F750B7EFCB6520AE01E01D082D7D476 ] Appinfo C:\Windows\System32\appinfo.dll
13:35:38.0834 5080 Appinfo - ok
13:35:38.0855 5080 [ 2D14788C5D0836292BEB27BBE109BE56 ] AppMgmt C:\Windows\System32\appmgmts.dll
13:35:38.0858 5080 AppMgmt - ok
13:35:38.0869 5080 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys
13:35:38.0870 5080 arc - ok
13:35:38.0882 5080 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:35:38.0883 5080 arcsas - ok
13:35:38.0980 5080 [ 108FB6DDB69E537A2EA53F425363FAE5 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
13:35:38.0981 5080 aspnet_state - ok
13:35:38.0985 5080 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:35:38.0986 5080 AsyncMac - ok
13:35:38.0991 5080 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys
13:35:38.0992 5080 atapi - ok
13:35:39.0023 5080 [ BCD7A47EF587DC00DD61D12D9C2D1E44 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
13:35:39.0026 5080 AudioEndpointBuilder - ok
13:35:39.0063 5080 [ 599B3F685A263A114FFAF3BE29C49C75 ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:35:39.0071 5080 Audiosrv - ok
13:35:39.0104 5080 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll
13:35:39.0105 5080 AxInstSV - ok
13:35:39.0135 5080 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
13:35:39.0138 5080 b06bdrv - ok
13:35:39.0156 5080 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
13:35:39.0156 5080 BasicDisplay - ok
13:35:39.0168 5080 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
13:35:39.0168 5080 BasicRender - ok
13:35:39.0198 5080 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll
13:35:39.0201 5080 BDESVC - ok
13:35:39.0212 5080 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys
13:35:39.0212 5080 Beep - ok
13:35:39.0252 5080 [ 9E6A544F465C582AB42444A217CF04DC ] BFE C:\Windows\System32\bfe.dll
13:35:39.0259 5080 BFE - ok
13:35:39.0303 5080 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll
13:35:39.0312 5080 BITS - ok
13:35:39.0448 5080 [ 13C358D27CBFAF537FA7CA48B9052CF3 ] Bluetooth Device Monitor C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
13:35:39.0454 5080 Bluetooth Device Monitor - ok
13:35:39.0482 5080 [ 7525C93645FDA8E9D8F677FEA833798A ] Bluetooth OBEX Service C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
13:35:39.0489 5080 Bluetooth OBEX Service - ok
13:35:39.0517 5080 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:35:39.0518 5080 bowser - ok
13:35:39.0547 5080 [ 038FA1B55531E7020DB705B42FCCE373 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
13:35:39.0550 5080 BrokerInfrastructure - ok
13:35:39.0586 5080 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll
13:35:39.0588 5080 Browser - ok
13:35:39.0619 5080 [ 6695200F455E251F0BCC9CE4D0978D59 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
13:35:39.0619 5080 BthAvrcpTg - ok
13:35:39.0646 5080 [ A8B20D852B07AE19A13B5D47EC4E4C3B ] BthEnum C:\Windows\System32\drivers\BthEnum.sys
13:35:39.0647 5080 BthEnum - ok
13:35:39.0661 5080 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
13:35:39.0662 5080 BthHFEnum - ok
13:35:39.0688 5080 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
13:35:39.0689 5080 bthhfhid - ok
13:35:39.0695 5080 [ 42201C346F0B8C458E1E9CDE04D68A2C ] BthLEEnum C:\Windows\system32\DRIVERS\BthLEEnum.sys
13:35:39.0696 5080 BthLEEnum - ok
13:35:39.0715 5080 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
13:35:39.0715 5080 BTHMODEM - ok
13:35:39.0736 5080 [ 091BB978E9504D0AD14586929431A957 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
13:35:39.0737 5080 BthPan - ok
13:35:39.0768 5080 [ 13795CAA34239D97A7211E7F9D96E012 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
13:35:39.0775 5080 BTHPORT - ok
13:35:39.0789 5080 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll
13:35:39.0790 5080 bthserv - ok
13:35:39.0807 5080 [ 1F715957F5236D30B6020A19A4271F6A ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
13:35:39.0808 5080 BTHUSB - ok
13:35:39.0823 5080 [ 7235891AF09D13C4214DEEE57ED331D0 ] btmaux C:\Windows\system32\DRIVERS\btmaux.sys
13:35:39.0824 5080 btmaux - ok
13:35:39.0858 5080 [ 76D0DDD58A773CA1BFB4D30AAE03517A ] btmhsf C:\Windows\system32\DRIVERS\btmhsf.sys
13:35:39.0862 5080 btmhsf - ok
13:35:39.0875 5080 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:35:39.0876 5080 cdfs - ok
13:35:39.0896 5080 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys
13:35:39.0897 5080 cdrom - ok
13:35:39.0929 5080 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll
13:35:39.0931 5080 CertPropSvc - ok
13:35:39.0945 5080 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys
13:35:39.0945 5080 circlass - ok
13:35:39.0982 5080 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys
13:35:39.0985 5080 CLFS - ok
13:35:40.0009 5080 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
13:35:40.0010 5080 CmBatt - ok
13:35:40.0041 5080 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys
13:35:40.0044 5080 CNG - ok
13:35:40.0063 5080 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
13:35:40.0064 5080 CompositeBus - ok
13:35:40.0068 5080 COMSysApp - ok
13:35:40.0073 5080 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys
13:35:40.0073 5080 condrv - ok
13:35:40.0140 5080 [ 06B278D3D74D3AD7FA8E8D8D6300F574 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
13:35:40.0144 5080 cphs - ok
13:35:40.0158 5080 cpuz136 - ok
13:35:40.0187 5080 [ 5CE2742F063731EC10C1B2EE386A2C08 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:35:40.0189 5080 CryptSvc - ok
13:35:40.0227 5080 [ F2C69C3D98249DE14D4B2832516D4FD5 ] CSC C:\Windows\system32\drivers\csc.sys
13:35:40.0231 5080 CSC - ok
13:35:40.0282 5080 [ 22CCB6AFF617AAC6121DF6CDA5ABF3F4 ] CscService C:\Windows\System32\cscsvc.dll
13:35:40.0290 5080 CscService - ok
13:35:40.0317 5080 [ C4D01BD86D6B207275FC143EEA951D75 ] dam C:\Windows\system32\drivers\dam.sys
13:35:40.0318 5080 dam - ok
13:35:40.0362 5080 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll
13:35:40.0371 5080 DcomLaunch - ok
13:35:40.0386 5080 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\Windows\System32\defragsvc.dll
13:35:40.0390 5080 defragsvc - ok
13:35:40.0403 5080 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
13:35:40.0407 5080 DeviceAssociationService - ok
13:35:40.0440 5080 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
13:35:40.0442 5080 DeviceInstall - ok
13:35:40.0476 5080 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
13:35:40.0477 5080 Dfsc - ok
13:35:40.0502 5080 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll
13:35:40.0506 5080 Dhcp - ok
13:35:40.0519 5080 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys
13:35:40.0520 5080 discache - ok
13:35:40.0536 5080 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\Windows\system32\drivers\disk.sys
13:35:40.0537 5080 disk - ok
13:35:40.0553 5080 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
13:35:40.0553 5080 dmvsc - ok
13:35:40.0579 5080 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:35:40.0582 5080 Dnscache - ok
13:35:40.0621 5080 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll
13:35:40.0624 5080 dot3svc - ok
13:35:40.0636 5080 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll
13:35:40.0638 5080 DPS - ok
13:35:40.0676 5080 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:35:40.0676 5080 drmkaud - ok
13:35:40.0714 5080 [ F87F4AAAF6664906248D11D5E579A53B ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
13:35:40.0717 5080 DsmSvc - ok
13:35:40.0775 5080 [ 6D1B8A9A2C0BD4851D8AF1AB43E67AD9 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:35:40.0784 5080 DXGKrnl - ok
13:35:40.0797 5080 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll
13:35:40.0798 5080 Eaphost - ok
13:35:40.0869 5080 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys
13:35:40.0887 5080 ebdrv - ok
13:35:40.0910 5080 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe
13:35:40.0911 5080 EFS - ok
13:35:40.0939 5080 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
13:35:40.0940 5080 EhStorClass - ok
13:35:40.0953 5080 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
13:35:40.0954 5080 EhStorTcgDrv - ok
13:35:40.0967 5080 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys
13:35:40.0968 5080 ErrDev - ok
13:35:41.0026 5080 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll
13:35:41.0029 5080 EventSystem - ok
13:35:41.0127 5080 [ 91CD2315EB4F0547E0A6573A9AF5B576 ] EvtEng D:\Program Files\Intel\WiFi\bin\EvtEng.exe
13:35:41.0133 5080 EvtEng - ok
13:35:41.0156 5080 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys
13:35:41.0158 5080 exfat - ok
13:35:41.0180 5080 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:35:41.0181 5080 fastfat - ok
13:35:41.0213 5080 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe
13:35:41.0221 5080 Fax - ok
13:35:41.0235 5080 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys
13:35:41.0235 5080 fdc - ok
13:35:41.0246 5080 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll
13:35:41.0247 5080 fdPHost - ok
13:35:41.0264 5080 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll
13:35:41.0265 5080 FDResPub - ok
13:35:41.0299 5080 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll
13:35:41.0301 5080 fhsvc - ok
13:35:41.0320 5080 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:35:41.0321 5080 FileInfo - ok
13:35:41.0331 5080 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:35:41.0332 5080 Filetrace - ok
13:35:41.0336 5080 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
