11:58:28.0717 0x0ef8 nv_agp - ok
11:58:28.0733 0x0ef8 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
11:58:28.0748 0x0ef8 ohci1394 - ok
11:58:28.0779 0x0ef8 [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:58:28.0795 0x0ef8 ose - ok
11:58:29.0013 0x0ef8 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7, F342100E2E9001F11FDF93F856B50FA43F9B85D2C6B5706EC0433E77206498DA ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:58:29.0138 0x0ef8 osppsvc - ok
11:58:29.0169 0x0ef8 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:58:29.0201 0x0ef8 p2pimsvc - ok
11:58:29.0232 0x0ef8 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll
11:58:29.0247 0x0ef8 p2psvc - ok
11:58:29.0279 0x0ef8 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:58:29.0279 0x0ef8 Parport - ok
11:58:29.0310 0x0ef8 [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:58:29.0310 0x0ef8 partmgr - ok
11:58:29.0325 0x0ef8 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
11:58:29.0325 0x0ef8 Parvdm - ok
11:58:29.0341 0x0ef8 [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:58:29.0357 0x0ef8 PcaSvc - ok
11:58:29.0388 0x0ef8 [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\Windows\system32\drivers\pci.sys
11:58:29.0388 0x0ef8 pci - ok
11:58:29.0403 0x0ef8 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys
11:58:29.0403 0x0ef8 pciide - ok
11:58:29.0419 0x0ef8 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
11:58:29.0435 0x0ef8 pcmcia - ok
11:58:29.0435 0x0ef8 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys
11:58:29.0435 0x0ef8 pcw - ok
11:58:29.0466 0x0ef8 [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:58:29.0481 0x0ef8 PEAUTH - ok
11:58:29.0544 0x0ef8 [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
11:58:29.0591 0x0ef8 PeerDistSvc - ok
11:58:29.0684 0x0ef8 [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\Windows\system32\pla.dll
11:58:29.0747 0x0ef8 pla - ok
11:58:29.0778 0x0ef8 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:58:29.0809 0x0ef8 PlugPlay - ok
11:58:29.0825 0x0ef8 [ 28460E94FFDF40BB28EFDB3D97E959E8, 1E414E6B43B989784371D26E88E9AA2C759BD802688DC9C782E737FFD67DD881 ] pneteth C:\Windows\system32\DRIVERS\pneteth.sys
11:58:29.0825 0x0ef8 pneteth - ok
11:58:29.0840 0x0ef8 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:58:29.0840 0x0ef8 PNRPAutoReg - ok
11:58:29.0856 0x0ef8 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:58:29.0871 0x0ef8 PNRPsvc - ok
11:58:29.0903 0x0ef8 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:58:29.0918 0x0ef8 PolicyAgent - ok
11:58:29.0981 0x0ef8 postgresql-8.4 - ok
11:58:30.0012 0x0ef8 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\Windows\system32\umpo.dll
11:58:30.0027 0x0ef8 Power - ok
11:58:30.0059 0x0ef8 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:58:30.0059 0x0ef8 PptpMiniport - ok
11:58:30.0074 0x0ef8 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys
11:58:30.0074 0x0ef8 Processor - ok
11:58:30.0105 0x0ef8 [ CADEFAC453040E370A1BDFF3973BE00D, 2E3DD8DA702468D8AB0F3CE27188B1991D4CB015FB36BAE4C6E7996B61CF49B8 ] ProfSvc C:\Windows\system32\profsvc.dll
11:58:30.0105 0x0ef8 ProfSvc - ok
11:58:30.0121 0x0ef8 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:58:30.0121 0x0ef8 ProtectedStorage - ok
11:58:30.0137 0x0ef8 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:58:30.0137 0x0ef8 Psched - ok
11:58:30.0230 0x0ef8 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
11:58:30.0261 0x0ef8 ql2300 - ok
11:58:30.0277 0x0ef8 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
11:58:30.0277 0x0ef8 ql40xx - ok
11:58:30.0308 0x0ef8 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll
11:58:30.0324 0x0ef8 QWAVE - ok
11:58:30.0324 0x0ef8 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:58:30.0339 0x0ef8 QWAVEdrv - ok
11:58:30.0339 0x0ef8 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:58:30.0339 0x0ef8 RasAcd - ok
11:58:30.0371 0x0ef8 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:58:30.0371 0x0ef8 RasAgileVpn - ok
11:58:30.0386 0x0ef8 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll
11:58:30.0386 0x0ef8 RasAuto - ok
11:58:30.0386 0x0ef8 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:58:30.0402 0x0ef8 Rasl2tp - ok
11:58:30.0417 0x0ef8 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll
11:58:30.0433 0x0ef8 RasMan - ok
11:58:30.0433 0x0ef8 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:58:30.0449 0x0ef8 RasPppoe - ok
11:58:30.0449 0x0ef8 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:58:30.0449 0x0ef8 RasSstp - ok
11:58:30.0480 0x0ef8 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:58:30.0480 0x0ef8 rdbss - ok
11:58:30.0495 0x0ef8 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:58:30.0495 0x0ef8 rdpbus - ok
11:58:30.0511 0x0ef8 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:58:30.0511 0x0ef8 RDPCDD - ok
11:58:30.0527 0x0ef8 [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
11:58:30.0542 0x0ef8 RDPDR - ok
11:58:30.0558 0x0ef8 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:58:30.0558 0x0ef8 RDPENCDD - ok
11:58:30.0558 0x0ef8 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:58:30.0558 0x0ef8 RDPREFMP - ok
11:58:30.0589 0x0ef8 [ F031683E6D1FEA157ABB2FF260B51E61, 83B552819A5964152882C527E1421DBCEAACC74DEB897E3C4B53F52F1467FED3 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:58:30.0589 0x0ef8 RDPWD - ok
11:58:30.0636 0x0ef8 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:58:30.0651 0x0ef8 rdyboost - ok
11:58:30.0667 0x0ef8 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll
11:58:30.0667 0x0ef8 RemoteAccess - ok
11:58:30.0683 0x0ef8 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:58:30.0698 0x0ef8 RemoteRegistry - ok
11:58:30.0729 0x0ef8 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:58:30.0729 0x0ef8 RpcEptMapper - ok
11:58:30.0745 0x0ef8 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe
11:58:30.0761 0x0ef8 RpcLocator - ok
11:58:30.0792 0x0ef8 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\Windows\system32\rpcss.dll
11:58:30.0807 0x0ef8 RpcSs - ok
11:58:30.0839 0x0ef8 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:58:30.0839 0x0ef8 rspndr - ok
11:58:30.0870 0x0ef8 [ 7DFD48E24479B68B258D8770121155A0, 3B5F7309403C46855DB888CF2058B07C9029690DBC7FB3224BAC7BE5547D2D57 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
11:58:30.0885 0x0ef8 RTL8167 - ok
11:58:30.0901 0x0ef8 [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap C:\Windows\system32\drivers\vms3cap.sys
11:58:30.0901 0x0ef8 s3cap - ok
11:58:30.0917 0x0ef8 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] SamSs C:\Windows\system32\lsass.exe
11:58:30.0917 0x0ef8 SamSs - ok
11:58:30.0948 0x0ef8 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:58:30.0948 0x0ef8 sbp2port - ok
11:58:30.0979 0x0ef8 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:58:30.0995 0x0ef8 SCardSvr - ok
11:58:31.0010 0x0ef8 [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:58:31.0010 0x0ef8 scfilter - ok
11:58:31.0073 0x0ef8 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll
11:58:31.0104 0x0ef8 Schedule - ok
11:58:31.0119 0x0ef8 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll
11:58:31.0135 0x0ef8 SCPolicySvc - ok
11:58:31.0151 0x0ef8 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:58:31.0166 0x0ef8 SDRSVC - ok
11:58:31.0182 0x0ef8 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:58:31.0182 0x0ef8 secdrv - ok
11:58:31.0197 0x0ef8 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll
11:58:31.0197 0x0ef8 seclogon - ok
11:58:31.0197 0x0ef8 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\System32\sens.dll
11:58:31.0213 0x0ef8 SENS - ok
11:58:31.0213 0x0ef8 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:58:31.0213 0x0ef8 SensrSvc - ok
11:58:31.0229 0x0ef8 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:58:31.0229 0x0ef8 Serenum - ok
11:58:31.0229 0x0ef8 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:58:31.0244 0x0ef8 Serial - ok
11:58:31.0244 0x0ef8 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:58:31.0244 0x0ef8 sermouse - ok
11:58:31.0275 0x0ef8 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll
11:58:31.0291 0x0ef8 SessionEnv - ok
11:58:31.0307 0x0ef8 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:58:31.0307 0x0ef8 sffdisk - ok
11:58:31.0307 0x0ef8 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:58:31.0307 0x0ef8 sffp_mmc - ok
11:58:31.0322 0x0ef8 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:58:31.0322 0x0ef8 sffp_sd - ok
11:58:31.0338 0x0ef8 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:58:31.0338 0x0ef8 sfloppy - ok
11:58:31.0369 0x0ef8 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:58:31.0385 0x0ef8 SharedAccess - ok
11:58:31.0400 0x0ef8 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:58:31.0416 0x0ef8 ShellHWDetection - ok
11:58:31.0431 0x0ef8 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\drivers\sisagp.sys
11:58:31.0431 0x0ef8 sisagp - ok
11:58:31.0447 0x0ef8 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:58:31.0447 0x0ef8 SiSRaid2 - ok
11:58:31.0463 0x0ef8 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:58:31.0463 0x0ef8 SiSRaid4 - ok
11:58:31.0494 0x0ef8 [ 50D9949020E02B847CD48F1243FCB895, 5BDAD5E44DE5B412645142810C5FCE4B2D9685F928FF4A6B836A9DCE7725BD78 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
11:58:31.0494 0x0ef8 SkypeUpdate - ok
11:58:31.0509 0x0ef8 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:58:31.0509 0x0ef8 Smb - ok
11:58:31.0541 0x0ef8 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:58:31.0541 0x0ef8 SNMPTRAP - ok
11:58:31.0541 0x0ef8 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys
11:58:31.0541 0x0ef8 spldr - ok
11:58:31.0572 0x0ef8 [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler C:\Windows\System32\spoolsv.exe
11:58:31.0572 0x0ef8 Spooler - ok
11:58:31.0743 0x0ef8 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe
11:58:31.0821 0x0ef8 sppsvc - ok
11:58:31.0837 0x0ef8 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:58:31.0853 0x0ef8 sppuinotify - ok
11:58:31.0884 0x0ef8 [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv C:\Windows\system32\DRIVERS\srv.sys
11:58:31.0899 0x0ef8 srv - ok
11:58:31.0931 0x0ef8 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:58:31.0946 0x0ef8 srv2 - ok
11:58:31.0977 0x0ef8 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:58:31.0977 0x0ef8 srvnet - ok
11:58:31.0993 0x0ef8 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:58:31.0993 0x0ef8 SSDPSRV - ok
11:58:32.0009 0x0ef8 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:58:32.0009 0x0ef8 SstpSvc - ok
11:58:32.0071 0x0ef8 [ 49D9C17FDDFAC66F27FA735E94923216, 18C8FE5B794927989CDD3BB7A5500C73CCC23559470EEB37D42FD9AD04098C0D ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
11:58:32.0071 0x0ef8 Stereo Service - ok
11:58:32.0087 0x0ef8 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:58:32.0087 0x0ef8 stexstor - ok
11:58:32.0118 0x0ef8 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll
11:58:32.0149 0x0ef8 StiSvc - ok
11:58:32.0165 0x0ef8 [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt C:\Windows\system32\drivers\vmstorfl.sys
11:58:32.0165 0x0ef8 storflt - ok
11:58:32.0196 0x0ef8 [ 0BF669F0A910BEDA4A32258D363AF2A5, 83EEBACDE4F69A2866B69CAA633F5C8B3CB01D88CEDB01B6EA5988E0A25CEE47 ] StorSvc C:\Windows\system32\storsvc.dll
11:58:32.0196 0x0ef8 StorSvc - ok
11:58:32.0211 0x0ef8 [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc C:\Windows\system32\drivers\storvsc.sys
11:58:32.0211 0x0ef8 storvsc - ok
11:58:32.0227 0x0ef8 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\drivers\swenum.sys
11:58:32.0227 0x0ef8 swenum - ok
11:58:32.0243 0x0ef8 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll
11:58:32.0258 0x0ef8 swprv - ok
11:58:32.0321 0x0ef8 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll
11:58:32.0367 0x0ef8 SysMain - ok
11:58:32.0383 0x0ef8 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
11:58:32.0383 0x0ef8 TabletInputService - ok
11:58:32.0414 0x0ef8 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll
11:58:32.0430 0x0ef8 TapiSrv - ok
11:58:32.0445 0x0ef8 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll
11:58:32.0445 0x0ef8 TBS - ok
11:58:32.0523 0x0ef8 [ CA59F7C570AF70BC174F477CFE2D9EE3, F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:58:32.0555 0x0ef8 Tcpip - ok
11:58:32.0617 0x0ef8 [ CA59F7C570AF70BC174F477CFE2D9EE3, F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:58:32.0679 0x0ef8 TCPIP6 - ok
11:58:32.0711 0x0ef8 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:58:32.0711 0x0ef8 tcpipreg - ok
11:58:32.0726 0x0ef8 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:58:32.0726 0x0ef8 TDPIPE - ok
11:58:32.0757 0x0ef8 [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:58:32.0757 0x0ef8 TDTCP - ok
11:58:32.0789 0x0ef8 [ B459575348C20E8121D6039DA063C704, 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:58:32.0789 0x0ef8 tdx - ok
11:58:33.0007 0x0ef8 [ DF4A7E1E2BA788E28747F1EF49692ED6, 3417C0C713AB086E31CA20D6DCE923FF224093CFF2BAA6F29DCCBD2BEE5EEED6 ] TeamViewer9 C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
11:58:33.0163 0x0ef8 TeamViewer9 - ok
11:58:33.0194 0x0ef8 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\drivers\termdd.sys
11:58:33.0194 0x0ef8 TermDD - ok
11:58:33.0241 0x0ef8 [ 382C804C92811BE57829D8E550A900E2, 5F52C2E7902024CF1C9CC0069F411C3F19CCA3DB209F437FA0F3932D4898EB50 ] TermService C:\Windows\System32\termsrv.dll
11:58:33.0272 0x0ef8 TermService - ok
11:58:33.0288 0x0ef8 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll
11:58:33.0288 0x0ef8 Themes - ok
11:58:33.0303 0x0ef8 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll
11:58:33.0319 0x0ef8 THREADORDER - ok
11:58:33.0335 0x0ef8 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll
11:58:33.0335 0x0ef8 TrkWks - ok
11:58:33.0397 0x0ef8 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:58:33.0413 0x0ef8 TrustedInstaller - ok
11:58:33.0444 0x0ef8 [ B37B08F2E5EEB1A37E448E09BACE1101, 32CC9E06B88BAB6FAB4696B744548DFCE9199A7FD2BA8B019F269CA75895852C ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:58:33.0444 0x0ef8 tssecsrv - ok
11:58:33.0459 0x0ef8 [ FD1D6C73E6333BE727CBCC6054247654, 6F7B9AE1A5986204DB3348D13B303F30FC17624939DA74D6BD114FAEED0FB30E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:58:33.0475 0x0ef8 TsUsbFlt - ok
11:58:33.0506 0x0ef8 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:58:33.0506 0x0ef8 tunnel - ok
11:58:33.0522 0x0ef8 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:58:33.0537 0x0ef8 uagp35 - ok
11:58:33.0553 0x0ef8 [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:58:33.0569 0x0ef8 udfs - ok
11:58:33.0584 0x0ef8 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:58:33.0584 0x0ef8 UI0Detect - ok
11:58:33.0615 0x0ef8 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:58:33.0615 0x0ef8 uliagpkx - ok
11:58:33.0631 0x0ef8 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\drivers\umbus.sys
11:58:33.0631 0x0ef8 umbus - ok
11:58:33.0647 0x0ef8 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:58:33.0647 0x0ef8 UmPass - ok
11:58:33.0678 0x0ef8 [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService C:\Windows\System32\umrdp.dll
11:58:33.0693 0x0ef8 UmRdpService - ok
11:58:33.0709 0x0ef8 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll
11:58:33.0725 0x0ef8 upnphost - ok
11:58:33.0740 0x0ef8 [ 71D97F1A3CC47A56728F7A400A3F8295, ED3FDB73D8A98D9BAF702C0F5C7AD79D525D19DCE1487D442536913BEA5C7F15 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:58:33.0740 0x0ef8 usbccgp - ok
11:58:33.0771 0x0ef8 [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:58:33.0771 0x0ef8 usbcir - ok
11:58:33.0803 0x0ef8 [ C4FB8E7ADEA9B5CEEA885A1B504B7E40, 3E0AE5D236890452F2EA33504309A7E5FE49C567FF6F68A83A5987F05ED01BF0 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
11:58:33.0803 0x0ef8 usbehci - ok
11:58:33.0834 0x0ef8 [ 86AA95ACB611001E26CD2C0145F2225A, 584D26E8C9407A4E717DCBF2D3819DB441C2D455B5FDA6654FBA3794E19B4D51 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:58:33.0849 0x0ef8 usbhub - ok
11:58:33.0865 0x0ef8 [ DCDF9855145A14DFCA0AB32308871961, 9A21013AD032195D54CE655DE5363E78BB74CC55C40B889520B478892F4BA40A ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
11:58:33.0865 0x0ef8 usbohci - ok
11:58:33.0881 0x0ef8 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:58:33.0881 0x0ef8 usbprint - ok
11:58:33.0896 0x0ef8 [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:58:33.0896 0x0ef8 USBSTOR - ok
11:58:33.0927 0x0ef8 [ 8E51D04175BAA14C4F79AA5F6D248770, 6CE2E45E272734A5D1D0C4CE2BD7B61C61C7538903E87203E376495D198EFBD0 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
11:58:33.0927 0x0ef8 usbuhci - ok
11:58:33.0943 0x0ef8 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll
11:58:33.0943 0x0ef8 UxSms - ok
11:58:33.0959 0x0ef8 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] VaultSvc C:\Windows\system32\lsass.exe
11:58:33.0959 0x0ef8 VaultSvc - ok
11:58:33.0974 0x0ef8 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:58:33.0974 0x0ef8 vdrvroot - ok
11:58:34.0005 0x0ef8 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe
11:58:34.0037 0x0ef8 vds - ok
11:58:34.0052 0x0ef8 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:58:34.0052 0x0ef8 vga - ok
11:58:34.0068 0x0ef8 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys
11:58:34.0068 0x0ef8 VgaSave - ok
11:58:34.0099 0x0ef8 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:58:34.0099 0x0ef8 vhdmp - ok
11:58:34.0130 0x0ef8 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys
11:58:34.0130 0x0ef8 viaagp - ok
11:58:34.0146 0x0ef8 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
11:58:34.0146 0x0ef8 ViaC7 - ok
11:58:34.0177 0x0ef8 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys
11:58:34.0177 0x0ef8 viaide - ok
11:58:34.0193 0x0ef8 [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus C:\Windows\system32\drivers\vmbus.sys
11:58:34.0208 0x0ef8 vmbus - ok
11:58:34.0224 0x0ef8 [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
11:58:34.0224 0x0ef8 VMBusHID - ok
11:58:34.0239 0x0ef8 [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:58:34.0255 0x0ef8 volmgr - ok
11:58:34.0271 0x0ef8 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:58:34.0286 0x0ef8 volmgrx - ok
11:58:34.0317 0x0ef8 [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:58:34.0333 0x0ef8 volsnap - ok
11:58:34.0349 0x0ef8 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:58:34.0349 0x0ef8 vsmraid - ok
11:58:34.0427 0x0ef8 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe
11:58:34.0458 0x0ef8 VSS - ok
11:58:34.0473 0x0ef8 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
11:58:34.0473 0x0ef8 vwifibus - ok
11:58:34.0505 0x0ef8 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll
11:58:34.0520 0x0ef8 W32Time - ok
11:58:34.0536 0x0ef8 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:58:34.0536 0x0ef8 WacomPen - ok
11:58:34.0567 0x0ef8 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:58:34.0567 0x0ef8 WANARP - ok
11:58:34.0567 0x0ef8 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:58:34.0583 0x0ef8 Wanarpv6 - ok
11:58:34.0676 0x0ef8 [ 353A04C273EC58475D8633E75CCD5604, FFAE53B6B53AEFC9E8A10BF27480E072D74430276BEB532FE1D473E9616D8CE0 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:58:34.0707 0x0ef8 WatAdminSvc - ok
11:58:34.0770 0x0ef8 [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\Windows\system32\wbengine.exe
11:58:34.0801 0x0ef8 wbengine - ok
11:58:34.0832 0x0ef8 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:58:34.0832 0x0ef8 WbioSrvc - ok
11:58:34.0863 0x0ef8 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:58:34.0879 0x0ef8 wcncsvc - ok
11:58:34.0895 0x0ef8 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:58:34.0895 0x0ef8 WcsPlugInService - ok
11:58:34.0895 0x0ef8 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:58:34.0895 0x0ef8 Wd - ok
11:58:34.0941 0x0ef8 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:58:34.0973 0x0ef8 Wdf01000 - ok
