Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o shlédnutí logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Prosím o shlédnutí logu

#1 Příspěvek od freeacer »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Martin Stroka at 2012-01-19 20:57:33
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 33 GB (21%) free of 156 GB
Total RAM: 4093 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:57:35, on 19.1.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
c:\program files (x86)\teamviewer\version7\TeamViewer.exe
C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Brownie\brpjp04a.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosHdpProc.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\TOSHIBA\HDMICtrlMan\HCMSoundChanger.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\trend micro\Martin Stroka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatc ... &%language
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files (x86)\Brownie\BrstsW64.exe Autorun
O4 - HKLM\..\Run: [Anti Trojan Elite] C:\Program Files (x86)\Anti Trojan Elite\TJEnder.exe :NO
O4 - HKCU\..\Run: [NokiaPCInternetAccess] "C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b
O4 - HKCU\..\Run: [Google Update] "C:\Users\Martin Stroka\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2704916375-464737053-844809292-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-2704916375-464737053-844809292-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - S-1-5-21-2704916375-464737053-844809292-1005 User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'UpdatusUser')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Brother BRAdminPro Scheduler (BRA_Scheduler) - Unknown owner - C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: Ochrana HDD TOSHIBA (Thpsrv) - Unknown owner - C:\Windows\system32\ThpSrv.exe (file missing)
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: webcamXP Service (wxpSvc) - Unknown owner - C:\Program Files (x86)\webcamXP 5\wService.exe