13:35:41.0336 5080 flpydisk - ok
13:35:41.0361 5080 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:35:41.0363 5080 FltMgr - ok
13:35:41.0393 5080 [ B8AFE7A30D34C0E9FDBA81632294547C ] fltsrv C:\Windows\system32\DRIVERS\fltsrv.sys
13:35:41.0394 5080 fltsrv - ok
13:35:41.0442 5080 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll
13:35:41.0455 5080 FontCache - ok
13:35:41.0562 5080 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:35:41.0563 5080 FontCache3.0.0.0 - ok
13:35:41.0579 5080 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
13:35:41.0580 5080 FsDepends - ok
13:35:41.0599 5080 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:35:41.0600 5080 Fs_Rec - ok
13:35:41.0754 5080 [ 895BA1CFF25E867CE5A52073E905C93B ] fussvc C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe
13:35:41.0756 5080 fussvc - ok
13:35:41.0802 5080 [ B99C240DEA85007044E178C1C9C75659 ] Futuremark SystemInfo Service C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
13:35:41.0804 5080 Futuremark SystemInfo Service - ok
13:35:41.0832 5080 [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
13:35:41.0834 5080 fvevol - ok
13:35:41.0860 5080 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
13:35:41.0861 5080 FxPPM - ok
13:35:41.0876 5080 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:35:41.0877 5080 gagp30kx - ok
13:35:41.0907 5080 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
13:35:41.0907 5080 gencounter - ok
13:35:41.0921 5080 [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
13:35:41.0922 5080 GPIOClx0101 - ok
13:35:41.0975 5080 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll
13:35:41.0989 5080 gpsvc - ok
13:35:42.0059 5080 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:35:42.0060 5080 gupdate - ok
13:35:42.0064 5080 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:35:42.0065 5080 gupdatem - ok
13:35:42.0098 5080 [ C2504AA983B5D411F7D31402E8B57725 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:35:42.0100 5080 HdAudAddService - ok
13:35:42.0115 5080 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
13:35:42.0115 5080 HDAudBus - ok
13:35:42.0133 5080 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
13:35:42.0133 5080 HidBatt - ok
13:35:42.0166 5080 [ 085F150D002B7F0153D3C06DDF33A143 ] HidBth C:\Windows\System32\drivers\hidbth.sys
13:35:42.0166 5080 HidBth - ok
13:35:42.0193 5080 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
13:35:42.0193 5080 hidi2c - ok
13:35:42.0198 5080 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys
13:35:42.0198 5080 HidIr - ok
13:35:42.0218 5080 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\system32\hidserv.dll
13:35:42.0219 5080 hidserv - ok
13:35:42.0247 5080 [ 9E11EE0F2E117B2D5A835B2B91752827 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
13:35:42.0247 5080 HidUsb - ok
13:35:42.0272 5080 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:35:42.0274 5080 hkmsvc - ok
13:35:42.0307 5080 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:35:42.0312 5080 HomeGroupListener - ok
13:35:42.0337 5080 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:35:42.0341 5080 HomeGroupProvider - ok
13:35:42.0367 5080 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
13:35:42.0368 5080 HpSAMD - ok
13:35:42.0421 5080 [ F4A91D985EB9D1D2717D538F3424603C ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:35:42.0426 5080 HTTP - ok
13:35:42.0446 5080 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
13:35:42.0447 5080 hwpolicy - ok
13:35:42.0463 5080 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
13:35:42.0463 5080 hyperkbd - ok
13:35:42.0483 5080 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
13:35:42.0484 5080 HyperVideo - ok
13:35:42.0500 5080 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
13:35:42.0501 5080 i8042prt - ok
13:35:42.0549 5080 [ 0FE66A51D81A25AACEAAE4C26308121D ] iaStorA C:\Windows\system32\drivers\iaStorA.sys
13:35:42.0552 5080 iaStorA - ok
13:35:42.0594 5080 [ 584068E03829BC5C63F54B05E6244E97 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
13:35:42.0595 5080 IAStorDataMgrSvc - ok
13:35:42.0631 5080 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
13:35:42.0634 5080 iaStorV - ok
13:35:42.0663 5080 [ C430482AC892D52CED021EDDD4D368A2 ] ibtfltcoex C:\Windows\system32\DRIVERS\iBtFltCoex.sys
13:35:42.0664 5080 ibtfltcoex - ok
13:35:42.0686 5080 [ 83FF82FE209E7997067B375DAD6CF23D ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
13:35:42.0688 5080 ICCS - ok
13:35:42.0813 5080 [ 348214F96642FD4FEF630DE021BA3540 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
13:35:42.0843 5080 igfx - ok
13:35:42.0868 5080 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:35:42.0868 5080 iirsp - ok
13:35:42.0905 5080 [ 531B5A98145DA689741A0AC18F14EA94 ] IKEEXT C:\Windows\System32\ikeext.dll
13:35:42.0917 5080 IKEEXT - ok
13:35:42.0944 5080 [ F5495B38BFB9149925F54F65AB40EFBF ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
13:35:42.0946 5080 IntcDAud - ok
13:35:42.0971 5080 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys
13:35:42.0972 5080 intelide - ok
13:35:42.0998 5080 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys
13:35:42.0999 5080 intelppm - ok
13:35:43.0015 5080 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:35:43.0016 5080 IpFilterDriver - ok
13:35:43.0062 5080 [ C217B8D2E58C57A319B16125C3D4B69C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:35:43.0072 5080 iphlpsvc - ok
13:35:43.0086 5080 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
13:35:43.0087 5080 IPMIDRV - ok
13:35:43.0103 5080 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
13:35:43.0104 5080 IPNAT - ok
13:35:43.0119 5080 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:35:43.0120 5080 IRENUM - ok
13:35:43.0140 5080 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:35:43.0140 5080 isapnp - ok
13:35:43.0155 5080 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
13:35:43.0156 5080 iScsiPrt - ok
13:35:43.0168 5080 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
13:35:43.0169 5080 kbdclass - ok
13:35:43.0190 5080 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
13:35:43.0190 5080 kbdhid - ok
13:35:43.0207 5080 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
13:35:43.0207 5080 kdnic - ok
13:35:43.0229 5080 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe
13:35:43.0231 5080 KeyIso - ok
13:35:43.0271 5080 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:35:43.0272 5080 KSecDD - ok
13:35:43.0304 5080 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
13:35:43.0306 5080 KSecPkg - ok
13:35:43.0324 5080 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
13:35:43.0325 5080 ksthunk - ok
13:35:43.0355 5080 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:35:43.0362 5080 KtmRm - ok
13:35:43.0401 5080 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\system32\srvsvc.dll
13:35:43.0407 5080 LanmanServer - ok
13:35:43.0440 5080 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:35:43.0446 5080 LanmanWorkstation - ok
13:35:43.0478 5080 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\Windows\system32\DRIVERS\LhdX64.sys
13:35:43.0479 5080 LHDmgr - ok
13:35:43.0502 5080 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:35:43.0502 5080 lltdio - ok
13:35:43.0534 5080 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:35:43.0538 5080 lltdsvc - ok
13:35:43.0554 5080 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:35:43.0555 5080 lmhosts - ok
13:35:43.0576 5080 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:35:43.0577 5080 LSI_SAS - ok
13:35:43.0599 5080 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
13:35:43.0600 5080 LSI_SAS2 - ok
13:35:43.0627 5080 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:35:43.0628 5080 LSI_SCSI - ok
13:35:43.0653 5080 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
13:35:43.0654 5080 LSI_SSS - ok
13:35:43.0700 5080 [ A57BA284F5996FFD32DCDBC41A4657DB ] LSM C:\Windows\System32\lsm.dll
13:35:43.0705 5080 LSM - ok
13:35:43.0754 5080 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys
13:35:43.0755 5080 luafv - ok
13:35:43.0781 5080 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys
13:35:43.0781 5080 megasas - ok
13:35:43.0810 5080 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
13:35:43.0812 5080 MegaSR - ok
13:35:43.0849 5080 [ 2BB3EAE2EA641515D4B205CAB29E1624 ] MEIx64 C:\Windows\System32\drivers\HECIx64.sys
13:35:43.0850 5080 MEIx64 - ok
13:35:43.0888 5080 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
13:35:43.0890 5080 MMCSS - ok
13:35:43.0914 5080 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
13:35:43.0914 5080 Modem - ok
13:35:43.0938 5080 [ EA8EAD3F5B762F889CC7F3966625B48B ] monitor C:\Windows\System32\drivers\monitor.sys
13:35:43.0939 5080 monitor - ok
13:35:43.0958 5080 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
13:35:43.0959 5080 mouclass - ok
13:35:43.0980 5080 [ C0ADEBED913295803B579ED288936CBB ] mouhid C:\Windows\System32\drivers\mouhid.sys
13:35:43.0981 5080 mouhid - ok
13:35:44.0002 5080 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
13:35:44.0003 5080 mountmgr - ok
13:35:44.0052 5080 [ 528A5C2570F468155A1B3CF0A2FF5EBD ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
13:35:44.0054 5080 MozillaMaintenance - ok
13:35:44.0090 5080 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:35:44.0091 5080 mpsdrv - ok
