Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
morphus
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 26 led 2010 23:05

Prosím o kontrolu logu

#1 Příspěvek od morphus »

Zdravím, prosím o kontrolu logu. PC bylo zavirováno, vyčistil jsem ho a prosil bych o kontrolu, zdali už je vše ok :).

Díky :thumbsup:

Tady je ten log, úplně jsem na něj zapomněl :D

PC bylo léčeno combofix, mwba,kis.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Josef Dolansky at 2011-10-14 15:09:19
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 95 GB (62%) free of 153 GB
Total RAM: 1015 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:09:21, on 14.10.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\TightVNC\tvnserver.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtblfs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Documents and Settings\Josef Dolansky\Local Settings\Temporary Internet Files\Content.IE5\KMWQ0W7A\RSIT[1].exe
C:\Program Files\trend micro\Josef Dolansky.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\listicka.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Nástroje Lištičky - {1EA00BE1-6E54-4E2A-8099-680300BF23E1} - C:\Program Files\Seznam.cz\toolbar\toolbar.dll
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [tvncontrol] "C:\Program Files\TightVNC\tvnserver.exe" -controlservice -slave
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Akcelerátor spuštění AutoCADu.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: K&ontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TightVNC Server (tvnserver) - GlavSoft LLC. - C:\Program Files\TightVNC\tvnserver.exe
O23 - Service: User Profile Hive Cleanup (UPHClean) - Windows (R) Codename Longhorn DDK provider - C:\Program Files\UPHClean\uphclean.exe

--
End of file - 12621 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{548CF3DE-523A-494F-A758-7A7DC2482DFD}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{704311D2-9A90-44B7-B7AF-AA7A3EB9A8B3}.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Josef Dolansky\Data aplikací\Mozilla\Firefox\Profiles\sl02c8xp.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {7AB6D133-2A14-4C11-B3AD-35B1548D38F9}:1.0, {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}:7.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"linkfilter@kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru
"virtualKeyboard@kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
"KavAntiBanner@Kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nexon.net/NxGame]
"Description"=Nexon Game Controller
"Path"=C:\Documents and Settings\All Users\Data aplikací\NexonUS\NGM\npNxGameUS.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0]
"Description"=BlackBerry Web Software Loading Helper Plug-In for Mozilla browsers
"Path"=C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll

C:\Program Files\Mozilla Firefox\extensions\
{7AB6D133-2A14-4C11-B3AD-35B1548D38F9}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat

C:\Program Files\Mozilla Firefox\plugins\
np32dsw.dll
npdeployJava1.dll
npnul32.dll
NPOFF12.DLL
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nsIQTScriptablePlugin.xpt
QuickTimePlugin.class
ShockwavePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Josef Dolansky\Data aplikací\Mozilla\Firefox\Profiles\sl02c8xp.default\extensions\
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
{20a82645-c095-46ed-80e3-08825760534b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll [2011-04-24 86416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
AcroIEToolbarHelper Class - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F}]
PDF-XChange Viewer IE-Plugin - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll [2008-08-31 1099032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-10-13 56712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll [2011-04-24 229776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Program Files\Seznam.cz\listicka.dll [2010-10-07 1961240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-07 187672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-09-30 155648]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-03-21 69632]
"Sunkist2k"=C:\Program Files\Multimedia Card Reader\shwicon2k.exe [2004-08-06 135168]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-03-24 1983816]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2008-09-19 236016]
"tvncontrol"=C:\Program Files\TightVNC\tvnserver.exe [2010-07-08 815704]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-05-04 252136]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2005-09-20 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2005-09-20 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2005-09-20 114688]
"SoundMAXPnP"=C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [2004-10-14 1388544]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2004-09-23 860160]
"RIMBBLaunchAgent.exe"=C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [2011-02-18 79192]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-04-24 202296]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2010-07-04 17408]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NCLaunch"=C:\WINDOWS\NCLAUNCH.EXe [2009-12-30 65536]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-10-09 139264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2006-10-30 256576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2010-06-24 247144]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-C740-7760-100000000002}\SC_Acrobat.exe
Akcelerátor spuštění AutoCADu.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
VPN Client.lnk - C:\WINDOWS\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-09-20 135168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2011-04-24 229776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe"="C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======File associations======

.scr - open - "C:\WINDOWS\system32\notepad.exe" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2011-10-14 15:01:41 ----D---- C:\Program Files\Unlocker
2011-10-14 14:58:39 ----D---- C:\rsit
2011-10-14 14:58:39 ----D---- C:\Program Files\trend micro
2011-10-14 14:39:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-10-14 14:39:17 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2011-10-14 14:38:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2011-10-14 10:08:48 ----A---- C:\WINDOWS\system32\default_user_class.dat
2011-10-14 09:30:53 ----A---- C:\WINDOWS\system32\drivers\klin.dat
2011-10-14 09:30:53 ----A---- C:\WINDOWS\system32\drivers\klick.dat
2011-10-14 09:28:21 ----D---- C:\Program Files\Kaspersky Lab
2011-10-14 09:28:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab
2011-10-14 09:27:53 ----A---- C:\WINDOWS\system32\drivers\klif.sys
2011-10-14 09:12:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2011-10-14 09:12:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2011-10-14 09:12:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2011-10-14 09:12:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676-v2$
2011-10-14 09:12:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-10-14 09:12:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-10-14 09:12:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-10-14 09:11:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-10-14 09:11:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-10-14 09:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-10-14 09:11:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-10-14 09:11:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-10-14 09:11:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-10-14 09:10:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-10-14 09:10:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893$
2011-10-14 09:09:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-10-14 09:09:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-10-14 09:09:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-10-14 09:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-10-14 09:08:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-10-14 09:08:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-10-14 09:08:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2011-10-14 09:08:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-10-14 09:08:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2011-10-14 09:08:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-10-14 09:07:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-10-14 09:07:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-10-14 09:07:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-10-14 09:07:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-10-14 09:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-10-14 09:06:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-10-14 09:06:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-10-14 09:06:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2011-10-14 09:06:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2011-10-14 09:06:16 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-10-14 09:06:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-10-14 09:05:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-10-14 09:05:40 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-10-14 09:05:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-10-14 09:05:17 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-10-14 09:05:10 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2011-10-14 09:05:01 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2011-10-14 09:04:54 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2011-10-14 09:04:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2011-10-14 09:04:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-10-14 09:04:29 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2011-10-14 09:04:22 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-10-14 09:04:06 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-10-14 09:03:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-10-14 09:03:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-10-14 09:03:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-10-14 09:03:32 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-10-14 09:03:24 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2011-10-14 09:03:17 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-10-14 09:03:09 ----D---- C:\WINDOWS\system32\DRM
2011-10-14 09:02:54 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-10-14 09:02:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-10-14 09:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2011-10-14 09:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2011-10-14 09:02:18 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2011-10-14 09:02:09 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2011-10-14 09:02:01 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2011-10-14 09:01:48 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2011-10-14 09:01:36 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2011-10-14 09:01:28 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2011-10-14 09:01:19 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2011-10-14 09:01:06 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2011-10-14 09:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2011-10-14 09:00:50 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2011-10-14 09:00:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2011-10-14 09:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2011-10-14 09:00:22 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2011-10-14 09:00:15 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2011-10-14 09:00:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2011-10-14 08:59:56 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2011-10-14 08:59:45 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2011-10-14 08:59:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2011-10-14 08:59:19 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2011-10-14 08:59:12 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2011-10-14 08:59:02 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2011-10-14 08:58:50 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2011-10-14 08:58:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2011-10-14 08:58:25 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2011-10-14 08:58:00 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2011-10-14 08:57:53 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2011-10-14 08:57:45 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2011-10-14 08:57:38 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2011-10-14 08:57:32 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2011-10-14 08:57:24 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2011-10-14 08:57:17 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2011-10-14 08:57:10 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2011-10-14 08:57:01 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2011-10-14 08:56:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2011-10-14 08:56:48 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2011-10-14 08:55:20 ----N---- C:\WINDOWS\system32\spmsg.dll
2011-10-14 08:55:19 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2011-10-14 08:53:16 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2011-10-14 08:39:01 ----A---- C:\WINDOWS\system32\wups2.dll
2011-10-14 08:33:48 ----D---- C:\Program Files\Seznam.cz
2011-10-14 08:30:18 ----SHD---- C:\RECYCLER
2011-10-14 07:51:38 ----D---- C:\Documents and Settings\Josef Dolansky\Data aplikací\ElevatedDiagnostics
2011-10-14 07:50:39 ----D---- C:\WINDOWS\system32\windowspowershell
2011-10-14 07:50:30 ----HDC---- C:\WINDOWS\$NtUninstallKB926139-v2$
2011-10-14 07:44:59 ----D---- C:\Program Files\Windows Resource Kits
2011-10-14 07:32:05 ----D---- C:\Program Files\UPHClean
2011-10-14 07:18:30 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2011-10-14 07:15:00 ----A---- C:\WINDOWS\ntbtlog.txt
2011-10-13 22:33:42 ----ASH---- C:\pagefile.sys
2011-10-13 21:30:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Research In Motion
2011-10-13 21:19:13 ----A---- C:\WINDOWS\system32\drivers\MidiSyn.sys
2011-10-13 21:18:36 ----A---- C:\WINDOWS\system32\drivers\senfilt.sys
2011-10-13 21:18:36 ----A---- C:\WINDOWS\system32\drivers\aeaudio.sys
2011-10-13 21:18:34 ----A---- C:\WINDOWS\system32\wdmioctl.dll
2011-10-13 21:18:34 ----A---- C:\WINDOWS\system32\SMMedia.dll
2011-10-13 21:18:32 ----D---- C:\WINDOWS\VirtualEar
2011-10-13 21:18:32 ----A---- C:\WINDOWS\system32\virtear.dll
2011-10-13 21:18:32 ----A---- C:\WINDOWS\system32\drivers\smwdm.sys
2011-10-13 21:18:32 ----A---- C:\WINDOWS\system32\Audio3d.dll
2011-10-13 21:18:31 ----A---- C:\WINDOWS\system32\DSndUp.exe
2011-10-13 21:18:31 ----A---- C:\WINDOWS\system32\CleanUp.exe
2011-10-13 21:15:30 ----A---- C:\WINDOWS\system32\igfxres.dll
2011-10-13 21:11:59 ----D---- C:\WINDOWS\Prefetch
2011-10-13 20:59:05 ----A---- C:\WINDOWS\OEWABLog.txt
2011-10-13 20:46:56 ----A---- C:\WINDOWS\system32\irclass.dll
2011-10-13 20:46:55 ----A---- C:\WINDOWS\system32\spxcoins.dll
2011-10-13 20:46:28 ----RA---- C:\WINDOWS\SET1F7.tmp
2011-10-13 20:46:20 ----RA---- C:\WINDOWS\SET1EB.tmp
2011-10-13 20:46:17 ----RA---- C:\WINDOWS\SET1E8.tmp
2011-10-13 20:44:28 ----A---- C:\WINDOWS\setuplog.txt
2011-10-13 18:24:14 ----D---- C:\Program Files\jv16 PowerTools 2011
2011-10-13 16:51:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2011-10-13 16:50:47 ----A---- C:\WINDOWS\system32\javaws.exe
2011-10-13 16:50:47 ----A---- C:\WINDOWS\system32\javaw.exe
2011-10-13 16:50:47 ----A---- C:\WINDOWS\system32\java.exe
2011-10-13 16:50:47 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-10-13 15:57:09 ----D---- C:\Program Files\Soluto
2011-10-13 15:50:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Soluto
2011-10-13 10:17:49 ----D---- C:\Program Files\ASUS
2011-10-13 10:16:54 ----D---- C:\Program Files\Microsoft Bootvis
2011-10-13 09:04:54 ----A---- C:\WINDOWS\imsins.BAK
2011-10-13 08:05:39 ----D---- C:\Program Files\Windows Installer Clean Up
2011-10-13 08:05:04 ----D---- C:\Program Files\MSECACHE
2011-10-13 07:45:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2011-10-13 07:40:12 ----D---- C:\Program Files\Yamicsoft
2011-10-12 20:32:06 ----D---- C:\Program Files\Sophos
2011-10-12 19:36:42 ----A---- C:\TDSSKiller.2.6.8.0_12.10.2011_19.36.42_log.txt
2011-10-12 19:13:50 ----A---- C:\viry.txt
2011-10-12 15:03:51 ----A---- C:\Dolansky viry.txt
2011-10-11 20:01:59 ----A---- C:\ComboFix.txt
2011-10-11 19:36:46 ----D---- C:\WINDOWS\temp
2011-10-11 19:14:31 ----D---- C:\WINDOWS\ERDNT