--
End of file - 12205 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\system32\HPSIsvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe"
C:\Windows\system32\ThpSrv.exe
C:\Windows\system32\TODDSrv.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2128
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000006f4
\??\C:\Windows\system32\conhost.exe "97881346333592482-408050060959780130-1261050992483255705-3352792371512943250
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"taskhost.exe"
taskeng.exe {DFA476E1-C226-4861-83F9-3BF698030B57}
"c:\program files (x86)\teamviewer\version7\TeamViewer.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe" /AUTORUN
"C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe" --action hooks --deferlog --log
"C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe" --action hooks --deferlog --log
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Apoint2K\Apoint.exe"
"C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe"
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe"
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
{29BD2294-5DD5-4136-A90B-F9EA2E1A9AD5}
{329BC4C6-EA86-4E75-A056-2FF41A6AB22D}
{3E80964B-630D-41BE-B7C7-13EB774B0D0E}
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Brownie\BrStsW64.exe" Autorun
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe"
"C:\Program Files (x86)\Brownie\brpjp04a.exe" "USB002" "Brother HL-3040CN series"
"C:\Program Files\Apoint2K\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files\Apoint2K\HidFind.exe"
"Apntex.exe"
\??\C:\Windows\system32\conhost.exe "-913577364-4960834461384527135-17320388124708918371192444383-959504855-941003357
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosHdpProc.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\tosBtProc.exe"
"C:\Program Files\TOSHIBA\HDMICtrlMan\HCMSoundChanger.exe" /SPEAKER
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Deskjet F4500 series#1325020111" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\info.txt
"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\log.txt
"c:\program files (x86)\teamviewer\version7\TeamViewer_Desktop.exe" --IPCport 5939
"D:\AVIRA záchranný systém\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2704916375-464737053-844809292-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2704916375-464737053-844809292-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Martin Stroka\AppData\Roaming\Mozilla\Firefox\Profiles\00oehbt4.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "smartwebprinting@hp.com:4.5, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {dc572301-7619-498c-a57d-39143191b318}:0.3.8.5, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.3.42, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.URL" - "http://toolbar.inbox.com/search/dispatc ... ge=cs&qkw="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
npdeployJava1.dll
nppdf32.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2011-11-10 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-11-10 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-08-24 8081952]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2009-07-22 312832]
"HDMICtrlMan"=C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [2009-08-03 1032536]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NokiaPCInternetAccess"=C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [2009-05-26 651264]
"Google Update"=C:\Users\Martin [2011-01-27 1946]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00TCrdMain]
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2009-08-05 909624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Martin [2011-01-27 1946]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-02-22 1226024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-09-08 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartFaceVWatcher]
C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-07-29 238080]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2009-08-13 570680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [2009-08-25 134032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosReelTimeMonitor]
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2009-08-06 35160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosSENotify]
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2009-08-03 709976]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-08-21 497504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TUSBSleepChargeSrv]
C:\Program Files (x86)\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe [2009-07-02 252288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Martin Stroka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~2\MIF5BA~1\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NPSStartup"= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
""= []
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2011-10-11 258512]
"BrStsWnd"=C:\Program Files (x86)\Brownie\BrstsW64.exe [2011-03-25 3695984]
"Anti Trojan Elite"=C:\Program Files (x86)\Anti Trojan Elite\TJEnder.exe [2012-01-19 4076544]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Promixis\Girder\girder.exe"="C:\Program Files (x86)\Promixis\Girder\girder.exe:*:Enabled:Trust Girder"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\Program Files (x86)\Promixis\Girder\girder.exe"="C:\Program Files (x86)\Promixis\Girder\girder.exe:*:Enabled:Trust Girder"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - %SystemRoot%\SysWow64\CScript.exe "%1" %*
.vbs - open - %SystemRoot%\SysWow64\CScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-01-19 19:35:15 ----D---- C:\rsit
2012-01-19 19:35:15 ----D---- C:\Program Files\trend micro
2012-01-19 13:20:20 ----D---- C:\Program Files (x86)\Anti Trojan Elite
2012-01-19 12:58:05 ----D---- C:\ProgramData\Spybot - Search & Destroy
2012-01-19 12:58:05 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2012-01-19 12:56:35 ----D---- C:\Users\Martin Stroka\AppData\Roaming\Safer Networking
2012-01-19 12:56:21 ----D---- C:\Program Files (x86)\Safer Networking
2012-01-18 20:57:09 ----D---- C:\Program Files (x86)\LinuxLive USB Creator
2012-01-16 16:34:17 ----A---- C:\Windows\system32\drivers\4860279drv.sys
2012-01-16 16:34:17 ----A---- C:\Windows\system32\drivers\25370561.sys
2012-01-16 01:07:55 ----A---- C:\Windows\system32\drivers\53833460.sys
2012-01-16 00:00:51 ----D---- C:\ProgramData\RegCure
2012-01-16 00:00:51 ----D---- C:\Program Files (x86)\RegCure
2012-01-15 21:33:09 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-01-15 21:33:08 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-01-15 21:33:06 ----D---- C:\Users\Martin Stroka\AppData\Roaming\PunkBuster
2012-01-15 20:36:56 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-01-15 20:36:56 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-01-15 20:36:56 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-01-15 20:36:56 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-01-15 20:36:56 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-01-15 20:36:56 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-01-15 20:36:55 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-01-15 20:36:55 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-01-15 20:36:51 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-01-15 20:36:51 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-01-15 20:36:50 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-01-15 20:36:50 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-01-15 20:36:48 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-01-15 20:36:48 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-01-15 20:36:46 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-01-15 20:36:46 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-01-15 20:36:45 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-01-15 20:36:45 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-01-15 20:36:45 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-01-15 20:36:45 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-01-15 20:36:44 ----A---- C:\Wi=1
MSVideo8=1
MSVideo8ndows\SYSWOW64\xactengine3_6.dll
2012-01-15 20:36:44 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-01-15 20:36:44 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-01-15 20:36:44 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-01-15 20:36:42 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-01-15 20:36:42 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-01-15 20:36:42 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-01-15 20:36:42 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-01-15 20:36:40 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-01-15 20:36:40 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-01-15 20:36:38 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-01-15 20:36:38 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-01-15 20:36:37 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-01-15 20:36:37 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-01-15 20:36:36 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-01-15 20:36:35 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-01-15 20:36:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-01-15 20:36:31 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-01-15 20:36:28 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-01-15 20:36:28 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-01-15 20:36:28 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-01-15 20:36:28 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-01-15 20:36:26 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-01-15 20:36:26 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-01-15 20:36:25 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-01-15 20:36:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-01-15 20:36:25 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-01-15 20:36:25 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-01-15 20:36:24 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-01-15 20:36:24 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-01-15 20:36:24 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-01-15 20:36:24 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-01-15 20:36:23 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-01-15 20:36:23 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-01-15 20:36:23 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-01-15 20:36:23 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-01-15 20:36:22 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-01-15 20:36:22 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-01-15 20:36:21 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-01-15 20:36:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-01-15 20:36:21 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-01-15 20:36:21 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-01-15 20:36:19 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-01-15 20:36:19 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-01-15 20:36:18 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-01-15 20:36:18 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-01-15 20:36:18 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-01-15 20:36:18 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-01-15 20:36:17 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-01-15 20:36:17 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-01-15 20:36:17 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-01-15 20:36:17 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-01-15 20:36:15 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-01-15 20:36:15 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-01-15 20:36:15 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-01-15 20:36:15 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-01-15 20:36:13 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-01-15 20:36:13 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-01-15 20:36:13 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-01-15 20:36:13 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-01-15 20:36:12 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-01-15 20:36:12 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-01-15 20:36:12 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-01-15 20:36:12 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-01-15 20:36:10 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-01-15 20:36:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-01-15 20:36:10 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-01-15 20:36:10 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-01-15 20:36:08 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-01-15 20:36:08 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-01-15 20:36:08 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-01-15 20:36:08 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-01-15 20:36:05 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-01-15 20:36:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-01-15 20:36:05 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-01-15 20:36:05 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-01-15 20:36:03 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-01-15 20:36:03 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-01-15 20:36:02 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-01-15 20:36:02 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-01-15 20:36:00 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-01-15 20:36:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-01-15 20:36:00 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-01-15 20:36:00 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-01-15 20:35:58 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-01-15 20:35:58 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-01-15 20:35:56 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-01-15 20:35:56 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-01-15 20:35:56 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-01-15 20:35:56 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-01-15 20:35:55 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-01-15 20:35:55 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-01-15 20:35:55 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-01-15 20:35:55 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-01-15 20:35:53 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-01-15 20:35:53 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-01-15 20:35:52 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-01-15 20:35:52 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-01-15 20:35:51 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-01-15 20:35:51 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-01-15 20:35:51 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-01-15 20:35:51 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-01-15 20:35:49 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2012-01-15 20:35:49 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-01-15 20:35:48 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-01-15 20:35:48 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-01-15 20:35:47 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-01-15 20:35:47 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-01-15 20:35:47 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-01-15 20:35:47 ----A---- C:\Windows\system32\d3dx10.dll
2012-01-15 20:35:45 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-01-15 20:35:45 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-01-15 20:35:44 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-01-15 20:35:44 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-01-15 20:35:44 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-01-15 20:35:44 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-01-15 20:35:42 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-01-15 20:35:42 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-01-15 20:35:41 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-01-15 20:35:41 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-01-15 20:35:41 ----A---- C:\Windows\system32\xinput1_2.dll
2012-01-15 20:35:41 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-01-15 20:35:40 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2012-01-15 20:35:40 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-01-15 20:35:40 ----A---- C:\Windows\system32\xinput1_1.dll
2012-01-15 20:35:40 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-01-15 20:35:39 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2012-01-15 20:35:39 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-01-15 20:35:30 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2012-01-15 20:35:30 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-01-15 20:35:29 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-01-15 20:35:29 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2012-01-15 20:35:29 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-01-15 20:35:29 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-01-15 20:35:28 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-01-15 20:35:28 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-01-15 20:35:26 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-01-15 20:35:26 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-01-15 20:35:24 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-01-15 20:35:24 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-01-15 20:35:22 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-01-15 20:35:22 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-01-15 20:35:20 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2012-01-15 20:35:20 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-01-15 20:35:19 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-01-15 20:35:19 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-01-10 21:19:29 ----A---- C:\Windows\system32\schannel.dll
2012-01-10 21:19:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-01-10 21:19:28 ----A---- C:\Windows\SYSWOW64\webio.dll
2012-01-10 21:19:28 ----A---- C:\Windows\SYSWOW64\schannel.dll
2012-01-10 21:19:28 ----A---- C:\Windows\system32\webio.dll
2012-01-10 21:19:28 ----A---- C:\Windows\system32\lsass.exe
2012-01-10 21:19:28 ----A---- C:\Windows\system32\lsasrv.dll
2012-01-10 21:19:28 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-01-10 21:19:28 ----A---- C:\Windows\system32\drivers\cng.sys
2012-01-10 21:19:27 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2012-01-10 21:19:27 ----A---- C:\Windows\SYSWOW64\secur32.dll
2012-01-10 21:19:27 ----A---- C:\Windows\system32\sspisrv.dll
2012-01-10 21:19:27 ----A---- C:\Windows\system32\sspicli.dll
2012-01-10 21:19:27 ----A---- C:\Windows\system32\secur32.dll
2012-01-10 20:21:45 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-01-10 20:21:45 ----A---- C:\Windows\system32\mshtmled.dll
2012-01-10 20:21:44 ----A---- C:\Windows\SYSWOW64\url.dll
2012-01-10 20:21:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-01-10 20:21:44 ----A---- C:\Windows\system32\url.dll
2012-01-10 20:21:44 ----A---- C:\Windows\system32\iertutil.dll
2012-01-10 20:21:43 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-01-10 20:21:43 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-01-10 20:21:43 ----A---- C:\Windows\system32\urlmon.dll
2012-01-10 20:21:43 ----A---- C:\Windows\system32\ieui.dll
2012-01-10 20:21:42 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-01-10 20:21:42 ----A---- C:\Windows\system32\wininet.dll
2012-01-10 20:21:42 ----A---- C:\Windows\system32\jsproxy.dll
2012-01-10 20:21:41 ----A---- C:\Windows\system32\jscript9.dll
2012-01-10 20:21:40 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-01-10 20:21:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-01-10 20:21:39 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-01-10 20:21:39 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-01-10 20:21:39 ----A---- C:\Windows\system32\jscript.dll
2012-01-10 20:21:36 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-01-10 20:21:36 ----A---- C:\Windows\system32\mshtml.dll
2012-01-10 20:21:35 ----A---- C:\Windows\system32\ieframe.dll
2012-01-10 20:20:08 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-01-10 20:20:08 ----A---- C:\Windows\system32\quartz.dll
2012-01-10 20:20:07 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-01-10 20:20:07 ----A---- C:\Windows\system32\qdvd.dll
2012-01-10 20:20:06 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-01-10 20:20:06 ----A---- C:\Windows\system32\ntdll.dll
2012-01-10 20:20:05 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-01-10 20:20:05 ----A---- C:\Windows\system32\packager.dll
2012-01-10 20:17:04 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-01-10 20:17:04 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-01-10 20:17:04 ----A---- C:\Windows\SYSWOW64\java.exe
2012-01-02 14:52:14 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-01-02 14:52:14 ----A---- C:\Windows\system32\tzres.dll
2011-12-30 22:34:36 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-30 22:16:49 ----A---- C:\Windows\system32\win32k.sys
2011-12-30 22:14:15 ----A---- C:\Windows\system32\EncDec.dll
2011-12-30 22:14:14 ----A---- C:\Windows\SYSWOW64\EncDec.dll

