CPU pořád na 100% prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
betisa
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

CPU pořád na 100% prosím o kontrolu logu

Příspěvekod betisa » 19 úno 2014 12:09

Prosím o kontrolu logu notebook stále jede na plný výkon...díky

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:01:49, on 19. 2. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\USB Camera2\VM332STI.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Users\Jituš\Desktop\hijackthis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seznam.cz/?clid=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [332BigDog] C:\Program Files (x86)\USB Camera2\VM332STI.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CPUM] C:\Users\Public\Public\run.vbs
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: @oem14.inf,%BcmBtRSupport.SVCNAME%;Bluetooth Radio Control Service (BcmBtRSupport) - Unknown owner - C:\Windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater15.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 8688 bytes
MB-GIGABYTE; CPU-INTEL CORE i5; CHLADIČ-COOLER MASTER;
GPU-ASUS GTX660; RAM-KINGSTON 2x4 GB DDR3-1333MHz; SYSTÉM SSD- CRUCIAL 232GB + HDD-SEAGATE 320GB; PSU-SEASONIC G-550;

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod jaro3 » 19 úno 2014 16:55

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
betisa
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod betisa » 20 úno 2014 07:18

Zdravím já ten mbam použil ještě před tvojí reakcí na muj příspěvek jelikož notebook jel pořád naplno včetně ventilátoru tak jsem s tím musel něco dělat.První log je před a druhý po odstranění "šmejdů"..zdá se že to pomohlo

alwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.02.19.06

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16599
Jituš :: JITUŠ-NB [administrátor]

19. 2. 2014 12:13:50
mbam-log-2014-02-19 (12-13-50).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 260839
Uplynulý čas: 4 minut, 37 sekund

Nalezené procesy v paměti: 1
C:\Users\Public\Public\minerd.exe (Riskware.BitcoinMiner) -> 3676 -> Bude smazán při restartu.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CPUM (Trojan.BitcoinMiner) -> Data: C:\Users\Public\Public\run.vbs -> Přesun do karantény a smazání se zdařilo.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 1
C:\Users\Public\Public (Trojan.BitcoinMiner) -> Bude smazán při restartu.

Nalezené soubory: 10
C:\Users\Public\Public\mining_proxy.exe (PUP.Proxy.BCM) -> Nebyla provedena žádná instrukce.
C:\Users\Public\Public\minerd.exe (Riskware.BitcoinMiner) -> Bude smazán při restartu.
C:\Users\Public\Public\run.vbs (Trojan.BitcoinMiner) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Public\Public\game.bat (Trojan.BitcoinMiner) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Public\Public\game.vbs (Trojan.BitcoinMiner) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Public\Public\libcurl.dll (Trojan.BitcoinMiner) -> Bude smazán při restartu.
C:\Users\Public\Public\mining_proxy.exe (Trojan.BitcoinMiner) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Public\Public\pthreadGC2.dll (Trojan.BitcoinMiner) -> Bude smazán při restartu.
C:\Users\Public\Public\run.bat (Trojan.BitcoinMiner) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Public\Public\zlib1.dll (Trojan.BitcoinMiner) -> Bude smazán při restartu.

(konec)
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
tady je druhý log po smazání trojanů

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.02.19.06

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16599
Jituš :: JITUŠ-NB [administrátor]

19. 2. 2014 12:24:47
mbam-log-2014-02-19 (12-24-47).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 260936
Uplynulý čas: 8 minut, 11 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)


X---------------------------------------------------------------------------------------------------------------------------------------------------------------------


# AdwCleaner v3.019 - Report created 20/02/2014 at 07:04:06
# Updated 17/02/2014 by Xplode
# Operating System : Windows 8 Pro (64 bits)
# Username : Jituš - JITUŠ-NB
# Running from : C:\Users\Jituš\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Windows\System32\Tasks\NCH Software

***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16537


-\\ Google Chrome v32.0.1700.107

[ File : C:\Users\Jituš\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1698 octets] - [19/02/2014 17:00:40]
AdwCleaner[R1].txt - [911 octets] - [20/02/2014 07:02:34]
AdwCleaner[S0].txt - [1621 octets] - [19/02/2014 17:02:02]
AdwCleaner[S1].txt - [835 octets] - [20/02/2014 07:04:06]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [894 octets] ##########
MB-GIGABYTE; CPU-INTEL CORE i5; CHLADIČ-COOLER MASTER;
GPU-ASUS GTX660; RAM-KINGSTON 2x4 GB DDR3-1333MHz; SYSTÉM SSD- CRUCIAL 232GB + HDD-SEAGATE 320GB; PSU-SEASONIC G-550;

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod jaro3 » 20 úno 2014 10:13

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
betisa
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod betisa » 20 úno 2014 13:01

Omluva za pozdější reakci,ale bohužel občas musím v práci něco dělat,taková je krušná doba.....tak proto

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 8 Pro x64
Ran by Jituç on źt 20. 02. 2014 at 12:18:09,94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{35F4D3E7-EEB0-4819-8833-15E92E4FF9DF}

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Program Files (x86)\eusing free registry cleaner"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\free registry cleaner"

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 20. 02. 2014 at 12:31:27,28
End of JRT log

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


RogueKiller V8.8.8 _x64_ [Feb 19 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Jituš [Práva správce]
Mód : Kontrola -- Datum : 02/20/2014 12:49:53
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 2 ¤¤¤
[SUSP PATH] slsvc.exe -- C:\Windows\slsvc.exe [-] -> SMAZÁNO [TermProc]
[SUSP PATH] PersonalizeEnabler.exe -- C:\Windows\PersonalizeEnabler.exe [-] -> SMAZÁNO [TermProc]

¤¤¤ ¤¤¤ Záznamy Registrů: : 6 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 1 ¤¤¤
[Jituš][SUSP UNIC] Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk : C:\Users\Jituš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk [-] -> NALEZENO

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST9500325AS +++++
--- User ---
[MBR] edfa9362cf9cdac3f154d6424fc7e169
[BSP] 15fc16227e8fccae680f59a76c9e4889 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 350 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 718848 | Size: 476588 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) USB2.0 Flash Disk USB Device +++++
--- User ---
[MBR] c7c38c635e4fdf42a95261e4f923cdd0
[BSP] fddc894a590d16f8c63f75a312dc22c6 : MBR Code unknown
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1948285285 | Size: 831044 Mo
1 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 28049408 | Size: 0 Mo
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] Po?adavek není podporován. )

