Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Viry Sirefef.DT a Rootkit.Kryptik.FW

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Lucas89
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 pro 2011 12:30

Viry Sirefef.DT a Rootkit.Kryptik.FW

#1 Příspěvek od Lucas89 »

Dobrý den,

ESET mi našel 3 viry, z toho byl jeden Sirefef.DN, u kterého se ukázalo, že byl vyléčen smazáním, ale už několikrát mi ho našel znovu a znovu napsal, že byl vyléčen. Pak mi to pořád hází, že tu mám Sirefef.DT a Rootkit.Kryptik.FW, často se mi ukáže modrá obrazovka a počítač se restartuje. Hledal jsem rady na internetu, ale nic, co by mi pomohlo. Děkuji za rady.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:41:46, on 14.12.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19170)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ICQ7.5\ICQ.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGGE.EXE
C:\Windows\system32\taskeng.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: PC Tools Browser Defender - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: PC Tools Browser Defender - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [EPSON SX125 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGGE.EXE /FU "C:\Windows\TEMP\E_SFD04.tmp" /EF "HKCU"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: mestrim - C:\Windows\system32\config\systemprofile\AppData\Local\mestrim.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Unknown owner - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe (file missing)

--
End of file - 7551 bytes

Lucas89
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 pro 2011 12:30

Re: Viry Sirefef.DT a Rootkit.Kryptik.FW

#2 Příspěvek od Lucas89 »

OTL bylo bohužel taky moc dlouhé, tak to vkládám také jako přílohu.

VirusTotal: http://www.virustotal.com/file-scan/rep ... 1323872733
Přílohy
Extras.rar
(12.99 KiB) Staženo 64 x

Lucas89
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 pro 2011 12:30

Re: Viry Sirefef.DT a Rootkit.Kryptik.FW

#3 Příspěvek od Lucas89 »

OTL
Přílohy
OTL.rar
(44.97 KiB) Staženo 63 x

Lucas89
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 pro 2011 12:30

Re: Viry Sirefef.DT a Rootkit.Kryptik.FW

#4 Příspěvek od Lucas89 »

XueTr
Přílohy
xuetrlog.rar
(157.46 KiB) Staženo 48 x

Lucas89
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 pro 2011 12:30

Re: Viry Sirefef.DT a Rootkit.Kryptik.FW

#5 Příspěvek od Lucas89 »

ComboFix 11-12-13.03 - Lukáš 14.12.2011 23:36:18.1.1 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2046.1047 [GMT 1:00]
Spuštěný z: c:\users\LukßÜ\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *Enabled/Outdated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.0 *Enabled/Outdated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\DSC_0018s.jpg
C:\DSC_0568.jpg
c:\program files\ESET\MiNODLogin
c:\program files\ESET\MiNODLogin\MiNODLogin.jar
c:\program files\ESET\MiNODLogin\MiNODLoginLib.dll
c:\program files\ESET\MiNODLogin\servidores.xml
c:\windows\$NtUninstallKB38314$\3683864121\@
c:\windows\$NtUninstallKB38314$\3683864121\bckfg.tmp
c:\windows\$NtUninstallKB38314$\3683864121\cfg.ini
c:\windows\$NtUninstallKB38314$\3683864121\Desktop.ini
c:\windows\$NtUninstallKB38314$\3683864121\keywords
c:\windows\$NtUninstallKB38314$\3683864121\kwrd.dll
c:\windows\$NtUninstallKB38314$\3683864121\L\qnbwvoto
c:\windows\$NtUninstallKB38314$\3683864121\U\00000001.@
c:\windows\$NtUninstallKB38314$\3683864121\U\00000002.@
c:\windows\$NtUninstallKB38314$\3683864121\U\00000004.@
c:\windows\$NtUninstallKB38314$\3683864121\U\80000000.@
c:\windows\$NtUninstallKB38314$\3683864121\U\80000004.@
c:\windows\$NtUninstallKB38314$\3683864121\U\80000032.@
c:\windows\$NtUninstallKB38314$\853765422
c:\windows\PFRO.log
c:\windows\system32\fci.exe.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-14 do 2011-12-14 )))))))))))))))))))))))))))))))
.
.
2011-12-14 22:50 . 2011-12-14 22:51 -------- d-----w- c:\users\Lukáš\AppData\Local\temp
2011-12-14 22:50 . 2011-12-14 22:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-14 12:24 . 2011-12-14 12:24 512 ----a-w- C:\PhysicalMBR.bin
2011-12-14 09:21 . 2011-12-14 09:21 -------- d-----w- c:\users\Lukáš\AppData\Roaming\SUPERAntiSpyware.com
2011-12-14 09:18 . 2011-12-14 09:21 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-12-14 09:18 . 2011-12-14 09:18 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-12-13 20:39 . 2011-09-28 12:14 56840 ----a-w- c:\windows\system32\drivers\PCTBD.sys
2011-12-13 20:39 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll
2011-12-13 20:39 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-12-13 20:39 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll
2011-12-13 20:39 . 2011-11-14 15:07 1681360 ----a-w- c:\windows\PCTBDRes.dll
2011-12-13 20:36 . 2011-12-13 20:36 -------- d-----w- c:\program files\PC Tools
2011-12-13 20:34 . 2011-11-22 18:42 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-12-13 20:34 . 2011-12-14 09:28 -------- d-----w- c:\program files\Common Files\PC Tools
2011-12-13 20:27 . 2011-12-14 09:10 -------- d-----w- c:\programdata\PC Tools
2011-12-13 20:27 . 2011-12-13 20:27 -------- d-----w- c:\users\Lukáš\AppData\Roaming\TestApp
2011-12-13 18:16 . 2011-12-13 18:16 22 --sha-w- c:\users\Lukáš\AppData\Roaming\Sys2662.Config.Repository.bin
2011-12-13 18:15 . 2011-12-13 18:25 -------- d-----w- c:\program files\jv16 PowerTools 2011
2011-12-13 18:14 . 2007-04-10 00:06 8192 ----a-w- c:\windows\system32\E_DCINST.DLL
2011-12-13 18:14 . 2009-10-01 02:01 63488 ----a-w- c:\windows\system32\E_FD4BGGE.DLL
2011-12-13 17:58 . 2011-12-13 17:58 388096 ----a-r- c:\users\Lukáš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-13 17:57 . 2011-12-13 17:57 -------- d-----w- c:\program files\Trend Micro
2011-12-11 16:42 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-11 16:42 . 2011-12-11 16:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-06 10:09 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{25813B1A-514D-452F-ABE7-7C4D98816EDD}\mpengine.dll
2011-12-05 19:45 . 2011-12-05 19:49 -------- d-----w- c:\program files\Angry Birds Rio
2011-12-01 15:25 . 2011-12-01 15:25 1510160 ----a-w- c:\users\Lukáš\AppData\Roaming\AngryBirdsSeasons.exe
2011-11-26 18:46 . 2011-11-26 18:48 -------- d-----w- c:\program files\Free Video Flip and Rotate
2011-11-26 18:46 . 2011-11-26 18:47 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2011-11-22 18:33 . 2011-12-05 19:47 -------- d-----w- c:\users\Lukáš\AppData\Roaming\Rovio
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-13 18:16 . 2011-12-13 18:16 22 --sha-w- c:\users\Lukáš\AppData\Roaming\Sys2662.Config.Repository.bin
2011-12-13 18:16 . 2011-12-13 18:16 22 --sha-w- c:\users\Lukáš\AppData\Roaming\Sys2662.Config.Repository.bin
2011-12-13 17:58 . 2011-12-13 17:58 388096 ----a-r- c:\users\Lukáš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-13 17:58 . 2011-12-13 17:58 388096 ----a-r- c:\users\Lukáš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-01 15:25 . 2011-12-01 15:25 1510160 ----a-w- c:\users\Lukáš\AppData\Roaming\AngryBirdsSeasons.exe
2011-12-01 15:25 . 2011-12-01 15:25 1510160 ----a-w- c:\users\Lukáš\AppData\Roaming\AngryBirdsSeasons.exe
2011-09-20 21:02 . 2011-11-09 15:01 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OODIIcon]
@="{14A94384-BBED-47ed-86C0-6BF63FD892D0}"
[HKEY_CLASSES_ROOT\CLSID\{14A94384-BBED-47ed-86C0-6BF63FD892D0}]
2011-03-14 06:13 111944 ----a-w- c:\program files\OO Software\DiskImage\oodishi.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"ICQ"="c:\program files\ICQ7.5\ICQ.exe" [2011-08-01 124480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 4431872]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mestrim]
2011-12-13 18:17 11264 ----a-w- c:\windows\System32\config\systemprofile\AppData\Local\mestrim.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iv39od7ft9
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Plugin
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2010-08-20 11:03 33120 ----a-w- c:\program files\Alcohol 120\AxAutoMntSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
2009-04-02 16:05 102400 ----a-w- c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-03-05 15:32 1135912 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-18 21:33 125952 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FTweakFCleaner]
2010-06-21 12:56 1763840 ----a-w- c:\program files\FCleaner\FCleaner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-02-09 07:38 133104 ----atw- c:\users\Lukáš\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2009-09-11 22:34 2524416 ----a-w- c:\program files\OO Software\Defrag\oodtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODITRAY.EXE]
2011-03-14 06:13 2196808 ----a-w- c:\program files\OO Software\DiskImage\ooditray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-07-07 07:34 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\recinfo234]
2007-10-23 12:52 2764800 ----a-w- c:\recinfo\RecInfo.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-03-27 07:55 24103720 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2006-11-10 20:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-25 03:23 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-18 21:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter
"fsc-reg"=c:\programdata\fsc-reg\fscreg.exe 20081205
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"FTweakFCleaner"=c:\program files\FCleaner\FCleaner.exe -a
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"RestartNeroSetup"="c:\users\LUK~1\AppData\Local\Temp\Nero Web\SetupXu.exe" MODE="update" STARTMODE="2" USERSEL="3" FAMILYNAME="Nero 7" RUNSETUPXU="1" UPGRADE="1"
"SMSERIAL"=c:\program files\Motorola\SMSERIAL\sm56hlpr.exe
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"SweetIM"=c:\program files\SweetIM\Messenger\SweetIM.exe
"Windows Mobile Device Center"=%windir%\WindowsMobile\wmdc.exe
"Ask and Record FLV Service"="c:\program files\Replay Media Catcher\FLVSrvc.exe" /run
"NPSStartup"=
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3854760281-1819818035-693825289-1000]
"EnableNotificationsRef"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD.sys [2011-09-28 56840]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-31 233472]
R4 gupdate1c9bba11f01461b;Služba Google Update (gupdate1c9bba11f01461b);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-12 133104]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-12 133104]
R4 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R4 OO DiskImage;OO DiskImage;c:\program files\OO Software\DiskImage\oodiag.exe [2011-03-14 2815304]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S0 oodisr;O&O DiskImage Snapshot/Restore Driver;c:\windows\system32\DRIVERS\oodisr.sys [2011-03-14 96336]
S0 oodisrh;oodisrh;c:\windows\system32\DRIVERS\oodisrh.sys [2011-03-14 28752]
S0 oodivd;O&O DiskImage Virtual Devices Driver;c:\windows\system32\DRIVERS\oodivd.sys [2011-03-14 171088]
S0 oodivdh;oodivdh;c:\windows\system32\DRIVERS\oodivdh.sys [2011-03-14 31824]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-03-12 436792]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2011-11-14 546768]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-04-04 46592]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-12 19:01]
.
2011-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-12 19:01]
.
2011-02-15 c:\windows\Tasks\User_Feed_Synchronization-{8CE03A15-C6DE-4DBF-9630-4D7EAFEFA9F2}.job
- c:\windows\system32\msfeedssync.exe [2011-12-13 04:44]
.
.
------- Doplňkový sken -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\qb9rzm7n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: QuickJava: {E6C1199F-E687-42da-8C24-E7770CC3AE66} - %profile%\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}
FF - Ext: Strata40: Strata40@SpewBoy.au - %profile%\extensions\Strata40@SpewBoy.au
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Media Plugin: plugin3@gameplaylabs.com - %profile%\extensions\plugin3@gameplaylabs.com
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
------- Asociace souborů -------
.
inifile\shell\mv2player\command="c:\program files\Mv2Player\Mv2PlayerPlus.exe" "%1"
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-ICQ - ~c:\program files\ICQ7.2\ICQ.exe
MSConfigStartUp-recinfo - RecInfo.exe
MSConfigStartUp-Regedit32 - c:\windows\system32\regedit.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-14 23:51
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="61B3B3F345714AA890D2487A8C8C222672C627200E806F9524AC9C86546440D6DA6502377BAD50D475663E2146F151AB9BDD5C5E4272C492692CA9CD02F1E69F2D2268785EEDAD5ABA991751540E49174756BBB56478C82BD6C04ECA0CED3F6C3BE1A4234E327D0323C1F6BAC74C61863A80F43BD310ACF1D3D6E397C47F6E632C5056F4AE70022AB665E760348F14AB7C611857F527428F098FA42483C14341EAC8808166911F4442C0D799B32EFD4EDB2F1DC5B5A1013E65C1B02FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808FEBC9E127BECC74CBA7FD869164D6794FEBC9E127BECC74C52D3D28CAA737354010BF4AE300FAACB07CA5AB1A0A1F5F0D902DB2B591DC22461CB18EFD1C16E00A57D4C04C70C6BF6810643D6F97BF0B76714CB59FCA74163B91846DB95A5781C3410BB3EA8B87058DD1F8CF0B8DB358D8E8326C4F412032B0EC7D38E590EDD5BAED911125923B0268DDEFC47230E01D153644C6AE906309C0FDC5AD9452151C818EBBF46A48D077108FE01384590F9B53E4042DBC6DC58B0F94E182348376ABE7D49DF3697ECB499C7B229B16D15A842D894313EBC276B330884EEE593DCA2EE6A68A95006EBDAD64C1B283AAF83F95034D1E5C9C0A73F437ADD64311B5258DE71B47D98056503B017D1566863F43D8FE25D524D89578D56172CA2A4198B4EE5278D5FA6EEEC9606AF6230E7A238A703FD8F0A299360F232A637F77909B1AA33A5C4F3A5E1C8668720CCD4FACC515181213647D21F2471F3F3B656782E22F7450CA208553F6F24BC7706897405F4B5346A9166543134ED0BD15A527F0DEBA471F9E10A08AE91E97E4874B4BEB30E379BFED766499058333B13C3A6816ED4836095B00B24190F31F92975E253823C988905316FE34A0C6C1C9188B2055ED3C91089B3C4A6AD7ED9B2B3D843C361D00326A93AC86A2E802C1929B27624AF9692CF0380119E5E2827FC09622BB3835282EA9B855FB45097E8F23B41970D777E5DC4B2A2ED2F600AC0834949125D5F7B87A70F17C3318868F9BCAC2561010E9D0A68CE987F8F2FD5B1C29DBB120B30BBE67DBA67AB60F3C01F5E6544C1D791BE610792D68B0A8771E90D2ED76D1D75B45864DBE36FD6F21EF614517A48FAE25E0DC1B8C2FD7F6C753C09AAB10709F2BDF827B16E0C3F28B489EC6393AD69A6AA1A0C0639E4E1A331DF30C5D2E6D6AE5F48647E5B2256FB6CBECC8DD2CA35450A7D30BD86F3B93823F0CF3635B822F45AAB0F8BF3776D9B5F64EB4BEC9D836D158B4AA9F08222F784EF89B74ACC1B54216BEC2374F469F6DFABD5970EC710101800CB192D89C874BB3D5406F696869FD8331A968E26C4C26EA9EAF1D290296193F7F8DC6729730368A3F76711AEBC"
"OODI05.00.00.01PRO"="1FE94BD6FB726A10E9707C2BD7420FB4CF98FD30C5417F39DA4D681F0FAE3CE8C977A0DECC60CD0352A5F69F008CEDC2FDF5D558B1E1BDC016D6FC0622EF8C1B211E574092DE2DF5E36351A010F95AC306324DF2DB8534E336099EBE5BE73F1368AE9A989AA6001E9DCEFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98088EDD5E5BE2F6E6678EDD5E5BE2F6E667FEBC9E127BECC74C3556B205A741B0B4EA86A34E24443EC9E499713C0DC68EA3F30BCF3C851CF850C55B3E66FC39BBA9ED5B0BF8CE71D0790959E399DC0140636992FD76CE6D8BADD4764229D6302DCB563B146E04AD9D41954620332F8C6F514E59436B6C48FE00C89FFAB61326A063E8FBE3DF56E778BF502FD39DE6E24E0109CCF7B22FD378F0C401864F971056CCADA283505803DC29C298924268742E1AC38E57BAEE2B453BB7F96C86C9D8B4FBF1EC6119245467C1383C51DB9E2485576C7480C506DFD6304E9B1340165DC3F34448CEE355A45BE2C3856AFDF647EE08368776E9D2F43FB27BACC73AEDEB31CEF9597F320EB41DFD3A159E8B62ABAA109505A11038E2B53DF7293A82434CCCB82B780FD67233B89233C00DBD570E9B65465E4C751C95185ABE3D7FF98D360C75B2AE797A2A495AB80E8FBEA14EA2C79545BAA62DEA6D65AA0E4D8F59C8D708D7313EA018E10F54996ABE1C1746105ABD55F1C31C123DC16368EFC62BF5CFFC4A8B194A7F4C939CF22EBEF5D3BFF12312FB131BFC04CE744C976EE5CD96364CC96A679E541BD7CB1903B37C61C1D593D984DC88DC37DBE84024481274B391FA6838842C100A5322715476471B5440C270FCC74B1D27173232DE2FD12558E0B14B260064FAD36F81F4D414CFB18628EB4436FC0674D2A280245A8A92BA9493BEA9289D1CB83909ED33784C752A69F66F594659416CBB972D2FEC74A5E4FA8F90D276530D3B7FF212CEF993F9DE928DCDC6096DE6626901B380333B3E2625ADBD280D4F54C9EEF3BBFCD492047A1C3FAFB89C7F4809655FB4D50C62F355AC3BFD1EACEE73015445DC084BA69D7E23505E6D61099665BF27F407199F459BB278AFBE59C6CF5080158CCF615FB540497ECAB87EB86BD00BBFD9F8C3DC917ADA1B53A55A1E34FB470603C4E1019EE735F886015FEF41F95C85712A353A9CC2CB4C0C85BC704B9A822D1FED59858FF18EDFC842AFC1F6624FC8E92ADD08109BB22825A3CF6DA71A8D15E1E41898A0AF05CCEA8BE2F9D0DF044D199D7150777F3D408A59297840384ABB72D9B41BD146494AEE80AE95F51B1A4AF43BE4C9C3BE201A4D931F296C891D139A0D8620062E915775D88EC6F0143B6D1B527465497A142E2254CE4BEAF5ED0146562CF18334966646DD3FF0321B1055CA402044BFA9D26A"
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2011-12-15 00:02:37
ComboFix-quarantined-files.txt 2011-12-14 23:02
.
Před spuštěním: 3 187 884 032
Po spuštění: 5 014 003 712
.
- - End Of File - - 680015C77431BAC62B23F355364BE1D1