======List of files/folders modified in the last 1 month======

2012-01-19 20:57:34 ----D---- C:\Windows\Temp
2012-01-19 19:35:22 ----D---- C:\Windows\Prefetch
2012-01-19 19:35:15 ----RD---- C:\Program Files
2012-01-19 19:13:22 ----A---- C:\Windows\Brownie.ini
2012-01-19 19:01:10 ----D---- C:\Windows\system32\config
2012-01-19 15:57:58 ----SHD---- C:\System Volume Information
2012-01-19 13:20:20 ----RD---- C:\Program Files (x86)
2012-01-19 12:58:05 ----HD---- C:\ProgramData
2012-01-19 10:35:38 ----D---- C:\Windows\system32\catroot2
2012-01-18 22:10:14 ----D---- C:\Windows\system32\Tasks
2012-01-18 20:59:03 ----D---- C:\Program Files (x86)\Hard Disk Sentinel
2012-01-16 22:02:57 ----D---- C:\Windows\system32\drivers
2012-01-16 09:27:46 ----D---- C:\Program Files (x86)\ProFact 3.0
2012-01-16 01:08:33 ----D---- C:\ProgramData\Kaspersky Lab
2012-01-16 00:51:07 ----D---- C:\Users\Martin Stroka\AppData\Roaming\uTorrent
2012-01-16 00:35:12 ----D---- C:\Program Files\Puran Defrag
2012-01-16 00:25:45 ----D---- C:\Windows\system32\NDF
2012-01-15 22:45:15 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-01-15 22:45:15 ----D---- C:\Program Files (x86)\Ubisoft
2012-01-15 22:45:11 ----SHD---- C:\Windows\Installer
2012-01-15 22:45:11 ----HD---- C:\Config.Msi
2012-01-15 22:44:07 ----RSD---- C:\Windows\assembly
2012-01-15 22:21:28 ----D---- C:\Windows\SYSWOW64\wbem
2012-01-15 22:08:08 ----D---- C:\Windows\SYSWOW64\sysprep
2012-01-15 22:08:08 ----D---- C:\Windows\SYSWOW64\Setup
2012-01-15 22:08:08 ----D---- C:\Windows\SysWOW64
2012-01-15 22:08:07 ----D---- C:\Windows\SYSWOW64\oobe
2012-01-15 22:08:07 ----D---- C:\Windows\SYSWOW64\MUI
2012-01-15 22:08:07 ----D---- C:\Windows\SYSWOW64\drivers
2012-01-15 22:08:07 ----D---- C:\Windows\SYSWOW64\config
2012-01-15 22:08:03 ----D---- C:\Windows\SYSWOW64\com
2012-01-15 21:56:00 ----D---- C:\ProgramData\Ubisoft
2012-01-15 21:33:07 ----D---- C:\Windows\system32\LogFiles
2012-01-15 21:32:15 ----D---- C:\Windows\winsxs
2012-01-15 20:36:57 ----D---- C:\Windows\System32
2012-01-10 21:34:27 ----D---- C:\Windows\system32\catroot
2012-01-10 20:47:11 ----D---- C:\Windows\Microsoft.NET
2012-01-10 20:36:24 ----D---- C:\Windows\ehome
2012-01-10 20:36:23 ----D---- C:\Windows\SYSWOW64\migration
2012-01-10 20:36:23 ----D---- C:\Windows\system32\migration
2012-01-10 20:36:23 ----D---- C:\Program Files\Internet Explorer
2012-01-10 20:36:23 ----D---- C:\Program Files (x86)\Internet Explorer
2012-01-10 20:28:01 ----A---- C:\Windows\system32\MRT.exe
2012-01-10 20:22:34 ----D---- C:\ProgramData\Microsoft Help
2012-01-10 20:16:59 ----D---- C:\Program Files (x86)\Java
2012-01-10 20:15:06 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-01-06 18:07:39 ----D---- C:\Windows\rescache
2012-01-03 03:01:31 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-01-03 03:01:31 ----D---- C:\Windows\system32\cs-CZ
2011-12-27 22:24:27 ----D---- C:\Windows
2011-12-27 22:16:05 ----A---- C:\Windows\win.ini
2011-12-27 22:15:50 ----D---- C:\Windows\twain_32
2011-12-27 22:07:53 ----D---- C:\Windows\inf

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 25370561;25370561; C:\Windows\system32\DRIVERS\25370561.sys [2012-01-16 460888]
R0 36090012;36090012 Boot Guard Driver; C:\Windows\system32\DRIVERS\36090012.sys [2009-10-22 40464]
R0 53833460;53833460; C:\Windows\system32\DRIVERS\53833460.sys [2012-01-16 460888]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 408600]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-06-20 834544]
R0 Thpdrv;TOSHIBA HDD Protection Driver; C:\Windows\system32\DRIVERS\thpdrv.sys [2009-06-29 34880]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver; C:\Windows\system32\DRIVERS\Thpevm.SYS [2009-06-29 14784]
R0 tos_sps64;TOSHIBA tos_sps64 Service; C:\Windows\system32\DRIVERS\tos_sps64.sys [2009-07-24 482384]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 36090011;36090011; C:\Windows\system32\DRIVERS\36090011.sys [2009-09-25 157712]
R1 4860279drv;4860279drv; C:\Windows\system32\DRIVERS\4860279drv.sys [2012-01-16 556632]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2012-01-10 130760]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2011-10-11 27760]
R1 PMCF;PMCF; \??\C:\Windows\system32\drivers\PMCF.sys [2009-03-20 16392]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2009-07-28 81768]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-07-18 314016]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-10-11 97312]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-07-18 43680]
R2 rimspci;rimspci; C:\Windows\system32\DRIVERS\rimspe64.sys [2009-07-02 60416]
R2 risdpcie;risdpcie; C:\Windows\system32\DRIVERS\risdpe64.sys [2009-07-28 81408]
R2 rixdpcie;rixdpcie; C:\Windows\system32\DRIVERS\rixdpe64.sys [2009-07-04 55808]
R3 Afc;PPdus ASPI Shell; C:\Windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-07-13 253488]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-09-21 1537024]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-08-24 1985184]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-07-08 174184]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2009-07-07 211432]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2009-07-13 19824]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2009-06-19 94336]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2009-08-05 58744]
S1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S2 ATE_PROCMON;ATE_PROCMON; \??\C:\Program Files (x86)\Anti Trojan Elite\ATEPMon.sys [2010-11-15 9984]
S2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\drivers\atikmdag.sys [2009-07-13 5020672]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver; \??\C:\Windows\system32\drivers\BVRPMPR5a64.SYS [2010-09-27 35840]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2010-03-06 20480]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 SIUSBXP;SIUSBXP; C:\Windows\system32\drivers\SiUSBXp.sys [2007-03-01 16384]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\SmSerl64.sys [2009-06-10 1227776]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 127488]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 18944]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 161280]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver; C:\Windows\system32\DRIVERS\ss_bserd.sys [2010-04-27 128000]
S3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2010-11-30 35112]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2009-06-19 50664]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2009-08-05 63856]
S3 TridVid;Video Grabber; C:\Windows\system32\DRIVERS\tridvid6010.sys [2010-10-10 287488]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-08-17 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-08-17 9216]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Realtime Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-10-11 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
R2 BRA_Scheduler;Brother BRAdminPro Scheduler; C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe [2010-09-15 65536]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2010-04-07 127800]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1640768]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-01-15 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
R2 Thpsrv;Ochrana HDD TOSHIBA; C:\Windows\system32\ThpSrv.exe [2009-07-08 531520]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-10-27 718384]
R3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2009-07-30 192368]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-20 1255736]
S4 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-02-18 462632]
S4 PuranDefrag;PuranDefrag; C:\Windows\system32\PuranDefragS.exe [2011-04-08 295424]
S4 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-08-21 488800]
S4 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-03 137560]

-----------------EOF-----------------
Nalezl jsem trojany : keylogger keymsall2010
keylogger Overseer-setup monitor
Trojan Silent_manager_install
Pomocí programu anti trojan elite...plus jsme procistil PC pomocí programu AVIRA desktop
Ale jde hlavne o to ze se jich nemuzu zbavit...porad se kopiruji nekam jinam a infikuji jine soubory...takze donekonecna odstranovani bez smyslu...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o shlédnutí logu

#2 Příspěvek od Rudy »

Poprosím o log ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Re: Prosím o shlédnutí logu

#3 Příspěvek od freeacer »

Rudy píše:Poprosím o log ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
zdravím...super...děkuju za ochotu...je to notebook kde je fakturacni program,faktury,dokumenty atd...takze to bude chvili trvat,ale urco se ozvu co nejdriv...delam to vzdalenou spravou,jdu zalohovat plus instalovat combofix a vytvorit log...zatim...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o shlédnutí logu

#4 Příspěvek od Rudy »

Záloha je, samozřejmě nutná. Při odvirování se může stát ledacos.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Re: Prosím o shlédnutí logu

#5 Příspěvek od freeacer »