======List of files/folders modified in the last 1 month======

2011-10-14 15:05:57 ----D---- C:\WINDOWS
2011-10-14 15:02:38 ----D---- C:\Program Files\Common Files
2011-10-14 15:02:20 ----RD---- C:\Program Files
2011-10-14 14:59:24 ----A---- C:\WINDOWS\wincmd.ini
2011-10-14 14:45:34 ----D---- C:\WINDOWS\system32\drivers
2011-10-14 14:44:36 ----D---- C:\WINDOWS\system32
2011-10-14 14:39:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-10-14 14:39:36 ----HD---- C:\WINDOWS\inf
2011-10-14 14:39:36 ----D---- C:\WINDOWS\system32\CatRoot
2011-10-14 14:39:34 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-10-14 14:36:34 ----SH---- C:\boot.ini
2011-10-14 14:36:34 ----A---- C:\WINDOWS\system.ini
2011-10-14 14:36:30 ----A---- C:\WINDOWS\win.ini
2011-10-14 14:29:33 ----D---- C:\WINDOWS\system32\CatRoot2
2011-10-14 14:24:24 ----D---- C:\WINDOWS\Microsoft.NET
2011-10-14 10:07:00 ----D---- C:\Documents and Settings\Josef Dolansky\Data aplikací\Research In Motion
2011-10-14 09:33:40 ----SHD---- C:\System Volume Information
2011-10-14 09:31:00 ----SHD---- C:\WINDOWS\Installer
2011-10-14 09:30:56 ----D---- C:\Config.Msi
2011-10-14 09:27:26 ----A---- C:\WINDOWS\AS_Debug.txt
2011-10-14 09:20:44 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-10-14 09:19:58 ----D---- C:\Ovladače
2011-10-14 09:14:22 ----D---- C:\WINDOWS\AppPatch
2011-10-14 09:14:21 ----D---- C:\WINDOWS\system32\wbem
2011-10-14 09:06:51 ----D---- C:\Program Files\Outlook Express
2011-10-14 09:06:36 ----D---- C:\Program Files\Internet Explorer
2011-10-14 09:06:33 ----HD---- C:\WINDOWS\$hf_mig$
2011-10-14 09:05:06 ----D---- C:\Program Files\Movie Maker
2011-10-14 08:55:04 ----D---- C:\Program Files\Windows Media Player
2011-10-14 08:55:01 ----D---- C:\WINDOWS\Help
2011-10-14 08:39:05 ----D---- C:\WINDOWS\SoftwareDistribution
2011-10-14 08:38:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-10-14 08:38:19 ----SD---- C:\WINDOWS\Tasks
2011-10-14 08:34:55 ----D---- C:\WINDOWS\system32\config
2011-10-14 08:34:49 ----D---- C:\WINDOWS\system32\cs-cz
2011-10-14 08:33:55 ----HD---- C:\WINDOWS\msdownld.tmp
2011-10-14 08:33:18 ----HDC---- C:\WINDOWS\ie8
2011-10-14 07:50:45 ----RSD---- C:\WINDOWS\assembly
2011-10-14 07:30:05 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-10-13 22:40:10 ----D---- C:\WINDOWS\system32\Setup
2011-10-13 22:40:01 ----D---- C:\WINDOWS\l2schemas
2011-10-13 22:40:00 ----D---- C:\WINDOWS\system32\usmt
2011-10-13 22:39:49 ----D---- C:\WINDOWS\ime
2011-10-13 22:39:48 ----RSD---- C:\WINDOWS\Fonts
2011-10-13 22:39:47 ----D---- C:\WINDOWS\network diagnostic
2011-10-13 22:39:47 ----D---- C:\WINDOWS\Media
2011-10-13 22:39:31 ----D---- C:\WINDOWS\PeerNet
2011-10-13 22:39:15 ----D---- C:\WINDOWS\system32\npp
2011-10-13 22:39:07 ----D---- C:\WINDOWS\msagent
2011-10-13 22:39:02 ----D---- C:\WINDOWS\system32\cs
2011-10-13 22:36:04 ----D---- C:\WINDOWS\system32\1029
2011-10-13 22:35:49 ----D---- C:\WINDOWS\twain_32
2011-10-13 22:35:07 ----D---- C:\WINDOWS\system32\icsxml
2011-10-13 22:34:37 ----D---- C:\WINDOWS\system32\1033
2011-10-13 22:33:42 ----D---- C:\WINDOWS\Driver Cache
2011-10-13 21:32:18 ----D---- C:\Program Files\Common Files\Research In Motion
2011-10-13 21:30:19 ----D---- C:\WINDOWS\WinSxS
2011-10-13 21:29:57 ----D---- C:\Program Files\Research In Motion
2011-10-13 21:18:32 ----D---- C:\WINDOWS\system
2011-10-13 21:18:13 ----D---- C:\Program Files\Common Files\InstallShield
2011-10-13 21:17:08 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-10-13 21:15:36 ----D---- C:\WINDOWS\Registration
2011-10-13 21:13:47 ----D---- C:\WINDOWS\system32\Restore
2011-10-13 20:59:01 ----A---- C:\WINDOWS\ODBCINST.INI
2011-10-13 20:58:38 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2011-10-13 20:58:35 ----D---- C:\WINDOWS\system32\ias
2011-10-13 20:58:09 ----RD---- C:\WINDOWS\Web
2011-10-13 20:58:02 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2011-10-13 20:57:39 ----D---- C:\WINDOWS\system32\oobe
2011-10-13 20:57:21 ----D---- C:\WINDOWS\system32\Com
2011-10-13 20:47:26 ----D---- C:\WINDOWS\security
2011-10-13 20:46:40 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2011-10-13 16:51:45 ----D---- C:\Program Files\Common Files\Java
2011-10-13 16:49:22 ----D---- C:\Program Files\Java
2011-10-13 15:51:06 ----D---- C:\Program Files\Super DVD Copy
2011-10-13 15:20:58 ----D---- C:\WINDOWS\system32\LogFiles
2011-10-13 10:17:44 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-13 09:08:22 ----A---- C:\WINDOWS\system32\MRT.exe
2011-10-13 09:07:37 ----D---- C:\Program Files\Microsoft Office
2011-10-13 09:06:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-10-13 07:37:45 ----D---- C:\install
2011-10-13 07:37:35 ----D---- C:\WINDOWS\Debug
2011-10-13 07:37:34 ----D---- C:\WINDOWS\Minidump
2011-10-13 07:10:50 ----D---- C:\Program Files\CCleaner
2011-10-11 19:45:34 ----D---- C:\WINDOWS\system32\drivers\etc
2011-10-11 11:57:00 ----D---- C:\Program Files\TightVNC
2011-10-11 11:56:56 ----D---- C:\Program Files\TomTom HOME 2
2011-10-04 20:40:51 ----D---- C:\Program Files\Mozilla Firefox
2011-10-03 10:31:24 ----A---- C:\WINDOWS\system32\mshtml.dll
2011-10-02 20:01:32 ----A---- C:\WINDOWS\NeroDigital.ini
2011-09-26 11:41:42 ----A---- C:\WINDOWS\system32\uiautomationcore.dll
2011-09-26 11:41:42 ----A---- C:\WINDOWS\system32\oleaccrc.dll
2011-09-26 11:41:20 ----A---- C:\WINDOWS\system32\oleacc.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 KL1;kl1; C:\WINDOWS\system32\DRIVERS\kl1.sys [2011-03-04 133208]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-09-03 115680]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-05-01 43528]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kl2;kl2; C:\WINDOWS\system32\DRIVERS\kl2.sys [2011-03-04 11352]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2011-10-14 565552]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-09-03 54368]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 cpuz135;cpuz135; \??\C:\WINDOWS\system32\drivers\cpuz135_x32.sys []
R2 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
R2 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS []
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2005-03-04 127872]
R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2008-11-16 131984]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-09-20 1302332]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2011-03-10 34608]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2009-11-02 19472]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2009-01-09 27136]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2008-04-14 5888]
R3 senfilt;senfilt; C:\WINDOWS\system32\drivers\senfilt.sys [2005-03-01 392704]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2005-03-28 220992]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2005-04-01 230272]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys []
S3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\JOSEFD~1\LOCALS~1\Temp\catchme.sys []
S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 k510bus;Sony Ericsson K510 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\k510bus.sys [2007-12-26 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2007-12-26 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\k510mdm.sys [2007-12-26 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2007-12-26 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\k510obex.sys [2007-12-26 83344]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys []
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k750mdfl.sys []
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\k750mdm.sys []
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\k750mgmt.sys []
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\k750obex.sys []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\1.tmp []
S3 MidiSyn;MidiSyn; C:\WINDOWS\system32\drivers\MidiSyn.sys [2004-09-14 88960]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys []
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys []
S3 nmwcdcj;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys []
S3 nmwcdcm;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys []
S3 RimUsb;zařízení BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys []
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 SunkFilt6;Alcor Micro Corp - 6360; \??\C:\WINDOWS\System32\Drivers\sunkfilt6.sys []
S3 SunkFilt62;Alcor Micro Corp - 6362; \??\C:\WINDOWS\System32\Drivers\sunkfilt62.sys []
S3 Sunkfiltp;HP && Alcor Micro Corp for Phison; \??\C:\WINDOWS\System32\Drivers\sunkfiltp.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-04-24 202296]
R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2007-01-31 98304]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2010-09-27 1528616]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2011-10-13 161664]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-12-25 81920]
R2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2008-09-19 170480]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
R2 tvnserver;TightVNC Server; C:\Program Files\TightVNC\tvnserver.exe [2010-07-08 815704]
R2 UPHClean;User Profile Hive Cleanup; C:\Program Files\UPHClean\uphclean.exe [2010-09-13 399872]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2008-09-19 1108464]
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-12-07 362992]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2008-09-19 313840]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2008-10-02 85096]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2006-10-30 492608]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-12-07 88560]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2006-11-06 210432]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe []

-----------------EOF-----------------
Naposledy upravil(a) morphus dne 14 říj 2011 16:27, celkem upraveno 1 x.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

Jaksi jste log opomenul vlozit :?:

CIm bylo PC nakazeno a cim leceno :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

morphus
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 26 led 2010 23:05

Re: Prosím o kontrolu logu

#3 Příspěvek od morphus »

vyosek píše:Zdravim a pekny den preji :)