Lucas89
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 pro 2011 12:30

Re: Viry Sirefef.DT a Rootkit.Kryptik.FW

#6 Příspěvek od Lucas89 »

ok, hotovo.

Lucas89
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 pro 2011 12:30

Re: Viry Sirefef.DT a Rootkit.Kryptik.FW

#7 Příspěvek od Lucas89 »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Lukáš at 2011-12-15 10:24:46
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 6 GB (4%) free of 152 GB
Total RAM: 2046 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:26:05, on 15.12.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19170)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ICQ7.5\ICQ.exe
C:\Windows\system32\taskeng.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lukáš\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Users\Lukáš\Desktop\RSIT.exe
C:\Program Files\trend micro\Lukáš.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: PC Tools Browser Defender - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: PC Tools Browser Defender - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: mestrim - C:\Windows\system32\config\systemprofile\AppData\Local\mestrim.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Unknown owner - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe (file missing)

--
End of file - 6807 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{8CE03A15-C6DE-4DBF-9630-4D7EAFEFA9F2}.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\qb9rzm7n.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8, {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8, {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15, {E6C1199F-E687-42da-8C24-E7770CC3AE66}:1.7.2, {dc572301-7619-498c-a57d-39143191b318}:0.3.8.6, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.3, plugin3@gameplaylabs.com:3.0, {20a82645-c095-46ed-80e3-08825760534b}:0.0.0, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.9, Strata40@SpewBoy.au:0.6.2"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.9&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{cb84136f-9c44-433a-9048-c5cd9df1dc16}"=C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@zylom.com/ZylomGamesPlayer]
"Description"=Zylom Games Player 1.00
"Path"=C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsIQTScriptablePlugin.xpt
nsIZylomPlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeploytk.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
npzylomgamesplayer.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\qb9rzm7n.default\extensions\
plugin3@gameplaylabs.com
staged-xpis
Strata40@SpewBoy.au
{800b5000-a755-47e1-992b-48a1c1357f07}
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
{dc572301-7619-498c-a57d-39143191b318}
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
{E6C1199F-E687-42da-8C24-E7770CC3AE66}

C:\Users\Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\qb9rzm7n.default\searchplugins\
amazondotcom.xml
ebay.xml
icqplugin-1.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.gif
icqplugin.src
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Defender BHO - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll [2011-11-14 1144784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-29 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-29 266240]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Defender - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll [2011-11-14 1144784]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-04-10 4431872]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-05-14 2029640]
"EEventManager"=C:\Program Files\Epson Software\Event Manager\EEventManager.exe [2009-12-03 976320]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1233920]
"ICQ"=C:\Program Files\ICQ7.5\ICQ.exe [2011-08-01 124480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files\Alcohol 120\AxAutoMntSrv.exe [2010-08-20 33120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-03-05 1135912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
C:\Windows\ehome\ehTray.exe [2008-01-18 125952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FTweakFCleaner]
C:\Program Files\FCleaner\FCleaner.exe [2010-06-21 1763840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Lukáš\AppData\Local\Google\Update\GoogleUpdate.exe [2009-02-09 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Program Files\OO Software\Defrag\oodtray.exe [2009-09-11 2524416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODITRAY.EXE]
C:\Program Files\OO Software\DiskImage\ooditray.exe [2011-03-14 2196808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE [2008-07-07 167936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\recinfo234]
c:\RecInfo\RecInfo.exe [2007-10-23 2764800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2009-03-27 24103720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-25 149280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-18 1008184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
C:\PROGRA~1\MCAFEE~1\20DEB9~1.181\SSSCHE~1.EXE []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2011-05-04 551296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mestrim]
C:\Windows\system32\config\system [2011-12-15 26476544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.cvid"=iccvid.dll
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.iac2"=iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=l3codeca.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.divxa32"=divxa32.acm
"vidc.mp43"=mpg4c32.dll
"vidc.ffds"=C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"wave1"=serwvdrv.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-12-15 10:24:46 ----D---- C:\rsit
2011-12-15 10:24:46 ----D---- C:\Program Files\trend micro
2011-12-15 00:02:53 ----SHD---- C:\$RECYCLE.BIN
2011-12-15 00:02:42 ----D---- C:\Windows\temp
2011-12-15 00:02:38 ----A---- C:\ComboFix.txt
2011-12-14 23:27:04 ----A---- C:\Windows\zip.exe
2011-12-14 23:27:04 ----A---- C:\Windows\SWSC.exe
2011-12-14 23:27:04 ----A---- C:\Windows\SWREG.exe
2011-12-14 23:27:04 ----A---- C:\Windows\sed.exe
2011-12-14 23:27:04 ----A---- C:\Windows\PEV.exe
2011-12-14 23:27:04 ----A---- C:\Windows\NIRCMD.exe
2011-12-14 23:27:04 ----A---- C:\Windows\MBR.exe
2011-12-14 23:27:04 ----A---- C:\Windows\grep.exe
2011-12-14 23:26:56 ----D---- C:\Windows\ERDNT
2011-12-14 23:23:42 ----D---- C:\Qoobox
2011-12-14 11:58:30 ----ASH---- C:\hiberfil.sys
2011-12-14 10:37:55 ----A---- C:\Windows\ntbtlog.txt
2011-12-14 10:21:17 ----D---- C:\Users\Lukáš\AppData\Roaming\SUPERAntiSpyware.com
2011-12-14 10:18:39 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-12-14 10:18:39 ----D---- C:\Program Files\SUPERAntiSpyware
2011-12-13 21:39:59 ----A---- C:\Windows\system32\drivers\PCTBD.sys
2011-12-13 21:39:58 ----A---- C:\Windows\BDTSupport.dll
2011-12-13 21:39:57 ----A---- C:\Windows\SGDetectionTool.dll
2011-12-13 21:39:56 ----A---- C:\Windows\PCTBDRes.dll
2011-12-13 21:39:56 ----A---- C:\Windows\PCTBDCore.dll
2011-12-13 21:36:42 ----D---- C:\Program Files\PC Tools
2011-12-13 21:35:49 ----A---- C:\Windows\system32\drivers\Cat.DB
2011-12-13 21:34:33 ----A---- C:\Windows\system32\drivers\PCTSD.sys
2011-12-13 21:34:09 ----D---- C:\Program Files\Common Files\PC Tools
2011-12-13 21:27:51 ----D---- C:\ProgramData\PC Tools
2011-12-13 21:27:50 ----D---- C:\Users\Lukáš\AppData\Roaming\TestApp
2011-12-13 19:24:50 ----A---- C:\Windows\system32\win32k.sys
2011-12-13 19:24:47 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-13 19:24:44 ----A---- C:\Windows\system32\urlmon.dll
2011-12-13 19:24:43 ----A---- C:\Windows\system32\wininet.dll
2011-12-13 19:24:43 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-13 19:24:42 ----A---- C:\Windows\system32\iertutil.dll
2011-12-13 19:24:41 ----A---- C:\Windows\system32\url.dll
2011-12-13 19:24:39 ----A---- C:\Windows\system32\mshtml.dll
2011-12-13 19:24:34 ----A---- C:\Windows\system32\ieframe.dll
2011-12-13 19:24:32 ----A---- C:\Windows\system32\mstime.dll
2011-12-13 19:24:32 ----A---- C:\Windows\system32\msfeeds.dll
2011-12-13 19:24:31 ----A---- C:\Windows\system32\occache.dll
2011-12-13 19:24:31 ----A---- C:\Windows\system32\ieui.dll
2011-12-13 19:24:31 ----A---- C:\Windows\system32\iepeers.dll
2011-12-13 19:24:31 ----A---- C:\Windows\system32\iedkcs32.dll
2011-12-13 19:24:30 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-13 19:24:30 ----A---- C:\Windows\system32\msfeedssync.exe
2011-12-13 19:24:30 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-12-13 19:24:30 ----A---- C:\Windows\system32\licmgr10.dll
2011-12-13 19:24:30 ----A---- C:\Windows\system32\ieUnatt.exe
2011-12-13 19:24:30 ----A---- C:\Windows\system32\iesysprep.dll
2011-12-13 19:24:30 ----A---- C:\Windows\system32\iesetup.dll
2011-12-13 19:24:30 ----A---- C:\Windows\system32\iernonce.dll
2011-12-13 19:24:30 ----A---- C:\Windows\system32\ie4uinit.exe
2011-12-13 19:24:26 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-12-13 19:24:25 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-12-13 19:24:19 ----A---- C:\Windows\system32\tzres.dll
2011-12-13 19:24:00 ----A---- C:\Windows\system32\EncDec.dll
2011-12-13 19:15:54 ----D---- C:\Program Files\jv16 PowerTools 2011
2011-12-13 19:14:18 ----A---- C:\Windows\system32\E_DCINST.DLL
2011-12-13 19:14:09 ----A---- C:\Windows\system32\E_FD4BGGE.DLL
2011-12-11 17:42:10 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-12-11 17:42:09 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-12-05 20:45:19 ----D---- C:\Program Files\Angry Birds Rio
2011-12-01 16:25:46 ----A---- C:\Users\Lukáš\AppData\Roaming\AngryBirdsSeasons.exe
2011-11-26 19:46:50 ----D---- C:\Program Files\Free Video Flip and Rotate
2011-11-26 19:46:50 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2011-11-22 19:33:28 ----D---- C:\Users\Lukáš\AppData\Roaming\Rovio