Výpis z Combofixu
ComboFix 12-01-19.02 - Martin Stroka 20.01.2012 18:18:42.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4093.2535 [GMT 1:00]
Spuštìný z: c:\users\Martin Stroka\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\AutocompletePro
c:\program files (x86)\AutocompletePro\InstTracker.exe
.
.
((((((((((((((((((((((((( Soubory vytvoøené od 2011-12-20 do 2012-01-20 )))))))))))))))))))))))))))))))
.
.
2012-01-20 17:27 . 2012-01-20 17:27 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-20 17:27 . 2012-01-20 17:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-20 17:27 . 2012-01-20 17:27 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-01-20 17:27 . 2012-01-20 17:27 -------- d-----w- c:\users\Fastro\AppData\Local\temp
2012-01-20 00:37 . 2012-01-20 00:37 -------- d-----w- c:\users\Martin Stroka\AppData\Roaming\Malwarebytes
2012-01-20 00:37 . 2012-01-20 00:37 -------- d-----w- c:\programdata\Malwarebytes
2012-01-20 00:37 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-20 00:37 . 2012-01-20 00:37 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-01-19 18:35 . 2012-01-19 19:57 -------- d-----w- c:\program files\trend micro
2012-01-19 18:35 . 2012-01-19 18:35 -------- d-----w- C:\rsit
2012-01-19 12:20 . 2012-01-19 12:22 -------- d-----w- c:\program files (x86)\Anti Trojan Elite
2012-01-19 11:58 . 2012-01-19 12:34 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-01-19 11:58 . 2012-01-19 12:04 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-01-19 11:56 . 2012-01-19 11:56 -------- d-----w- c:\users\Martin Stroka\AppData\Roaming\Safer Networking
2012-01-19 11:56 . 2012-01-19 11:56 -------- d-----w- c:\program files (x86)\Safer Networking
2012-01-18 19:57 . 2012-01-18 19:57 -------- d-----w- c:\program files (x86)\LinuxLive USB Creator
2012-01-16 15:34 . 2012-01-16 17:40 556632 ----a-w- c:\windows\system32\drivers\4860279drv.sys
2012-01-16 15:34 . 2012-01-16 17:40 460888 ----a-w- c:\windows\system32\drivers\25370561.sys
2012-01-16 00:07 . 2012-01-16 01:39 460888 ----a-w- c:\windows\system32\drivers\53833460.sys
2012-01-15 23:00 . 2012-01-15 23:14 -------- d-----w- c:\programdata\RegCure
2012-01-15 23:00 . 2012-01-15 23:12 -------- d-----w- c:\program files (x86)\RegCure
2012-01-15 21:49 . 2012-01-15 21:51 -------- d-----w- c:\users\Martin Stroka\AppData\Local\Ubisoft Game Launcher
2012-01-15 21:21 . 2012-01-15 21:21 -------- d-----w- c:\windows\SysWow64\wbem\Logs
2012-01-15 20:33 . 2012-01-15 20:33 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-15 20:33 . 2012-01-15 20:33 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-01-15 20:33 . 2012-01-15 20:33 -------- d-----w- c:\users\Martin Stroka\AppData\Roaming\PunkBuster
2012-01-15 19:35 . 2007-07-19 17:14 5073256 ----a-w- c:\windows\system32\d3dx9_35.dll
2012-01-10 20:19 . 2011-11-17 06:49 152432 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-10 19:21 . 2011-11-04 01:34 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-01-10 19:20 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 19:20 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-10 19:20 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-10 19:20 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-10 19:20 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-10 19:20 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-10 19:20 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-10 19:20 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-10 19:15 . 2012-01-10 19:15 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-10 19:15 . 2012-01-10 19:15 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-10 19:15 . 2012-01-10 19:15 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-10 19:15 . 2012-01-10 19:15 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-02 13:52 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2012-01-02 13:52 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-30 21:34 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-30 21:16 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-30 21:14 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-30 21:14 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-30 12:09 . 2011-12-30 12:09 -------- d-----w- c:\users\Fastro\AppData\Roaming\Avira
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-10 20:34 . 2011-10-23 07:09 130760 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-01-10 19:28 . 2011-06-28 06:41 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-17 06:35 . 2012-01-10 20:19 340992 ----a-w- c:\windows\system32\schannel.dll
2011-11-17 05:34 . 2012-01-10 20:19 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2011-11-10 04:54 . 2010-06-18 13:45 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2009-02-13 10:02 . 2009-02-13 10:02 80896 ----a-w- c:\program files\devcon_amd64.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštìcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaPCInternetAccess"="c:\program files (x86)\Nokia\PC Internet Access\NPCIA.exe" [2009-05-26 651264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"BrStsWnd"="c:\program files (x86)\Brownie\BrstsW64.exe" [2011-03-25 3695984]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
c:\users\Fastro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
_uninst_53833460.lnk - c:\users\Martin Stroka\AppData\Local\Temp\_uninst_53833460.bat [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2009-8-6 2680160]
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 ATE_PROCMON;ATE_PROCMON;c:\program files (x86)\Anti Trojan Elite\ATEPMon.sys [2010-11-15 9984]
R2 BRA_Scheduler;Brother BRAdminPro Scheduler;c:\program files (x86)\Brother\BRAdmin Professional 3\bratimer.exe [2010-09-15 65536]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [x]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 mvusbews;USB EWS Device;c:\windows\system32\Drivers\mvusbews.sys [x]
R3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [x]
R3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\DRIVERS\ss_bserd.sys [x]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448]
R3 TridVid;Video Grabber;c:\windows\system32\DRIVERS\tridvid6010.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x]
R3 WSDPrintDevice;Podpora tisku WSD prostøednictvím funkce UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
R3 wxpSvc;webcamXP Service;c:\program files (x86)\webcamXP 5\wService.exe [2011-07-27 5023744]
R4 NAUpdate;Aktualizace Nero;c:\program files (x86)\Nero\Update\NASvc.exe [2010-02-18 462632]
R4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [x]
R4 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-03 137560]
S0 25370561;25370561;c:\windows\system32\DRIVERS\25370561.sys [x]
S0 36090012;36090012 Boot Guard Driver;c:\windows\system32\DRIVERS\36090012.sys [x]
S0 53833460;53833460;c:\windows\system32\DRIVERS\53833460.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 36090011;36090011;c:\windows\system32\DRIVERS\36090011.sys [x]
S1 4860279drv;4860279drv;c:\windows\system32\DRIVERS\4860279drv.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 PMCF;PMCF;c:\windows\system32\drivers\PMCF.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys [x]
S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe64.sys [x]
S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys [x]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Ostatní služby/ovladaèe v pamìti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáøe 'Naplánované úlohy'
.
2012-01-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2704916375-464737053-844809292-1000Core.job
- c:\users\Martin Stroka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-26 16:04]
.
2012-01-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2704916375-464737053-844809292-1000UA.job
- c:\users\Martin Stroka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-26 16:04]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-24 8081952]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-07-22 312832]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplòkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: WikiKomentáøe Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files (x86)\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 10.0.0.1
FF - ProfilePath - c:\users\Martin Stroka\AppData\Roaming\Mozilla\Firefox\Profiles\00oehbt4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tbid=80093&language=cs&qkw=
.
.
------- Asociace souborù -------
.
JSEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
.
- - - - NEPLATNÉ POLOŽKY ODSTRANÌNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-NPSStartup - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
HKLM-Run-HDMICtrlMan - c:\program files (x86)\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\wxpSvc]
"ImagePath"="c:\program files (x86)\webcamXP 5\wService.exe /startedbyscm:5053B757-40E35B3B-webcamSRV"
.
--------------------- ZAMKNUTÉ KLÍÈE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2704916375-464737053-844809292-1000\Software\SecuROM\License information*]
"datasecu"=hex:6e,cd,0c,42,57,39,8a,8b,3e,e5,2d,b2,1e,26,aa,04,6a,55,35,ba,4a,
97,03,dd,e2,04,28,2b,eb,a9,78,9d,df,d9,a3,ab,e3,a3,23,3a,68,43,dd,9e,8c,94,\
"rkeysecu"=hex:07,71,e0,be,12,00,67,d2,1e,3f,bc,d7,41,81,3c,c9
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
@=""
"Installed"="1"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
@=""
"Installed"="1"
"NoChange"="1"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
@=""
"Installed"="1"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Hard Disk Sentinel\HDSentinel.exe
c:\program files (x86)\teamviewer\version7\TeamViewer.exe
c:\program files (x86)\TeamViewer\Version7\tv_w32.exe
c:\program files (x86)\teamviewer\version7\TeamViewer_Desktop.exe
.
**************************************************************************
.
Celkový èas: 2012-01-20 18:38:51 - poèítaè byl restartován
ComboFix-quarantined-files.txt 2012-01-20 17:38
.
Pøed spuštìním: Volných bajtù: 33 759 936 512
Po spuštìní: Volných bajtù: 44 096 802 816
.
- - End Of File - - E2B5D01C558ABFF60BE0A22C8C72F3CB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o shlédnutí logu