Jaksi jste log opomenul vlozit :?:

CIm bylo PC nakazeno a cim leceno :???:
Ještě napíši obsah virů:
Trojan-Dropper.Win32.Injector.jbp
Trojan-Downloader.JS.Iframe.cni
Backdoor.Win32.ZAccess.ang
Rootkit.Win32.ZAccess.g
HEUR:Trojan.Win32.Generic

Léčeno bylo jak jsem doplnil v předchozím příspěvku: combofix,mwba,kis :D

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#4 Příspěvek od vyosek »

:arrow: ComboFix se nepouziva bez doporuceni - vizte nize

:arrow: Nebezpeci CFka
  • Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
  • Maze stopy po haveti, takze v logu z RSIT neni nic videt
  • Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
  • CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
  • CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
:arrow: Poprosim o tyto logy
2011-10-12 19:36:42 ----A---- C:\TDSSKiller.2.6.8.0_12.10.2011_19.36.42_log.txt
2011-10-11 20:01:59 ----A---- C:\ComboFix.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

morphus
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 26 led 2010 23:05

Re: Prosím o kontrolu logu

#5 Příspěvek od morphus »

Combofix Log:
ComboFix 11-10-11.02 - ..... 11.10.2011 19:25:07.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.773 [GMT 2:00]
Spuštěný z:
AV: Aplikace Symantec Endpoint Protection *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\....\WINDOWS
C:\install.exe
c:\windows\$NtUninstallKB55719$
c:\windows\$NtUninstallKB55719$\2740726886
c:\windows\$NtUninstallKB55719$\981146659\@
c:\windows\$NtUninstallKB55719$\981146659\click.tlb
c:\windows\$NtUninstallKB55719$\981146659\L\rnuwjpsu
c:\windows\$NtUninstallKB55719$\981146659\loader.tlb
c:\windows\$NtUninstallKB55719$\981146659\U\@00000001
c:\windows\$NtUninstallKB55719$\981146659\U\@000000c0
c:\windows\$NtUninstallKB55719$\981146659\U\@000000cb
c:\windows\$NtUninstallKB55719$\981146659\U\@000000cf
c:\windows\$NtUninstallKB55719$\981146659\U\@80000000
c:\windows\$NtUninstallKB55719$\981146659\U\@800000c0
c:\windows\$NtUninstallKB55719$\981146659\U\@800000cb
c:\windows\$NtUninstallKB55719$\981146659\U\@800000cf
c:\windows\{2521BB91-29B1-4d7e-9137-AC9875D77735}
c:\windows\IsUn0405.exe
c:\windows\IsUn0407.exe
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\_000011_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\c_67380.nls
c:\windows\system32\d3d9caps.dat
c:\windows\WindowsUpdate.log
.
Nakažená kopie c:\windows\system32\drivers\mrxsmb.sys byla nalezena a vyléčena.
Obnovena kopie z - The cat found it :)
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_3a7b1c23
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-11 do 2011-10-11 )))))))))))))))))))))))))))))))
.
.
2011-10-11 17:18 . 2011-07-15 13:29 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-10-11 09:46 . 2011-10-11 09:46 -------- d-sh--w- c:\documents and settings\.....\Local Settings\Data aplikací\3a7b1c23
2011-09-28 18:40 . 2011-09-28 18:40 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2004-08-18 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-08-11 21:33 . 2011-08-11 21:33 1409 ----a-w- c:\windows\QTFont.for
2011-07-31 15:10 . 2011-06-25 09:10 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2011-07-31 15:10 . 2011-06-25 09:10 125488 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2009-12-30 65536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-09 149280]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2004-08-06 135168]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-24 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-09-21 615696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-09-19 236016]
"tvncontrol"="c:\program files\TightVNC\tvnserver.exe" [2010-07-08 815704]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2010-12-28 115560]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\....Nabídka Start\Programy\Po spuštění\
PowerReg Scheduler V3.exe [2007-2-25 225280]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-C740-7760-100000000002}\SC_Acrobat.exe [2007-1-9 25214]
Akcelerátor spuštění AutoCADu.lnk - c:\program files\Common Files\Autodesk Shared\acstart16.exe [2004-2-25 10872]
BlackBerry Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-9-21 1545488]
VPN Client.lnk - c:\windows\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico [2011-1-6 6144]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2006-10-30 08:36 256576 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 15:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-25 17:58 282624 ----a-w- c:\program files\QuickTime\qttask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-06-24 14:41 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Games\\Supreme\\Supreme.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\NexonUS\\NGM\\NGM.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\Program Files\\TightVNC\\tvnserver.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57224:TCP"= 57224:TCP:Pando Media Booster
"57224:UDP"= 57224:UDP:Pando Media Booster
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [31.7.2011 16:12 21992]
R2 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [14.3.2008 18:29 8064]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [24.6.2010 16:41 92008]
R2 tvnserver;TightVNC Server;c:\program files\TightVNC\tvnserver.exe [8.7.2010 15:28 815704]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [31.7.2011 16:41 105592]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [26.12.2007 12:32 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [26.12.2007 12:32 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [26.12.2007 12:32 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [26.12.2007 12:32 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [26.12.2007 12:32 83344]
S3 SunkFilt6;Alcor Micro Corp - 6360;\??\c:\windows\System32\Drivers\sunkfilt6.sys --> c:\windows\System32\Drivers\sunkfilt6.sys [?]
S3 SunkFilt62;Alcor Micro Corp - 6362;c:\windows\system32\drivers\sunkfilt62.sys [23.7.2004 14:55 46536]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-09-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 16:13]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mWindow Title = Microsoft Internet Explorer
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\documents and settings\....\Data aplikací\Mozilla\Firefox\Profiles\sl02c8xp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Sukoku: {7AB6D133-2A14-4C11-B3AD-35B1548D38F9} - c:\program files\Mozilla Firefox\extensions\{7AB6D133-2A14-4C11-B3AD-35B1548D38F9}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Garmin Communicator: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - %profile%\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
.
.
------- Asociace souborů -------
.
.scr=AutoCADLTScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
SafeBoot-Symantec Antvirus
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-Easy-WebPrint - c:\windows\IsUn0405.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-11 19:47
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-682003330-606747145-725345543-1007)
@Allowed: (Read) (S-1-5-21-682003330-606747145-725345543-1007)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2816)
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
c:\program files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
.
**************************************************************************
.
Celkový čas: 2011-10-11 20:01:58 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-11 18:01
.
Před spuštěním: Volných bajtů: 97 335 115 776
Po spuštění: Volných bajtů: 99 077 316 608
.
- - End Of File - - 21D833378E6165664C36CDF12C5BF959



