Po spuštění mi naskočí tabulka Windows Script Hosts, C:\users\byt, po odkliknutí OK zmizí. Posílám log z HJT, prosím o kontrolu. Moc děkuju ... mám Win 8.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:13:11, on 24. 9. 2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16688)
Boot mode: Normal
Running processes:
C:\Windows\inf\msbswiogr\msbswiogr.exe
C:\Windows\inf\msoyslqyv\msoyslqyv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\inf\msxqaj\msxqaj.exe
C:\Program Files (x86)\Opera\16.0.1196.73\opera.exe
C:\Program Files (x86)\Opera\16.0.1196.73\opera.exe
C:\Program Files (x86)\Opera\16.0.1196.73\opera.exe
C:\Program Files (x86)\Opera\16.0.1196.73\opera.exe
C:\Program Files (x86)\Opera\16.0.1196.73\opera.exe
C:\Program Files (x86)\Opera\16.0.1196.73\opera.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hal3000.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BS Player ControlBar Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player_ControlBar\prxtbBS_P.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: BS Player ControlBar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player_ControlBar\prxtbBS_P.dll
O3 - Toolbar: BS Player ControlBar Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player_ControlBar\prxtbBS_P.dll
O4 - HKLM\..\Run: [msnjufxSrv] C:\Windows\inf\msnjufx.vbe
O4 - HKLM\..\Run: [msjtbvbuSrv] C:\Windows\inf\msjtbvbu.vbe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NtVdmSrv] C:\Windows\inf\ntvdm.vbe
O4 - HKLM\..\Run: [4StoryPrePatch] C:\Program Files (x86)\Gameforge4D\4Story_CZ\PrePatch.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6763 bytes
Windows Script Hosts - kontrola logu HJT
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Windows Script Hosts - kontrola logu HJT
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Windows Script Hosts - kontrola logu HJT
Tady jsou oba logy, zatím moc díky ...
# AdwCleaner v3.005 - Report created 24/09/2013 at 18:39:28
# Updated 22/09/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : byt - RODINA
# Running from : C:\Users\byt\Desktop\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Program Files (x86)\BS_Player_ControlBar
Folder Found C:\Program Files (x86)\Conduit
Folder Found C:\Users\byt\AppData\LocalLow\BS_Player_ControlBar
Folder Found C:\Users\byt\AppData\LocalLow\Conduit
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software\BS_Player_ControlBar
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Found : [x64] HKCU\Software\Conduit
Key Found : HKLM\Software\BS_Player_ControlBar
Key Found : HKLM\SOFTWARE\Classes\CLSID\{055DD326-956C-4827-9467-A172509E81B3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1750559
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60A45D7B-70F8-40EA-8C0F-13AB61E1BB9F}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B96ADDB3-1388-4596-894A-8FBB67398195}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{055DD326-956C-4827-9467-A172509E81B3}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BS_Player_ControlBar Toolbar
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16688
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.conduit.com?SearchSource= ... =CT1750559
-\\ Mozilla Firefox v24.0 (cs)
[ File : C:\Users\byt\AppData\Roaming\Mozilla\Firefox\Profiles\5kiwwdo0.default\prefs.js ]
-\\ Google Chrome v29.0.1547.76
[ File : C:\Users\byt\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [3018 octets] - [24/09/2013 18:39:28]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3078 octets] ##########
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
http://www.malwarebytes.org
Verze: v2013.09.24.08
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16688
byt :: RODINA [administrátor]
Ochrana: Povolena
24. 9. 2013 18:52:45
MBAM-log-2013-09-24 (18-57-50).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 215701
Uplynulý čas: 3 minut, 54 sekund
Nalezené procesy v paměti: 3
C:\Windows\Inf\msbswiogr\msbswiogr.exe (BitcoinMiner) -> 3764 -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\msoyslqyv\msoyslqyv.exe (BitcoinMiner) -> 3784 -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\msxqaj\msxqaj.exe (BitcoinMiner) -> 3704 -> Nebyla provedena žádná instrukce.
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NtVdmSrv (Malware.Trace) -> Data: C:\Windows\inf\ntvdm.vbe -> Nebyla provedena žádná instrukce.
Nalezené datové položky v registru: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit) -> Špatný: (http://search.conduit.com?SearchSource= ... =CT1750559) Dobrý: (http://www.google.com) -> Nebyla provedena žádná instrukce.
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 5
C:\Windows\Inf\msbswiogr\msbswiogr.exe (BitcoinMiner) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\msoyslqyv\msoyslqyv.exe (BitcoinMiner) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\msxqaj\msxqaj.exe (BitcoinMiner) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\ntvdm.vbe (Malware.Trace) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\ntvdm.inf (Malware.Trace) -> Nebyla provedena žádná instrukce.
(konec)
# AdwCleaner v3.005 - Report created 24/09/2013 at 18:39:28
# Updated 22/09/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : byt - RODINA
# Running from : C:\Users\byt\Desktop\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Program Files (x86)\BS_Player_ControlBar
Folder Found C:\Program Files (x86)\Conduit
Folder Found C:\Users\byt\AppData\LocalLow\BS_Player_ControlBar
Folder Found C:\Users\byt\AppData\LocalLow\Conduit
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software\BS_Player_ControlBar
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Found : [x64] HKCU\Software\Conduit
Key Found : HKLM\Software\BS_Player_ControlBar
Key Found : HKLM\SOFTWARE\Classes\CLSID\{055DD326-956C-4827-9467-A172509E81B3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1750559
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60A45D7B-70F8-40EA-8C0F-13AB61E1BB9F}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B96ADDB3-1388-4596-894A-8FBB67398195}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{055DD326-956C-4827-9467-A172509E81B3}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BS_Player_ControlBar Toolbar
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16688
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.conduit.com?SearchSource= ... =CT1750559
-\\ Mozilla Firefox v24.0 (cs)
[ File : C:\Users\byt\AppData\Roaming\Mozilla\Firefox\Profiles\5kiwwdo0.default\prefs.js ]
-\\ Google Chrome v29.0.1547.76
[ File : C:\Users\byt\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [3018 octets] - [24/09/2013 18:39:28]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3078 octets] ##########
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
http://www.malwarebytes.org
Verze: v2013.09.24.08
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16688
byt :: RODINA [administrátor]
Ochrana: Povolena
24. 9. 2013 18:52:45
MBAM-log-2013-09-24 (18-57-50).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 215701
Uplynulý čas: 3 minut, 54 sekund
Nalezené procesy v paměti: 3
C:\Windows\Inf\msbswiogr\msbswiogr.exe (BitcoinMiner) -> 3764 -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\msoyslqyv\msoyslqyv.exe (BitcoinMiner) -> 3784 -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\msxqaj\msxqaj.exe (BitcoinMiner) -> 3704 -> Nebyla provedena žádná instrukce.
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NtVdmSrv (Malware.Trace) -> Data: C:\Windows\inf\ntvdm.vbe -> Nebyla provedena žádná instrukce.
Nalezené datové položky v registru: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit) -> Špatný: (http://search.conduit.com?SearchSource= ... =CT1750559) Dobrý: (http://www.google.com) -> Nebyla provedena žádná instrukce.
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 5
C:\Windows\Inf\msbswiogr\msbswiogr.exe (BitcoinMiner) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\msoyslqyv\msoyslqyv.exe (BitcoinMiner) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\msxqaj\msxqaj.exe (BitcoinMiner) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\ntvdm.vbe (Malware.Trace) -> Nebyla provedena žádná instrukce.
C:\Windows\Inf\ntvdm.inf (Malware.Trace) -> Nebyla provedena žádná instrukce.
(konec)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Windows Script Hosts - kontrola logu HJT
. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Windows Script Hosts - kontrola logu HJT
Tak snad jsem to vše provedla dobře, tady jsou všechny 4 logy :
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
http://www.malwarebytes.org
Verze: v2013.09.25.02
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16688
byt :: RODINA [administrátor]
Ochrana: Povolena
25. 9. 2013 22:36:42
mbam-log-2013-09-25 (22-36-42).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 215526
Uplynulý čas: 2 minut, 7 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit) -> Špatný: (http://search.conduit.com?SearchSource= ... =CT1750559) Dobrý: (http://www.google.com) -> Přesun do karantény a opravení se zdařilo.
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 1
C:\Windows\Inf\ntvdm.inf (Malware.Trace) -> Přesun do karantény a smazání se zdařilo.
(konec)
# AdwCleaner v3.005 - Report created 25/09/2013 at 22:44:15
# Updated 22/09/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : byt - RODINA
# Running from : C:\Users\byt\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\BS_Player_ControlBar
Folder Deleted : C:\Users\byt\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\byt\AppData\LocalLow\BS_Player_ControlBar
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1750559
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{055DD326-956C-4827-9467-A172509E81B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{055DD326-956C-4827-9467-A172509E81B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60A45D7B-70F8-40EA-8C0F-13AB61E1BB9F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B96ADDB3-1388-4596-894A-8FBB67398195}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\BS_Player_ControlBar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\BS_Player_ControlBar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BS_Player_ControlBar Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16688
-\\ Mozilla Firefox v24.0 (cs)
[ File : C:\Users\byt\AppData\Roaming\Mozilla\Firefox\Profiles\5kiwwdo0.default\prefs.js ]
-\\ Google Chrome v29.0.1547.76
[ File : C:\Users\byt\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [3162 octets] - [24/09/2013 18:39:28]
AdwCleaner[R1].txt - [3057 octets] - [25/09/2013 22:43:17]
AdwCleaner[S0].txt - [2999 octets] - [25/09/2013 22:44:15]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3059 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 8 x64
Ran by byt on st 25. 09. 2013 at 22:48:19,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E5B728EA-C52F-428E-A2A3-3FAE7ED5CA13}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 25. 09. 2013 at 22:53:44,71
End of JRT log
RogueKiller V8.6.12 _x64_ [Sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : byt [Práva správce]
Mód : Kontrola -- Datum : 09/25/2013 23:01:31
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD10EZEX-00RKKA0 +++++
--- User ---
[MBR] 124544447642830df46e584b23ee1d95
[BSP] 153fbedc6169cdc8a9a9eefe1f86713e : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 411648 | Size: 953667 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_09252013_230131.txt >>
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
http://www.malwarebytes.org
Verze: v2013.09.25.02
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16688
byt :: RODINA [administrátor]
Ochrana: Povolena
25. 9. 2013 22:36:42
mbam-log-2013-09-25 (22-36-42).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 215526
Uplynulý čas: 2 minut, 7 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit) -> Špatný: (http://search.conduit.com?SearchSource= ... =CT1750559) Dobrý: (http://www.google.com) -> Přesun do karantény a opravení se zdařilo.
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 1
C:\Windows\Inf\ntvdm.inf (Malware.Trace) -> Přesun do karantény a smazání se zdařilo.
(konec)
# AdwCleaner v3.005 - Report created 25/09/2013 at 22:44:15
# Updated 22/09/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : byt - RODINA
# Running from : C:\Users\byt\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\BS_Player_ControlBar
Folder Deleted : C:\Users\byt\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\byt\AppData\LocalLow\BS_Player_ControlBar
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1750559
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{055DD326-956C-4827-9467-A172509E81B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{055DD326-956C-4827-9467-A172509E81B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60A45D7B-70F8-40EA-8C0F-13AB61E1BB9F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B96ADDB3-1388-4596-894A-8FBB67398195}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\BS_Player_ControlBar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\BS_Player_ControlBar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BS_Player_ControlBar Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16688
-\\ Mozilla Firefox v24.0 (cs)
[ File : C:\Users\byt\AppData\Roaming\Mozilla\Firefox\Profiles\5kiwwdo0.default\prefs.js ]
-\\ Google Chrome v29.0.1547.76
[ File : C:\Users\byt\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [3162 octets] - [24/09/2013 18:39:28]
AdwCleaner[R1].txt - [3057 octets] - [25/09/2013 22:43:17]
AdwCleaner[S0].txt - [2999 octets] - [25/09/2013 22:44:15]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3059 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 8 x64
Ran by byt on st 25. 09. 2013 at 22:48:19,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E5B728EA-C52F-428E-A2A3-3FAE7ED5CA13}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 25. 09. 2013 at 22:53:44,71
End of JRT log
RogueKiller V8.6.12 _x64_ [Sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : byt [Práva správce]
Mód : Kontrola -- Datum : 09/25/2013 23:01:31
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD10EZEX-00RKKA0 +++++
--- User ---
[MBR] 124544447642830df46e584b23ee1d95
[BSP] 153fbedc6169cdc8a9a9eefe1f86713e : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 411648 | Size: 953667 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_09252013_230131.txt >>
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Windows Script Hosts - kontrola logu HJT
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Windows Script Hosts - kontrola logu HJT
RogueKiller V8.6.12 _x64_ [Sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : byt [Práva správce]
Mód : Odebrat -- Datum : 09/26/2013 23:09:06
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD10EZEX-00RKKA0 +++++
--- User ---
[MBR] 124544447642830df46e584b23ee1d95
[BSP] 153fbedc6169cdc8a9a9eefe1f86713e : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 411648 | Size: 953667 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_09262013_230906.txt >>
RKreport[0]_S_09262013_230858.txt
23:13:58.0886 4008 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
23:13:59.0058 4008 ============================================================
23:13:59.0058 4008 Current date / time: 2013/09/26 23:13:59.0058
23:13:59.0058 4008 SystemInfo:
23:13:59.0058 4008
23:13:59.0058 4008 OS Version: 6.2.9200 ServicePack: 0.0
23:13:59.0058 4008 Product type: Workstation
23:13:59.0058 4008 ComputerName: RODINA
23:13:59.0058 4008 UserName: byt
23:13:59.0058 4008 Windows directory: C:\Windows
23:13:59.0058 4008 System windows directory: C:\Windows
23:13:59.0058 4008 Running under WOW64
23:13:59.0058 4008 Processor architecture: Intel x64
23:13:59.0058 4008 Number of processors: 4
23:13:59.0058 4008 Page size: 0x1000
23:13:59.0058 4008 Boot type: Normal boot
23:13:59.0058 4008 ============================================================
23:13:59.0573 4008 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:13:59.0573 4008 ============================================================
23:13:59.0573 4008 \Device\Harddisk0\DR0:
23:13:59.0573 4008 MBR partitions:
23:13:59.0573 4008 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x64000
23:13:59.0573 4008 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x746A1800
23:13:59.0573 4008 ============================================================
23:13:59.0590 4008 C: <-> \Device\Harddisk0\DR0\Partition2
23:13:59.0590 4008 ============================================================
23:13:59.0590 4008 Initialize success
23:13:59.0590 4008 ============================================================
23:14:01.0949 5148 ============================================================
23:14:01.0949 5148 Scan started
23:14:01.0949 5148 Mode: Manual;
23:14:01.0949 5148 ============================================================
23:14:02.0534 5148 ================ Scan system memory ========================
23:14:02.0534 5148 System memory - ok
23:14:02.0534 5148 ================ Scan services =============================
23:14:02.0662 5148 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
23:14:02.0662 5148 1394ohci - ok
23:14:02.0678 5148 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys
23:14:02.0678 5148 3ware - ok
23:14:02.0725 5148 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys
23:14:02.0725 5148 ACPI - ok
23:14:02.0740 5148 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys
23:14:02.0740 5148 acpiex - ok
23:14:02.0756 5148 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
23:14:02.0756 5148 acpipagr - ok
23:14:02.0756 5148 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
23:14:02.0756 5148 AcpiPmi - ok
23:14:02.0772 5148 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys
23:14:02.0772 5148 acpitime - ok
23:14:02.0838 5148 [ 3109B16A0939BA11696EEB04F345D099 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
23:14:02.0854 5148 AdobeFlashPlayerUpdateSvc - ok
23:14:02.0870 5148 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
23:14:02.0885 5148 adp94xx - ok
23:14:02.0916 5148 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys
23:14:02.0916 5148 adpahci - ok
23:14:02.0916 5148 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
23:14:02.0916 5148 adpu320 - ok
23:14:02.0963 5148 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
23:14:02.0963 5148 AeLookupSvc - ok
23:14:02.0994 5148 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD C:\Windows\system32\drivers\afd.sys
23:14:02.0994 5148 AFD - ok
23:14:03.0010 5148 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys
23:14:03.0010 5148 agp440 - ok
23:14:03.0026 5148 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe
23:14:03.0041 5148 ALG - ok
23:14:03.0041 5148 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
23:14:03.0041 5148 AllUserInstallAgent - ok
23:14:03.0072 5148 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
23:14:03.0072 5148 AmdK8 - ok
23:14:03.0104 5148 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
23:14:03.0104 5148 AmdPPM - ok
23:14:03.0104 5148 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys
23:14:03.0119 5148 amdsata - ok
23:14:03.0135 5148 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
23:14:03.0135 5148 amdsbs - ok
23:14:03.0135 5148 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys
23:14:03.0135 5148 amdxata - ok
23:14:03.0150 5148 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys
23:14:03.0150 5148 AppID - ok
23:14:03.0166 5148 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll
23:14:03.0166 5148 AppIDSvc - ok
23:14:03.0182 5148 [ 4F750B7EFCB6520AE01E01D082D7D476 ] Appinfo C:\Windows\System32\appinfo.dll
23:14:03.0182 5148 Appinfo - ok
23:14:03.0182 5148 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys
23:14:03.0182 5148 arc - ok
23:14:03.0197 5148 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys
23:14:03.0197 5148 arcsas - ok
23:14:03.0197 5148 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
23:14:03.0197 5148 AsyncMac - ok
23:14:03.0213 5148 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys
23:14:03.0213 5148 atapi - ok
23:14:03.0228 5148 [ BCD7A47EF587DC00DD61D12D9C2D1E44 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
23:14:03.0228 5148 AudioEndpointBuilder - ok
23:14:03.0260 5148 [ 599B3F685A263A114FFAF3BE29C49C75 ] Audiosrv C:\Windows\System32\Audiosrv.dll
23:14:03.0260 5148 Audiosrv - ok
23:14:03.0275 5148 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll
23:14:03.0291 5148 AxInstSV - ok
23:14:03.0306 5148 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
23:14:03.0306 5148 b06bdrv - ok
23:14:03.0323 5148 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
23:14:03.0323 5148 BasicDisplay - ok
23:14:03.0323 5148 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
23:14:03.0323 5148 BasicRender - ok
23:14:03.0355 5148 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll
23:14:03.0355 5148 BDESVC - ok
23:14:03.0370 5148 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys
23:14:03.0370 5148 Beep - ok
23:14:03.0401 5148 [ 73133A0C0CA63817BFF2CB9DE65B64E7 ] BFE C:\Windows\System32\bfe.dll
23:14:03.0401 5148 BFE - ok
23:14:03.0448 5148 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll
23:14:03.0464 5148 BITS - ok
23:14:03.0479 5148 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys
23:14:03.0479 5148 bowser - ok
23:14:03.0511 5148 [ 038FA1B55531E7020DB705B42FCCE373 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
23:14:03.0526 5148 BrokerInfrastructure - ok
23:14:03.0542 5148 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll
23:14:03.0542 5148 Browser - ok
23:14:03.0573 5148 [ 6695200F455E251F0BCC9CE4D0978D59 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
23:14:03.0573 5148 BthAvrcpTg - ok
23:14:03.0573 5148 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
23:14:03.0573 5148 BthHFEnum - ok
23:14:03.0601 5148 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
23:14:03.0601 5148 bthhfhid - ok
23:14:03.0617 5148 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
23:14:03.0617 5148 BTHMODEM - ok
23:14:03.0633 5148 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll
23:14:03.0633 5148 bthserv - ok
23:14:03.0648 5148 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
23:14:03.0648 5148 cdfs - ok
23:14:03.0664 5148 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys
23:14:03.0664 5148 cdrom - ok
23:14:03.0679 5148 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll
23:14:03.0679 5148 CertPropSvc - ok
23:14:03.0695 5148 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys
23:14:03.0695 5148 circlass - ok
23:14:03.0711 5148 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys
23:14:03.0711 5148 CLFS - ok
23:14:03.0726 5148 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
23:14:03.0726 5148 CmBatt - ok
23:14:03.0773 5148 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys
23:14:03.0773 5148 CNG - ok
23:14:03.0789 5148 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
23:14:03.0789 5148 CompositeBus - ok
23:14:03.0804 5148 COMSysApp - ok
23:14:03.0804 5148 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys
23:14:03.0804 5148 condrv - ok
23:14:03.0837 5148 [ 5CE2742F063731EC10C1B2EE386A2C08 ] CryptSvc C:\Windows\system32\cryptsvc.dll
23:14:03.0839 5148 CryptSvc - ok
23:14:03.0854 5148 [ FAEF4C245BE832DB41B15DAAC336AFB7 ] dam C:\Windows\system32\drivers\dam.sys
23:14:03.0854 5148 dam - ok
23:14:03.0901 5148 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll
23:14:03.0901 5148 DcomLaunch - ok
23:14:03.0917 5148 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\Windows\System32\defragsvc.dll
23:14:03.0917 5148 defragsvc - ok
23:14:03.0932 5148 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
23:14:03.0932 5148 DeviceAssociationService - ok
23:14:03.0963 5148 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
23:14:03.0963 5148 DeviceInstall - ok
23:14:03.0979 5148 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
23:14:03.0979 5148 Dfsc - ok
23:14:04.0010 5148 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll
23:14:04.0010 5148 Dhcp - ok
23:14:04.0026 5148 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys
23:14:04.0026 5148 discache - ok
23:14:04.0051 5148 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\Windows\system32\drivers\disk.sys
23:14:04.0051 5148 disk - ok
23:14:04.0067 5148 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
23:14:04.0067 5148 dmvsc - ok
23:14:04.0082 5148 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll
23:14:04.0082 5148 Dnscache - ok
23:14:04.0098 5148 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll
23:14:04.0098 5148 dot3svc - ok
23:14:04.0113 5148 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll
23:14:04.0113 5148 DPS - ok
23:14:04.0145 5148 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
23:14:04.0145 5148 drmkaud - ok
23:14:04.0160 5148 [ F87F4AAAF6664906248D11D5E579A53B ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
23:14:04.0160 5148 DsmSvc - ok
23:14:04.0207 5148 [ 6D1B8A9A2C0BD4851D8AF1AB43E67AD9 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
23:14:04.0207 5148 DXGKrnl - ok
23:14:04.0223 5148 EagleX64 - ok
23:14:04.0238 5148 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll
23:14:04.0238 5148 Eaphost - ok
23:14:04.0301 5148 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys
23:14:04.0316 5148 ebdrv - ok
23:14:04.0347 5148 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe
23:14:04.0347 5148 EFS - ok
23:14:04.0347 5148 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
23:14:04.0347 5148 EhStorClass - ok
23:14:04.0363 5148 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
23:14:04.0363 5148 EhStorTcgDrv - ok
23:14:04.0379 5148 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys
23:14:04.0379 5148 ErrDev - ok
23:14:04.0410 5148 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll
23:14:04.0410 5148 EventSystem - ok
23:14:04.0425 5148 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys
23:14:04.0425 5148 exfat - ok
23:14:04.0441 5148 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys
23:14:04.0441 5148 fastfat - ok
23:14:04.0457 5148 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe
23:14:04.0474 5148 Fax - ok
23:14:04.0474 5148 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys
23:14:04.0474 5148 fdc - ok
23:14:04.0489 5148 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll
23:14:04.0489 5148 fdPHost - ok
23:14:04.0489 5148 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll
23:14:04.0505 5148 FDResPub - ok
23:14:04.0520 5148 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll
23:14:04.0520 5148 fhsvc - ok
23:14:04.0536 5148 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
23:14:04.0536 5148 FileInfo - ok
23:14:04.0536 5148 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
23:14:04.0536 5148 Filetrace - ok
23:14:04.0552 5148 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
23:14:04.0552 5148 flpydisk - ok
23:14:04.0567 5148 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
23:14:04.0567 5148 FltMgr - ok
23:14:04.0598 5148 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll
23:14:04.0614 5148 FontCache - ok
23:14:04.0676 5148 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
23:14:04.0676 5148 FontCache3.0.0.0 - ok
23:14:04.0692 5148 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
23:14:04.0692 5148 FsDepends - ok
23:14:04.0708 5148 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
23:14:04.0708 5148 Fs_Rec - ok
23:14:04.0739 5148 [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
23:14:04.0739 5148 fvevol - ok
23:14:04.0754 5148 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
23:14:04.0770 5148 FxPPM - ok
23:14:04.0786 5148 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
23:14:04.0786 5148 gagp30kx - ok
23:14:04.0801 5148 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
23:14:04.0817 5148 gencounter - ok
23:14:04.0832 5148 [ FC2B8B06BDBD3B6457F5A3DA9AD2410E ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
23:14:04.0832 5148 GPIOClx0101 - ok
23:14:04.0868 5148 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll
23:14:04.0899 5148 gpsvc - ok
23:14:04.0961 5148 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:14:04.0961 5148 gupdate - ok
23:14:04.0961 5148 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:14:04.0961 5148 gupdatem - ok
23:14:04.0992 5148 [ 630555943E5A3FE21010CE91EC7FC84F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
23:14:05.0008 5148 HdAudAddService - ok
23:14:05.0008 5148 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
23:14:05.0008 5148 HDAudBus - ok
23:14:05.0024 5148 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
23:14:05.0024 5148 HidBatt - ok
23:14:05.0039 5148 [ 085F150D002B7F0153D3C06DDF33A143 ] HidBth C:\Windows\System32\drivers\hidbth.sys
23:14:05.0039 5148 HidBth - ok
23:14:05.0070 5148 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
23:14:05.0070 5148 hidi2c - ok
23:14:05.0086 5148 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys
23:14:05.0086 5148 HidIr - ok
23:14:05.0086 5148 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\system32\hidserv.dll
23:14:05.0102 5148 hidserv - ok
23:14:05.0102 5148 [ 9E11EE0F2E117B2D5A835B2B91752827 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
23:14:05.0102 5148 HidUsb - ok
23:14:05.0133 5148 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll
23:14:05.0133 5148 hkmsvc - ok
23:14:05.0164 5148 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
23:14:05.0180 5148 HomeGroupListener - ok
23:14:05.0195 5148 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
23:14:05.0211 5148 HomeGroupProvider - ok
23:14:05.0211 5148 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
23:14:05.0211 5148 HpSAMD - ok
23:14:05.0258 5148 [ F4A91D985EB9D1D2717D538F3424603C ] HTTP C:\Windows\system32\drivers\HTTP.sys
23:14:05.0258 5148 HTTP - ok
23:14:05.0289 5148 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
23:14:05.0289 5148 hwpolicy - ok
23:14:05.0304 5148 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
23:14:05.0304 5148 hyperkbd - ok
23:14:05.0304 5148 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
23:14:05.0304 5148 HyperVideo - ok
23:14:05.0320 5148 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
23:14:05.0320 5148 i8042prt - ok
23:14:05.0336 5148 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
23:14:05.0336 5148 iaStorV - ok
23:14:05.0524 5148 [ E5272DDF2C9043411809171715B4633D ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
23:14:05.0602 5148 igfx - ok
23:14:05.0602 5148 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys
23:14:05.0602 5148 iirsp - ok
23:14:05.0633 5148 [ 3884117CE4FEC35E4A1A7A62918B1F34 ] IKEEXT C:\Windows\System32\ikeext.dll
23:14:05.0649 5148 IKEEXT - ok
23:14:05.0711 5148 [ 059DDDEDBE5701DC3B779D32798108AC ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
23:14:05.0727 5148 IntcAzAudAddService - ok
23:14:05.0742 5148 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys
23:14:05.0742 5148 intelide - ok
23:14:05.0742 5148 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys
23:14:05.0742 5148 intelppm - ok
23:14:05.0758 5148 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
23:14:05.0758 5148 IpFilterDriver - ok
23:14:05.0805 5148 [ C217B8D2E58C57A319B16125C3D4B69C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
23:14:05.0805 5148 iphlpsvc - ok
23:14:05.0805 5148 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
23:14:05.0820 5148 IPMIDRV - ok
23:14:05.0820 5148 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
23:14:05.0820 5148 IPNAT - ok
23:14:05.0820 5148 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys
23:14:05.0820 5148 IRENUM - ok
23:14:05.0836 5148 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
23:14:05.0836 5148 isapnp - ok
23:14:05.0852 5148 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
23:14:05.0852 5148 iScsiPrt - ok
23:14:05.0867 5148 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
23:14:05.0867 5148 kbdclass - ok
23:14:05.0867 5148 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
23:14:05.0867 5148 kbdhid - ok
23:14:05.0896 5148 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
23:14:05.0896 5148 kdnic - ok
23:14:05.0896 5148 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe
23:14:05.0896 5148 KeyIso - ok
23:14:05.0932 5148 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
23:14:05.0932 5148 KSecDD - ok
23:14:05.0947 5148 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
23:14:05.0947 5148 KSecPkg - ok
23:14:05.0963 5148 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
23:14:05.0963 5148 ksthunk - ok
23:14:05.0981 5148 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll
23:14:05.0981 5148 KtmRm - ok
23:14:05.0996 5148 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\system32\srvsvc.dll
23:14:06.0012 5148 LanmanServer - ok
23:14:06.0028 5148 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
23:14:06.0028 5148 LanmanWorkstation - ok
23:14:06.0043 5148 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
23:14:06.0043 5148 lltdio - ok
23:14:06.0059 5148 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll
23:14:06.0059 5148 lltdsvc - ok
23:14:06.0078 5148 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll
23:14:06.0078 5148 lmhosts - ok
23:14:06.0094 5148 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
23:14:06.0094 5148 LSI_SAS - ok
23:14:06.0094 5148 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
23:14:06.0094 5148 LSI_SAS2 - ok
23:14:06.0110 5148 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
23:14:06.0110 5148 LSI_SCSI - ok
23:14:06.0110 5148 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
23:14:06.0110 5148 LSI_SSS - ok
23:14:06.0125 5148 [ A57BA284F5996FFD32DCDBC41A4657DB ] LSM C:\Windows\System32\lsm.dll
23:14:06.0141 5148 LSM - ok
23:14:06.0157 5148 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys
23:14:06.0157 5148 luafv - ok
23:14:06.0172 5148 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
23:14:06.0172 5148 MBAMProtector - ok
23:14:06.0219 5148 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
23:14:06.0219 5148 MBAMScheduler - ok
23:14:06.0250 5148 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
23:14:06.0266 5148 MBAMService - ok
23:14:06.0281 5148 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys
23:14:06.0281 5148 megasas - ok
23:14:06.0297 5148 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
23:14:06.0297 5148 MegaSR - ok
23:14:06.0328 5148 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
23:14:06.0328 5148 MMCSS - ok
23:14:06.0328 5148 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
23:14:06.0328 5148 Modem - ok
23:14:06.0354 5148 [ EA8EAD3F5B762F889CC7F3966625B48B ] monitor C:\Windows\System32\drivers\monitor.sys
23:14:06.0354 5148 monitor - ok
23:14:06.0354 5148 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
23:14:06.0369 5148 mouclass - ok
23:14:06.0385 5148 [ C0ADEBED913295803B579ED288936CBB ] mouhid C:\Windows\System32\drivers\mouhid.sys
23:14:06.0385 5148 mouhid - ok
23:14:06.0401 5148 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
23:14:06.0401 5148 mountmgr - ok
23:14:06.0432 5148 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
23:14:06.0432 5148 mpsdrv - ok
23:14:06.0463 5148 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll
23:14:06.0494 5148 MpsSvc - ok
23:14:06.0494 5148 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
23:14:06.0494 5148 MRxDAV - ok
23:14:06.0525 5148 [ 93179D48066918323628CB016D8C94DC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
23:14:06.0525 5148 mrxsmb - ok
23:14:06.0557 5148 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
23:14:06.0557 5148 mrxsmb10 - ok
23:14:06.0588 5148 [ 5C7DD2E5759FFCCD2C7341C1B90F2B26 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
23:14:06.0603 5148 mrxsmb20 - ok
23:14:06.0619 5148 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
23:14:06.0619 5148 MsBridge - ok
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : byt [Práva správce]
Mód : Odebrat -- Datum : 09/26/2013 23:09:06
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD10EZEX-00RKKA0 +++++
--- User ---
[MBR] 124544447642830df46e584b23ee1d95
[BSP] 153fbedc6169cdc8a9a9eefe1f86713e : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 411648 | Size: 953667 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_09262013_230906.txt >>
RKreport[0]_S_09262013_230858.txt
23:13:58.0886 4008 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
23:13:59.0058 4008 ============================================================
23:13:59.0058 4008 Current date / time: 2013/09/26 23:13:59.0058
23:13:59.0058 4008 SystemInfo:
23:13:59.0058 4008
23:13:59.0058 4008 OS Version: 6.2.9200 ServicePack: 0.0
23:13:59.0058 4008 Product type: Workstation
23:13:59.0058 4008 ComputerName: RODINA
23:13:59.0058 4008 UserName: byt
23:13:59.0058 4008 Windows directory: C:\Windows
23:13:59.0058 4008 System windows directory: C:\Windows
23:13:59.0058 4008 Running under WOW64
23:13:59.0058 4008 Processor architecture: Intel x64
23:13:59.0058 4008 Number of processors: 4
23:13:59.0058 4008 Page size: 0x1000
23:13:59.0058 4008 Boot type: Normal boot
23:13:59.0058 4008 ============================================================
23:13:59.0573 4008 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:13:59.0573 4008 ============================================================
23:13:59.0573 4008 \Device\Harddisk0\DR0:
23:13:59.0573 4008 MBR partitions:
23:13:59.0573 4008 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x64000
23:13:59.0573 4008 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x746A1800
23:13:59.0573 4008 ============================================================
23:13:59.0590 4008 C: <-> \Device\Harddisk0\DR0\Partition2
23:13:59.0590 4008 ============================================================
23:13:59.0590 4008 Initialize success
23:13:59.0590 4008 ============================================================
23:14:01.0949 5148 ============================================================
23:14:01.0949 5148 Scan started
23:14:01.0949 5148 Mode: Manual;
23:14:01.0949 5148 ============================================================