#6 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Collect::
c:\windows\system32\drivers\4860279drv.sys
c:\windows\system32\drivers\25370561.sys
c:\windows\system32\drivers\53833460.sys
c:\users\Fastro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
_uninst_53833460.lnk
c:\users\Martin Stroka\AppData\Local\Temp\_uninst_53833460.bat
c:\windows\system32\DRIVERS\53833460.sys
c:\windows\system32\DRIVERS\36090011.sys
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2704916375-464737053-844809292-1000Core.job
c:\users\Martin Stroka\AppData\Local\Google\Update\GoogleUpdate.exe
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2704916375-464737053-844809292-1000UA.job

Driver::
25370561
36090012
36090011
4860279drv
53833460

Firefox::
FF - ProfilePath - c:\users\Martin Stroka\AppData\Roaming\Mozilla\Firefox\Profiles\00oehbt4.default\
FF - prefs.js: keyword.URL - hxxp://toolbar.inbox.com/search/dispatc ... ge=cs&qkw=

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Re: Prosím o shlédnutí logu

#7 Příspěvek od freeacer »

Takze nevim jestli uspech...spise ne...script jsem spustil podle postupu,pocitac se restartoval,pote se spustila instalace skriptu a pak sem spustil aviru a opet nalezla nejaky skryty objekt...mam ted spustitantitrojanelite?nebo je jeste nejaka moznost?dekuju za radu.
Přílohy
screen o nalezu skryteho objektu...
screen o nalezu skryteho objektu...
avira.jpg (127.89 KiB) Zobrazeno 1627 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o shlédnutí logu

#8 Příspěvek od Rudy »

Zkuste ještě TDSSKiller: http://support.kaspersky.com/downloads/ ... killer.zip . Rozbalte na plochu, spusťte a mechte pracovat. Pak sem dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Re: Prosím o shlédnutí logu

#9 Příspěvek od freeacer »