TDSSKiller log


19:36:42.0203 1468 TDSS rootkit removing tool 2.6.8.0 Oct 12 2011 07:30:54
19:36:42.0656 1468 ============================================================
19:36:42.0656 1468 Current date / time: 2011/10/12 19:36:42.0656
19:36:42.0656 1468 SystemInfo:
19:36:42.0656 1468
19:36:42.0656 1468 OS Version: 5.1.2600 ServicePack: 3.0
19:36:42.0656 1468 Product type: Workstation
19:36:42.0656 1468 ComputerName: EUROROOF-A35922
19:36:42.0656 1468 UserName: .....
19:36:42.0656 1468 Windows directory: C:\WINDOWS
19:36:42.0656 1468 System windows directory: C:\WINDOWS
19:36:42.0656 1468 Processor architecture: Intel x86
19:36:42.0656 1468 Number of processors: 2
19:36:42.0656 1468 Page size: 0x1000
19:36:42.0656 1468 Boot type: Safe boot with network
19:36:42.0656 1468 ============================================================
19:36:43.0671 1468 Initialize success
19:36:45.0703 1616 ============================================================
19:36:45.0703 1616 Scan started
19:36:45.0703 1616 Mode: Manual;
19:36:45.0703 1616 ============================================================
19:36:47.0328 1616 Abiosdsk - ok
19:36:47.0625 1616 abp480n5 - ok
19:36:48.0031 1616 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
19:36:48.0078 1616 ACPI - ok
19:36:48.0453 1616 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
19:36:48.0468 1616 ACPIEC - ok
19:36:48.0718 1616 ADILOADER - ok
19:36:49.0015 1616 adiusbaw - ok
19:36:49.0296 1616 adpu160m - ok
19:36:49.0703 1616 aeaudio (9f59ae2de835641fbb0c6afd80d8fa9b) C:\WINDOWS\system32\drivers\aeaudio.sys
19:36:49.0781 1616 aeaudio - ok
19:36:50.0156 1616 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
19:36:50.0218 1616 aec - ok
19:36:50.0578 1616 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
19:36:50.0609 1616 AFD - ok
19:36:50.0906 1616 Aha154x - ok
19:36:51.0203 1616 aic78u2 - ok
19:36:51.0500 1616 aic78xx - ok
19:36:51.0781 1616 AliIde - ok
19:36:52.0062 1616 amsint - ok
19:36:52.0375 1616 asc - ok
19:36:52.0656 1616 asc3350p - ok
19:36:52.0968 1616 asc3550 - ok
19:36:53.0343 1616 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
19:36:53.0359 1616 AsyncMac - ok
19:36:53.0703 1616 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
19:36:53.0703 1616 atapi - ok
19:36:54.0015 1616 Atdisk - ok
19:36:54.0390 1616 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
19:36:54.0406 1616 Atmarpc - ok
19:36:54.0734 1616 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
19:36:54.0750 1616 audstub - ok
19:36:55.0140 1616 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
19:36:55.0140 1616 Beep - ok
19:36:55.0250 1616 catchme - ok
19:36:55.0593 1616 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
19:36:55.0625 1616 cbidf2k - ok
19:36:55.0937 1616 cd20xrnt - ok
19:36:56.0296 1616 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
19:36:56.0296 1616 Cdaudio - ok
19:36:56.0656 1616 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
19:36:56.0671 1616 Cdfs - ok
19:36:57.0015 1616 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
19:36:57.0031 1616 Cdrom - ok
19:36:57.0296 1616 Changer - ok
19:36:57.0640 1616 CmdIde - ok
19:36:58.0015 1616 Cpqarray - ok
19:36:58.0390 1616 cpuz135 (c2eb4539a4f6ab6edd01bdc191619975) C:\WINDOWS\system32\drivers\cpuz135_x32.sys
19:36:58.0390 1616 cpuz135 - ok
19:36:58.0734 1616 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
19:36:58.0734 1616 CVirtA - ok
19:36:59.0156 1616 CVPNDRVA (cb90b2762b1a1d0b40496400c55b6ade) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
19:36:59.0265 1616 CVPNDRVA - ok
19:36:59.0593 1616 dac2w2k - ok
19:36:59.0843 1616 dac960nt - ok
19:37:00.0234 1616 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
19:37:00.0250 1616 Disk - ok
19:37:00.0812 1616 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
19:37:01.0046 1616 dmboot - ok
19:37:01.0453 1616 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
19:37:01.0500 1616 dmio - ok
19:37:01.0812 1616 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
19:37:01.0812 1616 dmload - ok
19:37:02.0156 1616 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
19:37:02.0171 1616 DMusic - ok
19:37:02.0687 1616 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\WINDOWS\system32\DRIVERS\dne2000.sys
19:37:02.0687 1616 DNE - ok
19:37:03.0156 1616 dpti2o - ok
19:37:03.0640 1616 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
19:37:03.0671 1616 drmkaud - ok
19:37:04.0093 1616 EagleNT - ok
19:37:04.0531 1616 eeCtrl (8f7dbc4be48f5388a6fe1f285e7948ef) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
19:37:04.0703 1616 eeCtrl - ok
19:37:04.0953 1616 EraserUtilRebootDrv (3ee14d400e0fdd0d214275a4a20b7022) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
19:37:05.0046 1616 EraserUtilRebootDrv - ok
19:37:05.0625 1616 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
19:37:05.0687 1616 Fastfat - ok
19:37:06.0078 1616 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
19:37:06.0078 1616 Fdc - ok
19:37:06.0515 1616 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
19:37:06.0515 1616 Fips - ok
19:37:07.0078 1616 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
19:37:07.0093 1616 Flpydisk - ok
19:37:07.0468 1616 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
19:37:07.0562 1616 FltMgr - ok
19:37:08.0015 1616 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
19:37:08.0031 1616 Fs_Rec - ok
19:37:08.0453 1616 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
19:37:08.0500 1616 Ftdisk - ok
19:37:08.0890 1616 GEARAspiWDM (4ac51459805264affd5f6fdfb9d9235f) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
19:37:08.0890 1616 GEARAspiWDM - ok
19:37:09.0328 1616 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
19:37:09.0343 1616 Gpc - ok
19:37:09.0703 1616 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
19:37:09.0703 1616 HidUsb - ok
19:37:10.0031 1616 hpn - ok
19:37:10.0500 1616 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
19:37:10.0609 1616 HTTP - ok
19:37:10.0703 1616 HWiNFO32 (acbb9ad0711ab723507c89fa4ba06c0f) C:\Program Files\HWiNFO32\HWiNFO32.SYS
19:37:10.0703 1616 HWiNFO32 - ok
19:37:11.0015 1616 i2omgmt - ok
19:37:11.0281 1616 i2omp - ok
19:37:11.0625 1616 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
19:37:11.0640 1616 i8042prt - ok
19:37:12.0453 1616 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
19:37:13.0062 1616 ialm - ok
19:37:13.0640 1616 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
19:37:13.0687 1616 Imapi - ok
19:37:14.0093 1616 ini910u - ok
19:37:14.0625 1616 IntelIde (57d928e548b38502abba7a77a6eb7312) C:\WINDOWS\system32\DRIVERS\intelide.sys
19:37:14.0640 1616 IntelIde - ok
19:37:15.0078 1616 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
19:37:15.0093 1616 intelppm - ok
19:37:15.0421 1616 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
19:37:15.0437 1616 Ip6Fw - ok
19:37:15.0765 1616 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
19:37:15.0781 1616 IpFilterDriver - ok
19:37:16.0093 1616 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
19:37:16.0093 1616 IpInIp - ok
19:37:16.0453 1616 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
19:37:16.0484 1616 IpNat - ok
19:37:16.0843 1616 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
19:37:16.0859 1616 IPSec - ok
19:37:17.0187 1616 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
19:37:17.0187 1616 IRENUM - ok
19:37:17.0593 1616 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
19:37:17.0609 1616 isapnp - ok
19:37:17.0984 1616 k510bus (b1fe6feac5a501c89057a69c9f5e9d1f) C:\WINDOWS\system32\DRIVERS\k510bus.sys
19:37:18.0000 1616 k510bus - ok
19:37:18.0343 1616 k510mdfl (7a4ecca08560e8ff330acaa4128af7b0) C:\WINDOWS\system32\DRIVERS\k510mdfl.sys
19:37:18.0343 1616 k510mdfl - ok
19:37:18.0734 1616 k510mdm (094d532b727030c3b8b6bd3b743d9526) C:\WINDOWS\system32\DRIVERS\k510mdm.sys
19:37:18.0765 1616 k510mdm - ok
19:37:19.0093 1616 k510mgmt (ad67bfa00ba39c65551338ee001cdddd) C:\WINDOWS\system32\DRIVERS\k510mgmt.sys
19:37:19.0125 1616 k510mgmt - ok
19:37:19.0515 1616 k510obex (7d5094b00a47d871a48d035beb3a0922) C:\WINDOWS\system32\DRIVERS\k510obex.sys
19:37:19.0546 1616 k510obex - ok
19:37:19.0828 1616 k750bus - ok
19:37:20.0140 1616 k750mdfl - ok
19:37:20.0468 1616 k750mdm - ok
19:37:20.0750 1616 k750mgmt - ok
19:37:21.0046 1616 k750obex - ok
19:37:21.0390 1616 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
19:37:21.0406 1616 Kbdclass - ok
19:37:21.0843 1616 kbdhid (86c8f23616c6c6e5b2776901c17b945b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
19:37:21.0859 1616 kbdhid - ok
19:37:22.0296 1616 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
19:37:22.0359 1616 kmixer - ok
19:37:23.0015 1616 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
19:37:23.0093 1616 KSecDD - ok
19:37:23.0515 1616 lbrtfdc - ok
19:37:23.0984 1616 MidiSyn (8c7d037a53b495e7c250fd70b158b581) C:\WINDOWS\system32\drivers\MidiSyn.sys
19:37:24.0062 1616 MidiSyn - ok
19:37:24.0531 1616 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
19:37:24.0562 1616 mnmdd - ok
19:37:25.0140 1616 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
19:37:25.0140 1616 Modem - ok
19:37:25.0609 1616 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
19:37:25.0625 1616 Mouclass - ok
19:37:26.0109 1616 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
19:37:26.0109 1616 mouhid - ok
19:37:26.0531 1616 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
19:37:26.0562 1616 MountMgr - ok
19:37:27.0000 1616 mraid35x - ok
19:37:27.0640 1616 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
19:37:27.0687 1616 MRxDAV - ok
19:37:28.0437 1616 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
19:37:28.0718 1616 MRxSmb - ok
19:37:29.0250 1616 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
19:37:29.0281 1616 Msfs - ok
19:37:29.0859 1616 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
19:37:29.0875 1616 MSKSSRV - ok
19:37:30.0531 1616 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
19:37:30.0531 1616 MSPCLOCK - ok
19:37:31.0140 1616 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
19:37:31.0234 1616 MSPQM - ok
19:37:31.0859 1616 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
19:37:31.0890 1616 mssmbios - ok
19:37:32.0359 1616 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
19:37:32.0421 1616 Mup - ok
19:37:32.0671 1616 NAVENG (920d9701bba90dbb7ccfd3536ea4d6f9) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110730.002\NAVENG.SYS
19:37:32.0875 1616 NAVENG - ok
19:37:33.0546 1616 NAVEX15 (31b1a9b53c3319b97f7874347cd992d2) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110730.002\NAVEX15.SYS
19:37:34.0312 1616 NAVEX15 - ok
19:37:34.0890 1616 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
19:37:34.0984 1616 NDIS - ok
19:37:35.0421 1616 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
19:37:35.0468 1616 NdisTapi - ok
19:37:36.0000 1616 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
19:37:36.0015 1616 Ndisuio - ok
19:37:36.0421 1616 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
19:37:36.0515 1616 NdisWan - ok
19:37:37.0125 1616 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
19:37:37.0140 1616 NDProxy - ok
19:37:37.0781 1616 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
19:37:37.0828 1616 NetBIOS - ok
19:37:38.0484 1616 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
19:37:38.0578 1616 NetBT - ok
19:37:39.0031 1616 nmwcd - ok
19:37:39.0421 1616 nmwcdc - ok
19:37:39.0921 1616 nmwcdcj - ok
19:37:40.0234 1616 nmwcdcm - ok
19:37:40.0781 1616 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
19:37:40.0812 1616 Npfs - ok
19:37:41.0484 1616 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
19:37:41.0812 1616 Ntfs - ok
19:37:42.0265 1616 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
19:37:42.0281 1616 Null - ok
19:37:42.0796 1616 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
19:37:42.0890 1616 NwlnkFlt - ok
19:37:43.0343 1616 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
19:37:43.0390 1616 NwlnkFwd - ok
19:37:43.0859 1616 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
19:37:43.0953 1616 Parport - ok
19:37:44.0421 1616 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
19:37:44.0453 1616 PartMgr - ok
19:37:44.0828 1616 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
19:37:44.0843 1616 ParVdm - ok
19:37:45.0281 1616 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
19:37:45.0312 1616 PCI - ok
19:37:45.0781 1616 PCIDump - ok
19:37:46.0265 1616 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
19:37:46.0281 1616 PCIIde - ok
19:37:46.0796 1616 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
19:37:46.0890 1616 Pcmcia - ok
19:37:47.0250 1616 PDCOMP - ok
19:37:47.0687 1616 PDFRAME - ok
19:37:48.0062 1616 PDRELI - ok
19:37:48.0468 1616 PDRFRAME - ok
19:37:48.0781 1616 perc2 - ok
19:37:49.0203 1616 perc2hib - ok
19:37:49.0843 1616 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
19:37:49.0875 1616 PptpMiniport - ok
19:37:50.0312 1616 prodrv06 (09921a58b4278bc16efa91a8fe480c50) C:\WINDOWS\System32\drivers\prodrv06.sys
19:37:50.0421 1616 prodrv06 - ok
19:37:50.0953 1616 prohlp02 (97184f49aa0733f6eea28ada265ba8da) C:\WINDOWS\system32\drivers\prohlp02.sys
19:37:50.0984 1616 prohlp02 - ok
19:37:51.0515 1616 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys
19:37:51.0546 1616 prosync1 - ok
19:37:52.0000 1616 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
19:37:52.0062 1616 PSched - ok
19:37:52.0578 1616 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
19:37:52.0609 1616 Ptilink - ok
19:37:53.0109 1616 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
19:37:53.0156 1616 PxHelp20 - ok
19:37:53.0671 1616 ql1080 - ok
19:37:54.0046 1616 Ql10wnt - ok
19:37:54.0421 1616 ql12160 - ok
19:37:54.0781 1616 ql1240 - ok
19:37:55.0218 1616 ql1280 - ok
19:37:55.0812 1616 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
19:37:55.0828 1616 RasAcd - ok
19:37:56.0296 1616 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
19:37:56.0312 1616 Rasl2tp - ok
19:37:56.0875 1616 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
19:37:56.0906 1616 RasPppoe - ok
19:37:57.0406 1616 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
19:37:57.0453 1616 Raspti - ok
19:37:58.0031 1616 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
19:37:58.0125 1616 Rdbss - ok
19:37:58.0640 1616 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
19:37:58.0640 1616 RDPCDD - ok
19:37:59.0156 1616 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