======List of files/folders modified in the last 1 month======

2011-12-15 10:24:46 ----D---- C:\Program Files
2011-12-15 10:21:51 ----SHD---- C:\System Volume Information
2011-12-15 10:19:42 ----D---- C:\Windows\System32
2011-12-15 10:19:42 ----D---- C:\Windows\inf
2011-12-15 10:19:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-15 10:13:09 ----AD---- C:\ProgramData\TEMP
2011-12-15 10:13:04 ----D---- C:\Windows
2011-12-14 23:58:05 ----D---- C:\Windows\Tasks
2011-12-14 23:51:56 ----A---- C:\Windows\system.ini
2011-12-14 23:51:36 ----D---- C:\Windows\system32\drivers\etc
2011-12-14 23:50:07 ----D---- C:\Program Files\ESET
2011-12-14 23:45:35 ----D---- C:\Windows\system32\drivers
2011-12-14 23:45:35 ----D---- C:\Windows\AppPatch
2011-12-14 23:45:31 ----D---- C:\Program Files\Common Files
2011-12-14 23:30:30 ----DC---- C:\Windows\$NtUninstallKB38314$
2011-12-14 10:21:16 ----D---- C:\ProgramData
2011-12-13 21:51:36 ----D---- C:\Users\Lukáš\AppData\Roaming\Azureus
2011-12-13 21:37:38 ----SHD---- C:\Windows\Installer
2011-12-13 21:37:37 ----D---- C:\Windows\winsxs
2011-12-13 21:17:35 ----D---- C:\Windows\rescache
2011-12-13 20:32:37 ----D---- C:\Lukáš
2011-12-13 20:19:39 ----D---- C:\Windows\system32\catroot
2011-12-13 20:12:11 ----D---- C:\Windows\system32\cs-CZ
2011-12-13 20:12:11 ----D---- C:\Program Files\Windows Mail
2011-12-13 20:12:11 ----D---- C:\Program Files\Internet Explorer
2011-12-13 20:12:10 ----D---- C:\Windows\system32\migration
2011-12-13 19:31:32 ----A---- C:\Windows\system32\mrt.exe
2011-12-13 19:24:02 ----D---- C:\Windows\system32\catroot2
2011-12-13 19:21:26 ----D---- C:\Windows\system32\oodag
2011-12-13 19:15:38 ----D---- C:\Windows\Prefetch
2011-12-13 19:07:06 ----SD---- C:\Windows\Downloaded Program Files
2011-12-13 19:02:55 ----D---- C:\Program Files\QIP
2011-12-12 08:31:51 ----RSD---- C:\Windows\Media
2011-12-12 08:31:50 ----D---- C:\Windows\ServiceProfiles
2011-12-10 01:07:51 ----D---- C:\Windows\Minidump
2011-12-08 23:09:58 ----D---- C:\Windows\system32\Tasks
2011-11-30 14:58:16 ----D---- C:\Program Files\Google
2011-11-29 16:05:05 ----D---- C:\Users\Lukáš\AppData\Roaming\ICQ
2011-11-24 23:15:34 ----D---- C:\Program Files\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-02-12 277784]
R0 oodisr;O&O DiskImage Snapshot/Restore Driver; C:\Windows\system32\DRIVERS\oodisr.sys [2011-03-14 96336]
R0 oodisrh;oodisrh; C:\Windows\system32\DRIVERS\oodisrh.sys [2011-03-14 28752]
R0 oodivd;O&O DiskImage Virtual Devices Driver; C:\Windows\system32\DRIVERS\oodivd.sys [2011-03-14 171088]
R0 oodivdh;oodivdh; C:\Windows\system32\DRIVERS\oodivdh.sys [2011-03-14 31824]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\Windows\System32\drivers\sfhlp02.sys [2005-02-23 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\Windows\System32\drivers\sfsync02.sys [2005-04-14 19968]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-03-12 436792]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
R1 epfwtdi;epfwtdi; C:\Windows\system32\DRIVERS\epfwtdi.sys [2009-05-14 55768]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys [2008-05-24 73728]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2008-07-07 56108]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-05-14 114472]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2009-05-14 133000]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-09-05 1183744]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-10-11 3155456]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2009-05-14 33096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-04-10 1764960]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2007-04-04 46592]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-08-31 22216]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-18 18432]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2010-06-23 259176]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-05-05 1095808]
S0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\Windows\System32\drivers\sfdrv01.sys [2005-04-04 48640]
S3 a1h6f7yf;a1h6f7yf; C:\Windows\system32\drivers\a1h6f7yf.sys []
S3 catchme;catchme; \??\C:\Users\LUK~1\AppData\Local\Temp\catchme.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 Inspect;Comodo Firewall Network Driver; C:\Windows\system32\DRIVERS\inspect.sys []
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\Windows\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\k750mdfl.sys [2005-07-07 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\Windows\system32\DRIVERS\k750mdm.sys [2005-07-07 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\Windows\system32\DRIVERS\k750mgmt.sys [2005-07-07 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\Windows\system32\DRIVERS\k750obex.sys [2005-07-07 79488]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 PCTBD;PC Tools Browser Defender Driver; C:\Windows\System32\Drivers\PCTBD.sys [2011-09-28 56840]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-04-10 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-18 35328]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-18 134016]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
S4 JRAID;JRAID; C:\Windows\system32\drivers\jraid.sys [2007-06-13 48256]
S4 nvrd32;NVIDIA nForce RAID Driver; C:\Windows\system32\drivers\nvrd32.sys [2007-07-02 131616]
S4 nvstor32;nvstor32; C:\Windows\system32\drivers\nvstor32.sys [2007-07-02 110112]
S4 viamraid;viamraid; C:\Windows\system32\drivers\viamraid.sys [2006-11-08 102912]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2011-08-12 116608]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-10-11 610304]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2011-11-14 546768]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
R2 O&O Defrag;O&O Defrag; C:\Program Files\OO Software\Defrag\oodag.exe [2009-09-11 1488128]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-18 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 TestHandler;Fujitsu Siemens Computers Diagnostic Testhandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe []
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-05-14 20680]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-03-31 233472]
S4 gupdate1c9bba11f01461b;Služba Google Update (gupdate1c9bba11f01461b); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-12 133104]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-12 133104]
S4 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S4 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 OO DiskImage;OO DiskImage; C:\Program Files\OO Software\DiskImage\oodiag.exe [2011-03-14 2815304]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2006-07-20 262247]
S4 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S4 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]

-----------------EOF-----------------

---------------------------------------------------------
---------------------------------------------------------
TDSSKiller