Dokončeno : << RKreport[0]_S_02202014_124953.txt >>


XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

12:52:38.0813 4672 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
12:52:50.0595 4672 ============================================================
12:52:50.0595 4672 Current date / time: 2014/02/20 12:52:50.0595
12:52:50.0595 4672 SystemInfo:
12:52:50.0595 4672
12:52:50.0595 4672 OS Version: 6.2.9200 ServicePack: 0.0
12:52:50.0595 4672 Product type: Workstation
12:52:50.0595 4672 ComputerName: JITUŠ-NB
12:52:50.0595 4672 UserName: Jituš
12:52:50.0595 4672 Windows directory: C:\Windows
12:52:50.0595 4672 System windows directory: C:\Windows
12:52:50.0595 4672 Running under WOW64
12:52:50.0595 4672 Processor architecture: Intel x64
12:52:50.0595 4672 Number of processors: 2
12:52:50.0595 4672 Page size: 0x1000
12:52:50.0595 4672 Boot type: Normal boot
12:52:50.0595 4672 ============================================================
12:52:51.0767 4672 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:52:51.0783 4672 Drive \Device\Harddisk1\DR1 - Size: 0x7E400000 (1.97 Gb), SectorSize: 0x200, Cylinders: 0x101, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
12:52:51.0783 4672 ============================================================
12:52:51.0783 4672 \Device\Harddisk0\DR0:
12:52:51.0783 4672 MBR partitions:
12:52:51.0783 4672 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAF000
12:52:51.0783 4672 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xAF800, BlocksNum 0x3A2D6000
12:52:51.0783 4672 \Device\Harddisk1\DR1:
12:52:51.0783 4672 MBR partitions:
12:52:51.0783 4672 ============================================================
12:52:51.0814 4672 C: <-> \Device\Harddisk0\DR0\Partition2
12:52:51.0814 4672 ============================================================
12:52:51.0814 4672 Initialize success
12:52:51.0814 4672 ============================================================
12:52:54.0799 3568 ============================================================
12:52:54.0799 3568 Scan started
12:52:54.0799 3568 Mode: Manual;
12:52:54.0799 3568 ============================================================
12:52:55.0471 3568 ================ Scan system memory ========================
12:52:55.0471 3568 System memory - ok
12:52:55.0471 3568 ================ Scan services =============================
12:52:55.0643 3568 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
12:52:55.0659 3568 1394ohci - ok
12:52:55.0674 3568 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys
12:52:55.0674 3568 3ware - ok
12:52:55.0721 3568 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys
12:52:55.0721 3568 ACPI - ok
12:52:55.0752 3568 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys
12:52:55.0752 3568 acpiex - ok
12:52:55.0768 3568 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
12:52:55.0768 3568 acpipagr - ok
12:52:55.0784 3568 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
12:52:55.0784 3568 AcpiPmi - ok
12:52:55.0784 3568 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys
12:52:55.0784 3568 acpitime - ok
12:52:55.0815 3568 [ 3B42D95D20CD2AACDB0564471AE43ED7 ] ACPIVPC C:\Windows\System32\drivers\AcpiVpc.sys
12:52:55.0815 3568 ACPIVPC - ok
12:52:55.0924 3568 [ C8C6C0D659734FDBF63F6F421A5416BC ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:52:55.0924 3568 AdobeFlashPlayerUpdateSvc - ok
12:52:55.0956 3568 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
12:52:55.0971 3568 adp94xx - ok
12:52:56.0002 3568 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys
12:52:56.0002 3568 adpahci - ok
12:52:56.0018 3568 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
12:52:56.0018 3568 adpu320 - ok
12:52:56.0065 3568 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
12:52:56.0065 3568 AeLookupSvc - ok
12:52:56.0112 3568 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD C:\Windows\system32\drivers\afd.sys
12:52:56.0127 3568 AFD - ok
12:52:56.0143 3568 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys
12:52:56.0143 3568 agp440 - ok
12:52:56.0159 3568 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe
12:52:56.0174 3568 ALG - ok
12:52:56.0190 3568 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
12:52:56.0206 3568 AllUserInstallAgent - ok
12:52:56.0221 3568 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
12:52:56.0221 3568 AmdK8 - ok
12:52:56.0252 3568 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
12:52:56.0252 3568 AmdPPM - ok
12:52:56.0284 3568 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys
12:52:56.0284 3568 amdsata - ok
12:52:56.0315 3568 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
12:52:56.0315 3568 amdsbs - ok
12:52:56.0331 3568 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys
12:52:56.0331 3568 amdxata - ok
12:52:56.0393 3568 [ 548DFB36A6B1A8123BBA4DCFE0BEAD83 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
12:52:56.0393 3568 AntiVirSchedulerService - ok
12:52:56.0424 3568 [ 2FC40C57EECC7C7E400654605E76A0B3 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
12:52:56.0440 3568 AntiVirService - ok
12:52:56.0487 3568 [ 823F34D1DEF120A657BB7529ABF4461F ] AppHostSvc C:\Windows\system32\inetsrv\apphostsvc.dll
12:52:56.0487 3568 AppHostSvc - ok
12:52:56.0518 3568 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys
12:52:56.0518 3568 AppID - ok
12:52:56.0565 3568 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll
12:52:56.0565 3568 AppIDSvc - ok
12:52:56.0581 3568 [ D64C4AFEE8277F35EF729A2B924666B0 ] Appinfo C:\Windows\System32\appinfo.dll
12:52:56.0581 3568 Appinfo - ok
12:52:56.0596 3568 [ 2D14788C5D0836292BEB27BBE109BE56 ] AppMgmt C:\Windows\System32\appmgmts.dll
12:52:56.0612 3568 AppMgmt - ok
12:52:56.0612 3568 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys
12:52:56.0627 3568 arc - ok
12:52:56.0643 3568 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys
12:52:56.0659 3568 arcsas - ok
12:52:56.0737 3568 [ 108FB6DDB69E537A2EA53F425363FAE5 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
12:52:56.0737 3568 aspnet_state - ok
12:52:56.0752 3568 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
12:52:56.0752 3568 AsyncMac - ok
12:52:56.0768 3568 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys
12:52:56.0768 3568 atapi - ok
12:52:56.0799 3568 [ 810ED88782952228AF9C0985FB7D259E ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
12:52:56.0799 3568 AudioEndpointBuilder - ok
12:52:56.0862 3568 [ 25CA8B87479A374919563B3EE7136F32 ] Audiosrv C:\Windows\System32\Audiosrv.dll
12:52:56.0862 3568 Audiosrv - ok
12:52:56.0893 3568 [ 25B63A3C24A5E0223A35DE2F0D9E0FAF ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
12:52:56.0909 3568 avgntflt - ok
12:52:56.0924 3568 [ A83691240C1568E6A3EAA5C86D9F8AE3 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
12:52:56.0924 3568 avipbb - ok
12:52:56.0940 3568 [ CD0E732347BF09717E0BDDC0C66699AB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
12:52:56.0940 3568 avkmgr - ok
12:52:56.0987 3568 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll
12:52:56.0987 3568 AxInstSV - ok
12:52:57.0034 3568 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
12:52:57.0034 3568 b06bdrv - ok
12:52:57.0049 3568 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
12:52:57.0049 3568 BasicDisplay - ok
12:52:57.0081 3568 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
12:52:57.0081 3568 BasicRender - ok
12:52:57.0112 3568 [ BAA00D80B2CFADFFAC8E552D06D4A1A2 ] bcbtums C:\Windows\system32\drivers\bcbtums.sys
12:52:57.0112 3568 bcbtums - ok
12:52:57.0268 3568 [ 2FE2E0EBCDF1EF22A34B44CED1E59893 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl63a.sys
12:52:57.0346 3568 BCM43XX - ok
12:52:57.0440 3568 [ B84DDDB667E1D5957050A458E9EE99C8 ] BcmBtRSupport C:\Windows\system32\BtwRSupportService.exe
12:52:57.0471 3568 BcmBtRSupport - ok
12:52:57.0503 3568 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll
12:52:57.0518 3568 BDESVC - ok
12:52:57.0534 3568 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys
12:52:57.0549 3568 Beep - ok
12:52:57.0581 3568 [ 9E6A544F465C582AB42444A217CF04DC ] BFE C:\Windows\System32\bfe.dll
12:52:57.0596 3568 BFE - ok
12:52:57.0643 3568 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll
12:52:57.0674 3568 BITS - ok
12:52:57.0690 3568 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys
12:52:57.0690 3568 bowser - ok
12:52:57.0721 3568 [ 975398A3D2C1FEA73FC93931978DF354 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
12:52:57.0721 3568 BrokerInfrastructure - ok
12:52:57.0768 3568 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll
12:52:57.0768 3568 Browser - ok
12:52:57.0799 3568 [ 0B2EE8B36081C1039EA3D20B952A8DDC ] bthav C:\Windows\system32\drivers\bthav.sys
12:52:57.0799 3568 bthav - ok
12:52:57.0815 3568 [ F17DEEAC7D51D44CF1BFF8DD4F0A2B6D ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
12:52:57.0831 3568 BthAvrcpTg - ok
12:52:57.0862 3568 [ A8B20D852B07AE19A13B5D47EC4E4C3B ] BthEnum C:\Windows\System32\drivers\BthEnum.sys
12:52:57.0862 3568 BthEnum - ok
12:52:57.0893 3568 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
12:52:57.0909 3568 BthHFEnum - ok
12:52:57.0924 3568 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
12:52:57.0924 3568 bthhfhid - ok
12:52:57.0956 3568 [ 42201C346F0B8C458E1E9CDE04D68A2C ] BthLEEnum C:\Windows\system32\DRIVERS\BthLEEnum.sys
12:52:57.0956 3568 BthLEEnum - ok
12:52:57.0971 3568 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
12:52:57.0987 3568 BTHMODEM - ok
12:52:58.0003 3568 [ 091BB978E9504D0AD14586929431A957 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
12:52:58.0018 3568 BthPan - ok
12:52:58.0065 3568 [ B2FD839F9AF51B8580C02B89AC6C6C89 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
12:52:58.0096 3568 BTHPORT - ok
12:52:58.0128 3568 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll
12:52:58.0128 3568 bthserv - ok
12:52:58.0159 3568 [ 1F715957F5236D30B6020A19A4271F6A ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
12:52:58.0159 3568 BTHUSB - ok
12:52:58.0159 3568 btwampfl - ok
12:52:58.0174 3568 btwaudio - ok
12:52:58.0174 3568 btwavdt - ok
12:52:58.0190 3568 btwl2cap - ok
12:52:58.0206 3568 btwrchid - ok
12:52:58.0237 3568 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
12:52:58.0237 3568 cdfs - ok
12:52:58.0268 3568 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys
12:52:58.0268 3568 cdrom - ok
12:52:58.0315 3568 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll
12:52:58.0315 3568 CertPropSvc - ok
12:52:58.0346 3568 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys
12:52:58.0346 3568 circlass - ok
12:52:58.0362 3568 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys
12:52:58.0378 3568 CLFS - ok
12:52:58.0409 3568 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
12:52:58.0409 3568 CmBatt - ok
12:52:58.0456 3568 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys
12:52:58.0456 3568 CNG - ok
12:52:58.0518 3568 [ 1F925AA990A6A446E8BA926B2D0A5201 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys
12:52:58.0549 3568 CnxtHdAudService - ok
12:52:58.0565 3568 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
12:52:58.0565 3568 CompositeBus - ok
12:52:58.0565 3568 COMSysApp - ok
12:52:58.0581 3568 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys
12:52:58.0581 3568 condrv - ok
12:52:58.0737 3568 [ 815F3180B5117E42E422188E9CCC89C6 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
12:52:58.0737 3568 cphs - ok
12:52:58.0768 3568 [ F0E78B119D12BA81F163D48C0FF30B9A ] CryptSvc C:\Windows\system32\cryptsvc.dll
12:52:58.0768 3568 CryptSvc - ok
12:52:58.0815 3568 [ F2C69C3D98249DE14D4B2832516D4FD5 ] CSC C:\Windows\system32\drivers\csc.sys
12:52:58.0831 3568 CSC - ok
12:52:58.0878 3568 [ 22CCB6AFF617AAC6121DF6CDA5ABF3F4 ] CscService C:\Windows\System32\cscsvc.dll
12:52:58.0909 3568 CscService - ok
12:52:58.0956 3568 [ 48AED45DF009081AF3F5144F7D624674 ] CxAudMsg C:\Windows\system32\CxAudMsg64.exe
12:52:58.0956 3568 CxAudMsg - ok
12:52:58.0987 3568 [ C4D01BD86D6B207275FC143EEA951D75 ] dam C:\Windows\system32\drivers\dam.sys
12:52:58.0987 3568 dam - ok
12:52:59.0034 3568 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll
12:52:59.0049 3568 DcomLaunch - ok
12:52:59.0096 3568 [ C8650D1F61149AA546BDBC99172EBBC1 ] DEFRAGSVC C:\Windows\System32\defragsvc.dll
12:52:59.0096 3568 DEFRAGSVC - ok
12:52:59.0128 3568 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
12:52:59.0128 3568 DeviceAssociationService - ok
12:52:59.0159 3568 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
12:52:59.0174 3568 DeviceInstall - ok