19:37:59.0265 1616 RDPWD - ok
19:37:59.0828 1616 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
19:37:59.0859 1616 redbook - ok
19:38:00.0531 1616 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys
19:38:00.0531 1616 RimUsb - ok
19:38:01.0046 1616 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
19:38:01.0062 1616 RimVSerPort - ok
19:38:01.0437 1616 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
19:38:01.0437 1616 ROOTMODEM - ok
19:38:02.0062 1616 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
19:38:02.0078 1616 Secdrv - ok
19:38:02.0890 1616 senfilt (bb596a578330ad794c6769b588af6bb4) C:\WINDOWS\system32\drivers\senfilt.sys
19:38:03.0156 1616 senfilt - ok
19:38:03.0671 1616 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
19:38:03.0703 1616 serenum - ok
19:38:04.0234 1616 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
19:38:04.0281 1616 Serial - ok
19:38:05.0000 1616 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
19:38:05.0000 1616 sfhlp01 - ok
19:38:05.0531 1616 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
19:38:05.0531 1616 Sfloppy - ok
19:38:06.0109 1616 Simbad - ok
19:38:06.0671 1616 smwdm (1319ea66a96250d59665d133c0ff7cd0) C:\WINDOWS\system32\drivers\smwdm.sys
19:38:06.0828 1616 smwdm - ok
19:38:07.0390 1616 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
19:38:07.0390 1616 SONYPVU1 - ok
19:38:07.0875 1616 Sparrow - ok
19:38:08.0171 1616 SPBBCDrv (e87cf104f12c92401c4d33c50a3d5dc8) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
19:38:08.0375 1616 SPBBCDrv - ok
19:38:09.0000 1616 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
19:38:09.0015 1616 splitter - ok
19:38:09.0734 1616 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
19:38:09.0953 1616 sr - ok
19:38:10.0859 1616 SRTSP (b36f8d6a02ff2b3a53e250a629782f29) C:\WINDOWS\system32\Drivers\SRTSP.SYS
19:38:11.0031 1616 SRTSP - ok
19:38:11.0796 1616 SRTSPL (e99bd98ac171a29fc1ba9376be87ae73) C:\WINDOWS\system32\Drivers\SRTSPL.SYS
19:38:11.0921 1616 SRTSPL - ok
19:38:12.0656 1616 SRTSPX (1af34729898063e9b7df8d149d767e07) C:\WINDOWS\system32\Drivers\SRTSPX.SYS
19:38:12.0734 1616 SRTSPX - ok
19:38:13.0468 1616 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
19:38:13.0765 1616 Srv - ok
19:38:14.0218 1616 SunkFilt6 - ok
19:38:14.0875 1616 SunkFilt62 (38cc705ff41cc49daed796cfb419bea2) C:\WINDOWS\System32\Drivers\sunkfilt62.sys
19:38:14.0906 1616 SunkFilt62 - ok
19:38:15.0375 1616 Sunkfiltp - ok
19:38:16.0140 1616 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
19:38:16.0140 1616 swenum - ok
19:38:16.0796 1616 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
19:38:16.0812 1616 swmidi - ok
19:38:17.0281 1616 symc810 - ok
19:38:17.0687 1616 symc8xx - ok
19:38:18.0203 1616 SymEvent (e42a34e6f5ca71a84d4c2de620aad13d) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
19:38:18.0296 1616 SymEvent - ok
19:38:18.0796 1616 SYMREDRV (394b2368212114d538316812af60fddd) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
19:38:18.0812 1616 SYMREDRV - ok
19:38:19.0312 1616 SYMTDI (d46676bb414c7531bdffe637a33f5033) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
19:38:19.0312 1616 SYMTDI - ok
19:38:19.0734 1616 sym_hi - ok
19:38:20.0218 1616 sym_u3 - ok
19:38:20.0734 1616 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
19:38:20.0765 1616 sysaudio - ok
19:38:21.0453 1616 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
19:38:21.0625 1616 Tcpip - ok
19:38:22.0296 1616 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
19:38:22.0296 1616 TDPIPE - ok
19:38:22.0718 1616 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
19:38:22.0718 1616 TDTCP - ok
19:38:23.0421 1616 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
19:38:23.0500 1616 TermDD - ok
19:38:24.0125 1616 TosIde - ok
19:38:24.0718 1616 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
19:38:24.0781 1616 Udfs - ok
19:38:25.0265 1616 ultra - ok
19:38:26.0109 1616 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
19:38:26.0328 1616 Update - ok
19:38:27.0093 1616 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
19:38:27.0093 1616 usbccgp - ok
19:38:27.0625 1616 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
19:38:27.0656 1616 usbehci - ok
19:38:28.0171 1616 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
19:38:28.0203 1616 usbhub - ok
19:38:28.0703 1616 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
19:38:28.0734 1616 usbprint - ok
19:38:29.0359 1616 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
19:38:29.0375 1616 usbscan - ok
19:38:30.0000 1616 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
19:38:30.0000 1616 USBSTOR - ok
19:38:30.0562 1616 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
19:38:30.0609 1616 usbuhci - ok
19:38:31.0078 1616 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
19:38:31.0078 1616 VgaSave - ok
19:38:31.0390 1616 ViaIde - ok
19:38:31.0859 1616 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
19:38:31.0875 1616 VolSnap - ok
19:38:32.0453 1616 vsdatant (0354ba3a5ba5e28cc247eb5f5dd8793c) C:\WINDOWS\system32\vsdatant.sys
19:38:33.0281 1616 vsdatant - ok
19:38:33.0921 1616 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
19:38:33.0921 1616 Wanarp - ok
19:38:34.0375 1616 WDICA - ok
19:38:34.0953 1616 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
19:38:34.0984 1616 wdmaud - ok
19:38:35.0718 1616 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
19:38:35.0734 1616 WS2IFSL - ok
19:38:36.0250 1616 WudfPf (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
19:38:36.0281 1616 WudfPf - ok
19:38:36.0859 1616 WudfRd (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
19:38:36.0953 1616 WudfRd - ok
19:38:37.0515 1616 yukonwxp (ae9573e9563771c7f2f333e728fe7e76) C:\WINDOWS\system32\DRIVERS\yk51x86.sys
19:38:37.0671 1616 yukonwxp - ok
19:38:37.0765 1616 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
19:38:39.0140 1616 \Device\Harddisk0\DR0 - ok
19:38:39.0171 1616 Boot (0x1200) (c28b3bd46be7b473a4df93ef8efc495e) \Device\Harddisk0\DR0\Partition0
19:38:39.0171 1616 \Device\Harddisk0\DR0\Partition0 - ok
19:38:39.0171 1616 ============================================================
19:38:39.0171 1616 Scan finished
19:38:39.0171 1616 ============================================================
19:38:39.0296 1608 Detected object count: 0
19:38:39.0296 1608 Actual detected object count: 0
19:39:15.0031 0724 ============================================================
19:39:15.0031 0724 Scan started
19:39:15.0031 0724 Mode: Manual; SigCheck; TDLFS;
19:39:15.0031 0724 ============================================================
19:39:17.0046 0724 Abiosdsk - ok
19:39:17.0656 0724 abp480n5 - ok
19:39:18.0484 0724 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
19:39:20.0390 0724 ACPI - ok
19:39:20.0968 0724 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
19:39:21.0250 0724 ACPIEC - ok
19:39:21.0734 0724 ADILOADER - ok
19:39:22.0218 0724 adiusbaw - ok
19:39:22.0765 0724 adpu160m - ok
19:39:23.0515 0724 aeaudio (9f59ae2de835641fbb0c6afd80d8fa9b) C:\WINDOWS\system32\drivers\aeaudio.sys
19:39:23.0671 0724 aeaudio ( UnsignedFile.Multi.Generic ) - warning
19:39:23.0671 0724 aeaudio - detected UnsignedFile.Multi.Generic (1)
19:39:24.0312 0724 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
19:39:24.0468 0724 aec - ok
19:39:25.0406 0724 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
19:39:25.0812 0724 AFD - ok
19:39:26.0312 0724 Aha154x - ok
19:39:26.0750 0724 aic78u2 - ok
19:39:27.0203 0724 aic78xx - ok
19:39:27.0625 0724 AliIde - ok
19:39:27.0984 0724 amsint - ok
19:39:28.0468 0724 asc - ok
19:39:28.0921 0724 asc3350p - ok
19:39:29.0343 0724 asc3550 - ok
19:39:29.0796 0724 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
19:39:30.0046 0724 AsyncMac - ok
19:39:30.0593 0724 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
19:39:30.0812 0724 atapi - ok
19:39:31.0234 0724 Atdisk - ok
19:39:32.0062 0724 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
19:39:32.0328 0724 Atmarpc - ok
19:39:33.0250 0724 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
19:39:33.0421 0724 audstub - ok
19:39:34.0109 0724 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
19:39:34.0281 0724 Beep - ok
19:39:34.0593 0724 catchme - ok
19:39:35.0312 0724 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
19:39:35.0500 0724 cbidf2k - ok
19:39:36.0015 0724 cd20xrnt - ok
19:39:36.0468 0724 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
19:39:36.0625 0724 Cdaudio - ok
19:39:37.0265 0724 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
19:39:37.0453 0724 Cdfs - ok
19:39:37.0968 0724 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
19:39:38.0156 0724 Cdrom - ok
19:39:38.0593 0724 Changer - ok
19:39:38.0953 0724 CmdIde - ok
19:39:39.0531 0724 Cpqarray - ok
19:39:40.0421 0724 cpuz135 (c2eb4539a4f6ab6edd01bdc191619975) C:\WINDOWS\system32\drivers\cpuz135_x32.sys
19:39:40.0984 0724 cpuz135 - ok
19:39:41.0578 0724 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\WINDOWS\system32\DRIVERS\CVirtA.sys
19:39:41.0671 0724 CVirtA - ok
19:39:42.0312 0724 CVPNDRVA (cb90b2762b1a1d0b40496400c55b6ade) C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
19:39:42.0343 0724 CVPNDRVA ( UnsignedFile.Multi.Generic ) - warning
19:39:42.0343 0724 CVPNDRVA - detected UnsignedFile.Multi.Generic (1)
19:39:42.0828 0724 dac2w2k - ok
19:39:43.0312 0724 dac960nt - ok
19:39:43.0859 0724 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
19:39:44.0078 0724 Disk - ok
19:39:45.0015 0724 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
19:39:45.0406 0724 dmboot - ok
19:39:46.0031 0724 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
19:39:46.0187 0724 dmio - ok
19:39:46.0718 0724 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
19:39:46.0890 0724 dmload - ok
19:39:47.0375 0724 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
19:39:47.0515 0724 DMusic - ok
19:39:48.0015 0724 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\WINDOWS\system32\DRIVERS\dne2000.sys
19:39:48.0031 0724 DNE - ok
19:39:48.0421 0724 dpti2o - ok
19:39:48.0890 0724 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
19:39:49.0031 0724 drmkaud - ok
19:39:49.0468 0724 EagleNT - ok
19:39:49.0937 0724 eeCtrl (8f7dbc4be48f5388a6fe1f285e7948ef) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
19:39:50.0156 0724 eeCtrl - ok
19:39:50.0375 0724 EraserUtilRebootDrv (3ee14d400e0fdd0d214275a4a20b7022) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
19:39:50.0406 0724 EraserUtilRebootDrv - ok
19:39:50.0953 0724 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
19:39:51.0125 0724 Fastfat - ok
19:39:51.0593 0724 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
19:39:51.0828 0724 Fdc - ok
19:39:52.0328 0724 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
19:39:52.0625 0724 Fips - ok
19:39:53.0109 0724 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
19:39:53.0265 0724 Flpydisk - ok
19:39:53.0812 0724 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
19:39:54.0046 0724 FltMgr - ok
19:39:54.0531 0724 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
19:39:54.0718 0724 Fs_Rec - ok
19:39:55.0218 0724 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
19:39:55.0421 0724 Ftdisk - ok
19:39:55.0875 0724 GEARAspiWDM (4ac51459805264affd5f6fdfb9d9235f) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
19:39:55.0890 0724 GEARAspiWDM - ok
19:39:56.0375 0724 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
19:39:56.0718 0724 Gpc - ok
19:39:57.0343 0724 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
19:39:57.0546 0724 HidUsb - ok
19:39:58.0109 0724 hpn - ok
19:39:58.0906 0724 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
19:39:59.0046 0724 HTTP - ok
19:39:59.0265 0724 HWiNFO32 (acbb9ad0711ab723507c89fa4ba06c0f) C:\Program Files\HWiNFO32\HWiNFO32.SYS
19:39:59.0328 0724 HWiNFO32 ( UnsignedFile.Multi.Generic ) - warning
19:39:59.0328 0724 HWiNFO32 - detected UnsignedFile.Multi.Generic (1)
19:39:59.0703 0724 i2omgmt - ok
19:40:00.0109 0724 i2omp - ok
19:40:00.0875 0724 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
19:40:01.0109 0724 i8042prt - ok
19:40:02.0109 0724 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
19:40:02.0843 0724 ialm - ok
19:40:03.0359 0724 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
19:40:03.0500 0724 Imapi - ok
19:40:03.0921 0724 ini910u - ok
19:40:04.0328 0724 IntelIde (57d928e548b38502abba7a77a6eb7312) C:\WINDOWS\system32\DRIVERS\intelide.sys
19:40:04.0500 0724 IntelIde - ok
19:40:05.0093 0724 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
19:40:05.0281 0724 intelppm - ok
19:40:05.0796 0724 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
19:40:05.0937 0724 Ip6Fw - ok
19:40:06.0390 0724 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
19:40:06.0562 0724 IpFilterDriver - ok
19:40:07.0109 0724 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
19:40:07.0250 0724 IpInIp - ok
19:40:07.0796 0724 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
19:40:07.0984 0724 IpNat - ok
19:40:08.0515 0724 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
19:40:08.0703 0724 IPSec - ok
19:40:09.0250 0724 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
19:40:09.0390 0724 IRENUM - ok
19:40:10.0031 0724 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
19:40:10.0187 0724 isapnp - ok
19:40:10.0812 0724 k510bus (b1fe6feac5a501c89057a69c9f5e9d1f) C:\WINDOWS\system32\DRIVERS\k510bus.sys
19:40:10.0953 0724 k510bus - ok
19:40:11.0500 0724 k510mdfl (7a4ecca08560e8ff330acaa4128af7b0) C:\WINDOWS\system32\DRIVERS\k510mdfl.sys
19:40:12.0109 0724 k510mdfl - ok
19:40:12.0781 0724 k510mdm (094d532b727030c3b8b6bd3b743d9526) C:\WINDOWS\system32\DRIVERS\k510mdm.sys
19:40:12.0843 0724 k510mdm - ok
19:40:13.0500 0724 k510mgmt (ad67bfa00ba39c65551338ee001cdddd) C:\WINDOWS\system32\DRIVERS\k510mgmt.sys
19:40:13.0656 0724 k510mgmt - ok
19:40:14.0375 0724 k510obex (7d5094b00a47d871a48d035beb3a0922) C:\WINDOWS\system32\DRIVERS\k510obex.sys
19:40:14.0531 0724 k510obex - ok
19:40:14.0937 0724 k750bus - ok
19:40:15.0406 0724 k750mdfl - ok
19:40:15.0859 0724 k750mdm - ok
19:40:16.0328 0724 k750mgmt - ok
19:40:16.0765 0724 k750obex - ok
19:40:17.0156 0724 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
19:40:17.0281 0724 Kbdclass - ok
19:40:17.0609 0724 kbdhid (86c8f23616c6c6e5b2776901c17b945b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
19:40:17.0734 0724 kbdhid - ok