10:49:25.0364 3232 TDSS rootkit removing tool 2.6.23.0 Dec 13 2011 10:39:31
10:49:25.0529 3232 ============================================================
10:49:25.0529 3232 Current date / time: 2011/12/15 10:49:25.0529
10:49:25.0529 3232 SystemInfo:
10:49:25.0529 3232
10:49:25.0529 3232 OS Version: 6.0.6002 ServicePack: 2.0
10:49:25.0529 3232 Product type: Workstation
10:49:25.0530 3232 ComputerName: LUKÁŠ
10:49:25.0530 3232 UserName: Lukáš
10:49:25.0530 3232 Windows directory: C:\Windows
10:49:25.0530 3232 System windows directory: C:\Windows
10:49:25.0530 3232 Processor architecture: Intel x86
10:49:25.0530 3232 Number of processors: 1
10:49:25.0530 3232 Page size: 0x1000
10:49:25.0530 3232 Boot type: Normal boot
10:49:25.0530 3232 ============================================================
10:49:26.0287 3232 Initialize success
10:49:51.0381 3576 ============================================================
10:49:51.0381 3576 Scan started
10:49:51.0381 3576 Mode: Manual; SigCheck; TDLFS;
10:49:51.0381 3576 ============================================================
10:49:51.0816 3576 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
10:49:52.0041 3576 ACPI - ok
10:49:52.0113 3576 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
10:49:52.0213 3576 adp94xx - ok
10:49:52.0264 3576 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
10:49:52.0294 3576 adpahci - ok
10:49:52.0343 3576 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
10:49:52.0365 3576 adpu160m - ok
10:49:52.0418 3576 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
10:49:52.0442 3576 adpu320 - ok
10:49:52.0528 3576 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
10:49:52.0643 3576 AFD - ok
10:49:52.0718 3576 agp440 (198636e76971ebc96404547ec0fd5e75) C:\Windows\system32\drivers\agp440.sys
10:49:52.0758 3576 agp440 - ok
10:49:52.0808 3576 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
10:49:52.0835 3576 aic78xx - ok
10:49:52.0891 3576 aliide (0b3b337a68d9a75cc8d787dc98b53d79) C:\Windows\system32\drivers\aliide.sys
10:49:52.0907 3576 aliide - ok
10:49:52.0960 3576 amdagp (2363abc8989a14fd7247ca6f4e89d397) C:\Windows\system32\drivers\amdagp.sys
10:49:52.0974 3576 amdagp - ok
10:49:53.0018 3576 amdide (468a204966d09f327a662c35f4b15dd3) C:\Windows\system32\drivers\amdide.sys
10:49:53.0058 3576 amdide - ok
10:49:53.0104 3576 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
10:49:53.0328 3576 AmdK7 - ok
10:49:53.0369 3576 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
10:49:53.0469 3576 AmdK8 - ok
10:49:53.0532 3576 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
10:49:53.0553 3576 arc - ok
10:49:53.0594 3576 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
10:49:53.0673 3576 arcsas - ok
10:49:53.0733 3576 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
10:49:53.0907 3576 AsyncMac - ok
10:49:53.0952 3576 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
10:49:53.0989 3576 atapi - ok
10:49:54.0058 3576 athr (2846f5ee802889d500fcf5cc48b28381) C:\Windows\system32\DRIVERS\athr.sys
10:49:54.0183 3576 athr - ok
10:49:54.0329 3576 atikmdag (389a2668e0c0c6698a6b565632c7f43a) C:\Windows\system32\DRIVERS\atikmdag.sys
10:49:54.0583 3576 atikmdag - ok
10:49:54.0658 3576 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
10:49:54.0720 3576 Beep - ok
10:49:54.0756 3576 blbdrive - ok
10:49:54.0813 3576 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
10:49:54.0961 3576 bowser - ok
10:49:55.0027 3576 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
10:49:55.0155 3576 BrFiltLo - ok
10:49:55.0209 3576 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
10:49:55.0293 3576 BrFiltUp - ok
10:49:55.0355 3576 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
10:49:55.0500 3576 Brserid - ok
10:49:55.0535 3576 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
10:49:55.0613 3576 BrSerWdm - ok
10:49:55.0658 3576 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
10:49:55.0739 3576 BrUsbMdm - ok
10:49:55.0775 3576 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
10:49:55.0844 3576 BrUsbSer - ok
10:49:55.0889 3576 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
10:49:55.0972 3576 BTHMODEM - ok
10:49:56.0080 3576 catchme - ok
10:49:56.0129 3576 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
10:49:56.0195 3576 cdfs - ok
10:49:56.0252 3576 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
10:49:56.0348 3576 cdrom - ok
10:49:56.0404 3576 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
10:49:56.0461 3576 circlass - ok
10:49:56.0527 3576 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
10:49:56.0559 3576 CLFS - ok
10:49:56.0623 3576 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
10:49:56.0676 3576 CmBatt - ok
10:49:56.0728 3576 cmdide (2ac0c92b29ec21838f4cb46adb26bcc0) C:\Windows\system32\drivers\cmdide.sys
10:49:56.0774 3576 cmdide - ok
10:49:56.0824 3576 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
10:49:56.0843 3576 Compbatt - ok
10:49:56.0877 3576 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
10:49:56.0895 3576 crcdisk - ok
10:49:56.0931 3576 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
10:49:57.0092 3576 Crusoe - ok
10:49:57.0176 3576 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
10:49:57.0268 3576 DfsC - ok
10:49:57.0351 3576 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
10:49:57.0430 3576 disk - ok
10:49:57.0567 3576 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
10:49:57.0695 3576 drmkaud - ok
10:49:57.0780 3576 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
10:49:57.0855 3576 DXGKrnl - ok
10:49:57.0908 3576 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
10:49:58.0073 3576 E1G60 - ok
10:49:58.0141 3576 eamon (e31464ce787e3a0ffea55baa591897f0) C:\Windows\system32\DRIVERS\eamon.sys
10:49:58.0322 3576 eamon - ok
10:49:58.0405 3576 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
10:49:58.0443 3576 Ecache - ok
10:49:58.0514 3576 ehdrv (2c95a7a87e4272c1fff9baf579677db3) C:\Windows\system32\DRIVERS\ehdrv.sys
10:49:58.0540 3576 ehdrv - ok
10:49:58.0700 3576 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
10:49:58.0850 3576 elxstor - ok
10:49:58.0933 3576 epfw (c2c9a92b560a775c65b89e78dcb6951a) C:\Windows\system32\DRIVERS\epfw.sys
10:49:58.0947 3576 epfw - ok
10:49:58.0989 3576 Epfwndis (73fc7c4a5952b5493c6be2708d1538c0) C:\Windows\system32\DRIVERS\Epfwndis.sys
10:49:59.0000 3576 Epfwndis - ok
10:49:59.0063 3576 epfwtdi (cd6d97a7a88a78fa6f1732b75971ead0) C:\Windows\system32\DRIVERS\epfwtdi.sys
10:49:59.0074 3576 epfwtdi - ok
10:49:59.0171 3576 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
10:49:59.0309 3576 exfat - ok
10:49:59.0378 3576 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
10:49:59.0455 3576 fastfat - ok
10:49:59.0514 3576 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
10:49:59.0603 3576 fdc - ok
10:49:59.0682 3576 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
10:49:59.0704 3576 FileInfo - ok
10:49:59.0747 3576 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
10:49:59.0855 3576 Filetrace - ok
10:49:59.0920 3576 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
10:50:00.0021 3576 flpydisk - ok
10:50:00.0061 3576 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
10:50:00.0082 3576 FltMgr - ok
10:50:00.0198 3576 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\Windows\system32\FsUsbExDisk.SYS
10:50:00.0222 3576 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
10:50:00.0222 3576 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
10:50:00.0299 3576 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
10:50:00.0376 3576 Fs_Rec - ok
10:50:00.0429 3576 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
10:50:00.0447 3576 gagp30kx - ok
10:50:00.0544 3576 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
10:50:00.0669 3576 HdAudAddService - ok
10:50:00.0735 3576 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
10:50:00.0824 3576 HDAudBus - ok
10:50:00.0869 3576 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
10:50:01.0006 3576 HidBth - ok
10:50:01.0059 3576 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
10:50:01.0113 3576 HidIr - ok
10:50:01.0164 3576 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
10:50:01.0208 3576 HidUsb - ok
10:50:01.0255 3576 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
10:50:01.0273 3576 HpCISSs - ok
10:50:01.0337 3576 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
10:50:01.0447 3576 HTTP - ok
10:50:01.0491 3576 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
10:50:01.0507 3576 i2omp - ok
10:50:01.0557 3576 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
10:50:01.0597 3576 i8042prt - ok
10:50:01.0651 3576 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\Windows\system32\DRIVERS\iaStor.sys
10:50:01.0668 3576 iaStor - ok
10:50:01.0721 3576 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
10:50:01.0743 3576 iaStorV - ok
10:50:01.0823 3576 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
10:50:01.0837 3576 iirsp - ok
10:50:01.0872 3576 Inspect - ok
10:50:01.0960 3576 IntcAzAudAddService (4fa59a84069d9d0991bae34cc4aff99c) C:\Windows\system32\drivers\RTKVHDA.sys
10:50:02.0095 3576 IntcAzAudAddService - ok
10:50:02.0150 3576 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
10:50:02.0196 3576 intelide - ok
10:50:02.0253 3576 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
10:50:02.0315 3576 intelppm - ok
10:50:02.0371 3576 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:50:02.0429 3576 IpFilterDriver - ok
10:50:02.0458 3576 IpInIp - ok
10:50:02.0520 3576 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
10:50:02.0667 3576 IPMIDRV - ok
10:50:02.0772 3576 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
10:50:02.0856 3576 IPNAT - ok
10:50:02.0907 3576 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
10:50:03.0019 3576 IRENUM - ok
10:50:03.0050 3576 isapnp (ce2997a0c3b0049a3188c4f0c7a04bc9) C:\Windows\system32\drivers\isapnp.sys
10:50:03.0064 3576 isapnp - ok
10:50:03.0113 3576 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
10:50:03.0132 3576 iScsiPrt - ok
10:50:03.0214 3576 ISODrive (bf71a06ff065e3fd7e32ea67dca34885) C:\Program Files\UltraISO\drivers\ISODrive.sys
10:50:03.0250 3576 ISODrive ( UnsignedFile.Multi.Generic ) - warning
10:50:03.0250 3576 ISODrive - detected UnsignedFile.Multi.Generic (1)
10:50:03.0297 3576 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
10:50:03.0314 3576 iteatapi - ok
10:50:03.0370 3576 itecir (e4b04a0d8b237ecf026d849439f1bcce) C:\Windows\system32\DRIVERS\itecir.sys
10:50:03.0418 3576 itecir - ok
10:50:03.0462 3576 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
10:50:03.0479 3576 iteraid - ok
10:50:03.0514 3576 JRAID (c1632fe31d1824a43dea29725312e3fa) C:\Windows\system32\drivers\jraid.sys