13:35:44.0153 5080 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll
13:35:44.0163 5080 MpsSvc - ok
13:35:44.0180 5080 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:35:44.0182 5080 MRxDAV - ok
13:35:44.0237 5080 [ 93179D48066918323628CB016D8C94DC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:35:44.0239 5080 mrxsmb - ok
13:35:44.0267 5080 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:35:44.0269 5080 mrxsmb10 - ok
13:35:44.0281 5080 [ 5C7DD2E5759FFCCD2C7341C1B90F2B26 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:35:44.0283 5080 mrxsmb20 - ok
13:35:44.0313 5080 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
13:35:44.0314 5080 MsBridge - ok
13:35:44.0332 5080 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe
13:35:44.0335 5080 MSDTC - ok
13:35:44.0351 5080 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:35:44.0352 5080 Msfs - ok
13:35:44.0386 5080 [ C32A7A39B960A42BA9D4FBE47213CA03 ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
13:35:44.0386 5080 msgpiowin32 - ok
13:35:44.0399 5080 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
13:35:44.0400 5080 mshidkmdf - ok
13:35:44.0412 5080 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
13:35:44.0412 5080 mshidumdf - ok
13:35:44.0429 5080 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:35:44.0430 5080 msisadrv - ok
13:35:44.0458 5080 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:35:44.0461 5080 MSiSCSI - ok
13:35:44.0464 5080 msiserver - ok
13:35:44.0483 5080 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:35:44.0483 5080 MSKSSRV - ok
13:35:44.0494 5080 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
13:35:44.0494 5080 MsLldp - ok
13:35:44.0504 5080 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:35:44.0505 5080 MSPCLOCK - ok
13:35:44.0515 5080 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:35:44.0515 5080 MSPQM - ok
13:35:44.0541 5080 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:35:44.0543 5080 MsRPC - ok
13:35:44.0567 5080 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
13:35:44.0567 5080 mssmbios - ok
13:35:44.0571 5080 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:35:44.0571 5080 MSTEE - ok
13:35:44.0584 5080 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
13:35:44.0584 5080 MTConfig - ok
13:35:44.0605 5080 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
13:35:44.0605 5080 Mup - ok
13:35:44.0626 5080 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
13:35:44.0627 5080 mvumis - ok
13:35:44.0667 5080 [ 85B42715B134BF8ABE035078F81E0A8C ] MyWiFiDHCPDNS D:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
13:35:44.0670 5080 MyWiFiDHCPDNS - ok
13:35:44.0705 5080 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
13:35:44.0711 5080 napagent - ok
13:35:44.0735 5080 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:35:44.0738 5080 NativeWifiP - ok
13:35:44.0770 5080 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
13:35:44.0773 5080 NcaSvc - ok
13:35:44.0789 5080 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
13:35:44.0791 5080 NcdAutoSetup - ok
13:35:44.0826 5080 [ A10E176F3B2BF83EDE7B5C4658C93B66 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:35:44.0832 5080 NDIS - ok
13:35:44.0853 5080 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
13:35:44.0854 5080 NdisCap - ok
13:35:44.0871 5080 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
13:35:44.0872 5080 NdisImPlatform - ok
13:35:44.0898 5080 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:35:44.0899 5080 NdisTapi - ok
13:35:44.0955 5080 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:35:44.0955 5080 Ndisuio - ok
13:35:44.0978 5080 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:35:44.0979 5080 NdisWan - ok
13:35:44.0984 5080 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
13:35:44.0985 5080 NDISWANLEGACY - ok
13:35:45.0012 5080 [ 3730942D7DB2F8BB5F84542B7FF6F650 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:35:45.0013 5080 NDProxy - ok
13:35:45.0033 5080 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
13:35:45.0034 5080 Ndu - ok
13:35:45.0056 5080 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:35:45.0056 5080 NetBIOS - ok
13:35:45.0079 5080 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
13:35:45.0082 5080 NetBT - ok
13:35:45.0093 5080 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
13:35:45.0094 5080 Netlogon - ok
13:35:45.0128 5080 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
13:35:45.0132 5080 Netman - ok
13:35:45.0169 5080 [ 79FA9393C67EBBF92A56923592CF7A7C ] netprofm C:\Windows\System32\netprofmsvc.dll
13:35:45.0175 5080 netprofm - ok
13:35:45.0223 5080 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:35:45.0241 5080 NetTcpPortSharing - ok
13:35:45.0325 5080 [ E506547A38381E4A6B35A85BD074ABCD ] NETwNe64 C:\Windows\system32\DRIVERS\NETwew00.sys
13:35:45.0343 5080 NETwNe64 - ok
13:35:45.0373 5080 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:35:45.0373 5080 nfrd960 - ok
13:35:45.0422 5080 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:35:45.0427 5080 NlaSvc - ok
13:35:45.0439 5080 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:35:45.0440 5080 Npfs - ok
13:35:45.0468 5080 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
13:35:45.0469 5080 npsvctrig - ok
13:35:45.0491 5080 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
13:35:45.0493 5080 nsi - ok
13:35:45.0519 5080 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:35:45.0519 5080 nsiproxy - ok
13:35:45.0578 5080 [ 76929F4A69E425911A63B407E26C2589 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:35:45.0589 5080 Ntfs - ok
13:35:45.0609 5080 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
13:35:45.0609 5080 Null - ok
13:35:45.0798 5080 [ EE6B7B6A54BCAFF516E30B1C15467495 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:35:45.0858 5080 nvlddmkm - ok
13:35:45.0875 5080 [ 4086D655D237E091ECC34BEC94E55C3E ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
13:35:45.0875 5080 nvpciflt - ok
13:35:45.0901 5080 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:35:45.0902 5080 nvraid - ok
13:35:45.0928 5080 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:35:45.0929 5080 nvstor - ok
13:35:46.0209 5080 [ 912602BB857F31BAAD644C993D0E5F8D ] NvStreamSvc D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
13:35:46.0458 5080 NvStreamSvc - ok
13:35:46.0512 5080 [ 25626309AD2F81D47C829CCB5E46E478 ] nvsvc C:\Windows\system32\nvvsvc.exe
13:35:46.0522 5080 nvsvc - ok
13:35:46.0602 5080 [ 056EF5C4AF4BD002AEAE417412C8EB71 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
13:35:46.0613 5080 nvUpdatusService - ok
13:35:46.0641 5080 [ 92E4BEE1A9EC0572F794B5BAECC0B599 ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
13:35:46.0642 5080 nvvad_WaveExtensible - ok
13:35:46.0670 5080 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:35:46.0671 5080 nv_agp - ok
13:35:46.0696 5080 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
13:35:46.0701 5080 p2pimsvc - ok
13:35:46.0724 5080 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
13:35:46.0731 5080 p2psvc - ok
13:35:46.0742 5080 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
13:35:46.0744 5080 Parport - ok
13:35:46.0764 5080 [ D6ACCF9F2EEEEA711C14EFD976E573F3 ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:35:46.0765 5080 partmgr - ok
13:35:46.0793 5080 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
13:35:46.0799 5080 PcaSvc - ok
13:35:46.0814 5080 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
13:35:46.0815 5080 pci - ok
13:35:46.0828 5080 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
13:35:46.0828 5080 pciide - ok
13:35:46.0857 5080 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:35:46.0859 5080 pcmcia - ok
13:35:46.0870 5080 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
13:35:46.0871 5080 pcw - ok
13:35:46.0903 5080 [ 0698DEDEAD6A00AD0D468C687D830FBF ] pdc C:\Windows\system32\drivers\pdc.sys
13:35:46.0904 5080 pdc - ok
13:35:46.0943 5080 [ 61FE70659CD43E07F94DA4DC31DEC493 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:35:46.0948 5080 PEAUTH - ok
13:35:47.0003 5080 [ DF0D9BDCB600913F40FF125BF8CE1979 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
13:35:47.0033 5080 PeerDistSvc - ok
13:35:47.0095 5080 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
13:35:47.0099 5080 PerfHost - ok
13:35:47.0151 5080 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
13:35:47.0167 5080 pla - ok
13:35:47.0217 5080 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:35:47.0222 5080 PlugPlay - ok
13:35:47.0246 5080 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
13:35:47.0249 5080 PNRPAutoReg - ok
13:35:47.0284 5080 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
13:35:47.0288 5080 PNRPsvc - ok
13:35:47.0321 5080 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:35:47.0334 5080 PolicyAgent - ok
13:35:47.0369 5080 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
13:35:47.0373 5080 Power - ok
13:35:47.0404 5080 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:35:47.0405 5080 PptpMiniport - ok
13:35:47.0487 5080 [ 9D59831262CAD44E709D695FC9D5E7AB ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
13:35:47.0515 5080 PrintNotify - ok
13:35:47.0554 5080 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
13:35:47.0555 5080 Processor - ok
13:35:47.0602 5080 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
13:35:47.0607 5080 ProfSvc - ok