23:50:35.0199 3676 TDSS rootkit removing tool 2.7.6.0 Jan 19 2012 13:09:04
23:50:35.0347 3676 ============================================================
23:50:35.0347 3676 Current date / time: 2012/01/20 23:50:35.0347
23:50:35.0347 3676 SystemInfo:
23:50:35.0347 3676
23:50:35.0347 3676 OS Version: 6.1.7601 ServicePack: 1.0
23:50:35.0347 3676 Product type: Workstation
23:50:35.0347 3676 ComputerName: MARTINSTROKA
23:50:35.0347 3676 UserName: Martin Stroka
23:50:35.0347 3676 Windows directory: C:\Windows
23:50:35.0347 3676 System windows directory: C:\Windows
23:50:35.0347 3676 Running under WOW64
23:50:35.0348 3676 Processor architecture: Intel x64
23:50:35.0348 3676 Number of processors: 2
23:50:35.0348 3676 Page size: 0x1000
23:50:35.0348 3676 Boot type: Normal boot
23:50:35.0348 3676 ============================================================
23:50:36.0399 3676 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:50:36.0515 3676 Initialize success
23:50:57.0559 4956 ============================================================
23:50:57.0559 4956 Scan started
23:50:57.0559 4956 Mode: Manual; SigCheck; TDLFS;
23:50:57.0559 4956 ============================================================
23:50:58.0755 4956 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
23:50:58.0897 4956 1394ohci - ok
23:50:59.0052 4956 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
23:50:59.0081 4956 ACPI - ok
23:50:59.0234 4956 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
23:50:59.0323 4956 AcpiPmi - ok
23:50:59.0479 4956 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
23:50:59.0532 4956 adp94xx - ok
23:50:59.0694 4956 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
23:50:59.0733 4956 adpahci - ok
23:50:59.0874 4956 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
23:50:59.0896 4956 adpu320 - ok
23:50:59.0933 4956 Afc - ok
23:51:00.0080 4956 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
23:51:00.0135 4956 AFD - ok
23:51:00.0266 4956 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
23:51:00.0285 4956 agp440 - ok
23:51:00.0463 4956 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
23:51:00.0476 4956 aliide - ok
23:51:00.0619 4956 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
23:51:00.0637 4956 amdide - ok
23:51:00.0767 4956 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
23:51:00.0859 4956 AmdK8 - ok
23:51:00.0959 4956 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
23:51:00.0995 4956 AmdPPM - ok
23:51:01.0125 4956 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
23:51:01.0155 4956 amdsata - ok
23:51:01.0292 4956 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
23:51:01.0353 4956 amdsbs - ok
23:51:01.0492 4956 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
23:51:01.0513 4956 amdxata - ok
23:51:01.0739 4956 ApfiltrService (1661f9c9e4b0049fa0a5e30264375a87) C:\Windows\system32\DRIVERS\Apfiltr.sys
23:51:01.0841 4956 ApfiltrService - ok
23:51:01.0995 4956 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
23:51:02.0276 4956 AppID - ok
23:51:02.0436 4956 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
23:51:02.0453 4956 arc - ok
23:51:02.0590 4956 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
23:51:02.0614 4956 arcsas - ok
23:51:02.0749 4956 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
23:51:02.0899 4956 AsyncMac - ok
23:51:03.0040 4956 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
23:51:03.0060 4956 atapi - ok
23:51:03.0198 4956 ATE_PROCMON (8492eaadb882c0f0b38a40dee1206445) C:\Program Files (x86)\Anti Trojan Elite\ATEPMon.sys
23:51:03.0247 4956 ATE_PROCMON ( UnsignedFile.Multi.Generic ) - warning
23:51:03.0247 4956 ATE_PROCMON - detected UnsignedFile.Multi.Generic (1)
23:51:03.0413 4956 athr (88a02b6046356e6be4e387faa7451439) C:\Windows\system32\DRIVERS\athrx.sys
23:51:03.0507 4956 athr - ok
23:51:03.0766 4956 atikmdag (3efd964d52221360af0673cd61c2f4f5) C:\Windows\system32\drivers\atikmdag.sys
23:51:04.0016 4956 atikmdag - ok
23:51:04.0168 4956 atksgt (fc0e8778c000291caf60eb88c011e931) C:\Windows\system32\DRIVERS\atksgt.sys
23:51:04.0201 4956 atksgt - ok
23:51:04.0413 4956 avgntflt (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\Windows\system32\DRIVERS\avgntflt.sys
23:51:04.0424 4956 avgntflt - ok
23:51:04.0571 4956 avipbb (f1c9db5f7b2a56a0b29667d22ba540fc) C:\Windows\system32\DRIVERS\avipbb.sys
23:51:04.0595 4956 avipbb - ok
23:51:04.0760 4956 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
23:51:04.0801 4956 avkmgr - ok
23:51:04.0966 4956 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
23:51:05.0029 4956 b06bdrv - ok
23:51:05.0162 4956 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
23:51:05.0206 4956 b57nd60a - ok
23:51:05.0328 4956 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
23:51:05.0380 4956 Beep - ok
23:51:05.0526 4956 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
23:51:05.0578 4956 blbdrive - ok
23:51:05.0724 4956 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
23:51:05.0790 4956 bowser - ok
23:51:05.0956 4956 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
23:51:05.0992 4956 BrFiltLo - ok
23:51:06.0106 4956 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
23:51:06.0128 4956 BrFiltUp - ok
23:51:06.0263 4956 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
23:51:06.0332 4956 BridgeMP - ok
23:51:06.0465 4956 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
23:51:06.0525 4956 Brserid - ok
23:51:06.0634 4956 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
23:51:06.0665 4956 BrSerWdm - ok
23:51:06.0794 4956 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
23:51:06.0833 4956 BrUsbMdm - ok
23:51:06.0949 4956 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
23:51:07.0010 4956 BrUsbSer - ok
23:51:07.0159 4956 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
23:51:07.0201 4956 BTHMODEM - ok
23:51:07.0396 4956 BVRPMPR5a64 (9887ca12f407d7fbc7f48f3678f5f0b6) C:\Windows\system32\drivers\BVRPMPR5a64.SYS
23:51:07.0410 4956 BVRPMPR5a64 - ok
23:51:07.0474 4956 catchme - ok
23:51:07.0590 4956 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
23:51:07.0656 4956 cdfs - ok
23:51:07.0790 4956 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
23:51:07.0848 4956 cdrom - ok
23:51:08.0011 4956 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
23:51:08.0063 4956 circlass - ok
23:51:08.0167 4956 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
23:51:08.0190 4956 CLFS - ok
23:51:08.0364 4956 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
23:51:08.0394 4956 CmBatt - ok
23:51:08.0523 4956 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
23:51:08.0547 4956 cmdide - ok
23:51:08.0686 4956 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
23:51:08.0726 4956 CNG - ok
23:51:08.0875 4956 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
23:51:08.0891 4956 Compbatt - ok
23:51:09.0029 4956 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
23:51:09.0089 4956 CompositeBus - ok
23:51:09.0224 4956 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
23:51:09.0244 4956 crcdisk - ok
23:51:09.0424 4956 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
23:51:09.0477 4956 DfsC - ok
23:51:09.0587 4956 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
23:51:09.0653 4956 discache - ok
23:51:09.0811 4956 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
23:51:09.0835 4956 Disk - ok
23:51:09.0994 4956 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys
23:51:10.0036 4956 Dot4 - ok
23:51:10.0190 4956 Dot4Print (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\DRIVERS\Dot4Prt.sys
23:51:10.0223 4956 Dot4Print - ok
23:51:10.0343 4956 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys
23:51:10.0389 4956 dot4usb - ok
23:51:10.0518 4956 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
23:51:10.0559 4956 drmkaud - ok
23:51:10.0696 4956 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
23:51:10.0734 4956 DXGKrnl - ok
23:51:10.0836 4956 eamonm - ok
23:51:11.0038 4956 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
23:51:11.0194 4956 ebdrv - ok
23:51:11.0355 4956 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
23:51:11.0394 4956 elxstor - ok
23:51:11.0516 4956 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
23:51:11.0565 4956 ErrDev - ok
23:51:11.0728 4956 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
23:51:11.0794 4956 exfat - ok
23:51:11.0916 4956 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
23:51:11.0979 4956 fastfat - ok
23:51:12.0097 4956 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
23:51:12.0141 4956 fdc - ok
23:51:12.0262 4956 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
23:51:12.0279 4956 FileInfo - ok
23:51:12.0387 4956 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
23:51:12.0462 4956 Filetrace - ok
23:51:12.0580 4956 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
23:51:12.0608 4956 flpydisk - ok
23:51:12.0757 4956 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
23:51:12.0787 4956 FltMgr - ok
23:51:12.0896 4956 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
23:51:12.0912 4956 FsDepends - ok
23:51:13.0006 4956 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
23:51:13.0025 4956 Fs_Rec - ok
23:51:13.0167 4956 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
23:51:13.0198 4956 fvevol - ok
23:51:13.0325 4956 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
23:51:13.0342 4956 gagp30kx - ok
23:51:13.0483 4956 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
23:51:13.0504 4956 hamachi - ok
23:51:13.0609 4956 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
23:51:13.0677 4956 hcw85cir - ok
23:51:13.0821 4956 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
23:51:13.0871 4956 HdAudAddService - ok
23:51:13.0991 4956 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
23:51:14.0039 4956 HDAudBus - ok
23:51:14.0145 4956 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