10:50:03.0552 3576 JRAID - ok
10:50:03.0610 3576 k750bus (fe8300320281d658a7854d5cfc02a63f) C:\Windows\system32\DRIVERS\k750bus.sys
10:50:03.0654 3576 k750bus - ok
10:50:03.0710 3576 k750mdfl (f44521f63c0c00364fa3d59db980de6a) C:\Windows\system32\DRIVERS\k750mdfl.sys
10:50:03.0730 3576 k750mdfl - ok
10:50:03.0817 3576 k750mdm (e93323c3ed5e8923a177740a973c27b2) C:\Windows\system32\DRIVERS\k750mdm.sys
10:50:03.0907 3576 k750mdm - ok
10:50:03.0959 3576 k750mgmt (9d5f5a70ca0b7c428efcd73db50e6ac7) C:\Windows\system32\DRIVERS\k750mgmt.sys
10:50:04.0038 3576 k750mgmt - ok
10:50:04.0095 3576 k750obex (81ca2d57b2c14f76f4ba80846784bb3d) C:\Windows\system32\DRIVERS\k750obex.sys
10:50:04.0138 3576 k750obex - ok
10:50:04.0208 3576 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
10:50:04.0236 3576 kbdclass - ok
10:50:04.0291 3576 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
10:50:04.0360 3576 kbdhid - ok
10:50:04.0448 3576 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
10:50:04.0519 3576 KSecDD - ok
10:50:04.0635 3576 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
10:50:04.0748 3576 lltdio - ok
10:50:04.0917 3576 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
10:50:04.0931 3576 LSI_FC - ok
10:50:04.0971 3576 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
10:50:05.0008 3576 LSI_SAS - ok
10:50:05.0045 3576 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
10:50:05.0065 3576 LSI_SCSI - ok
10:50:05.0115 3576 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
10:50:05.0161 3576 luafv - ok
10:50:05.0225 3576 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys
10:50:05.0248 3576 MBAMProtector - ok
10:50:05.0320 3576 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
10:50:05.0342 3576 megasas - ok
10:50:05.0421 3576 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
10:50:05.0470 3576 Modem - ok
10:50:05.0521 3576 MODEMCSA (cbb59c41f19efea1a000793e08070a62) C:\Windows\system32\drivers\MODEMCSA.sys
10:50:05.0580 3576 MODEMCSA - ok
10:50:05.0639 3576 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
10:50:05.0713 3576 monitor - ok
10:50:05.0764 3576 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
10:50:05.0787 3576 mouclass - ok
10:50:05.0839 3576 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
10:50:05.0977 3576 mouhid - ok
10:50:06.0040 3576 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
10:50:06.0122 3576 MountMgr - ok
10:50:06.0189 3576 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
10:50:06.0217 3576 mpio - ok
10:50:06.0260 3576 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
10:50:06.0339 3576 mpsdrv - ok
10:50:06.0383 3576 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
10:50:06.0419 3576 Mraid35x - ok
10:50:06.0472 3576 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
10:50:06.0557 3576 MRxDAV - ok
10:50:06.0624 3576 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
10:50:06.0709 3576 mrxsmb - ok
10:50:06.0787 3576 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:50:06.0841 3576 mrxsmb10 - ok
10:50:06.0883 3576 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:50:06.0989 3576 mrxsmb20 - ok
10:50:07.0037 3576 msahci (2681302b63b318cbea6c82902ac5428c) C:\Windows\system32\drivers\msahci.sys
10:50:07.0052 3576 msahci - ok
10:50:07.0089 3576 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
10:50:07.0103 3576 msdsm - ok
10:50:07.0162 3576 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
10:50:07.0232 3576 Msfs - ok
10:50:07.0269 3576 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
10:50:07.0282 3576 msisadrv - ok
10:50:07.0358 3576 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
10:50:07.0408 3576 MSKSSRV - ok
10:50:07.0447 3576 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
10:50:07.0488 3576 MSPCLOCK - ok
10:50:07.0530 3576 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
10:50:07.0575 3576 MSPQM - ok
10:50:07.0630 3576 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
10:50:07.0658 3576 MsRPC - ok
10:50:07.0696 3576 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
10:50:07.0713 3576 mssmbios - ok
10:50:07.0752 3576 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
10:50:07.0825 3576 MSTEE - ok
10:50:07.0872 3576 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
10:50:07.0920 3576 Mup - ok
10:50:07.0996 3576 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
10:50:08.0073 3576 NativeWifiP - ok
10:50:08.0125 3576 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
10:50:08.0163 3576 NDIS - ok
10:50:08.0230 3576 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
10:50:08.0274 3576 NdisTapi - ok
10:50:08.0318 3576 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
10:50:08.0359 3576 Ndisuio - ok
10:50:08.0398 3576 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
10:50:08.0446 3576 NdisWan - ok
10:50:08.0498 3576 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
10:50:08.0532 3576 NDProxy - ok
10:50:08.0577 3576 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
10:50:08.0662 3576 NetBIOS - ok
10:50:08.0708 3576 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
10:50:08.0823 3576 netbt - ok
10:50:08.0923 3576 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
10:50:08.0944 3576 nfrd960 - ok
10:50:09.0028 3576 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
10:50:09.0145 3576 Npfs - ok
10:50:09.0205 3576 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
10:50:09.0249 3576 nsiproxy - ok
10:50:09.0318 3576 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
10:50:09.0464 3576 Ntfs - ok
10:50:09.0519 3576 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
10:50:09.0597 3576 ntrigdigi - ok
10:50:09.0640 3576 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
10:50:09.0733 3576 Null - ok
10:50:09.0776 3576 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
10:50:09.0824 3576 nvraid - ok
10:50:09.0872 3576 nvrd32 (ed399014a8029de02ba5ae01da8cc9ee) C:\Windows\system32\drivers\nvrd32.sys
10:50:09.0889 3576 nvrd32 - ok
10:50:09.0924 3576 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
10:50:09.0954 3576 nvstor - ok
10:50:10.0005 3576 nvstor32 (703e3a7093b0fac0eebadbb8e931ecaf) C:\Windows\system32\drivers\nvstor32.sys
10:50:10.0064 3576 nvstor32 - ok
10:50:10.0102 3576 nv_agp (925eb9e53eca4473a2d156a02b7418e3) C:\Windows\system32\drivers\nv_agp.sys
10:50:10.0126 3576 nv_agp - ok
10:50:10.0156 3576 NwlnkFlt - ok
10:50:10.0184 3576 NwlnkFwd - ok
10:50:10.0276 3576 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
10:50:10.0371 3576 ohci1394 - ok
10:50:10.0464 3576 oodisr (442c58e9dfe1f2789f5f196ab31fe950) C:\Windows\system32\DRIVERS\oodisr.sys
10:50:10.0485 3576 oodisr - ok
10:50:10.0511 3576 oodisrh (a6cc11b5ed17c83e5b96c02f3510d158) C:\Windows\system32\DRIVERS\oodisrh.sys
10:50:10.0525 3576 oodisrh - ok
10:50:10.0563 3576 oodivd (cb6274d69fb72fb6e644512b82f292e2) C:\Windows\system32\DRIVERS\oodivd.sys
10:50:10.0579 3576 oodivd - ok
10:50:10.0621 3576 oodivdh (2edc50e184a151ff4733cad111761370) C:\Windows\system32\DRIVERS\oodivdh.sys
10:50:10.0633 3576 oodivdh - ok
10:50:10.0705 3576 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
10:50:10.0826 3576 Parport - ok
10:50:10.0865 3576 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
10:50:10.0920 3576 partmgr - ok
10:50:10.0970 3576 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
10:50:11.0095 3576 Parvdm - ok
10:50:11.0176 3576 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\Windows\system32\DRIVERS\pccsmcfd.sys
10:50:11.0200 3576 pccsmcfd - ok
10:50:11.0292 3576 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
10:50:11.0318 3576 pci - ok
10:50:11.0373 3576 pciide (353968946bcb766f6c5c01717686b382) C:\Windows\system32\drivers\pciide.sys
10:50:11.0393 3576 pciide - ok
10:50:11.0440 3576 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
10:50:11.0466 3576 pcmcia - ok
10:50:11.0532 3576 PCTBD (3a0262b85b5bb4d4cfc096ea00ed610b) C:\Windows\system32\Drivers\PCTBD.sys
10:50:11.0554 3576 PCTBD - ok
10:50:11.0616 3576 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
10:50:11.0819 3576 PEAUTH - ok
10:50:12.0013 3576 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
10:50:12.0064 3576 PptpMiniport - ok
10:50:12.0104 3576 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
10:50:12.0180 3576 Processor - ok
10:50:12.0258 3576 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
10:50:12.0293 3576 PSched - ok
10:50:12.0352 3576 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
10:50:12.0438 3576 ql2300 - ok
10:50:12.0502 3576 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
10:50:12.0520 3576 ql40xx - ok
10:50:12.0587 3576 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
10:50:12.0623 3576 QWAVEdrv - ok
10:50:12.0692 3576 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
10:50:12.0764 3576 RasAcd - ok
10:50:12.0828 3576 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
10:50:12.0968 3576 Rasl2tp - ok
10:50:13.0033 3576 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
10:50:13.0122 3576 RasPppoe - ok
10:50:13.0162 3576 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
10:50:13.0193 3576 RasSstp - ok
10:50:13.0246 3576 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
10:50:13.0288 3576 rdbss - ok
10:50:13.0336 3576 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
10:50:13.0422 3576 RDPCDD - ok
10:50:13.0490 3576 rdpdr (87ee019fe9fbff071d76ccf9ec794646) C:\Windows\system32\drivers\rdpdr.sys
10:50:13.0516 3576 rdpdr - ok
10:50:13.0549 3576 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
10:50:13.0591 3576 RDPENCDD - ok
10:50:13.0655 3576 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
10:50:13.0701 3576 RDPWD - ok
10:50:13.0779 3576 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
10:50:13.0845 3576 rspndr - ok
10:50:13.0924 3576 RTL8169 (2d19a7469ea19993d0c12e627f4530bc) C:\Windows\system32\DRIVERS\Rtlh86.sys
10:50:14.0008 3576 RTL8169 - ok
10:50:14.0087 3576 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
10:50:14.0101 3576 SASDIFSV - ok
10:50:14.0157 3576 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
10:50:14.0172 3576 SASKUTIL - ok
10:50:14.0249 3576 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
10:50:14.0303 3576 sbp2port - ok
10:50:14.0418 3576 SCDEmu (3b35ce540758bbabb721e234cb5a4f3f) C:\Windows\system32\drivers\SCDEmu.sys
10:50:14.0514 3576 SCDEmu ( UnsignedFile.Multi.Generic ) - warning
10:50:14.0515 3576 SCDEmu - detected UnsignedFile.Multi.Generic (1)
10:50:14.0587 3576 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
10:50:14.0740 3576 secdrv - ok
10:50:14.0826 3576 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
10:50:14.0946 3576 Serenum - ok
10:50:14.0994 3576 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