12:52:59.0206 3568 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
12:52:59.0206 3568 Dfsc - ok
12:52:59.0237 3568 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll
12:52:59.0253 3568 Dhcp - ok
12:52:59.0268 3568 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys
12:52:59.0268 3568 discache - ok
12:52:59.0284 3568 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\Windows\system32\drivers\disk.sys
12:52:59.0299 3568 disk - ok
12:52:59.0315 3568 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
12:52:59.0315 3568 dmvsc - ok
12:52:59.0346 3568 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll
12:52:59.0362 3568 Dnscache - ok
12:52:59.0393 3568 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll
12:52:59.0409 3568 dot3svc - ok
12:52:59.0440 3568 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll
12:52:59.0440 3568 DPS - ok
12:52:59.0471 3568 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
12:52:59.0471 3568 drmkaud - ok
12:52:59.0487 3568 [ BF48F32EE248C3D371DA5DC93BBEADA7 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
12:52:59.0487 3568 DsmSvc - ok
12:52:59.0549 3568 [ ED120AA770A78B5079F8C7BB5AF8A035 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
12:52:59.0581 3568 DXGKrnl - ok
12:52:59.0612 3568 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll
12:52:59.0612 3568 Eaphost - ok
12:52:59.0721 3568 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys
12:52:59.0768 3568 ebdrv - ok
12:52:59.0799 3568 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe
12:52:59.0799 3568 EFS - ok
12:52:59.0815 3568 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
12:52:59.0815 3568 EhStorClass - ok
12:52:59.0846 3568 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
12:52:59.0846 3568 EhStorTcgDrv - ok
12:52:59.0878 3568 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys
12:52:59.0878 3568 ErrDev - ok
12:52:59.0909 3568 [ 37D255ED3F10F27C1C79E3378178F0B9 ] ETD C:\Windows\system32\DRIVERS\ETD.sys
12:52:59.0924 3568 ETD - ok
12:52:59.0971 3568 [ DA8B66ECC36FE257D0683FBFF0AF272F ] ETDService C:\Program Files\Elantech\ETDService.exe
12:52:59.0971 3568 ETDService - ok
12:53:00.0018 3568 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll
12:53:00.0034 3568 EventSystem - ok
12:53:00.0112 3568 [ 933723A47E9B7B22208F79F0F40A249A ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
12:53:00.0128 3568 EvtEng - ok
12:53:00.0159 3568 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys
12:53:00.0159 3568 exfat - ok
12:53:00.0190 3568 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys
12:53:00.0190 3568 fastfat - ok
12:53:00.0237 3568 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe
12:53:00.0237 3568 Fax - ok
12:53:00.0268 3568 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys
12:53:00.0268 3568 fdc - ok
12:53:00.0284 3568 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll
12:53:00.0284 3568 fdPHost - ok
12:53:00.0299 3568 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll
12:53:00.0299 3568 FDResPub - ok
12:53:00.0331 3568 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll
12:53:00.0346 3568 fhsvc - ok
12:53:00.0362 3568 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
12:53:00.0362 3568 FileInfo - ok
12:53:00.0393 3568 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
12:53:00.0393 3568 Filetrace - ok
12:53:00.0409 3568 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
12:53:00.0409 3568 flpydisk - ok
12:53:00.0440 3568 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
12:53:00.0440 3568 FltMgr - ok
12:53:00.0503 3568 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll
12:53:00.0534 3568 FontCache - ok
12:53:00.0612 3568 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:53:00.0612 3568 FontCache3.0.0.0 - ok
12:53:00.0628 3568 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
12:53:00.0643 3568 FsDepends - ok
12:53:00.0659 3568 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
12:53:00.0659 3568 Fs_Rec - ok
12:53:00.0690 3568 [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
12:53:00.0706 3568 fvevol - ok
12:53:00.0721 3568 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
12:53:00.0721 3568 FxPPM - ok
12:53:00.0737 3568 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
12:53:00.0737 3568 gagp30kx - ok
12:53:00.0768 3568 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
12:53:00.0784 3568 gencounter - ok
12:53:00.0800 3568 [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
12:53:00.0800 3568 GPIOClx0101 - ok
12:53:00.0878 3568 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll
12:53:00.0940 3568 gpsvc - ok
12:53:00.0971 3568 [ B9893A68032A6D9ADDB5B98287C630F7 ] grmnusb C:\Windows\system32\drivers\grmnusb.sys
12:53:00.0971 3568 grmnusb - ok
12:53:01.0034 3568 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:53:01.0034 3568 gupdate - ok
12:53:01.0050 3568 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:53:01.0050 3568 gupdatem - ok
12:53:01.0081 3568 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
12:53:01.0081 3568 gusvc - ok
12:53:01.0128 3568 [ C2504AA983B5D411F7D31402E8B57725 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:53:01.0128 3568 HdAudAddService - ok
12:53:01.0159 3568 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
12:53:01.0159 3568 HDAudBus - ok
12:53:01.0190 3568 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
12:53:01.0190 3568 HidBatt - ok
12:53:01.0206 3568 [ A25BAE8C1F2830C8E5625EC7E4E968BE ] HidBth C:\Windows\System32\drivers\hidbth.sys
12:53:01.0206 3568 HidBth - ok
12:53:01.0253 3568 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
12:53:01.0253 3568 hidi2c - ok
12:53:01.0268 3568 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys
12:53:01.0268 3568 HidIr - ok
12:53:01.0300 3568 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\system32\hidserv.dll
12:53:01.0300 3568 hidserv - ok
12:53:01.0315 3568 [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
12:53:01.0315 3568 HidUsb - ok
12:53:01.0347 3568 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll
12:53:01.0347 3568 hkmsvc - ok
12:53:01.0378 3568 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
12:53:01.0393 3568 HomeGroupListener - ok
12:53:01.0440 3568 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
12:53:01.0440 3568 HomeGroupProvider - ok
12:53:01.0472 3568 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
12:53:01.0472 3568 HpSAMD - ok
12:53:01.0518 3568 [ 29CB98187BB5711F7759540976D295FC ] HTTP C:\Windows\system32\drivers\HTTP.sys
12:53:01.0534 3568 HTTP - ok
12:53:01.0565 3568 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
12:53:01.0565 3568 hwpolicy - ok
12:53:01.0581 3568 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
12:53:01.0581 3568 hyperkbd - ok
12:53:01.0597 3568 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
12:53:01.0597 3568 HyperVideo - ok
12:53:01.0612 3568 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
12:53:01.0612 3568 i8042prt - ok
12:53:01.0659 3568 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
12:53:01.0659 3568 iaStorV - ok
12:53:01.0831 3568 [ 348214F96642FD4FEF630DE021BA3540 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
12:53:01.0894 3568 igfx - ok
12:53:01.0925 3568 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys
12:53:01.0925 3568 iirsp - ok
12:53:01.0972 3568 [ 531B5A98145DA689741A0AC18F14EA94 ] IKEEXT C:\Windows\System32\ikeext.dll
12:53:01.0987 3568 IKEEXT - ok
12:53:02.0019 3568 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys
12:53:02.0019 3568 intelide - ok
12:53:02.0050 3568 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys
12:53:02.0050 3568 intelppm - ok
12:53:02.0066 3568 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:53:02.0066 3568 IpFilterDriver - ok
12:53:02.0128 3568 [ C217B8D2E58C57A319B16125C3D4B69C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
12:53:02.0159 3568 iphlpsvc - ok
12:53:02.0175 3568 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
12:53:02.0175 3568 IPMIDRV - ok
12:53:02.0190 3568 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
12:53:02.0190 3568 IPNAT - ok
12:53:02.0206 3568 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys
12:53:02.0206 3568 IRENUM - ok
12:53:02.0222 3568 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
12:53:02.0222 3568 isapnp - ok
12:53:02.0253 3568 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
12:53:02.0269 3568 iScsiPrt - ok
12:53:02.0284 3568 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
12:53:02.0284 3568 kbdclass - ok
12:53:02.0300 3568 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
12:53:02.0300 3568 kbdhid - ok
12:53:02.0316 3568 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
12:53:02.0316 3568 kdnic - ok
12:53:02.0331 3568 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe
12:53:02.0331 3568 KeyIso - ok
12:53:02.0378 3568 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
12:53:02.0378 3568 KSecDD - ok
12:53:02.0409 3568 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
12:53:02.0409 3568 KSecPkg - ok
12:53:02.0425 3568 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
12:53:02.0425 3568 ksthunk - ok
12:53:02.0472 3568 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll
12:53:02.0487 3568 KtmRm - ok
12:53:02.0519 3568 [ 8412D334F6B18F655BFF430E9DB1ABC6 ] L1C C:\Windows\system32\DRIVERS\L1C63x64.sys
12:53:02.0519 3568 L1C - ok
12:53:02.0566 3568 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\system32\srvsvc.dll
12:53:02.0566 3568 LanmanServer - ok
12:53:02.0597 3568 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:53:02.0612 3568 LanmanWorkstation - ok
12:53:02.0644 3568 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\Windows\system32\DRIVERS\LhdX64.sys
12:53:02.0644 3568 LHDmgr - ok
12:53:02.0675 3568 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
12:53:02.0675 3568 lltdio - ok
12:53:02.0706 3568 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll
12:53:02.0722 3568 lltdsvc - ok
12:53:02.0737 3568 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll
12:53:02.0737 3568 lmhosts - ok
12:53:02.0753 3568 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
12:53:02.0769 3568 LSI_SAS - ok
12:53:02.0769 3568 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
12:53:02.0769 3568 LSI_SAS2 - ok
12:53:02.0784 3568 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
12:53:02.0784 3568 LSI_SCSI - ok
12:53:02.0800 3568 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
12:53:02.0800 3568 LSI_SSS - ok
12:53:02.0847 3568 [ A57BA284F5996FFD32DCDBC41A4657DB ] LSM C:\Windows\System32\lsm.dll
12:53:02.0862 3568 LSM - ok
12:53:02.0894 3568 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys
12:53:02.0894 3568 luafv - ok
12:53:02.0925 3568 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
12:53:02.0941 3568 MBAMProtector - ok
12:53:02.0987 3568 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
12:53:02.0987 3568 MBAMScheduler - ok
12:53:03.0019 3568 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
12:53:03.0034 3568 MBAMService - ok
12:53:03.0050 3568 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys
12:53:03.0050 3568 megasas - ok
12:53:03.0066 3568 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
12:53:03.0081 3568 MegaSR - ok
12:53:03.0112 3568 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\Windows\System32\drivers\HECIx64.sys
12:53:03.0112 3568 MEIx64 - ok
12:53:03.0175 3568 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
12:53:03.0175 3568 Microsoft Office Groove Audit Service - ok
12:53:03.0191 3568 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
12:53:03.0206 3568 MMCSS - ok
12:53:03.0238 3568 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
12:53:03.0238 3568 Modem - ok
12:53:03.0253 3568 [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
12:53:03.0253 3568 monitor - ok
12:53:03.0269 3568 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
12:53:03.0269 3568 mouclass - ok
12:53:03.0284 3568 [ CB2527B8B87D83E56FBF3944BBB6F606 ] mouhid C:\Windows\System32\drivers\mouhid.sys
12:53:03.0284 3568 mouhid - ok
12:53:03.0300 3568 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
12:53:03.0300 3568 mountmgr - ok
12:53:03.0331 3568 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
12:53:03.0331 3568 mpsdrv - ok
Naposledy upravil(a) betisa dne 20 úno 2014 13:05, celkem upraveno 1 x.
MB-GIGABYTE; CPU-INTEL CORE i5; CHLADIČ-COOLER MASTER;
GPU-ASUS GTX660; RAM-KINGSTON 2x4 GB DDR3-1333MHz; SYSTÉM SSD- CRUCIAL 232GB + HDD-SEAGATE 320GB; PSU-SEASONIC G-550;

Uživatelský avatar
betisa
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod betisa » 20 úno 2014 13:02

12:53:03.0378 3568 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll
12:53:03.0394 3568 MpsSvc - ok
12:53:03.0441 3568 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
12:53:03.0441 3568 MRxDAV - ok
12:53:03.0472 3568 [ 93179D48066918323628CB016D8C94DC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
12:53:03.0488 3568 mrxsmb - ok
12:53:03.0519 3568 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:53:03.0519 3568 mrxsmb10 - ok
12:53:03.0550 3568 [ 5C7DD2E5759FFCCD2C7341C1B90F2B26 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:53:03.0550 3568 mrxsmb20 - ok
12:53:03.0581 3568 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
12:53:03.0581 3568 MsBridge - ok
12:53:03.0628 3568 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe
12:53:03.0628 3568 MSDTC - ok
12:53:03.0659 3568 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
12:53:03.0659 3568 Msfs - ok
12:53:03.0675 3568 [ C32A7A39B960A42BA9D4FBE47213CA03 ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
12:53:03.0691 3568 msgpiowin32 - ok
12:53:03.0706 3568 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
12:53:03.0706 3568 mshidkmdf - ok
12:53:03.0722 3568 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
12:53:03.0722 3568 mshidumdf - ok
12:53:03.0753 3568 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
12:53:03.0753 3568 msisadrv - ok
12:53:03.0800 3568 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
12:53:03.0800 3568 MSiSCSI - ok
12:53:03.0816 3568 msiserver - ok
12:53:03.0816 3568 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
12:53:03.0831 3568 MSKSSRV - ok
12:53:03.0847 3568 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
12:53:03.0847 3568 MsLldp - ok
12:53:03.0863 3568 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
12:53:03.0863 3568 MSPCLOCK - ok
12:53:03.0863 3568 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
12:53:03.0863 3568 MSPQM - ok
12:53:03.0894 3568 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
12:53:03.0909 3568 MsRPC - ok
12:53:03.0925 3568 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
12:53:03.0925 3568 mssmbios - ok
12:53:03.0941 3568 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
12:53:03.0941 3568 MSTEE - ok
12:53:03.0956 3568 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
12:53:03.0956 3568 MTConfig - ok
12:53:03.0972 3568 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
12:53:03.0972 3568 Mup - ok
12:53:04.0003 3568 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
12:53:04.0003 3568 mvumis - ok
12:53:04.0034 3568 [ D8C1FE237762249C879760E7F3ABFC1F ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
12:53:04.0034 3568 MyWiFiDHCPDNS - ok
12:53:04.0081 3568 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
12:53:04.0113 3568 napagent - ok
12:53:04.0144 3568 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
12:53:04.0159 3568 NativeWifiP - ok
12:53:04.0191 3568 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
12:53:04.0191 3568 NcaSvc - ok
12:53:04.0206 3568 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
12:53:04.0222 3568 NcdAutoSetup - ok
12:53:04.0269 3568 [ 03CFE4108D1DE16D6C59455B5C73319C ] NDIS C:\Windows\system32\drivers\ndis.sys
12:53:04.0284 3568 NDIS - ok
12:53:04.0300 3568 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
12:53:04.0300 3568 NdisCap - ok
12:53:04.0331 3568 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
12:53:04.0347 3568 NdisImPlatform - ok
12:53:04.0378 3568 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
12:53:04.0378 3568 NdisTapi - ok
12:53:04.0394 3568 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
12:53:04.0394 3568 Ndisuio - ok
12:53:04.0425 3568 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
12:53:04.0425 3568 NdisWan - ok
12:53:04.0456 3568 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
12:53:04.0456 3568 NDISWANLEGACY - ok
12:53:04.0472 3568 [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
12:53:04.0472 3568 NDProxy - ok
12:53:04.0488 3568 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
12:53:04.0488 3568 Ndu - ok
12:53:04.0503 3568 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
12:53:04.0503 3568 NetBIOS - ok
12:53:04.0534 3568 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
12:53:04.0534 3568 NetBT - ok
12:53:04.0550 3568 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
12:53:04.0550 3568 Netlogon - ok
12:53:04.0581 3568 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
12:53:04.0597 3568 Netman - ok
12:53:04.0644 3568 [ AABC045A313259EBE5D1BB88383859D6 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:53:04.0644 3568 NetMsmqActivator - ok
12:53:04.0659 3568 [ AABC045A313259EBE5D1BB88383859D6 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:53:04.0659 3568 NetPipeActivator - ok
12:53:04.0691 3568 [ 5FF52E13C72838D87DAF228EC9E92C89 ] netprofm C:\Windows\System32\netprofmsvc.dll
12:53:04.0722 3568 netprofm - ok
12:53:04.0769 3568 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:53:04.0784 3568 NetTcpActivator - ok
12:53:04.0784 3568 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:53:04.0784 3568 NetTcpPortSharing - ok
12:53:04.0816 3568 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
12:53:04.0816 3568 nfrd960 - ok
12:53:04.0847 3568 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
12:53:04.0863 3568 NlaSvc - ok
12:53:04.0894 3568 [ 907B5E1E4A592E5EDC5E4CCBDE4863C2 ] nmwcd C:\Windows\system32\drivers\ccdcmbx64.sys
12:53:04.0894 3568 nmwcd - ok
12:53:04.0925 3568 [ 41C1AC1F3613435EB32D67BCB80A5FA5 ] nmwcdc C:\Windows\system32\drivers\ccdcmbox64.sys
12:53:04.0925 3568 nmwcdc - ok
12:53:04.0941 3568 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
12:53:04.0941 3568 Npfs - ok
12:53:04.0956 3568 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
12:53:04.0956 3568 npsvctrig - ok
12:53:04.0988 3568 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
12:53:04.0988 3568 nsi - ok
12:53:05.0019 3568 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
12:53:05.0019 3568 nsiproxy - ok
12:53:05.0097 3568 [ 76929F4A69E425911A63B407E26C2589 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
12:53:05.0128 3568 Ntfs - ok
12:53:05.0144 3568 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
12:53:05.0144 3568 Null - ok
12:53:05.0535 3568 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
12:53:05.0738 3568 nvlddmkm - ok
12:53:05.0753 3568 [ 918841B2454F4F2BD94479692079490B ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
12:53:05.0769 3568 nvpciflt - ok
12:53:05.0785 3568 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
12:53:05.0800 3568 nvraid - ok
12:53:05.0831 3568 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
12:53:05.0831 3568 nvstor - ok
12:53:05.0878 3568 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe
12:53:05.0894 3568 nvsvc - ok
12:53:05.0972 3568 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
12:53:05.0988 3568 nvUpdatusService - ok
12:53:06.0003 3568 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
12:53:06.0019 3568 nv_agp - ok
12:53:06.0097 3568 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
12:53:06.0113 3568 odserv - ok
12:53:06.0144 3568 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:53:06.0144 3568 ose - ok
12:53:06.0191 3568 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
12:53:06.0206 3568 p2pimsvc - ok
12:53:06.0238 3568 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
12:53:06.0269 3568 p2psvc - ok
12:53:06.0300 3568 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
12:53:06.0300 3568 Parport - ok
12:53:06.0332 3568 [ D6ACCF9F2EEEEA711C14EFD976E573F3 ] partmgr C:\Windows\system32\drivers\partmgr.sys
12:53:06.0332 3568 partmgr - ok
12:53:06.0363 3568 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
12:53:06.0378 3568 PcaSvc - ok
12:53:06.0410 3568 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
12:53:06.0410 3568 pci - ok
12:53:06.0425 3568 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
12:53:06.0425 3568 pciide - ok
12:53:06.0457 3568 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
12:53:06.0457 3568 pcmcia - ok
12:53:06.0472 3568 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
12:53:06.0472 3568 pcw - ok
12:53:06.0503 3568 [ AECC24430301DBC6A76916E3029B6B83 ] pdc C:\Windows\system32\drivers\pdc.sys
12:53:06.0503 3568 pdc - ok
12:53:06.0535 3568 [ 70DBB6A8B52B3830922F1C5789E1BEEB ] PEAUTH C:\Windows\system32\drivers\peauth.sys
12:53:06.0550 3568 PEAUTH - ok
12:53:06.0660 3568 [ DF0D9BDCB600913F40FF125BF8CE1979 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
12:53:06.0738 3568 PeerDistSvc - ok
12:53:06.0816 3568 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
12:53:06.0832 3568 PerfHost - ok
12:53:06.0894 3568 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
12:53:06.0941 3568 pla - ok
12:53:06.0972 3568 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