11:58:34.0988 0x0ef8 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:58:34.0988 0x0ef8 WdiServiceHost - ok
11:58:35.0004 0x0ef8 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:58:35.0019 0x0ef8 WdiSystemHost - ok
11:58:35.0035 0x0ef8 [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient C:\Windows\System32\webclnt.dll
11:58:35.0051 0x0ef8 WebClient - ok
11:58:35.0066 0x0ef8 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:58:35.0066 0x0ef8 Wecsvc - ok
11:58:35.0082 0x0ef8 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:58:35.0082 0x0ef8 wercplsupport - ok
11:58:35.0097 0x0ef8 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll
11:58:35.0097 0x0ef8 WerSvc - ok
11:58:35.0129 0x0ef8 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:58:35.0129 0x0ef8 WfpLwf - ok
11:58:35.0144 0x0ef8 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:58:35.0144 0x0ef8 WIMMount - ok
11:58:35.0207 0x0ef8 [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:58:35.0238 0x0ef8 WinDefend - ok
11:58:35.0253 0x0ef8 WinHttpAutoProxySvc - ok
11:58:35.0300 0x0ef8 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:58:35.0316 0x0ef8 Winmgmt - ok
11:58:35.0394 0x0ef8 [ 1B91CD34EA3A90AB6A4EF0550174F4CC, 5B6618615EBFBA594C945AD35F5C68DA8C6053892B6D12D626BB6120910D80DC ] WinRM C:\Windows\system32\WsmSvc.dll
11:58:35.0456 0x0ef8 WinRM - ok
11:58:35.0503 0x0ef8 [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUSB C:\Windows\system32\DRIVERS\WinUSB.sys
11:58:35.0503 0x0ef8 WinUSB - ok
11:58:35.0550 0x0ef8 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:58:35.0612 0x0ef8 Wlansvc - ok
11:58:35.0628 0x0ef8 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:58:35.0628 0x0ef8 WmiAcpi - ok
11:58:35.0659 0x0ef8 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:58:35.0659 0x0ef8 wmiApSrv - ok
11:58:35.0721 0x0ef8 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:58:35.0753 0x0ef8 WMPNetworkSvc - ok
11:58:35.0784 0x0ef8 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:58:35.0815 0x0ef8 WPCSvc - ok
11:58:35.0846 0x0ef8 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:58:35.0862 0x0ef8 WPDBusEnum - ok
11:58:35.0877 0x0ef8 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:58:35.0893 0x0ef8 ws2ifsl - ok
11:58:35.0909 0x0ef8 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\System32\wscsvc.dll
11:58:35.0909 0x0ef8 wscsvc - ok
11:58:35.0924 0x0ef8 WSearch - ok
11:58:36.0033 0x0ef8 [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll
11:58:36.0143 0x0ef8 wuauserv - ok
11:58:36.0174 0x0ef8 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:58:36.0189 0x0ef8 WudfPf - ok
11:58:36.0189 0x0ef8 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:58:36.0205 0x0ef8 WUDFRd - ok
11:58:36.0221 0x0ef8 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:58:36.0221 0x0ef8 wudfsvc - ok
11:58:36.0267 0x0ef8 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4, 10D9FDEDAB1FB2E76D54661AFA5C1A6B1B0980525F38F5D061537077841C6AEE ] WwanSvc C:\Windows\System32\wwansvc.dll
11:58:36.0283 0x0ef8 WwanSvc - ok
11:58:36.0330 0x0ef8 [ 74EC37B9EAF9FCA015B933A526825C7A, E75D73422B4383210F912B424377D5F2DBBF0E9418A2F450636B689572B1B9F6 ] {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC} C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl
11:58:36.0345 0x0ef8 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC} - ok
11:58:36.0361 0x0ef8 ================ Scan global ===============================
11:58:36.0392 0x0ef8 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
11:58:36.0408 0x0ef8 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
11:58:36.0439 0x0ef8 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
11:58:36.0470 0x0ef8 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
11:58:36.0501 0x0ef8 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
11:58:36.0517 0x0ef8 [ Global ] - ok
11:58:36.0517 0x0ef8 ================ Scan MBR ==================================
11:58:36.0517 0x0ef8 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:58:36.0969 0x0ef8 \Device\Harddisk0\DR0 - ok
11:58:36.0969 0x0ef8 ================ Scan VBR ==================================
11:58:36.0969 0x0ef8 [ 12BDD1C05FCFE9A4D0C38C6C180F42E5 ] \Device\Harddisk0\DR0\Partition1
11:58:36.0969 0x0ef8 \Device\Harddisk0\DR0\Partition1 - ok
11:58:36.0985 0x0ef8 [ B76DDEF4BD512DC571B5EEEAAFBD4457 ] \Device\Harddisk0\DR0\Partition2
11:58:37.0001 0x0ef8 \Device\Harddisk0\DR0\Partition2 - ok
11:58:37.0001 0x0ef8 Waiting for KSN requests completion. In queue: 324
11:58:38.0015 0x0ef8 Waiting for KSN requests completion. In queue: 324
11:58:39.0029 0x0ef8 Waiting for KSN requests completion. In queue: 17
11:58:40.0058 0x0ef8 AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.4.304.0 ), 0x60000 ( disabled : updated )
11:58:40.0058 0x0ef8 Win FW state via NFP2: disabled
11:58:42.0804 0x0ef8 ============================================================
11:58:42.0804 0x0ef8 Scan finished
11:58:42.0804 0x0ef8 ============================================================
11:58:42.0819 0x1600 Detected object count: 0
11:58:42.0819 0x1600 Actual detected object count: 0
11:59:01.0305 0x1024 Deinitialize success
prosím o kontrolu Vyřešeno
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: prosím o kontrolu
ComboFix 14-01-08.03 - mnouckk 10.01.2014 17:41:07.1.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3070.2160 [GMT 1:00]
Spuštěný z: c:\users\mnouckk\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\mnouckk\AppData\Roaming\Roaming
c:\users\mnouckk\AppData\Roaming\svchost.exe
D:\install.exe
D:\yxmj.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-10 do 2014-01-10 )))))))))))))))))))))))))))))))
.
.
2014-01-10 16:49 . 2014-01-10 16:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-10 11:12 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{98F19FC2-0F36-4F7D-9D4B-115D1D06C4C8}\mpengine.dll
2014-01-10 09:57 . 2014-01-10 09:57 22688 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2014-01-10 09:57 . 2014-01-10 09:57 -------- d-----w- c:\program files\HWiNFO32
2014-01-10 08:59 . 2014-01-10 08:59 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2014-01-09 22:38 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\programdata\Malwarebytes
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-01-09 22:28 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-09 22:20 . 2014-01-10 07:30 -------- d-----w- C:\AdwCleaner
2014-01-09 19:04 . 2014-01-09 19:04 -------- d-----w- c:\program files\HiJack
2014-01-05 12:28 . 2014-01-05 12:28 -------- d-----w- c:\programdata\Codemasters
2014-01-05 12:26 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\system32\nircmdc.exe
2014-01-05 11:35 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-05 11:35 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-05 11:35 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-05 11:35 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-05 11:35 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-05 11:35 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-05 11:35 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-04 19:26 . 2014-01-04 19:26 -------- d-----w- c:\program files\GSC World Publishing
2014-01-04 10:59 . 2013-12-05 08:42 34080 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2014-01-04 10:57 . 2013-12-10 02:13 982232 ----a-w- c:\windows\system32\nvspcap.dll
2014-01-04 10:56 . 2014-01-04 10:56 -------- d-----w- c:\program files\AGEIA Technologies
2014-01-04 10:55 . 2014-01-10 11:00 -------- d-----w- c:\programdata\NVIDIA
2014-01-04 10:55 . 2013-11-11 14:26 4321056 ----a-w- c:\windows\system32\nvcpl.dll
2014-01-04 10:55 . 2013-11-11 14:26 3036960 ----a-w- c:\windows\system32\nvsvc.dll
2014-01-04 10:55 . 2013-11-11 14:26 664352 ----a-w- c:\windows\system32\nvvsvc.exe
2014-01-04 10:55 . 2013-11-11 14:26 62752 ----a-w- c:\windows\system32\nvshext.dll
2014-01-04 10:55 . 2013-11-11 14:26 209184 ----a-w- c:\windows\system32\nvmctray.dll
2014-01-04 10:54 . 2013-11-14 11:55 53024 ----a-w- c:\windows\system32\OpenCL.dll
2014-01-04 10:54 . 2014-01-04 11:00 -------- d-----w- c:\programdata\NVIDIA Corporation
2014-01-04 10:49 . 2014-01-04 10:59 -------- d-----w- c:\program files\NVIDIA Corporation
2014-01-04 10:49 . 2014-01-04 10:49 -------- d-----w- C:\NVIDIA
2014-01-04 10:44 . 2005-10-28 13:58 45056 ----a-w- c:\windows\system32\ActiveDestopOCX.ocx
2014-01-04 10:43 . 2014-01-04 10:43 -------- d-----w- c:\program files\MSI
2014-01-04 10:43 . 1998-10-02 18:00 327168 ----a-w- c:\windows\IsUninst.exe
2014-01-04 10:38 . 2008-10-02 09:07 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2014-01-04 10:16 . 2014-01-04 10:22 -------- d-----w- c:\program files\AIMP3
2014-01-04 10:06 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2014-01-04 09:53 . 2014-01-04 09:56 -------- d-----w- c:\windows\system32\MRT
2014-01-03 21:32 . 2014-01-03 21:32 -------- d-----w- c:\programdata\The Revills Games
2014-01-03 21:31 . 2014-01-03 21:32 -------- d-----w- c:\program files\Common Files\Adobe
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\program files\Legends of Solitaire 2 - Curse of the Dragons
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\windows\Legends of Solitaire 2 - Curse of the Dragons
2014-01-01 22:16 . 2014-01-01 22:16 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Synchronization Services
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\windows\PCHEALTH
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Sync Framework
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2014-01-01 20:42 . 2014-01-01 20:42 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2014-01-01 20:41 . 2014-01-01 20:41 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-01-01 20:40 . 2014-01-02 22:18 -------- d-----w- c:\programdata\Microsoft Help
2014-01-01 20:40 . 2014-01-01 20:40 -------- d-----r- C:\MSOCache
2014-01-01 20:34 . 2014-01-01 20:34 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-01-01 20:34 . 2014-01-01 20:34 -------- d-----w- c:\program files\DAEMON Tools Lite
2014-01-01 20:27 . 2014-01-01 20:40 -------- d-----w- c:\programdata\DAEMON Tools Lite
2014-01-01 19:21 . 2014-01-02 13:37 -------- d-----w- c:\program files\Holdem Manager 2
2014-01-01 13:37 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2014-01-01 13:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-01-01 13:37 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe
2014-01-01 13:37 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-01 01:24 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-01-01 01:24 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-01-01 01:10 . 2014-01-01 01:10 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-12-31 18:43 . 2013-10-30 02:19 301568 ----a-w- c:\windows\system32\msieftp.dll
2013-12-31 18:43 . 2013-09-25 02:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-12-31 18:43 . 2013-09-25 01:57 247808 ----a-w- c:\windows\system32\schannel.dll
2013-12-31 18:43 . 2013-07-04 12:16 369848 ----a-w- c:\windows\system32\drivers\cng.sys
2013-12-31 18:43 . 2013-09-25 02:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-12-31 18:43 . 2013-09-25 01:57 99840 ----a-w- c:\windows\system32\sspicli.dll
2013-12-31 18:43 . 2013-09-25 01:57 22016 ----a-w- c:\windows\system32\secur32.dll
2013-12-31 18:43 . 2013-09-25 01:56 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-12-31 18:43 . 2013-09-25 01:56 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2013-12-31 18:43 . 2013-09-25 00:49 22016 ----a-w- c:\windows\system32\lsass.exe
2013-12-31 18:43 . 2013-09-25 00:49 15872 ----a-w- c:\windows\system32\sspisrv.dll
2013-12-31 18:41 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-12-31 18:40 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-12-31 18:39 . 2012-10-09 17:40 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-12-31 18:14 . 2014-01-05 09:36 -------- d-----w- c:\users\postgres
2013-12-31 18:08 . 2014-01-01 19:46 -------- d-----w- c:\program files\PSQLINSTALL
2013-12-31 15:44 . 2013-12-31 15:44 -------- d-----w- c:\programdata\SP_FT_Logs
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\SPReview
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\EventProviders
2013-12-31 07:51 . 2014-01-06 16:27 -------- d-----w- c:\users\Guest
2013-12-30 22:34 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-12-30 22:32 . 2010-11-20 12:30 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys
2013-12-30 22:31 . 2010-11-20 12:21 8704 ----a-w- c:\windows\system32\rdpcfgex.dll
2013-12-30 21:57 . 2013-10-27 22:41 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DD6078AC-1BDD-4201-B14C-36B308FCA642}\gapaengine.dll
2013-12-30 21:42 . 2013-12-30 21:42 -------- d-----w- c:\program files\Microsoft Security Client
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Common Files\InstallShield
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Browser Configuration Utility
2013-12-30 19:23 . 2008-05-02 14:08 146528 ----a-w- c:\windows\system32\dvmurl.dll
2013-12-30 19:22 . 2013-12-30 19:26 16608 ----a-w- c:\windows\gdrv.sys
2013-12-30 18:13 . 2013-12-30 22:09 -------- d-----w- c:\program files\LenovoUsbDriver
2013-12-30 17:24 . 2013-12-30 17:26 -------- d-----w- c:\program files\PdaNet for Android
2013-12-30 17:24 . 2011-07-19 10:28 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2013-12-30 17:24 . 2009-11-08 01:41 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2013-12-30 17:24 . 2009-11-08 01:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\TeamViewer
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\Common Files\Skype
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----r- c:\program files\Skype
2013-12-30 16:58 . 2014-01-03 11:10 -------- d-----w- c:\programdata\Skype
2013-12-30 14:43 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-12-30 14:43 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-12-30 14:43 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2013-12-30 14:43 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-12-30 14:43 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2013-12-30 14:43 . 2013-02-12 03:32 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-12-30 14:42 . 2012-11-02 05:11 376832 ----a-w- c:\windows\system32\dpnet.dll
2013-12-30 14:42 . 2010-11-20 11:57 2560 ----a-w- c:\windows\system32\dpnaddr.dll
2013-12-30 14:42 . 2011-02-18 05:39 31232 ----a-w- c:\windows\system32\prevhost.exe
2013-12-30 14:42 . 2013-01-24 04:47 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-12-30 14:42 . 2011-03-03 05:38 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2013-12-30 14:42 . 2011-03-03 05:36 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2013-12-30 14:42 . 2011-10-01 04:37 708608 ----a-w- c:\program files\Common Files\System\wab32.dll
2013-12-30 14:42 . 2013-03-19 04:48 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-12-30 14:42 . 2013-03-19 02:49 69632 ----a-w- c:\windows\system32\smss.exe
2013-12-30 14:37 . 2012-11-01 04:47 1389568 ----a-w- c:\windows\system32\msxml6.dll
2013-12-30 14:37 . 2011-05-03 04:30 741376 ----a-w- c:\windows\system32\inetcomm.dll
2013-12-30 14:36 . 2013-01-03 05:04 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-12-30 14:36 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2013-12-30 14:36 . 2011-11-19 14:01 67072 ----a-w- c:\windows\system32\packager.dll
2013-12-30 14:34 . 2011-10-26 04:32 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-12-30 14:33 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-10 10:53 . 2014-01-10 07:47 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16384 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14912 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35968 ----a-w- c:\windows\system32\drivers\winusb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 9728 ----a-w- c:\windows\system32\drivers\wfplwf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 63488 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43392 ----a-w- c:\windows\system32\drivers\winhv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\watchdog.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21632 ----a-w- c:\windows\system32\drivers\wacompen.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19024 ----a-w- c:\windows\system32\drivers\wd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19008 ----a-w- c:\windows\system32\drivers\wimmount.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14336 ----a-w- c:\windows\system32\drivers\vwifimp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 48128 ----a-w- c:\windows\system32\drivers\vwififlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40704 ----a-w- c:\windows\system32\drivers\vmstorfl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 297040 ----a-w- c:\windows\system32\drivers\volmgrx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 245632 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\vwifibus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 141904 ----a-w- c:\windows\system32\drivers\vsmraid.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 5632 ----a-w- c:\windows\system32\drivers\vms3cap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17920 ----a-w- c:\windows\system32\drivers\VMBusHID.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 175360 ----a-w- c:\windows\system32\drivers\vmbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 111616 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53328 ----a-w- c:\windows\system32\drivers\VIAAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52736 ----a-w- c:\windows\system32\drivers\viac7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\vgapnp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16976 ----a-w- c:\windows\system32\drivers\viaide.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 160128 ----a-w- c:\windows\system32\drivers\vhdmp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 32832 ----a-w- c:\windows\system32\drivers\vdrvroot.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\usbrpm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25088 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\usbprint.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 284672 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 6016 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 8192 ----a-w- c:\windows\system32\drivers\umpass.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 57424 ----a-w- c:\windows\system32\drivers\ULIAGPKX.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 55888 ----a-w- c:\windows\system32\drivers\UAGP35.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52224 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 39936 ----a-w- c:\windows\system32\drivers\umbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 246784 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 108544 ----a-w- c:\windows\system32\drivers\tunnel.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 74752 ----a-w- c:\windows\system32\drivers\tdx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 18432 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21504 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53632 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 28032 ----a-w- c:\windows\system32\drivers\storvsc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21072 ----a-w- c:\windows\system32\drivers\stexstor.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 148864 ----a-w- c:\windows\system32\drivers\storport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 12240 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 311808 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 310272 ----a-w- c:\windows\system32\drivers\srv2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 77888 ----a-w- c:\windows\system32\drivers\sisraid4.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 71168 ----a-w- c:\windows\system32\drivers\smb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 52304 ----a-w- c:\windows\system32\drivers\SISAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 405504 ----a-w- c:\windows\system32\drivers\spsys.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40016 ----a-w- c:\windows\system32\drivers\sisraid2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17472 ----a-w- c:\windows\system32\drivers\spldr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17408 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 13824 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 83456 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 26624 ----a-w- c:\windows\system32\drivers\scfilter.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 19968 ----a-w- c:\windows\system32\drivers\sermouse.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 17920 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 140160 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12288 ----a-w- c:\windows\system32\drivers\sffp_mmc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 11264 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 85376 ----a-w- c:\windows\system32\drivers\sbp2port.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 8192 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 60928 ----a-w- c:\windows\system32\drivers\rspndr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 2152088 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 139776 ----a-w- c:\windows\system32\drivers\Rt86win7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 173440 ----a-w- c:\windows\system32\drivers\rdyboost.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 117760 ----a-w- c:\windows\system32\drivers\rmcast.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 7168 ----a-w- c:\windows\system32\drivers\RDPREFMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys.bak