10:50:15.0140 3576 Serial - ok
10:50:15.0203 3576 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
10:50:15.0282 3576 sermouse - ok
10:50:15.0406 3576 sfdrv01 (b659e4af7534e3516ddc0b820db8f910) C:\Windows\system32\drivers\sfdrv01.sys
10:50:15.0500 3576 sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
10:50:15.0500 3576 sfdrv01 - detected UnsignedFile.Multi.Generic (1)
10:50:15.0573 3576 sffdisk (55b145d4248012d306da8e92fa9fdc20) C:\Windows\system32\drivers\sffdisk.sys
10:50:15.0630 3576 sffdisk - ok
10:50:15.0683 3576 sffp_mmc (b86dfcd55294a0495571a27b861e6ef3) C:\Windows\system32\drivers\sffp_mmc.sys
10:50:15.0797 3576 sffp_mmc - ok
10:50:15.0860 3576 sffp_sd (5b327b59fae2b01c34690d91ed03786e) C:\Windows\system32\drivers\sffp_sd.sys
10:50:15.0918 3576 sffp_sd - ok
10:50:15.0997 3576 sfhlp02 (64b9ab76f1b16eb059cb6cdd906c067a) C:\Windows\system32\drivers\sfhlp02.sys
10:50:16.0018 3576 sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
10:50:16.0018 3576 sfhlp02 - detected UnsignedFile.Multi.Generic (1)
10:50:16.0073 3576 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
10:50:16.0224 3576 sfloppy - ok
10:50:16.0250 3576 sfsync02 (3fcb3fe43737b0ef6fe759fc0b886a69) C:\Windows\system32\drivers\sfsync02.sys
10:50:16.0269 3576 sfsync02 ( UnsignedFile.Multi.Generic ) - warning
10:50:16.0269 3576 sfsync02 - detected UnsignedFile.Multi.Generic (1)
10:50:16.0344 3576 sisagp (e5773c4cff310d00a59db01ef4074135) C:\Windows\system32\drivers\sisagp.sys
10:50:16.0402 3576 sisagp - ok
10:50:16.0441 3576 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
10:50:16.0500 3576 SiSRaid2 - ok
10:50:16.0543 3576 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
10:50:16.0581 3576 SiSRaid4 - ok
10:50:16.0654 3576 Smb (3254d50ed2b31e66e186563b395e8476) C:\Windows\system32\DRIVERS\smb.sys
10:50:16.0656 3576 Smb ( Rootkit.Win32.ZAccess.k ) - infected
10:50:16.0656 3576 Smb - detected Rootkit.Win32.ZAccess.k (0)
10:50:16.0728 3576 smserial (7e6628d18d30f14a56c0d9116310ab8a) C:\Windows\system32\DRIVERS\smserial.sys
10:50:16.0840 3576 smserial - ok
10:50:16.0919 3576 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
10:50:16.0966 3576 spldr - ok
10:50:17.0029 3576 sptd (a199171385be17973fd800fa91f8f78a) C:\Windows\system32\Drivers\sptd.sys
10:50:17.0030 3576 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: a199171385be17973fd800fa91f8f78a
10:50:17.0031 3576 sptd ( LockedFile.Multi.Generic ) - warning
10:50:17.0031 3576 sptd - detected LockedFile.Multi.Generic (1)
10:50:17.0105 3576 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
10:50:17.0159 3576 srv - ok
10:50:17.0200 3576 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
10:50:17.0241 3576 srv2 - ok
10:50:17.0284 3576 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
10:50:17.0319 3576 srvnet - ok
10:50:17.0416 3576 ss_bbus (eaa66218cd39f5bb1b4853a78c67c787) C:\Windows\system32\DRIVERS\ss_bbus.sys
10:50:17.0432 3576 ss_bbus - ok
10:50:17.0487 3576 ss_bmdfl (91765f99914ed8693d8bc76524f21581) C:\Windows\system32\DRIVERS\ss_bmdfl.sys
10:50:17.0503 3576 ss_bmdfl - ok
10:50:17.0546 3576 ss_bmdm (840e7b738b03c10ee91d9b7d3d6eff15) C:\Windows\system32\DRIVERS\ss_bmdm.sys
10:50:17.0592 3576 ss_bmdm - ok
10:50:17.0662 3576 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
10:50:17.0686 3576 swenum - ok
10:50:17.0772 3576 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
10:50:17.0841 3576 Symc8xx - ok
10:50:17.0907 3576 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
10:50:17.0927 3576 Sym_hi - ok
10:50:17.0988 3576 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
10:50:18.0048 3576 Sym_u3 - ok
10:50:18.0178 3576 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
10:50:18.0296 3576 Tcpip - ok
10:50:18.0377 3576 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
10:50:18.0460 3576 Tcpip6 - ok
10:50:18.0524 3576 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
10:50:18.0565 3576 tcpipreg - ok
10:50:18.0623 3576 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
10:50:18.0778 3576 TDPIPE - ok
10:50:18.0872 3576 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
10:50:18.0963 3576 TDTCP - ok
10:50:19.0012 3576 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
10:50:19.0057 3576 tdx - ok
10:50:19.0095 3576 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
10:50:19.0112 3576 TermDD - ok
10:50:19.0238 3576 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
10:50:19.0280 3576 tssecsrv - ok
10:50:19.0329 3576 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
10:50:19.0380 3576 tunmp - ok
10:50:19.0429 3576 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
10:50:19.0471 3576 tunnel - ok
10:50:19.0528 3576 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
10:50:19.0604 3576 uagp35 - ok
10:50:19.0661 3576 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
10:50:19.0690 3576 udfs - ok
10:50:19.0760 3576 uliagpkx (5895ef4d0f1424392ee6439250e25677) C:\Windows\system32\drivers\uliagpkx.sys
10:50:19.0774 3576 uliagpkx - ok
10:50:19.0824 3576 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
10:50:19.0874 3576 uliahci - ok
10:50:19.0916 3576 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
10:50:19.0936 3576 UlSata - ok
10:50:20.0001 3576 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
10:50:20.0056 3576 ulsata2 - ok
10:50:20.0113 3576 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
10:50:20.0162 3576 umbus - ok
10:50:20.0241 3576 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
10:50:20.0297 3576 usbccgp - ok
10:50:20.0342 3576 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
10:50:20.0456 3576 usbcir - ok
10:50:20.0506 3576 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
10:50:20.0594 3576 usbehci - ok
10:50:20.0640 3576 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
10:50:20.0678 3576 usbhub - ok
10:50:20.0713 3576 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
10:50:20.0811 3576 usbohci - ok
10:50:20.0865 3576 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
10:50:20.0916 3576 usbprint - ok
10:50:20.0969 3576 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
10:50:21.0021 3576 usbscan - ok
10:50:21.0069 3576 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:50:21.0145 3576 USBSTOR - ok
10:50:21.0191 3576 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
10:50:21.0225 3576 usbuhci - ok
10:50:21.0277 3576 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
10:50:21.0325 3576 usbvideo - ok
10:50:21.0383 3576 usb_rndisx (35c9095fa7076466afbfc5b9ec4b779e) C:\Windows\system32\DRIVERS\usb8023x.sys
10:50:21.0425 3576 usb_rndisx - ok
10:50:21.0498 3576 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
10:50:21.0596 3576 vga - ok
10:50:21.0649 3576 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
10:50:21.0701 3576 VgaSave - ok
10:50:21.0736 3576 viaagp (66e64d5cbeb047c90e65f0962483a5b2) C:\Windows\system32\drivers\viaagp.sys
10:50:21.0752 3576 viaagp - ok
10:50:21.0793 3576 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
10:50:21.0867 3576 ViaC7 - ok
10:50:21.0922 3576 viaide (7100b56688c5d6d7695d18fd001f0cd6) C:\Windows\system32\drivers\viaide.sys
10:50:21.0938 3576 viaide - ok
10:50:21.0973 3576 viamraid (7dc3e1dc6e4f8be381c31bfea578412a) C:\Windows\system32\drivers\viamraid.sys
10:50:21.0990 3576 viamraid - ok
10:50:22.0035 3576 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
10:50:22.0051 3576 volmgr - ok
10:50:22.0102 3576 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
10:50:22.0134 3576 volmgrx - ok
10:50:22.0184 3576 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
10:50:22.0243 3576 volsnap - ok
10:50:22.0278 3576 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
10:50:22.0332 3576 vsmraid - ok
10:50:22.0408 3576 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
10:50:22.0492 3576 WacomPen - ok
10:50:22.0540 3576 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
10:50:22.0574 3576 Wanarp - ok
10:50:22.0593 3576 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
10:50:22.0624 3576 Wanarpv6 - ok
10:50:22.0693 3576 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
10:50:22.0706 3576 Wd - ok
10:50:22.0752 3576 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys
10:50:22.0767 3576 WDC_SAM - ok
10:50:22.0826 3576 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
10:50:22.0863 3576 Wdf01000 - ok
10:50:23.0058 3576 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
10:50:23.0105 3576 WmiAcpi - ok
10:50:23.0203 3576 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
10:50:23.0247 3576 WpdUsb - ok
10:50:23.0318 3576 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
10:50:23.0382 3576 ws2ifsl - ok
10:50:23.0482 3576 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
10:50:23.0538 3576 WUDFRd - ok
10:50:23.0605 3576 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
10:50:23.0761 3576 \Device\Harddisk0\DR0 - ok
10:50:23.0771 3576 Boot (0x1200) (238123a347c280693e355e11e48d9538) \Device\Harddisk0\DR0\Partition0
10:50:23.0772 3576 \Device\Harddisk0\DR0\Partition0 - ok
10:50:23.0803 3576 Boot (0x1200) (51bc467334dc1bdb04983b0071d191c5) \Device\Harddisk0\DR0\Partition1
10:50:23.0805 3576 \Device\Harddisk0\DR0\Partition1 - ok
10:50:23.0824 3576 ============================================================
10:50:23.0824 3576 Scan finished
10:50:23.0824 3576 ============================================================
10:50:23.0843 1308 Detected object count: 8
10:50:23.0843 1308 Actual detected object count: 8
10:50:58.0476 1308 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
10:50:58.0476 1308 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:50:58.0477 1308 ISODrive ( UnsignedFile.Multi.Generic ) - skipped by user
10:50:58.0477 1308 ISODrive ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:50:58.0484 1308 SCDEmu ( UnsignedFile.Multi.Generic ) - skipped by user
10:50:58.0484 1308 SCDEmu ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:50:58.0489 1308 sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
10:50:58.0489 1308 sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:50:58.0493 1308 sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
10:50:58.0494 1308 sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:50:58.0500 1308 sfsync02 ( UnsignedFile.Multi.Generic ) - skipped by user
10:50:58.0501 1308 sfsync02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:50:58.0505 1308 Smb ( Rootkit.Win32.ZAccess.k ) - skipped by user
10:50:58.0505 1308 Smb ( Rootkit.Win32.ZAccess.k ) - User select action: Skip
10:50:58.0510 1308 sptd ( LockedFile.Multi.Generic ) - skipped by user
10:50:58.0510 1308 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
Přílohy
správa.jpg
správa.jpg (39.16 KiB) Zobrazeno 1564 x