19:40:18.0156 0724 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
19:40:18.0281 0724 kmixer - ok
19:40:18.0656 0724 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
19:40:18.0796 0724 KSecDD - ok
19:40:19.0234 0724 lbrtfdc - ok
19:40:19.0828 0724 MidiSyn (8c7d037a53b495e7c250fd70b158b581) C:\WINDOWS\system32\drivers\MidiSyn.sys
19:40:19.0906 0724 MidiSyn - ok
19:40:20.0250 0724 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
19:40:20.0375 0724 mnmdd - ok
19:40:20.0812 0724 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
19:40:20.0921 0724 Modem - ok
19:40:21.0265 0724 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
19:40:21.0390 0724 Mouclass - ok
19:40:21.0703 0724 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
19:40:21.0828 0724 mouhid - ok
19:40:22.0234 0724 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
19:40:22.0343 0724 MountMgr - ok
19:40:22.0640 0724 mraid35x - ok
19:40:23.0031 0724 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
19:40:23.0156 0724 MRxDAV - ok
19:40:23.0656 0724 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
19:40:23.0859 0724 MRxSmb - ok
19:40:24.0218 0724 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
19:40:24.0343 0724 Msfs - ok
19:40:24.0671 0724 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
19:40:24.0796 0724 MSKSSRV - ok
19:40:25.0140 0724 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
19:40:25.0265 0724 MSPCLOCK - ok
19:40:25.0609 0724 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
19:40:25.0750 0724 MSPQM - ok
19:40:26.0078 0724 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
19:40:26.0203 0724 mssmbios - ok
19:40:26.0609 0724 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
19:40:26.0671 0724 Mup - ok
19:40:26.0921 0724 NAVENG (920d9701bba90dbb7ccfd3536ea4d6f9) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110730.002\NAVENG.SYS
19:40:26.0937 0724 NAVENG - ok
19:40:27.0937 0724 NAVEX15 (31b1a9b53c3319b97f7874347cd992d2) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110730.002\NAVEX15.SYS
19:40:28.0875 0724 NAVEX15 - ok
19:40:29.0406 0724 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
19:40:29.0578 0724 NDIS - ok
19:40:30.0000 0724 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
19:40:30.0125 0724 NdisTapi - ok
19:40:30.0609 0724 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
19:40:30.0765 0724 Ndisuio - ok
19:40:31.0125 0724 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
19:40:31.0250 0724 NdisWan - ok
19:40:31.0609 0724 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
19:40:31.0671 0724 NDProxy - ok
19:40:32.0046 0724 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
19:40:32.0171 0724 NetBIOS - ok
19:40:32.0546 0724 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
19:40:32.0671 0724 NetBT - ok
19:40:32.0984 0724 nmwcd - ok
19:40:33.0234 0724 nmwcdc - ok
19:40:33.0484 0724 nmwcdcj - ok
19:40:33.0750 0724 nmwcdcm - ok
19:40:34.0031 0724 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
19:40:34.0156 0724 Npfs - ok
19:40:34.0703 0724 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
19:40:34.0921 0724 Ntfs - ok
19:40:35.0250 0724 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
19:40:35.0375 0724 Null - ok
19:40:35.0734 0724 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
19:40:35.0906 0724 NwlnkFlt - ok
19:40:36.0406 0724 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
19:40:36.0578 0724 NwlnkFwd - ok
19:40:37.0093 0724 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
19:40:37.0250 0724 Parport - ok
19:40:37.0781 0724 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
19:40:37.0968 0724 PartMgr - ok
19:40:38.0421 0724 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
19:40:38.0593 0724 ParVdm - ok
19:40:39.0093 0724 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
19:40:39.0250 0724 PCI - ok
19:40:39.0703 0724 PCIDump - ok
19:40:40.0671 0724 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
19:40:40.0875 0724 PCIIde - ok
19:40:41.0750 0724 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
19:40:41.0921 0724 Pcmcia - ok
19:40:42.0359 0724 PDCOMP - ok
19:40:42.0921 0724 PDFRAME - ok
19:40:43.0437 0724 PDRELI - ok
19:40:43.0953 0724 PDRFRAME - ok
19:40:44.0390 0724 perc2 - ok
19:40:45.0000 0724 perc2hib - ok
19:40:45.0421 0724 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
19:40:45.0562 0724 PptpMiniport - ok
19:40:45.0968 0724 prodrv06 (09921a58b4278bc16efa91a8fe480c50) C:\WINDOWS\System32\drivers\prodrv06.sys
19:40:46.0015 0724 prodrv06 ( UnsignedFile.Multi.Generic ) - warning
19:40:46.0015 0724 prodrv06 - detected UnsignedFile.Multi.Generic (1)
19:40:46.0578 0724 prohlp02 (97184f49aa0733f6eea28ada265ba8da) C:\WINDOWS\system32\drivers\prohlp02.sys
19:40:46.0625 0724 prohlp02 ( UnsignedFile.Multi.Generic ) - warning
19:40:46.0625 0724 prohlp02 - detected UnsignedFile.Multi.Generic (1)
19:40:47.0109 0724 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys
19:40:47.0125 0724 prosync1 ( UnsignedFile.Multi.Generic ) - warning
19:40:47.0125 0724 prosync1 - detected UnsignedFile.Multi.Generic (1)
19:40:47.0578 0724 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
19:40:47.0718 0724 PSched - ok
19:40:48.0093 0724 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
19:40:48.0218 0724 Ptilink - ok
19:40:48.0562 0724 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
19:40:48.0578 0724 PxHelp20 - ok
19:40:48.0859 0724 ql1080 - ok
19:40:49.0125 0724 Ql10wnt - ok
19:40:49.0390 0724 ql12160 - ok
19:40:49.0703 0724 ql1240 - ok
19:40:49.0984 0724 ql1280 - ok
19:40:50.0312 0724 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
19:40:50.0437 0724 RasAcd - ok
19:40:50.0812 0724 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
19:40:50.0937 0724 Rasl2tp - ok
19:40:51.0281 0724 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
19:40:51.0406 0724 RasPppoe - ok
19:40:51.0703 0724 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
19:40:51.0828 0724 Raspti - ok
19:40:52.0187 0724 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
19:40:52.0343 0724 Rdbss - ok
19:40:52.0703 0724 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
19:40:52.0953 0724 RDPCDD - ok
19:40:53.0484 0724 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
19:40:53.0656 0724 RDPWD - ok
19:40:54.0203 0724 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
19:40:54.0359 0724 redbook - ok
19:40:54.0890 0724 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys
19:40:55.0046 0724 RimUsb - ok
19:40:55.0484 0724 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
19:40:55.0609 0724 RimVSerPort - ok
19:40:56.0171 0724 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
19:40:56.0375 0724 ROOTMODEM - ok
19:40:57.0125 0724 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
19:40:57.0281 0724 Secdrv - ok
19:40:58.0140 0724 senfilt (bb596a578330ad794c6769b588af6bb4) C:\WINDOWS\system32\drivers\senfilt.sys
19:40:58.0312 0724 senfilt ( UnsignedFile.Multi.Generic ) - warning
19:40:58.0312 0724 senfilt - detected UnsignedFile.Multi.Generic (1)
19:40:59.0031 0724 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
19:40:59.0265 0724 serenum - ok
19:40:59.0843 0724 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
19:41:00.0000 0724 Serial - ok
19:41:00.0640 0724 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
19:41:00.0671 0724 sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
19:41:00.0671 0724 sfhlp01 - detected UnsignedFile.Multi.Generic (1)
19:41:01.0312 0724 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
19:41:01.0500 0724 Sfloppy - ok
19:41:02.0000 0724 Simbad - ok
19:41:02.0828 0724 smwdm (1319ea66a96250d59665d133c0ff7cd0) C:\WINDOWS\system32\drivers\smwdm.sys
19:41:02.0890 0724 smwdm ( UnsignedFile.Multi.Generic ) - warning
19:41:02.0890 0724 smwdm - detected UnsignedFile.Multi.Generic (1)
19:41:03.0375 0724 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
19:41:03.0578 0724 SONYPVU1 - ok
19:41:04.0031 0724 Sparrow - ok
19:41:04.0453 0724 SPBBCDrv (e87cf104f12c92401c4d33c50a3d5dc8) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
19:41:04.0640 0724 SPBBCDrv - ok
19:41:05.0234 0724 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
19:41:05.0375 0724 splitter - ok
19:41:06.0031 0724 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
19:41:06.0281 0724 sr - ok
19:41:07.0109 0724 SRTSP (b36f8d6a02ff2b3a53e250a629782f29) C:\WINDOWS\system32\Drivers\SRTSP.SYS
19:41:07.0140 0724 SRTSP - ok
19:41:07.0937 0724 SRTSPL (e99bd98ac171a29fc1ba9376be87ae73) C:\WINDOWS\system32\Drivers\SRTSPL.SYS
19:41:07.0953 0724 SRTSPL - ok
19:41:08.0578 0724 SRTSPX (1af34729898063e9b7df8d149d767e07) C:\WINDOWS\system32\Drivers\SRTSPX.SYS
19:41:08.0609 0724 SRTSPX - ok
19:41:09.0375 0724 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
19:41:09.0671 0724 Srv - ok
19:41:10.0109 0724 SunkFilt6 - ok
19:41:10.0734 0724 SunkFilt62 (38cc705ff41cc49daed796cfb419bea2) C:\WINDOWS\System32\Drivers\sunkfilt62.sys
19:41:10.0781 0724 SunkFilt62 ( UnsignedFile.Multi.Generic ) - warning
19:41:10.0781 0724 SunkFilt62 - detected UnsignedFile.Multi.Generic (1)
19:41:11.0281 0724 Sunkfiltp - ok
19:41:11.0765 0724 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
19:41:11.0953 0724 swenum - ok
19:41:12.0531 0724 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
19:41:12.0718 0724 swmidi - ok
19:41:13.0281 0724 symc810 - ok
19:41:13.0890 0724 symc8xx - ok
19:41:14.0546 0724 SymEvent (e42a34e6f5ca71a84d4c2de620aad13d) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
19:41:14.0593 0724 SymEvent - ok
19:41:15.0281 0724 SYMREDRV (394b2368212114d538316812af60fddd) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
19:41:15.0281 0724 SYMREDRV - ok
19:41:15.0984 0724 SYMTDI (d46676bb414c7531bdffe637a33f5033) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
19:41:16.0000 0724 SYMTDI - ok
19:41:16.0515 0724 sym_hi - ok
19:41:16.0984 0724 sym_u3 - ok
19:41:17.0562 0724 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
19:41:17.0718 0724 sysaudio - ok
19:41:18.0453 0724 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
19:41:18.0765 0724 Tcpip - ok
19:41:19.0359 0724 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
19:41:19.0546 0724 TDPIPE - ok
19:41:20.0093 0724 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
19:41:20.0296 0724 TDTCP - ok
19:41:20.0890 0724 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
19:41:21.0078 0724 TermDD - ok
19:41:21.0562 0724 TosIde - ok
19:41:22.0171 0724 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
19:41:22.0375 0724 Udfs - ok
19:41:22.0890 0724 ultra - ok
19:41:23.0578 0724 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
19:41:23.0953 0724 Update - ok
19:41:24.0625 0724 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
19:41:24.0796 0724 usbccgp - ok
19:41:25.0406 0724 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
19:41:25.0609 0724 usbehci - ok
19:41:26.0125 0724 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
19:41:26.0265 0724 usbhub - ok
19:41:26.0703 0724 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
19:41:26.0890 0724 usbprint - ok
19:41:27.0421 0724 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
19:41:27.0593 0724 usbscan - ok
19:41:28.0203 0724 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
19:41:28.0406 0724 USBSTOR - ok
19:41:28.0843 0724 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
19:41:29.0015 0724 usbuhci - ok
19:41:29.0671 0724 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
19:41:29.0859 0724 VgaSave - ok
19:41:30.0312 0724 ViaIde - ok
19:41:30.0812 0724 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
19:41:30.0968 0724 VolSnap - ok
19:41:31.0703 0724 vsdatant (0354ba3a5ba5e28cc247eb5f5dd8793c) C:\WINDOWS\system32\vsdatant.sys
19:41:31.0859 0724 vsdatant - ok
19:41:32.0609 0724 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
19:41:32.0796 0724 Wanarp - ok
19:41:33.0359 0724 WDICA - ok
19:41:34.0031 0724 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
19:41:34.0156 0724 wdmaud - ok
19:41:34.0687 0724 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
19:41:34.0937 0724 WS2IFSL - ok
19:41:35.0546 0724 WudfPf (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
19:41:35.0796 0724 WudfPf - ok
19:41:36.0296 0724 WudfRd (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
19:41:36.0359 0724 WudfRd - ok
19:41:36.0906 0724 yukonwxp (ae9573e9563771c7f2f333e728fe7e76) C:\WINDOWS\system32\DRIVERS\yk51x86.sys
19:41:37.0062 0724 yukonwxp - ok
19:41:37.0109 0724 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
19:41:39.0406 0724 \Device\Harddisk0\DR0 - ok
19:41:39.0453 0724 Boot (0x1200) (c28b3bd46be7b473a4df93ef8efc495e) \Device\Harddisk0\DR0\Partition0
19:41:39.0468 0724 \Device\Harddisk0\DR0\Partition0 - ok
19:41:39.0468 0724 ============================================================
19:41:39.0468 0724 Scan finished
19:41:39.0468 0724 ============================================================
19:41:39.0609 0716 Detected object count: 10
19:41:39.0609 0716 Actual detected object count: 10
19:46:01.0359 0716 aeaudio ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0359 0716 aeaudio ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0359 0716 CVPNDRVA ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0359 0716 CVPNDRVA ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0359 0716 HWiNFO32 ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0359 0716 HWiNFO32 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0375 0716 prodrv06 ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0375 0716 prodrv06 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0375 0716 prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0375 0716 prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0375 0716 prosync1 ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0375 0716 prosync1 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0390 0716 senfilt ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0390 0716 senfilt ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0390 0716 sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0390 0716 sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0406 0716 smwdm ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0406 0716 smwdm ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:01.0406 0716 SunkFilt62 ( UnsignedFile.Multi.Generic ) - skipped by user
19:46:01.0406 0716 SunkFilt62 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:46:05.0234 1464 Deinitialize success