13:35:47.0644 5080 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
13:35:47.0645 5080 Psched - ok
13:35:47.0678 5080 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
13:35:47.0685 5080 QWAVE - ok
13:35:47.0699 5080 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:35:47.0700 5080 QWAVEdrv - ok
13:35:47.0720 5080 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:35:47.0720 5080 RasAcd - ok
13:35:47.0748 5080 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
13:35:47.0749 5080 RasAgileVpn - ok
13:35:47.0782 5080 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
13:35:47.0786 5080 RasAuto - ok
13:35:47.0810 5080 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:35:47.0812 5080 Rasl2tp - ok
13:35:47.0838 5080 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
13:35:47.0845 5080 RasMan - ok
13:35:47.0864 5080 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:35:47.0865 5080 RasPppoe - ok
13:35:47.0883 5080 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:35:47.0884 5080 RasSstp - ok
13:35:47.0924 5080 [ CA03D642ACE58E1BA54E4B383F91CD69 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:35:47.0927 5080 rdbss - ok
13:35:47.0955 5080 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
13:35:47.0956 5080 rdpbus - ok
13:35:47.0978 5080 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
13:35:47.0980 5080 RDPDR - ok
13:35:48.0011 5080 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
13:35:48.0011 5080 RdpVideoMiniport - ok
13:35:48.0030 5080 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:35:48.0031 5080 RDPWD - ok
13:35:48.0062 5080 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
13:35:48.0063 5080 rdyboost - ok
13:35:48.0142 5080 [ 86177A203F65E08FB91D53A6F2475363 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
13:35:48.0143 5080 RegSrvc - ok
13:35:48.0177 5080 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:35:48.0180 5080 RemoteAccess - ok
13:35:48.0204 5080 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:35:48.0207 5080 RemoteRegistry - ok
13:35:48.0250 5080 [ CCBFCABDFE2BC22F0645CEAADDB36004 ] RFCOMM C:\Windows\System32\drivers\rfcomm.sys
13:35:48.0251 5080 RFCOMM - ok
13:35:48.0304 5080 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
13:35:48.0306 5080 RpcEptMapper - ok
13:35:48.0327 5080 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
13:35:48.0328 5080 RpcLocator - ok
13:35:48.0372 5080 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
13:35:48.0377 5080 RpcSs - ok
13:35:48.0389 5080 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:35:48.0390 5080 rspndr - ok
13:35:48.0421 5080 [ 55E66BAE5B30E09FDE217FBF0CDAA579 ] RSUSBVSTOR C:\Windows\System32\Drivers\RtsUVStor.sys
13:35:48.0423 5080 RSUSBVSTOR - ok
13:35:48.0452 5080 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys
13:35:48.0455 5080 RTL8168 - ok
13:35:48.0604 5080 [ 02FE42ED9CBB4CBE806ED1E906D7AC8F ] rtsuvc C:\Windows\system32\DRIVERS\rtsuvc.sys
13:35:48.0648 5080 rtsuvc - ok
13:35:48.0670 5080 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
13:35:48.0670 5080 s3cap - ok
13:35:48.0698 5080 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
13:35:48.0699 5080 SamSs - ok
13:35:48.0726 5080 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:35:48.0727 5080 sbp2port - ok
13:35:48.0747 5080 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:35:48.0751 5080 SCardSvr - ok
13:35:48.0763 5080 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
13:35:48.0764 5080 scfilter - ok
13:35:48.0808 5080 [ ED40ED9A65F3E79A8C43DD50C5FDADBF ] Schedule C:\Windows\system32\schedsvc.dll
13:35:48.0821 5080 Schedule - ok
13:35:48.0859 5080 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:35:48.0861 5080 SCPolicySvc - ok
13:35:48.0899 5080 [ 98636FB2973B8876A7F0BECD076CF109 ] sdbus C:\Windows\System32\drivers\sdbus.sys
13:35:48.0900 5080 sdbus - ok
13:35:48.0915 5080 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:35:48.0918 5080 SDRSVC - ok
13:35:48.0942 5080 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
13:35:48.0942 5080 sdstor - ok
13:35:48.0963 5080 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:35:48.0963 5080 secdrv - ok
13:35:48.0976 5080 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
13:35:48.0978 5080 seclogon - ok
13:35:49.0003 5080 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll
13:35:49.0005 5080 SENS - ok
13:35:49.0044 5080 [ DDA4CAF29D8C0A297F886BFE561E6659 ] SensorsSimulatorDriver C:\Windows\system32\DRIVERS\WUDFRd.sys
13:35:49.0045 5080 SensorsSimulatorDriver - ok
13:35:49.0064 5080 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
13:35:49.0071 5080 SensrSvc - ok
13:35:49.0097 5080 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
13:35:49.0098 5080 SerCx - ok
13:35:49.0120 5080 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
13:35:49.0121 5080 Serenum - ok
13:35:49.0145 5080 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
13:35:49.0146 5080 Serial - ok
13:35:49.0166 5080 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
13:35:49.0166 5080 sermouse - ok
13:35:49.0202 5080 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
13:35:49.0207 5080 SessionEnv - ok
13:35:49.0249 5080 [ DDA1B38A59DE5096E2619D4CFDE01F4A ] sfdrv01a C:\Windows\system32\drivers\sfdrv01a.sys
13:35:49.0250 5080 sfdrv01a - ok
13:35:49.0273 5080 [ 17F6BD95BF04B924F4C05CE78BEF8AE6 ] sfhlp02 C:\Windows\system32\drivers\sfhlp02.sys
13:35:49.0274 5080 sfhlp02 - ok
13:35:49.0290 5080 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
13:35:49.0291 5080 sfloppy - ok
13:35:49.0320 5080 sfrem01 - ok
13:35:49.0341 5080 [ C2FC1E7B64D844251A1AF6BCADFE4C14 ] sfsync04 C:\Windows\system32\drivers\sfsync04.sys
13:35:49.0342 5080 sfsync04 - ok
13:35:49.0371 5080 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:35:49.0376 5080 SharedAccess - ok
13:35:49.0412 5080 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:35:49.0419 5080 ShellHWDetection - ok
13:35:49.0436 5080 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
13:35:49.0436 5080 SiSRaid2 - ok
13:35:49.0446 5080 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:35:49.0447 5080 SiSRaid4 - ok
13:35:49.0511 5080 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
13:35:49.0513 5080 SkypeUpdate - ok
13:35:49.0544 5080 [ 165AB7677D53868AA61FB26B739C66DB ] SmbDrvI C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys
13:35:49.0544 5080 SmbDrvI - ok
13:35:49.0583 5080 [ BBFB94699C8C265A6AF5FD51BDE26DFC ] snapman C:\Windows\system32\DRIVERS\snapman.sys
13:35:49.0585 5080 snapman - ok
13:35:49.0597 5080 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:35:49.0599 5080 SNMPTRAP - ok
13:35:49.0655 5080 [ F9369327409492097B0BB7CE86BD29DE ] Soluto C:\Windows\system32\DRIVERS\Soluto.sys
13:35:49.0656 5080 Soluto - ok
13:35:49.0749 5080 [ A58E8599AA15628CCCD991BFB0AC0EBC ] SolutoLauncherService D:\Program Files\Soluto\SolutoLauncherService.exe
13:35:49.0750 5080 SolutoLauncherService - ok
13:35:49.0796 5080 [ 0FA2D9E29AE6D321EC68DD8F1B9E1181 ] SolutoRemoteService D:\Program Files\Soluto\SolutoRemoteService.exe
13:35:49.0814 5080 SolutoRemoteService - ok
13:35:49.0838 5080 [ 151DBFF45C9190D3C85E3BD38423BA72 ] SolutoService D:\Program Files\Soluto\SolutoService.exe
13:35:49.0842 5080 SolutoService - ok
13:35:49.0875 5080 [ FD3AF5575B99871BADB94E7699DBCE08 ] spaceport C:\Windows\system32\drivers\spaceport.sys
13:35:49.0877 5080 spaceport - ok
13:35:49.0918 5080 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
13:35:49.0919 5080 SpbCx - ok
13:35:49.0959 5080 [ 52B9158CBF1E0B627634EF50B27FF14B ] Speechsrv D:\Program Files (x86)\LAN Voice Chat\Speechs.exe
13:35:49.0964 5080 Speechsrv - ok
13:35:50.0023 5080 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
13:35:50.0029 5080 Spooler - ok
13:35:50.0116 5080 [ EC84D961501054F87A6878EC5D53388F ] sppsvc C:\Windows\system32\sppsvc.exe
13:35:50.0146 5080 sppsvc - ok
13:35:50.0148 5080 ================ Scan global ===============================
13:35:50.0190 5080 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
13:35:50.0223 5080 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
13:35:50.0245 5080 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
13:35:50.0275 5080 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
13:35:50.0279 5080 [Global] - ok
13:35:50.0279 5080 ================ Scan MBR ==================================
13:35:50.0292 5080 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:35:50.0447 5080 \Device\Harddisk0\DR0 - ok
13:35:50.0448 5080 ================ Scan VBR ==================================
13:35:50.0450 5080 [ B00CB9DAC7D51A91064A82A5EFAD1DCF ] \Device\Harddisk0\DR0\Partition1
13:35:50.0451 5080 \Device\Harddisk0\DR0\Partition1 - ok
13:35:50.0466 5080 [ EC6C97A09A297816EDA0298FB02B8054 ] \Device\Harddisk0\DR0\Partition2
13:35:50.0467 5080 \Device\Harddisk0\DR0\Partition2 - ok
13:35:50.0488 5080 [ 70B59553A40A55F060B358862E35CB09 ] \Device\Harddisk0\DR0\Partition3
13:35:50.0490 5080 \Device\Harddisk0\DR0\Partition3 - ok
13:35:50.0490 5080 ============================================================
13:35:50.0490 5080 Scan finished
13:35:50.0490 5080 ============================================================
13:35:50.0500 0092 Detected object count: 0
13:35:50.0500 0092 Actual detected object count: 0
13:36:15.0202 4764 Deinitialize success
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod memphisto » 03 zář 2013 17:03