Lucas89
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 pro 2011 12:30

Re: Viry Sirefef.DT a Rootkit.Kryptik.FW

#8 Příspěvek od Lucas89 »

14:34:38.0979 1144 TDSS rootkit removing tool 2.6.23.0 Dec 13 2011 10:39:31
14:34:39.0469 1144 ============================================================
14:34:39.0469 1144 Current date / time: 2011/12/15 14:34:39.0469
14:34:39.0469 1144 SystemInfo:
14:34:39.0469 1144
14:34:39.0470 1144 OS Version: 6.0.6002 ServicePack: 2.0
14:34:39.0470 1144 Product type: Workstation
14:34:39.0470 1144 ComputerName: LUKÁŠ
14:34:39.0470 1144 UserName: Lukáš
14:34:39.0470 1144 Windows directory: C:\Windows
14:34:39.0470 1144 System windows directory: C:\Windows
14:34:39.0470 1144 Processor architecture: Intel x86
14:34:39.0470 1144 Number of processors: 1
14:34:39.0470 1144 Page size: 0x1000
14:34:39.0470 1144 Boot type: Normal boot
14:34:39.0470 1144 ============================================================
14:34:40.0082 1144 Initialize success
14:34:44.0315 1452 ============================================================
14:34:44.0315 1452 Scan started
14:34:44.0315 1452 Mode: Manual; SigCheck; TDLFS;
14:34:44.0315 1452 ============================================================
14:34:44.0695 1452 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
14:34:44.0827 1452 ACPI - ok
14:34:44.0913 1452 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
14:34:44.0939 1452 adp94xx - ok
14:34:44.0998 1452 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
14:34:45.0021 1452 adpahci - ok
14:34:45.0066 1452 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
14:34:45.0081 1452 adpu160m - ok
14:34:45.0130 1452 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
14:34:45.0152 1452 adpu320 - ok
14:34:45.0228 1452 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
14:34:45.0285 1452 AFD - ok
14:34:45.0331 1452 agp440 (198636e76971ebc96404547ec0fd5e75) C:\Windows\system32\drivers\agp440.sys
14:34:45.0352 1452 agp440 - ok
14:34:45.0396 1452 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
14:34:45.0412 1452 aic78xx - ok
14:34:45.0459 1452 aliide (0b3b337a68d9a75cc8d787dc98b53d79) C:\Windows\system32\drivers\aliide.sys
14:34:45.0473 1452 aliide - ok
14:34:45.0528 1452 amdagp (2363abc8989a14fd7247ca6f4e89d397) C:\Windows\system32\drivers\amdagp.sys
14:34:45.0588 1452 amdagp - ok
14:34:45.0639 1452 amdide (468a204966d09f327a662c35f4b15dd3) C:\Windows\system32\drivers\amdide.sys
14:34:45.0652 1452 amdide - ok
14:34:45.0695 1452 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
14:34:45.0762 1452 AmdK7 - ok
14:34:45.0804 1452 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
14:34:45.0873 1452 AmdK8 - ok
14:34:45.0922 1452 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
14:34:45.0937 1452 arc - ok
14:34:45.0972 1452 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
14:34:46.0030 1452 arcsas - ok
14:34:46.0081 1452 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
14:34:46.0157 1452 AsyncMac - ok
14:34:46.0220 1452 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
14:34:46.0237 1452 atapi - ok
14:34:46.0304 1452 athr (2846f5ee802889d500fcf5cc48b28381) C:\Windows\system32\DRIVERS\athr.sys
14:34:46.0402 1452 athr - ok
14:34:46.0543 1452 atikmdag (389a2668e0c0c6698a6b565632c7f43a) C:\Windows\system32\DRIVERS\atikmdag.sys
14:34:46.0733 1452 atikmdag - ok
14:34:46.0792 1452 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
14:34:46.0827 1452 Beep - ok
14:34:46.0857 1452 blbdrive - ok
14:34:46.0902 1452 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
14:34:46.0923 1452 bowser - ok
14:34:46.0971 1452 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
14:34:47.0001 1452 BrFiltLo - ok
14:34:47.0043 1452 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
14:34:47.0074 1452 BrFiltUp - ok
14:34:47.0133 1452 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
14:34:47.0214 1452 Brserid - ok
14:34:47.0258 1452 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
14:34:47.0319 1452 BrSerWdm - ok
14:34:47.0348 1452 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
14:34:47.0403 1452 BrUsbMdm - ok
14:34:47.0432 1452 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
14:34:47.0492 1452 BrUsbSer - ok
14:34:47.0532 1452 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
14:34:47.0587 1452 BTHMODEM - ok
14:34:47.0691 1452 catchme - ok
14:34:47.0740 1452 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
14:34:47.0779 1452 cdfs - ok
14:34:47.0830 1452 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
14:34:47.0858 1452 cdrom - ok
14:34:47.0914 1452 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
14:34:47.0946 1452 circlass - ok
14:34:47.0993 1452 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
14:34:48.0015 1452 CLFS - ok
14:34:48.0079 1452 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
14:34:48.0112 1452 CmBatt - ok
14:34:48.0161 1452 cmdide (2ac0c92b29ec21838f4cb46adb26bcc0) C:\Windows\system32\drivers\cmdide.sys
14:34:48.0176 1452 cmdide - ok
14:34:48.0213 1452 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
14:34:48.0227 1452 Compbatt - ok
14:34:48.0256 1452 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
14:34:48.0299 1452 crcdisk - ok
14:34:48.0342 1452 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
14:34:48.0397 1452 Crusoe - ok
14:34:48.0476 1452 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
14:34:48.0495 1452 DfsC - ok
14:34:48.0564 1452 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
14:34:48.0583 1452 disk - ok
14:34:48.0645 1452 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
14:34:48.0670 1452 drmkaud - ok
14:34:48.0731 1452 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
14:34:48.0764 1452 DXGKrnl - ok
14:34:48.0807 1452 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
14:34:48.0869 1452 E1G60 - ok
14:34:48.0925 1452 eamon (e31464ce787e3a0ffea55baa591897f0) C:\Windows\system32\DRIVERS\eamon.sys
14:34:48.0984 1452 eamon - ok
14:34:49.0036 1452 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
14:34:49.0056 1452 Ecache - ok
14:34:49.0122 1452 ehdrv (2c95a7a87e4272c1fff9baf579677db3) C:\Windows\system32\DRIVERS\ehdrv.sys
14:34:49.0159 1452 ehdrv - ok
14:34:49.0264 1452 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
14:34:49.0283 1452 elxstor - ok
14:34:49.0343 1452 epfw (c2c9a92b560a775c65b89e78dcb6951a) C:\Windows\system32\DRIVERS\epfw.sys
14:34:49.0364 1452 epfw - ok
14:34:49.0410 1452 Epfwndis (73fc7c4a5952b5493c6be2708d1538c0) C:\Windows\system32\DRIVERS\Epfwndis.sys
14:34:49.0421 1452 Epfwndis - ok
14:34:49.0483 1452 epfwtdi (cd6d97a7a88a78fa6f1732b75971ead0) C:\Windows\system32\DRIVERS\epfwtdi.sys
14:34:49.0495 1452 epfwtdi - ok
14:34:49.0591 1452 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
14:34:49.0616 1452 exfat - ok
14:34:49.0676 1452 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
14:34:49.0704 1452 fastfat - ok
14:34:49.0746 1452 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
14:34:49.0800 1452 fdc - ok
14:34:49.0869 1452 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
14:34:49.0891 1452 FileInfo - ok
14:34:49.0934 1452 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
14:34:49.0967 1452 Filetrace - ok
14:34:50.0018 1452 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
14:34:50.0072 1452 flpydisk - ok
14:34:50.0098 1452 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
14:34:50.0118 1452 FltMgr - ok
14:34:50.0241 1452 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\Windows\system32\FsUsbExDisk.SYS
14:34:50.0249 1452 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
14:34:50.0249 1452 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
14:34:50.0330 1452 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
14:34:50.0356 1452 Fs_Rec - ok
14:34:50.0416 1452 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
14:34:50.0431 1452 gagp30kx - ok
14:34:50.0519 1452 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
14:34:50.0576 1452 HdAudAddService - ok
14:34:50.0646 1452 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
14:34:50.0685 1452 HDAudBus - ok
14:34:50.0723 1452 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
14:34:50.0777 1452 HidBth - ok
14:34:50.0824 1452 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
14:34:50.0872 1452 HidIr - ok
14:34:50.0928 1452 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
14:34:50.0954 1452 HidUsb - ok
14:34:50.0997 1452 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
14:34:51.0011 1452 HpCISSs - ok
14:34:51.0068 1452 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
14:34:51.0095 1452 HTTP - ok
14:34:51.0133 1452 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
14:34:51.0147 1452 i2omp - ok
14:34:51.0200 1452 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
14:34:51.0250 1452 i8042prt - ok
14:34:51.0304 1452 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\Windows\system32\DRIVERS\iaStor.sys
14:34:51.0320 1452 iaStor - ok
14:34:51.0363 1452 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
14:34:51.0380 1452 iaStorV - ok
14:34:51.0465 1452 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
14:34:51.0478 1452 iirsp - ok
14:34:51.0511 1452 Inspect - ok
14:34:51.0602 1452 IntcAzAudAddService (4fa59a84069d9d0991bae34cc4aff99c) C:\Windows\system32\drivers\RTKVHDA.sys
14:34:51.0713 1452 IntcAzAudAddService - ok
14:34:51.0749 1452 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
14:34:51.0788 1452 intelide - ok
14:34:51.0828 1452 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
14:34:51.0863 1452 intelppm - ok
14:34:51.0914 1452 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:34:51.0953 1452 IpFilterDriver - ok
14:34:51.0983 1452 IpInIp - ok
14:34:52.0017 1452 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
14:34:52.0072 1452 IPMIDRV - ok
14:34:52.0113 1452 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
14:34:52.0147 1452 IPNAT - ok
14:34:52.0182 1452 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
14:34:52.0243 1452 IRENUM - ok
14:34:52.0280 1452 isapnp (ce2997a0c3b0049a3188c4f0c7a04bc9) C:\Windows\system32\drivers\isapnp.sys
14:34:52.0295 1452 isapnp - ok
14:34:52.0342 1452 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
14:34:52.0361 1452 iScsiPrt - ok
14:34:52.0434 1452 ISODrive (bf71a06ff065e3fd7e32ea67dca34885) C:\Program Files\UltraISO\drivers\ISODrive.sys
14:34:52.0464 1452 ISODrive ( UnsignedFile.Multi.Generic ) - warning
14:34:52.0464 1452 ISODrive - detected UnsignedFile.Multi.Generic (1)
14:34:52.0505 1452 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
14:34:52.0566 1452 iteatapi - ok
14:34:52.0622 1452 itecir (e4b04a0d8b237ecf026d849439f1bcce) C:\Windows\system32\DRIVERS\itecir.sys
14:34:52.0638 1452 itecir - ok
14:34:52.0670 1452 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
14:34:52.0685 1452 iteraid - ok
14:34:52.0721 1452 JRAID (c1632fe31d1824a43dea29725312e3fa) C:\Windows\system32\drivers\jraid.sys
14:34:52.0738 1452 JRAID - ok
14:34:52.0804 1452 k750bus (fe8300320281d658a7854d5cfc02a63f) C:\Windows\system32\DRIVERS\k750bus.sys
14:34:52.0820 1452 k750bus - ok
14:34:52.0873 1452 k750mdfl (f44521f63c0c00364fa3d59db980de6a) C:\Windows\system32\DRIVERS\k750mdfl.sys
14:34:52.0887 1452 k750mdfl - ok
14:34:52.0935 1452 k750mdm (e93323c3ed5e8923a177740a973c27b2) C:\Windows\system32\DRIVERS\k750mdm.sys
14:34:52.0951 1452 k750mdm - ok
14:34:52.0999 1452 k750mgmt (9d5f5a70ca0b7c428efcd73db50e6ac7) C:\Windows\system32\DRIVERS\k750mgmt.sys
14:34:53.0021 1452 k750mgmt - ok
14:34:53.0080 1452 k750obex (81ca2d57b2c14f76f4ba80846784bb3d) C:\Windows\system32\DRIVERS\k750obex.sys
14:34:53.0096 1452 k750obex - ok
14:34:53.0146 1452 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
14:34:53.0160 1452 kbdclass - ok
14:34:53.0209 1452 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
14:34:53.0235 1452 kbdhid - ok
14:34:53.0307 1452 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
14:34:53.0334 1452 KSecDD - ok
14:34:53.0409 1452 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
14:34:53.0443 1452 lltdio - ok
14:34:53.0513 1452 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
14:34:53.0528 1452 LSI_FC - ok
14:34:53.0578 1452 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
14:34:53.0593 1452 LSI_SAS - ok
14:34:53.0652 1452 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
14:34:53.0666 1452 LSI_SCSI - ok
14:34:53.0692 1452 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
14:34:53.0727 1452 luafv - ok
14:34:53.0765 1452 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys
14:34:53.0783 1452 MBAMProtector - ok
14:34:53.0849 1452 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
14:34:53.0862 1452 megasas - ok
14:34:53.0928 1452 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
14:34:53.0960 1452 Modem - ok
14:34:54.0017 1452 MODEMCSA (cbb59c41f19efea1a000793e08070a62) C:\Windows\system32\drivers\MODEMCSA.sys
14:34:54.0055 1452 MODEMCSA - ok
14:34:54.0101 1452 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
14:34:54.0135 1452 monitor - ok
14:34:54.0181 1452 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
14:34:54.0196 1452 mouclass - ok
14:34:54.0246 1452 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
14:34:54.0279 1452 mouhid - ok
14:34:54.0336 1452 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
14:34:54.0350 1452 MountMgr - ok
14:34:54.0406 1452 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
14:34:54.0445 1452 mpio - ok
14:34:54.0489 1452 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
14:34:54.0515 1452 mpsdrv - ok
14:34:54.0555 1452 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
14:34:54.0574 1452 Mraid35x - ok
14:34:54.0607 1452 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
14:34:54.0630 1452 MRxDAV - ok
14:34:54.0674 1452 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
14:34:54.0717 1452 mrxsmb - ok
14:34:54.0759 1452 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:34:54.0780 1452 mrxsmb10 - ok
14:34:54.0816 1452 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:34:54.0844 1452 mrxsmb20 - ok
14:34:54.0887 1452 msahci (2681302b63b318cbea6c82902ac5428c) C:\Windows\system32\drivers\msahci.sys
14:34:54.0902 1452 msahci - ok
14:34:54.0940 1452 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
14:34:54.0955 1452 msdsm - ok
14:34:55.0012 1452 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
14:34:55.0047 1452 Msfs - ok
14:34:55.0075 1452 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
14:34:55.0090 1452 msisadrv - ok
14:34:55.0153 1452 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
14:34:55.0185 1452 MSKSSRV - ok
14:34:55.0219 1452 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
14:34:55.0252 1452 MSPCLOCK - ok
14:34:55.0279 1452 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
14:34:55.0314 1452 MSPQM - ok
14:34:55.0369 1452 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
14:34:55.0388 1452 MsRPC - ok
14:34:55.0424 1452 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
14:34:55.0442 1452 mssmbios - ok
14:34:55.0480 1452 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
14:34:55.0536 1452 MSTEE - ok
14:34:55.0578 1452 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
14:34:55.0596 1452 Mup - ok
14:34:55.0668 1452 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
14:34:55.0718 1452 NativeWifiP - ok
14:34:55.0764 1452 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
14:34:55.0793 1452 NDIS - ok
14:34:55.0858 1452 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
14:34:55.0889 1452 NdisTapi - ok
14:34:55.0924 1452 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
14:34:55.0956 1452 Ndisuio - ok
14:34:55.0993 1452 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
14:34:56.0020 1452 NdisWan - ok
14:34:56.0070 1452 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
14:34:56.0097 1452 NDProxy - ok
14:34:56.0139 1452 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
14:34:56.0178 1452 NetBIOS - ok
14:34:56.0215 1452 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
14:34:56.0243 1452 netbt - ok