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#6 Příspěvek od vyosek »

:arrow: Neumazavejte prosim z tech logu nic, pak se tezko tvori skripty :?:

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\documents and settings\Josef Dolansky\Local Settings\Data aplikací\3a7b1c23
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"=-
    "SSBkgdUpdate"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000000
    
    File::
    c:\windows\Tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\User_Feed_Synchronization-{548CF3DE-523A-494F-A758-7A7DC2482DFD}.job
    C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Acrobat Speed Launcher.lnk 
    C:\WINDOWS\tasks\User_Feed_Synchronization-{704311D2-9A90-44B7-B7AF-AA7A3EB9A8B3}.job
    C:\WINDOWS\SET1F7.tmp
    C:\WINDOWS\SET1EB.tmp
    C:\WINDOWS\SET1E8.tmp
    C:\WINDOWS\system32\1.tmp
    
    RegNull::
    [HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Microsoft\SystemCertificates\AddressBook*]
    [HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
    
    Driver::
    MEMSWEEP2
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

morphus
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 26 led 2010 23:05

Re: Prosím o kontrolu logu

#7 Příspěvek od morphus »

Script do combofixu proveden a zde je log

Ještě jsem chtěl dodat, že při zavirování byl nabourán Symantec endpoint protector a po vyčištštění pc nešel odinstalovat, tak byl manuálně vymazán podle postupu a pomocí aplikace na vymazání na stránkách Symantecu. Ale stejně i po vyčištění mi systém stále hlásí ( i Combofix) že je stále funkční a zapnut, prosím o radu jak to opravit.