12:53:06.0972 3568 PlugPlay - ok
12:53:06.0988 3568 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
12:53:07.0004 3568 PNRPAutoReg - ok
12:53:07.0019 3568 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
12:53:07.0035 3568 PNRPsvc - ok
12:53:07.0082 3568 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
12:53:07.0097 3568 PolicyAgent - ok
12:53:07.0129 3568 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
12:53:07.0129 3568 Power - ok
12:53:07.0160 3568 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
12:53:07.0160 3568 PptpMiniport - ok
12:53:07.0285 3568 [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
12:53:07.0363 3568 PrintNotify - ok
12:53:07.0410 3568 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
12:53:07.0410 3568 Processor - ok
12:53:07.0457 3568 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
12:53:07.0457 3568 ProfSvc - ok
12:53:07.0488 3568 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
12:53:07.0488 3568 Psched - ok
12:53:07.0535 3568 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
12:53:07.0550 3568 QWAVE - ok
12:53:07.0566 3568 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
12:53:07.0566 3568 QWAVEdrv - ok
12:53:07.0582 3568 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
12:53:07.0582 3568 RasAcd - ok
12:53:07.0629 3568 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
12:53:07.0629 3568 RasAgileVpn - ok
12:53:07.0660 3568 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
12:53:07.0660 3568 RasAuto - ok
12:53:07.0675 3568 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
12:53:07.0691 3568 Rasl2tp - ok
12:53:07.0722 3568 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
12:53:07.0738 3568 RasMan - ok
12:53:07.0754 3568 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
12:53:07.0754 3568 RasPppoe - ok
12:53:07.0785 3568 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
12:53:07.0785 3568 RasSstp - ok
12:53:07.0816 3568 [ B72C33DBD5326B3864CF2091AF8B906B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
12:53:07.0816 3568 rdbss - ok
12:53:07.0847 3568 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
12:53:07.0847 3568 rdpbus - ok
12:53:07.0863 3568 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
12:53:07.0863 3568 RDPDR - ok
12:53:07.0894 3568 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
12:53:07.0894 3568 RdpVideoMiniport - ok
12:53:07.0910 3568 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
12:53:07.0910 3568 RDPWD - ok
12:53:07.0925 3568 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
12:53:07.0925 3568 rdyboost - ok
12:53:08.0004 3568 [ 695C4AC7D0B5002040C7540364C43940 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
12:53:08.0004 3568 RegSrvc - ok
12:53:08.0035 3568 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
12:53:08.0035 3568 RemoteAccess - ok
12:53:08.0082 3568 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
12:53:08.0082 3568 RemoteRegistry - ok
12:53:08.0129 3568 [ 17EF582CBC4809F96B9E6D0543480763 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
12:53:08.0129 3568 RFCOMM - ok
12:53:08.0160 3568 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
12:53:08.0160 3568 RpcEptMapper - ok
12:53:08.0191 3568 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
12:53:08.0191 3568 RpcLocator - ok
12:53:08.0222 3568 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
12:53:08.0238 3568 RpcSs - ok
12:53:08.0269 3568 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
12:53:08.0269 3568 rspndr - ok
12:53:08.0301 3568 [ 301FBA4594FB5C0A469299A65106B4AA ] s1018bus C:\Windows\System32\drivers\s1018bus.sys
12:53:08.0301 3568 s1018bus - ok
12:53:08.0332 3568 [ D1D7C744F79710357E60FC04D125ED01 ] s1018mdfl C:\Windows\system32\DRIVERS\s1018mdfl.sys
12:53:08.0332 3568 s1018mdfl - ok
12:53:08.0347 3568 [ 7DBE12CCCD837D4266B2DDD80A329C09 ] s1018mdm C:\Windows\system32\DRIVERS\s1018mdm.sys
12:53:08.0347 3568 s1018mdm - ok
12:53:08.0379 3568 [ 065FF5E62D2D18A6D93FD925546CD549 ] s1018mgmt C:\Windows\system32\DRIVERS\s1018mgmt.sys
12:53:08.0394 3568 s1018mgmt - ok
12:53:08.0410 3568 [ 5101D815BDF0D667E3D5F0EA727CAAEE ] s1018nd5 C:\Windows\system32\DRIVERS\s1018nd5.sys
12:53:08.0410 3568 s1018nd5 - ok
12:53:08.0426 3568 [ 13F220C65B444AC9BDA49DACFC3230BB ] s1018obex C:\Windows\system32\DRIVERS\s1018obex.sys
12:53:08.0426 3568 s1018obex - ok
12:53:08.0457 3568 [ CE7D8BCE80211D8A35F6BD7A87791860 ] s1018unic C:\Windows\System32\drivers\s1018unic.sys
12:53:08.0457 3568 s1018unic - ok
12:53:08.0504 3568 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
12:53:08.0504 3568 s3cap - ok
12:53:08.0519 3568 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
12:53:08.0519 3568 SamSs - ok
12:53:08.0551 3568 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
12:53:08.0551 3568 sbp2port - ok
12:53:08.0582 3568 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
12:53:08.0598 3568 SCardSvr - ok
12:53:08.0613 3568 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
12:53:08.0613 3568 scfilter - ok
12:53:08.0660 3568 [ EDCDF4DB82EF825B94B190D544C8C58B ] Schedule C:\Windows\system32\schedsvc.dll
12:53:08.0707 3568 Schedule - ok
12:53:08.0738 3568 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
12:53:08.0754 3568 SCPolicySvc - ok
12:53:08.0785 3568 [ 12F06525912BBEF67837DE47D87C60A9 ] sdbus C:\Windows\System32\drivers\sdbus.sys
12:53:08.0785 3568 sdbus - ok
12:53:08.0832 3568 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
12:53:08.0832 3568 SDRSVC - ok
12:53:08.0863 3568 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
12:53:08.0863 3568 sdstor - ok
12:53:08.0894 3568 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
12:53:08.0894 3568 secdrv - ok
12:53:08.0910 3568 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
12:53:08.0910 3568 seclogon - ok
12:53:08.0941 3568 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll
12:53:08.0941 3568 SENS - ok
12:53:08.0973 3568 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
12:53:08.0988 3568 SensrSvc - ok
12:53:09.0004 3568 [ 8167B3DF18CF957BB87F328F131D5570 ] Ser2pl C:\Windows\system32\DRIVERS\ser2pl64.sys
12:53:09.0004 3568 Ser2pl - ok
12:53:09.0051 3568 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
12:53:09.0051 3568 SerCx - ok
12:53:09.0066 3568 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
12:53:09.0066 3568 Serenum - ok
12:53:09.0098 3568 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
12:53:09.0098 3568 Serial - ok
12:53:09.0113 3568 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
12:53:09.0113 3568 sermouse - ok
12:53:09.0176 3568 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
12:53:09.0191 3568 SessionEnv - ok
12:53:09.0223 3568 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
12:53:09.0223 3568 sfloppy - ok
12:53:09.0254 3568 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
12:53:09.0285 3568 SharedAccess - ok
12:53:09.0332 3568 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:53:09.0348 3568 ShellHWDetection - ok
12:53:09.0379 3568 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
12:53:09.0379 3568 SiSRaid2 - ok
12:53:09.0394 3568 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
12:53:09.0394 3568 SiSRaid4 - ok
12:53:09.0441 3568 [ F5BBEDF602C310B00036EB2DBF4348A5 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
12:53:09.0441 3568 SkypeUpdate - ok
12:53:09.0473 3568 [ E2411CB89F0EC5E4D18AED0397AB07DD ] slsvc C:\Windows\slsvc.exe
12:53:09.0473 3568 slsvc - ok
12:53:09.0519 3568 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
12:53:09.0519 3568 SNMPTRAP - ok
12:53:09.0551 3568 [ 465F3C355CE5ED2779B8F460F14C5A78 ] spaceport C:\Windows\system32\drivers\spaceport.sys
12:53:09.0551 3568 spaceport - ok
12:53:09.0566 3568 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
12:53:09.0566 3568 SpbCx - ok
12:53:09.0613 3568 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
12:53:09.0629 3568 Spooler - ok
12:53:09.0785 3568 [ EC84D961501054F87A6878EC5D53388F ] sppsvc C:\Windows\system32\sppsvc.exe
12:53:09.0863 3568 sppsvc - ok
12:53:09.0863 3568 sptd - ok
12:53:09.0895 3568 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\Windows\system32\DRIVERS\srv.sys
12:53:09.0910 3568 srv - ok
12:53:09.0957 3568 [ 9912FDF63EC78E1977083E20DEAE4889 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
12:53:09.0973 3568 srv2 - ok
12:53:10.0004 3568 [ FD8B4F201B681C555A4AF41922C52557 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
12:53:10.0004 3568 srvnet - ok
12:53:10.0051 3568 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
12:53:10.0051 3568 SSDPSRV - ok
12:53:10.0082 3568 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\Windows\system32\sstpsvc.dll
12:53:10.0082 3568 SstpSvc - ok
12:53:10.0098 3568 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\Windows\system32\drivers\stexstor.sys
12:53:10.0098 3568 stexstor - ok
12:53:10.0145 3568 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\Windows\System32\wiaservc.dll