14:34:56.0315 1452 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
14:34:56.0329 1452 nfrd960 - ok
14:34:56.0411 1452 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
14:34:56.0470 1452 Npfs - ok
14:34:56.0510 1452 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
14:34:56.0545 1452 nsiproxy - ok
14:34:56.0601 1452 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
14:34:56.0655 1452 Ntfs - ok
14:34:56.0713 1452 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
14:34:56.0767 1452 ntrigdigi - ok
14:34:56.0812 1452 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
14:34:56.0844 1452 Null - ok
14:34:56.0881 1452 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
14:34:56.0895 1452 nvraid - ok
14:34:56.0944 1452 nvrd32 (ed399014a8029de02ba5ae01da8cc9ee) C:\Windows\system32\drivers\nvrd32.sys
14:34:56.0964 1452 nvrd32 - ok
14:34:56.0996 1452 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
14:34:57.0010 1452 nvstor - ok
14:34:57.0054 1452 nvstor32 (703e3a7093b0fac0eebadbb8e931ecaf) C:\Windows\system32\drivers\nvstor32.sys
14:34:57.0067 1452 nvstor32 - ok
14:34:57.0106 1452 nv_agp (925eb9e53eca4473a2d156a02b7418e3) C:\Windows\system32\drivers\nv_agp.sys
14:34:57.0121 1452 nv_agp - ok
14:34:57.0144 1452 NwlnkFlt - ok
14:34:57.0167 1452 NwlnkFwd - ok
14:34:57.0258 1452 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
14:34:57.0314 1452 ohci1394 - ok
14:34:57.0402 1452 oodisr (442c58e9dfe1f2789f5f196ab31fe950) C:\Windows\system32\DRIVERS\oodisr.sys
14:34:57.0416 1452 oodisr - ok
14:34:57.0450 1452 oodisrh (a6cc11b5ed17c83e5b96c02f3510d158) C:\Windows\system32\DRIVERS\oodisrh.sys
14:34:57.0461 1452 oodisrh - ok
14:34:57.0501 1452 oodivd (cb6274d69fb72fb6e644512b82f292e2) C:\Windows\system32\DRIVERS\oodivd.sys
14:34:57.0516 1452 oodivd - ok
14:34:57.0548 1452 oodivdh (2edc50e184a151ff4733cad111761370) C:\Windows\system32\DRIVERS\oodivdh.sys
14:34:57.0560 1452 oodivdh - ok
14:34:57.0632 1452 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
14:34:57.0687 1452 Parport - ok
14:34:57.0747 1452 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
14:34:57.0789 1452 partmgr - ok
14:34:57.0831 1452 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
14:34:57.0885 1452 Parvdm - ok
14:34:57.0959 1452 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\Windows\system32\DRIVERS\pccsmcfd.sys
14:34:57.0974 1452 pccsmcfd - ok
14:34:58.0041 1452 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
14:34:58.0059 1452 pci - ok
14:34:58.0100 1452 pciide (353968946bcb766f6c5c01717686b382) C:\Windows\system32\drivers\pciide.sys
14:34:58.0114 1452 pciide - ok
14:34:58.0155 1452 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
14:34:58.0172 1452 pcmcia - ok
14:34:58.0226 1452 PCTBD (3a0262b85b5bb4d4cfc096ea00ed610b) C:\Windows\system32\Drivers\PCTBD.sys
14:34:58.0243 1452 PCTBD - ok
14:34:58.0296 1452 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
14:34:58.0393 1452 PEAUTH - ok
14:34:58.0517 1452 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
14:34:58.0552 1452 PptpMiniport - ok
14:34:58.0597 1452 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
14:34:58.0653 1452 Processor - ok
14:34:58.0718 1452 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
14:34:58.0745 1452 PSched - ok
14:34:58.0811 1452 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
14:34:58.0859 1452 ql2300 - ok
14:34:58.0906 1452 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
14:34:58.0922 1452 ql40xx - ok
14:34:58.0980 1452 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
14:34:58.0998 1452 QWAVEdrv - ok
14:34:59.0053 1452 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
14:34:59.0085 1452 RasAcd - ok
14:34:59.0165 1452 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
14:34:59.0200 1452 Rasl2tp - ok
14:34:59.0259 1452 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
14:34:59.0316 1452 RasPppoe - ok
14:34:59.0366 1452 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
14:34:59.0387 1452 RasSstp - ok
14:34:59.0428 1452 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
14:34:59.0458 1452 rdbss - ok
14:34:59.0484 1452 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
14:34:59.0517 1452 RDPCDD - ok
14:34:59.0581 1452 rdpdr (87ee019fe9fbff071d76ccf9ec794646) C:\Windows\system32\drivers\rdpdr.sys
14:34:59.0601 1452 rdpdr - ok
14:34:59.0625 1452 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
14:34:59.0659 1452 RDPENCDD - ok
14:34:59.0702 1452 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
14:34:59.0731 1452 RDPWD - ok
14:34:59.0817 1452 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
14:34:59.0850 1452 rspndr - ok
14:34:59.0917 1452 RTL8169 (2d19a7469ea19993d0c12e627f4530bc) C:\Windows\system32\DRIVERS\Rtlh86.sys
14:34:59.0937 1452 RTL8169 - ok
14:35:00.0035 1452 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
14:35:00.0047 1452 SASDIFSV - ok
14:35:00.0105 1452 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
14:35:00.0141 1452 SASKUTIL - ok
14:35:00.0197 1452 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
14:35:00.0211 1452 sbp2port - ok
14:35:00.0299 1452 SCDEmu (3b35ce540758bbabb721e234cb5a4f3f) C:\Windows\system32\drivers\SCDEmu.sys
14:35:00.0311 1452 SCDEmu ( UnsignedFile.Multi.Generic ) - warning
14:35:00.0312 1452 SCDEmu - detected UnsignedFile.Multi.Generic (1)
14:35:00.0368 1452 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
14:35:00.0423 1452 secdrv - ok
14:35:00.0507 1452 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
14:35:00.0562 1452 Serenum - ok
14:35:00.0598 1452 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
14:35:00.0679 1452 Serial - ok
14:35:00.0751 1452 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
14:35:00.0783 1452 sermouse - ok
14:35:00.0898 1452 sfdrv01 (b659e4af7534e3516ddc0b820db8f910) C:\Windows\system32\drivers\sfdrv01.sys
14:35:00.0905 1452 sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
14:35:00.0905 1452 sfdrv01 - detected UnsignedFile.Multi.Generic (1)
14:35:00.0965 1452 sffdisk (55b145d4248012d306da8e92fa9fdc20) C:\Windows\system32\drivers\sffdisk.sys
14:35:00.0981 1452 sffdisk - ok
14:35:01.0019 1452 sffp_mmc (b86dfcd55294a0495571a27b861e6ef3) C:\Windows\system32\drivers\sffp_mmc.sys
14:35:01.0036 1452 sffp_mmc - ok
14:35:01.0073 1452 sffp_sd (5b327b59fae2b01c34690d91ed03786e) C:\Windows\system32\drivers\sffp_sd.sys
14:35:01.0090 1452 sffp_sd - ok
14:35:01.0145 1452 sfhlp02 (64b9ab76f1b16eb059cb6cdd906c067a) C:\Windows\system32\drivers\sfhlp02.sys
14:35:01.0152 1452 sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
14:35:01.0152 1452 sfhlp02 - detected UnsignedFile.Multi.Generic (1)
14:35:01.0198 1452 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
14:35:01.0274 1452 sfloppy - ok
14:35:01.0300 1452 sfsync02 (3fcb3fe43737b0ef6fe759fc0b886a69) C:\Windows\system32\drivers\sfsync02.sys
14:35:01.0307 1452 sfsync02 ( UnsignedFile.Multi.Generic ) - warning
14:35:01.0307 1452 sfsync02 - detected UnsignedFile.Multi.Generic (1)
14:35:01.0390 1452 sisagp (e5773c4cff310d00a59db01ef4074135) C:\Windows\system32\drivers\sisagp.sys
14:35:01.0451 1452 sisagp - ok
14:35:01.0497 1452 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
14:35:01.0554 1452 SiSRaid2 - ok
14:35:01.0597 1452 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
14:35:01.0616 1452 SiSRaid4 - ok
14:35:01.0679 1452 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
14:35:01.0706 1452 Smb - ok
14:35:01.0774 1452 smserial (7e6628d18d30f14a56c0d9116310ab8a) C:\Windows\system32\DRIVERS\smserial.sys
14:35:01.0826 1452 smserial - ok
14:35:01.0888 1452 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
14:35:01.0905 1452 spldr - ok
14:35:01.0976 1452 sptd (a199171385be17973fd800fa91f8f78a) C:\Windows\system32\Drivers\sptd.sys
14:35:01.0976 1452 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: a199171385be17973fd800fa91f8f78a
14:35:01.0978 1452 sptd ( LockedFile.Multi.Generic ) - warning
14:35:01.0978 1452 sptd - detected LockedFile.Multi.Generic (1)
14:35:02.0049 1452 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
14:35:02.0072 1452 srv - ok
14:35:02.0113 1452 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
14:35:02.0141 1452 srv2 - ok
14:35:02.0175 1452 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
14:35:02.0195 1452 srvnet - ok
14:35:02.0285 1452 ss_bbus (eaa66218cd39f5bb1b4853a78c67c787) C:\Windows\system32\DRIVERS\ss_bbus.sys
14:35:02.0298 1452 ss_bbus - ok
14:35:02.0357 1452 ss_bmdfl (91765f99914ed8693d8bc76524f21581) C:\Windows\system32\DRIVERS\ss_bmdfl.sys
14:35:02.0368 1452 ss_bmdfl - ok
14:35:02.0404 1452 ss_bmdm (840e7b738b03c10ee91d9b7d3d6eff15) C:\Windows\system32\DRIVERS\ss_bmdm.sys
14:35:02.0418 1452 ss_bmdm - ok
14:35:02.0475 1452 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
14:35:02.0489 1452 swenum - ok
14:35:02.0561 1452 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
14:35:02.0574 1452 Symc8xx - ok
14:35:02.0631 1452 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
14:35:02.0645 1452 Sym_hi - ok
14:35:02.0700 1452 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
14:35:02.0715 1452 Sym_u3 - ok
14:35:02.0833 1452 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
14:35:02.0884 1452 Tcpip - ok
14:35:02.0944 1452 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
14:35:02.0998 1452 Tcpip6 - ok
14:35:03.0048 1452 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
14:35:03.0068 1452 tcpipreg - ok
14:35:03.0114 1452 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
14:35:03.0146 1452 TDPIPE - ok
14:35:03.0184 1452 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
14:35:03.0219 1452 TDTCP - ok
14:35:03.0270 1452 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
14:35:03.0297 1452 tdx - ok
14:35:03.0341 1452 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
14:35:03.0357 1452 TermDD - ok
14:35:03.0472 1452 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
14:35:03.0505 1452 tssecsrv - ok
14:35:03.0553 1452 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
14:35:03.0571 1452 tunmp - ok
14:35:03.0608 1452 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
14:35:03.0628 1452 tunnel - ok
14:35:03.0677 1452 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
14:35:03.0693 1452 uagp35 - ok
14:35:03.0751 1452 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
14:35:03.0780 1452 udfs - ok
14:35:03.0838 1452 uliagpkx (5895ef4d0f1424392ee6439250e25677) C:\Windows\system32\drivers\uliagpkx.sys
14:35:03.0853 1452 uliagpkx - ok
14:35:03.0903 1452 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
14:35:03.0921 1452 uliahci - ok
14:35:03.0973 1452 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
14:35:03.0988 1452 UlSata - ok
14:35:04.0045 1452 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
14:35:04.0083 1452 ulsata2 - ok
14:35:04.0137 1452 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
14:35:04.0169 1452 umbus - ok
14:35:04.0242 1452 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
14:35:04.0294 1452 usbccgp - ok
14:35:04.0333 1452 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
14:35:04.0389 1452 usbcir - ok
14:35:04.0440 1452 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
14:35:04.0481 1452 usbehci - ok
14:35:04.0518 1452 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
14:35:04.0572 1452 usbhub - ok
14:35:04.0614 1452 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
14:35:04.0668 1452 usbohci - ok
14:35:04.0711 1452 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
14:35:04.0750 1452 usbprint - ok
14:35:04.0803 1452 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
14:35:04.0830 1452 usbscan - ok
14:35:04.0869 1452 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:35:04.0921 1452 USBSTOR - ok
14:35:04.0969 1452 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
14:35:04.0995 1452 usbuhci - ok
14:35:05.0055 1452 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
14:35:05.0089 1452 usbvideo - ok
14:35:05.0139 1452 usb_rndisx (35c9095fa7076466afbfc5b9ec4b779e) C:\Windows\system32\DRIVERS\usb8023x.sys
14:35:05.0165 1452 usb_rndisx - ok
14:35:05.0243 1452 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
14:35:05.0304 1452 vga - ok
14:35:05.0350 1452 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
14:35:05.0383 1452 VgaSave - ok
14:35:05.0425 1452 viaagp (66e64d5cbeb047c90e65f0962483a5b2) C:\Windows\system32\drivers\viaagp.sys
14:35:05.0441 1452 viaagp - ok
14:35:05.0483 1452 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
14:35:05.0537 1452 ViaC7 - ok
14:35:05.0589 1452 viaide (7100b56688c5d6d7695d18fd001f0cd6) C:\Windows\system32\drivers\viaide.sys
14:35:05.0603 1452 viaide - ok
14:35:05.0648 1452 viamraid (7dc3e1dc6e4f8be381c31bfea578412a) C:\Windows\system32\drivers\viamraid.sys
14:35:05.0664 1452 viamraid - ok
14:35:05.0713 1452 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
14:35:05.0727 1452 volmgr - ok
14:35:05.0780 1452 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
14:35:05.0801 1452 volmgrx - ok
14:35:05.0838 1452 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
14:35:05.0860 1452 volsnap - ok
14:35:05.0887 1452 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
14:35:05.0927 1452 vsmraid - ok
14:35:05.0986 1452 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
14:35:06.0043 1452 WacomPen - ok
14:35:06.0095 1452 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
14:35:06.0122 1452 Wanarp - ok
14:35:06.0135 1452 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
14:35:06.0164 1452 Wanarpv6 - ok
14:35:06.0226 1452 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
14:35:06.0240 1452 Wd - ok
14:35:06.0286 1452 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys
14:35:06.0301 1452 WDC_SAM - ok
14:35:06.0359 1452 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
14:35:06.0386 1452 Wdf01000 - ok
14:35:06.0548 1452 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
14:35:06.0574 1452 WmiAcpi - ok
14:35:06.0670 1452 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
14:35:06.0690 1452 WpdUsb - ok
14:35:06.0762 1452 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
14:35:06.0795 1452 ws2ifsl - ok
14:35:06.0882 1452 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
14:35:06.0916 1452 WUDFRd - ok
14:35:06.0972 1452 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
14:35:07.0128 1452 \Device\Harddisk0\DR0 - ok
14:35:07.0139 1452 Boot (0x1200) (238123a347c280693e355e11e48d9538) \Device\Harddisk0\DR0\Partition0
14:35:07.0140 1452 \Device\Harddisk0\DR0\Partition0 - ok
14:35:07.0170 1452 Boot (0x1200) (51bc467334dc1bdb04983b0071d191c5) \Device\Harddisk0\DR0\Partition1
14:35:07.0173 1452 \Device\Harddisk0\DR0\Partition1 - ok
14:35:07.0177 1452 ============================================================
14:35:07.0178 1452 Scan finished
14:35:07.0178 1452 ============================================================
14:35:07.0197 3960 Detected object count: 7
14:35:07.0197 3960 Actual detected object count: 7
14:35:11.0617 3960 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
14:35:11.0618 3960 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:35:11.0618 3960 ISODrive ( UnsignedFile.Multi.Generic ) - skipped by user
14:35:11.0618 3960 ISODrive ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:35:11.0623 3960 SCDEmu ( UnsignedFile.Multi.Generic ) - skipped by user
14:35:11.0623 3960 SCDEmu ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:35:11.0626 3960 sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
14:35:11.0626 3960 sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:35:11.0629 3960 sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
14:35:11.0629 3960 sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:35:11.0632 3960 sfsync02 ( UnsignedFile.Multi.Generic ) - skipped by user
14:35:11.0632 3960 sfsync02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:35:11.0635 3960 sptd ( LockedFile.Multi.Generic ) - skipped by user
14:35:11.0635 3960 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
Přílohy
logxuetr.rar
(111.32 KiB) Staženo 83 x


Odpovědět