23:14:02.0534 5148 ================ Scan system memory ========================
23:14:02.0534 5148 System memory - ok
23:14:02.0534 5148 ================ Scan services =============================
23:14:02.0662 5148 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
23:14:02.0662 5148 1394ohci - ok
23:14:02.0678 5148 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys
23:14:02.0678 5148 3ware - ok
23:14:02.0725 5148 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys
23:14:02.0725 5148 ACPI - ok
23:14:02.0740 5148 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys
23:14:02.0740 5148 acpiex - ok
23:14:02.0756 5148 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
23:14:02.0756 5148 acpipagr - ok
23:14:02.0756 5148 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
23:14:02.0756 5148 AcpiPmi - ok
23:14:02.0772 5148 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys
23:14:02.0772 5148 acpitime - ok
23:14:02.0838 5148 [ 3109B16A0939BA11696EEB04F345D099 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
23:14:02.0854 5148 AdobeFlashPlayerUpdateSvc - ok
23:14:02.0870 5148 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
23:14:02.0885 5148 adp94xx - ok
23:14:02.0916 5148 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys
23:14:02.0916 5148 adpahci - ok
23:14:02.0916 5148 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
23:14:02.0916 5148 adpu320 - ok
23:14:02.0963 5148 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
23:14:02.0963 5148 AeLookupSvc - ok
23:14:02.0994 5148 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD C:\Windows\system32\drivers\afd.sys
23:14:02.0994 5148 AFD - ok
23:14:03.0010 5148 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys
23:14:03.0010 5148 agp440 - ok
23:14:03.0026 5148 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe
23:14:03.0041 5148 ALG - ok
23:14:03.0041 5148 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
23:14:03.0041 5148 AllUserInstallAgent - ok
23:14:03.0072 5148 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
23:14:03.0072 5148 AmdK8 - ok
23:14:03.0104 5148 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
23:14:03.0104 5148 AmdPPM - ok
23:14:03.0104 5148 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys
23:14:03.0119 5148 amdsata - ok
23:14:03.0135 5148 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
23:14:03.0135 5148 amdsbs - ok
23:14:03.0135 5148 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys
23:14:03.0135 5148 amdxata - ok
23:14:03.0150 5148 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys
23:14:03.0150 5148 AppID - ok
23:14:03.0166 5148 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll
23:14:03.0166 5148 AppIDSvc - ok
23:14:03.0182 5148 [ 4F750B7EFCB6520AE01E01D082D7D476 ] Appinfo C:\Windows\System32\appinfo.dll
23:14:03.0182 5148 Appinfo - ok
23:14:03.0182 5148 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys
23:14:03.0182 5148 arc - ok
23:14:03.0197 5148 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys
23:14:03.0197 5148 arcsas - ok
23:14:03.0197 5148 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
23:14:03.0197 5148 AsyncMac - ok
23:14:03.0213 5148 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys
23:14:03.0213 5148 atapi - ok
23:14:03.0228 5148 [ BCD7A47EF587DC00DD61D12D9C2D1E44 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
23:14:03.0228 5148 AudioEndpointBuilder - ok
23:14:03.0260 5148 [ 599B3F685A263A114FFAF3BE29C49C75 ] Audiosrv C:\Windows\System32\Audiosrv.dll
23:14:03.0260 5148 Audiosrv - ok
23:14:03.0275 5148 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll
23:14:03.0291 5148 AxInstSV - ok
23:14:03.0306 5148 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
23:14:03.0306 5148 b06bdrv - ok
23:14:03.0323 5148 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
23:14:03.0323 5148 BasicDisplay - ok
23:14:03.0323 5148 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
23:14:03.0323 5148 BasicRender - ok
23:14:03.0355 5148 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll
23:14:03.0355 5148 BDESVC - ok
23:14:03.0370 5148 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys
23:14:03.0370 5148 Beep - ok
23:14:03.0401 5148 [ 73133A0C0CA63817BFF2CB9DE65B64E7 ] BFE C:\Windows\System32\bfe.dll
23:14:03.0401 5148 BFE - ok
23:14:03.0448 5148 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll
23:14:03.0464 5148 BITS - ok
23:14:03.0479 5148 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys
23:14:03.0479 5148 bowser - ok
23:14:03.0511 5148 [ 038FA1B55531E7020DB705B42FCCE373 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
23:14:03.0526 5148 BrokerInfrastructure - ok
23:14:03.0542 5148 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll
23:14:03.0542 5148 Browser - ok
23:14:03.0573 5148 [ 6695200F455E251F0BCC9CE4D0978D59 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
23:14:03.0573 5148 BthAvrcpTg - ok
23:14:03.0573 5148 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
23:14:03.0573 5148 BthHFEnum - ok
23:14:03.0601 5148 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
23:14:03.0601 5148 bthhfhid - ok
23:14:03.0617 5148 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
23:14:03.0617 5148 BTHMODEM - ok
23:14:03.0633 5148 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll
23:14:03.0633 5148 bthserv - ok
23:14:03.0648 5148 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
23:14:03.0648 5148 cdfs - ok
23:14:03.0664 5148 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys
23:14:03.0664 5148 cdrom - ok
23:14:03.0679 5148 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll
23:14:03.0679 5148 CertPropSvc - ok
23:14:03.0695 5148 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys
23:14:03.0695 5148 circlass - ok
23:14:03.0711 5148 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys
23:14:03.0711 5148 CLFS - ok
23:14:03.0726 5148 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
23:14:03.0726 5148 CmBatt - ok
23:14:03.0773 5148 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys
23:14:03.0773 5148 CNG - ok
23:14:03.0789 5148 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
23:14:03.0789 5148 CompositeBus - ok
23:14:03.0804 5148 COMSysApp - ok
23:14:03.0804 5148 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys
23:14:03.0804 5148 condrv - ok
23:14:03.0837 5148 [ 5CE2742F063731EC10C1B2EE386A2C08 ] CryptSvc C:\Windows\system32\cryptsvc.dll
23:14:03.0839 5148 CryptSvc - ok
23:14:03.0854 5148 [ FAEF4C245BE832DB41B15DAAC336AFB7 ] dam C:\Windows\system32\drivers\dam.sys
23:14:03.0854 5148 dam - ok
23:14:03.0901 5148 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll
23:14:03.0901 5148 DcomLaunch - ok
23:14:03.0917 5148 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\Windows\System32\defragsvc.dll
23:14:03.0917 5148 defragsvc - ok
23:14:03.0932 5148 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
23:14:03.0932 5148 DeviceAssociationService - ok
23:14:03.0963 5148 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
23:14:03.0963 5148 DeviceInstall - ok
23:14:03.0979 5148 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
23:14:03.0979 5148 Dfsc - ok
23:14:04.0010 5148 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll
23:14:04.0010 5148 Dhcp - ok
23:14:04.0026 5148 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys
23:14:04.0026 5148 discache - ok
23:14:04.0051 5148 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\Windows\system32\drivers\disk.sys
23:14:04.0051 5148 disk - ok
23:14:04.0067 5148 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
23:14:04.0067 5148 dmvsc - ok
23:14:04.0082 5148 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll
23:14:04.0082 5148 Dnscache - ok
23:14:04.0098 5148 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll
23:14:04.0098 5148 dot3svc - ok
23:14:04.0113 5148 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll
23:14:04.0113 5148 DPS - ok
23:14:04.0145 5148 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
23:14:04.0145 5148 drmkaud - ok
23:14:04.0160 5148 [ F87F4AAAF6664906248D11D5E579A53B ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
23:14:04.0160 5148 DsmSvc - ok
23:14:04.0207 5148 [ 6D1B8A9A2C0BD4851D8AF1AB43E67AD9 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
23:14:04.0207 5148 DXGKrnl - ok
23:14:04.0223 5148 EagleX64 - ok
23:14:04.0238 5148 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll
23:14:04.0238 5148 Eaphost - ok
23:14:04.0301 5148 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys
23:14:04.0316 5148 ebdrv - ok
23:14:04.0347 5148 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe
23:14:04.0347 5148 EFS - ok
23:14:04.0347 5148 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
23:14:04.0347 5148 EhStorClass - ok
23:14:04.0363 5148 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
23:14:04.0363 5148 EhStorTcgDrv - ok
23:14:04.0379 5148 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys
23:14:04.0379 5148 ErrDev - ok
23:14:04.0410 5148 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll
23:14:04.0410 5148 EventSystem - ok
23:14:04.0425 5148 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys
23:14:04.0425 5148 exfat - ok
23:14:04.0441 5148 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys
23:14:04.0441 5148 fastfat - ok
23:14:04.0457 5148 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe
23:14:04.0474 5148 Fax - ok
23:14:04.0474 5148 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys
23:14:04.0474 5148 fdc - ok
23:14:04.0489 5148 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll
23:14:04.0489 5148 fdPHost - ok
23:14:04.0489 5148 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll
23:14:04.0505 5148 FDResPub - ok
23:14:04.0520 5148 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll
23:14:04.0520 5148 fhsvc - ok
23:14:04.0536 5148 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
23:14:04.0536 5148 FileInfo - ok
23:14:04.0536 5148 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
23:14:04.0536 5148 Filetrace - ok
23:14:04.0552 5148 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
23:14:04.0552 5148 flpydisk - ok
23:14:04.0567 5148 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
23:14:04.0567 5148 FltMgr - ok
23:14:04.0598 5148 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll
23:14:04.0614 5148 FontCache - ok
23:14:04.0676 5148 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
23:14:04.0676 5148 FontCache3.0.0.0 - ok
23:14:04.0692 5148 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
23:14:04.0692 5148 FsDepends - ok
23:14:04.0708 5148 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
23:14:04.0708 5148 Fs_Rec - ok
23:14:04.0739 5148 [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
23:14:04.0739 5148 fvevol - ok
23:14:04.0754 5148 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
23:14:04.0770 5148 FxPPM - ok
23:14:04.0786 5148 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
23:14:04.0786 5148 gagp30kx - ok
23:14:04.0801 5148 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
23:14:04.0817 5148 gencounter - ok
23:14:04.0832 5148 [ FC2B8B06BDBD3B6457F5A3DA9AD2410E ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
23:14:04.0832 5148 GPIOClx0101 - ok
23:14:04.0868 5148 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll
23:14:04.0899 5148 gpsvc - ok
23:14:04.0961 5148 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:14:04.0961 5148 gupdate - ok
23:14:04.0961 5148 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:14:04.0961 5148 gupdatem - ok
23:14:04.0992 5148 [ 630555943E5A3FE21010CE91EC7FC84F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
23:14:05.0008 5148 HdAudAddService - ok
23:14:05.0008 5148 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
23:14:05.0008 5148 HDAudBus - ok
23:14:05.0024 5148 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
23:14:05.0024 5148 HidBatt - ok
23:14:05.0039 5148 [ 085F150D002B7F0153D3C06DDF33A143 ] HidBth C:\Windows\System32\drivers\hidbth.sys
23:14:05.0039 5148 HidBth - ok
23:14:05.0070 5148 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
23:14:05.0070 5148 hidi2c - ok
23:14:05.0086 5148 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys
23:14:05.0086 5148 HidIr - ok
23:14:05.0086 5148 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\system32\hidserv.dll
23:14:05.0102 5148 hidserv - ok
23:14:05.0102 5148 [ 9E11EE0F2E117B2D5A835B2B91752827 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
23:14:05.0102 5148 HidUsb - ok
23:14:05.0133 5148 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll
23:14:05.0133 5148 hkmsvc - ok
23:14:05.0164 5148 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
23:14:05.0180 5148 HomeGroupListener - ok
23:14:05.0195 5148 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
23:14:05.0211 5148 HomeGroupProvider - ok
23:14:05.0211 5148 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
23:14:05.0211 5148 HpSAMD - ok
23:14:05.0258 5148 [ F4A91D985EB9D1D2717D538F3424603C ] HTTP C:\Windows\system32\drivers\HTTP.sys
23:14:05.0258 5148 HTTP - ok
23:14:05.0289 5148 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
23:14:05.0289 5148 hwpolicy - ok
23:14:05.0304 5148 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
23:14:05.0304 5148 hyperkbd - ok
23:14:05.0304 5148 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
23:14:05.0304 5148 HyperVideo - ok
23:14:05.0320 5148 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
23:14:05.0320 5148 i8042prt - ok
23:14:05.0336 5148 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
23:14:05.0336 5148 iaStorV - ok
23:14:05.0524 5148 [ E5272DDF2C9043411809171715B4633D ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
23:14:05.0602 5148 igfx - ok
23:14:05.0602 5148 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys
23:14:05.0602 5148 iirsp - ok
23:14:05.0633 5148 [ 3884117CE4FEC35E4A1A7A62918B1F34 ] IKEEXT C:\Windows\System32\ikeext.dll
23:14:05.0649 5148 IKEEXT - ok
23:14:05.0711 5148 [ 059DDDEDBE5701DC3B779D32798108AC ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
23:14:05.0727 5148 IntcAzAudAddService - ok
23:14:05.0742 5148 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys
23:14:05.0742 5148 intelide - ok
23:14:05.0742 5148 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys
23:14:05.0742 5148 intelppm - ok
23:14:05.0758 5148 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
23:14:05.0758 5148 IpFilterDriver - ok
23:14:05.0805 5148 [ C217B8D2E58C57A319B16125C3D4B69C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
23:14:05.0805 5148 iphlpsvc - ok
23:14:05.0805 5148 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
23:14:05.0820 5148 IPMIDRV - ok
23:14:05.0820 5148 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
23:14:05.0820 5148 IPNAT - ok
23:14:05.0820 5148 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys
23:14:05.0820 5148 IRENUM - ok
23:14:05.0836 5148 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
23:14:05.0836 5148 isapnp - ok
23:14:05.0852 5148 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
23:14:05.0852 5148 iScsiPrt - ok
23:14:05.0867 5148 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
23:14:05.0867 5148 kbdclass - ok
23:14:05.0867 5148 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
23:14:05.0867 5148 kbdhid - ok
23:14:05.0896 5148 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
23:14:05.0896 5148 kdnic - ok
23:14:05.0896 5148 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe
23:14:05.0896 5148 KeyIso - ok
23:14:05.0932 5148 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
23:14:05.0932 5148 KSecDD - ok
23:14:05.0947 5148 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
23:14:05.0947 5148 KSecPkg - ok
23:14:05.0963 5148 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
23:14:05.0963 5148 ksthunk - ok
23:14:05.0981 5148 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll
23:14:05.0981 5148 KtmRm - ok
23:14:05.0996 5148 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\system32\srvsvc.dll
23:14:06.0012 5148 LanmanServer - ok
23:14:06.0028 5148 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
23:14:06.0028 5148 LanmanWorkstation - ok
23:14:06.0043 5148 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
23:14:06.0043 5148 lltdio - ok
23:14:06.0059 5148 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll
23:14:06.0059 5148 lltdsvc - ok
23:14:06.0078 5148 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll
23:14:06.0078 5148 lmhosts - ok
23:14:06.0094 5148 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
23:14:06.0094 5148 LSI_SAS - ok
23:14:06.0094 5148 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
23:14:06.0094 5148 LSI_SAS2 - ok
23:14:06.0110 5148 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
23:14:06.0110 5148 LSI_SCSI - ok
23:14:06.0110 5148 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
23:14:06.0110 5148 LSI_SSS - ok
23:14:06.0125 5148 [ A57BA284F5996FFD32DCDBC41A4657DB ] LSM C:\Windows\System32\lsm.dll
23:14:06.0141 5148 LSM - ok
23:14:06.0157 5148 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys
23:14:06.0157 5148 luafv - ok
23:14:06.0172 5148 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
23:14:06.0172 5148 MBAMProtector - ok
23:14:06.0219 5148 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
23:14:06.0219 5148 MBAMScheduler - ok
23:14:06.0250 5148 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
23:14:06.0266 5148 MBAMService - ok
23:14:06.0281 5148 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys
23:14:06.0281 5148 megasas - ok
23:14:06.0297 5148 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
23:14:06.0297 5148 MegaSR - ok
23:14:06.0328 5148 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
23:14:06.0328 5148 MMCSS - ok
23:14:06.0328 5148 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
23:14:06.0328 5148 Modem - ok
23:14:06.0354 5148 [ EA8EAD3F5B762F889CC7F3966625B48B ] monitor C:\Windows\System32\drivers\monitor.sys
23:14:06.0354 5148 monitor - ok
23:14:06.0354 5148 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
23:14:06.0369 5148 mouclass - ok
23:14:06.0385 5148 [ C0ADEBED913295803B579ED288936CBB ] mouhid C:\Windows\System32\drivers\mouhid.sys
23:14:06.0385 5148 mouhid - ok
23:14:06.0401 5148 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
23:14:06.0401 5148 mountmgr - ok
23:14:06.0432 5148 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
23:14:06.0432 5148 mpsdrv - ok
23:14:06.0463 5148 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll
23:14:06.0494 5148 MpsSvc - ok
23:14:06.0494 5148 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
23:14:06.0494 5148 MRxDAV - ok
23:14:06.0525 5148 [ 93179D48066918323628CB016D8C94DC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
23:14:06.0525 5148 mrxsmb - ok
23:14:06.0557 5148 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
23:14:06.0557 5148 mrxsmb10 - ok
23:14:06.0588 5148 [ 5C7DD2E5759FFCCD2C7341C1B90F2B26 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
23:14:06.0603 5148 mrxsmb20 - ok
23:14:06.0619 5148 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
23:14:06.0619 5148 MsBridge - ok