23:51:14.0194 4956 HidBatt - ok
23:51:14.0305 4956 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
23:51:14.0360 4956 HidBth - ok
23:51:14.0468 4956 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
23:51:14.0512 4956 HidIr - ok
23:51:14.0669 4956 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
23:51:14.0708 4956 HidUsb - ok
23:51:14.0895 4956 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
23:51:14.0912 4956 HpSAMD - ok
23:51:15.0108 4956 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
23:51:15.0179 4956 HTTP - ok
23:51:15.0282 4956 Huawei - ok
23:51:15.0426 4956 hwdatacard - ok
23:51:15.0551 4956 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
23:51:15.0570 4956 hwpolicy - ok
23:51:15.0670 4956 hwusbdev - ok
23:51:15.0824 4956 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
23:51:15.0857 4956 i8042prt - ok
23:51:15.0966 4956 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys
23:51:15.0980 4956 iaStor - ok
23:51:16.0122 4956 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
23:51:16.0157 4956 iaStorV - ok
23:51:16.0279 4956 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
23:51:16.0332 4956 iirsp - ok
23:51:16.0512 4956 IntcAzAudAddService (b6e61b181884527cc5b68c2d79504b43) C:\Windows\system32\drivers\RTKVHD64.sys
23:51:16.0571 4956 IntcAzAudAddService - ok
23:51:16.0690 4956 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
23:51:16.0715 4956 intelide - ok
23:51:16.0831 4956 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
23:51:16.0858 4956 intelppm - ok
23:51:16.0995 4956 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
23:51:17.0050 4956 IpFilterDriver - ok
23:51:17.0168 4956 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
23:51:17.0202 4956 IPMIDRV - ok
23:51:17.0299 4956 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
23:51:17.0379 4956 IPNAT - ok
23:51:17.0494 4956 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
23:51:17.0569 4956 IRENUM - ok
23:51:17.0704 4956 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
23:51:17.0719 4956 isapnp - ok
23:51:17.0841 4956 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
23:51:17.0879 4956 iScsiPrt - ok
23:51:18.0013 4956 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
23:51:18.0034 4956 kbdclass - ok
23:51:18.0202 4956 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
23:51:18.0252 4956 kbdhid - ok
23:51:18.0390 4956 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
23:51:18.0413 4956 KSecDD - ok
23:51:18.0533 4956 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
23:51:18.0555 4956 KSecPkg - ok
23:51:18.0682 4956 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
23:51:18.0745 4956 ksthunk - ok
23:51:18.0920 4956 lirsgt (156ab2e56dc3ca0b582e3362e07cded7) C:\Windows\system32\DRIVERS\lirsgt.sys
23:51:18.0939 4956 lirsgt - ok
23:51:19.0080 4956 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
23:51:19.0157 4956 lltdio - ok
23:51:19.0292 4956 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
23:51:19.0311 4956 LSI_FC - ok
23:51:19.0450 4956 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
23:51:19.0468 4956 LSI_SAS - ok
23:51:19.0626 4956 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
23:51:19.0651 4956 LSI_SAS2 - ok
23:51:19.0776 4956 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
23:51:19.0802 4956 LSI_SCSI - ok
23:51:19.0933 4956 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
23:51:20.0000 4956 luafv - ok
23:51:20.0136 4956 MBAMProtector (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys
23:51:20.0149 4956 MBAMProtector - ok
23:51:20.0277 4956 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
23:51:20.0293 4956 megasas - ok
23:51:20.0427 4956 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
23:51:20.0467 4956 MegaSR - ok
23:51:20.0605 4956 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
23:51:20.0668 4956 Modem - ok
23:51:20.0779 4956 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
23:51:20.0829 4956 monitor - ok
23:51:20.0966 4956 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
23:51:20.0990 4956 mouclass - ok
23:51:21.0133 4956 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
23:51:21.0175 4956 mouhid - ok
23:51:21.0289 4956 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
23:51:21.0303 4956 mountmgr - ok
23:51:21.0418 4956 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
23:51:21.0438 4956 mpio - ok
23:51:21.0545 4956 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
23:51:21.0605 4956 mpsdrv - ok
23:51:21.0730 4956 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
23:51:21.0814 4956 MRxDAV - ok
23:51:21.0927 4956 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
23:51:21.0976 4956 mrxsmb - ok
23:51:22.0087 4956 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
23:51:22.0147 4956 mrxsmb10 - ok
23:51:22.0263 4956 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
23:51:22.0299 4956 mrxsmb20 - ok
23:51:22.0417 4956 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
23:51:22.0430 4956 msahci - ok
23:51:22.0563 4956 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
23:51:22.0586 4956 msdsm - ok
23:51:22.0727 4956 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
23:51:22.0765 4956 Msfs - ok
23:51:22.0876 4956 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
23:51:22.0946 4956 mshidkmdf - ok
23:51:23.0066 4956 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
23:51:23.0079 4956 msisadrv - ok
23:51:23.0212 4956 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
23:51:23.0270 4956 MSKSSRV - ok
23:51:23.0396 4956 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
23:51:23.0452 4956 MSPCLOCK - ok
23:51:23.0579 4956 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
23:51:23.0645 4956 MSPQM - ok
23:51:23.0774 4956 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
23:51:23.0793 4956 MsRPC - ok
23:51:23.0909 4956 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
23:51:23.0921 4956 mssmbios - ok
23:51:24.0046 4956 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
23:51:24.0103 4956 MSTEE - ok
23:51:24.0207 4956 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
23:51:24.0254 4956 MTConfig - ok
23:51:24.0377 4956 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
23:51:24.0394 4956 Mup - ok
23:51:24.0549 4956 mvusbews (8fa52b6049596fe2fdbc8a5e8b14ebfc) C:\Windows\system32\Drivers\mvusbews.sys
23:51:24.0596 4956 mvusbews - ok
23:51:24.0741 4956 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
23:51:24.0793 4956 NativeWifiP - ok
23:51:24.0995 4956 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
23:51:25.0023 4956 NDIS - ok
23:51:25.0150 4956 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
23:51:25.0236 4956 NdisCap - ok
23:51:25.0359 4956 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
23:51:25.0418 4956 NdisTapi - ok
23:51:25.0565 4956 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
23:51:25.0627 4956 Ndisuio - ok
23:51:25.0751 4956 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
23:51:25.0807 4956 NdisWan - ok
23:51:25.0929 4956 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
23:51:25.0996 4956 NDProxy - ok
23:51:26.0159 4956 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
23:51:26.0230 4956 NetBIOS - ok
23:51:26.0381 4956 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
23:51:26.0473 4956 NetBT - ok
23:51:26.0635 4956 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
23:51:26.0662 4956 nfrd960 - ok
23:51:26.0808 4956 nmwcd (907b5e1e4a592e5edc5e4ccbde4863c2) C:\Windows\system32\drivers\ccdcmbx64.sys
23:51:26.0851 4956 nmwcd - ok
23:51:27.0008 4956 nmwcdc (41c1ac1f3613435eb32d67bcb80a5fa5) C:\Windows\system32\drivers\ccdcmbox64.sys
23:51:27.0081 4956 nmwcdc - ok
23:51:27.0195 4956 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
23:51:27.0248 4956 Npfs - ok
23:51:27.0362 4956 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
23:51:27.0415 4956 nsiproxy - ok
23:51:27.0575 4956 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
23:51:27.0625 4956 Ntfs - ok
23:51:27.0722 4956 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
23:51:27.0797 4956 Null - ok
23:51:27.0927 4956 NVHDA (10204955027011e08a9dc27737a48a54) C:\Windows\system32\drivers\nvhda64v.sys
23:51:27.0950 4956 NVHDA - ok
23:51:28.0393 4956 nvlddmkm (b15258b1f45f9571758ac6bb2f043b01) C:\Windows\system32\DRIVERS\nvlddmkm.sys
23:51:28.0915 4956 nvlddmkm - ok
23:51:29.0107 4956 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
23:51:29.0129 4956 nvraid - ok
23:51:29.0251 4956 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
23:51:29.0272 4956 nvstor - ok
23:51:29.0439 4956 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
23:51:29.0471 4956 nv_agp - ok
23:51:29.0591 4956 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
23:51:29.0648 4956 ohci1394 - ok
23:51:29.0818 4956 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
23:51:29.0849 4956 Parport - ok
23:51:29.0960 4956 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
23:51:29.0976 4956 partmgr - ok
23:51:30.0147 4956 pccsmcfd (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
23:51:30.0204 4956 pccsmcfd - ok
23:51:30.0317 4956 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
23:51:30.0336 4956 pci - ok
23:51:30.0444 4956 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
23:51:30.0457 4956 pciide - ok
23:51:30.0561 4956 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
23:51:30.0583 4956 pcmcia - ok
23:51:30.0687 4956 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
23:51:30.0708 4956 pcw - ok
23:51:30.0829 4956 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
23:51:30.0910 4956 PEAUTH - ok
23:51:31.0061 4956 PGEffect (663962900e7fea522126ba287715bb4a) C:\Windows\system32\DRIVERS\pgeffect.sys
23:51:31.0078 4956 PGEffect - ok
23:51:31.0243 4956 PMCF (b7a792764e896e8621901550908d6ad8) C:\Windows\system32\drivers\PMCF.sys