Jak to vypadá teď?
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod CZechBoY » 03 zář 2013 20:38

pořád pohoda :-)
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod memphisto » 03 zář 2013 22:07

Dej ještě pro jistotu CF

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod CZechBoY » 03 zář 2013 22:24

ok, mrknu na to zítra, dneska mám deadline :D
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod memphisto » 03 zář 2013 22:29

V pohodě... Já už mám taky pomalu dost :-)
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod CZechBoY » 07 zář 2013 17:34

tak jsem si udělal čas na ten sken, zapl lux a trošku poklidil v pokoji :D ono se občas hodí udělat si takovej úklid v pc i v pokoji :D


ComboFix 13-09-06.01 - czech_000 . 09. 2013 17:23:26.1.4 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.3956.2431 [GMT 2:00]
Spuštěný z: c:\users\czech_000\Desktop\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
ADS - Windows: deleted 12 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\windows\SysWow64\frapsvid.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-07 do 2013-09-07 )))))))))))))))))))))))))))))))
.
.
2013-09-03 18:25 . 2013-09-03 18:42 -------- d-----w- c:\users\czech_000\AppData\Roaming\Apple Computer
2013-09-03 18:25 . 2013-09-03 18:25 -------- d-----w- c:\users\czech_000\AppData\Local\Apple Computer
2013-09-03 18:24 . 2012-08-21 11:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-09-03 18:24 . 2013-09-03 18:24 -------- d-----w- d:\program files (x86)\iTunes
2013-09-03 18:24 . 2013-09-03 18:24 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-03 18:24 . 2013-09-03 18:24 -------- d-----w- c:\programdata\Apple Computer
2013-09-03 18:13 . 2013-09-03 18:13 -------- d-----w- c:\users\czech_000\AppData\Local\Apple
2013-09-03 18:13 . 2013-09-03 18:13 -------- d-----w- c:\program files\Common Files\Apple
2013-09-03 18:13 . 2013-09-03 18:24 -------- d-----w- c:\program files (x86)\Common Files\Apple
2013-09-03 18:13 . 2013-09-03 18:13 -------- d-----w- c:\programdata\Apple
2013-09-02 18:23 . 2013-09-02 18:23 -------- d-----w- C:\AdwCleaner
2013-09-02 13:33 . 2013-09-02 13:36 -------- d-----w- c:\users\czech_000\AppData\Roaming\HandBrake
2013-09-01 20:42 . 2013-09-01 20:42 -------- d-----w- C:\NvidiaLogging
2013-09-01 12:52 . 2013-08-17 18:07 54728 ----a-w- c:\windows\system32\drivers\Soluto.sys
2013-09-01 12:48 . 2013-09-01 12:48 -------- d-----w- c:\windows\system32\appmgmt
2013-08-31 23:27 . 2013-09-02 01:44 1496704 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1029\ResourceCache.dll
2013-08-31 23:25 . 2013-08-31 23:25 -------- d-----w- d:\program files (x86)\Common7
2013-08-31 23:25 . 2013-08-31 23:25 -------- d-----w- d:\program files (x86)\Team Tools
2013-08-31 23:25 . 2013-08-31 23:25 -------- d-----w- c:\windows\SysWow64\1029
2013-08-31 23:24 . 2013-08-31 23:24 -------- d-----w- c:\windows\system32\1029
2013-08-31 23:20 . 2013-08-31 23:20 -------- d-----w- c:\program files (x86)\Common Files\DirectX
2013-08-31 23:07 . 2013-09-02 01:44 1488160 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2013-08-31 23:04 . 2013-08-31 23:25 -------- d-----w- d:\program files (x86)\Microsoft SQL Server Compact Edition
2013-08-31 23:04 . 2013-08-31 23:16 -------- d-----w- c:\programdata\Windows App Certification Kit
2013-08-31 23:03 . 2013-08-31 23:03 -------- d-----w- c:\program files (x86)\Common Files\Microsoft
2013-08-31 23:03 . 2013-08-31 23:03 -------- d-----w- c:\programdata\PreEmptive Solutions
2013-08-31 23:00 . 2013-08-31 23:01 -------- d-----w- c:\windows\SysWow64\1033
2013-08-31 22:58 . 2013-09-02 01:42 -------- d-----w- c:\program files (x86)\Common Files\Merge Modules
2013-08-31 22:57 . 2013-08-31 23:05 -------- d-----w- d:\program files (x86)\Microsoft Visual Studio 11.0
2013-08-31 22:57 . 2013-08-31 22:57 -------- d-----w- c:\windows\system32\1033
2013-08-31 22:56 . 2013-08-31 22:56 -------- d-----w- c:\windows\symbols
2013-08-31 21:21 . 2013-08-31 21:21 -------- d-----w- d:\program files (x86)\Secure Download Manager(onthehub)
2013-08-31 21:21 . 2013-08-31 21:21 -------- d-----w- c:\users\czech_000\AppData\Roaming\e-academy Inc
2013-08-31 20:42 . 2013-08-31 22:08 -------- d-----w- c:\users\czech_000\AppData\Local\NFS Underground 2
2013-08-30 12:08 . 2013-08-30 12:10 -------- d-----w- c:\users\czech_000\.VirtualBox
2013-08-30 12:07 . 2013-07-04 13:58 238352 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2013-08-30 12:07 . 2013-07-04 13:57 120080 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2013-08-29 13:29 . 2013-09-03 18:24 -------- dc----w- c:\windows\system32\DRVSTORE
2013-08-29 13:28 . 2013-09-01 13:02 -------- d-----w- c:\programdata\Soluto
2013-08-28 21:34 . 2013-08-28 22:16 -------- d-----w- c:\users\czech_000\AppData\Roaming\CodeBlocks
2013-08-28 21:33 . 2013-08-28 21:34 -------- d-----w- d:\program files (x86)\CodeBlocks
2013-08-27 23:36 . 2013-09-04 09:51 -------- d-----w- c:\users\czech_000\AppData\Local\gtk-2.0
2013-08-27 23:35 . 2013-08-27 23:35 -------- d-----w- c:\users\czech_000\.thumbnails
2013-08-27 23:24 . 2013-09-04 09:51 -------- d-----w- c:\users\czech_000\.gimp-2.8
2013-08-27 23:24 . 2013-08-27 23:24 -------- d-----w- c:\users\czech_000\AppData\Local\gegl-0.2
2013-08-27 17:32 . 2013-08-27 17:32 -------- d-----w- c:\users\czech_000\AppData\Roaming\ParetoLogic
2013-08-27 17:32 . 2013-08-27 17:32 -------- d-----w- c:\users\czech_000\AppData\Roaming\DriverCure
2013-08-27 15:42 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A24B45D3-B93C-44FD-8E36-4F747A822D77}\mpengine.dll
2013-08-27 01:41 . 2013-08-27 17:16 -------- d-----w- c:\users\czech_000\AppData\Local\Conduit
2013-08-27 01:41 . 2013-08-27 01:41 -------- d-----w- c:\users\czech_000\AppData\Local\CRE
2013-08-27 01:40 . 2013-08-27 01:40 -------- d-----w- c:\users\czech_000\AppData\Roaming\Free CUDA Movie Converter
2013-08-27 01:40 . 2002-01-05 14:37 344064 ----a-w- c:\windows\SysWow64\msvcr70.dll
2013-08-27 01:06 . 2013-08-27 01:06 -------- d-----w- c:\users\czech_000\AppData\Roaming\AnvSoft
2013-08-27 01:06 . 2011-11-28 12:51 33872 ----a-w- c:\windows\system32\drivers\anvsnddrv.sys
2013-08-27 00:10 . 2013-08-27 00:10 -------- d-----w- c:\users\czech_000\AppData\Local\SplitMediaLabs
2013-08-27 00:10 . 2013-09-01 12:53 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin
2013-08-27 00:10 . 2013-08-27 00:10 -------- d-----w- c:\programdata\SplitMediaLabs
2013-08-27 00:10 . 2013-08-27 00:10 -------- d-----w- c:\users\czech_000\AppData\Roaming\SplitMediaLabs
2013-08-26 15:49 . 2013-08-31 20:21 -------- d-----w- d:\program files (x86)\Passware
2013-08-25 14:50 . 2013-08-25 14:50 -------- d-----w- c:\users\czech_000\AppData\Roaming\Thunderbird
2013-08-25 14:50 . 2013-08-25 14:50 -------- d-----w- c:\users\czech_000\AppData\Local\Thunderbird
2013-08-21 23:07 . 2013-08-21 23:31 -------- d-----w- c:\programdata\NFS Underground
2013-08-21 22:56 . 2013-08-21 23:03 -------- d-----w- d:\program files (x86)\JDownloader
2013-08-21 22:50 . 2013-08-31 20:36 -------- d-----w- d:\program files (x86)\EA GAMES
2013-08-20 18:41 . 2013-08-20 18:41 -------- d--h--w- c:\windows\system32\WLANProfiles
2013-08-20 18:41 . 2013-08-20 18:41 -------- d-----w- c:\users\czech_000\AppData\Roaming\Intel
2013-08-20 18:40 . 2013-08-20 18:40 -------- d-----w- c:\users\UpdatusUser\Roaming
2013-08-20 18:40 . 2013-08-20 18:40 -------- d-----w- c:\users\Public\Roaming
2013-08-20 18:40 . 2013-08-20 18:40 -------- d-----w- c:\users\Default\Roaming
2013-08-20 18:40 . 2013-08-20 18:40 -------- d-----w- c:\users\czech_000\Roaming
2013-08-20 18:40 . 2013-08-20 18:40 -------- d-----w- c:\program files\Common Files\Intel
2013-08-20 18:40 . 2013-08-20 18:40 -------- d-----w- c:\programdata\Intel.sav
2013-08-20 18:39 . 2013-09-02 01:44 -------- d-----w- c:\programdata\Package Cache
2013-08-18 14:00 . 2013-08-18 14:00 1160576 ----a-w- c:\windows\is-TAGGB.exe
2013-08-18 10:05 . 2013-08-18 10:05 -------- d-----w- c:\users\czech_000\AppData\Roaming\LibreOffice
2013-08-18 10:05 . 2013-09-03 19:32 -------- d-----w- d:\program files (x86)\LibreOffice 4
2013-08-17 15:27 . 2013-08-17 15:27 -------- d-----w- d:\program files (x86)\Windows Defender
2013-08-17 14:03 . 2013-07-26 05:13 2241024 ----a-w- c:\windows\system32\wininet.dll
2013-08-17 14:03 . 2013-07-26 05:12 136704 ----a-w- c:\windows\system32\iesysprep.dll
2013-08-17 14:03 . 2013-07-26 05:13 1084928 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-08-17 14:03 . 2013-07-26 05:12 15405056 ----a-w- c:\windows\system32\ieframe.dll
2013-08-17 14:03 . 2013-07-26 05:12 855552 ----a-w- c:\windows\system32\jscript.dll
2013-08-17 14:03 . 2013-07-26 05:12 19239424 ----a-w- c:\windows\system32\mshtml.dll
2013-08-17 14:03 . 2013-07-26 05:12 2647040 ----a-w- c:\windows\system32\iertutil.dll
2013-08-17 14:03 . 2013-07-26 05:12 3958784 ----a-w- c:\windows\system32\jscript9.dll
2013-08-17 14:02 . 2013-07-26 03:12 2877440 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-08-17 14:02 . 2013-07-13 06:16 1889280 ----a-w- c:\windows\system32\crypt32.dll
2013-08-17 14:02 . 2013-07-13 06:18 337408 ----a-w- c:\windows\system32\wintrust.dll
2013-08-17 14:02 . 2013-07-13 04:23 1568256 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-08-17 14:02 . 2013-07-13 06:16 68096 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-17 14:02 . 2013-07-13 06:15 124416 ----a-w- c:\windows\system32\apprepapi.dll
2013-08-17 14:02 . 2013-07-13 04:24 261120 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-08-17 14:02 . 2013-07-13 04:23 87040 ----a-w- c:\windows\SysWow64\apprepapi.dll
2013-08-17 14:02 . 2013-07-13 06:15 98304 ----a-w- c:\windows\system32\apprepsync.dll
2013-08-17 14:02 . 2013-07-13 04:23 74240 ----a-w- c:\windows\SysWow64\apprepsync.dll
2013-08-12 16:01 . 2013-08-12 17:11 -------- d-----w- d:\program files (x86)\Battlefield 2
2013-08-10 17:54 . 2013-08-10 17:54 -------- d-----w- c:\programdata\GARMIN
2013-08-10 08:21 . 2013-08-10 08:21 -------- d-----w- d:\program files (x86)\LAN Voice Chat
2013-08-10 07:47 . 2013-08-10 07:53 102912 ----a-w- c:\windows\system32\dfboottime.exe
2013-08-10 06:33 . 2013-08-27 17:18 -------- d-----w- c:\users\czech_000\AppData\Local\Opera Software
2013-08-09 19:45 . 2013-08-09 19:45 310368 ----a-w- c:\windows\system32\drivers\snapman.sys
2013-08-09 19:45 . 2013-08-09 19:45 132704 ----a-w- c:\windows\system32\drivers\fltsrv.sys
2013-08-09 19:44 . 2013-08-09 19:45 -------- d-----w- c:\program files (x86)\Common Files\Acronis
2013-08-09 19:44 . 2013-08-09 19:44 -------- d-----w- d:\program files (x86)\Acronis
2013-08-09 19:40 . 2013-08-09 19:46 -------- d-----w- d:\program files (x86)\StuntGP
2013-08-09 19:40 . 2013-08-10 10:37 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2013-08-09 19:03 . 2013-09-07 00:16 -------- d-----w- c:\users\czech_000\AppData\Roaming\uTorrent
2013-08-09 17:31 . 2013-08-09 17:45 -------- d---a-w- d:\program files (x86)\Tennis Critters
2013-08-09 15:51 . 2009-04-24 10:14 39424 ----a-w- c:\windows\SysWow64\cdrvxf32.dll
2013-08-09 15:51 . 2009-04-24 10:14 31744 ----a-w- c:\windows\SysWow64\cdrvhf32.dll
2013-08-09 15:51 . 2009-04-24 10:14 28672 ----a-w- c:\windows\SysWow64\cdrvdl32.dll
2013-08-09 15:51 . 2009-04-24 10:14 18432 ----a-w- c:\windows\SysWow64\commsc32.dll
2013-08-09 15:51 . 2009-04-24 10:14 109248 ----a-w- c:\windows\SysWow64\mswinsck.ocx
2013-08-09 15:51 . 2009-04-24 10:13 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2013-08-09 15:51 . 2009-04-24 10:13 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2013-08-09 15:51 . 2009-04-24 10:13 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2013-08-09 15:51 . 2009-04-24 10:13 1047552 ----a-w- c:\windows\SysWow64\mfc71u.dll
2013-08-09 15:51 . 2013-08-09 15:51 -------- d-----w- c:\program files (x86)\Common Files\WildPackets
2013-08-09 15:48 . 2013-08-09 15:48 89088 ----a-w- c:\windows\SysWow64\NWKL2_64.DLL
2013-08-09 15:48 . 2013-08-09 15:48 89088 ----a-w- c:\windows\system32\NWKL2_64.DLL
2013-08-09 15:48 . 2013-08-09 15:48 86016 ----a-w- c:\windows\SysWow64\KL2DLL32.DLL
2013-08-09 15:48 . 2013-08-09 15:48 86016 ----a-w- c:\windows\system32\KL2DLL32.DLL
2013-08-09 15:48 . 2013-08-09 15:48 74240 ----a-w- c:\windows\SysWow64\KL2DLL64.DLL
2013-08-09 15:48 . 2013-08-09 15:48 74240 ----a-w- c:\windows\system32\KL2DLL64.DLL
2013-08-09 15:48 . 2013-08-09 15:48 143360 ----a-w- c:\windows\SysWow64\NWKL2_32.DLL
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-17 15:22 . 2013-07-14 23:28 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-08-17 07:49 . 2013-07-14 16:00 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-07-28 09:02 . 2013-07-28 09:02 388096 ----a-r- c:\users\czech_000\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-07-24 12:52 . 2013-07-24 12:52 224016 --s---r- c:\windows\SysWow64\TABCTL32.OCX
2013-07-24 12:52 . 2013-07-24 12:52 152848 --s---r- c:\windows\SysWow64\COMDLG32.OCX
2013-07-24 12:52 . 2013-07-24 12:52 1010720 --s---r- c:\windows\SysWow64\MSCHRT20.OCX
2013-07-24 12:52 . 2013-07-24 12:52 1081616 --s---r- c:\windows\SysWow64\MSCOMCTL.OCX
2013-07-18 21:52 . 2013-07-14 13:50 6656 ----a-w- c:\windows\system32\lpcio.dll
2013-07-17 09:52 . 2013-07-17 09:52 4262128 ----a-w- c:\windows\system32\wlihvui.dll
2013-07-17 09:52 . 2013-07-17 09:52 2353904 ----a-w- c:\windows\system32\iwmssvc.dll
2013-07-14 22:30 . 2013-07-14 22:30 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-14 22:30 . 2013-07-14 22:30 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-07-14 22:30 . 2013-07-14 22:30 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-07-14 14:27 . 2013-07-14 14:27 19872 ----a-w- c:\windows\system32\LenovoSDKEmSubSystem.dll
2013-07-14 14:27 . 2012-06-19 23:12 66560 ----a-w- c:\windows\system32\drivers\UMDF\LenovoVhid.dll
2013-07-14 14:27 . 2012-02-21 03:48 1511280 ----a-w- c:\windows\system32\WudfUpdate_01011.dll
2013-07-14 14:27 . 2013-07-14 14:27 39008 ----a-w- c:\windows\system32\drivers\LhdX64.sys
2013-07-14 14:27 . 2012-05-15 07:22 33560 ----a-w- c:\windows\system32\drivers\AcpiVpc.sys
2013-07-14 13:38 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-07-04 13:57 . 2013-07-04 13:57 146704 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2013-07-04 13:57 . 2013-07-04 13:57 131856 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2013-07-04 13:56 . 2013-07-04 13:56 204048 ----a-w- c:\windows\system32\VBoxNetFltNobj.dll
2013-06-27 22:04 . 2012-07-26 08:14 78200 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 22:04 . 2012-07-26 08:14 693112 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-21 12:06 . 2013-07-14 22:41 925648 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2013-06-21 12:06 . 2013-07-14 22:41 9239344 ----a-w- c:\windows\system32\nvcuda.dll
2013-06-21 12:06 . 2013-07-14 22:41 7687592 ----a-w- c:\windows\SysWow64\nvcuda.dll
2013-06-21 12:06 . 2013-07-14 22:41 7641832 ----a-w- c:\windows\system32\nvopencl.dll
2013-06-21 12:06 . 2013-07-14 22:41 6324360 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-06-21 12:06 . 2013-07-14 22:41 572704 ----a-w- c:\windows\system32\NvFBC64.dll
2013-06-21 12:06 . 2013-07-14 22:41 570656 ----a-w- c:\windows\system32\NvIFR64.dll
2013-06-21 12:06 . 2013-07-14 22:41 467232 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-06-21 12:06 . 2013-07-14 22:41 465184 ----a-w- c:\windows\SysWow64\NvFBC.dll
2013-06-21 12:06 . 2013-07-14 22:41 432928 ----a-w- c:\windows\system32\nvEncodeAPI64.dll
2013-06-21 12:06 . 2013-07-14 22:41 372000 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll
2013-06-21 12:06 . 2013-07-14 22:41 30496 ----a-w- c:\windows\system32\drivers\nvpciflt.sys
2013-06-21 12:06 . 2013-07-14 22:41 2953504 ----a-w- c:\windows\system32\nvcuvid.dll
2013-06-21 12:06 . 2013-07-14 22:41 2936208 ----a-w- c:\windows\system32\nvapi64.dll
2013-06-21 12:06 . 2013-07-14 22:41 27781920 ----a-w- c:\windows\system32\nvoglv64.dll
2013-06-21 12:06 . 2013-07-14 22:41 2777888 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2013-06-21 12:06 . 2013-07-14 22:41 266448 ----a-w- c:\windows\system32\nvinitx.dll
2013-06-21 12:06 . 2013-07-14 22:41 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-06-21 12:06 . 2013-07-14 22:41 25256224 ----a-w- c:\windows\system32\nvcompiler.dll
2013-06-21 12:06 . 2013-07-14 22:41 2363680 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-06-21 12:06 . 2013-07-14 22:41 218592 ----a-w- c:\windows\system32\nvoglshim64.dll
2013-06-21 12:06 . 2013-07-14 22:41 214448 ----a-w- c:\windows\SysWow64\nvinit.dll
2013-06-21 12:06 . 2013-07-14 22:41 21102368 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-06-21 12:06 . 2013-07-14 22:41 2002720 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2013-06-21 12:06 . 2013-07-14 22:41 1832224 ----a-w- c:\windows\system32\nvdispco6432049.dll
2013-06-21 12:06 . 2013-07-14 22:41 181488 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2013-06-21 12:06 . 2013-07-14 22:41 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2013-06-21 12:06 . 2013-07-14 22:41 15920536 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-06-21 12:06 . 2013-07-14 22:41 15144928 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-06-21 12:06 . 2013-07-14 22:41 1511712 ----a-w- c:\windows\system32\nvdispgenco6432049.dll
2013-06-21 12:06 . 2013-07-14 22:41 13411896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06 . 2013-07-14 22:41 12427240 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-06-21 12:06 . 2013-07-14 22:41 11235104 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-06-21 12:06 . 2013-07-14 22:41 1059560 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-06-21 10:23 . 2013-07-14 22:43 6496544 ----a-w- c:\windows\system32\nvcpl.dll
2013-06-21 10:23 . 2013-07-14 22:43 3514656 ----a-w- c:\windows\system32\nvsvc64.dll
2013-06-21 10:23 . 2013-07-14 22:43 884512 ----a-w- c:\windows\system32\nvvsvc.exe
2013-06-21 10:23 . 2013-07-14 22:43 67072 ----a-w- c:\windows\system32\nv3dappshextr.dll
2013-06-21 10:23 . 2013-07-14 22:43 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-06-21 10:23 . 2013-07-14 22:43 2555680 ----a-w- c:\windows\system32\nvsvcr.dll
2013-06-21 10:23 . 2013-07-14 22:43 237856 ----a-w- c:\windows\system32\nvmctray.dll
2013-06-21 10:23 . 2013-07-14 22:43 1025312 ----a-w- c:\windows\system32\nv3dappshext.dll
2013-06-21 10:23 . 2013-07-14 22:42 575264 ----a-w- c:\windows\SysWow64\oemdspif.dll
2013-06-20 04:17 . 2013-07-14 22:43 3253909 ----a-w- c:\windows\system32\nvcoproc.bin
2013-06-16 22:41 . 2013-07-17 11:22 997632 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-06-12 08:56 . 2013-06-12 08:56 3343840 ----a-w- c:\windows\system32\drivers\NETwew00.sys
2013-06-09 17:53 . 2013-06-09 17:53 83024 ----a-w- c:\windows\SysWow64\mfcm110u.dll
2013-06-09 17:53 . 2013-06-09 17:53 83016 ----a-w- c:\windows\SysWow64\mfcm110.dll
2013-06-09 17:53 . 2013-06-09 17:53 8247888 ----a-w- c:\windows\SysWow64\mfc110ud.dll
2013-06-09 17:53 . 2013-06-09 17:53 8177224 ----a-w- c:\windows\SysWow64\mfc110d.dll
2013-06-09 17:53 . 2013-06-09 17:53 74832 ----a-w- c:\windows\SysWow64\mfc110fra.dll