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-04-02 75048]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2013-12-10 982232]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"mshnpmisSrv"="c:\windows\inf\mshnpmis.vbe" [2013-08-27 1558]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-12-31 280576]
.
c:\users\mnouckk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Bitcoin.lnk - c:\program files\Bitcoin\bitcoin-qt.exe -min [2011-1-30 22613504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:a1179063 /dir:C:\Program
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 13312]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-12-30 1343400]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-01-01 243128]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2014-01-10 22688]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2013/12/29 23:46];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-04-02 08:11 87536]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;c:/postgreSQL/bin/pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-11-11 414496]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-29 22:18 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-29 22:40]
.
2014-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-29 22:18]
.
2014-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-29 22:18]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 77.48.100.254 212.80.66.7
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight]
"ImagePath"="\??\"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-01-10 17:51:22
ComboFix-quarantined-files.txt 2014-01-10 16:51
.
Před spuštěním: Volných bajtů: 50 328 334 336
Po spuštění: Volných bajtů: 50 795 114 496
.
- - End Of File - - 00B7C0A6A7512536A4131E756D3B0E6D
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3070.2160 [GMT 1:00]
Spuštěný z: c:\users\mnouckk\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\mnouckk\AppData\Roaming\Roaming
c:\users\mnouckk\AppData\Roaming\svchost.exe
D:\install.exe
D:\yxmj.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-10 do 2014-01-10 )))))))))))))))))))))))))))))))
.
.
2014-01-10 16:49 . 2014-01-10 16:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-10 11:12 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{98F19FC2-0F36-4F7D-9D4B-115D1D06C4C8}\mpengine.dll
2014-01-10 09:57 . 2014-01-10 09:57 22688 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2014-01-10 09:57 . 2014-01-10 09:57 -------- d-----w- c:\program files\HWiNFO32
2014-01-10 08:59 . 2014-01-10 08:59 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2014-01-09 22:38 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\programdata\Malwarebytes
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-01-09 22:28 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-09 22:20 . 2014-01-10 07:30 -------- d-----w- C:\AdwCleaner
2014-01-09 19:04 . 2014-01-09 19:04 -------- d-----w- c:\program files\HiJack
2014-01-05 12:28 . 2014-01-05 12:28 -------- d-----w- c:\programdata\Codemasters
2014-01-05 12:26 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\system32\nircmdc.exe
2014-01-05 11:35 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-05 11:35 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-05 11:35 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-05 11:35 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-05 11:35 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-05 11:35 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-05 11:35 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-04 19:26 . 2014-01-04 19:26 -------- d-----w- c:\program files\GSC World Publishing
2014-01-04 10:59 . 2013-12-05 08:42 34080 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2014-01-04 10:57 . 2013-12-10 02:13 982232 ----a-w- c:\windows\system32\nvspcap.dll
2014-01-04 10:56 . 2014-01-04 10:56 -------- d-----w- c:\program files\AGEIA Technologies
2014-01-04 10:55 . 2014-01-10 11:00 -------- d-----w- c:\programdata\NVIDIA
2014-01-04 10:55 . 2013-11-11 14:26 4321056 ----a-w- c:\windows\system32\nvcpl.dll
2014-01-04 10:55 . 2013-11-11 14:26 3036960 ----a-w- c:\windows\system32\nvsvc.dll
2014-01-04 10:55 . 2013-11-11 14:26 664352 ----a-w- c:\windows\system32\nvvsvc.exe
2014-01-04 10:55 . 2013-11-11 14:26 62752 ----a-w- c:\windows\system32\nvshext.dll
2014-01-04 10:55 . 2013-11-11 14:26 209184 ----a-w- c:\windows\system32\nvmctray.dll
2014-01-04 10:54 . 2013-11-14 11:55 53024 ----a-w- c:\windows\system32\OpenCL.dll
2014-01-04 10:54 . 2014-01-04 11:00 -------- d-----w- c:\programdata\NVIDIA Corporation
2014-01-04 10:49 . 2014-01-04 10:59 -------- d-----w- c:\program files\NVIDIA Corporation
2014-01-04 10:49 . 2014-01-04 10:49 -------- d-----w- C:\NVIDIA
2014-01-04 10:44 . 2005-10-28 13:58 45056 ----a-w- c:\windows\system32\ActiveDestopOCX.ocx
2014-01-04 10:43 . 2014-01-04 10:43 -------- d-----w- c:\program files\MSI
2014-01-04 10:43 . 1998-10-02 18:00 327168 ----a-w- c:\windows\IsUninst.exe
2014-01-04 10:38 . 2008-10-02 09:07 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2014-01-04 10:16 . 2014-01-04 10:22 -------- d-----w- c:\program files\AIMP3
2014-01-04 10:06 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2014-01-04 09:53 . 2014-01-04 09:56 -------- d-----w- c:\windows\system32\MRT
2014-01-03 21:32 . 2014-01-03 21:32 -------- d-----w- c:\programdata\The Revills Games
2014-01-03 21:31 . 2014-01-03 21:32 -------- d-----w- c:\program files\Common Files\Adobe
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\program files\Legends of Solitaire 2 - Curse of the Dragons
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\windows\Legends of Solitaire 2 - Curse of the Dragons
2014-01-01 22:16 . 2014-01-01 22:16 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Synchronization Services
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\windows\PCHEALTH
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Sync Framework
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2014-01-01 20:42 . 2014-01-01 20:42 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2014-01-01 20:41 . 2014-01-01 20:41 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-01-01 20:40 . 2014-01-02 22:18 -------- d-----w- c:\programdata\Microsoft Help
2014-01-01 20:40 . 2014-01-01 20:40 -------- d-----r- C:\MSOCache
2014-01-01 20:34 . 2014-01-01 20:34 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-01-01 20:34 . 2014-01-01 20:34 -------- d-----w- c:\program files\DAEMON Tools Lite
2014-01-01 20:27 . 2014-01-01 20:40 -------- d-----w- c:\programdata\DAEMON Tools Lite
2014-01-01 19:21 . 2014-01-02 13:37 -------- d-----w- c:\program files\Holdem Manager 2
2014-01-01 13:37 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2014-01-01 13:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-01-01 13:37 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe
2014-01-01 13:37 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-01 01:24 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-01-01 01:24 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-01-01 01:10 . 2014-01-01 01:10 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-12-31 18:43 . 2013-10-30 02:19 301568 ----a-w- c:\windows\system32\msieftp.dll
2013-12-31 18:43 . 2013-09-25 02:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-12-31 18:43 . 2013-09-25 01:57 247808 ----a-w- c:\windows\system32\schannel.dll
2013-12-31 18:43 . 2013-07-04 12:16 369848 ----a-w- c:\windows\system32\drivers\cng.sys
2013-12-31 18:43 . 2013-09-25 02:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-12-31 18:43 . 2013-09-25 01:57 99840 ----a-w- c:\windows\system32\sspicli.dll
2013-12-31 18:43 . 2013-09-25 01:57 22016 ----a-w- c:\windows\system32\secur32.dll
2013-12-31 18:43 . 2013-09-25 01:56 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-12-31 18:43 . 2013-09-25 01:56 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2013-12-31 18:43 . 2013-09-25 00:49 22016 ----a-w- c:\windows\system32\lsass.exe
2013-12-31 18:43 . 2013-09-25 00:49 15872 ----a-w- c:\windows\system32\sspisrv.dll
2013-12-31 18:41 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-12-31 18:40 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-12-31 18:39 . 2012-10-09 17:40 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-12-31 18:14 . 2014-01-05 09:36 -------- d-----w- c:\users\postgres
2013-12-31 18:08 . 2014-01-01 19:46 -------- d-----w- c:\program files\PSQLINSTALL
2013-12-31 15:44 . 2013-12-31 15:44 -------- d-----w- c:\programdata\SP_FT_Logs
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\SPReview
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\EventProviders
2013-12-31 07:51 . 2014-01-06 16:27 -------- d-----w- c:\users\Guest
2013-12-30 22:34 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-12-30 22:32 . 2010-11-20 12:30 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys
2013-12-30 22:31 . 2010-11-20 12:21 8704 ----a-w- c:\windows\system32\rdpcfgex.dll
2013-12-30 21:57 . 2013-10-27 22:41 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DD6078AC-1BDD-4201-B14C-36B308FCA642}\gapaengine.dll
2013-12-30 21:42 . 2013-12-30 21:42 -------- d-----w- c:\program files\Microsoft Security Client
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Common Files\InstallShield
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Browser Configuration Utility
2013-12-30 19:23 . 2008-05-02 14:08 146528 ----a-w- c:\windows\system32\dvmurl.dll
2013-12-30 19:22 . 2013-12-30 19:26 16608 ----a-w- c:\windows\gdrv.sys
2013-12-30 18:13 . 2013-12-30 22:09 -------- d-----w- c:\program files\LenovoUsbDriver
2013-12-30 17:24 . 2013-12-30 17:26 -------- d-----w- c:\program files\PdaNet for Android
2013-12-30 17:24 . 2011-07-19 10:28 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2013-12-30 17:24 . 2009-11-08 01:41 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2013-12-30 17:24 . 2009-11-08 01:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\TeamViewer
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\Common Files\Skype
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----r- c:\program files\Skype
2013-12-30 16:58 . 2014-01-03 11:10 -------- d-----w- c:\programdata\Skype
2013-12-30 14:43 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-12-30 14:43 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-12-30 14:43 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2013-12-30 14:43 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-12-30 14:43 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2013-12-30 14:43 . 2013-02-12 03:32 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-12-30 14:42 . 2012-11-02 05:11 376832 ----a-w- c:\windows\system32\dpnet.dll
2013-12-30 14:42 . 2010-11-20 11:57 2560 ----a-w- c:\windows\system32\dpnaddr.dll
2013-12-30 14:42 . 2011-02-18 05:39 31232 ----a-w- c:\windows\system32\prevhost.exe
2013-12-30 14:42 . 2013-01-24 04:47 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-12-30 14:42 . 2011-03-03 05:38 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2013-12-30 14:42 . 2011-03-03 05:36 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2013-12-30 14:42 . 2011-10-01 04:37 708608 ----a-w- c:\program files\Common Files\System\wab32.dll
2013-12-30 14:42 . 2013-03-19 04:48 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-12-30 14:42 . 2013-03-19 02:49 69632 ----a-w- c:\windows\system32\smss.exe
2013-12-30 14:37 . 2012-11-01 04:47 1389568 ----a-w- c:\windows\system32\msxml6.dll
2013-12-30 14:37 . 2011-05-03 04:30 741376 ----a-w- c:\windows\system32\inetcomm.dll
2013-12-30 14:36 . 2013-01-03 05:04 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-12-30 14:36 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2013-12-30 14:36 . 2011-11-19 14:01 67072 ----a-w- c:\windows\system32\packager.dll
2013-12-30 14:34 . 2011-10-26 04:32 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-12-30 14:33 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-10 10:53 . 2014-01-10 07:47 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16384 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14912 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35968 ----a-w- c:\windows\system32\drivers\winusb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 9728 ----a-w- c:\windows\system32\drivers\wfplwf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 63488 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43392 ----a-w- c:\windows\system32\drivers\winhv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\watchdog.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21632 ----a-w- c:\windows\system32\drivers\wacompen.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19024 ----a-w- c:\windows\system32\drivers\wd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19008 ----a-w- c:\windows\system32\drivers\wimmount.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14336 ----a-w- c:\windows\system32\drivers\vwifimp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 48128 ----a-w- c:\windows\system32\drivers\vwififlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40704 ----a-w- c:\windows\system32\drivers\vmstorfl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 297040 ----a-w- c:\windows\system32\drivers\volmgrx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 245632 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\vwifibus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 141904 ----a-w- c:\windows\system32\drivers\vsmraid.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 5632 ----a-w- c:\windows\system32\drivers\vms3cap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17920 ----a-w- c:\windows\system32\drivers\VMBusHID.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 175360 ----a-w- c:\windows\system32\drivers\vmbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 111616 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53328 ----a-w- c:\windows\system32\drivers\VIAAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52736 ----a-w- c:\windows\system32\drivers\viac7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\vgapnp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16976 ----a-w- c:\windows\system32\drivers\viaide.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 160128 ----a-w- c:\windows\system32\drivers\vhdmp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 32832 ----a-w- c:\windows\system32\drivers\vdrvroot.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\usbrpm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25088 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\usbprint.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 284672 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 6016 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 8192 ----a-w- c:\windows\system32\drivers\umpass.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 57424 ----a-w- c:\windows\system32\drivers\ULIAGPKX.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 55888 ----a-w- c:\windows\system32\drivers\UAGP35.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52224 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 39936 ----a-w- c:\windows\system32\drivers\umbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 246784 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 108544 ----a-w- c:\windows\system32\drivers\tunnel.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 74752 ----a-w- c:\windows\system32\drivers\tdx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 18432 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21504 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53632 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 28032 ----a-w- c:\windows\system32\drivers\storvsc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21072 ----a-w- c:\windows\system32\drivers\stexstor.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 148864 ----a-w- c:\windows\system32\drivers\storport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 12240 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 311808 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 310272 ----a-w- c:\windows\system32\drivers\srv2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 77888 ----a-w- c:\windows\system32\drivers\sisraid4.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 71168 ----a-w- c:\windows\system32\drivers\smb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 52304 ----a-w- c:\windows\system32\drivers\SISAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 405504 ----a-w- c:\windows\system32\drivers\spsys.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40016 ----a-w- c:\windows\system32\drivers\sisraid2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17472 ----a-w- c:\windows\system32\drivers\spldr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17408 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 13824 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 83456 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 26624 ----a-w- c:\windows\system32\drivers\scfilter.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 19968 ----a-w- c:\windows\system32\drivers\sermouse.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 17920 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 140160 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12288 ----a-w- c:\windows\system32\drivers\sffp_mmc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 11264 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 85376 ----a-w- c:\windows\system32\drivers\sbp2port.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 8192 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 60928 ----a-w- c:\windows\system32\drivers\rspndr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 2152088 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 139776 ----a-w- c:\windows\system32\drivers\Rt86win7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 173440 ----a-w- c:\windows\system32\drivers\rdyboost.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 117760 ----a-w- c:\windows\system32\drivers\rmcast.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 7168 ----a-w- c:\windows\system32\drivers\RDPREFMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys.bak
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-04-02 75048]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2013-12-10 982232]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"mshnpmisSrv"="c:\windows\inf\mshnpmis.vbe" [2013-08-27 1558]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-12-31 280576]
.
c:\users\mnouckk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Bitcoin.lnk - c:\program files\Bitcoin\bitcoin-qt.exe -min [2011-1-30 22613504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:a1179063 /dir:C:\Program
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 13312]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-12-30 1343400]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-01-01 243128]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2014-01-10 22688]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2013/12/29 23:46];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-04-02 08:11 87536]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;c:/postgreSQL/bin/pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-11-11 414496]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-29 22:18 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-29 22:40]
.
2014-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-29 22:18]
.
2014-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-29 22:18]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 77.48.100.254 212.80.66.7
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight]
"ImagePath"="\??\"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-01-10 17:51:22
ComboFix-quarantined-files.txt 2014-01-10 16:51
.
Před spuštěním: Volných bajtů: 50 328 334 336
Po spuštění: Volných bajtů: 50 795 114 496
.
- - End Of File - - 00B7C0A6A7512536A4131E756D3B0E6D
A36C5E4F47E84449FF07ED3517B43A31
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
c:\windows\Tasks\Adobe Flash Player Updater.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Folder::
c:\program files\Skype\Updater
Driver::
SkypeUpdate
RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Re: prosím o kontrolu
ComboFIX
ComboFix 14-01-08.03 - mnouckk 11.01.2014 18:04:26.2.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3070.2246 [GMT 1:00]
Spuštěný z: c:\users\mnouckk\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\mnouckk\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
C:\ujip.pif
c:\windows\security\Database\tmp.edb
D:\autorun.inf
D:\sjngvm.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-11 do 2014-01-11 )))))))))))))))))))))))))))))))
.
.
2014-01-11 17:12 . 2014-01-11 17:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-11 16:50 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AFBA969F-7CEA-4409-BA7B-00B586B7E3C8}\mpengine.dll
2014-01-10 18:11 . 2013-12-19 18:37 2555168 ----a-w- c:\windows\system32\nvsvcr.dll
2014-01-10 18:09 . 2013-12-19 20:26 9657464 ----a-w- c:\windows\system32\nvopencl.dll
2014-01-10 18:09 . 2013-12-19 20:26 893728 ----a-w- c:\windows\system32\nvdispgenco3233221.dll
2014-01-10 18:09 . 2013-12-19 20:26 852768 ----a-w- c:\windows\system32\NvIFR.dll
2014-01-10 18:09 . 2013-12-19 20:26 847648 ----a-w- c:\windows\system32\NvFBC.dll
2014-01-10 18:09 . 2013-12-19 20:26 2947872 ----a-w- c:\windows\system32\nvcuvid.dll
2014-01-10 18:09 . 2013-12-19 20:26 2747680 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-01-10 18:09 . 2013-12-19 20:26 22960416 ----a-w- c:\windows\system32\nvoglv32.dll
2014-01-10 18:09 . 2013-12-19 20:26 15877216 ----a-w- c:\windows\system32\nvwgf2um.dll
2014-01-10 18:09 . 2013-12-19 20:26 1049888 ----a-w- c:\windows\system32\nvdispco3233221.dll
2014-01-10 18:09 . 2013-12-19 20:26 10471712 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-01-10 18:09 . 2013-12-19 20:26 9700224 ----a-w- c:\windows\system32\nvcuda.dll
2014-01-10 18:09 . 2013-12-19 20:26 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2014-01-10 11:12 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-01-10 09:57 . 2014-01-10 09:57 22688 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2014-01-10 09:57 . 2014-01-10 09:57 -------- d-----w- c:\program files\HWiNFO32
2014-01-10 08:59 . 2014-01-10 08:59 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\programdata\Malwarebytes
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-01-09 22:28 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-09 22:20 . 2014-01-10 07:30 -------- d-----w- C:\AdwCleaner
2014-01-09 19:04 . 2014-01-09 19:04 -------- d-----w- c:\program files\HiJack
2014-01-05 12:28 . 2014-01-05 12:28 -------- d-----w- c:\programdata\Codemasters
2014-01-05 12:26 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\system32\nircmdc.exe
2014-01-05 11:35 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-05 11:35 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-05 11:35 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-05 11:35 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-05 11:35 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-05 11:35 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-05 11:35 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-04 19:26 . 2014-01-04 19:26 -------- d-----w- c:\program files\GSC World Publishing
2014-01-04 10:59 . 2013-12-05 08:42 34080 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2014-01-04 10:57 . 2013-12-10 02:13 982232 ----a-w- c:\windows\system32\nvspcap.dll
2014-01-04 10:56 . 2014-01-04 10:56 -------- d-----w- c:\program files\AGEIA Technologies
2014-01-04 10:55 . 2014-01-11 17:14 -------- d-----w- c:\programdata\NVIDIA
2014-01-04 10:55 . 2013-12-19 18:37 4317984 ----a-w- c:\windows\system32\nvcpl.dll
2014-01-04 10:55 . 2013-12-19 18:37 3036960 ----a-w- c:\windows\system32\nvsvc.dll
2014-01-04 10:55 . 2013-12-19 18:37 664352 ----a-w- c:\windows\system32\nvvsvc.exe
2014-01-04 10:55 . 2013-12-19 18:37 62752 ----a-w- c:\windows\system32\nvshext.dll
2014-01-04 10:55 . 2013-12-19 18:37 376096 ----a-w- c:\windows\system32\nvmctray.dll
2014-01-04 10:54 . 2013-12-19 20:26 53024 ----a-w- c:\windows\system32\OpenCL.dll
2014-01-04 10:54 . 2014-01-04 11:00 -------- d-----w- c:\programdata\NVIDIA Corporation
2014-01-04 10:53 . 2013-12-05 08:42 32544 ----a-w- c:\windows\system32\nvaudcap32v.dll
2014-01-04 10:53 . 2013-11-14 11:55 893728 ----a-w- c:\windows\system32\nvdispgenco3233182.dll
2014-01-04 10:53 . 2013-11-14 11:55 1049888 ----a-w- c:\windows\system32\nvdispco3233182.dll
2014-01-04 10:53 . 2013-12-19 20:26 2698272 ----a-w- c:\windows\system32\nvapi.dll
2014-01-04 10:49 . 2014-01-10 18:12 -------- d-----w- c:\program files\NVIDIA Corporation
2014-01-04 10:49 . 2014-01-04 10:49 -------- d-----w- C:\NVIDIA
2014-01-04 10:44 . 2005-10-28 13:58 45056 ----a-w- c:\windows\system32\ActiveDestopOCX.ocx
2014-01-04 10:43 . 2014-01-04 10:43 -------- d-----w- c:\program files\MSI
2014-01-04 10:43 . 1998-10-02 18:00 327168 ----a-w- c:\windows\IsUninst.exe
2014-01-04 10:38 . 2008-10-02 09:07 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2014-01-04 10:16 . 2014-01-11 15:22 -------- d-----w- c:\program files\AIMP3
2014-01-04 10:06 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2014-01-04 09:53 . 2014-01-04 09:56 -------- d-----w- c:\windows\system32\MRT
2014-01-03 21:32 . 2014-01-03 21:32 -------- d-----w- c:\programdata\The Revills Games
2014-01-03 21:31 . 2014-01-03 21:32 -------- d-----w- c:\program files\Common Files\Adobe
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\program files\Legends of Solitaire 2 - Curse of the Dragons
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\windows\Legends of Solitaire 2 - Curse of the Dragons
2014-01-01 22:16 . 2014-01-01 22:16 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Synchronization Services
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\windows\PCHEALTH
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Sync Framework
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2014-01-01 20:42 . 2014-01-01 20:42 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2014-01-01 20:41 . 2014-01-01 20:41 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-01-01 20:40 . 2014-01-02 22:18 -------- d-----w- c:\programdata\Microsoft Help
2014-01-01 20:40 . 2014-01-01 20:40 -------- d-----r- C:\MSOCache
2014-01-01 20:34 . 2014-01-01 20:34 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-01-01 20:34 . 2014-01-10 18:53 -------- d-----w- c:\program files\DAEMON Tools Lite
2014-01-01 20:27 . 2014-01-01 20:40 -------- d-----w- c:\programdata\DAEMON Tools Lite
2014-01-01 19:21 . 2014-01-02 13:37 -------- d-----w- c:\program files\Holdem Manager 2
2014-01-01 13:37 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2014-01-01 13:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-01-01 13:37 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe
2014-01-01 13:37 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-01 01:24 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-01-01 01:24 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-01-01 01:10 . 2014-01-01 01:10 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-12-31 18:43 . 2013-10-30 02:19 301568 ----a-w- c:\windows\system32\msieftp.dll
2013-12-31 18:43 . 2013-09-25 02:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-12-31 18:43 . 2013-09-25 01:57 247808 ----a-w- c:\windows\system32\schannel.dll
2013-12-31 18:43 . 2013-07-04 12:16 369848 ----a-w- c:\windows\system32\drivers\cng.sys
2013-12-31 18:43 . 2013-09-25 02:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-12-31 18:43 . 2013-09-25 01:57 99840 ----a-w- c:\windows\system32\sspicli.dll
2013-12-31 18:43 . 2013-09-25 01:57 22016 ----a-w- c:\windows\system32\secur32.dll
2013-12-31 18:43 . 2013-09-25 01:56 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-12-31 18:43 . 2013-09-25 01:56 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2013-12-31 18:43 . 2013-09-25 00:49 22016 ----a-w- c:\windows\system32\lsass.exe
2013-12-31 18:43 . 2013-09-25 00:49 15872 ----a-w- c:\windows\system32\sspisrv.dll
2013-12-31 18:41 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-12-31 18:40 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-12-31 18:39 . 2012-10-09 17:40 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-12-31 18:14 . 2014-01-05 09:36 -------- d-----w- c:\users\postgres
2013-12-31 18:08 . 2014-01-01 19:46 -------- d-----w- c:\program files\PSQLINSTALL
2013-12-31 15:44 . 2013-12-31 15:44 -------- d-----w- c:\programdata\SP_FT_Logs
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\SPReview
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\EventProviders
2013-12-31 07:51 . 2014-01-11 09:11 -------- d-----w- c:\users\Guest
2013-12-30 22:34 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-12-30 22:32 . 2010-11-20 12:30 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys
2013-12-30 22:31 . 2010-11-20 12:21 8704 ----a-w- c:\windows\system32\rdpcfgex.dll
2013-12-30 21:57 . 2013-10-27 22:41 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DD6078AC-1BDD-4201-B14C-36B308FCA642}\gapaengine.dll
2013-12-30 21:42 . 2013-12-30 21:42 -------- d-----w- c:\program files\Microsoft Security Client
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Common Files\InstallShield
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Browser Configuration Utility
2013-12-30 19:23 . 2008-05-02 14:08 146528 ----a-w- c:\windows\system32\dvmurl.dll
2013-12-30 19:22 . 2013-12-30 19:26 16608 ----a-w- c:\windows\gdrv.sys
2013-12-30 18:13 . 2013-12-30 22:09 -------- d-----w- c:\program files\LenovoUsbDriver
2013-12-30 17:24 . 2013-12-30 17:26 -------- d-----w- c:\program files\PdaNet for Android
2013-12-30 17:24 . 2011-07-19 10:28 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2013-12-30 17:24 . 2009-11-08 01:41 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2013-12-30 17:24 . 2009-11-08 01:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\TeamViewer
2013-12-30 16:58 . 2014-01-11 17:12 -------- d-----r- c:\program files\Skype
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\Common Files\Skype
2013-12-30 16:58 . 2014-01-03 11:10 -------- d-----w- c:\programdata\Skype
2013-12-30 14:43 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-12-30 14:43 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-12-30 14:43 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2013-12-30 14:43 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-12-30 14:43 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-10 10:53 . 2014-01-10 07:47 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16384 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14912 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35968 ----a-w- c:\windows\system32\drivers\winusb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 9728 ----a-w- c:\windows\system32\drivers\wfplwf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 63488 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43392 ----a-w- c:\windows\system32\drivers\winhv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\watchdog.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21632 ----a-w- c:\windows\system32\drivers\wacompen.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19024 ----a-w- c:\windows\system32\drivers\wd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19008 ----a-w- c:\windows\system32\drivers\wimmount.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14336 ----a-w- c:\windows\system32\drivers\vwifimp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 48128 ----a-w- c:\windows\system32\drivers\vwififlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40704 ----a-w- c:\windows\system32\drivers\vmstorfl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 297040 ----a-w- c:\windows\system32\drivers\volmgrx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 245632 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\vwifibus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 141904 ----a-w- c:\windows\system32\drivers\vsmraid.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 5632 ----a-w- c:\windows\system32\drivers\vms3cap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17920 ----a-w- c:\windows\system32\drivers\VMBusHID.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 175360 ----a-w- c:\windows\system32\drivers\vmbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 111616 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53328 ----a-w- c:\windows\system32\drivers\VIAAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52736 ----a-w- c:\windows\system32\drivers\viac7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\vgapnp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16976 ----a-w- c:\windows\system32\drivers\viaide.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 160128 ----a-w- c:\windows\system32\drivers\vhdmp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 32832 ----a-w- c:\windows\system32\drivers\vdrvroot.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\usbrpm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25088 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\usbprint.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 284672 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 6016 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 8192 ----a-w- c:\windows\system32\drivers\umpass.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 57424 ----a-w- c:\windows\system32\drivers\ULIAGPKX.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 55888 ----a-w- c:\windows\system32\drivers\UAGP35.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52224 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 39936 ----a-w- c:\windows\system32\drivers\umbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 246784 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 108544 ----a-w- c:\windows\system32\drivers\tunnel.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 74752 ----a-w- c:\windows\system32\drivers\tdx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 18432 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21504 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53632 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 28032 ----a-w- c:\windows\system32\drivers\storvsc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21072 ----a-w- c:\windows\system32\drivers\stexstor.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 148864 ----a-w- c:\windows\system32\drivers\storport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 12240 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 311808 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 310272 ----a-w- c:\windows\system32\drivers\srv2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 77888 ----a-w- c:\windows\system32\drivers\sisraid4.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 71168 ----a-w- c:\windows\system32\drivers\smb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 52304 ----a-w- c:\windows\system32\drivers\SISAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 405504 ----a-w- c:\windows\system32\drivers\spsys.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40016 ----a-w- c:\windows\system32\drivers\sisraid2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17472 ----a-w- c:\windows\system32\drivers\spldr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17408 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 13824 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 83456 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 26624 ----a-w- c:\windows\system32\drivers\scfilter.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 19968 ----a-w- c:\windows\system32\drivers\sermouse.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 17920 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 140160 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12288 ----a-w- c:\windows\system32\drivers\sffp_mmc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 11264 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 85376 ----a-w- c:\windows\system32\drivers\sbp2port.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 8192 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 60928 ----a-w- c:\windows\system32\drivers\rspndr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 2152088 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 139776 ----a-w- c:\windows\system32\drivers\Rt86win7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 173440 ----a-w- c:\windows\system32\drivers\rdyboost.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 117760 ----a-w- c:\windows\system32\drivers\rmcast.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 7168 ----a-w- c:\windows\system32\drivers\RDPREFMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys.bak
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
"uTorrent"="c:\users\mnouckk\AppData\Roaming\uTorrent\utorrent.exe" [2013-12-29 393728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-04-02 75048]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2013-12-10 982232]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"mshnpmisSrv"="c:\windows\inf\mshnpmis.vbe" [2013-08-27 1558]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-12-31 280576]
.