Re: Windows Script Hosts - kontrola logu HJT
23:14:06.0619 5148 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe
23:14:06.0635 5148 MSDTC - ok
23:14:06.0650 5148 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
23:14:06.0650 5148 Msfs - ok
23:14:06.0666 5148 [ C32A7A39B960A42BA9D4FBE47213CA03 ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
23:14:06.0666 5148 msgpiowin32 - ok
23:14:06.0666 5148 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
23:14:06.0666 5148 mshidkmdf - ok
23:14:06.0666 5148 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
23:14:06.0666 5148 mshidumdf - ok
23:14:06.0681 5148 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
23:14:06.0681 5148 msisadrv - ok
23:14:06.0697 5148 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
23:14:06.0697 5148 MSiSCSI - ok
23:14:06.0713 5148 msiserver - ok
23:14:06.0713 5148 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
23:14:06.0713 5148 MSKSSRV - ok
23:14:06.0713 5148 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
23:14:06.0713 5148 MsLldp - ok
23:14:06.0728 5148 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
23:14:06.0728 5148 MSPCLOCK - ok
23:14:06.0731 5148 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
23:14:06.0731 5148 MSPQM - ok
23:14:06.0747 5148 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
23:14:06.0747 5148 MsRPC - ok
23:14:06.0763 5148 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
23:14:06.0763 5148 mssmbios - ok
23:14:06.0763 5148 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
23:14:06.0763 5148 MSTEE - ok
23:14:06.0763 5148 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
23:14:06.0763 5148 MTConfig - ok
23:14:06.0778 5148 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
23:14:06.0778 5148 Mup - ok
23:14:06.0794 5148 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
23:14:06.0794 5148 mvumis - ok
23:14:06.0810 5148 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
23:14:06.0810 5148 napagent - ok
23:14:06.0841 5148 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
23:14:06.0841 5148 NativeWifiP - ok
23:14:06.0856 5148 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
23:14:06.0856 5148 NcaSvc - ok
23:14:06.0872 5148 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
23:14:06.0872 5148 NcdAutoSetup - ok
23:14:06.0903 5148 [ A10E176F3B2BF83EDE7B5C4658C93B66 ] NDIS C:\Windows\system32\drivers\ndis.sys
23:14:06.0903 5148 NDIS - ok
23:14:06.0919 5148 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
23:14:06.0919 5148 NdisCap - ok
23:14:06.0934 5148 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
23:14:06.0934 5148 NdisImPlatform - ok
23:14:06.0950 5148 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
23:14:06.0950 5148 NdisTapi - ok
23:14:06.0950 5148 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
23:14:06.0950 5148 Ndisuio - ok
23:14:06.0966 5148 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
23:14:06.0966 5148 NdisWan - ok
23:14:06.0966 5148 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
23:14:06.0966 5148 NDISWANLEGACY - ok
23:14:06.0987 5148 [ 3730942D7DB2F8BB5F84542B7FF6F650 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
23:14:06.0987 5148 NDProxy - ok
23:14:06.0987 5148 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
23:14:07.0003 5148 Ndu - ok
23:14:07.0003 5148 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
23:14:07.0003 5148 NetBIOS - ok
23:14:07.0019 5148 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
23:14:07.0019 5148 NetBT - ok
23:14:07.0034 5148 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
23:14:07.0034 5148 Netlogon - ok
23:14:07.0050 5148 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
23:14:07.0050 5148 Netman - ok
23:14:07.0086 5148 [ 79FA9393C67EBBF92A56923592CF7A7C ] netprofm C:\Windows\System32\netprofmsvc.dll
23:14:07.0086 5148 netprofm - ok
23:14:07.0133 5148 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:14:07.0149 5148 NetTcpPortSharing - ok
23:14:07.0164 5148 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
23:14:07.0164 5148 nfrd960 - ok
23:14:07.0195 5148 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
23:14:07.0211 5148 NlaSvc - ok
23:14:07.0211 5148 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
23:14:07.0211 5148 Npfs - ok
23:14:07.0227 5148 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
23:14:07.0227 5148 npsvctrig - ok
23:14:07.0242 5148 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
23:14:07.0242 5148 nsi - ok
23:14:07.0258 5148 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
23:14:07.0258 5148 nsiproxy - ok
23:14:07.0305 5148 [ 76929F4A69E425911A63B407E26C2589 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
23:14:07.0336 5148 Ntfs - ok
23:14:07.0351 5148 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
23:14:07.0351 5148 Null - ok
23:14:07.0367 5148 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
23:14:07.0367 5148 NVHDA - ok
23:14:07.0556 5148 [ FCBA1C22727939E7CFF9EB08FE9692AB ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
23:14:07.0603 5148 nvlddmkm - ok
23:14:07.0618 5148 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
23:14:07.0618 5148 nvraid - ok
23:14:07.0618 5148 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
23:14:07.0634 5148 nvstor - ok
23:14:07.0650 5148 [ 84948366BDC2D86EC4316A6FCC0C8561 ] NvStUSB C:\Windows\System32\drivers\nvstusb.sys
23:14:07.0665 5148 NvStUSB - ok
23:14:07.0696 5148 [ 10C232F6CFFD51D2332898AE7AE0FF23 ] nvsvc C:\Windows\system32\nvvsvc.exe
23:14:07.0712 5148 nvsvc - ok
23:14:07.0759 5148 [ 4789E020D2617046862D1790FC235FF6 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
23:14:07.0774 5148 nvUpdatusService - ok
23:14:07.0790 5148 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
23:14:07.0790 5148 nv_agp - ok
23:14:07.0806 5148 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
23:14:07.0806 5148 p2pimsvc - ok
23:14:07.0837 5148 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
23:14:07.0837 5148 p2psvc - ok
23:14:07.0852 5148 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
23:14:07.0852 5148 Parport - ok
23:14:07.0868 5148 [ D6ACCF9F2EEEEA711C14EFD976E573F3 ] partmgr C:\Windows\system32\drivers\partmgr.sys
23:14:07.0884 5148 partmgr - ok
23:14:07.0899 5148 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
23:14:07.0915 5148 PcaSvc - ok
23:14:07.0930 5148 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
23:14:07.0930 5148 pci - ok
23:14:07.0930 5148 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
23:14:07.0930 5148 pciide - ok
23:14:07.0946 5148 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
23:14:07.0946 5148 pcmcia - ok
23:14:07.0962 5148 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
23:14:07.0962 5148 pcw - ok
23:14:07.0977 5148 [ 0698DEDEAD6A00AD0D468C687D830FBF ] pdc C:\Windows\system32\drivers\pdc.sys
23:14:07.0977 5148 pdc - ok
23:14:08.0024 5148 [ 61FE70659CD43E07F94DA4DC31DEC493 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
23:14:08.0024 5148 PEAUTH - ok
23:14:08.0102 5148 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
23:14:08.0102 5148 PerfHost - ok
23:14:08.0149 5148 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
23:14:08.0165 5148 pla - ok
23:14:08.0196 5148 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
23:14:08.0196 5148 PlugPlay - ok
23:14:08.0212 5148 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
23:14:08.0212 5148 PNRPAutoReg - ok
23:14:08.0227 5148 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
23:14:08.0227 5148 PNRPsvc - ok
23:14:08.0243 5148 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
23:14:08.0258 5148 PolicyAgent - ok
23:14:08.0286 5148 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
23:14:08.0286 5148 Power - ok
23:14:08.0301 5148 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
23:14:08.0301 5148 PptpMiniport - ok
23:14:08.0348 5148 [ 9D59831262CAD44E709D695FC9D5E7AB ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
23:14:08.0379 5148 PrintNotify - ok
23:14:08.0410 5148 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
23:14:08.0410 5148 Processor - ok
23:14:08.0426 5148 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
23:14:08.0426 5148 ProfSvc - ok
23:14:08.0445 5148 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
23:14:08.0445 5148 Psched - ok
23:14:08.0461 5148 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
23:14:08.0461 5148 QWAVE - ok
23:14:08.0477 5148 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
23:14:08.0477 5148 QWAVEdrv - ok
23:14:08.0477 5148 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
23:14:08.0477 5148 RasAcd - ok
23:14:08.0492 5148 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
23:14:08.0492 5148 RasAgileVpn - ok
23:14:08.0508 5148 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
23:14:08.0523 5148 RasAuto - ok
23:14:08.0523 5148 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
23:14:08.0523 5148 Rasl2tp - ok
23:14:08.0555 5148 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
23:14:08.0555 5148 RasMan - ok
23:14:08.0570 5148 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
23:14:08.0570 5148 RasPppoe - ok
23:14:08.0586 5148 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
23:14:08.0586 5148 RasSstp - ok
23:14:08.0617 5148 [ CA03D642ACE58E1BA54E4B383F91CD69 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
23:14:08.0617 5148 rdbss - ok
23:14:08.0648 5148 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
23:14:08.0648 5148 rdpbus - ok
23:14:08.0664 5148 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
23:14:08.0679 5148 RDPDR - ok
23:14:08.0711 5148 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
23:14:08.0711 5148 RdpVideoMiniport - ok
23:14:08.0726 5148 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
23:14:08.0726 5148 RDPWD - ok
23:14:08.0757 5148 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
23:14:08.0757 5148 rdyboost - ok
23:14:08.0757 5148 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
23:14:08.0773 5148 RemoteAccess - ok
23:14:08.0773 5148 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
23:14:08.0789 5148 RemoteRegistry - ok
23:14:08.0804 5148 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
23:14:08.0804 5148 RpcEptMapper - ok
23:14:08.0820 5148 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
23:14:08.0820 5148 RpcLocator - ok
23:14:08.0836 5148 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
23:14:08.0851 5148 RpcSs - ok
23:14:08.0851 5148 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
23:14:08.0867 5148 rspndr - ok
23:14:08.0882 5148 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys
23:14:08.0882 5148 RTL8168 - ok
23:14:08.0914 5148 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
23:14:08.0914 5148 s3cap - ok
23:14:08.0945 5148 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
23:14:08.0945 5148 SamSs - ok
23:14:08.0945 5148 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
23:14:08.0945 5148 sbp2port - ok
23:14:08.0976 5148 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
23:14:08.0976 5148 SCardSvr - ok
23:14:08.0992 5148 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
23:14:08.0992 5148 scfilter - ok
23:14:09.0023 5148 [ ED40ED9A65F3E79A8C43DD50C5FDADBF ] Schedule C:\Windows\system32\schedsvc.dll
23:14:09.0054 5148 Schedule - ok
23:14:09.0070 5148 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
23:14:09.0085 5148 SCPolicySvc - ok
23:14:09.0101 5148 [ F58B030A0664385C707B8C1C63682041 ] sdbus C:\Windows\System32\drivers\sdbus.sys
23:14:09.0101 5148 sdbus - ok
23:14:09.0117 5148 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
23:14:09.0132 5148 SDRSVC - ok
23:14:09.0148 5148 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
23:14:09.0148 5148 sdstor - ok
23:14:09.0164 5148 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
23:14:09.0164 5148 secdrv - ok
23:14:09.0179 5148 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
23:14:09.0179 5148 seclogon - ok
23:14:09.0195 5148 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll
23:14:09.0195 5148 SENS - ok
23:14:09.0210 5148 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
23:14:09.0210 5148 SensrSvc - ok
23:14:09.0226 5148 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
23:14:09.0226 5148 SerCx - ok
23:14:09.0242 5148 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
23:14:09.0242 5148 Serenum - ok
23:14:09.0263 5148 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
23:14:09.0263 5148 Serial - ok
23:14:09.0263 5148 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
23:14:09.0263 5148 sermouse - ok
23:14:09.0279 5148 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
23:14:09.0279 5148 SessionEnv - ok
23:14:09.0295 5148 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
23:14:09.0295 5148 sfloppy - ok
23:14:09.0312 5148 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
23:14:09.0319 5148 SharedAccess - ok
23:14:09.0334 5148 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
23:14:09.0350 5148 ShellHWDetection - ok
23:14:09.0350 5148 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
23:14:09.0350 5148 SiSRaid2 - ok
23:14:09.0350 5148 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
23:14:09.0350 5148 SiSRaid4 - ok
23:14:09.0381 5148 [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
23:14:09.0381 5148 SkypeUpdate - ok
23:14:09.0400 5148 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
23:14:09.0400 5148 SNMPTRAP - ok
23:14:09.0414 5148 [ FD3AF5575B99871BADB94E7699DBCE08 ] spaceport C:\Windows\system32\drivers\spaceport.sys
23:14:09.0414 5148 spaceport - ok
23:14:09.0429 5148 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
23:14:09.0429 5148 SpbCx - ok
23:14:09.0445 5148 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
23:14:09.0445 5148 Spooler - ok
23:14:09.0516 5148 [ 061A977C920FBE4BF71FF47C966DDDCA ] sppsvc C:\Windows\system32\sppsvc.exe
23:14:09.0548 5148 sppsvc - ok
23:14:09.0563 5148 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\Windows\system32\DRIVERS\srv.sys
23:14:09.0563 5148 srv - ok
23:14:09.0594 5148 [ 56218A571ECF8D55E0CDFF8DF2546CF1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
23:14:09.0594 5148 srv2 - ok
23:14:09.0626 5148 [ 14FC338B80CFF7E04215133B568D15C4 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
23:14:09.0626 5148 srvnet - ok
23:14:09.0641 5148 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
23:14:09.0657 5148 SSDPSRV - ok
23:14:09.0672 5148 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\Windows\system32\sstpsvc.dll
23:14:09.0672 5148 SstpSvc - ok
23:14:09.0719 5148 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
23:14:09.0719 5148 Stereo Service - ok
23:14:09.0735 5148 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\Windows\system32\drivers\stexstor.sys
23:14:09.0735 5148 stexstor - ok
23:14:09.0766 5148 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\Windows\System32\wiaservc.dll
23:14:09.0782 5148 stisvc - ok
23:14:09.0813 5148 [ B240874B2CA0CD02E8CD11E140B14C57 ] storahci C:\Windows\system32\drivers\storahci.sys
23:14:09.0813 5148 storahci - ok
23:14:09.0828 5148 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
23:14:09.0828 5148 storflt - ok
23:14:09.0860 5148 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\Windows\system32\storsvc.dll
23:14:09.0860 5148 StorSvc - ok
23:14:09.0875 5148 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\Windows\system32\drivers\storvsc.sys
23:14:09.0875 5148 storvsc - ok
23:14:09.0875 5148 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\Windows\system32\svsvc.dll
23:14:09.0875 5148 svsvc - ok
23:14:09.0891 5148 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\Windows\System32\drivers\swenum.sys
23:14:09.0891 5148 swenum - ok
23:14:09.0912 5148 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\Windows\System32\swprv.dll
23:14:09.0922 5148 swprv - ok
23:14:09.0948 5148 [ A06CB9269D29EE3D0F3F5630ABB660B8 ] SysMain C:\Windows\system32\sysmain.dll
23:14:09.0979 5148 SysMain - ok
23:14:10.0010 5148 [ 6FB88606C4A71E1BFAF97D63A676C673 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
23:14:10.0010 5148 SystemEventsBroker - ok
23:14:10.0026 5148 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll
23:14:10.0026 5148 TabletInputService - ok
23:14:10.0041 5148 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\Windows\System32\tapisrv.dll
23:14:10.0057 5148 TapiSrv - ok
23:14:10.0104 5148 [ 1794C43A000A47D92B3304FC1E3E512A ] Tcpip C:\Windows\system32\drivers\tcpip.sys
23:14:10.0135 5148 Tcpip - ok
23:14:10.0166 5148 [ 1794C43A000A47D92B3304FC1E3E512A ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
23:14:10.0182 5148 TCPIP6 - ok
23:14:10.0197 5148 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
23:14:10.0197 5148 tcpipreg - ok
23:14:10.0213 5148 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
23:14:10.0213 5148 tdx - ok
23:14:10.0228 5148 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\Windows\System32\drivers\terminpt.sys
23:14:10.0228 5148 terminpt - ok
23:14:10.0244 5148 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\Windows\System32\termsrv.dll
23:14:10.0260 5148 TermService - ok
23:14:10.0260 5148 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\Windows\system32\themeservice.dll
23:14:10.0275 5148 Themes - ok
23:14:10.0300 5148 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\Windows\system32\mmcss.dll
23:14:10.0300 5148 THREADORDER - ok
23:14:10.0328 5148 [ 4515B9E4140F04FB3907692DF89FCA87 ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll
23:14:10.0328 5148 TimeBroker - ok
23:14:10.0360 5148 [ 6F0BFF80EE2A5BC841286A51F893CBAD ] TPM C:\Windows\system32\drivers\tpm.sys
23:14:10.0360 5148 TPM - ok
23:14:10.0375 5148 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\Windows\System32\trkwks.dll
23:14:10.0391 5148 TrkWks - ok
23:14:10.0422 5148 [ 8ABBB5CE0C62E0A6D28F32F44B7F865C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
23:14:10.0422 5148 TrustedInstaller - ok
23:14:10.0438 5148 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
23:14:10.0438 5148 TsUsbFlt - ok
23:14:10.0453 5148 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
23:14:10.0453 5148 TsUsbGD - ok
23:14:10.0469 5148 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
23:14:10.0469 5148 tunnel - ok
23:14:10.0469 5148 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\Windows\system32\drivers\uagp35.sys
23:14:10.0469 5148 uagp35 - ok
23:14:10.0485 5148 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
23:14:10.0485 5148 UASPStor - ok
23:14:10.0516 5148 [ 4834158B8D06A153FADAB6B85320FBBE ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys
23:14:10.0516 5148 UCX01000 - ok
23:14:10.0547 5148 [ 25C50F4EDF70D0A831E0566BD181CCF2 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
23:14:10.0547 5148 udfs - ok
23:14:10.0563 5148 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\Windows\system32\UI0Detect.exe
23:14:10.0563 5148 UI0Detect - ok
23:14:10.0578 5148 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
23:14:10.0578 5148 uliagpkx - ok
23:14:10.0578 5148 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\Windows\System32\drivers\umbus.sys