ComboFix 11-10-15.01 - Josef Dolansky 15.10.2011 7:05.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.466 [GMT 2:00]
Spuštěný z: c:\documents and settings\Josef Dolansky\Plocha\Combik.exe
Použité ovládací přepínače :: c:\documents and settings\Josef Dolansky\Plocha\CFScript.txt
AV: Aplikace Symantec Endpoint Protection *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C}
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
FILE ::
"c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Acrobat Speed Launcher.lnk"
"c:\windows\SET1E8.tmp"
"c:\windows\SET1EB.tmp"
"c:\windows\SET1F7.tmp"
"c:\windows\system32\1.tmp"
"c:\windows\Tasks\AppleSoftwareUpdate.job"
"c:\windows\tasks\User_Feed_Synchronization-{548CF3DE-523A-494F-A758-7A7DC2482DFD}.job"
"c:\windows\tasks\User_Feed_Synchronization-{704311D2-9A90-44B7-B7AF-AA7A3EB9A8B3}.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Josef Dolansky\Local Settings\Temporary Internet Files\Windows12111_ConfigRepository.bin
c:\windows\COM+.log
c:\windows\DPINST.LOG
c:\windows\regopt.log
c:\windows\system32\
c:\windows\system32\default_user_class.dat.LOG
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_MEMSWEEP2
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-15 do 2011-10-15 )))))))))))))))))))))))))))))))
.
.
2011-10-14 18:59 . 2008-04-13 20:05 29502 -c--a-w- c:\windows\system32\dllcache\pca200e.sys
2011-10-14 18:58 . 2001-08-17 18:50 198144 -c--a-w- c:\windows\system32\dllcache\nv3.sys
2011-10-14 18:57 . 2001-08-17 18:50 27936 -c--a-w- c:\windows\system32\dllcache\n9i3d.sys
2011-10-14 18:56 . 2008-04-13 22:16 49024 -c--a-w- c:\windows\system32\dllcache\mstape.sys
2011-10-14 18:56 . 2001-08-17 19:48 12416 -c--a-w- c:\windows\system32\dllcache\msriffwv.sys
2011-10-14 18:56 . 2001-08-17 20:00 2944 -c--a-w- c:\windows\system32\dllcache\msmpu401.sys
2011-10-14 18:56 . 2008-04-13 22:24 22016 -c--a-w- c:\windows\system32\dllcache\msircomm.sys
2011-10-14 18:56 . 2001-08-17 20:02 35200 -c--a-w- c:\windows\system32\dllcache\msgame.sys
2011-10-14 18:56 . 2001-08-17 19:48 6016 -c--a-w- c:\windows\system32\dllcache\msfsio.sys
2011-10-14 18:56 . 2008-04-13 22:16 51200 -c--a-w- c:\windows\system32\dllcache\msdv.sys
2011-10-14 18:54 . 2008-04-13 20:09 20864 -c--a-w- c:\windows\system32\dllcache\lwadihid.sys
2011-10-14 18:53 . 2008-04-14 06:51 48640 -c--a-w- c:\windows\system32\dllcache\kdsui.dll
2011-10-14 18:52 . 2001-10-24 10:24 90200 -c--a-w- c:\windows\system32\dllcache\io8ports.dll
2011-10-14 18:51 . 2001-08-17 20:06 38528 -c--a-w- c:\windows\system32\dllcache\ibmvcap.sys
2011-10-14 18:50 . 2001-08-17 19:28 391199 -c--a-w- c:\windows\system32\dllcache\hsf_k56k.sys
2011-10-14 18:49 . 2001-08-17 20:02 2688 -c--a-w- c:\windows\system32\dllcache\hidswvd.sys
2011-10-14 18:48 . 2001-10-24 10:24 71680 -c--a-w- c:\windows\system32\dllcache\fnfilter.dll
2011-10-14 18:47 . 2001-10-24 10:25 53248 -c--a-w- c:\windows\system32\dllcache\eqndiag.exe
2011-10-14 18:46 . 2001-08-17 18:11 29696 -c--a-w- c:\windows\system32\dllcache\dm9pci5.sys
2011-10-14 18:45 . 2001-08-17 19:52 14720 -c--a-w- c:\windows\system32\dllcache\dac960nt.sys
2011-10-14 18:44 . 2001-10-24 09:52 980034 -c--a-w- c:\windows\system32\dllcache\cicap.sys
2011-10-14 18:43 . 2001-08-17 19:12 10368 -c--a-w- c:\windows\system32\dllcache\brusbscn.sys
2011-10-14 18:42 . 2001-08-17 20:07 56960 -c--a-w- c:\windows\system32\dllcache\aic78xx.sys
2011-10-14 18:34 . 2003-03-21 16:05 232808 ----a-w- C:\Q328213_WXP_SP2_x86_CSY.exe
2011-10-14 17:44 . 2011-10-14 17:44 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Research In Motion
2011-10-14 17:42 . 2011-10-14 17:43 -------- d-----w- c:\program files\Common Files\Research In Motion
2011-10-14 13:01 . 2011-10-14 16:02 -------- d-----w- c:\program files\Unlocker
2011-10-14 12:58 . 2011-10-14 13:09 -------- d-----w- c:\program files\trend micro
2011-10-14 12:58 . 2011-10-14 12:58 -------- d-----w- C:\rsit
2011-10-14 08:05 . 2011-10-14 08:05 -------- d-----w- c:\documents and settings\Josef Dolansky\Local Settings\Data aplikací\Research In Motion
2011-10-14 07:30 . 2011-10-14 07:48 97961 ----a-w- c:\windows\system32\drivers\klick.dat
2011-10-14 07:30 . 2011-10-14 07:48 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2011-10-14 07:28 . 2011-10-15 05:19 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Kaspersky Lab
2011-10-14 07:28 . 2011-10-14 07:28 -------- d-----w- c:\program files\Kaspersky Lab
2011-10-14 07:03 . 2011-10-14 07:03 -------- d-----w- c:\windows\system32\DRM
2011-10-14 06:52 . 2011-08-23 15:41 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-10-14 06:52 . 2011-08-22 23:41 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-10-14 06:52 . 2011-08-22 23:41 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-10-14 06:52 . 2011-08-22 23:41 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-10-14 06:52 . 2011-08-22 23:41 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-10-14 06:52 . 2011-08-22 23:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-10-14 06:49 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-10-14 06:42 . 2010-12-09 15:14 2194944 -c--a-w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-10-14 06:39 . 2009-08-06 17:24 44768 ----a-w- c:\windows\system32\wups2.dll
2011-10-14 06:37 . 2011-10-14 06:37 22 --sha-w- c:\documents and settings\Josef Dolansky\Data aplikací\Sys2662.Config.Repository.bin
2011-10-14 06:33 . 2011-10-14 18:17 -------- d-----w- c:\program files\Seznam.cz
2011-10-14 05:51 . 2011-10-14 05:51 -------- d-----w- c:\documents and settings\Josef Dolansky\Data aplikací\ElevatedDiagnostics
2011-10-14 05:44 . 2011-10-14 05:44 -------- d-----w- c:\program files\Windows Resource Kits
2011-10-14 05:32 . 2011-10-14 05:32 -------- d-----w- c:\program files\UPHClean
2011-10-14 05:06 . 2011-10-14 05:06 -------- d-----w- c:\documents and settings\Josef Dolansky\Local Settings\Data aplikací\Sun
2011-10-13 19:19 . 2004-09-14 10:55 88960 ----a-w- c:\windows\system32\drivers\MidiSyn.sys
2011-10-13 19:15 . 2005-09-20 09:36 139264 ----a-w- c:\windows\system32\igfxres.dll
2011-10-13 19:00 . 2008-04-14 12:00 70656 -c--a-w- c:\windows\system32\dllcache\korwbrkr.dll
2011-10-13 18:59 . 2008-04-14 12:00 19456 -c--a-w- c:\windows\system32\dllcache\agt0804.dll
2011-10-13 18:46 . 2008-04-14 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-10-13 18:46 . 2008-04-14 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2011-10-13 18:46 . 2008-04-14 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-10-13 18:46 . 2008-04-14 12:00 16825 ----a-r- c:\windows\SET1F7.tmp
2011-10-13 18:46 . 2008-04-14 12:00 1088840 ----a-r- c:\windows\SET1EB.tmp
2011-10-13 18:46 . 2008-04-14 12:00 1246067 ----a-r- c:\windows\SET1E8.tmp
2011-10-13 16:24 . 2011-10-14 18:15 -------- d-----w- c:\program files\jv16 PowerTools 2011
2011-10-13 14:50 . 2011-10-13 14:49 611224 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-10-13 14:50 . 2011-10-13 14:49 544656 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-13 14:50 . 2011-10-13 14:49 128000 ----a-w- c:\windows\system32\javacpl.cpl
2011-10-13 13:50 . 2011-10-13 19:16 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Soluto
2011-10-13 08:17 . 2011-10-13 08:17 -------- d-----w- c:\program files\ASUS
2011-10-13 08:16 . 2011-10-14 18:16 -------- d-----w- c:\program files\Microsoft Bootvis
2011-10-13 06:05 . 2011-10-13 06:05 3584 ----a-r- c:\documents and settings\Josef Dolansky\Data aplikací\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2011-10-13 06:05 . 2011-10-13 06:05 -------- d-----w- c:\program files\Windows Installer Clean Up
2011-10-13 06:05 . 2011-10-13 06:05 -------- d-----w- c:\program files\MSECACHE
2011-10-13 05:45 . 2011-10-13 05:46 -------- d-----w- c:\documents and settings\Josef Dolansky\Local Settings\Data aplikací\NPE
2011-10-13 05:45 . 2011-10-13 05:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Norton
2011-10-13 05:40 . 2011-10-13 05:40 -------- d-----w- c:\program files\Yamicsoft
2011-10-11 18:34 . 2011-10-11 18:34 -------- d-sh--w- c:\documents and settings\LocalService\IECompatCache
2011-10-11 18:34 . 2011-10-11 18:34 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2011-10-11 18:33 . 2011-10-11 18:33 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2011-10-11 09:46 . 2011-10-12 05:51 -------- d-sh--w- c:\documents and settings\Josef Dolansky\Local Settings\Data aplikací\3a7b1c23
2011-09-28 18:40 . 2011-09-28 18:40 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-26 09:41 . 2008-07-29 17:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2008-04-14 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2008-04-14 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-09 09:12 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 14:10 . 2008-04-14 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:41 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:41 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:41 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2008-04-14 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-11 21:33 . 2011-08-11 21:33 1409 ----a-w- c:\windows\QTFont.for
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2009-12-30 65536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2004-08-06 135168]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-24 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"tvncontrol"="c:\program files\TightVNC\tvnserver.exe" [2010-07-08 815704]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-18 44544]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-C740-7760-100000000002}\SC_Acrobat.exe [2007-1-9 25214]
Akcelerátor spuštění AutoCADu.lnk - c:\program files\Common Files\Autodesk Shared\acstart16.exe [2004-2-25 10872]
VPN Client.lnk - c:\windows\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico [2011-1-6 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-10-09 10:28 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-06-24 14:41 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
.
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [4.3.2011 13:23 11352]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [31.7.2011 16:12 21992]
R2 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [14.3.2008 18:29 8064]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [24.6.2010 16:41 92008]
R2 tvnserver;TightVNC Server;c:\program files\TightVNC\tvnserver.exe [8.7.2010 15:28 815704]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [10.3.2011 18:34 34608]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2.11.2009 20:27 19472]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [26.12.2007 12:32 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [26.12.2007 12:32 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [26.12.2007 12:32 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [26.12.2007 12:32 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [26.12.2007 12:32 83344]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 SunkFilt6;Alcor Micro Corp - 6360;\??\c:\windows\System32\Drivers\sunkfilt6.sys --> c:\windows\System32\Drivers\sunkfilt6.sys [?]
S3 SunkFilt62;Alcor Micro Corp - 6362;c:\windows\system32\drivers\sunkfilt62.sys [23.7.2004 14:55 46536]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - uphcleanhlp
.
Obsah adresáře 'Naplánované úlohy'
.
2011-10-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 16:13]
.
2011-10-15 c:\windows\Tasks\User_Feed_Synchronization-{548CF3DE-523A-494F-A758-7A7DC2482DFD}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
2011-10-15 c:\windows\Tasks\User_Feed_Synchronization-{704311D2-9A90-44B7-B7AF-AA7A3EB9A8B3}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mWindow Title = Microsoft Internet Explorer
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Přidat do Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
TCP: DhcpNameServer = 192.168.1.1 89.235.33.1 89.235.33.2
FF - ProfilePath - c:\documents and settings\Josef Dolansky\Data aplikací\Mozilla\Firefox\Profiles\sl02c8xp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Sukoku: {7AB6D133-2A14-4C11-B3AD-35B1548D38F9} - c:\program files\Mozilla Firefox\extensions\{7AB6D133-2A14-4C11-B3AD-35B1548D38F9}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru
FF - Ext: Kaspersky Virtual Keyboard: virtualKeyboard@kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF - Ext: Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Garmin Communicator: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - %profile%\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - (no file)
SafeBoot-SolutoService
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-15 07:20
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-682003330-606747145-725345543-1007)
@Allowed: (Read) (S-1-5-21-682003330-606747145-725345543-1007)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(172)
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\UPHClean\uphclean.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-10-15 07:25:01 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-15 05:24
ComboFix2.txt 2011-10-14 16:38
.
Před spuštěním: Volných bajtů: 99 810 242 560
Po spuštění: Volných bajtů: 100 104 495 104
.
- - End Of File - - B01FD6D1466325D913BDE0DC7C96445A

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#8 Příspěvek od vyosek »

:arrow: Omlouvam se za zdrzeni - pracovni povinnosti

:arrow: Zkuste projet PC timto ftp://ftp.symantec.com/public/english_u ... l_Tool.exe

:arrow: Prihlaste se do nouzoveho rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)

:arrow: Aplikujte tento skript pro ComboFix - postup je stejny

Kód: Vybrat vše

KillAll::

SecCenter::
AV: Aplikace Symantec Endpoint Protection *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C}
{FB06448E-52B8-493A-90F3-E43226D3305C}

Folder::
c:\documents and settings\Josef Dolansky\Local Settings\Data aplikací\3a7b1c23

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
"SSBkgdUpdate"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000

File::
c:\windows\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{548CF3DE-523A-494F-A758-7A7DC2482DFD}.job
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Acrobat Speed Launcher.lnk
C:\WINDOWS\tasks\User_Feed_Synchronization-{704311D2-9A90-44B7-B7AF-AA7A3EB9A8B3}.job
C:\WINDOWS\SET1F7.tmp
C:\WINDOWS\SET1EB.tmp
C:\WINDOWS\SET1E8.tmp
C:\WINDOWS\system32\1.tmp

RegLock::
[HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Microsoft\SystemCertificates\AddressBook*]
[HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Policies\Microsoft\SystemCertificates\AddressBook*]

RegNull::
[HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Microsoft\SystemCertificates\AddressBook*]
[HKEY_USERS\S-1-5-21-682003330-606747145-725345543-1007\Software\Policies\Microsoft\SystemCertificates\AddressBook*]

Driver::
MEMSWEEP2
uphcleanhlp

Reboot::
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět