Prosím o kontrolu logu z HJT - notebook HP 6730s Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

JANíčOK
Level 3
Level 3
Příspěvky: 471
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod JANíčOK » 13 pro 2012 08:47

Prosím vás o kontrolu logu HJT z notebooku HP 6730s.
Je tu viac problémov, napr.: Windows sa dlho spúšťa (niekedy sa nespustí vôbec, zostane iba čierna obrazovka), klávesnica pri písaní robí čo chce (náhodne označuje napísaný text, presúva kurzor a pod.)
Vopred ďakujem.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:41:28, on 13. 12. 2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Lexmark X1100 Series\LXBKbmgr.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe /tray
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [lxbkbmgr.exe] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {5852F5ED-8BF4-11D4-A245-0080C6F74284} (isInstalled Class) - http://javadl-esd.sun.com/update/1.6.0/ ... s-i586.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE

--
End of file - 10464 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod jaro3 » 13 pro 2012 09:59

Odinstaluj:
Spybot-S&D

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5852F5ED-8BF4-11D4-A245-0080C6F74284} (isInstalled Class) - http://javadl-esd.sun.com/update/1.6.0/ ... s-i586.cab

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Malwarebytes' Anti-Malware--
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

JANíčOK
Level 3
Level 3
Příspěvky: 471
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod JANíčOK » 13 pro 2012 14:57

Posielam log z Malwarebytes' Anti-Malware. Všetko ostatné som urobil podľa pokynov.
Zatiaľ ďakujem.

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Verzia databázy: v2012.12.13.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Adakar s.r.o :: ADAKARSRO-PC [administrátor]

13. 12. 2012 14:34:00
mbam-log-2012-12-13 (14-34-00).txt

Typ kontroly: Rýchla kontrola
Možnosti kontroly zapnuté: Pamäť | Po spustení | Registre | Systémové súbory | Heuristika/Extra | Heuristika/Shuriken | PUP | PUM
Možnosti kontroly vypnuté: P2P
Objektov kontrolovaných: 190100
Uplynutý čas: 7 min, 43 sek

Detegované služby pamäte: 0
(Škodlivé položky neboli zistené)

Detegované moduly pamäte: 0
(Škodlivé položky neboli zistené)

Detegované registračné kľúče: 0
(Škodlivé položky neboli zistené)

Detegované registračné hodnoty: 0
(Škodlivé položky neboli zistené)

Detegované položky registračných dát: 0
(Škodlivé položky neboli zistené)

Detegované priečinky: 0
(Škodlivé položky neboli zistené)

Detegované súbory: 0
(Škodlivé položky neboli zistené)

(koniec)

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod Žbeky » 13 pro 2012 22:19

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

JANíčOK
Level 3
Level 3
Příspěvky: 471
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod JANíčOK » 14 pro 2012 06:18

Log z TDSSKiller rozdelený na 2 časti:

06:14:28.0525 2756 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
06:14:28.0712 2756 ============================================================
06:14:28.0712 2756 Current date / time: 2012/12/14 06:14:28.0712
06:14:28.0712 2756 SystemInfo:
06:14:28.0712 2756
06:14:28.0712 2756 OS Version: 6.0.6002 ServicePack: 2.0
06:14:28.0712 2756 Product type: Workstation
06:14:28.0712 2756 ComputerName: ADAKARSRO-PC
06:14:28.0712 2756 UserName: Adakar s.r.o
06:14:28.0712 2756 Windows directory: C:\Windows
06:14:28.0712 2756 System windows directory: C:\Windows
06:14:28.0712 2756 Processor architecture: Intel x86
06:14:28.0712 2756 Number of processors: 2
06:14:28.0712 2756 Page size: 0x1000
06:14:28.0712 2756 Boot type: Normal boot
06:14:28.0712 2756 ============================================================
06:14:29.0242 2756 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
06:14:29.0242 2756 ============================================================
06:14:29.0242 2756 \Device\Harddisk0\DR0:
06:14:29.0242 2756 MBR partitions:
06:14:29.0242 2756 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x4B25000
06:14:29.0242 2756 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x4B25800, BlocksNum 0x1869F800
06:14:29.0242 2756 ============================================================
06:14:29.0273 2756 C: <-> \Device\Harddisk0\DR0\Partition1
06:14:29.0320 2756 D: <-> \Device\Harddisk0\DR0\Partition2
06:14:29.0320 2756 ============================================================
06:14:29.0320 2756 Initialize success
06:14:29.0320 2756 ============================================================
06:14:31.0941 3044 ============================================================
06:14:31.0941 3044 Scan started
06:14:31.0941 3044 Mode: Manual;
06:14:31.0941 3044 ============================================================
06:14:32.0284 3044 ================ Scan system memory ========================
06:14:32.0284 3044 System memory - ok
06:14:32.0284 3044 ================ Scan services =============================
06:14:32.0581 3044 [ CC1F1D3D70DC13C2C281488D347D4415 ] Accelerometer C:\Windows\system32\DRIVERS\Accelerometer.sys
06:14:32.0596 3044 Accelerometer - ok
06:14:32.0627 3044 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
06:14:32.0643 3044 ACPI - ok
06:14:32.0690 3044 [ BF9DE454F80A1516D4D582520B2D6EDD ] ADIHdAudAddService C:\Windows\system32\drivers\ADIHdAud.sys
06:14:32.0690 3044 ADIHdAudAddService - ok
06:14:32.0799 3044 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
06:14:32.0799 3044 AdobeFlashPlayerUpdateSvc - ok
06:14:32.0846 3044 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
06:14:32.0846 3044 adp94xx - ok
06:14:32.0877 3044 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
06:14:32.0893 3044 adpahci - ok
06:14:32.0908 3044 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
06:14:32.0908 3044 adpu160m - ok
06:14:32.0939 3044 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
06:14:32.0939 3044 adpu320 - ok
06:14:32.0986 3044 [ 30EB9BCF0D1E4EDD3905AE003AC0C1AC ] AEADIFilters C:\Windows\system32\AEADISRV.EXE
06:14:32.0986 3044 AEADIFilters - ok
06:14:33.0033 3044 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
06:14:33.0033 3044 AeLookupSvc - ok
06:14:33.0127 3044 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
06:14:33.0127 3044 AFD - ok
06:14:33.0205 3044 [ 9C9D3B7A05445B1AB2DF4D0C4D6B77E8 ] AgereModemAudio C:\Program Files\LSI SoftModem\agrsmsvc.exe
06:14:33.0205 3044 AgereModemAudio - ok
06:14:33.0345 3044 [ 3712986CC3ABF0DC656B43525B9D1279 ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys
06:14:33.0376 3044 AgereSoftModem - ok
06:14:33.0407 3044 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
06:14:33.0407 3044 agp440 - ok
06:14:33.0439 3044 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
06:14:33.0439 3044 aic78xx - ok
06:14:33.0470 3044 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
06:14:33.0470 3044 ALG - ok
06:14:33.0485 3044 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
06:14:33.0485 3044 aliide - ok
06:14:33.0517 3044 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
06:14:33.0517 3044 amdagp - ok
06:14:33.0532 3044 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
06:14:33.0532 3044 amdide - ok
06:14:33.0548 3044 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
06:14:33.0563 3044 AmdK7 - ok
06:14:33.0563 3044 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
06:14:33.0579 3044 AmdK8 - ok
06:14:33.0610 3044 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
06:14:33.0610 3044 Appinfo - ok
06:14:33.0641 3044 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
06:14:33.0641 3044 arc - ok
06:14:33.0657 3044 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
06:14:33.0657 3044 arcsas - ok
06:14:33.0673 3044 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
06:14:33.0673 3044 AsyncMac - ok
06:14:33.0704 3044 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
06:14:33.0704 3044 atapi - ok
06:14:33.0751 3044 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
06:14:33.0751 3044 AudioEndpointBuilder - ok
06:14:33.0766 3044 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
06:14:33.0766 3044 Audiosrv - ok
06:14:33.0797 3044 [ 06740BCA09A1D6A7B2D753F17D0BB10B ] BCM42RLY C:\Windows\system32\drivers\BCM42RLY.sys
06:14:33.0797 3044 BCM42RLY - ok
06:14:33.0922 3044 [ 40FB1D9065E668CD4BEEFF0A804C40E0 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
06:14:33.0953 3044 BCM43XX - ok
06:14:34.0000 3044 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
06:14:34.0000 3044 Beep - ok
06:14:34.0047 3044 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
06:14:34.0047 3044 BFE - ok
06:14:34.0094 3044 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
06:14:34.0094 3044 BITS - ok
06:14:34.0125 3044 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
06:14:34.0125 3044 blbdrive - ok
06:14:34.0172 3044 [ 73686FE0B2E0469F89FD2075BE724704 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
06:14:34.0172 3044 Bonjour Service - ok
06:14:34.0203 3044 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
06:14:34.0219 3044 bowser - ok
06:14:34.0234 3044 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
06:14:34.0250 3044 BrFiltLo - ok
06:14:34.0265 3044 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
06:14:34.0265 3044 BrFiltUp - ok
06:14:34.0343 3044 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
06:14:34.0343 3044 Browser - ok
06:14:34.0375 3044 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
06:14:34.0375 3044 Brserid - ok
06:14:34.0390 3044 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
06:14:34.0390 3044 BrSerWdm - ok
06:14:34.0406 3044 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
06:14:34.0406 3044 BrUsbMdm - ok
06:14:34.0421 3044 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
06:14:34.0421 3044 BrUsbSer - ok
06:14:34.0484 3044 [ 6D39C954799B63BA866910234CF7D726 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
06:14:34.0484 3044 BthEnum - ok
06:14:34.0515 3044 [ 9A966A8E86D1771911AE34A20D11BFF3 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
06:14:34.0515 3044 BTHMODEM - ok
06:14:34.0546 3044 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
06:14:34.0546 3044 BthPan - ok
06:14:34.0640 3044 [ 611FF3F2F095C8D4A6D4CFD9DCC09793 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
06:14:34.0640 3044 BTHPORT - ok
06:14:34.0671 3044 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll
06:14:34.0671 3044 BthServ - ok
06:14:34.0702 3044 [ D330803EAB2A15CAEC7F011F1D4CB30E ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
06:14:34.0702 3044 BTHUSB - ok
06:14:34.0733 3044 [ D57D29132EFE13A83133D9BD449E0CF1 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
06:14:34.0733 3044 btwaudio - ok
06:14:34.0749 3044 [ D282C14A69357D0E1BAFAECC2CA98C3A ] btwavdt C:\Windows\system32\drivers\btwavdt.sys
06:14:34.0749 3044 btwavdt - ok
06:14:34.0827 3044 [ 7CAA4410C25026B9BEE85F6C7F86B19B ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
06:14:34.0843 3044 btwdins - ok
06:14:34.0843 3044 [ AAFD7CB76BA61FBB08E302DA208C974A ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
06:14:34.0843 3044 btwl2cap - ok
06:14:34.0858 3044 [ 02EB4D2B05967DF2D32F29C84AB1FB17 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
06:14:34.0858 3044 btwrchid - ok
06:14:34.0889 3044 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
06:14:34.0889 3044 cdfs - ok
06:14:34.0921 3044 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
06:14:34.0921 3044 cdrom - ok
06:14:34.0936 3044 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
06:14:34.0936 3044 CertPropSvc - ok
06:14:34.0967 3044 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
06:14:34.0967 3044 circlass - ok
06:14:35.0014 3044 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
06:14:35.0014 3044 CLFS - ok
06:14:35.0077 3044 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
06:14:35.0077 3044 clr_optimization_v2.0.50727_32 - ok
06:14:35.0139 3044 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
06:14:35.0139 3044 clr_optimization_v4.0.30319_32 - ok
06:14:35.0170 3044 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
06:14:35.0170 3044 CmBatt - ok
06:14:35.0201 3044 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
06:14:35.0217 3044 cmdide - ok
06:14:35.0311 3044 [ C7A0E61D5714AC20DE52D4F66EC773B8 ] Com4QLBEx C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
06:14:35.0311 3044 Com4QLBEx - ok
06:14:35.0342 3044 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
06:14:35.0342 3044 Compbatt - ok
06:14:35.0357 3044 COMSysApp - ok
06:14:35.0373 3044 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
06:14:35.0373 3044 crcdisk - ok
06:14:35.0389 3044 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
06:14:35.0389 3044 Crusoe - ok
06:14:35.0435 3044 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
06:14:35.0435 3044 CryptSvc - ok
06:14:35.0482 3044 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
06:14:35.0482 3044 DcomLaunch - ok
06:14:35.0529 3044 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
06:14:35.0545 3044 DfsC - ok
06:14:35.0607 3044 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
06:14:35.0638 3044 DFSR - ok
06:14:35.0685 3044 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
06:14:35.0685 3044 Dhcp - ok
06:14:35.0716 3044 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
06:14:35.0716 3044 disk - ok
06:14:35.0763 3044 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
06:14:35.0763 3044 Dnscache - ok
06:14:35.0810 3044 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
06:14:35.0810 3044 dot3svc - ok
06:14:35.0841 3044 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
06:14:35.0841 3044 DPS - ok
06:14:35.0903 3044 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
06:14:35.0903 3044 drmkaud - ok
06:14:35.0950 3044 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
06:14:35.0950 3044 DXGKrnl - ok
06:14:35.0997 3044 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
06:14:35.0997 3044 E1G60 - ok
06:14:36.0044 3044 [ 8A45015E85A4DCE0086B9973F0FD9A20 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
06:14:36.0059 3044 eamonm - ok
06:14:36.0106 3044 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
06:14:36.0106 3044 EapHost - ok
06:14:36.0137 3044 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
06:14:36.0137 3044 Ecache - ok
06:14:36.0200 3044 [ 5412ED24FFFCA64E2F0168399B86C952 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
06:14:36.0200 3044 ehdrv - ok
06:14:36.0278 3044 [ AD4FAADE819E0DA9933BEA7C01D2C763 ] ekrn C:\Program Files\ESET\ESET Smart Security\ekrn.exe
06:14:36.0293 3044 ekrn - ok
06:14:36.0309 3044 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
06:14:36.0325 3044 elxstor - ok
06:14:36.0371 3044 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
06:14:36.0387 3044 EMDMgmt - ok
06:14:36.0434 3044 [ 774BABCB1144513DC86992003740B774 ] epfw C:\Windows\system32\DRIVERS\epfw.sys
06:14:36.0434 3044 epfw - ok
06:14:36.0465 3044 [ 2C22CC39309EE06AE870C183BF2A769D ] EpfwLWF C:\Windows\system32\DRIVERS\EpfwLWF.sys
06:14:36.0465 3044 EpfwLWF - ok
06:14:36.0527 3044 [ 2B4E5F01A4E786B422F4D617B51FA7D9 ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
06:14:36.0527 3044 epfwwfp - ok
06:14:36.0543 3044 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
06:14:36.0543 3044 ErrDev - ok
06:14:36.0590 3044 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
06:14:36.0590 3044 EventSystem - ok
06:14:36.0621 3044 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
06:14:36.0621 3044 exfat - ok
06:14:36.0652 3044 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
06:14:36.0652 3044 fastfat - ok
06:14:36.0683 3044 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
06:14:36.0683 3044 fdc - ok
06:14:36.0715 3044 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
06:14:36.0715 3044 fdPHost - ok
06:14:36.0730 3044 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
06:14:36.0730 3044 FDResPub - ok
06:14:36.0746 3044 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
06:14:36.0746 3044 FileInfo - ok
06:14:36.0777 3044 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
06:14:36.0777 3044 Filetrace - ok
06:14:36.0824 3044 [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
06:14:36.0839 3044 FLEXnet Licensing Service - ok
06:14:36.0855 3044 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
06:14:36.0855 3044 flpydisk - ok
06:14:36.0902 3044 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
06:14:36.0917 3044 FltMgr - ok
06:14:37.0011 3044 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
06:14:37.0011 3044 FontCache - ok
06:14:37.0105 3044 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
06:14:37.0120 3044 FontCache3.0.0.0 - ok
06:14:37.0136 3044 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
06:14:37.0136 3044 Fs_Rec - ok
06:14:37.0167 3044 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
06:14:37.0167 3044 gagp30kx - ok
06:14:37.0229 3044 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
06:14:37.0229 3044 gpsvc - ok
06:14:37.0292 3044 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
06:14:37.0292 3044 gupdate - ok
06:14:37.0339 3044 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
06:14:37.0339 3044 gupdatem - ok
06:14:37.0385 3044 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
06:14:37.0385 3044 gusvc - ok
06:14:37.0417 3044 [ 93AEE3434935FC2F805FEFD8DC5ED1B4 ] HBtnKey C:\Windows\system32\DRIVERS\cpqbttn.sys
06:14:37.0432 3044 HBtnKey - ok
06:14:37.0463 3044 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
06:14:37.0463 3044 HdAudAddService - ok
06:14:37.0510 3044 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
06:14:37.0510 3044 HDAudBus - ok
06:14:37.0557 3044 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
06:14:37.0557 3044 HidBth - ok
06:14:37.0573 3044 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
06:14:37.0573 3044 HidIr - ok
06:14:37.0604 3044 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
06:14:37.0604 3044 hidserv - ok
06:14:37.0651 3044 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
06:14:37.0651 3044 HidUsb - ok
06:14:37.0666 3044 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
06:14:37.0666 3044 hkmsvc - ok
06:14:37.0697 3044 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
06:14:37.0697 3044 HpCISSs - ok
06:14:37.0729 3044 [ 4EF10B866C62ABBEAF7511CDD05A19BE ] hpdskflt C:\Windows\system32\DRIVERS\hpdskflt.sys
06:14:37.0729 3044 hpdskflt - ok
06:14:37.0775 3044 [ 1210960FF8928950D2A786895B0C424A ] HpqKbFiltr C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
06:14:37.0775 3044 HpqKbFiltr - ok
06:14:37.0838 3044 [ FDF273A845F1FFCCEADF363AAF47582F ] hpqwmiex C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
06:14:37.0838 3044 hpqwmiex - ok
06:14:37.0853 3044 [ C0BEB56ED79B59B7B33D0AA6C38A0BA6 ] hpsrv C:\Windows\system32\Hpservice.exe
06:14:37.0853 3044 hpsrv - ok
06:14:37.0885 3044 [ 0EEECA26C8D4BDE2A4664DB058A81937 ] HTTP C:\Windows\system32\drivers\HTTP.sys
06:14:37.0900 3044 HTTP - ok
06:14:37.0931 3044 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
06:14:37.0931 3044 i2omp - ok
06:14:37.0947 3044 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
06:14:37.0963 3044 i8042prt - ok
06:14:38.0009 3044 [ D782F0C741EE2D50AC8D38774597FB2B ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
06:14:38.0009 3044 IAANTMON - ok
06:14:38.0056 3044 [ D9D3F168A2FD4C2380D98821A3FF3357 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
06:14:38.0072 3044 iaStor - ok
06:14:38.0103 3044 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
06:14:38.0103 3044 iaStorV - ok
06:14:38.0197 3044 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
06:14:38.0212 3044 idsvc - ok
06:14:38.0337 3044 [ D97E70E4E243C9660F91C1112E36C73B ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
06:14:38.0368 3044 igfx - ok
06:14:38.0399 3044 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
06:14:38.0399 3044 iirsp - ok
06:14:38.0431 3044 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
06:14:38.0446 3044 IKEEXT - ok
06:14:38.0462 3044 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
06:14:38.0462 3044 intelide - ok
06:14:38.0477 3044 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
06:14:38.0477 3044 intelppm - ok
06:14:38.0509 3044 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
06:14:38.0524 3044 IPBusEnum - ok
06:14:38.0540 3044 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
06:14:38.0540 3044 IpFilterDriver - ok
06:14:38.0571 3044 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
06:14:38.0571 3044 iphlpsvc - ok
06:14:38.0587 3044 IpInIp - ok
06:14:38.0618 3044 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
06:14:38.0618 3044 IPMIDRV - ok
06:14:38.0633 3044 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
06:14:38.0633 3044 IPNAT - ok
06:14:38.0665 3044 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
06:14:38.0665 3044 IRENUM - ok
06:14:38.0680 3044 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
06:14:38.0680 3044 isapnp - ok
06:14:38.0727 3044 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
06:14:38.0727 3044 iScsiPrt - ok
06:14:38.0758 3044 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
06:14:38.0758 3044 iteatapi - ok
06:14:38.0774 3044 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
06:14:38.0774 3044 iteraid - ok
06:14:38.0805 3044 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
06:14:38.0805 3044 kbdclass - ok
06:14:38.0836 3044 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
06:14:38.0836 3044 kbdhid - ok
06:14:38.0867 3044 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
06:14:38.0867 3044 KeyIso - ok
06:14:38.0914 3044 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
06:14:38.0914 3044 KSecDD - ok
06:14:38.0961 3044 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
06:14:38.0961 3044 KtmRm - ok
06:14:38.0992 3044 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll
06:14:39.0008 3044 LanmanServer - ok
06:14:39.0039 3044 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
06:14:39.0039 3044 LanmanWorkstation - ok
06:14:39.0086 3044 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
06:14:39.0086 3044 lltdio - ok
06:14:39.0133 3044 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
06:14:39.0133 3044 lltdsvc - ok
06:14:39.0148 3044 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
06:14:39.0164 3044 lmhosts - ok
06:14:39.0195 3044 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
06:14:39.0195 3044 LSI_FC - ok
06:14:39.0211 3044 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
06:14:39.0211 3044 LSI_SAS - ok
06:14:39.0242 3044 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
06:14:39.0242 3044 LSI_SCSI - ok
06:14:39.0257 3044 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
06:14:39.0273 3044 luafv - ok
06:14:39.0273 3044 lxbk_device - ok
06:14:39.0304 3044 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
06:14:39.0304 3044 megasas - ok
06:14:39.0335 3044 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
06:14:39.0335 3044 MegaSR - ok
06:14:39.0367 3044 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
06:14:39.0367 3044 MMCSS - ok
06:14:39.0398 3044 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
06:14:39.0398 3044 Modem - ok
06:14:39.0413 3044 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
06:14:39.0413 3044 monitor - ok
06:14:39.0429 3044 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
06:14:39.0429 3044 mouclass - ok
06:14:39.0460 3044 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
06:14:39.0460 3044 mouhid - ok
06:14:39.0476 3044 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
06:14:39.0476 3044 MountMgr - ok
06:14:39.0507 3044 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
06:14:39.0507 3044 mpio - ok
06:14:39.0538 3044 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
06:14:39.0538 3044 mpsdrv - ok
06:14:39.0569 3044 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
06:14:39.0585 3044 MpsSvc - ok
06:14:39.0601 3044 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
06:14:39.0601 3044 Mraid35x - ok
06:14:39.0647 3044 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
06:14:39.0647 3044 MRxDAV - ok
06:14:39.0679 3044 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
06:14:39.0679 3044 mrxsmb - ok
06:14:39.0725 3044 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
06:14:39.0725 3044 mrxsmb10 - ok
06:14:39.0741 3044 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
06:14:39.0741 3044 mrxsmb20 - ok
06:14:39.0788 3044 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
06:14:39.0788 3044 msahci - ok
06:14:39.0819 3044 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
06:14:39.0819 3044 msdsm - ok
06:14:39.0835 3044 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
06:14:39.0835 3044 MSDTC - ok
06:14:39.0866 3044 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
06:14:39.0866 3044 Msfs - ok
06:14:39.0897 3044 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
06:14:39.0897 3044 msisadrv - ok
06:14:39.0928 3044 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
06:14:39.0928 3044 MSiSCSI - ok
06:14:39.0928 3044 msiserver - ok
06:14:39.0959 3044 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
06:14:39.0959 3044 MSKSSRV - ok
06:14:39.0975 3044 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
06:14:39.0975 3044 MSPCLOCK - ok
06:14:40.0006 3044 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
06:14:40.0006 3044 MSPQM - ok
06:14:40.0037 3044 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
06:14:40.0037 3044 MsRPC - ok
06:14:40.0053 3044 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
06:14:40.0053 3044 mssmbios - ok
06:14:40.0069 3044 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
06:14:40.0069 3044 MSTEE - ok
06:14:40.0100 3044 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
06:14:40.0100 3044 Mup - ok
06:14:40.0131 3044 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
06:14:40.0131 3044 napagent - ok
06:14:40.0178 3044 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
06:14:40.0178 3044 NativeWifiP - ok
06:14:40.0209 3044 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
06:14:40.0209 3044 NDIS - ok
06:14:40.0240 3044 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
06:14:40.0240 3044 NdisTapi - ok
06:14:40.0256 3044 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
06:14:40.0256 3044 Ndisuio - ok
06:14:40.0287 3044 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
06:14:40.0287 3044 NdisWan - ok
06:14:40.0303 3044 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
06:14:40.0303 3044 NDProxy - ok
06:14:40.0318 3044 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
06:14:40.0318 3044 NetBIOS - ok
06:14:40.0349 3044 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
06:14:40.0349 3044 netbt - ok
06:14:40.0365 3044 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
06:14:40.0381 3044 Netlogon - ok
06:14:40.0412 3044 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
06:14:40.0412 3044 Netman - ok
06:14:40.0443 3044 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
06:14:40.0443 3044 netprofm - ok
06:14:40.0474 3044 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
06:14:40.0490 3044 NetTcpPortSharing - ok
06:14:40.0521 3044 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
06:14:40.0521 3044 nfrd960 - ok
06:14:40.0537 3044 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
06:14:40.0552 3044 NlaSvc - ok
06:14:40.0568 3044 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
06:14:40.0583 3044 Npfs - ok
06:14:40.0615 3044 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
06:14:40.0615 3044 nsi - ok
06:14:40.0630 3044 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
06:14:40.0630 3044 nsiproxy - ok
06:14:40.0693 3044 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
06:14:40.0708 3044 Ntfs - ok
06:14:40.0739 3044 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
06:14:40.0739 3044 ntrigdigi - ok
06:14:40.0755 3044 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
06:14:40.0755 3044 Null - ok
06:14:40.0786 3044 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
06:14:40.0786 3044 nvraid - ok
06:14:40.0802 3044 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
06:14:40.0802 3044 nvstor - ok
06:14:40.0817 3044 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
06:14:40.0817 3044 nv_agp - ok
06:14:40.0833 3044 NwlnkFlt - ok
06:14:40.0833 3044 NwlnkFwd - ok
06:14:40.0927 3044 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
06:14:40.0942 3044 odserv - ok
06:14:40.0973 3044 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
06:14:40.0973 3044 ohci1394 - ok
06:14:41.0005 3044 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
06:14:41.0005 3044 ose - ok
06:14:41.0051 3044 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
06:14:41.0067 3044 p2pimsvc - ok
06:14:41.0083 3044 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
06:14:41.0098 3044 p2psvc - ok
06:14:41.0114 3044 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
06:14:41.0114 3044 Parport - ok
06:14:41.0145 3044 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
06:14:41.0145 3044 partmgr - ok
06:14:41.0176 3044 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
06:14:41.0176 3044 Parvdm - ok
06:14:41.0223 3044 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
06:14:41.0223 3044 PcaSvc - ok
06:14:41.0270 3044 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
06:14:41.0270 3044 pci - ok
06:14:41.0285 3044 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
06:14:41.0285 3044 pciide - ok
06:14:41.0317 3044 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
06:14:41.0332 3044 pcmcia - ok
06:14:41.0363 3044 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
06:14:41.0379 3044 PEAUTH - ok
06:14:41.0457 3044 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
06:14:41.0488 3044 pla - ok
06:14:41.0519 3044 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
06:14:41.0519 3044 PlugPlay - ok
06:14:41.0551 3044 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
06:14:41.0566 3044 PNRPAutoReg - ok
06:14:41.0582 3044 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
06:14:41.0582 3044 PNRPsvc - ok
06:14:41.0613 3044 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
06:14:41.0613 3044 PolicyAgent - ok
06:14:41.0644 3044 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
06:14:41.0644 3044 PptpMiniport - ok
06:14:41.0675 3044 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
06:14:41.0675 3044 Processor - ok
06:14:41.0691 3044 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
06:14:41.0707 3044 ProfSvc - ok
06:14:41.0722 3044 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
06:14:41.0722 3044 ProtectedStorage - ok
06:14:41.0753 3044 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
06:14:41.0753 3044 PSched - ok
06:14:41.0800 3044 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
06:14:41.0816 3044 ql2300 - ok
06:14:41.0863 3044 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
06:14:41.0863 3044 ql40xx - ok
06:14:41.0909 3044 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
06:14:41.0909 3044 QWAVE - ok
06:14:41.0925 3044 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
06:14:41.0925 3044 QWAVEdrv - ok
06:14:41.0956 3044 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
06:14:41.0956 3044 RasAcd - ok
06:14:41.0972 3044 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
06:14:41.0972 3044 RasAuto - ok
06:14:42.0003 3044 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
06:14:42.0003 3044 Rasl2tp - ok
06:14:42.0050 3044 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
06:14:42.0065 3044 RasMan - ok
06:14:42.0097 3044 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
06:14:42.0097 3044 RasPppoe - ok
06:14:42.0128 3044 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
06:14:42.0128 3044 RasSstp - ok
06:14:42.0159 3044 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
06:14:42.0175 3044 rdbss - ok
06:14:42.0190 3044 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
06:14:42.0190 3044 RDPCDD - ok
06:14:42.0221 3044 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
06:14:42.0221 3044 rdpdr - ok
06:14:42.0237 3044 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
06:14:42.0237 3044 RDPENCDD - ok
06:14:42.0268 3044 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
06:14:42.0268 3044 RDPWD - ok
06:14:42.0315 3044 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
06:14:42.0315 3044 RemoteAccess - ok
06:14:42.0346 3044 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
06:14:42.0362 3044 RemoteRegistry - ok
06:14:42.0393 3044 [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
06:14:42.0393 3044 RFCOMM - ok
06:14:42.0424 3044 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
06:14:42.0424 3044 RpcLocator - ok
06:14:42.0455 3044 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
06:14:42.0455 3044 RpcSs - ok
06:14:42.0502 3044 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
06:14:42.0502 3044 rspndr - ok
06:14:42.0533 3044 [ D259D085F215B57B7170DC2D0B646B2A ] s1039bus C:\Windows\system32\DRIVERS\s1039bus.sys
06:14:42.0533 3044 s1039bus - ok
06:14:42.0549 3044 [ 4D2B6621B5913E8B1CBB650A6037B8A2 ] s1039mdfl C:\Windows\system32\DRIVERS\s1039mdfl.sys
06:14:42.0549 3044 s1039mdfl - ok
06:14:42.0580 3044 [ 8149799844AB2E91EA92E9CAD4224254 ] s1039mdm C:\Windows\system32\DRIVERS\s1039mdm.sys
06:14:42.0580 3044 s1039mdm - ok
06:14:42.0611 3044 [ 5E91068B3F5E003B83D8A99DC0C76E2C ] s1039mgmt C:\Windows\system32\DRIVERS\s1039mgmt.sys
06:14:42.0611 3044 s1039mgmt - ok
06:14:42.0627 3044 [ DF54DBF1C4105D2074D07929F6BA91AA ] s1039nd5 C:\Windows\system32\DRIVERS\s1039nd5.sys
06:14:42.0627 3044 s1039nd5 - ok
06:14:42.0643 3044 [ 1BC084B0708D42E29E2222346149E52F ] s1039obex C:\Windows\system32\DRIVERS\s1039obex.sys
06:14:42.0658 3044 s1039obex - ok
06:14:42.0674 3044 [ 2E8CCB7BF5B1EB34BCF4EBF880B3E11C ] s1039unic C:\Windows\system32\DRIVERS\s1039unic.sys
06:14:42.0674 3044 s1039unic - ok
06:14:42.0689 3044 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
06:14:42.0705 3044 SamSs - ok
06:14:42.0736 3044 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
06:14:42.0736 3044 sbp2port - ok
06:14:42.0845 3044 [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
06:14:42.0861 3044 SBSDWSCService - ok
06:14:42.0892 3044 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
06:14:42.0892 3044 SCardSvr - ok
06:14:42.0939 3044 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
06:14:42.0939 3044 Schedule - ok
06:14:42.0970 3044 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
06:14:42.0970 3044 SCPolicySvc - ok
06:14:43.0001 3044 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
06:14:43.0001 3044 SDRSVC - ok
06:14:43.0017 3044 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
06:14:43.0017 3044 secdrv - ok
06:14:43.0033 3044 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
06:14:43.0033 3044 seclogon - ok
06:14:43.0048 3044 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
06:14:43.0048 3044 SENS - ok
06:14:43.0079 3044 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
06:14:43.0079 3044 Serenum - ok
06:14:43.0095 3044 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
06:14:43.0111 3044 Serial - ok
06:14:43.0111 3044 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
06:14:43.0126 3044 sermouse - ok
06:14:43.0157 3044 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
06:14:43.0157 3044 SessionEnv - ok
06:14:43.0173 3044 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
06:14:43.0173 3044 sffdisk - ok
06:14:43.0189 3044 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
06:14:43.0189 3044 sffp_mmc - ok
06:14:43.0204 3044 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
06:14:43.0220 3044 sffp_sd - ok
06:14:43.0235 3044 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
06:14:43.0235 3044 sfloppy - ok
06:14:43.0298 3044 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
06:14:43.0298 3044 SharedAccess - ok
06:14:43.0345 3044 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
06:14:43.0345 3044 ShellHWDetection - ok
06:14:43.0376 3044 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
06:14:43.0376 3044 sisagp - ok
06:14:43.0407 3044 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
06:14:43.0407 3044 SiSRaid2 - ok
06:14:43.0423 3044 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
06:14:43.0423 3044 SiSRaid4 - ok
06:14:43.0469 3044 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
06:14:43.0469 3044 SkypeUpdate - ok
06:14:43.0594 3044 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
06:14:43.0641 3044 slsvc - ok
06:14:43.0688 3044 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
06:14:43.0688 3044 SLUINotify - ok
06:14:43.0719 3044 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
06:14:43.0719 3044 Smb - ok
06:14:43.0750 3044 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
06:14:43.0750 3044 SNMPTRAP - ok
06:14:43.0875 3044 [ 50660E6B082A7BF86751A003C3BB5210 ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
06:14:43.0906 3044 SNP2UVC - ok
06:14:43.0969 3044 [ E603BEE916153164B990A9DE49C04B9B ] Sony Ericsson PCCompanion C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
06:14:43.0969 3044 Sony Ericsson PCCompanion - ok
06:14:44.0000 3044 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
06:14:44.0015 3044 spldr - ok
06:14:44.0047 3044 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
06:14:44.0047 3044 Spooler - ok
06:14:44.0078 3044 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
06:14:44.0078 3044 srv - ok
06:14:44.0125 3044 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
06:14:44.0125 3044 srv2 - ok
06:14:44.0171 3044 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
06:14:44.0171 3044 srvnet - ok
06:14:44.0203 3044 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
06:14:44.0203 3044 SSDPSRV - ok
06:14:44.0218 3044 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
06:14:44.0218 3044 SstpSvc - ok
06:14:44.0265 3044 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
06:14:44.0265 3044 stisvc - ok
06:14:44.0296 3044 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
06:14:44.0296 3044 swenum - ok
06:14:44.0343 3044 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
06:14:44.0343 3044 swprv - ok
06:14:44.0374 3044 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
06:14:44.0374 3044 Symc8xx - ok
06:14:44.0390 3044 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
06:14:44.0390 3044 Sym_hi - ok
06:14:44.0405 3044 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
06:14:44.0421 3044 Sym_u3 - ok
06:14:44.0483 3044 [ 0E8676FB3BB95AA40FDF7A4A31018C8B ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
06:14:44.0483 3044 SynTP - ok
06:14:44.0530 3044 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
06:14:44.0546 3044 SysMain - ok
06:14:44.0561 3044 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
06:14:44.0561 3044 TabletInputService - ok
06:14:44.0608 3044 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
06:14:44.0608 3044 TapiSrv - ok
06:14:44.0639 3044 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
06:14:44.0639 3044 TBS - ok
06:14:44.0702 3044 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
06:14:44.0702 3044 Tcpip - ok
06:14:44.0717 3044 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
06:14:44.0733 3044 Tcpip6 - ok
06:14:44.0749 3044 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
06:14:44.0749 3044 tcpipreg - ok
06:14:44.0780 3044 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
06:14:44.0780 3044 TDPIPE - ok
06:14:44.0795 3044 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
06:14:44.0795 3044 TDTCP - ok
06:14:44.0827 3044 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
06:14:44.0827 3044 tdx - ok
06:14:44.0873 3044 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
06:14:44.0889 3044 TermDD - ok
06:14:44.0920 3044 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
06:14:44.0920 3044 TermService - ok
06:14:44.0951 3044 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
06:14:44.0951 3044 Themes - ok
06:14:44.0967 3044 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
06:14:44.0967 3044 THREADORDER - ok
06:14:44.0998 3044 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
06:14:45.0014 3044 TrkWks - ok
06:14:45.0061 3044 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
06:14:45.0061 3044 TrustedInstaller - ok
06:14:45.0092 3044 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
06:14:45.0092 3044 tssecsrv - ok
06:14:45.0107 3044 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
06:14:45.0123 3044 tunmp - ok
06:14:45.0154 3044 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
06:14:45.0154 3044 tunnel - ok
06:14:45.0170 3044 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
06:14:45.0170 3044 uagp35 - ok
06:14:45.0217 3044 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
06:14:45.0232 3044 udfs - ok
06:14:45.0263 3044 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
06:14:45.0279 3044 UI0Detect - ok
06:14:45.0279 3044 UIUSys - ok
06:14:45.0310 3044 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
06:14:45.0310 3044 uliagpkx - ok
06:14:45.0341 3044 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
06:14:45.0341 3044 uliahci - ok
06:14:45.0357 3044 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
06:14:45.0373 3044 UlSata - ok
06:14:45.0388 3044 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
06:14:45.0388 3044 ulsata2 - ok
06:14:45.0404 3044 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
06:14:45.0404 3044 umbus - ok
06:14:45.0435 3044 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
06:14:45.0435 3044 upnphost - ok
06:14:45.0482 3044 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
06:14:45.0482 3044 usbccgp - ok
06:14:45.0529 3044 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
06:14:45.0529 3044 usbcir - ok
06:14:45.0560 3044 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
06:14:45.0560 3044 usbehci - ok
06:14:45.0591 3044 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
06:14:45.0591 3044 usbhub - ok
06:14:45.0622 3044 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
06:14:45.0622 3044 usbohci - ok
06:14:45.0653 3044 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
06:14:45.0653 3044 usbprint - ok
06:14:45.0685 3044 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
06:14:45.0685 3044 usbscan - ok
06:14:45.0716 3044 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
06:14:45.0716 3044 USBSTOR - ok
06:14:45.0747 3044 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
06:14:45.0747 3044 usbuhci - ok
06:14:45.0778 3044 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
06:14:45.0778 3044 usbvideo - ok
06:14:45.0825 3044 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
06:14:45.0825 3044 UxSms - ok
06:14:45.0856 3044 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
06:14:45.0856 3044 vds - ok
06:14:45.0887 3044 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
06:14:45.0887 3044 vga - ok
06:14:45.0903 3044 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
06:14:45.0903 3044 VgaSave - ok
06:14:45.0919 3044 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
06:14:45.0919 3044 viaagp - ok
06:14:45.0950 3044 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
06:14:45.0965 3044 ViaC7 - ok
Naposledy upravil(a) JANíčOK dne 14 pro 2012 06:20, celkem upraveno 1 x.

JANíčOK
Level 3
Level 3
Příspěvky: 471
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod JANíčOK » 14 pro 2012 06:18

06:14:45.0981 3044 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
06:14:45.0981 3044 viaide - ok
06:14:46.0012 3044 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
06:14:46.0012 3044 volmgr - ok
06:14:46.0043 3044 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
06:14:46.0059 3044 volmgrx - ok
06:14:46.0090 3044 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
06:14:46.0090 3044 volsnap - ok
06:14:46.0121 3044 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
06:14:46.0121 3044 vsmraid - ok
06:14:46.0168 3044 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
06:14:46.0199 3044 VSS - ok
06:14:46.0231 3044 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
06:14:46.0231 3044 W32Time - ok
06:14:46.0262 3044 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
06:14:46.0262 3044 WacomPen - ok
06:14:46.0293 3044 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
06:14:46.0293 3044 Wanarp - ok
06:14:46.0309 3044 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
06:14:46.0309 3044 Wanarpv6 - ok
06:14:46.0340 3044 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
06:14:46.0340 3044 wcncsvc - ok
06:14:46.0371 3044 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
06:14:46.0371 3044 WcsPlugInService - ok
06:14:46.0387 3044 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
06:14:46.0387 3044 Wd - ok
06:14:46.0433 3044 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
06:14:46.0433 3044 Wdf01000 - ok
06:14:46.0465 3044 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
06:14:46.0465 3044 WdiServiceHost - ok
06:14:46.0480 3044 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
06:14:46.0496 3044 WdiSystemHost - ok
06:14:46.0527 3044 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
06:14:46.0543 3044 WebClient - ok
06:14:46.0574 3044 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
06:14:46.0574 3044 Wecsvc - ok
06:14:46.0605 3044 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
06:14:46.0605 3044 wercplsupport - ok
06:14:46.0652 3044 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
06:14:46.0652 3044 WerSvc - ok
06:14:46.0714 3044 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
06:14:46.0714 3044 WinDefend - ok
06:14:46.0730 3044 WinHttpAutoProxySvc - ok
06:14:46.0777 3044 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
06:14:46.0777 3044 Winmgmt - ok
06:14:46.0839 3044 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
06:14:46.0855 3044 WinRM - ok
06:14:46.0917 3044 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
06:14:46.0933 3044 Wlansvc - ok
06:14:46.0995 3044 [ DE83AD216C71D31AC6ECFBDCF058F1BD ] wltrysvc C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
06:14:46.0995 3044 wltrysvc - ok
06:14:47.0026 3044 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
06:14:47.0026 3044 WmiAcpi - ok
06:14:47.0073 3044 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
06:14:47.0073 3044 wmiApSrv - ok
06:14:47.0135 3044 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
06:14:47.0151 3044 WMPNetworkSvc - ok
06:14:47.0167 3044 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
06:14:47.0182 3044 WPCSvc - ok
06:14:47.0213 3044 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
06:14:47.0229 3044 WPDBusEnum - ok
06:14:47.0260 3044 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
06:14:47.0260 3044 WpdUsb - ok
06:14:47.0354 3044 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
06:14:47.0369 3044 WPFFontCache_v0400 - ok
06:14:47.0385 3044 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
06:14:47.0385 3044 ws2ifsl - ok
06:14:47.0416 3044 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll
06:14:47.0416 3044 wscsvc - ok
06:14:47.0432 3044 WSearch - ok
06:14:47.0541 3044 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
06:14:47.0572 3044 wuauserv - ok
06:14:47.0619 3044 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
06:14:47.0619 3044 WudfPf - ok
06:14:47.0650 3044 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
06:14:47.0650 3044 WUDFRd - ok
06:14:47.0697 3044 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
06:14:47.0697 3044 wudfsvc - ok
06:14:47.0744 3044 [ 3D6641F3EC2FBE31205F8692D70A36B8 ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
06:14:47.0744 3044 yukonwlh - ok
06:14:47.0775 3044 ================ Scan global ===============================
06:14:47.0837 3044 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
06:14:47.0869 3044 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
06:14:47.0884 3044 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
06:14:47.0915 3044 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
06:14:47.0915 3044 [Global] - ok
06:14:47.0915 3044 ================ Scan MBR ==================================
06:14:47.0931 3044 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
06:14:48.0165 3044 \Device\Harddisk0\DR0 - ok
06:14:48.0165 3044 ================ Scan VBR ==================================
06:14:48.0165 3044 [ 9175687E71BAF1D8A5C7830AC8771950 ] \Device\Harddisk0\DR0\Partition1
06:14:48.0165 3044 \Device\Harddisk0\DR0\Partition1 - ok
06:14:48.0181 3044 [ 2656CBCB42881CFA19F55BCF9A38D45F ] \Device\Harddisk0\DR0\Partition2
06:14:48.0181 3044 \Device\Harddisk0\DR0\Partition2 - ok
06:14:48.0181 3044 ============================================================
06:14:48.0181 3044 Scan finished
06:14:48.0181 3044 ============================================================
06:14:48.0212 3248 Detected object count: 0
06:14:48.0212 3248 Actual detected object count: 0
06:14:52.0720 1912 Deinitialize success

JANíčOK
Level 3
Level 3
Příspěvky: 471
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod JANíčOK » 14 pro 2012 06:41

Posielam log z ComboFix-u:

ComboFix 12-12-13.02 - Adakar s.r.o . 12. 2012 6:24.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.421.1051.18.1976.1022 [GMT 1:00]
Running from: c:\users\Adakar s.r.o\Desktop\ComboFix.exe
AV: ESET Smart Security 5.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Adakar s.r.o\AppData\Roaming\Microsoft\Windows\Recent\východ.docx
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\drivers\npf.sys
.
Infected copy of c:\windows\system32\samsrv.dll was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6002.18005_none_b3d9d2699e1659b0\samsrv.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-11-14 to 2012-12-14 )))))))))))))))))))))))))))))))
.
.
2012-12-13 13:37 . 2012-12-13 13:37 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\Google
2012-12-13 13:29 . 2012-12-13 13:29 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\ESET
2012-12-13 13:28 . 2012-12-13 13:28 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\Broadcom
2012-12-13 07:26 . 2012-12-13 07:26 388096 ----a-r- c:\users\Adakar s.r.o\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-12-13 07:26 . 2012-12-13 07:26 -------- d-----w- c:\program files\Trend Micro
2012-12-13 07:15 . 2012-12-13 07:15 -------- d-----w- c:\users\Adakar s.r.o\AppData\Roaming\Malwarebytes
2012-12-13 07:15 . 2012-12-13 07:15 -------- d-----w- c:\programdata\Malwarebytes
2012-12-13 07:14 . 2012-12-13 07:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-12-13 07:14 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-13 06:21 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-12-13 06:20 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-12-13 06:20 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-12-13 06:20 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
2012-12-13 06:20 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-12-13 06:20 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-12-13 06:20 . 2012-07-26 03:39 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-12-13 06:20 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-12-13 06:20 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2012-12-13 06:20 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-12-13 06:20 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2012-12-12 16:54 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D1B0AF2D-76BD-4D4B-BC24-1C0DBA34C68B}\mpengine.dll
2012-12-12 16:54 . 2012-11-13 01:36 2048000 ----a-w- c:\windows\system32\win32k.sys
2012-12-12 16:54 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
2012-12-12 16:54 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2012-12-12 16:54 . 2012-08-21 11:47 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2012-12-12 16:54 . 2012-11-08 03:46 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-12 16:54 . 2012-11-08 01:36 293376 ----a-w- c:\windows\system32\atmfd.dll
2012-12-12 16:54 . 2012-11-13 01:29 2048 ----a-w- c:\windows\system32\tzres.dll
2012-12-04 09:16 . 2012-12-05 18:39 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\NFS Underground 2
2012-11-15 20:53 . 2012-09-25 16:19 75776 ----a-w- c:\windows\system32\synceng.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-13 07:43 . 2012-11-13 12:34 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-13 07:43 . 2012-11-13 12:34 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-01 01:04 . 2012-11-01 01:04 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-01 01:04 . 2012-11-01 01:04 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-01 01:04 . 2012-11-01 01:04 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-01 01:04 . 2012-11-01 01:04 161792 ----a-w- c:\windows\system32\msls31.dll
2012-11-01 01:04 . 2012-11-01 01:04 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-01 01:04 . 2012-11-01 01:04 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-11-01 01:04 . 2012-11-01 01:04 367104 ----a-w- c:\windows\system32\html.iec
2012-11-01 01:04 . 2012-11-01 01:04 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-11-01 01:04 . 2012-11-01 01:04 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-01 01:04 . 2012-11-01 01:04 152064 ----a-w- c:\windows\system32\wextract.exe
2012-11-01 01:04 . 2012-11-01 01:04 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-11-01 01:04 . 2012-11-01 01:04 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-11-01 01:04 . 2012-11-01 01:04 11776 ----a-w- c:\windows\system32\mshta.exe
2012-11-01 01:04 . 2012-11-01 01:04 101888 ----a-w- c:\windows\system32\admparse.dll
2012-11-01 01:04 . 2012-11-01 01:04 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-01-31 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-06-04 1791272]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-10 145944]
"lxbkbmgr.exe"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2008-02-28 74408]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-10 150040]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2010-01-08 186904]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-10 170520]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-12-11 1310720]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 3117344]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-8-11 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2010-06-17 11:40 3488256 ----a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-07-31 11:20 38872 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2011-03-09 15:42 4367360 ----a-w- c:\program files\Broadcom\Broadcom 802.11\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2011-01-24 10:42 427008 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2011-01-31 19:24 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-12-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-13 07:43]
.
2012-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-31 19:24]
.
2012-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-31 19:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 4.4.4.4 8.8.8.8
FF - ProfilePath - c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=16621&l=dis&gct=hp
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 2233703&q=
FF - Ext: Anti-Banner: KavAntiBanner@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
FF - Ext: Kaspersky URL poradce: linkfilter@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - %profile%\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-12-14 06:35
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(2264)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Hpservice.exe
c:\program files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
c:\program files\Broadcom\Broadcom 802.11\bcmwltry.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\AEADISRV.EXE
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\ESET\ESET Smart Security\ekrn.exe
c:\windows\system32\lxbkcoms.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\windows\system32\conime.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Lexmark X1100 Series\lxbkbmon.exe
c:\program files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
c:\program files\Hewlett-Packard\Shared\hpqToaster.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2012-12-14 06:39:41 - machine was rebooted
ComboFix-quarantined-files.txt 2012-12-14 05:39
.
Pre-Run: 3 717 103 616 bytes free
Post-Run: 3 516 325 888 bytes free
.
- - End Of File - - C37D3BC3EBF5E10E3B105BBA6581C679

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod jaro3 » 14 pro 2012 10:11

Odinstaluj:
Spybot
od Kaspersky taky , pokud najdeš.

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
File::
c:\program files\Spybot - Search & Destroy\SDWinSec.exe

Folder::
c:\program files\Spybot - Search & Destroy

Firefox::
FF - ProfilePath - c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com?o=16621&l=dis&gct=hp
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 2233703&q=
FF - Ext: Anti-Banner: KavAntiBanner@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
FF - Ext: Kaspersky URL poradce: linkfilter@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - %profile%\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}



RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

JANíčOK
Level 3
Level 3
Příspěvky: 471
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod JANíčOK » 14 pro 2012 13:07