c:\users\mnouckk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Bitcoin.lnk - c:\program files\Bitcoin\bitcoin-qt.exe -min [2011-1-30 22613504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:a1179063 /dir:C:\Program
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 13312]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-12-30 1343400]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-01-01 243128]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2014-01-10 22688]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2013/12/29 23:46];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-04-02 08:11 87536]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;c:/postgreSQL/bin/pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-19 411936]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-29 22:18 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-29 22:40]
.
2014-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-29 22:18]
.
2014-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-29 22:18]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 77.48.100.254 212.80.66.7
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight]
"ImagePath"="\??\"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\postgresql\bin\pg_ctl.exe
c:\windows\system32\rundll32.exe
c:\postgresql\bin\postgres.exe
c:\windows\system32\conhost.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\windows\system32\taskhost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\windows\RtHDVCpl.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
c:\program files\Microsoft Security Client\MpCmdRun.exe
.
**************************************************************************
.
Celkový čas: 2014-01-11 18:20:25 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-11 17:20
ComboFix2.txt 2014-01-10 16:51
.
Před spuštěním: Volných bajtů: 48 947 261 440
Po spuštění: Volných bajtů: 48 620 576 768
.
- - End Of File - - 9ED4A90A0ACED424A77EEC2162EC005D
A36C5E4F47E84449FF07ED3517B43A31
ComboFix 14-01-08.03 - mnouckk 11.01.2014 18:04:26.2.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3070.2246 [GMT 1:00]
Spuštěný z: c:\users\mnouckk\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\mnouckk\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
C:\ujip.pif
c:\windows\security\Database\tmp.edb
D:\autorun.inf
D:\sjngvm.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-11 do 2014-01-11 )))))))))))))))))))))))))))))))
.
.
2014-01-11 17:12 . 2014-01-11 17:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-11 16:50 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AFBA969F-7CEA-4409-BA7B-00B586B7E3C8}\mpengine.dll
2014-01-10 18:11 . 2013-12-19 18:37 2555168 ----a-w- c:\windows\system32\nvsvcr.dll
2014-01-10 18:09 . 2013-12-19 20:26 9657464 ----a-w- c:\windows\system32\nvopencl.dll
2014-01-10 18:09 . 2013-12-19 20:26 893728 ----a-w- c:\windows\system32\nvdispgenco3233221.dll
2014-01-10 18:09 . 2013-12-19 20:26 852768 ----a-w- c:\windows\system32\NvIFR.dll
2014-01-10 18:09 . 2013-12-19 20:26 847648 ----a-w- c:\windows\system32\NvFBC.dll
2014-01-10 18:09 . 2013-12-19 20:26 2947872 ----a-w- c:\windows\system32\nvcuvid.dll
2014-01-10 18:09 . 2013-12-19 20:26 2747680 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-01-10 18:09 . 2013-12-19 20:26 22960416 ----a-w- c:\windows\system32\nvoglv32.dll
2014-01-10 18:09 . 2013-12-19 20:26 15877216 ----a-w- c:\windows\system32\nvwgf2um.dll
2014-01-10 18:09 . 2013-12-19 20:26 1049888 ----a-w- c:\windows\system32\nvdispco3233221.dll
2014-01-10 18:09 . 2013-12-19 20:26 10471712 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-01-10 18:09 . 2013-12-19 20:26 9700224 ----a-w- c:\windows\system32\nvcuda.dll
2014-01-10 18:09 . 2013-12-19 20:26 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2014-01-10 11:12 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-01-10 09:57 . 2014-01-10 09:57 22688 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2014-01-10 09:57 . 2014-01-10 09:57 -------- d-----w- c:\program files\HWiNFO32
2014-01-10 08:59 . 2014-01-10 08:59 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\programdata\Malwarebytes
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-01-09 22:28 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-09 22:20 . 2014-01-10 07:30 -------- d-----w- C:\AdwCleaner
2014-01-09 19:04 . 2014-01-09 19:04 -------- d-----w- c:\program files\HiJack
2014-01-05 12:28 . 2014-01-05 12:28 -------- d-----w- c:\programdata\Codemasters
2014-01-05 12:26 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\system32\nircmdc.exe
2014-01-05 11:35 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-05 11:35 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-05 11:35 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-05 11:35 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-05 11:35 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-05 11:35 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-05 11:35 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-04 19:26 . 2014-01-04 19:26 -------- d-----w- c:\program files\GSC World Publishing
2014-01-04 10:59 . 2013-12-05 08:42 34080 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2014-01-04 10:57 . 2013-12-10 02:13 982232 ----a-w- c:\windows\system32\nvspcap.dll
2014-01-04 10:56 . 2014-01-04 10:56 -------- d-----w- c:\program files\AGEIA Technologies
2014-01-04 10:55 . 2014-01-11 17:14 -------- d-----w- c:\programdata\NVIDIA
2014-01-04 10:55 . 2013-12-19 18:37 4317984 ----a-w- c:\windows\system32\nvcpl.dll
2014-01-04 10:55 . 2013-12-19 18:37 3036960 ----a-w- c:\windows\system32\nvsvc.dll
2014-01-04 10:55 . 2013-12-19 18:37 664352 ----a-w- c:\windows\system32\nvvsvc.exe
2014-01-04 10:55 . 2013-12-19 18:37 62752 ----a-w- c:\windows\system32\nvshext.dll
2014-01-04 10:55 . 2013-12-19 18:37 376096 ----a-w- c:\windows\system32\nvmctray.dll
2014-01-04 10:54 . 2013-12-19 20:26 53024 ----a-w- c:\windows\system32\OpenCL.dll
2014-01-04 10:54 . 2014-01-04 11:00 -------- d-----w- c:\programdata\NVIDIA Corporation
2014-01-04 10:53 . 2013-12-05 08:42 32544 ----a-w- c:\windows\system32\nvaudcap32v.dll
2014-01-04 10:53 . 2013-11-14 11:55 893728 ----a-w- c:\windows\system32\nvdispgenco3233182.dll
2014-01-04 10:53 . 2013-11-14 11:55 1049888 ----a-w- c:\windows\system32\nvdispco3233182.dll
2014-01-04 10:53 . 2013-12-19 20:26 2698272 ----a-w- c:\windows\system32\nvapi.dll
2014-01-04 10:49 . 2014-01-10 18:12 -------- d-----w- c:\program files\NVIDIA Corporation
2014-01-04 10:49 . 2014-01-04 10:49 -------- d-----w- C:\NVIDIA
2014-01-04 10:44 . 2005-10-28 13:58 45056 ----a-w- c:\windows\system32\ActiveDestopOCX.ocx
2014-01-04 10:43 . 2014-01-04 10:43 -------- d-----w- c:\program files\MSI
2014-01-04 10:43 . 1998-10-02 18:00 327168 ----a-w- c:\windows\IsUninst.exe
2014-01-04 10:38 . 2008-10-02 09:07 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2014-01-04 10:16 . 2014-01-11 15:22 -------- d-----w- c:\program files\AIMP3
2014-01-04 10:06 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2014-01-04 09:53 . 2014-01-04 09:56 -------- d-----w- c:\windows\system32\MRT
2014-01-03 21:32 . 2014-01-03 21:32 -------- d-----w- c:\programdata\The Revills Games
2014-01-03 21:31 . 2014-01-03 21:32 -------- d-----w- c:\program files\Common Files\Adobe
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\program files\Legends of Solitaire 2 - Curse of the Dragons
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\windows\Legends of Solitaire 2 - Curse of the Dragons
2014-01-01 22:16 . 2014-01-01 22:16 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Synchronization Services
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\windows\PCHEALTH
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Sync Framework
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2014-01-01 20:42 . 2014-01-01 20:42 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2014-01-01 20:41 . 2014-01-01 20:41 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-01-01 20:40 . 2014-01-02 22:18 -------- d-----w- c:\programdata\Microsoft Help
2014-01-01 20:40 . 2014-01-01 20:40 -------- d-----r- C:\MSOCache
2014-01-01 20:34 . 2014-01-01 20:34 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-01-01 20:34 . 2014-01-10 18:53 -------- d-----w- c:\program files\DAEMON Tools Lite
2014-01-01 20:27 . 2014-01-01 20:40 -------- d-----w- c:\programdata\DAEMON Tools Lite
2014-01-01 19:21 . 2014-01-02 13:37 -------- d-----w- c:\program files\Holdem Manager 2
2014-01-01 13:37 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2014-01-01 13:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-01-01 13:37 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe
2014-01-01 13:37 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-01 01:24 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-01-01 01:24 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-01-01 01:10 . 2014-01-01 01:10 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-12-31 18:43 . 2013-10-30 02:19 301568 ----a-w- c:\windows\system32\msieftp.dll
2013-12-31 18:43 . 2013-09-25 02:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-12-31 18:43 . 2013-09-25 01:57 247808 ----a-w- c:\windows\system32\schannel.dll
2013-12-31 18:43 . 2013-07-04 12:16 369848 ----a-w- c:\windows\system32\drivers\cng.sys
2013-12-31 18:43 . 2013-09-25 02:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-12-31 18:43 . 2013-09-25 01:57 99840 ----a-w- c:\windows\system32\sspicli.dll
2013-12-31 18:43 . 2013-09-25 01:57 22016 ----a-w- c:\windows\system32\secur32.dll
2013-12-31 18:43 . 2013-09-25 01:56 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-12-31 18:43 . 2013-09-25 01:56 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2013-12-31 18:43 . 2013-09-25 00:49 22016 ----a-w- c:\windows\system32\lsass.exe
2013-12-31 18:43 . 2013-09-25 00:49 15872 ----a-w- c:\windows\system32\sspisrv.dll
2013-12-31 18:41 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-12-31 18:40 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-12-31 18:39 . 2012-10-09 17:40 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-12-31 18:14 . 2014-01-05 09:36 -------- d-----w- c:\users\postgres
2013-12-31 18:08 . 2014-01-01 19:46 -------- d-----w- c:\program files\PSQLINSTALL
2013-12-31 15:44 . 2013-12-31 15:44 -------- d-----w- c:\programdata\SP_FT_Logs
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\SPReview
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\EventProviders
2013-12-31 07:51 . 2014-01-11 09:11 -------- d-----w- c:\users\Guest
2013-12-30 22:34 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-12-30 22:32 . 2010-11-20 12:30 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys
2013-12-30 22:31 . 2010-11-20 12:21 8704 ----a-w- c:\windows\system32\rdpcfgex.dll
2013-12-30 21:57 . 2013-10-27 22:41 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DD6078AC-1BDD-4201-B14C-36B308FCA642}\gapaengine.dll
2013-12-30 21:42 . 2013-12-30 21:42 -------- d-----w- c:\program files\Microsoft Security Client
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Common Files\InstallShield
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Browser Configuration Utility
2013-12-30 19:23 . 2008-05-02 14:08 146528 ----a-w- c:\windows\system32\dvmurl.dll
2013-12-30 19:22 . 2013-12-30 19:26 16608 ----a-w- c:\windows\gdrv.sys
2013-12-30 18:13 . 2013-12-30 22:09 -------- d-----w- c:\program files\LenovoUsbDriver
2013-12-30 17:24 . 2013-12-30 17:26 -------- d-----w- c:\program files\PdaNet for Android
2013-12-30 17:24 . 2011-07-19 10:28 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2013-12-30 17:24 . 2009-11-08 01:41 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2013-12-30 17:24 . 2009-11-08 01:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\TeamViewer
2013-12-30 16:58 . 2014-01-11 17:12 -------- d-----r- c:\program files\Skype
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\Common Files\Skype
2013-12-30 16:58 . 2014-01-03 11:10 -------- d-----w- c:\programdata\Skype
2013-12-30 14:43 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-12-30 14:43 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-12-30 14:43 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2013-12-30 14:43 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-12-30 14:43 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-10 10:53 . 2014-01-10 07:47 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16384 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14912 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35968 ----a-w- c:\windows\system32\drivers\winusb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 9728 ----a-w- c:\windows\system32\drivers\wfplwf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 63488 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43392 ----a-w- c:\windows\system32\drivers\winhv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\watchdog.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21632 ----a-w- c:\windows\system32\drivers\wacompen.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19024 ----a-w- c:\windows\system32\drivers\wd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19008 ----a-w- c:\windows\system32\drivers\wimmount.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14336 ----a-w- c:\windows\system32\drivers\vwifimp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 48128 ----a-w- c:\windows\system32\drivers\vwififlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40704 ----a-w- c:\windows\system32\drivers\vmstorfl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 297040 ----a-w- c:\windows\system32\drivers\volmgrx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 245632 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\vwifibus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 141904 ----a-w- c:\windows\system32\drivers\vsmraid.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 5632 ----a-w- c:\windows\system32\drivers\vms3cap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17920 ----a-w- c:\windows\system32\drivers\VMBusHID.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 175360 ----a-w- c:\windows\system32\drivers\vmbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 111616 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53328 ----a-w- c:\windows\system32\drivers\VIAAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52736 ----a-w- c:\windows\system32\drivers\viac7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\vgapnp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16976 ----a-w- c:\windows\system32\drivers\viaide.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 160128 ----a-w- c:\windows\system32\drivers\vhdmp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 32832 ----a-w- c:\windows\system32\drivers\vdrvroot.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\usbrpm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25088 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\usbprint.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 284672 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 6016 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 8192 ----a-w- c:\windows\system32\drivers\umpass.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 57424 ----a-w- c:\windows\system32\drivers\ULIAGPKX.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 55888 ----a-w- c:\windows\system32\drivers\UAGP35.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52224 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 39936 ----a-w- c:\windows\system32\drivers\umbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 246784 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 108544 ----a-w- c:\windows\system32\drivers\tunnel.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 74752 ----a-w- c:\windows\system32\drivers\tdx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 18432 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21504 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53632 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 28032 ----a-w- c:\windows\system32\drivers\storvsc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21072 ----a-w- c:\windows\system32\drivers\stexstor.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 148864 ----a-w- c:\windows\system32\drivers\storport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 12240 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 311808 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 310272 ----a-w- c:\windows\system32\drivers\srv2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 77888 ----a-w- c:\windows\system32\drivers\sisraid4.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 71168 ----a-w- c:\windows\system32\drivers\smb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 52304 ----a-w- c:\windows\system32\drivers\SISAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 405504 ----a-w- c:\windows\system32\drivers\spsys.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40016 ----a-w- c:\windows\system32\drivers\sisraid2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17472 ----a-w- c:\windows\system32\drivers\spldr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17408 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 13824 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 83456 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 26624 ----a-w- c:\windows\system32\drivers\scfilter.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 19968 ----a-w- c:\windows\system32\drivers\sermouse.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 17920 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 140160 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12288 ----a-w- c:\windows\system32\drivers\sffp_mmc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 11264 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 85376 ----a-w- c:\windows\system32\drivers\sbp2port.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 8192 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 60928 ----a-w- c:\windows\system32\drivers\rspndr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 2152088 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 139776 ----a-w- c:\windows\system32\drivers\Rt86win7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 173440 ----a-w- c:\windows\system32\drivers\rdyboost.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 117760 ----a-w- c:\windows\system32\drivers\rmcast.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 7168 ----a-w- c:\windows\system32\drivers\RDPREFMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys.bak
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
"uTorrent"="c:\users\mnouckk\AppData\Roaming\uTorrent\utorrent.exe" [2013-12-29 393728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-04-02 75048]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2013-12-10 982232]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"mshnpmisSrv"="c:\windows\inf\mshnpmis.vbe" [2013-08-27 1558]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-12-31 280576]
.
c:\users\mnouckk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Bitcoin.lnk - c:\program files\Bitcoin\bitcoin-qt.exe -min [2011-1-30 22613504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:a1179063 /dir:C:\Program
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 13312]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-12-30 1343400]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-01-01 243128]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2014-01-10 22688]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2013/12/29 23:46];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-04-02 08:11 87536]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;c:/postgreSQL/bin/pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-19 411936]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-29 22:18 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-29 22:40]
.
2014-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-29 22:18]
.
2014-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-29 22:18]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 77.48.100.254 212.80.66.7
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight]
"ImagePath"="\??\"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\postgresql\bin\pg_ctl.exe
c:\windows\system32\rundll32.exe
c:\postgresql\bin\postgres.exe
c:\windows\system32\conhost.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\windows\system32\taskhost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\windows\RtHDVCpl.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
c:\program files\Microsoft Security Client\MpCmdRun.exe
.
**************************************************************************
.
Celkový čas: 2014-01-11 18:20:25 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-11 17:20
ComboFix2.txt 2014-01-10 16:51
.
Před spuštěním: Volných bajtů: 48 947 261 440
Po spuštění: Volných bajtů: 48 620 576 768
.
- - End Of File - - 9ED4A90A0ACED424A77EEC2162EC005D
A36C5E4F47E84449FF07ED3517B43A31
Re: prosím o kontrolu
HJT
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:22:38, on 11.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files\CyberLink\Shared files\brs.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\Explorer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\HiJack\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\System32\dvmurl.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Nvtmru] "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
O4 - HKLM\..\Run: [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [mshnpmisSrv] C:\Windows\inf\mshnpmis.vbe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Users\mnouckk\AppData\Roaming\uTorrent\utorrent.exe"
O4 - HKUS\S-1-5-21-1195113856-586066616-2882415649-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'postgres')
O4 - HKUS\S-1-5-21-1195113856-586066616-2882415649-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'postgres')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Bitcoin.lnk = C:\Program Files\Bitcoin\bitcoin-qt.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: postgresql-8.4 - PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - c:/postgreSQL/bin/pg_ctl.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
--
End of file - 6832 bytes
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:22:38, on 11.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files\CyberLink\Shared files\brs.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\Explorer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\HiJack\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\System32\dvmurl.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Nvtmru] "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
O4 - HKLM\..\Run: [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [mshnpmisSrv] C:\Windows\inf\mshnpmis.vbe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Users\mnouckk\AppData\Roaming\uTorrent\utorrent.exe"
O4 - HKUS\S-1-5-21-1195113856-586066616-2882415649-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'postgres')
O4 - HKUS\S-1-5-21-1195113856-586066616-2882415649-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'postgres')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Bitcoin.lnk = C:\Program Files\Bitcoin\bitcoin-qt.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: postgresql-8.4 - PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - c:/postgreSQL/bin/pg_ctl.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
--
End of file - 6832 bytes
Re: prosím o kontrolu
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-11 18:24:07
-----------------------------
18:24:07.061 OS Version: Windows 6.1.7601 Service Pack 1
18:24:07.077 Number of processors: 4 586 0x203
18:24:07.077 ComputerName: MNOUCKK-PC UserName: mnouckk
18:24:07.903 Initialize success
18:24:12.760 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T1L0-6
18:24:12.760 Disk 0 Vendor: WDC_WD5000AAKS-00A7B2 01.03B01 Size: 476938MB BusType: 3
18:24:12.838 Disk 0 MBR read successfully
18:24:12.853 Disk 0 MBR scan
18:24:12.853 Disk 0 Windows 7 default MBR code
18:24:12.853 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 99998 MB offset 63
18:24:12.869 Disk 0 Partition - 00 0F Extended LBA 376931 MB offset 204796620
18:24:12.884 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 376931 MB offset 204796683
18:24:12.900 Disk 0 scanning sectors +976752000
18:24:12.931 Disk 0 scanning C:\Windows\system32\drivers
18:24:24.553 Service scanning
18:24:35.614 Modules scanning
18:24:39.014 Disk 0 trace - called modules:
18:24:39.046 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys
18:24:39.061 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85e0c030]
18:24:39.061 3 CLASSPNP.SYS[8b18a59e] -> nt!IofCallDriver -> [0x858e0918]
18:24:39.077 5 ACPI.sys[8ac163d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T1L0-6[0x858e8030]
18:24:39.077 Scan finished successfully
18:24:45.348 Disk 0 MBR has been saved successfully to "C:\Users\mnouckk\Desktop\MBR.dat"
18:24:45.348 The log file has been saved successfully to "C:\Users\mnouckk\Desktop\aswMBR.txt"
Run date: 2014-01-11 18:24:07
-----------------------------
18:24:07.061 OS Version: Windows 6.1.7601 Service Pack 1
18:24:07.077 Number of processors: 4 586 0x203
18:24:07.077 ComputerName: MNOUCKK-PC UserName: mnouckk
18:24:07.903 Initialize success
18:24:12.760 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T1L0-6
18:24:12.760 Disk 0 Vendor: WDC_WD5000AAKS-00A7B2 01.03B01 Size: 476938MB BusType: 3
18:24:12.838 Disk 0 MBR read successfully
18:24:12.853 Disk 0 MBR scan
18:24:12.853 Disk 0 Windows 7 default MBR code
18:24:12.853 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 99998 MB offset 63
18:24:12.869 Disk 0 Partition - 00 0F Extended LBA 376931 MB offset 204796620
18:24:12.884 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 376931 MB offset 204796683
18:24:12.900 Disk 0 scanning sectors +976752000
18:24:12.931 Disk 0 scanning C:\Windows\system32\drivers
18:24:24.553 Service scanning
18:24:35.614 Modules scanning
18:24:39.014 Disk 0 trace - called modules:
18:24:39.046 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys
18:24:39.061 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85e0c030]
18:24:39.061 3 CLASSPNP.SYS[8b18a59e] -> nt!IofCallDriver -> [0x858e0918]
18:24:39.077 5 ACPI.sys[8ac163d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T1L0-6[0x858e8030]
18:24:39.077 Scan finished successfully
18:24:45.348 Disk 0 MBR has been saved successfully to "C:\Users\mnouckk\Desktop\MBR.dat"
18:24:45.348 The log file has been saved successfully to "C:\Users\mnouckk\Desktop\aswMBR.txt"
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
====================================================
Vyčisti systém CCleanerem
====================================================
Stáhni si zde DelFix
http://general-changelog-team.fr/fr/dow ... e/9-delfix
ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci
Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem. Jinak je zpráva zde:
v C: \ DelFix.txt
Jak to vypadá s problémy?
Start-Spustit a zadej ComboFix /Uninstall
====================================================
Vyčisti systém CCleanerem
====================================================
Stáhni si zde DelFix
http://general-changelog-team.fr/fr/dow ... e/9-delfix
ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci
Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem. Jinak je zpráva zde:
v C: \ DelFix.txt
Jak to vypadá s problémy?
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Re: prosím o kontrolu
# DelFix v10.6 - Logfile created 12/01/2014 at 18:45:49
# Updated 11/11/2013 by Xplode
# Username : mnouckk - MNOUCKK-PC
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
~ Removing disinfection tools ...
Deleted : C:\AdwCleaner
Deleted : C:\Users\mnouckk\Desktop\RK_Quarantine
Deleted : C:\ComboFix.txt
Deleted : C:\TDSSKiller.2.8.16.0_10.01.2014_11.57.19_log.txt
Deleted : C:\TDSSKiller.3.0.0.19_10.01.2014_11.57.46_log.txt
Deleted : C:\Users\mnouckk\Desktop\adwcleaner.exe
Deleted : C:\Users\mnouckk\Desktop\aswmbr.exe
Deleted : C:\Users\mnouckk\Desktop\aswMBR.txt
Deleted : C:\Users\mnouckk\Desktop\HiJackThis.lnk
Deleted : C:\Users\mnouckk\Desktop\MBR.dat
Deleted : C:\Users\mnouckk\Desktop\RKreport[0]_D_01102014_115550.txt
Deleted : C:\Users\mnouckk\Desktop\RKreport[0]_S_01102014_115335.txt
Deleted : C:\Users\mnouckk\Desktop\RogueKiller.exe
Deleted : C:\Users\mnouckk\Downloads\HiJackThis.msi
Deleted : C:\Users\mnouckk\Downloads\tdsskiller.zip
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
~ Cleaning system restore ...
Deleted : RP #61 [ComboFix created restore point | 01/11/2014 17:02:46]
Deleted : RP #62 [Windows Update | 01/12/2014 17:42:57]
New restore point created !
########## - EOF - ##########
Rychlost PC se znatelně zvýšila, videa a stránky jsou plynulé a navíc zmizelo "záhadné" vypadávání internetu :)
Jen dotaz: nějak stručně, v čem byl problém? Abych se tomu mohl napříště vyhnout... A je Esencial od Microsoftu dostačující ochrana pro PC?
Děkuji za pomoc! :)
# Updated 11/11/2013 by Xplode
# Username : mnouckk - MNOUCKK-PC
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
~ Removing disinfection tools ...
Deleted : C:\AdwCleaner
Deleted : C:\Users\mnouckk\Desktop\RK_Quarantine
Deleted : C:\ComboFix.txt
Deleted : C:\TDSSKiller.2.8.16.0_10.01.2014_11.57.19_log.txt
Deleted : C:\TDSSKiller.3.0.0.19_10.01.2014_11.57.46_log.txt
Deleted : C:\Users\mnouckk\Desktop\adwcleaner.exe
Deleted : C:\Users\mnouckk\Desktop\aswmbr.exe
Deleted : C:\Users\mnouckk\Desktop\aswMBR.txt
Deleted : C:\Users\mnouckk\Desktop\HiJackThis.lnk
Deleted : C:\Users\mnouckk\Desktop\MBR.dat
Deleted : C:\Users\mnouckk\Desktop\RKreport[0]_D_01102014_115550.txt
Deleted : C:\Users\mnouckk\Desktop\RKreport[0]_S_01102014_115335.txt
Deleted : C:\Users\mnouckk\Desktop\RogueKiller.exe
Deleted : C:\Users\mnouckk\Downloads\HiJackThis.msi
Deleted : C:\Users\mnouckk\Downloads\tdsskiller.zip
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
~ Cleaning system restore ...
Deleted : RP #61 [ComboFix created restore point | 01/11/2014 17:02:46]
Deleted : RP #62 [Windows Update | 01/12/2014 17:42:57]
New restore point created !
########## - EOF - ##########
Rychlost PC se znatelně zvýšila, videa a stránky jsou plynulé a navíc zmizelo "záhadné" vypadávání internetu :)
Jen dotaz: nějak stručně, v čem byl problém? Abych se tomu mohl napříště vyhnout... A je Esencial od Microsoftu dostačující ochrana pro PC?
Děkuji za pomoc! :)
Re: prosím o kontrolu
# DelFix v10.6 - Logfile created 12/01/2014 at 18:45:49
# Updated 11/11/2013 by Xplode
# Username : mnouckk - MNOUCKK-PC
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
~ Removing disinfection tools ...
Deleted : C:\AdwCleaner
Deleted : C:\Users\mnouckk\Desktop\RK_Quarantine
Deleted : C:\ComboFix.txt
Deleted : C:\TDSSKiller.2.8.16.0_10.01.2014_11.57.19_log.txt
Deleted : C:\TDSSKiller.3.0.0.19_10.01.2014_11.57.46_log.txt
Deleted : C:\Users\mnouckk\Desktop\adwcleaner.exe
Deleted : C:\Users\mnouckk\Desktop\aswmbr.exe
Deleted : C:\Users\mnouckk\Desktop\aswMBR.txt
Deleted : C:\Users\mnouckk\Desktop\HiJackThis.lnk
Deleted : C:\Users\mnouckk\Desktop\MBR.dat
Deleted : C:\Users\mnouckk\Desktop\RKreport[0]_D_01102014_115550.txt
Deleted : C:\Users\mnouckk\Desktop\RKreport[0]_S_01102014_115335.txt
Deleted : C:\Users\mnouckk\Desktop\RogueKiller.exe
Deleted : C:\Users\mnouckk\Downloads\HiJackThis.msi
Deleted : C:\Users\mnouckk\Downloads\tdsskiller.zip
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
~ Cleaning system restore ...
Deleted : RP #61 [ComboFix created restore point | 01/11/2014 17:02:46]
Deleted : RP #62 [Windows Update | 01/12/2014 17:42:57]
New restore point created !
########## - EOF - ##########
Rychlost PC se znatelně zvýšila, videa a stránky jsou plynulé a navíc zmizelo "záhadné" vypadávání internetu :)
Jen dotaz: nějak stručně, v čem byl problém? Abych se tomu mohl napříště vyhnout... A je Essential od Microsoftu dostačující ochrana pro PC?
Děkuji za pomoc! :)
# Updated 11/11/2013 by Xplode
# Username : mnouckk - MNOUCKK-PC
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
~ Removing disinfection tools ...
Deleted : C:\AdwCleaner
Deleted : C:\Users\mnouckk\Desktop\RK_Quarantine
Deleted : C:\ComboFix.txt
Deleted : C:\TDSSKiller.2.8.16.0_10.01.2014_11.57.19_log.txt
Deleted : C:\TDSSKiller.3.0.0.19_10.01.2014_11.57.46_log.txt
Deleted : C:\Users\mnouckk\Desktop\adwcleaner.exe
Deleted : C:\Users\mnouckk\Desktop\aswmbr.exe
Deleted : C:\Users\mnouckk\Desktop\aswMBR.txt
Deleted : C:\Users\mnouckk\Desktop\HiJackThis.lnk
Deleted : C:\Users\mnouckk\Desktop\MBR.dat
Deleted : C:\Users\mnouckk\Desktop\RKreport[0]_D_01102014_115550.txt
Deleted : C:\Users\mnouckk\Desktop\RKreport[0]_S_01102014_115335.txt
Deleted : C:\Users\mnouckk\Desktop\RogueKiller.exe
Deleted : C:\Users\mnouckk\Downloads\HiJackThis.msi
Deleted : C:\Users\mnouckk\Downloads\tdsskiller.zip
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
~ Cleaning system restore ...
Deleted : RP #61 [ComboFix created restore point | 01/11/2014 17:02:46]
Deleted : RP #62 [Windows Update | 01/12/2014 17:42:57]
New restore point created !
########## - EOF - ##########
Rychlost PC se znatelně zvýšila, videa a stránky jsou plynulé a navíc zmizelo "záhadné" vypadávání internetu :)
Jen dotaz: nějak stručně, v čem byl problém? Abych se tomu mohl napříště vyhnout... A je Essential od Microsoftu dostačující ochrana pro PC?
Děkuji za pomoc! :)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\windows\system32\nircmdc.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
Návod
Kód: Vybrat vše
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\System32\dvmurl.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mshnpmisSrv] C:\Windows\inf\mshnpmis.vbe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\mnouckk\AppData\Roaming\uTorrent\utorrent.exe"
O4 - HKUS\S-1-5-21-1195113856-586066616-2882415649-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'postgres')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\inf\mshnpmis.vbe
Folder::
c:\program files\Google\Update
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\windows\system32\nircmdc.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: prosím o kontrolu
ComboFix 14-01-13.01 - mnouckk 13.01.2014 13:39:28.1.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3070.2099 [GMT 1:00]
Spuštěný z: c:\users\mnouckk\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\mnouckk\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\inf\mshnpmis.vbe"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.22.3\GoogleUpdate.exe
c:\program files\Google\Update\1.3.22.3\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.22.3\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.22.3\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.22.3\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.22.3\goopdate.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_am.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ar.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_bg.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_bn.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ca.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_cs.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_da.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_de.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_el.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_en.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_es.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_et.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_fa.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_fi.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_fil.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_fr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_gu.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_hi.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_hr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_hu.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_id.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_is.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_it.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_iw.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ja.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_kn.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ko.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_lt.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_lv.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ml.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_mr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ms.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_nl.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_no.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_pl.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ro.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ru.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sk.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sl.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sv.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sw.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ta.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_te.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_th.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_tr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_uk.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ur.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_vi.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.22.3\psmachine.dll
c:\program files\Google\Update\1.3.22.3\psuser.dll
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.3\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\31.0.1650.63\31.0.1650.63_chrome_installer.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\users\mnouckk\AppData\Roaming\Roaming
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-13 do 2014-01-13 )))))))))))))))))))))))))))))))
.
.
2014-01-13 12:47 . 2014-01-13 12:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-13 12:32 . 2014-01-13 12:32 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7257326A-87CA-41A9-9DD0-9D64EC1427E4}\offreg.dll
2014-01-12 17:43 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7257326A-87CA-41A9-9DD0-9D64EC1427E4}\mpengine.dll
2014-01-11 18:46 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-01-10 18:11 . 2013-12-19 18:37 2555168 ----a-w- c:\windows\system32\nvsvcr.dll
2014-01-10 18:09 . 2013-12-19 20:26 9657464 ----a-w- c:\windows\system32\nvopencl.dll
2014-01-10 18:09 . 2013-12-19 20:26 893728 ----a-w- c:\windows\system32\nvdispgenco3233221.dll
2014-01-10 18:09 . 2013-12-19 20:26 852768 ----a-w- c:\windows\system32\NvIFR.dll
2014-01-10 18:09 . 2013-12-19 20:26 847648 ----a-w- c:\windows\system32\NvFBC.dll
2014-01-10 18:09 . 2013-12-19 20:26 2947872 ----a-w- c:\windows\system32\nvcuvid.dll
2014-01-10 18:09 . 2013-12-19 20:26 2747680 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-01-10 18:09 . 2013-12-19 20:26 22960416 ----a-w- c:\windows\system32\nvoglv32.dll
2014-01-10 18:09 . 2013-12-19 20:26 15877216 ----a-w- c:\windows\system32\nvwgf2um.dll
2014-01-10 18:09 . 2013-12-19 20:26 1049888 ----a-w- c:\windows\system32\nvdispco3233221.dll
2014-01-10 18:09 . 2013-12-19 20:26 10471712 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-01-10 18:09 . 2013-12-19 20:26 9700224 ----a-w- c:\windows\system32\nvcuda.dll
2014-01-10 18:09 . 2013-12-19 20:26 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2014-01-10 09:57 . 2014-01-10 09:57 22688 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2014-01-10 09:57 . 2014-01-10 09:57 -------- d-----w- c:\program files\HWiNFO32
2014-01-10 08:59 . 2014-01-10 08:59 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\programdata\Malwarebytes
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-01-09 22:28 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-09 19:04 . 2014-01-09 19:04 -------- d-----w- c:\program files\HiJack
2014-01-05 12:28 . 2014-01-05 12:28 -------- d-----w- c:\programdata\Codemasters
2014-01-05 12:26 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\system32\nircmdc.exe
2014-01-05 11:35 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-05 11:35 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-05 11:35 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-05 11:35 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-05 11:35 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-05 11:35 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-05 11:35 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-04 19:26 . 2014-01-04 19:26 -------- d-----w- c:\program files\GSC World Publishing
2014-01-04 10:59 . 2013-12-05 08:42 34080 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2014-01-04 10:57 . 2013-12-10 02:13 982232 ----a-w- c:\windows\system32\nvspcap.dll
2014-01-04 10:56 . 2014-01-04 10:56 -------- d-----w- c:\program files\AGEIA Technologies
2014-01-04 10:55 . 2014-01-13 12:48 -------- d-----w- c:\programdata\NVIDIA
2014-01-04 10:55 . 2013-12-19 18:37 4317984 ----a-w- c:\windows\system32\nvcpl.dll
2014-01-04 10:55 . 2013-12-19 18:37 3036960 ----a-w- c:\windows\system32\nvsvc.dll
2014-01-04 10:55 . 2013-12-19 18:37 664352 ----a-w- c:\windows\system32\nvvsvc.exe
2014-01-04 10:55 . 2013-12-19 18:37 62752 ----a-w- c:\windows\system32\nvshext.dll
2014-01-04 10:55 . 2013-12-19 18:37 376096 ----a-w- c:\windows\system32\nvmctray.dll
2014-01-04 10:54 . 2013-12-19 20:26 53024 ----a-w- c:\windows\system32\OpenCL.dll
2014-01-04 10:54 . 2014-01-04 11:00 -------- d-----w- c:\programdata\NVIDIA Corporation
2014-01-04 10:53 . 2013-12-05 08:42 32544 ----a-w- c:\windows\system32\nvaudcap32v.dll
2014-01-04 10:53 . 2013-11-14 11:55 893728 ----a-w- c:\windows\system32\nvdispgenco3233182.dll
2014-01-04 10:53 . 2013-11-14 11:55 1049888 ----a-w- c:\windows\system32\nvdispco3233182.dll
2014-01-04 10:53 . 2013-12-19 20:26 2698272 ----a-w- c:\windows\system32\nvapi.dll
2014-01-04 10:49 . 2014-01-10 18:12 -------- d-----w- c:\program files\NVIDIA Corporation
2014-01-04 10:44 . 2005-10-28 13:58 45056 ----a-w- c:\windows\system32\ActiveDestopOCX.ocx
2014-01-04 10:43 . 2014-01-04 10:43 -------- d-----w- c:\program files\MSI
2014-01-04 10:43 . 1998-10-02 18:00 327168 ----a-w- c:\windows\IsUninst.exe
2014-01-04 10:38 . 2008-10-02 09:07 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2014-01-04 10:16 . 2014-01-11 18:48 -------- d-----w- c:\program files\AIMP3
2014-01-04 10:06 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2014-01-04 09:53 . 2014-01-04 09:56 -------- d-----w- c:\windows\system32\MRT
2014-01-03 21:32 . 2014-01-03 21:32 -------- d-----w- c:\programdata\The Revills Games
2014-01-03 21:31 . 2014-01-03 21:32 -------- d-----w- c:\program files\Common Files\Adobe
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\program files\Legends of Solitaire 2 - Curse of the Dragons
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\windows\Legends of Solitaire 2 - Curse of the Dragons
2014-01-01 22:16 . 2014-01-01 22:16 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Synchronization Services
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\windows\PCHEALTH
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Sync Framework
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2014-01-01 20:42 . 2014-01-01 20:42 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2014-01-01 20:41 . 2014-01-01 20:41 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-01-01 20:40 . 2014-01-02 22:18 -------- d-----w- c:\programdata\Microsoft Help
2014-01-01 20:40 . 2014-01-01 20:40 -------- d-----r- C:\MSOCache
2014-01-01 20:34 . 2014-01-01 20:34 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-01-01 20:34 . 2014-01-10 18:53 -------- d-----w- c:\program files\DAEMON Tools Lite
2014-01-01 20:27 . 2014-01-01 20:40 -------- d-----w- c:\programdata\DAEMON Tools Lite
2014-01-01 19:21 . 2014-01-02 13:37 -------- d-----w- c:\program files\Holdem Manager 2
2014-01-01 13:37 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2014-01-01 13:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-01-01 13:37 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe
2014-01-01 13:37 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-01 01:24 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-01-01 01:24 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-01-01 01:10 . 2014-01-01 01:10 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-12-31 18:43 . 2013-10-30 02:19 301568 ----a-w- c:\windows\system32\msieftp.dll
2013-12-31 18:43 . 2013-09-25 02:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-12-31 18:43 . 2013-09-25 01:57 247808 ----a-w- c:\windows\system32\schannel.dll
2013-12-31 18:43 . 2013-07-04 12:16 369848 ----a-w- c:\windows\system32\drivers\cng.sys
2013-12-31 18:43 . 2013-09-25 02:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-12-31 18:43 . 2013-09-25 01:57 99840 ----a-w- c:\windows\system32\sspicli.dll
2013-12-31 18:43 . 2013-09-25 01:57 22016 ----a-w- c:\windows\system32\secur32.dll
2013-12-31 18:43 . 2013-09-25 01:56 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-12-31 18:43 . 2013-09-25 01:56 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2013-12-31 18:43 . 2013-09-25 00:49 22016 ----a-w- c:\windows\system32\lsass.exe
2013-12-31 18:43 . 2013-09-25 00:49 15872 ----a-w- c:\windows\system32\sspisrv.dll
2013-12-31 18:41 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-12-31 18:40 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-12-31 18:39 . 2012-10-09 17:40 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-12-31 18:14 . 2014-01-13 09:52 -------- d-----w- c:\users\postgres
2013-12-31 18:08 . 2014-01-01 19:46 -------- d-----w- c:\program files\PSQLINSTALL
2013-12-31 15:44 . 2013-12-31 15:44 -------- d-----w- c:\programdata\SP_FT_Logs
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\SPReview
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\EventProviders
2013-12-31 07:51 . 2014-01-11 09:11 -------- d-----w- c:\users\Guest
2013-12-30 22:34 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-12-30 22:32 . 2010-11-20 12:30 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys
2013-12-30 22:31 . 2010-11-20 12:21 8704 ----a-w- c:\windows\system32\rdpcfgex.dll
2013-12-30 21:57 . 2013-10-27 22:41 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DD6078AC-1BDD-4201-B14C-36B308FCA642}\gapaengine.dll
2013-12-30 21:42 . 2013-12-30 21:42 -------- d-----w- c:\program files\Microsoft Security Client
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Common Files\InstallShield
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Browser Configuration Utility
2013-12-30 19:23 . 2008-05-02 14:08 146528 ----a-w- c:\windows\system32\dvmurl.dll
2013-12-30 19:22 . 2013-12-30 19:26 16608 ----a-w- c:\windows\gdrv.sys
2013-12-30 18:13 . 2013-12-30 22:09 -------- d-----w- c:\program files\LenovoUsbDriver
2013-12-30 17:24 . 2013-12-30 17:26 -------- d-----w- c:\program files\PdaNet for Android
2013-12-30 17:24 . 2011-07-19 10:28 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2013-12-30 17:24 . 2009-11-08 01:41 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2013-12-30 17:24 . 2009-11-08 01:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\TeamViewer
2013-12-30 16:58 . 2014-01-11 17:12 -------- d-----r- c:\program files\Skype
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\Common Files\Skype
2013-12-30 16:58 . 2014-01-03 11:10 -------- d-----w- c:\programdata\Skype
2013-12-30 14:43 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-12-30 14:43 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-12-30 14:43 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2013-12-30 14:43 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-12-30 14:43 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2013-12-30 14:43 . 2013-02-12 03:32 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-10 10:53 . 2014-01-10 07:47 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16384 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14912 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35968 ----a-w- c:\windows\system32\drivers\winusb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 9728 ----a-w- c:\windows\system32\drivers\wfplwf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 63488 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43392 ----a-w- c:\windows\system32\drivers\winhv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\watchdog.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21632 ----a-w- c:\windows\system32\drivers\wacompen.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19024 ----a-w- c:\windows\system32\drivers\wd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19008 ----a-w- c:\windows\system32\drivers\wimmount.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14336 ----a-w- c:\windows\system32\drivers\vwifimp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 48128 ----a-w- c:\windows\system32\drivers\vwififlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40704 ----a-w- c:\windows\system32\drivers\vmstorfl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 297040 ----a-w- c:\windows\system32\drivers\volmgrx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 245632 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\vwifibus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 141904 ----a-w- c:\windows\system32\drivers\vsmraid.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 5632 ----a-w- c:\windows\system32\drivers\vms3cap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17920 ----a-w- c:\windows\system32\drivers\VMBusHID.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 175360 ----a-w- c:\windows\system32\drivers\vmbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 111616 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53328 ----a-w- c:\windows\system32\drivers\VIAAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52736 ----a-w- c:\windows\system32\drivers\viac7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\vgapnp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16976 ----a-w- c:\windows\system32\drivers\viaide.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 160128 ----a-w- c:\windows\system32\drivers\vhdmp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 32832 ----a-w- c:\windows\system32\drivers\vdrvroot.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\usbrpm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25088 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\usbprint.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 284672 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 6016 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 8192 ----a-w- c:\windows\system32\drivers\umpass.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 57424 ----a-w- c:\windows\system32\drivers\ULIAGPKX.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 55888 ----a-w- c:\windows\system32\drivers\UAGP35.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52224 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 39936 ----a-w- c:\windows\system32\drivers\umbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 246784 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 108544 ----a-w- c:\windows\system32\drivers\tunnel.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 74752 ----a-w- c:\windows\system32\drivers\tdx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 18432 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21504 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53632 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 28032 ----a-w- c:\windows\system32\drivers\storvsc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21072 ----a-w- c:\windows\system32\drivers\stexstor.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 148864 ----a-w- c:\windows\system32\drivers\storport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 12240 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 311808 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 310272 ----a-w- c:\windows\system32\drivers\srv2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 77888 ----a-w- c:\windows\system32\drivers\sisraid4.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 71168 ----a-w- c:\windows\system32\drivers\smb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 52304 ----a-w- c:\windows\system32\drivers\SISAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 405504 ----a-w- c:\windows\system32\drivers\spsys.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40016 ----a-w- c:\windows\system32\drivers\sisraid2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17472 ----a-w- c:\windows\system32\drivers\spldr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17408 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 13824 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 83456 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 26624 ----a-w- c:\windows\system32\drivers\scfilter.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 19968 ----a-w- c:\windows\system32\drivers\sermouse.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 17920 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 140160 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12288 ----a-w- c:\windows\system32\drivers\sffp_mmc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 11264 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 85376 ----a-w- c:\windows\system32\drivers\sbp2port.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 8192 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 60928 ----a-w- c:\windows\system32\drivers\rspndr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 2152088 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 139776 ----a-w- c:\windows\system32\drivers\Rt86win7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 173440 ----a-w- c:\windows\system32\drivers\rdyboost.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 117760 ----a-w- c:\windows\system32\drivers\rmcast.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 7168 ----a-w- c:\windows\system32\drivers\RDPREFMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys.bak
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-04-02 75048]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2013-12-10 982232]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
.
c:\users\mnouckk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Bitcoin.lnk - c:\program files\Bitcoin\bitcoin-qt.exe -min [2011-1-30 22613504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:a1179063 /dir:C:\Program
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 13312]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-12-30 1343400]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-01-01 243128]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2014-01-10 22688]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2013/12/29 23:46];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-04-02 08:11 87536]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;c:/postgreSQL/bin/pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-19 411936]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-29 22:18 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-29 22:40]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 77.48.100.254 212.80.66.7
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight]
"ImagePath"="\??\"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\postgresql\bin\pg_ctl.exe
c:\windows\system32\rundll32.exe
c:\postgresql\bin\postgres.exe
c:\windows\system32\conhost.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\windows\system32\taskhost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\windows\RtHDVCpl.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2014-01-13 13:53:33 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-13 12:53
.
Před spuštěním: Volných bajtů: 54 152 118 272
Po spuštění: Volných bajtů: 54 065 577 984
.
- - End Of File - - 2808637E16959A70FFA7ADE8CEB4AB9C
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3070.2099 [GMT 1:00]
Spuštěný z: c:\users\mnouckk\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\mnouckk\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\inf\mshnpmis.vbe"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.22.3\GoogleUpdate.exe
c:\program files\Google\Update\1.3.22.3\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.22.3\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.22.3\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.22.3\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.22.3\goopdate.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_am.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ar.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_bg.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_bn.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ca.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_cs.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_da.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_de.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_el.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_en.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_es.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_et.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_fa.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_fi.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_fil.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_fr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_gu.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_hi.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_hr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_hu.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_id.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_is.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_it.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_iw.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ja.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_kn.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ko.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_lt.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_lv.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ml.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_mr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ms.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_nl.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_no.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_pl.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ro.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ru.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sk.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sl.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sv.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_sw.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ta.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_te.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_th.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_tr.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_uk.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_ur.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_vi.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.22.3\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.22.3\psmachine.dll
c:\program files\Google\Update\1.3.22.3\psuser.dll
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.3\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\31.0.1650.63\31.0.1650.63_chrome_installer.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\users\mnouckk\AppData\Roaming\Roaming
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-13 do 2014-01-13 )))))))))))))))))))))))))))))))
.
.
2014-01-13 12:47 . 2014-01-13 12:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-13 12:32 . 2014-01-13 12:32 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7257326A-87CA-41A9-9DD0-9D64EC1427E4}\offreg.dll
2014-01-12 17:43 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7257326A-87CA-41A9-9DD0-9D64EC1427E4}\mpengine.dll
2014-01-11 18:46 . 2013-12-03 17:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-01-10 18:11 . 2013-12-19 18:37 2555168 ----a-w- c:\windows\system32\nvsvcr.dll
2014-01-10 18:09 . 2013-12-19 20:26 9657464 ----a-w- c:\windows\system32\nvopencl.dll
2014-01-10 18:09 . 2013-12-19 20:26 893728 ----a-w- c:\windows\system32\nvdispgenco3233221.dll
2014-01-10 18:09 . 2013-12-19 20:26 852768 ----a-w- c:\windows\system32\NvIFR.dll
2014-01-10 18:09 . 2013-12-19 20:26 847648 ----a-w- c:\windows\system32\NvFBC.dll
2014-01-10 18:09 . 2013-12-19 20:26 2947872 ----a-w- c:\windows\system32\nvcuvid.dll
2014-01-10 18:09 . 2013-12-19 20:26 2747680 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-01-10 18:09 . 2013-12-19 20:26 22960416 ----a-w- c:\windows\system32\nvoglv32.dll
2014-01-10 18:09 . 2013-12-19 20:26 15877216 ----a-w- c:\windows\system32\nvwgf2um.dll
2014-01-10 18:09 . 2013-12-19 20:26 1049888 ----a-w- c:\windows\system32\nvdispco3233221.dll
2014-01-10 18:09 . 2013-12-19 20:26 10471712 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-01-10 18:09 . 2013-12-19 20:26 9700224 ----a-w- c:\windows\system32\nvcuda.dll
2014-01-10 18:09 . 2013-12-19 20:26 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2014-01-10 09:57 . 2014-01-10 09:57 22688 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2014-01-10 09:57 . 2014-01-10 09:57 -------- d-----w- c:\program files\HWiNFO32
2014-01-10 08:59 . 2014-01-10 08:59 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\programdata\Malwarebytes
2014-01-09 22:28 . 2014-01-09 22:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-01-09 22:28 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-09 19:04 . 2014-01-09 19:04 -------- d-----w- c:\program files\HiJack
2014-01-05 12:28 . 2014-01-05 12:28 -------- d-----w- c:\programdata\Codemasters
2014-01-05 12:26 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\system32\nircmdc.exe
2014-01-05 11:35 . 2013-09-04 01:15 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-05 11:35 . 2013-09-04 01:14 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-05 11:35 . 2013-09-04 01:14 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-05 11:35 . 2013-09-04 01:14 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-05 11:35 . 2013-09-04 01:14 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-05 11:35 . 2013-09-04 01:14 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-05 11:35 . 2013-09-04 01:14 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-04 19:26 . 2014-01-04 19:26 -------- d-----w- c:\program files\GSC World Publishing
2014-01-04 10:59 . 2013-12-05 08:42 34080 ----a-w- c:\windows\system32\drivers\nvvad32v.sys
2014-01-04 10:57 . 2013-12-10 02:13 982232 ----a-w- c:\windows\system32\nvspcap.dll
2014-01-04 10:56 . 2014-01-04 10:56 -------- d-----w- c:\program files\AGEIA Technologies
2014-01-04 10:55 . 2014-01-13 12:48 -------- d-----w- c:\programdata\NVIDIA
2014-01-04 10:55 . 2013-12-19 18:37 4317984 ----a-w- c:\windows\system32\nvcpl.dll
2014-01-04 10:55 . 2013-12-19 18:37 3036960 ----a-w- c:\windows\system32\nvsvc.dll
2014-01-04 10:55 . 2013-12-19 18:37 664352 ----a-w- c:\windows\system32\nvvsvc.exe
2014-01-04 10:55 . 2013-12-19 18:37 62752 ----a-w- c:\windows\system32\nvshext.dll
2014-01-04 10:55 . 2013-12-19 18:37 376096 ----a-w- c:\windows\system32\nvmctray.dll
2014-01-04 10:54 . 2013-12-19 20:26 53024 ----a-w- c:\windows\system32\OpenCL.dll
2014-01-04 10:54 . 2014-01-04 11:00 -------- d-----w- c:\programdata\NVIDIA Corporation
2014-01-04 10:53 . 2013-12-05 08:42 32544 ----a-w- c:\windows\system32\nvaudcap32v.dll
2014-01-04 10:53 . 2013-11-14 11:55 893728 ----a-w- c:\windows\system32\nvdispgenco3233182.dll
2014-01-04 10:53 . 2013-11-14 11:55 1049888 ----a-w- c:\windows\system32\nvdispco3233182.dll
2014-01-04 10:53 . 2013-12-19 20:26 2698272 ----a-w- c:\windows\system32\nvapi.dll
2014-01-04 10:49 . 2014-01-10 18:12 -------- d-----w- c:\program files\NVIDIA Corporation
2014-01-04 10:44 . 2005-10-28 13:58 45056 ----a-w- c:\windows\system32\ActiveDestopOCX.ocx
2014-01-04 10:43 . 2014-01-04 10:43 -------- d-----w- c:\program files\MSI
2014-01-04 10:43 . 1998-10-02 18:00 327168 ----a-w- c:\windows\IsUninst.exe
2014-01-04 10:38 . 2008-10-02 09:07 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2014-01-04 10:16 . 2014-01-11 18:48 -------- d-----w- c:\program files\AIMP3
2014-01-04 10:06 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2014-01-04 09:53 . 2014-01-04 09:56 -------- d-----w- c:\windows\system32\MRT
2014-01-03 21:32 . 2014-01-03 21:32 -------- d-----w- c:\programdata\The Revills Games
2014-01-03 21:31 . 2014-01-03 21:32 -------- d-----w- c:\program files\Common Files\Adobe
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\program files\Legends of Solitaire 2 - Curse of the Dragons
2014-01-03 21:31 . 2014-01-03 21:31 -------- d-----w- c:\windows\Legends of Solitaire 2 - Curse of the Dragons
2014-01-01 22:16 . 2014-01-01 22:16 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Synchronization Services
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\windows\PCHEALTH
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft Sync Framework
2014-01-01 20:44 . 2014-01-01 20:44 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2014-01-01 20:42 . 2014-01-01 20:42 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2014-01-01 20:41 . 2014-01-01 20:41 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-01-01 20:40 . 2014-01-02 22:18 -------- d-----w- c:\programdata\Microsoft Help
2014-01-01 20:40 . 2014-01-01 20:40 -------- d-----r- C:\MSOCache
2014-01-01 20:34 . 2014-01-01 20:34 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-01-01 20:34 . 2014-01-10 18:53 -------- d-----w- c:\program files\DAEMON Tools Lite
2014-01-01 20:27 . 2014-01-01 20:40 -------- d-----w- c:\programdata\DAEMON Tools Lite
2014-01-01 19:21 . 2014-01-02 13:37 -------- d-----w- c:\program files\Holdem Manager 2
2014-01-01 13:37 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2014-01-01 13:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-01-01 13:37 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe
2014-01-01 13:37 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-01 01:24 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-01-01 01:24 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-01-01 01:10 . 2014-01-01 01:10 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-12-31 18:43 . 2013-10-30 02:19 301568 ----a-w- c:\windows\system32\msieftp.dll
2013-12-31 18:43 . 2013-09-25 02:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-12-31 18:43 . 2013-09-25 01:57 247808 ----a-w- c:\windows\system32\schannel.dll
2013-12-31 18:43 . 2013-07-04 12:16 369848 ----a-w- c:\windows\system32\drivers\cng.sys
2013-12-31 18:43 . 2013-09-25 02:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-12-31 18:43 . 2013-09-25 01:57 99840 ----a-w- c:\windows\system32\sspicli.dll
2013-12-31 18:43 . 2013-09-25 01:57 22016 ----a-w- c:\windows\system32\secur32.dll
2013-12-31 18:43 . 2013-09-25 01:56 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-12-31 18:43 . 2013-09-25 01:56 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2013-12-31 18:43 . 2013-09-25 00:49 22016 ----a-w- c:\windows\system32\lsass.exe
2013-12-31 18:43 . 2013-09-25 00:49 15872 ----a-w- c:\windows\system32\sspisrv.dll
2013-12-31 18:41 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-12-31 18:40 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-12-31 18:39 . 2012-10-09 17:40 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-12-31 18:14 . 2014-01-13 09:52 -------- d-----w- c:\users\postgres
2013-12-31 18:08 . 2014-01-01 19:46 -------- d-----w- c:\program files\PSQLINSTALL
2013-12-31 15:44 . 2013-12-31 15:44 -------- d-----w- c:\programdata\SP_FT_Logs
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\SPReview
2013-12-31 07:54 . 2013-12-31 07:54 -------- d-----w- c:\windows\system32\EventProviders
2013-12-31 07:51 . 2014-01-11 09:11 -------- d-----w- c:\users\Guest
2013-12-30 22:34 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-12-30 22:32 . 2010-11-20 12:30 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys
2013-12-30 22:31 . 2010-11-20 12:21 8704 ----a-w- c:\windows\system32\rdpcfgex.dll
2013-12-30 21:57 . 2013-10-27 22:41 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DD6078AC-1BDD-4201-B14C-36B308FCA642}\gapaengine.dll
2013-12-30 21:42 . 2013-12-30 21:42 -------- d-----w- c:\program files\Microsoft Security Client
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Common Files\InstallShield
2013-12-30 19:23 . 2013-12-30 19:23 -------- d-----w- c:\program files\Browser Configuration Utility
2013-12-30 19:23 . 2008-05-02 14:08 146528 ----a-w- c:\windows\system32\dvmurl.dll
2013-12-30 19:22 . 2013-12-30 19:26 16608 ----a-w- c:\windows\gdrv.sys
2013-12-30 18:13 . 2013-12-30 22:09 -------- d-----w- c:\program files\LenovoUsbDriver
2013-12-30 17:24 . 2013-12-30 17:26 -------- d-----w- c:\program files\PdaNet for Android
2013-12-30 17:24 . 2011-07-19 10:28 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2013-12-30 17:24 . 2009-11-08 01:41 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2013-12-30 17:24 . 2009-11-08 01:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\TeamViewer
2013-12-30 16:58 . 2014-01-11 17:12 -------- d-----r- c:\program files\Skype
2013-12-30 16:58 . 2013-12-30 16:58 -------- d-----w- c:\program files\Common Files\Skype
2013-12-30 16:58 . 2014-01-03 11:10 -------- d-----w- c:\programdata\Skype
2013-12-30 14:43 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-12-30 14:43 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-12-30 14:43 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2013-12-30 14:43 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-12-30 14:43 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2013-12-30 14:43 . 2013-02-12 03:32 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-10 10:53 . 2014-01-10 07:47 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16384 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14912 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 11264 ----a-w- c:\windows\system32\drivers\wmiacpi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35968 ----a-w- c:\windows\system32\drivers\winusb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 9728 ----a-w- c:\windows\system32\drivers\wfplwf.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 63488 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43392 ----a-w- c:\windows\system32\drivers\winhv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\watchdog.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21632 ----a-w- c:\windows\system32\drivers\wacompen.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19024 ----a-w- c:\windows\system32\drivers\wd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19008 ----a-w- c:\windows\system32\drivers\wimmount.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 14336 ----a-w- c:\windows\system32\drivers\vwifimp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\volmgr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 48128 ----a-w- c:\windows\system32\drivers\vwififlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40704 ----a-w- c:\windows\system32\drivers\vmstorfl.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 297040 ----a-w- c:\windows\system32\drivers\volmgrx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 245632 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\vwifibus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 141904 ----a-w- c:\windows\system32\drivers\vsmraid.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 5632 ----a-w- c:\windows\system32\drivers\vms3cap.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17920 ----a-w- c:\windows\system32\drivers\VMBusHID.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 175360 ----a-w- c:\windows\system32\drivers\vmbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 111616 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53328 ----a-w- c:\windows\system32\drivers\VIAAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52736 ----a-w- c:\windows\system32\drivers\viac7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\vgapnp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 16976 ----a-w- c:\windows\system32\drivers\viaide.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 160128 ----a-w- c:\windows\system32\drivers\vhdmp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 32832 ----a-w- c:\windows\system32\drivers\vdrvroot.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 26112 ----a-w- c:\windows\system32\drivers\usbrpm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25088 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 19968 ----a-w- c:\windows\system32\drivers\usbprint.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 284672 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 6016 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 8192 ----a-w- c:\windows\system32\drivers\umpass.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 57424 ----a-w- c:\windows\system32\drivers\ULIAGPKX.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 55888 ----a-w- c:\windows\system32\drivers\UAGP35.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 52224 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 39936 ----a-w- c:\windows\system32\drivers\umbus.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 246784 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 108544 ----a-w- c:\windows\system32\drivers\tunnel.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 74752 ----a-w- c:\windows\system32\drivers\tdx.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53120 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 18432 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 24576 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21504 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 53632 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 28032 ----a-w- c:\windows\system32\drivers\storvsc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 21072 ----a-w- c:\windows\system32\drivers\stexstor.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 148864 ----a-w- c:\windows\system32\drivers\storport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 12240 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 311808 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 310272 ----a-w- c:\windows\system32\drivers\srv2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 77888 ----a-w- c:\windows\system32\drivers\sisraid4.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 71168 ----a-w- c:\windows\system32\drivers\smb.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 52304 ----a-w- c:\windows\system32\drivers\SISAGP.SYS.bak
2014-01-10 10:53 . 2014-01-10 07:47 405504 ----a-w- c:\windows\system32\drivers\spsys.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 40016 ----a-w- c:\windows\system32\drivers\sisraid2.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17472 ----a-w- c:\windows\system32\drivers\spldr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:47 17408 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 13824 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 83456 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 26624 ----a-w- c:\windows\system32\drivers\scfilter.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 19968 ----a-w- c:\windows\system32\drivers\sermouse.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 17920 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 140160 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 12288 ----a-w- c:\windows\system32\drivers\sffp_mmc.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 11264 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 85376 ----a-w- c:\windows\system32\drivers\sbp2port.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 8192 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 60928 ----a-w- c:\windows\system32\drivers\rspndr.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 2152088 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 139776 ----a-w- c:\windows\system32\drivers\Rt86win7.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 173440 ----a-w- c:\windows\system32\drivers\rdyboost.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 117760 ----a-w- c:\windows\system32\drivers\rmcast.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 7168 ----a-w- c:\windows\system32\drivers\RDPREFMP.sys.bak
2014-01-10 10:53 . 2014-01-10 07:46 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys.bak
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-04-02 75048]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2013-12-10 982232]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
.
c:\users\mnouckk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Bitcoin.lnk - c:\program files\Bitcoin\bitcoin-qt.exe -min [2011-1-30 22613504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:a1179063 /dir:C:\Program
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 13312]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-12-30 1343400]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-01-01 243128]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2014-01-10 22688]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2013/12/29 23:46];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-04-02 08:11 87536]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;c:/postgreSQL/bin/pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-19 411936]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-29 22:18 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-29 22:40]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 77.48.100.254 212.80.66.7
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrueSight]
"ImagePath"="\??\"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\postgresql\bin\pg_ctl.exe
c:\windows\system32\rundll32.exe
c:\postgresql\bin\postgres.exe
c:\windows\system32\conhost.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\postgresql\bin\postgres.exe
c:\windows\system32\taskhost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\windows\RtHDVCpl.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2014-01-13 13:53:33 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-13 12:53
.
Před spuštěním: Volných bajtů: 54 152 118 272
Po spuštění: Volných bajtů: 54 065 577 984
.
- - End Of File - - 2808637E16959A70FFA7ADE8CEB4AB9C
A36C5E4F47E84449FF07ED3517B43A31
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 103 hostů