2013-06-09 17:53 . 2013-06-09 17:53 74832 ----a-w- c:\windows\SysWow64\mfc110deu.dll
2013-06-09 17:53 . 2013-06-09 17:53 73808 ----a-w- c:\windows\SysWow64\mfc110esn.dll
2013-06-09 17:53 . 2013-06-09 17:53 72784 ----a-w- c:\windows\SysWow64\mfc110ita.dll
2013-06-09 17:53 . 2013-06-09 17:53 70736 ----a-w- c:\windows\SysWow64\mfc110rus.dll
2013-06-09 17:53 . 2013-06-09 17:53 65104 ----a-w- c:\windows\SysWow64\mfc110enu.dll
2013-06-09 17:53 . 2013-06-09 17:53 53840 ----a-w- c:\windows\SysWow64\mfc110jpn.dll
2013-06-09 17:53 . 2013-06-09 17:53 53328 ----a-w- c:\windows\SysWow64\mfc110kor.dll
2013-06-09 17:53 . 2013-06-09 17:53 46160 ----a-w- c:\windows\SysWow64\mfc110cht.dll
2013-06-09 17:53 . 2013-06-09 17:53 46160 ----a-w- c:\windows\SysWow64\mfc110chs.dll
2013-06-09 17:53 . 2013-06-09 17:53 4456520 ----a-w- c:\windows\SysWow64\mfc110u.dll
2013-06-09 17:53 . 2013-06-09 17:53 4421192 ----a-w- c:\windows\SysWow64\mfc110.dll
2013-06-09 17:53 . 2013-06-09 17:53 164424 ----a-w- c:\windows\SysWow64\atl110.dll
2013-06-09 17:53 . 2013-06-09 17:53 111696 ----a-w- c:\windows\SysWow64\mfcm110d.dll
2013-06-09 17:53 . 2013-06-09 17:53 110672 ----a-w- c:\windows\SysWow64\mfcm110ud.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll c:\progra~2\NVIDIA~1\NVSTRE~1\rxinput.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ dfboottime \??\c:\windows\System32\dfboottime.cfg\0autocheck autochk *
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys;c:\windows\SYSNATIVE\drivers\sfdrv01a.sys [x]
R3 AcuWVSSchedulerv8;Acunetix WVS Scheduler v8;d:\program files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe;d:\program files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe [x]
R3 anvsnddrv;AnvSoft Virtual Sound Device;c:\windows\system32\drivers\anvsnddrv.sys;c:\windows\SYSNATIVE\drivers\anvsnddrv.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;d:\program files\Intel\WiFi\bin\PanDhcpDns.exe;d:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 NvStreamSvc;NVIDIA Streamer Service;d:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;d:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 SolutoRemoteService;Soluto Remote Service;d:\program files\Soluto\SolutoRemoteService.exe;d:\program files\Soluto\SolutoRemoteService.exe [x]
R3 Speechsrv;Glasovne poruke;d:\program files (x86)\LAN Voice Chat\Speechs.exe;d:\program files (x86)\LAN Voice Chat\Speechs.exe [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TeamViewer8;TeamViewer 8;d:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;d:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;d:\program files\Intel\WiFi\bin\ZeroConfigService.exe;d:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys;c:\windows\SYSNATIVE\DRIVERS\Soluto.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 SolutoLauncherService;Soluto Launcher Service;d:\program files\Soluto\SolutoLauncherService.exe;d:\program files\Soluto\SolutoLauncherService.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;d:\program files\Soluto\SolutoService.exe;d:\program files\Soluto\SolutoService.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 IAStorDataMgrSvc;Úložná technologie Intel® Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 NETwNe64;@oem56.inf,___ %NIC_Service_DispName_WIN8_64%;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit;c:\windows\system32\DRIVERS\NETwew00.sys;c:\windows\SYSNATIVE\DRIVERS\NETwew00.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-04 10:20 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.66\Installer\chrmstp.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2012-08-27 11577216]
"RtsFT"="RTFTrack.exe" [2012-08-27 6334096]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-27 1028896]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-19 172168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-19 441992]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"IntelPROSet"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2013-07-17 4791024]
"Soluto"="d:\program files\soluto\soluto.exe" [2013-08-17 1252896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SYSTEM32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Inspect Element with DebugBar - d:\program files (x86)\Core Services\DebugBar\DebugInfoBar.dll/247
IE: Odeslat do Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: DhcpNameServer = 10.0.0.100 10.0.0.200
FF - ProfilePath - c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 54&UM=3&q=
FF - ExtSQL: 2013-08-09 11:44; firebug@software.joehewitt.com; c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\extensions\firebug@software.joehewitt.com.xpi
FF - ExtSQL: 2013-08-09 11:44; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-08-09 11:45; {d49a148e-817e-4025-bee3-5d541376de3b}; c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\extensions\{d49a148e-817e-4025-bee3-5d541376de3b}.xpi
FF - ExtSQL: 2013-08-09 11:45; firegestures@xuldev.org; c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\extensions\firegestures@xuldev.org.xpi
FF - ExtSQL: 2013-08-09 11:45; firefinder@robertnyman.com; c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\extensions\firefinder@robertnyman.com.xpi
FF - ExtSQL: 2013-08-24 14:18; {3c6e1eed-a07e-4c80-9cf3-66ea0bf40b37}; c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\extensions\{3c6e1eed-a07e-4c80-9cf3-66ea0bf40b37}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-SynLenovoGestureMgr - d:\program files (x86)\Synaptics\SynTP\SynLenovoGestureMgr.exe
.
.
Binary file temp00 matches
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Celkový čas: 2013-09-07 17:32:56
ComboFix-quarantined-files.txt 2013-09-07 15:32
.
Před spuštěním: 98 631 610 368 bytes free
Po spuštění: 98 607 853 568 bytes free
.
- - End Of File - - CE6F90D2B990972D5D0AD439A8CCD57A
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT - nákaza v MBAM

Příspěvekod jaro3 » 08 zář 2013 10:34

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
Collect::
c:\windows\is-TAGGB.exe

Folder::
c:\users\czech_000\AppData\Local\Conduit
c:\program files (x86)\Skype\Updater

Driver::
SkypeUpdate

DDS::
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SYSTEM32\blank.htm
uInternet Settings,ProxyOverride = *.local

Firefox::
FF - ProfilePath - c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 54&UM=3&q=

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 85 hostů