ComboFix 12-12-13.02 - Adakar s.r.o . 12. 2012 11:52:56.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.421.1051.18.1976.749 [GMT 1:00]
Running from: c:\users\Adakar s.r.o\Desktop\ComboFix.exe
Command switches used :: c:\users\Adakar s.r.o\Desktop\CFScript.txt
AV: ESET Smart Security 5.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\Spybot - Search & Destroy\SDWinSec.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\content\ffjcext\ffjcext.js
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\content\ffjcext\ffjcext.xul
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\install.rdf
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\content\ffjcext\ffjcext.js
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\content\ffjcext\ffjcext.xul
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext\ffjcext.dtd
c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\install.rdf
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\components\abhelperxpcom.dll
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\components\comp.xpt
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\content\firefoxOverlay.xul
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\content\kavab.png
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\content\Loger.js
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\content\overlay.js
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\chrome.manifest
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\install.rdf
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\locale\cs\kavab.dtd
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\locale\en\kavab.dtd
c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\skin\overlay.css
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\components\comp.xpt
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\components\kavlinkfilter.dll
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\data.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\fflinkfilter.png
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\firefoxOverlay.xul
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\HighlightDocTimeObject.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\IKavFilteredLink.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\IKavLink.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\IKavLinkCollection.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\IKavLinkFilter.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\IKavLinkFilterListener.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\IKavLinkFilterSyncListener.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\IKavLinkFilterSyncObj.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\IKavLinkHighlightFilter.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\Loger.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\main.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\options.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\options.xul
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\overlay.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\content\TaskQueue.js
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\chrome.manifest
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\install.rdf
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\locale\cs\fflinkfilter.dtd
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\locale\en\fflinkfilter.dtd
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\skin\kbrd.png
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\skin\logo.png
c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\skin\overlay.css
c:\program files\Spybot - Search & Destroy
c:\program files\Spybot - Search & Destroy\advcheck.dll
c:\program files\Spybot - Search & Destroy\Help\Slovensky.Resident.chm
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\ConduitAutoCompleteSearch.js
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\ConduitAutoCompleteSearch.xpt
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\ConduitToolbar.idl
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\ConduitToolbar.js
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\ConduitToolbar.xpt
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\FFExternalAlert.dll
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\FFExternalAlert.xpt
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\RadioWMPCore.dll
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\RadioWMPCore.xpt
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\defaults\default_radio_skin.xml
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\defaults\fbAlert.js
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\chrome.manifest
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\chrome\4shared.com.jar
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\install.rdf
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\lib\xpcom.js
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\META-INF\manifest.mf
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\META-INF\zigbert.rsa
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\META-INF\zigbert.sf
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\searchplugin\conduit.gif
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\searchplugin\conduit.ico
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\searchplugin\conduit.PNG
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\searchplugin\conduit.src
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\searchplugin\conduit.xml
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\setup.ini
c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\version.txt
.
.
((((((((((((((((((((((((( Files Created from 2012-11-14 to 2012-12-14 )))))))))))))))))))))))))))))))
.
.
2012-12-14 11:03 . 2012-12-14 11:05 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\temp
2012-12-14 11:03 . 2012-12-14 11:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-12-14 10:46 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E8289279-91D5-42F5-AB31-E46978D11468}\mpengine.dll
2012-12-13 13:37 . 2012-12-13 13:37 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\Google
2012-12-13 13:29 . 2012-12-13 13:29 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\ESET
2012-12-13 13:28 . 2012-12-13 13:28 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\Broadcom
2012-12-13 07:26 . 2012-12-13 07:26 388096 ----a-r- c:\users\Adakar s.r.o\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-12-13 07:26 . 2012-12-13 07:26 -------- d-----w- c:\program files\Trend Micro
2012-12-13 07:15 . 2012-12-13 07:15 -------- d-----w- c:\users\Adakar s.r.o\AppData\Roaming\Malwarebytes
2012-12-13 07:15 . 2012-12-13 07:15 -------- d-----w- c:\programdata\Malwarebytes
2012-12-13 07:14 . 2012-12-13 07:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-12-13 07:14 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-13 06:21 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-12-13 06:20 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-12-13 06:20 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-12-13 06:20 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
2012-12-13 06:20 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-12-13 06:20 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-12-13 06:20 . 2012-07-26 03:39 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-12-13 06:20 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-12-13 06:20 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2012-12-13 06:20 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-12-13 06:20 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2012-12-12 16:54 . 2012-11-13 01:36 2048000 ----a-w- c:\windows\system32\win32k.sys
2012-12-12 16:54 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
2012-12-12 16:54 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2012-12-12 16:54 . 2012-08-21 11:47 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2012-12-12 16:54 . 2012-11-08 03:46 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-12 16:54 . 2012-11-08 01:36 293376 ----a-w- c:\windows\system32\atmfd.dll
2012-12-12 16:54 . 2012-11-13 01:29 2048 ----a-w- c:\windows\system32\tzres.dll
2012-12-04 09:16 . 2012-12-05 18:39 -------- d-----w- c:\users\Adakar s.r.o\AppData\Local\NFS Underground 2
2012-11-15 20:53 . 2012-09-25 16:19 75776 ----a-w- c:\windows\system32\synceng.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-13 07:43 . 2012-11-13 12:34 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-13 07:43 . 2012-11-13 12:34 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-01 01:04 . 2012-11-01 01:04 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-01 01:04 . 2012-11-01 01:04 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-01 01:04 . 2012-11-01 01:04 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-01 01:04 . 2012-11-01 01:04 161792 ----a-w- c:\windows\system32\msls31.dll
2012-11-01 01:04 . 2012-11-01 01:04 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-01 01:04 . 2012-11-01 01:04 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-11-01 01:04 . 2012-11-01 01:04 367104 ----a-w- c:\windows\system32\html.iec
2012-11-01 01:04 . 2012-11-01 01:04 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-11-01 01:04 . 2012-11-01 01:04 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-01 01:04 . 2012-11-01 01:04 152064 ----a-w- c:\windows\system32\wextract.exe
2012-11-01 01:04 . 2012-11-01 01:04 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-11-01 01:04 . 2012-11-01 01:04 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-11-01 01:04 . 2012-11-01 01:04 11776 ----a-w- c:\windows\system32\mshta.exe
2012-11-01 01:04 . 2012-11-01 01:04 101888 ----a-w- c:\windows\system32\admparse.dll
2012-11-01 01:04 . 2012-11-01 01:04 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-01-31 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-06-04 1791272]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-10 145944]
"lxbkbmgr.exe"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2008-02-28 74408]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-10 150040]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2010-01-08 186904]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-10 170520]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-12-11 1310720]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 3117344]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-8-11 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2010-06-17 11:40 3488256 ----a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-07-31 11:20 38872 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2011-03-09 15:42 4367360 ----a-w- c:\program files\Broadcom\Broadcom 802.11\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2011-01-24 10:42 427008 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2011-01-31 19:24 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-12-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-13 07:43]
.
2012-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-31 19:24]
.
2012-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-31 19:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 4.4.4.4 8.8.8.8
FF - ProfilePath - c:\users\Adakar s.r.o\AppData\Roaming\Mozilla\Firefox\Profiles\i9spxs7c.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-12-14 12:05
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(6052)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Hpservice.exe
c:\windows\system32\WLANExt.exe
c:\program files\Broadcom\Broadcom 802.11\bcmwltry.exe
c:\windows\system32\AEADISRV.EXE
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\ESET\ESET Smart Security\ekrn.exe
c:\windows\system32\lxbkcoms.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Lexmark X1100 Series\lxbkbmon.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\program files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
c:\program files\Hewlett-Packard\Shared\hpqToaster.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2012-12-14 12:14:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-12-14 11:14
ComboFix2.txt 2012-12-14 05:39
.
Pre-Run: 3 712 774 144 bytes free
Post-Run: 3 564 679 168 bytes free
.
- - End Of File - - DF13DA8C9D7819139FE20299CE0719A7

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod jaro3 » 14 pro 2012 21:35

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.


V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\windows\system32\samsrv.dll

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/

vlož nový log z HJT+ info o problémech.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

JANíčOK
Level 3
Level 3
Příspěvky: 471
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod JANíčOK » 19 pro 2012 13:57

Posielam log z aswMBR:

aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-19 13:53:21
-----------------------------
13:53:21.396 OS Version: Windows 6.0.6002 Service Pack 2
13:53:21.396 Number of processors: 2 586 0xF0D
13:53:21.396 ComputerName: ADAKARSRO-PC UserName: Adakar s.r.o
13:54:30.145 Initialize success
13:54:39.248 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
13:54:39.248 Disk 0 Vendor: TOSHIBA_ LV01 Size: 238475MB BusType: 3
13:54:39.264 Disk 0 MBR read successfully
13:54:39.264 Disk 0 MBR scan
13:54:39.264 Disk 0 Windows VISTA default MBR code
13:54:39.279 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 38474 MB offset 2048
13:54:39.295 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 199999 MB offset 78796800
13:54:39.311 Disk 0 scanning sectors +488394752
13:54:39.451 Disk 0 scanning C:\Windows\system32\drivers
13:54:49.295 Service scanning
13:55:13.397 Modules scanning
13:55:39.636 Disk 0 trace - called modules:
13:55:39.667 ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys hal.dll acpi.sys iaStor.sys
13:55:39.667 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8d040ac8]
13:55:39.683 3 CLASSPNP.SYS[8efa78b3] -> nt!IofCallDriver -> [0x8cb58520]
13:55:39.698 5 hpdskflt.sys[8ef89f92] -> nt!IofCallDriver -> [0x8bfe5208]
13:55:39.698 7 acpi.sys[806a66bc] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8c04f028]
13:55:39.714 Scan finished successfully
13:56:22.952 Disk 0 MBR has been saved successfully to "C:\Users\Adakar s.r.o\Desktop\MBR.dat"
13:56:22.984 The log file has been saved successfully to "C:\Users\Adakar s.r.o\Desktop\aswMBR.txt"

JANíčOK
Level 3
Level 3
Příspěvky: 471
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - notebook HP 6730s

Příspěvekod JANíčOK » 19 pro 2012 14:06

Tu je výsledok testu z VirusTotal.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 31 hostů