12:53:10.0176 3568 stisvc - ok
12:53:10.0207 3568 [ C588BBD37B432CE3204E5765B459E6B2 ] storahci C:\Windows\system32\drivers\storahci.sys
12:53:10.0207 3568 storahci - ok
12:53:10.0223 3568 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
12:53:10.0223 3568 storflt - ok
12:53:10.0270 3568 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\Windows\system32\storsvc.dll
12:53:10.0270 3568 StorSvc - ok
12:53:10.0285 3568 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\Windows\system32\drivers\storvsc.sys
12:53:10.0285 3568 storvsc - ok
12:53:10.0301 3568 [ 1A36AC469140F87CDE62D7F8524E270C ] storvsp C:\Windows\System32\drivers\storvsp.sys
12:53:10.0301 3568 storvsp - ok
12:53:10.0316 3568 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\Windows\system32\svsvc.dll
12:53:10.0332 3568 svsvc - ok
12:53:10.0348 3568 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\Windows\System32\drivers\swenum.sys
12:53:10.0348 3568 swenum - ok
12:53:10.0379 3568 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\Windows\System32\swprv.dll
12:53:10.0410 3568 swprv - ok
12:53:10.0457 3568 [ DC21E1F06343773D7E24362DCEF7944B ] SysMain C:\Windows\system32\sysmain.dll
12:53:10.0520 3568 SysMain - ok
12:53:10.0551 3568 [ E219BF7BCCFE4881B0C053C7E0B47ECC ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
12:53:10.0551 3568 SystemEventsBroker - ok
12:53:10.0566 3568 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll
12:53:10.0582 3568 TabletInputService - ok
12:53:10.0598 3568 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\Windows\System32\tapisrv.dll
12:53:10.0613 3568 TapiSrv - ok
12:53:10.0707 3568 [ F4F78B7F39BD56BD0BFE4C4399398F6F ] Tcpip C:\Windows\system32\drivers\tcpip.sys
12:53:10.0738 3568 Tcpip - ok
12:53:10.0816 3568 [ F4F78B7F39BD56BD0BFE4C4399398F6F ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
12:53:10.0848 3568 TCPIP6 - ok
12:53:10.0879 3568 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
12:53:10.0879 3568 tcpipreg - ok
12:53:10.0910 3568 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
12:53:10.0910 3568 tdx - ok
12:53:11.0098 3568 [ F67C21CC4195F6AFC447418FE163E156 ] TeamViewer8 C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
12:53:11.0176 3568 TeamViewer8 - ok
12:53:11.0191 3568 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\Windows\System32\drivers\terminpt.sys
12:53:11.0191 3568 terminpt - ok
12:53:11.0254 3568 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\Windows\System32\termsrv.dll
12:53:11.0285 3568 TermService - ok
12:53:11.0301 3568 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\Windows\system32\themeservice.dll
12:53:11.0316 3568 Themes - ok
12:53:11.0332 3568 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\Windows\system32\mmcss.dll
12:53:11.0332 3568 THREADORDER - ok
12:53:11.0379 3568 [ FF4135424A79DCC2998276D8E39C9B4D ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll
12:53:11.0379 3568 TimeBroker - ok
12:53:11.0410 3568 [ B44EFE254C0B3719E4037088D24FE4B5 ] TPM C:\Windows\system32\drivers\tpm.sys
12:53:11.0410 3568 TPM - ok
12:53:11.0441 3568 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\Windows\System32\trkwks.dll
12:53:11.0457 3568 TrkWks - ok
12:53:11.0504 3568 [ 8D516AEF3C1DF980664CF17BB1FF6093 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:53:11.0504 3568 TrustedInstaller - ok
12:53:11.0551 3568 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
12:53:11.0551 3568 TsUsbFlt - ok
12:53:11.0566 3568 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
12:53:11.0566 3568 TsUsbGD - ok
12:53:11.0598 3568 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
12:53:11.0598 3568 tunnel - ok
12:53:11.0613 3568 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\Windows\system32\drivers\uagp35.sys
12:53:11.0629 3568 uagp35 - ok
12:53:11.0629 3568 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
12:53:11.0629 3568 UASPStor - ok
12:53:11.0660 3568 [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys
12:53:11.0676 3568 UCX01000 - ok
12:53:11.0707 3568 [ DC5A461591C71AF7F19DC048A81E3F88 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
12:53:11.0707 3568 udfs - ok
12:53:11.0738 3568 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\Windows\system32\UI0Detect.exe
12:53:11.0754 3568 UI0Detect - ok
12:53:11.0754 3568 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
12:53:11.0754 3568 uliagpkx - ok
12:53:11.0785 3568 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\Windows\System32\drivers\umbus.sys
12:53:11.0785 3568 umbus - ok
12:53:11.0801 3568 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\Windows\System32\drivers\umpass.sys
12:53:11.0801 3568 UmPass - ok
12:53:11.0863 3568 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\Windows\System32\umrdp.dll
12:53:11.0879 3568 UmRdpService - ok
12:53:11.0910 3568 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\Windows\System32\upnphost.dll
12:53:11.0926 3568 upnphost - ok
12:53:11.0957 3568 [ 4E93C8496359E97830C75AC36393654D ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
12:53:11.0957 3568 upperdev - ok
12:53:11.0988 3568 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
12:53:11.0988 3568 usbccgp - ok
12:53:12.0020 3568 [ B395B62B62F28106218FA6FB17F4C797 ] usbcir C:\Windows\System32\drivers\usbcir.sys
12:53:12.0020 3568 usbcir - ok
12:53:12.0051 3568 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci C:\Windows\System32\drivers\usbehci.sys
12:53:12.0051 3568 usbehci - ok
12:53:12.0098 3568 [ ADBF89B8E0BB372FEFE2E4B84E1E20AE ] usbhub C:\Windows\System32\drivers\usbhub.sys
12:53:12.0098 3568 usbhub - ok
12:53:12.0129 3568 [ C5986337DE3BF63ABD9ED4D834D34B89 ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
12:53:12.0129 3568 USBHUB3 - ok
12:53:12.0160 3568 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\Windows\System32\drivers\usbohci.sys
12:53:12.0160 3568 usbohci - ok
12:53:12.0176 3568 [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint C:\Windows\System32\drivers\usbprint.sys
12:53:12.0176 3568 usbprint - ok
12:53:12.0207 3568 [ 72334EC4B3FD4EB270623E32E701B57D ] usbser C:\Windows\system32\drivers\usbser.sys
12:53:12.0207 3568 usbser - ok
12:53:12.0238 3568 [ 8844CB19A37B65E27049D4A7786726A9 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
12:53:12.0238 3568 UsbserFilt - ok
12:53:12.0270 3568 [ F77177F6C95B2116EE7AD23B5EF57007 ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
12:53:12.0270 3568 USBSTOR - ok
12:53:12.0301 3568 [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
12:53:12.0301 3568 usbuhci - ok
12:53:12.0332 3568 [ 09799E701B4327097E9F63D3FE221083 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
12:53:12.0332 3568 usbvideo - ok
12:53:12.0363 3568 [ 9CD4259AD15F84DE27B94A956C978D6C ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
12:53:12.0379 3568 USBXHCI - ok
12:53:12.0395 3568 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\Windows\system32\lsass.exe
12:53:12.0395 3568 VaultSvc - ok
12:53:12.0426 3568 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
12:53:12.0426 3568 vdrvroot - ok
12:53:12.0473 3568 [ 8A8CDA9E3CF2E0B4C6CC19FBC6FB9A71 ] vds C:\Windows\System32\vds.exe
12:53:12.0488 3568 vds - ok
12:53:12.0504 3568 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
12:53:12.0520 3568 VerifierExt - ok
12:53:12.0551 3568 [ 8628FA679F0EC4B709CCD1F6B6A3233B ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
12:53:12.0551 3568 vhdmp - ok
12:53:12.0567 3568 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\Windows\system32\drivers\viaide.sys
12:53:12.0567 3568 viaide - ok
12:53:12.0598 3568 [ 0E43886F01C85B47BA0A3157274BCF59 ] Vid C:\Windows\System32\drivers\Vid.sys
12:53:12.0598 3568 Vid - ok
12:53:12.0645 3568 [ 71B51CF0B12E216D1FA8262B3B8E7DB4 ] vm332avs C:\Windows\System32\Drivers\vm332avs.sys
12:53:12.0660 3568 vm332avs - ok
12:53:12.0692 3568 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\Windows\system32\drivers\vmbus.sys
12:53:12.0692 3568 vmbus - ok
12:53:12.0707 3568 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
12:53:12.0723 3568 VMBusHID - ok
12:53:12.0738 3568 [ B4F432A51826FFC66F4DF72A83E8E4B1 ] vmbusr C:\Windows\System32\drivers\vmbusr.sys
12:53:12.0738 3568 vmbusr - ok
12:53:12.0785 3568 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\Windows\System32\ICSvc.dll
12:53:12.0801 3568 vmicheartbeat - ok
12:53:12.0817 3568 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
12:53:12.0817 3568 vmickvpexchange - ok
12:53:12.0832 3568 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\Windows\System32\ICSvc.dll
12:53:12.0848 3568 vmicrdv - ok
12:53:12.0863 3568 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\Windows\System32\ICSvc.dll
12:53:12.0863 3568 vmicshutdown - ok
12:53:12.0879 3568 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\Windows\System32\ICSvc.dll
12:53:12.0879 3568 vmictimesync - ok
12:53:12.0895 3568 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\Windows\System32\ICSvc.dll
12:53:12.0910 3568 vmicvss - ok
12:53:12.0926 3568 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\Windows\system32\drivers\volmgr.sys
12:53:12.0926 3568 volmgr - ok
12:53:12.0957 3568 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
12:53:12.0957 3568 volmgrx - ok
12:53:12.0988 3568 [ 2FB3CDFD5EAF4CD9D4AFAF96877D13AE ] volsnap C:\Windows\system32\drivers\volsnap.sys
12:53:12.0988 3568 volsnap - ok
12:53:13.0020 3568 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\Windows\System32\drivers\vpci.sys
12:53:13.0020 3568 vpci - ok
12:53:13.0035 3568 [ 0190AFFF28F600461C0164353CC7EE27 ] vpcivsp C:\Windows\System32\drivers\vpcivsp.sys
12:53:13.0051 3568 vpcivsp - ok
12:53:13.0051 3568 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
12:53:13.0067 3568 vsmraid - ok
12:53:13.0129 3568 [ EA658570314042C914964FC72AB50E6B ] VSS C:\Windows\system32\vssvc.exe
12:53:13.0145 3568 VSS - ok
12:53:13.0176 3568 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
12:53:13.0192 3568 VSTXRAID - ok
12:53:13.0207 3568 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
12:53:13.0207 3568 vwifibus - ok
12:53:13.0223 3568 [ 095E943D27025E4D588AF0A72CC2318F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
12:53:13.0223 3568 vwififlt - ok
12:53:13.0238 3568 [ 73FA1A41A97A5C34ADC03B3577FF1A86 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
12:53:13.0238 3568 vwifimp - ok
12:53:13.0270 3568 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\Windows\system32\w32time.dll
12:53:13.0285 3568 W32Time - ok
12:53:13.0348 3568 [ 901CC968412F8155B08D7ABE0171166A ] W3SVC C:\Windows\system32\inetsrv\iisw3adm.dll
12:53:13.0363 3568 W3SVC - ok
12:53:13.0395 3568 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\Windows\System32\drivers\wacompen.sys
12:53:13.0395 3568 WacomPen - ok
12:53:13.0410 3568 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
12:53:13.0410 3568 Wanarp - ok
12:53:13.0426 3568 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
12:53:13.0426 3568 Wanarpv6 - ok
12:53:13.0457 3568 [ 901CC968412F8155B08D7ABE0171166A ] WAS C:\Windows\system32\inetsrv\iisw3adm.dll
12:53:13.0473 3568 WAS - ok
12:53:13.0535 3568 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\Windows\system32\wbengine.exe
12:53:13.0567 3568 wbengine - ok
12:53:13.0613 3568 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
12:53:13.0629 3568 WbioSrvc - ok
12:53:13.0660 3568 [ D9C1E82651BF19C6FF69CEC6FD400124 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
12:53:13.0676 3568 Wcmsvc - ok
12:53:13.0754 3568 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\Windows\System32\wcncsvc.dll
12:53:13.0770 3568 wcncsvc - ok
12:53:13.0785 3568 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:53:13.0801 3568 WcsPlugInService - ok
12:53:13.0817 3568 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\Windows\system32\drivers\wd.sys
12:53:13.0817 3568 Wd - ok
12:53:13.0832 3568 [ 6F4B5DDDC3B86091E94BC47347A78AF7 ] WdBoot C:\Windows\system32\drivers\WdBoot.sys
12:53:13.0832 3568 WdBoot - ok
12:53:13.0879 3568 [ 2ADC985B85A71BD7D99712EC0C24358B ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
12:53:13.0895 3568 Wdf01000 - ok
12:53:13.0910 3568 [ 99D404A9A0AFC4734E014EBEBAC13F8F ] WdFilter C:\Windows\system32\drivers\WdFilter.sys
12:53:13.0910 3568 WdFilter - ok
12:53:13.0942 3568 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\Windows\system32\wdi.dll
12:53:13.0942 3568 WdiServiceHost - ok
12:53:13.0957 3568 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\Windows\system32\wdi.dll
12:53:13.0973 3568 WdiSystemHost - ok
12:53:14.0004 3568 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\Windows\System32\webclnt.dll
12:53:14.0020 3568 WebClient - ok
12:53:14.0035 3568 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\Windows\system32\wecsvc.dll
12:53:14.0051 3568 Wecsvc - ok
12:53:14.0067 3568 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\Windows\System32\wercplsupport.dll
12:53:14.0082 3568 wercplsupport - ok
12:53:14.0113 3568 [ 5F70EBFC1F75B487DE79501E3CCBDB54 ] WerSvc C:\Windows\System32\WerSvc.dll
12:53:14.0113 3568 WerSvc - ok
12:53:14.0160 3568 [ FE762D3498719C3A23471BBA62F747B4 ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys
12:53:14.0160 3568 WFPLWFS - ok
12:53:14.0207 3568 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\Windows\System32\wiarpc.dll
12:53:14.0207 3568 WiaRpc - ok
12:53:14.0223 3568 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
12:53:14.0223 3568 WIMMount - ok
12:53:14.0254 3568 WinDefend - ok
12:53:14.0317 3568 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
12:53:14.0332 3568 WinHttpAutoProxySvc - ok
12:53:14.0395 3568 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
12:53:14.0395 3568 Winmgmt - ok
12:53:14.0520 3568 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\Windows\system32\WsmSvc.dll
12:53:14.0629 3568 WinRM - ok
12:53:14.0676 3568 [ BB20956C424531003F7FA6CD36F11D5D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
12:53:14.0692 3568 WinUsb - ok
12:53:14.0754 3568 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\Windows\System32\wlansvc.dll
12:53:14.0770 3568 WlanSvc - ok
12:53:14.0848 3568 [ B330CE47FB74A6BE9A3FFFF4B3F64D9B ] wlidsvc C:\Windows\system32\wlidsvc.dll
12:53:14.0910 3568 wlidsvc - ok
12:53:14.0942 3568 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
12:53:14.0942 3568 WmiAcpi - ok
12:53:14.0973 3568 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
12:53:14.0989 3568 wmiApSrv - ok
12:53:15.0004 3568 WMPNetworkSvc - ok
12:53:15.0035 3568 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys
12:53:15.0035 3568 wpcfltr - ok
12:53:15.0067 3568 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\Windows\System32\wpcsvc.dll
12:53:15.0082 3568 WPCSvc - ok
12:53:15.0129 3568 [ 39D8AB837F91B729D12D32ED81E2062F ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
12:53:15.0129 3568 WPDBusEnum - ok
12:53:15.0145 3568 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
12:53:15.0145 3568 WpdUpFltr - ok
12:53:15.0176 3568 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
12:53:15.0176 3568 ws2ifsl - ok
12:53:15.0207 3568 [ FB0C1B7F94FA08E72F19F6F2CE7210E1 ] wscsvc C:\Windows\System32\wscsvc.dll
12:53:15.0207 3568 wscsvc - ok
12:53:15.0207 3568 WSearch - ok
12:53:15.0317 3568 [ C10BFFEE7E0D7A1366E84F251796C51D ] WSService C:\Windows\System32\WSService.dll
12:53:15.0395 3568 WSService - ok
12:53:15.0504 3568 [ A8484C0CB54DB48180FB7CA00F1C3F8F ] wuauserv C:\Windows\system32\wuaueng.dll
12:53:15.0551 3568 wuauserv - ok
12:53:15.0582 3568 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
12:53:15.0582 3568 WudfPf - ok
12:53:15.0614 3568 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys
12:53:15.0614 3568 WUDFRd - ok
12:53:15.0645 3568 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
12:53:15.0645 3568 wudfsvc - ok
12:53:15.0660 3568 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
12:53:15.0676 3568 WUDFWpdFs - ok
12:53:15.0692 3568 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdMtp C:\Windows\system32\DRIVERS\WUDFRd.sys
12:53:15.0692 3568 WUDFWpdMtp - ok
12:53:15.0723 3568 [ F9D8D2E6ECE08B278621D5BF3A7240A6 ] WwanSvc C:\Windows\System32\wwansvc.dll
12:53:15.0754 3568 WwanSvc - ok
12:53:15.0848 3568 [ 7055B389BD0DA0B19236BF43CDDF0E1A ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
12:53:15.0864 3568 ZeroConfigService - ok
12:53:15.0910 3568 ================ Scan global ===============================
12:53:15.0957 3568 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
12:53:15.0973 3568 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
12:53:16.0004 3568 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
12:53:16.0051 3568 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
12:53:16.0051 3568 [Global] - ok
12:53:16.0051 3568 ================ Scan MBR ==================================
12:53:16.0067 3568 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:53:16.0379 3568 \Device\Harddisk0\DR0 - ok
12:53:16.0379 3568 [ 762886D57AF4A2788D8AE380281A1F3B ] \Device\Harddisk1\DR1
12:53:23.0225 3568 \Device\Harddisk1\DR1 - ok
12:53:23.0225 3568 ================ Scan VBR ==================================
12:53:23.0288 3568 [ 31C685A2268686EE4AECBC4FAF6A135B ] \Device\Harddisk0\DR0\Partition1
12:53:23.0288 3568 \Device\Harddisk0\DR0\Partition1 - ok
12:53:23.0304 3568 [ A1B97E298736C6B5D8567545F207FFDB ] \Device\Harddisk0\DR0\Partition2
12:53:23.0319 3568 \Device\Harddisk0\DR0\Partition2 - ok
12:53:23.0319 3568 ============================================================
12:53:23.0319 3568 Scan finished
12:53:23.0319 3568 ============================================================
12:53:23.0335 3480 Detected object count: 0
12:53:23.0335 3480 Actual detected object count: 0
12:55:04.0288 1476 Deinitialize success
MB-GIGABYTE; CPU-INTEL CORE i5; CHLADIČ-COOLER MASTER;
GPU-ASUS GTX660; RAM-KINGSTON 2x4 GB DDR3-1333MHz; SYSTÉM SSD- CRUCIAL 232GB + HDD-SEAGATE 320GB; PSU-SEASONIC G-550;

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod Orcus » 21 úno 2014 07:09

V Rogukilleru se nic neodstranilo, takže ještě jednou, jak psal jaro3.

Poté vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
betisa
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod betisa » 22 úno 2014 17:28

ComboFix 14-02-20.01 - Jituš . 02. 2014 15:06:52.3.2 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.3996.2774 [GMT 1:00]
Spuštěný z: c:\users\Jituš\Desktop\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-22 do 2014-02-22 )))))))))))))))))))))))))))))))
.
.
2014-02-22 14:14 . 2014-02-22 14:14 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-02-22 14:14 . 2014-02-22 14:14 -------- d-----w- c:\users\Jituš\AppData\Local\temp
2014-02-22 14:14 . 2014-02-22 14:14 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2014-02-22 14:14 . 2014-02-22 14:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-20 11:18 . 2014-02-20 11:18 -------- d-----w- c:\windows\ERUNT
2014-02-19 16:00 . 2014-02-20 06:04 -------- d-----w- C:\AdwCleaner
2014-02-19 11:39 . 2014-02-19 12:15 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2014-02-19 11:39 . 2014-02-19 15:14 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2014-02-09 11:25 . 2014-02-09 11:25 -------- d-----w- c:\windows\ServiceProfiles\LocalService\winhttp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-12 19:00 . 2013-03-10 07:07 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-01-06 19:23 . 2014-01-06 19:23 4558848 ----a-w- c:\windows\SysWow64\GPhotos.scr
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"332BigDog"="c:\program files (x86)\USB Camera2\VM332STI.EXE" [2012-03-20 548864]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-09-25 386336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 bthav;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys;c:\windows\SYSNATIVE\drivers\bthav.sys [x]
R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 L1C;Ovladač miniportu NDIS pro řadič Qualcomm Atheros AR813x/AR815x PCI-E Ethernet;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\System32\drivers\s1018bus.sys;c:\windows\SYSNATIVE\drivers\s1018bus.sys [x]
R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys;c:\windows\SYSNATIVE\DRIVERS\s1018mdfl.sys [x]
R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys;c:\windows\SYSNATIVE\DRIVERS\s1018mdm.sys [x]
R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys;c:\windows\SYSNATIVE\DRIVERS\s1018mgmt.sys [x]
R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys;c:\windows\SYSNATIVE\DRIVERS\s1018nd5.sys [x]
R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys;c:\windows\SYSNATIVE\DRIVERS\s1018obex.sys [x]
R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\System32\drivers\s1018unic.sys;c:\windows\SYSNATIVE\drivers\s1018unic.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 BcmBtRSupport;Bluetooth Radio Control Service;c:\windows\system32\BtwRSupportService.exe;c:\windows\SYSNATIVE\BtwRSupportService.exe [x]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x]
S2 ETDService;Elan Service;c:\program files\Elantech\ETDService.exe;c:\program files\Elantech\ETDService.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys;c:\windows\SYSNATIVE\drivers\bcbtums.sys [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 vm332avs;Lenovo Camera2;c:\windows\System32\Drivers\vm332avs.sys;c:\windows\SYSNATIVE\Drivers\vm332avs.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
apphost REG_MULTI_SZ apphostsvc
iissvcs REG_MULTI_SZ w3svc was
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-02-04 20:31 1211720 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.107\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-07 20:42]
.
2014-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-13 07:04]
.
2014-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-13 07:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2013-01-25 17079376]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2013-01-25 191568]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2012-06-14 887968]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2012-06-13 1647616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/?clid=2
uDefault_Search_URL = hxxp://www.google.com/ie
uLocal Page = c:\windows\system32\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 91.217.52.2 91.217.52.3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-VideoPad - c:\program files (x86)\NCH Software\VideoPad\videopad.exe
AddRemove-WavePad - c:\program files (x86)\NCH Software\WavePad\wavepad.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Celkový čas: 2014-02-22 15:19:29
ComboFix-quarantined-files.txt 2014-02-22 14:19
.
Před spuštěním: 447 446 556 672 bytes free
Po spuštění: 447 366 881 280 bytes free
.
- - End Of File - - AB5DC9C3A6D4300A4C4CCC995F3FF155
A36C5E4F47E84449FF07ED3517B43A31
MB-GIGABYTE; CPU-INTEL CORE i5; CHLADIČ-COOLER MASTER;
GPU-ASUS GTX660; RAM-KINGSTON 2x4 GB DDR3-1333MHz; SYSTÉM SSD- CRUCIAL 232GB + HDD-SEAGATE 320GB; PSU-SEASONIC G-550;

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod Orcus » 22 úno 2014 20:39

Orcus píše:V Rogukilleru se nic neodstranilo, takže ještě jednou, jak psal jaro3.


Poté znovu CF log.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
betisa
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod betisa » 22 úno 2014 21:16

Pokud dělám vše dle Jara:tj.

počkej až skončí Prescan -vyhledávání škodlivých procesů - Zkontroluj , zda máš zaškrtnuto:

Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na„Prohledat“.

U toho políčka prohledat se konkrétně píše,že prohledá registry bez mazání a to jsem dělal.
Pokud mám něco mazat je tam konkrétní políčko smazat ale o tom nikde Jaro nepíše.
Teď tedy nevím jak pokračovat....pokud dávám pouze prohledat,tak program registry pouze prohledá,ale nic sám neodstraní....
MB-GIGABYTE; CPU-INTEL CORE i5; CHLADIČ-COOLER MASTER;
GPU-ASUS GTX660; RAM-KINGSTON 2x4 GB DDR3-1333MHz; SYSTÉM SSD- CRUCIAL 232GB + HDD-SEAGATE 320GB; PSU-SEASONIC G-550;

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod jaro3 » 23 úno 2014 09:54

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Folder::
c:\programdata\Spybot - Search & Destroy
c:\program files (x86)\Spybot - Search & Destroy 2
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Google\Update

Driver::
SkypeUpdate

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
betisa
Level 1.5
Level 1.5
Příspěvky: 100
Registrován: duben 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: CPU pořád na 100% prosím o kontrolu logu

Příspěvekod betisa » 23 úno 2014 17:37

RogueKiller V8.8.8 _x64_ [Feb 19 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Jituš [Práva správce]
Mód : Kontrola -- Datum : 02/23/2014 17:26:42
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 2 ¤¤¤
[SUSP PATH] slsvc.exe -- C:\Windows\slsvc.exe [-] -> SMAZÁNO [TermProc]
[SUSP PATH] PersonalizeEnabler.exe -- C:\Windows\PersonalizeEnabler.exe [-] -> SMAZÁNO [TermProc]

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST9500325AS +++++
--- User ---
[MBR] edfa9362cf9cdac3f154d6424fc7e169
[BSP] 15fc16227e8fccae680f59a76c9e4889 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 350 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 718848 | Size: 476588 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_02232014_172642.txt >>

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:29:12, on 23. 2. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\USB Camera2\VM332STI.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Users\Jituš\Desktop\HijackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [332BigDog] C:\Program Files (x86)\USB Camera2\VM332STI.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\syswow64\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: @oem14.inf,%BcmBtRSupport.SVCNAME%;Bluetooth Radio Control Service (BcmBtRSupport) - Unknown owner - C:\Windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 8455 bytes


XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

ComboFix 14-02-20.01 - Jituš . 02. 2014 16:29:47.4.2 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.3996.2705 [GMT 1:00]
Spuštěný z: c:\users\JituÜ\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\JituÜ\Desktop\CFScript.txt
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-23 do 2014-02-23 )))))))))))))))))))))))))))))))
.
.
2014-02-23 15:38 . 2014-02-23 15:38 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-02-23 15:38 . 2014-02-23 15:38 -------- d-----w- c:\users\Jituš\AppData\Local\temp
2014-02-23 15:38 . 2014-02-23 15:38 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2014-02-23 15:38 . 2014-02-23 15:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-20 11:18 . 2014-02-20 11:18 -------- d-----w- c:\windows\ERUNT
2014-02-19 16:00 . 2014-02-20 06:04 -------- d-----w- C:\AdwCleaner
2014-02-19 11:39 . 2014-02-19 12:15 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2014-02-19 11:39 . 2014-02-19 15:14 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2014-02-09 11:25 . 2014-02-09 11:25 -------- d-----w- c:\windows\ServiceProfiles\LocalService\winhttp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-12 19:00 . 2013-03-10 07:07 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-01-06 19:23 . 2014-01-06 19:23 4558848 ----a-w- c:\windows\SysWow64\GPhotos.scr
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"332BigDog"="c:\program files (x86)\USB Camera2\VM332STI.EXE" [2012-03-20 548864]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-09-25 386336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 bthav;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys;c:\windows\SYSNATIVE\drivers\bthav.sys [x]
R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 L1C;Ovladač miniportu NDIS pro řadič Qualcomm Atheros AR813x/AR815x PCI-E Ethernet;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\System32\drivers\s1018bus.sys;c:\windows\SYSNATIVE\drivers\s1018bus.sys [x]
R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys;c:\windows\SYSNATIVE\DRIVERS\s1018mdfl.sys [x]
R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys;c:\windows\SYSNATIVE\DRIVERS\s1018mdm.sys [x]
R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys;c:\windows\SYSNATIVE\DRIVERS\s1018mgmt.sys [x]
R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys;c:\windows\SYSNATIVE\DRIVERS\s1018nd5.sys [x]
R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys;c:\windows\SYSNATIVE\DRIVERS\s1018obex.sys [x]
R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\System32\drivers\s1018unic.sys;c:\windows\SYSNATIVE\drivers\s1018unic.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 BcmBtRSupport;Bluetooth Radio Control Service;c:\windows\system32\BtwRSupportService.exe;c:\windows\SYSNATIVE\BtwRSupportService.exe [x]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x]
S2 ETDService;Elan Service;c:\program files\Elantech\ETDService.exe;c:\program files\Elantech\ETDService.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys;c:\windows\SYSNATIVE\drivers\bcbtums.sys [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 vm332avs;Lenovo Camera2;c:\windows\System32\Drivers\vm332avs.sys;c:\windows\SYSNATIVE\Drivers\vm332avs.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
apphost REG_MULTI_SZ apphostsvc
iissvcs REG_MULTI_SZ w3svc was
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-02-23 11:37 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.117\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-07 20:42]
.
2014-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-13 07:04]
.
2014-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-13 07:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2013-01-25 17079376]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2013-01-25 191568]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968]
"ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2012-06-14 887968]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2012-06-13 1647616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/?clid=2
uDefault_Search_URL = hxxp://www.google.com/ie
uLocal Page = c:\windows\system32\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 91.217.52.2 91.217.52.3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-VideoPad - c:\program files (x86)\NCH Software\VideoPad\videopad.exe
AddRemove-WavePad - c:\program files (x86)\NCH Software\WavePad\wavepad.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Celkový čas: 2014-02-23 16:49:19
ComboFix-quarantined-files.txt 2014-02-23 15:49
ComboFix2.txt 2014-02-22 14:19
.
Před spuštěním: 447 417 384 960 bytes free
Po spuštění: 446 967 513 088 bytes free
.
- - End Of File - - EDBCD7F5F3578167A4EB040A3AEB8B93
A36C5E4F47E84449FF07ED3517B43A31

ten program aswMBR mi krátce po skenování napíše že program přestal pracovat a ukončí se...
MB-GIGABYTE; CPU-INTEL CORE i5; CHLADIČ-COOLER MASTER;
GPU-ASUS GTX660; RAM-KINGSTON 2x4 GB DDR3-1333MHz; SYSTÉM SSD- CRUCIAL 232GB + HDD-SEAGATE 320GB; PSU-SEASONIC G-550;


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 104 hostů