23:14:10.0578 5148 umbus - ok
23:14:10.0594 5148 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\Windows\System32\drivers\umpass.sys
23:14:10.0594 5148 UmPass - ok
23:14:10.0610 5148 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\Windows\System32\umrdp.dll
23:14:10.0610 5148 UmRdpService - ok
23:14:10.0625 5148 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\Windows\System32\upnphost.dll
23:14:10.0641 5148 upnphost - ok
23:14:10.0641 5148 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
23:14:10.0641 5148 usbccgp - ok
23:14:10.0656 5148 [ B395B62B62F28106218FA6FB17F4C797 ] usbcir C:\Windows\System32\drivers\usbcir.sys
23:14:10.0656 5148 usbcir - ok
23:14:10.0672 5148 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci C:\Windows\System32\drivers\usbehci.sys
23:14:10.0672 5148 usbehci - ok
23:14:10.0688 5148 [ ADBF89B8E0BB372FEFE2E4B84E1E20AE ] usbhub C:\Windows\System32\drivers\usbhub.sys
23:14:10.0688 5148 usbhub - ok
23:14:10.0719 5148 [ EA040D4C6C94F315A85F3D0EAA884B37 ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
23:14:10.0719 5148 USBHUB3 - ok
23:14:10.0734 5148 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\Windows\System32\drivers\usbohci.sys
23:14:10.0734 5148 usbohci - ok
23:14:10.0750 5148 [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint C:\Windows\System32\drivers\usbprint.sys
23:14:10.0750 5148 usbprint - ok
23:14:10.0766 5148 [ BFC7FE4AAEB61317A921871B4085EF4B ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
23:14:10.0766 5148 USBSTOR - ok
23:14:10.0781 5148 [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
23:14:10.0781 5148 usbuhci - ok
23:14:10.0812 5148 [ 09799E701B4327097E9F63D3FE221083 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
23:14:10.0812 5148 usbvideo - ok
23:14:10.0844 5148 [ 1ADCF0A490C2845637B334626669CD6F ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
23:14:10.0844 5148 USBXHCI - ok
23:14:10.0859 5148 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\Windows\system32\lsass.exe
23:14:10.0859 5148 VaultSvc - ok
23:14:10.0875 5148 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
23:14:10.0875 5148 vdrvroot - ok
23:14:10.0922 5148 [ 1B4488988E5E7512E6C5CD1255E9E973 ] vds C:\Windows\System32\vds.exe
23:14:10.0937 5148 vds - ok
23:14:10.0953 5148 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
23:14:10.0953 5148 VerifierExt - ok
23:14:10.0984 5148 [ 500BE6B2E49883720D0AE8BB859ED7A3 ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
23:14:11.0000 5148 vhdmp - ok
23:14:11.0015 5148 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\Windows\system32\drivers\viaide.sys
23:14:11.0015 5148 viaide - ok
23:14:11.0031 5148 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\Windows\system32\drivers\vmbus.sys
23:14:11.0031 5148 vmbus - ok
23:14:11.0031 5148 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
23:14:11.0031 5148 VMBusHID - ok
23:14:11.0062 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\Windows\System32\ICSvc.dll
23:14:11.0062 5148 vmicheartbeat - ok
23:14:11.0078 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
23:14:11.0078 5148 vmickvpexchange - ok
23:14:11.0078 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\Windows\System32\ICSvc.dll
23:14:11.0093 5148 vmicrdv - ok
23:14:11.0093 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\Windows\System32\ICSvc.dll
23:14:11.0093 5148 vmicshutdown - ok
23:14:11.0109 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\Windows\System32\ICSvc.dll
23:14:11.0109 5148 vmictimesync - ok
23:14:11.0109 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\Windows\System32\ICSvc.dll
23:14:11.0109 5148 vmicvss - ok
23:14:11.0124 5148 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\Windows\system32\drivers\volmgr.sys
23:14:11.0124 5148 volmgr - ok
23:14:11.0145 5148 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
23:14:11.0145 5148 volmgrx - ok
23:14:11.0160 5148 [ 78A5BBA3819FFFC62FFEC3E2220D102D ] volsnap C:\Windows\system32\drivers\volsnap.sys
23:14:11.0160 5148 volsnap - ok
23:14:11.0160 5148 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\Windows\System32\drivers\vpci.sys
23:14:11.0160 5148 vpci - ok
23:14:11.0176 5148 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
23:14:11.0176 5148 vsmraid - ok
23:14:11.0207 5148 [ D0C69E44BC1E1D4AD290FD84104623D8 ] VSS C:\Windows\system32\vssvc.exe
23:14:11.0238 5148 VSS - ok
23:14:11.0254 5148 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
23:14:11.0254 5148 VSTXRAID - ok
23:14:11.0254 5148 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
23:14:11.0254 5148 vwifibus - ok
23:14:11.0282 5148 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\Windows\system32\w32time.dll
23:14:11.0282 5148 W32Time - ok
23:14:11.0292 5148 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\Windows\System32\drivers\wacompen.sys
23:14:11.0292 5148 WacomPen - ok
23:14:11.0323 5148 [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
23:14:11.0323 5148 Wanarp - ok
23:14:11.0323 5148 [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
23:14:11.0323 5148 Wanarpv6 - ok
23:14:11.0370 5148 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\Windows\system32\wbengine.exe
23:14:11.0401 5148 wbengine - ok
23:14:11.0432 5148 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
23:14:11.0432 5148 WbioSrvc - ok
23:14:11.0479 5148 [ AF1349386D4C6786EF4E34FACEF15042 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
23:14:11.0479 5148 Wcmsvc - ok
23:14:11.0510 5148 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\Windows\System32\wcncsvc.dll
23:14:11.0526 5148 wcncsvc - ok
23:14:11.0541 5148 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
23:14:11.0541 5148 WcsPlugInService - ok
23:14:11.0541 5148 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\Windows\system32\drivers\wd.sys
23:14:11.0557 5148 Wd - ok
23:14:11.0572 5148 [ FD47DF026B32969B8A68721A0243E8EE ] WdBoot C:\Windows\system32\drivers\WdBoot.sys
23:14:11.0572 5148 WdBoot - ok
23:14:11.0619 5148 [ 2ADC985B85A71BD7D99712EC0C24358B ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
23:14:11.0619 5148 Wdf01000 - ok
23:14:11.0635 5148 [ 5F425D842DD6ADE9F95A51A0616AFAD7 ] WdFilter C:\Windows\system32\drivers\WdFilter.sys
23:14:11.0650 5148 WdFilter - ok
23:14:11.0666 5148 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\Windows\system32\wdi.dll
23:14:11.0666 5148 WdiServiceHost - ok
23:14:11.0666 5148 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\Windows\system32\wdi.dll
23:14:11.0666 5148 WdiSystemHost - ok
23:14:11.0697 5148 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\Windows\System32\webclnt.dll
23:14:11.0697 5148 WebClient - ok
23:14:11.0713 5148 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\Windows\system32\wecsvc.dll
23:14:11.0713 5148 Wecsvc - ok
23:14:11.0728 5148 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\Windows\System32\wercplsupport.dll
23:14:11.0728 5148 wercplsupport - ok
23:14:11.0744 5148 [ 5F70EBFC1F75B487DE79501E3CCBDB54 ] WerSvc C:\Windows\System32\WerSvc.dll
23:14:11.0760 5148 WerSvc - ok
23:14:11.0775 5148 [ 3F1F31883EAC9DDDF836ACC6D1DAC36C ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys
23:14:11.0775 5148 WFPLWFS - ok
23:14:11.0791 5148 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\Windows\System32\wiarpc.dll
23:14:11.0791 5148 WiaRpc - ok
23:14:11.0806 5148 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
23:14:11.0806 5148 WIMMount - ok
23:14:11.0822 5148 WinDefend - ok
23:14:11.0869 5148 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
23:14:11.0884 5148 WinHttpAutoProxySvc - ok
23:14:11.0931 5148 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
23:14:11.0931 5148 Winmgmt - ok
23:14:12.0009 5148 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\Windows\system32\WsmSvc.dll
23:14:12.0072 5148 WinRM - ok
23:14:12.0118 5148 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\Windows\System32\wlansvc.dll
23:14:12.0150 5148 WlanSvc - ok
23:14:12.0200 5148 [ B330CE47FB74A6BE9A3FFFF4B3F64D9B ] wlidsvc C:\Windows\system32\wlidsvc.dll
23:14:12.0262 5148 wlidsvc - ok
23:14:12.0262 5148 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
23:14:12.0262 5148 WmiAcpi - ok
23:14:12.0298 5148 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
23:14:12.0298 5148 wmiApSrv - ok
23:14:12.0315 5148 WMPNetworkSvc - ok
23:14:12.0330 5148 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys
23:14:12.0330 5148 wpcfltr - ok
23:14:12.0330 5148 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\Windows\System32\wpcsvc.dll
23:14:12.0346 5148 WPCSvc - ok
23:14:12.0362 5148 [ 3013658A4D327854BEEC4A08D9655194 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
23:14:12.0362 5148 WPDBusEnum - ok
23:14:12.0362 5148 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
23:14:12.0377 5148 WpdUpFltr - ok
23:14:12.0377 5148 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
23:14:12.0377 5148 ws2ifsl - ok
23:14:12.0408 5148 [ 012CFE7F0F95266F554EE3B91EE2128A ] wscsvc C:\Windows\System32\wscsvc.dll
23:14:12.0408 5148 wscsvc - ok
23:14:12.0408 5148 WSearch - ok
23:14:12.0477 5148 [ D4D04839F3DFAF09D94BAB1016F7A297 ] WSService C:\Windows\System32\WSService.dll
23:14:12.0540 5148 WSService - ok
23:14:12.0618 5148 [ 9DEC60D4783377097014DFCCA31E69F8 ] wuauserv C:\Windows\system32\wuaueng.dll
23:14:12.0680 5148 wuauserv - ok
23:14:12.0696 5148 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
23:14:12.0696 5148 WudfPf - ok
23:14:12.0711 5148 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys
23:14:12.0711 5148 WUDFRd - ok
23:14:12.0711 5148 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFSensorLP C:\Windows\system32\DRIVERS\WUDFRd.sys
23:14:12.0711 5148 WUDFSensorLP - ok
23:14:12.0727 5148 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
23:14:12.0727 5148 wudfsvc - ok
23:14:12.0743 5148 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
23:14:12.0743 5148 WUDFWpdFs - ok
23:14:12.0758 5148 [ 6D9E07436B6646EC8F7EFFD39B6BA288 ] WwanSvc C:\Windows\System32\wwansvc.dll
23:14:12.0774 5148 WwanSvc - ok
23:14:12.0774 5148 ================ Scan global ===============================
23:14:12.0805 5148 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
23:14:12.0821 5148 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
23:14:12.0852 5148 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
23:14:12.0899 5148 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
23:14:12.0899 5148 [Global] - ok
23:14:12.0899 5148 ================ Scan MBR ==================================
23:14:12.0945 5148 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
23:14:13.0150 5148 \Device\Harddisk0\DR0 - ok
23:14:13.0150 5148 ================ Scan VBR ==================================
23:14:13.0165 5148 [ 0387EAD2C47BDB5E291342C4191A7D06 ] \Device\Harddisk0\DR0\Partition1
23:14:13.0165 5148 \Device\Harddisk0\DR0\Partition1 - ok
23:14:13.0181 5148 [ BCDD2E1635744E5E00227616817203EC ] \Device\Harddisk0\DR0\Partition2
23:14:13.0181 5148 \Device\Harddisk0\DR0\Partition2 - ok
23:14:13.0181 5148 ============================================================
23:14:13.0181 5148 Scan finished
23:14:13.0181 5148 ============================================================
23:14:13.0196 3320 Detected object count: 0
23:14:13.0196 3320 Actual detected object count: 0
ComboFix 13-09-26.03 - byt . 09. 2013 23:25:21.1.4 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.8183.7022 [GMT 2:00]
Spuštěný z: c:\users\byt\Desktop\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\byt\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-26 do 2013-09-26 )))))))))))))))))))))))))))))))
.
.
2013-09-26 15:26 . 2013-09-26 15:28 -------- d-----w- c:\users\Itachi
2013-09-26 11:36 . 2013-09-26 11:36 304816 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10218.bin
2013-09-25 20:48 . 2013-09-25 20:48 -------- d-----w- c:\windows\ERUNT
2013-09-24 18:19 . 2013-09-04 20:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F2490F32-7EB2-4DD0-A728-38962EF18A8C}\mpengine.dll
2013-09-24 16:50 . 2013-09-24 16:50 -------- d-----w- c:\programdata\Malwarebytes
2013-09-24 16:50 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-24 16:50 . 2013-09-24 16:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-09-24 16:39 . 2013-09-25 20:44 -------- d-----w- C:\AdwCleaner
2013-09-24 12:45 . 2001-09-05 01:18 77824 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2013-09-24 12:45 . 2001-09-05 01:18 225280 ----a-w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2013-09-24 12:45 . 2001-09-05 01:14 176128 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2013-09-24 12:45 . 2001-09-05 01:13 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2013-09-24 12:44 . 2001-09-05 11:24 610436 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2013-09-23 21:56 . 2013-09-23 21:56 -------- d-----w- c:\program files (x86)\Trend Micro
2013-09-23 21:42 . 2013-09-23 21:42 -------- d-----w- c:\program files (x86)\CGN
2013-09-22 19:17 . 2013-06-21 05:04 19187712 ----a-w- c:\program files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-22 19:17 . 2013-06-21 04:46 18523648 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-22 07:21 . 2012-11-06 04:20 516608 ----a-w- c:\windows\SysWow64\winhttp.dll
2013-09-22 07:20 . 2012-10-17 04:32 1172992 ----a-w- c:\windows\system32\mfnetsrc.dll
2013-09-22 07:19 . 2012-11-27 04:19 3245568 ----a-w- c:\windows\system32\rdpcorets.dll
2013-09-22 07:18 . 2012-09-20 07:55 3265256 ----a-w- c:\windows\system32\drivers\evbda.sys
2013-09-22 07:17 . 2012-09-20 06:31 80896 ----a-w- c:\windows\system32\mmcss.dll
2013-09-20 12:07 . 2013-09-05 20:09 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-20 12:07 . 2013-09-05 20:09 694232 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-19 18:02 . 2013-09-19 18:03 -------- d-----w- c:\windows\system32\MRT
2013-09-17 16:44 . 2013-03-02 02:45 1627648 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-09-17 16:43 . 2012-08-31 00:52 17888 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-09-17 16:42 . 2012-08-31 00:53 17888 ----a-w- c:\windows\SysWow64\msvcr100_clr0400.dll
2013-09-17 16:39 . 2013-04-09 04:51 3552768 ----a-w- c:\windows\system32\tquery.dll
2013-09-17 16:26 . 2013-09-24 12:45 -------- d-----w- c:\program files (x86)\LucasArts
2013-09-17 16:22 . 2005-04-03 21:02 753664 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-09-17 16:22 . 2005-04-03 21:02 69714 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-09-17 16:22 . 2005-04-03 21:01 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-09-17 16:22 . 2005-04-03 21:00 184320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-09-17 16:22 . 2005-04-03 21:00 63488 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-09-17 16:22 . 2005-04-03 20:59 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-09-17 16:22 . 2013-09-17 16:22 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-09-17 16:22 . 2013-09-17 16:22 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-09-16 18:45 . 2013-09-16 18:46 -------- d-----w- c:\programdata\Ashampoo
2013-09-16 18:45 . 2013-09-16 18:45 -------- d-----w- c:\program files (x86)\Ashampoo
2013-09-16 18:43 . 2013-09-16 18:43 -------- d-----w- c:\program files (x86)\Gameforge4D
2013-09-16 17:39 . 2013-08-21 04:12 1084928 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-16 17:38 . 2013-07-09 06:07 2233168 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-16 17:37 . 2013-02-12 00:17 20992 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-09-16 15:51 . 2013-09-16 15:51 -------- d-----w- c:\program files (x86)\Webteh
2013-09-16 15:49 . 2013-09-16 15:49 -------- d-----w- c:\program files (x86)\VideoLAN
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\programdata\Oracle
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-09-16 15:04 . 2013-09-16 15:04 868264 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-09-16 15:04 . 2013-09-16 15:04 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-09-16 15:04 . 2013-09-16 15:04 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\program files (x86)\Java
2013-09-16 14:35 . 2013-09-16 14:35 -------- d-----w- c:\program files (x86)\Reference Assemblies
2013-09-16 14:35 . 2013-09-16 14:35 -------- d-----w- c:\program files (x86)\MSBuild
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\windows\SysWow64\XPSViewer
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\program files\Reference Assemblies
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\program files\MSBuild
2013-09-16 14:31 . 2013-09-16 14:31 -------- d-----w- c:\program files (x86)\Womble Multimedia
2013-09-16 13:40 . 2013-09-16 13:40 50784 ----a-w- c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-09-16 13:40 . 2013-09-16 13:40 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-09-15 22:44 . 1998-01-23 10:22 304128 ----a-w- c:\windows\IsUninst.exe
2013-09-15 19:10 . 2012-07-06 02:02 778856 ----a-w- c:\windows\SysWow64\PresentationNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 35400 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2013-09-15 19:10 . 2012-07-06 02:02 102528 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 35400 ----a-w- c:\windows\system32\TsWpfWrp.exe
2013-09-15 19:10 . 2012-07-06 02:02 124040 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 1166440 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2013-09-15 19:05 . 2013-09-15 19:06 -------- d-----w- c:\program files\WinRAR
2013-09-15 18:37 . 2013-09-15 18:37 -------- d-----w- c:\program files (x86)\WinRAR 4.20 CZ (Pln verze) 32-64 bit - McAdmin
2013-09-15 18:09 . 2013-09-25 21:04 -------- d-----w- c:\program files (x86)\Opera
2013-09-15 17:37 . 2013-09-15 17:37 -------- d-----w- c:\program files (x86)\Google
2013-09-15 17:28 . 2013-09-26 21:28 -------- d-----w- c:\users\byt
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-15 17:28 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"msnjufxSrv"="c:\windows\inf\msnjufx.vbe" [2013-08-27 1558]
"msjtbvbuSrv"="c:\windows\inf\msjtbvbu.vbe" [2013-08-27 1558]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\System32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-19 18:50 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-15 21:43]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-15 17:37]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-15 17:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-03-06 6469736]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\byt\AppData\Roaming\Mozilla\Firefox\Profiles\5kiwwdo0.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-NtVdmSrv - c:\windows\inf\ntvdm.vbe
Wow6432Node-HKLM-Run-4StoryPrePatch - c:\program files (x86)\Gameforge4D\4Story_CZ\PrePatch.exe
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Celkový čas: 2013-09-26 23:30:40
ComboFix-quarantined-files.txt 2013-09-26 21:30
.
Před spuštěním: 938 799 521 792 bytes free
Po spuštění: 938 220 515 328 bytes free
.
- - End Of File - - D132F4C270940E2839CF64030FD6F22F
A36C5E4F47E84449FF07ED3517B43A31
Log z TDSSKiller jsem musela rozdělit, zpráva mi hlásila moc znaků. Zatím moc díky ...
23:14:06.0635 5148 MSDTC - ok
23:14:06.0650 5148 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
23:14:06.0650 5148 Msfs - ok
23:14:06.0666 5148 [ C32A7A39B960A42BA9D4FBE47213CA03 ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
23:14:06.0666 5148 msgpiowin32 - ok
23:14:06.0666 5148 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
23:14:06.0666 5148 mshidkmdf - ok
23:14:06.0666 5148 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
23:14:06.0666 5148 mshidumdf - ok
23:14:06.0681 5148 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
23:14:06.0681 5148 msisadrv - ok
23:14:06.0697 5148 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
23:14:06.0697 5148 MSiSCSI - ok
23:14:06.0713 5148 msiserver - ok
23:14:06.0713 5148 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
23:14:06.0713 5148 MSKSSRV - ok
23:14:06.0713 5148 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
23:14:06.0713 5148 MsLldp - ok
23:14:06.0728 5148 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
23:14:06.0728 5148 MSPCLOCK - ok
23:14:06.0731 5148 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
23:14:06.0731 5148 MSPQM - ok
23:14:06.0747 5148 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
23:14:06.0747 5148 MsRPC - ok
23:14:06.0763 5148 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
23:14:06.0763 5148 mssmbios - ok
23:14:06.0763 5148 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
23:14:06.0763 5148 MSTEE - ok
23:14:06.0763 5148 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
23:14:06.0763 5148 MTConfig - ok
23:14:06.0778 5148 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
23:14:06.0778 5148 Mup - ok
23:14:06.0794 5148 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
23:14:06.0794 5148 mvumis - ok
23:14:06.0810 5148 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
23:14:06.0810 5148 napagent - ok
23:14:06.0841 5148 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
23:14:06.0841 5148 NativeWifiP - ok
23:14:06.0856 5148 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
23:14:06.0856 5148 NcaSvc - ok
23:14:06.0872 5148 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
23:14:06.0872 5148 NcdAutoSetup - ok
23:14:06.0903 5148 [ A10E176F3B2BF83EDE7B5C4658C93B66 ] NDIS C:\Windows\system32\drivers\ndis.sys
23:14:06.0903 5148 NDIS - ok
23:14:06.0919 5148 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
23:14:06.0919 5148 NdisCap - ok
23:14:06.0934 5148 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
23:14:06.0934 5148 NdisImPlatform - ok
23:14:06.0950 5148 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
23:14:06.0950 5148 NdisTapi - ok
23:14:06.0950 5148 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
23:14:06.0950 5148 Ndisuio - ok
23:14:06.0966 5148 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
23:14:06.0966 5148 NdisWan - ok
23:14:06.0966 5148 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
23:14:06.0966 5148 NDISWANLEGACY - ok
23:14:06.0987 5148 [ 3730942D7DB2F8BB5F84542B7FF6F650 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
23:14:06.0987 5148 NDProxy - ok
23:14:06.0987 5148 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
23:14:07.0003 5148 Ndu - ok
23:14:07.0003 5148 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
23:14:07.0003 5148 NetBIOS - ok
23:14:07.0019 5148 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
23:14:07.0019 5148 NetBT - ok
23:14:07.0034 5148 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
23:14:07.0034 5148 Netlogon - ok
23:14:07.0050 5148 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
23:14:07.0050 5148 Netman - ok
23:14:07.0086 5148 [ 79FA9393C67EBBF92A56923592CF7A7C ] netprofm C:\Windows\System32\netprofmsvc.dll
23:14:07.0086 5148 netprofm - ok
23:14:07.0133 5148 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:14:07.0149 5148 NetTcpPortSharing - ok
23:14:07.0164 5148 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
23:14:07.0164 5148 nfrd960 - ok
23:14:07.0195 5148 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
23:14:07.0211 5148 NlaSvc - ok
23:14:07.0211 5148 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
23:14:07.0211 5148 Npfs - ok
23:14:07.0227 5148 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
23:14:07.0227 5148 npsvctrig - ok
23:14:07.0242 5148 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
23:14:07.0242 5148 nsi - ok
23:14:07.0258 5148 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
23:14:07.0258 5148 nsiproxy - ok
23:14:07.0305 5148 [ 76929F4A69E425911A63B407E26C2589 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
23:14:07.0336 5148 Ntfs - ok
23:14:07.0351 5148 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
23:14:07.0351 5148 Null - ok
23:14:07.0367 5148 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
23:14:07.0367 5148 NVHDA - ok
23:14:07.0556 5148 [ FCBA1C22727939E7CFF9EB08FE9692AB ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
23:14:07.0603 5148 nvlddmkm - ok
23:14:07.0618 5148 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
23:14:07.0618 5148 nvraid - ok
23:14:07.0618 5148 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
23:14:07.0634 5148 nvstor - ok
23:14:07.0650 5148 [ 84948366BDC2D86EC4316A6FCC0C8561 ] NvStUSB C:\Windows\System32\drivers\nvstusb.sys
23:14:07.0665 5148 NvStUSB - ok
23:14:07.0696 5148 [ 10C232F6CFFD51D2332898AE7AE0FF23 ] nvsvc C:\Windows\system32\nvvsvc.exe
23:14:07.0712 5148 nvsvc - ok
23:14:07.0759 5148 [ 4789E020D2617046862D1790FC235FF6 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
23:14:07.0774 5148 nvUpdatusService - ok
23:14:07.0790 5148 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
23:14:07.0790 5148 nv_agp - ok
23:14:07.0806 5148 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
23:14:07.0806 5148 p2pimsvc - ok
23:14:07.0837 5148 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
23:14:07.0837 5148 p2psvc - ok
23:14:07.0852 5148 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
23:14:07.0852 5148 Parport - ok
23:14:07.0868 5148 [ D6ACCF9F2EEEEA711C14EFD976E573F3 ] partmgr C:\Windows\system32\drivers\partmgr.sys
23:14:07.0884 5148 partmgr - ok
23:14:07.0899 5148 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
23:14:07.0915 5148 PcaSvc - ok
23:14:07.0930 5148 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
23:14:07.0930 5148 pci - ok
23:14:07.0930 5148 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
23:14:07.0930 5148 pciide - ok
23:14:07.0946 5148 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
23:14:07.0946 5148 pcmcia - ok
23:14:07.0962 5148 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
23:14:07.0962 5148 pcw - ok
23:14:07.0977 5148 [ 0698DEDEAD6A00AD0D468C687D830FBF ] pdc C:\Windows\system32\drivers\pdc.sys
23:14:07.0977 5148 pdc - ok
23:14:08.0024 5148 [ 61FE70659CD43E07F94DA4DC31DEC493 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
23:14:08.0024 5148 PEAUTH - ok
23:14:08.0102 5148 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
23:14:08.0102 5148 PerfHost - ok
23:14:08.0149 5148 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
23:14:08.0165 5148 pla - ok
23:14:08.0196 5148 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
23:14:08.0196 5148 PlugPlay - ok
23:14:08.0212 5148 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
23:14:08.0212 5148 PNRPAutoReg - ok
23:14:08.0227 5148 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
23:14:08.0227 5148 PNRPsvc - ok
23:14:08.0243 5148 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
23:14:08.0258 5148 PolicyAgent - ok
23:14:08.0286 5148 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
23:14:08.0286 5148 Power - ok
23:14:08.0301 5148 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
23:14:08.0301 5148 PptpMiniport - ok
23:14:08.0348 5148 [ 9D59831262CAD44E709D695FC9D5E7AB ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
23:14:08.0379 5148 PrintNotify - ok
23:14:08.0410 5148 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
23:14:08.0410 5148 Processor - ok
23:14:08.0426 5148 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
23:14:08.0426 5148 ProfSvc - ok
23:14:08.0445 5148 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
23:14:08.0445 5148 Psched - ok
23:14:08.0461 5148 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
23:14:08.0461 5148 QWAVE - ok
23:14:08.0477 5148 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
23:14:08.0477 5148 QWAVEdrv - ok
23:14:08.0477 5148 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
23:14:08.0477 5148 RasAcd - ok
23:14:08.0492 5148 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
23:14:08.0492 5148 RasAgileVpn - ok
23:14:08.0508 5148 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
23:14:08.0523 5148 RasAuto - ok
23:14:08.0523 5148 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
23:14:08.0523 5148 Rasl2tp - ok
23:14:08.0555 5148 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
23:14:08.0555 5148 RasMan - ok
23:14:08.0570 5148 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
23:14:08.0570 5148 RasPppoe - ok
23:14:08.0586 5148 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
23:14:08.0586 5148 RasSstp - ok
23:14:08.0617 5148 [ CA03D642ACE58E1BA54E4B383F91CD69 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
23:14:08.0617 5148 rdbss - ok
23:14:08.0648 5148 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
23:14:08.0648 5148 rdpbus - ok
23:14:08.0664 5148 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
23:14:08.0679 5148 RDPDR - ok
23:14:08.0711 5148 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
23:14:08.0711 5148 RdpVideoMiniport - ok
23:14:08.0726 5148 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
23:14:08.0726 5148 RDPWD - ok
23:14:08.0757 5148 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
23:14:08.0757 5148 rdyboost - ok
23:14:08.0757 5148 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
23:14:08.0773 5148 RemoteAccess - ok
23:14:08.0773 5148 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
23:14:08.0789 5148 RemoteRegistry - ok
23:14:08.0804 5148 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
23:14:08.0804 5148 RpcEptMapper - ok
23:14:08.0820 5148 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
23:14:08.0820 5148 RpcLocator - ok
23:14:08.0836 5148 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
23:14:08.0851 5148 RpcSs - ok
23:14:08.0851 5148 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
23:14:08.0867 5148 rspndr - ok
23:14:08.0882 5148 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys
23:14:08.0882 5148 RTL8168 - ok
23:14:08.0914 5148 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
23:14:08.0914 5148 s3cap - ok
23:14:08.0945 5148 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
23:14:08.0945 5148 SamSs - ok
23:14:08.0945 5148 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
23:14:08.0945 5148 sbp2port - ok
23:14:08.0976 5148 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
23:14:08.0976 5148 SCardSvr - ok
23:14:08.0992 5148 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
23:14:08.0992 5148 scfilter - ok
23:14:09.0023 5148 [ ED40ED9A65F3E79A8C43DD50C5FDADBF ] Schedule C:\Windows\system32\schedsvc.dll
23:14:09.0054 5148 Schedule - ok
23:14:09.0070 5148 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
23:14:09.0085 5148 SCPolicySvc - ok
23:14:09.0101 5148 [ F58B030A0664385C707B8C1C63682041 ] sdbus C:\Windows\System32\drivers\sdbus.sys
23:14:09.0101 5148 sdbus - ok
23:14:09.0117 5148 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
23:14:09.0132 5148 SDRSVC - ok
23:14:09.0148 5148 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
23:14:09.0148 5148 sdstor - ok
23:14:09.0164 5148 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
23:14:09.0164 5148 secdrv - ok
23:14:09.0179 5148 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
23:14:09.0179 5148 seclogon - ok
23:14:09.0195 5148 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll
23:14:09.0195 5148 SENS - ok
23:14:09.0210 5148 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
23:14:09.0210 5148 SensrSvc - ok
23:14:09.0226 5148 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
23:14:09.0226 5148 SerCx - ok
23:14:09.0242 5148 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
23:14:09.0242 5148 Serenum - ok
23:14:09.0263 5148 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
23:14:09.0263 5148 Serial - ok
23:14:09.0263 5148 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
23:14:09.0263 5148 sermouse - ok
23:14:09.0279 5148 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
23:14:09.0279 5148 SessionEnv - ok
23:14:09.0295 5148 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
23:14:09.0295 5148 sfloppy - ok
23:14:09.0312 5148 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
23:14:09.0319 5148 SharedAccess - ok
23:14:09.0334 5148 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
23:14:09.0350 5148 ShellHWDetection - ok
23:14:09.0350 5148 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
23:14:09.0350 5148 SiSRaid2 - ok
23:14:09.0350 5148 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
23:14:09.0350 5148 SiSRaid4 - ok
23:14:09.0381 5148 [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
23:14:09.0381 5148 SkypeUpdate - ok
23:14:09.0400 5148 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
23:14:09.0400 5148 SNMPTRAP - ok
23:14:09.0414 5148 [ FD3AF5575B99871BADB94E7699DBCE08 ] spaceport C:\Windows\system32\drivers\spaceport.sys
23:14:09.0414 5148 spaceport - ok
23:14:09.0429 5148 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
23:14:09.0429 5148 SpbCx - ok
23:14:09.0445 5148 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
23:14:09.0445 5148 Spooler - ok
23:14:09.0516 5148 [ 061A977C920FBE4BF71FF47C966DDDCA ] sppsvc C:\Windows\system32\sppsvc.exe
23:14:09.0548 5148 sppsvc - ok
23:14:09.0563 5148 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\Windows\system32\DRIVERS\srv.sys
23:14:09.0563 5148 srv - ok
23:14:09.0594 5148 [ 56218A571ECF8D55E0CDFF8DF2546CF1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
23:14:09.0594 5148 srv2 - ok
23:14:09.0626 5148 [ 14FC338B80CFF7E04215133B568D15C4 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
23:14:09.0626 5148 srvnet - ok
23:14:09.0641 5148 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
23:14:09.0657 5148 SSDPSRV - ok
23:14:09.0672 5148 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\Windows\system32\sstpsvc.dll
23:14:09.0672 5148 SstpSvc - ok
23:14:09.0719 5148 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
23:14:09.0719 5148 Stereo Service - ok
23:14:09.0735 5148 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\Windows\system32\drivers\stexstor.sys
23:14:09.0735 5148 stexstor - ok
23:14:09.0766 5148 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\Windows\System32\wiaservc.dll
23:14:09.0782 5148 stisvc - ok
23:14:09.0813 5148 [ B240874B2CA0CD02E8CD11E140B14C57 ] storahci C:\Windows\system32\drivers\storahci.sys
23:14:09.0813 5148 storahci - ok
23:14:09.0828 5148 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
23:14:09.0828 5148 storflt - ok
23:14:09.0860 5148 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\Windows\system32\storsvc.dll
23:14:09.0860 5148 StorSvc - ok
23:14:09.0875 5148 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\Windows\system32\drivers\storvsc.sys
23:14:09.0875 5148 storvsc - ok
23:14:09.0875 5148 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\Windows\system32\svsvc.dll
23:14:09.0875 5148 svsvc - ok
23:14:09.0891 5148 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\Windows\System32\drivers\swenum.sys
23:14:09.0891 5148 swenum - ok
23:14:09.0912 5148 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\Windows\System32\swprv.dll
23:14:09.0922 5148 swprv - ok
23:14:09.0948 5148 [ A06CB9269D29EE3D0F3F5630ABB660B8 ] SysMain C:\Windows\system32\sysmain.dll
23:14:09.0979 5148 SysMain - ok
23:14:10.0010 5148 [ 6FB88606C4A71E1BFAF97D63A676C673 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
23:14:10.0010 5148 SystemEventsBroker - ok
23:14:10.0026 5148 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll
23:14:10.0026 5148 TabletInputService - ok
23:14:10.0041 5148 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\Windows\System32\tapisrv.dll
23:14:10.0057 5148 TapiSrv - ok
23:14:10.0104 5148 [ 1794C43A000A47D92B3304FC1E3E512A ] Tcpip C:\Windows\system32\drivers\tcpip.sys
23:14:10.0135 5148 Tcpip - ok
23:14:10.0166 5148 [ 1794C43A000A47D92B3304FC1E3E512A ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
23:14:10.0182 5148 TCPIP6 - ok
23:14:10.0197 5148 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
23:14:10.0197 5148 tcpipreg - ok
23:14:10.0213 5148 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
23:14:10.0213 5148 tdx - ok
23:14:10.0228 5148 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\Windows\System32\drivers\terminpt.sys
23:14:10.0228 5148 terminpt - ok
23:14:10.0244 5148 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\Windows\System32\termsrv.dll
23:14:10.0260 5148 TermService - ok
23:14:10.0260 5148 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\Windows\system32\themeservice.dll
23:14:10.0275 5148 Themes - ok
23:14:10.0300 5148 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\Windows\system32\mmcss.dll
23:14:10.0300 5148 THREADORDER - ok
23:14:10.0328 5148 [ 4515B9E4140F04FB3907692DF89FCA87 ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll
23:14:10.0328 5148 TimeBroker - ok
23:14:10.0360 5148 [ 6F0BFF80EE2A5BC841286A51F893CBAD ] TPM C:\Windows\system32\drivers\tpm.sys
23:14:10.0360 5148 TPM - ok
23:14:10.0375 5148 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\Windows\System32\trkwks.dll
23:14:10.0391 5148 TrkWks - ok
23:14:10.0422 5148 [ 8ABBB5CE0C62E0A6D28F32F44B7F865C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
23:14:10.0422 5148 TrustedInstaller - ok
23:14:10.0438 5148 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
23:14:10.0438 5148 TsUsbFlt - ok
23:14:10.0453 5148 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
23:14:10.0453 5148 TsUsbGD - ok
23:14:10.0469 5148 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
23:14:10.0469 5148 tunnel - ok
23:14:10.0469 5148 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\Windows\system32\drivers\uagp35.sys
23:14:10.0469 5148 uagp35 - ok
23:14:10.0485 5148 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
23:14:10.0485 5148 UASPStor - ok
23:14:10.0516 5148 [ 4834158B8D06A153FADAB6B85320FBBE ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys
23:14:10.0516 5148 UCX01000 - ok
23:14:10.0547 5148 [ 25C50F4EDF70D0A831E0566BD181CCF2 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
23:14:10.0547 5148 udfs - ok
23:14:10.0563 5148 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\Windows\system32\UI0Detect.exe
23:14:10.0563 5148 UI0Detect - ok
23:14:10.0578 5148 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
23:14:10.0578 5148 uliagpkx - ok
23:14:10.0578 5148 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\Windows\System32\drivers\umbus.sys
23:14:10.0578 5148 umbus - ok
23:14:10.0594 5148 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\Windows\System32\drivers\umpass.sys
23:14:10.0594 5148 UmPass - ok
23:14:10.0610 5148 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\Windows\System32\umrdp.dll
23:14:10.0610 5148 UmRdpService - ok
23:14:10.0625 5148 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\Windows\System32\upnphost.dll
23:14:10.0641 5148 upnphost - ok
23:14:10.0641 5148 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
23:14:10.0641 5148 usbccgp - ok
23:14:10.0656 5148 [ B395B62B62F28106218FA6FB17F4C797 ] usbcir C:\Windows\System32\drivers\usbcir.sys
23:14:10.0656 5148 usbcir - ok
23:14:10.0672 5148 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci C:\Windows\System32\drivers\usbehci.sys
23:14:10.0672 5148 usbehci - ok
23:14:10.0688 5148 [ ADBF89B8E0BB372FEFE2E4B84E1E20AE ] usbhub C:\Windows\System32\drivers\usbhub.sys
23:14:10.0688 5148 usbhub - ok
23:14:10.0719 5148 [ EA040D4C6C94F315A85F3D0EAA884B37 ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
23:14:10.0719 5148 USBHUB3 - ok
23:14:10.0734 5148 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\Windows\System32\drivers\usbohci.sys
23:14:10.0734 5148 usbohci - ok
23:14:10.0750 5148 [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint C:\Windows\System32\drivers\usbprint.sys
23:14:10.0750 5148 usbprint - ok
23:14:10.0766 5148 [ BFC7FE4AAEB61317A921871B4085EF4B ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
23:14:10.0766 5148 USBSTOR - ok
23:14:10.0781 5148 [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
23:14:10.0781 5148 usbuhci - ok
23:14:10.0812 5148 [ 09799E701B4327097E9F63D3FE221083 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
23:14:10.0812 5148 usbvideo - ok
23:14:10.0844 5148 [ 1ADCF0A490C2845637B334626669CD6F ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
23:14:10.0844 5148 USBXHCI - ok
23:14:10.0859 5148 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\Windows\system32\lsass.exe
23:14:10.0859 5148 VaultSvc - ok
23:14:10.0875 5148 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
23:14:10.0875 5148 vdrvroot - ok
23:14:10.0922 5148 [ 1B4488988E5E7512E6C5CD1255E9E973 ] vds C:\Windows\System32\vds.exe
23:14:10.0937 5148 vds - ok
23:14:10.0953 5148 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
23:14:10.0953 5148 VerifierExt - ok
23:14:10.0984 5148 [ 500BE6B2E49883720D0AE8BB859ED7A3 ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
23:14:11.0000 5148 vhdmp - ok
23:14:11.0015 5148 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\Windows\system32\drivers\viaide.sys
23:14:11.0015 5148 viaide - ok
23:14:11.0031 5148 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\Windows\system32\drivers\vmbus.sys
23:14:11.0031 5148 vmbus - ok
23:14:11.0031 5148 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
23:14:11.0031 5148 VMBusHID - ok
23:14:11.0062 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\Windows\System32\ICSvc.dll
23:14:11.0062 5148 vmicheartbeat - ok
23:14:11.0078 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
23:14:11.0078 5148 vmickvpexchange - ok
23:14:11.0078 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\Windows\System32\ICSvc.dll
23:14:11.0093 5148 vmicrdv - ok
23:14:11.0093 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\Windows\System32\ICSvc.dll
23:14:11.0093 5148 vmicshutdown - ok
23:14:11.0109 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\Windows\System32\ICSvc.dll
23:14:11.0109 5148 vmictimesync - ok
23:14:11.0109 5148 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\Windows\System32\ICSvc.dll
23:14:11.0109 5148 vmicvss - ok
23:14:11.0124 5148 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\Windows\system32\drivers\volmgr.sys
23:14:11.0124 5148 volmgr - ok
23:14:11.0145 5148 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
23:14:11.0145 5148 volmgrx - ok
23:14:11.0160 5148 [ 78A5BBA3819FFFC62FFEC3E2220D102D ] volsnap C:\Windows\system32\drivers\volsnap.sys
23:14:11.0160 5148 volsnap - ok
23:14:11.0160 5148 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\Windows\System32\drivers\vpci.sys
23:14:11.0160 5148 vpci - ok
23:14:11.0176 5148 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
23:14:11.0176 5148 vsmraid - ok
23:14:11.0207 5148 [ D0C69E44BC1E1D4AD290FD84104623D8 ] VSS C:\Windows\system32\vssvc.exe
23:14:11.0238 5148 VSS - ok
23:14:11.0254 5148 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
23:14:11.0254 5148 VSTXRAID - ok
23:14:11.0254 5148 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
23:14:11.0254 5148 vwifibus - ok
23:14:11.0282 5148 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\Windows\system32\w32time.dll
23:14:11.0282 5148 W32Time - ok
23:14:11.0292 5148 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\Windows\System32\drivers\wacompen.sys
23:14:11.0292 5148 WacomPen - ok
23:14:11.0323 5148 [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
23:14:11.0323 5148 Wanarp - ok
23:14:11.0323 5148 [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
23:14:11.0323 5148 Wanarpv6 - ok
23:14:11.0370 5148 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\Windows\system32\wbengine.exe
23:14:11.0401 5148 wbengine - ok
23:14:11.0432 5148 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
23:14:11.0432 5148 WbioSrvc - ok
23:14:11.0479 5148 [ AF1349386D4C6786EF4E34FACEF15042 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
23:14:11.0479 5148 Wcmsvc - ok
23:14:11.0510 5148 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\Windows\System32\wcncsvc.dll
23:14:11.0526 5148 wcncsvc - ok
23:14:11.0541 5148 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
23:14:11.0541 5148 WcsPlugInService - ok
23:14:11.0541 5148 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\Windows\system32\drivers\wd.sys
23:14:11.0557 5148 Wd - ok
23:14:11.0572 5148 [ FD47DF026B32969B8A68721A0243E8EE ] WdBoot C:\Windows\system32\drivers\WdBoot.sys
23:14:11.0572 5148 WdBoot - ok
23:14:11.0619 5148 [ 2ADC985B85A71BD7D99712EC0C24358B ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
23:14:11.0619 5148 Wdf01000 - ok
23:14:11.0635 5148 [ 5F425D842DD6ADE9F95A51A0616AFAD7 ] WdFilter C:\Windows\system32\drivers\WdFilter.sys
23:14:11.0650 5148 WdFilter - ok
23:14:11.0666 5148 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\Windows\system32\wdi.dll
23:14:11.0666 5148 WdiServiceHost - ok
23:14:11.0666 5148 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\Windows\system32\wdi.dll
23:14:11.0666 5148 WdiSystemHost - ok
23:14:11.0697 5148 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\Windows\System32\webclnt.dll
23:14:11.0697 5148 WebClient - ok
23:14:11.0713 5148 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\Windows\system32\wecsvc.dll
23:14:11.0713 5148 Wecsvc - ok
23:14:11.0728 5148 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\Windows\System32\wercplsupport.dll
23:14:11.0728 5148 wercplsupport - ok
23:14:11.0744 5148 [ 5F70EBFC1F75B487DE79501E3CCBDB54 ] WerSvc C:\Windows\System32\WerSvc.dll
23:14:11.0760 5148 WerSvc - ok
23:14:11.0775 5148 [ 3F1F31883EAC9DDDF836ACC6D1DAC36C ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys
23:14:11.0775 5148 WFPLWFS - ok
23:14:11.0791 5148 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\Windows\System32\wiarpc.dll
23:14:11.0791 5148 WiaRpc - ok
23:14:11.0806 5148 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
23:14:11.0806 5148 WIMMount - ok
23:14:11.0822 5148 WinDefend - ok
23:14:11.0869 5148 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
23:14:11.0884 5148 WinHttpAutoProxySvc - ok
23:14:11.0931 5148 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
23:14:11.0931 5148 Winmgmt - ok
23:14:12.0009 5148 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\Windows\system32\WsmSvc.dll
23:14:12.0072 5148 WinRM - ok
23:14:12.0118 5148 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\Windows\System32\wlansvc.dll
23:14:12.0150 5148 WlanSvc - ok
23:14:12.0200 5148 [ B330CE47FB74A6BE9A3FFFF4B3F64D9B ] wlidsvc C:\Windows\system32\wlidsvc.dll
23:14:12.0262 5148 wlidsvc - ok
23:14:12.0262 5148 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
23:14:12.0262 5148 WmiAcpi - ok
23:14:12.0298 5148 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
23:14:12.0298 5148 wmiApSrv - ok
23:14:12.0315 5148 WMPNetworkSvc - ok
23:14:12.0330 5148 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys
23:14:12.0330 5148 wpcfltr - ok
23:14:12.0330 5148 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\Windows\System32\wpcsvc.dll
23:14:12.0346 5148 WPCSvc - ok
23:14:12.0362 5148 [ 3013658A4D327854BEEC4A08D9655194 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
23:14:12.0362 5148 WPDBusEnum - ok
23:14:12.0362 5148 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
23:14:12.0377 5148 WpdUpFltr - ok
23:14:12.0377 5148 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
23:14:12.0377 5148 ws2ifsl - ok
23:14:12.0408 5148 [ 012CFE7F0F95266F554EE3B91EE2128A ] wscsvc C:\Windows\System32\wscsvc.dll
23:14:12.0408 5148 wscsvc - ok
23:14:12.0408 5148 WSearch - ok
23:14:12.0477 5148 [ D4D04839F3DFAF09D94BAB1016F7A297 ] WSService C:\Windows\System32\WSService.dll
23:14:12.0540 5148 WSService - ok
23:14:12.0618 5148 [ 9DEC60D4783377097014DFCCA31E69F8 ] wuauserv C:\Windows\system32\wuaueng.dll
23:14:12.0680 5148 wuauserv - ok
23:14:12.0696 5148 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
23:14:12.0696 5148 WudfPf - ok
23:14:12.0711 5148 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys
23:14:12.0711 5148 WUDFRd - ok
23:14:12.0711 5148 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFSensorLP C:\Windows\system32\DRIVERS\WUDFRd.sys
23:14:12.0711 5148 WUDFSensorLP - ok
23:14:12.0727 5148 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
23:14:12.0727 5148 wudfsvc - ok
23:14:12.0743 5148 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
23:14:12.0743 5148 WUDFWpdFs - ok
23:14:12.0758 5148 [ 6D9E07436B6646EC8F7EFFD39B6BA288 ] WwanSvc C:\Windows\System32\wwansvc.dll
23:14:12.0774 5148 WwanSvc - ok
23:14:12.0774 5148 ================ Scan global ===============================
23:14:12.0805 5148 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
23:14:12.0821 5148 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
23:14:12.0852 5148 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
23:14:12.0899 5148 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
23:14:12.0899 5148 [Global] - ok
23:14:12.0899 5148 ================ Scan MBR ==================================
23:14:12.0945 5148 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
23:14:13.0150 5148 \Device\Harddisk0\DR0 - ok
23:14:13.0150 5148 ================ Scan VBR ==================================
23:14:13.0165 5148 [ 0387EAD2C47BDB5E291342C4191A7D06 ] \Device\Harddisk0\DR0\Partition1
23:14:13.0165 5148 \Device\Harddisk0\DR0\Partition1 - ok
23:14:13.0181 5148 [ BCDD2E1635744E5E00227616817203EC ] \Device\Harddisk0\DR0\Partition2
23:14:13.0181 5148 \Device\Harddisk0\DR0\Partition2 - ok
23:14:13.0181 5148 ============================================================
23:14:13.0181 5148 Scan finished
23:14:13.0181 5148 ============================================================
23:14:13.0196 3320 Detected object count: 0
23:14:13.0196 3320 Actual detected object count: 0
ComboFix 13-09-26.03 - byt . 09. 2013 23:25:21.1.4 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.8183.7022 [GMT 2:00]
Spuštěný z: c:\users\byt\Desktop\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\byt\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-26 do 2013-09-26 )))))))))))))))))))))))))))))))
.
.
2013-09-26 15:26 . 2013-09-26 15:28 -------- d-----w- c:\users\Itachi
2013-09-26 11:36 . 2013-09-26 11:36 304816 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10218.bin
2013-09-25 20:48 . 2013-09-25 20:48 -------- d-----w- c:\windows\ERUNT
2013-09-24 18:19 . 2013-09-04 20:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F2490F32-7EB2-4DD0-A728-38962EF18A8C}\mpengine.dll
2013-09-24 16:50 . 2013-09-24 16:50 -------- d-----w- c:\programdata\Malwarebytes
2013-09-24 16:50 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-24 16:50 . 2013-09-24 16:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-09-24 16:39 . 2013-09-25 20:44 -------- d-----w- C:\AdwCleaner
2013-09-24 12:45 . 2001-09-05 01:18 77824 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2013-09-24 12:45 . 2001-09-05 01:18 225280 ----a-w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2013-09-24 12:45 . 2001-09-05 01:14 176128 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2013-09-24 12:45 . 2001-09-05 01:13 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2013-09-24 12:44 . 2001-09-05 11:24 610436 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2013-09-23 21:56 . 2013-09-23 21:56 -------- d-----w- c:\program files (x86)\Trend Micro
2013-09-23 21:42 . 2013-09-23 21:42 -------- d-----w- c:\program files (x86)\CGN
2013-09-22 19:17 . 2013-06-21 05:04 19187712 ----a-w- c:\program files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-22 19:17 . 2013-06-21 04:46 18523648 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-22 07:21 . 2012-11-06 04:20 516608 ----a-w- c:\windows\SysWow64\winhttp.dll
2013-09-22 07:20 . 2012-10-17 04:32 1172992 ----a-w- c:\windows\system32\mfnetsrc.dll
2013-09-22 07:19 . 2012-11-27 04:19 3245568 ----a-w- c:\windows\system32\rdpcorets.dll
2013-09-22 07:18 . 2012-09-20 07:55 3265256 ----a-w- c:\windows\system32\drivers\evbda.sys
2013-09-22 07:17 . 2012-09-20 06:31 80896 ----a-w- c:\windows\system32\mmcss.dll
2013-09-20 12:07 . 2013-09-05 20:09 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-20 12:07 . 2013-09-05 20:09 694232 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-19 18:02 . 2013-09-19 18:03 -------- d-----w- c:\windows\system32\MRT
2013-09-17 16:44 . 2013-03-02 02:45 1627648 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-09-17 16:43 . 2012-08-31 00:52 17888 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-09-17 16:42 . 2012-08-31 00:53 17888 ----a-w- c:\windows\SysWow64\msvcr100_clr0400.dll
2013-09-17 16:39 . 2013-04-09 04:51 3552768 ----a-w- c:\windows\system32\tquery.dll
2013-09-17 16:26 . 2013-09-24 12:45 -------- d-----w- c:\program files (x86)\LucasArts
2013-09-17 16:22 . 2005-04-03 21:02 753664 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-09-17 16:22 . 2005-04-03 21:02 69714 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-09-17 16:22 . 2005-04-03 21:01 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-09-17 16:22 . 2005-04-03 21:00 184320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-09-17 16:22 . 2005-04-03 21:00 63488 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-09-17 16:22 . 2005-04-03 20:59 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-09-17 16:22 . 2013-09-17 16:22 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-09-17 16:22 . 2013-09-17 16:22 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-09-16 18:45 . 2013-09-16 18:46 -------- d-----w- c:\programdata\Ashampoo
2013-09-16 18:45 . 2013-09-16 18:45 -------- d-----w- c:\program files (x86)\Ashampoo
2013-09-16 18:43 . 2013-09-16 18:43 -------- d-----w- c:\program files (x86)\Gameforge4D
2013-09-16 17:39 . 2013-08-21 04:12 1084928 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-16 17:38 . 2013-07-09 06:07 2233168 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-16 17:37 . 2013-02-12 00:17 20992 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-09-16 15:51 . 2013-09-16 15:51 -------- d-----w- c:\program files (x86)\Webteh
2013-09-16 15:49 . 2013-09-16 15:49 -------- d-----w- c:\program files (x86)\VideoLAN
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\programdata\Oracle
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-09-16 15:04 . 2013-09-16 15:04 868264 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-09-16 15:04 . 2013-09-16 15:04 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-09-16 15:04 . 2013-09-16 15:04 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\program files (x86)\Java
2013-09-16 14:35 . 2013-09-16 14:35 -------- d-----w- c:\program files (x86)\Reference Assemblies
2013-09-16 14:35 . 2013-09-16 14:35 -------- d-----w- c:\program files (x86)\MSBuild
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\windows\SysWow64\XPSViewer
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\program files\Reference Assemblies
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\program files\MSBuild
2013-09-16 14:31 . 2013-09-16 14:31 -------- d-----w- c:\program files (x86)\Womble Multimedia
2013-09-16 13:40 . 2013-09-16 13:40 50784 ----a-w- c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-09-16 13:40 . 2013-09-16 13:40 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-09-15 22:44 . 1998-01-23 10:22 304128 ----a-w- c:\windows\IsUninst.exe
2013-09-15 19:10 . 2012-07-06 02:02 778856 ----a-w- c:\windows\SysWow64\PresentationNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 35400 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2013-09-15 19:10 . 2012-07-06 02:02 102528 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 35400 ----a-w- c:\windows\system32\TsWpfWrp.exe
2013-09-15 19:10 . 2012-07-06 02:02 124040 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 1166440 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2013-09-15 19:05 . 2013-09-15 19:06 -------- d-----w- c:\program files\WinRAR
2013-09-15 18:37 . 2013-09-15 18:37 -------- d-----w- c:\program files (x86)\WinRAR 4.20 CZ (Pln verze) 32-64 bit - McAdmin
2013-09-15 18:09 . 2013-09-25 21:04 -------- d-----w- c:\program files (x86)\Opera
2013-09-15 17:37 . 2013-09-15 17:37 -------- d-----w- c:\program files (x86)\Google
2013-09-15 17:28 . 2013-09-26 21:28 -------- d-----w- c:\users\byt
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-15 17:28 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"msnjufxSrv"="c:\windows\inf\msnjufx.vbe" [2013-08-27 1558]
"msjtbvbuSrv"="c:\windows\inf\msjtbvbu.vbe" [2013-08-27 1558]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\System32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-19 18:50 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-15 21:43]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-15 17:37]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-15 17:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-03-06 6469736]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\byt\AppData\Roaming\Mozilla\Firefox\Profiles\5kiwwdo0.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-NtVdmSrv - c:\windows\inf\ntvdm.vbe
Wow6432Node-HKLM-Run-4StoryPrePatch - c:\program files (x86)\Gameforge4D\4Story_CZ\PrePatch.exe
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Celkový čas: 2013-09-26 23:30:40
ComboFix-quarantined-files.txt 2013-09-26 21:30
.
Před spuštěním: 938 799 521 792 bytes free
Po spuštění: 938 220 515 328 bytes free
.
- - End Of File - - D132F4C270940E2839CF64030FD6F22F
A36C5E4F47E84449FF07ED3517B43A31
Log z TDSSKiller jsem musela rozdělit, zpráva mi hlásila moc znaků. Zatím moc díky ...

- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Windows Script Hosts - kontrola logu HJT
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\windows\inf\msnjufx.vbe
c:\windows\inf\msjtbvbu.vbe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
c:\users\byt je tvoje přihlašovací jméno ne?
Toto otestuj na Virustotal
c:\windows\inf\msnjufx.vbe
c:\windows\inf\msjtbvbu.vbe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
c:\users\byt je tvoje přihlašovací jméno ne?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Windows Script Hosts - kontrola logu HJT
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
http://files.avast.com/files/rootkit-scanner/aswmbr.exe
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
Collect::
c:\windows\inf\msnjufx.vbe
c:\windows\inf\msjtbvbu.vbe
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Folder::
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Google\Update
Driver::
SkypeUpdate
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"msnjufxSrv"=-
"msjtbvbuSrv"=-
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
http://files.avast.com/files/rootkit-scanner/aswmbr.exe
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Windows Script Hosts - kontrola logu HJT
ComboFix 13-09-26.03 - byt . 09. 2013 23:49:49.2.4 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.8183.6716 [GMT 2:00]
Spuštěný z: c:\users\byt\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\byt\Desktop\CFScript.txt
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.21.153\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.153\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.153\psuser.dll
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\29.0.1547.76\29.0.1547.76_29.0.1547.66_chrome_updater.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.exe
c:\windows\inf\msjtbvbu.vbe
c:\windows\inf\msnjufx.vbe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Legacy_gupdate
-------\Legacy_gupdatem
-------\Legacy_gupdate
-------\Legacy_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-28 do 2013-09-28 )))))))))))))))))))))))))))))))
.
.
2013-09-28 21:53 . 2013-09-28 21:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-28 21:53 . 2013-09-28 21:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-27 17:04 . 2013-09-27 17:04 107832 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-09-27 17:04 . 2013-09-27 17:04 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-09-27 17:04 . 2013-09-27 17:04 2250024 ----a-w- c:\windows\SysWow64\pbsvc.exe
2013-09-27 17:01 . 2013-09-27 17:01 -------- d-----w- c:\program files (x86)\Ubisoft
2013-09-27 15:53 . 2013-08-07 05:15 144896 ----a-w- c:\windows\system32\tssdisai.dll
2013-09-26 15:26 . 2013-09-26 15:28 -------- d-----w- c:\users\Itachi
2013-09-26 11:36 . 2013-09-26 11:36 304816 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10218.bin
2013-09-25 20:48 . 2013-09-25 20:48 -------- d-----w- c:\windows\ERUNT
2013-09-24 18:19 . 2013-09-04 20:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F2490F32-7EB2-4DD0-A728-38962EF18A8C}\mpengine.dll
2013-09-24 16:50 . 2013-09-24 16:50 -------- d-----w- c:\programdata\Malwarebytes
2013-09-24 16:50 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-24 16:50 . 2013-09-24 16:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-09-24 16:39 . 2013-09-25 20:44 -------- d-----w- C:\AdwCleaner
2013-09-24 12:45 . 2001-09-05 01:18 77824 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2013-09-24 12:45 . 2001-09-05 01:18 225280 ----a-w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2013-09-24 12:45 . 2001-09-05 01:14 176128 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2013-09-24 12:45 . 2001-09-05 01:13 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2013-09-24 12:44 . 2001-09-05 11:24 610436 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2013-09-23 21:56 . 2013-09-23 21:56 -------- d-----w- c:\program files (x86)\Trend Micro
2013-09-23 21:42 . 2013-09-23 21:42 -------- d-----w- c:\program files (x86)\CGN
2013-09-22 19:17 . 2013-06-21 05:04 19187712 ----a-w- c:\program files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-22 19:17 . 2013-06-21 04:46 18523648 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-22 07:21 . 2012-11-06 04:20 516608 ----a-w- c:\windows\SysWow64\winhttp.dll
2013-09-22 07:20 . 2012-10-17 04:32 1172992 ----a-w- c:\windows\system32\mfnetsrc.dll
2013-09-22 07:19 . 2012-11-27 04:19 3245568 ----a-w- c:\windows\system32\rdpcorets.dll
2013-09-22 07:18 . 2012-09-20 07:55 3265256 ----a-w- c:\windows\system32\drivers\evbda.sys
2013-09-22 07:17 . 2012-09-20 06:31 80896 ----a-w- c:\windows\system32\mmcss.dll
2013-09-20 12:07 . 2013-09-18 23:26 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-20 12:07 . 2013-09-18 23:26 694232 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-19 18:02 . 2013-09-19 18:03 -------- d-----w- c:\windows\system32\MRT
2013-09-17 16:44 . 2013-03-02 02:45 1627648 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-09-17 16:43 . 2012-08-31 00:52 17888 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-09-17 16:42 . 2012-08-31 00:53 17888 ----a-w- c:\windows\SysWow64\msvcr100_clr0400.dll
2013-09-17 16:39 . 2013-04-09 04:51 3552768 ----a-w- c:\windows\system32\tquery.dll
2013-09-17 16:26 . 2013-09-24 12:45 -------- d-----w- c:\program files (x86)\LucasArts
2013-09-17 16:22 . 2005-04-03 21:02 753664 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-09-17 16:22 . 2005-04-03 21:02 69714 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-09-17 16:22 . 2005-04-03 21:01 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-09-17 16:22 . 2005-04-03 21:00 184320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-09-17 16:22 . 2005-04-03 21:00 63488 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-09-17 16:22 . 2005-04-03 20:59 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-09-17 16:22 . 2013-09-17 16:22 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-09-17 16:22 . 2013-09-17 16:22 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-09-16 18:45 . 2013-09-16 18:46 -------- d-----w- c:\programdata\Ashampoo
2013-09-16 18:45 . 2013-09-16 18:45 -------- d-----w- c:\program files (x86)\Ashampoo
2013-09-16 18:43 . 2013-09-16 18:43 -------- d-----w- c:\program files (x86)\Gameforge4D
2013-09-16 17:39 . 2013-08-21 04:12 1084928 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-16 17:38 . 2013-07-09 06:07 2233168 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-16 17:37 . 2013-02-12 00:17 20992 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-09-16 15:51 . 2013-09-16 15:51 -------- d-----w- c:\program files (x86)\Webteh
2013-09-16 15:49 . 2013-09-16 15:49 -------- d-----w- c:\program files (x86)\VideoLAN
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\programdata\Oracle
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-09-16 15:04 . 2013-09-16 15:04 868264 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-09-16 15:04 . 2013-09-16 15:04 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-09-16 15:04 . 2013-09-16 15:04 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\program files (x86)\Java
2013-09-16 14:35 . 2013-09-16 14:35 -------- d-----w- c:\program files (x86)\Reference Assemblies
2013-09-16 14:35 . 2013-09-16 14:35 -------- d-----w- c:\program files (x86)\MSBuild
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\windows\SysWow64\XPSViewer
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\program files\Reference Assemblies
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\program files\MSBuild
2013-09-16 14:31 . 2013-09-16 14:31 -------- d-----w- c:\program files (x86)\Womble Multimedia
2013-09-16 13:40 . 2013-09-16 13:40 50784 ----a-w- c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-09-16 13:40 . 2013-09-16 13:40 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-09-15 22:44 . 1998-01-23 10:22 304128 ----a-w- c:\windows\IsUninst.exe
2013-09-15 19:10 . 2012-07-06 02:02 778856 ----a-w- c:\windows\SysWow64\PresentationNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 35400 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2013-09-15 19:10 . 2012-07-06 02:02 102528 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 35400 ----a-w- c:\windows\system32\TsWpfWrp.exe
2013-09-15 19:10 . 2012-07-06 02:02 124040 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 1166440 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2013-09-15 19:05 . 2013-09-15 19:06 -------- d-----w- c:\program files\WinRAR
2013-09-15 18:37 . 2013-09-15 18:37 -------- d-----w- c:\program files (x86)\WinRAR 4.20 CZ (Pln verze) 32-64 bit - McAdmin
2013-09-15 18:09 . 2013-09-25 21:04 -------- d-----w- c:\program files (x86)\Opera
2013-09-15 17:37 . 2013-09-28 21:54 -------- d-----w- c:\program files (x86)\Google
2013-09-15 17:28 . 2013-09-26 21:28 -------- d-----w- c:\users\byt
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-15 17:28 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"NtVdmSrv"="c:\windows\inf\ntvdm.vbe" [BU]
"4StoryPrePatch"="c:\program files (x86)\Gameforge4D\4Story_CZ\PrePatch.exe" [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\System32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-19 18:50 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-15 21:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-03-06 6469736]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\byt\AppData\Roaming\Mozilla\Firefox\Profiles\5kiwwdo0.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-09-28 23:57:05 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-28 21:57
ComboFix2.txt 2013-09-26 21:30
.
Před spuštěním: 922 295 267 328 bytes free
Po spuštění: 922 064 883 712 bytes free
.
- - End Of File - - E060202D1F371304B4D7EF5CEDE65ED7
A36C5E4F47E84449FF07ED3517B43A31
Nahr nˇ probŘhlo ŁspŘçnŘ
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.8183.6716 [GMT 2:00]
Spuštěný z: c:\users\byt\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\byt\Desktop\CFScript.txt
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.21.153\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.21.153\goopdate.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.21.153\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.21.153\psmachine.dll
c:\program files (x86)\Google\Update\1.3.21.153\psuser.dll
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\29.0.1547.76\29.0.1547.76_29.0.1547.66_chrome_updater.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.exe
c:\windows\inf\msjtbvbu.vbe
c:\windows\inf\msnjufx.vbe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Legacy_gupdate
-------\Legacy_gupdatem
-------\Legacy_gupdate
-------\Legacy_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-28 do 2013-09-28 )))))))))))))))))))))))))))))))
.
.
2013-09-28 21:53 . 2013-09-28 21:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-28 21:53 . 2013-09-28 21:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-27 17:04 . 2013-09-27 17:04 107832 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-09-27 17:04 . 2013-09-27 17:04 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-09-27 17:04 . 2013-09-27 17:04 2250024 ----a-w- c:\windows\SysWow64\pbsvc.exe
2013-09-27 17:01 . 2013-09-27 17:01 -------- d-----w- c:\program files (x86)\Ubisoft
2013-09-27 15:53 . 2013-08-07 05:15 144896 ----a-w- c:\windows\system32\tssdisai.dll
2013-09-26 15:26 . 2013-09-26 15:28 -------- d-----w- c:\users\Itachi
2013-09-26 11:36 . 2013-09-26 11:36 304816 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10218.bin
2013-09-25 20:48 . 2013-09-25 20:48 -------- d-----w- c:\windows\ERUNT
2013-09-24 18:19 . 2013-09-04 20:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F2490F32-7EB2-4DD0-A728-38962EF18A8C}\mpengine.dll
2013-09-24 16:50 . 2013-09-24 16:50 -------- d-----w- c:\programdata\Malwarebytes
2013-09-24 16:50 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-24 16:50 . 2013-09-24 16:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-09-24 16:39 . 2013-09-25 20:44 -------- d-----w- C:\AdwCleaner
2013-09-24 12:45 . 2001-09-05 01:18 77824 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2013-09-24 12:45 . 2001-09-05 01:18 225280 ----a-w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2013-09-24 12:45 . 2001-09-05 01:14 176128 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2013-09-24 12:45 . 2001-09-05 01:13 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2013-09-24 12:44 . 2001-09-05 11:24 610436 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2013-09-23 21:56 . 2013-09-23 21:56 -------- d-----w- c:\program files (x86)\Trend Micro
2013-09-23 21:42 . 2013-09-23 21:42 -------- d-----w- c:\program files (x86)\CGN
2013-09-22 19:17 . 2013-06-21 05:04 19187712 ----a-w- c:\program files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-22 19:17 . 2013-06-21 04:46 18523648 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-09-22 07:21 . 2012-11-06 04:20 516608 ----a-w- c:\windows\SysWow64\winhttp.dll
2013-09-22 07:20 . 2012-10-17 04:32 1172992 ----a-w- c:\windows\system32\mfnetsrc.dll
2013-09-22 07:19 . 2012-11-27 04:19 3245568 ----a-w- c:\windows\system32\rdpcorets.dll
2013-09-22 07:18 . 2012-09-20 07:55 3265256 ----a-w- c:\windows\system32\drivers\evbda.sys
2013-09-22 07:17 . 2012-09-20 06:31 80896 ----a-w- c:\windows\system32\mmcss.dll
2013-09-20 12:07 . 2013-09-18 23:26 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-20 12:07 . 2013-09-18 23:26 694232 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-19 18:02 . 2013-09-19 18:03 -------- d-----w- c:\windows\system32\MRT
2013-09-17 16:44 . 2013-03-02 02:45 1627648 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-09-17 16:43 . 2012-08-31 00:52 17888 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-09-17 16:42 . 2012-08-31 00:53 17888 ----a-w- c:\windows\SysWow64\msvcr100_clr0400.dll
2013-09-17 16:39 . 2013-04-09 04:51 3552768 ----a-w- c:\windows\system32\tquery.dll
2013-09-17 16:26 . 2013-09-24 12:45 -------- d-----w- c:\program files (x86)\LucasArts
2013-09-17 16:22 . 2005-04-03 21:02 753664 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-09-17 16:22 . 2005-04-03 21:02 69714 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-09-17 16:22 . 2005-04-03 21:01 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-09-17 16:22 . 2005-04-03 21:00 184320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-09-17 16:22 . 2005-04-03 21:00 63488 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-09-17 16:22 . 2005-04-03 20:59 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-09-17 16:22 . 2013-09-17 16:22 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-09-17 16:22 . 2013-09-17 16:22 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-09-16 18:45 . 2013-09-16 18:46 -------- d-----w- c:\programdata\Ashampoo
2013-09-16 18:45 . 2013-09-16 18:45 -------- d-----w- c:\program files (x86)\Ashampoo
2013-09-16 18:43 . 2013-09-16 18:43 -------- d-----w- c:\program files (x86)\Gameforge4D
2013-09-16 17:39 . 2013-08-21 04:12 1084928 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-16 17:38 . 2013-07-09 06:07 2233168 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-16 17:37 . 2013-02-12 00:17 20992 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-09-16 15:51 . 2013-09-16 15:51 -------- d-----w- c:\program files (x86)\Webteh
2013-09-16 15:49 . 2013-09-16 15:49 -------- d-----w- c:\program files (x86)\VideoLAN
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\programdata\Oracle
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-09-16 15:04 . 2013-09-16 15:04 868264 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-09-16 15:04 . 2013-09-16 15:04 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-09-16 15:04 . 2013-09-16 15:04 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-16 15:04 . 2013-09-16 15:04 -------- d-----w- c:\program files (x86)\Java
2013-09-16 14:35 . 2013-09-16 14:35 -------- d-----w- c:\program files (x86)\Reference Assemblies
2013-09-16 14:35 . 2013-09-16 14:35 -------- d-----w- c:\program files (x86)\MSBuild
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\windows\SysWow64\XPSViewer
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\program files\Reference Assemblies
2013-09-16 14:34 . 2013-09-16 14:34 -------- d-----w- c:\program files\MSBuild
2013-09-16 14:31 . 2013-09-16 14:31 -------- d-----w- c:\program files (x86)\Womble Multimedia
2013-09-16 13:40 . 2013-09-16 13:40 50784 ----a-w- c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-09-16 13:40 . 2013-09-16 13:40 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-09-15 22:44 . 1998-01-23 10:22 304128 ----a-w- c:\windows\IsUninst.exe
2013-09-15 19:10 . 2012-07-06 02:02 778856 ----a-w- c:\windows\SysWow64\PresentationNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 35400 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2013-09-15 19:10 . 2012-07-06 02:02 102528 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 35400 ----a-w- c:\windows\system32\TsWpfWrp.exe
2013-09-15 19:10 . 2012-07-06 02:02 124040 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-09-15 19:10 . 2012-07-06 02:02 1166440 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2013-09-15 19:05 . 2013-09-15 19:06 -------- d-----w- c:\program files\WinRAR
2013-09-15 18:37 . 2013-09-15 18:37 -------- d-----w- c:\program files (x86)\WinRAR 4.20 CZ (Pln verze) 32-64 bit - McAdmin
2013-09-15 18:09 . 2013-09-25 21:04 -------- d-----w- c:\program files (x86)\Opera
2013-09-15 17:37 . 2013-09-28 21:54 -------- d-----w- c:\program files (x86)\Google
2013-09-15 17:28 . 2013-09-26 21:28 -------- d-----w- c:\users\byt
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-15 17:28 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"NtVdmSrv"="c:\windows\inf\ntvdm.vbe" [BU]
"4StoryPrePatch"="c:\program files (x86)\Gameforge4D\4Story_CZ\PrePatch.exe" [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\System32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-19 18:50 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-15 21:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-03-06 6469736]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\byt\AppData\Roaming\Mozilla\Firefox\Profiles\5kiwwdo0.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-09-28 23:57:05 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-28 21:57
ComboFix2.txt 2013-09-26 21:30
.
Před spuštěním: 922 295 267 328 bytes free
Po spuštění: 922 064 883 712 bytes free
.
- - End Of File - - E060202D1F371304B4D7EF5CEDE65ED7
A36C5E4F47E84449FF07ED3517B43A31
Nahr nˇ probŘhlo ŁspŘçnŘ
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 115 hostů