23:51:31.0259 4956 PMCF - ok
23:51:31.0477 4956 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
23:51:31.0544 4956 PptpMiniport - ok
23:51:31.0641 4956 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
23:51:31.0683 4956 Processor - ok
23:51:31.0844 4956 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
23:51:31.0906 4956 Psched - ok
23:51:32.0081 4956 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
23:51:32.0131 4956 ql2300 - ok
23:51:32.0241 4956 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
23:51:32.0262 4956 ql40xx - ok
23:51:32.0372 4956 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
23:51:32.0428 4956 QWAVEdrv - ok
23:51:32.0563 4956 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
23:51:32.0602 4956 RasAcd - ok
23:51:32.0729 4956 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
23:51:32.0771 4956 RasAgileVpn - ok
23:51:32.0897 4956 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
23:51:32.0964 4956 Rasl2tp - ok
23:51:33.0075 4956 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
23:51:33.0145 4956 RasPppoe - ok
23:51:33.0277 4956 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
23:51:33.0361 4956 RasSstp - ok
23:51:33.0499 4956 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
23:51:33.0577 4956 rdbss - ok
23:51:33.0679 4956 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
23:51:33.0713 4956 rdpbus - ok
23:51:33.0821 4956 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
23:51:33.0879 4956 RDPCDD - ok
23:51:34.0000 4956 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
23:51:34.0045 4956 RDPENCDD - ok
23:51:34.0141 4956 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
23:51:34.0197 4956 RDPREFMP - ok
23:51:34.0315 4956 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
23:51:34.0359 4956 RDPWD - ok
23:51:34.0495 4956 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
23:51:34.0512 4956 rdyboost - ok
23:51:34.0644 4956 rimspci (e20b1907fc72a3664ece21e3c20fc63d) C:\Windows\system32\DRIVERS\rimspe64.sys
23:51:34.0680 4956 rimspci - ok
23:51:34.0800 4956 risdpcie (7dda2e5cf452dad24b1be704225c18ee) C:\Windows\system32\DRIVERS\risdpe64.sys
23:51:34.0895 4956 risdpcie - ok
23:51:35.0042 4956 rixdpcie (6a1cd4674505e6791390a1ab71da1fbe) C:\Windows\system32\DRIVERS\rixdpe64.sys
23:51:35.0087 4956 rixdpcie - ok
23:51:35.0224 4956 ROOTMODEM (388d3dd1a6457280f3badba9f3acd6b1) C:\Windows\system32\Drivers\RootMdm.sys
23:51:35.0295 4956 ROOTMODEM - ok
23:51:35.0446 4956 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
23:51:35.0512 4956 rspndr - ok
23:51:35.0679 4956 RTL8167 (ee082e06a82ff630351d1e0ebbd3d8d0) C:\Windows\system32\DRIVERS\Rt64win7.sys
23:51:35.0703 4956 RTL8167 - ok
23:51:35.0824 4956 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
23:51:35.0851 4956 sbp2port - ok
23:51:35.0996 4956 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
23:51:36.0049 4956 scfilter - ok
23:51:36.0180 4956 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys
23:51:36.0225 4956 sdbus - ok
23:51:36.0352 4956 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
23:51:36.0414 4956 secdrv - ok
23:51:36.0548 4956 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
23:51:36.0572 4956 Serenum - ok
23:51:36.0713 4956 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
23:51:36.0777 4956 Serial - ok
23:51:36.0895 4956 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
23:51:36.0930 4956 sermouse - ok
23:51:37.0109 4956 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
23:51:37.0159 4956 sffdisk - ok
23:51:37.0267 4956 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
23:51:37.0306 4956 sffp_mmc - ok
23:51:37.0421 4956 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
23:51:37.0472 4956 sffp_sd - ok
23:51:37.0588 4956 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
23:51:37.0743 4956 sfloppy - ok
23:51:37.0914 4956 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
23:51:37.0971 4956 SiSRaid2 - ok
23:51:38.0088 4956 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
23:51:38.0108 4956 SiSRaid4 - ok
23:51:38.0283 4956 SIUSBXP (50aad2a07bd8b90a8cfb4f6d7a4d165a) C:\Windows\system32\drivers\SiUSBXp.sys
23:51:38.0329 4956 SIUSBXP - ok
23:51:38.0457 4956 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
23:51:38.0514 4956 Smb - ok
23:51:38.0674 4956 smserial (7ae8bca90539ecbde87ac45ba1436be3) C:\Windows\system32\DRIVERS\SmSerl64.sys
23:51:38.0737 4956 smserial - ok
23:51:38.0870 4956 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
23:51:38.0887 4956 spldr - ok
23:51:39.0078 4956 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
23:51:39.0078 4956 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
23:51:39.0081 4956 sptd ( LockedFile.Multi.Generic ) - warning
23:51:39.0081 4956 sptd - detected LockedFile.Multi.Generic (1)
23:51:39.0196 4956 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
23:51:39.0254 4956 srv - ok
23:51:39.0380 4956 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
23:51:39.0400 4956 srv2 - ok
23:51:39.0520 4956 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
23:51:39.0563 4956 srvnet - ok
23:51:39.0718 4956 ss_bbus (ef806d212d34b0e173baeb3564d53e37) C:\Windows\system32\DRIVERS\ss_bbus.sys
23:51:39.0744 4956 ss_bbus - ok
23:51:39.0876 4956 ss_bmdfl (08b1b34abebeb6ac2dea06900c56411e) C:\Windows\system32\DRIVERS\ss_bmdfl.sys
23:51:39.0892 4956 ss_bmdfl - ok
23:51:39.0921 4956 ss_bmdm (71a9da6beaa4cb54dfb827fb78600a5d) C:\Windows\system32\DRIVERS\ss_bmdm.sys
23:51:39.0937 4956 ss_bmdm - ok
23:51:40.0068 4956 ss_bserd (677cdc98f8363accaae783fde1599c2a) C:\Windows\system32\DRIVERS\ss_bserd.sys
23:51:40.0093 4956 ss_bserd - ok
23:51:40.0228 4956 StarOpen - ok
23:51:40.0336 4956 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
23:51:40.0351 4956 stexstor - ok
23:51:40.0482 4956 StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys
23:51:40.0531 4956 StillCam - ok
23:51:40.0671 4956 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
23:51:40.0695 4956 swenum - ok
23:51:40.0927 4956 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
23:51:40.0981 4956 Tcpip - ok
23:51:41.0171 4956 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
23:51:41.0218 4956 TCPIP6 - ok
23:51:41.0336 4956 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
23:51:41.0393 4956 tcpipreg - ok
23:51:41.0528 4956 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\Windows\system32\DRIVERS\tdcmdpst.sys
23:51:41.0547 4956 tdcmdpst - ok
23:51:41.0649 4956 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
23:51:41.0736 4956 TDPIPE - ok
23:51:41.0848 4956 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
23:51:41.0902 4956 TDTCP - ok
23:51:42.0043 4956 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
23:51:42.0104 4956 tdx - ok
23:51:42.0274 4956 teamviewervpn (f5520dbb47c60ee83024b38720abda24) C:\Windows\system32\DRIVERS\teamviewervpn.sys
23:51:42.0308 4956 teamviewervpn - ok
23:51:42.0430 4956 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
23:51:42.0458 4956 TermDD - ok
23:51:42.0626 4956 TFsExDisk (48d9d00c2e0e72c3d4f52772c80355f6) C:\Windows\System32\Drivers\TFsExDisk.sys
23:51:42.0645 4956 TFsExDisk - ok
23:51:42.0800 4956 Thpdrv (c013f6acaa9761f571bd28dada7c157d) C:\Windows\system32\DRIVERS\thpdrv.sys
23:51:42.0815 4956 Thpdrv - ok
23:51:42.0941 4956 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\Windows\system32\DRIVERS\Thpevm.SYS
23:51:42.0952 4956 Thpevm - ok
23:51:43.0137 4956 tosporte (8021f63311797085949fa387f7c83583) C:\Windows\system32\DRIVERS\tosporte.sys
23:51:43.0157 4956 tosporte - ok
23:51:43.0280 4956 tosrfbd (71bb669bfcade1580fdce010abc76310) C:\Windows\system32\DRIVERS\tosrfbd.sys
23:51:43.0298 4956 tosrfbd - ok
23:51:43.0446 4956 tosrfbnp (62512b5277d88600f8bd4b7aec43569d) C:\Windows\system32\Drivers\tosrfbnp.sys
23:51:43.0454 4956 tosrfbnp - ok
23:51:43.0573 4956 Tosrfcom (c523a9186c39d65cc9adebb2e1b93ccd) C:\Windows\system32\Drivers\tosrfcom.sys
23:51:43.0591 4956 Tosrfcom - ok
23:51:43.0698 4956 tosrfec (11699d47b3491d86249c168496d55c92) C:\Windows\system32\DRIVERS\tosrfec.sys
23:51:43.0708 4956 tosrfec - ok
23:51:43.0836 4956 Tosrfhid (451b8c1815c6cc39650af916c2a382cd) C:\Windows\system32\DRIVERS\Tosrfhid.sys
23:51:43.0858 4956 Tosrfhid - ok
23:51:43.0998 4956 tosrfnds (b6fdc3c76ffe9c5171eea9c37ea367c2) C:\Windows\system32\DRIVERS\tosrfnds.sys
23:51:44.0016 4956 tosrfnds - ok
23:51:44.0150 4956 TosRfSnd (e1e045240c1184fa6628f3c7e7ff85d8) C:\Windows\system32\drivers\tosrfsnd.sys
23:51:44.0162 4956 TosRfSnd - ok
23:51:44.0287 4956 Tosrfusb (da7aa562448e29ca895895920bff8946) C:\Windows\system32\DRIVERS\tosrfusb.sys
23:51:44.0308 4956 Tosrfusb - ok
23:51:44.0461 4956 tos_sps64 (09ff7b0b1b5c3d225495cb6f5a9b39f8) C:\Windows\system32\DRIVERS\tos_sps64.sys
23:51:44.0480 4956 tos_sps64 - ok
23:51:44.0617 4956 TridVid (39ad15ec81f8a91dadf983f8316606ed) C:\Windows\system32\DRIVERS\tridvid6010.sys
23:51:44.0673 4956 TridVid - ok
23:51:44.0831 4956 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
23:51:44.0896 4956 tssecsrv - ok
23:51:45.0042 4956 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
23:51:45.0115 4956 TsUsbFlt - ok
23:51:45.0268 4956 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
23:51:45.0340 4956 tunnel - ok
23:51:45.0485 4956 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
23:51:45.0500 4956 TVALZ - ok
23:51:45.0608 4956 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
23:51:45.0634 4956 uagp35 - ok
23:51:45.0765 4956 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
23:51:45.0820 4956 udfs - ok
23:51:45.0972 4956 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
23:51:45.0994 4956 uliagpkx - ok
23:51:46.0104 4956 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
23:51:46.0143 4956 umbus - ok
23:51:46.0274 4956 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
23:51:46.0317 4956 UmPass - ok
23:51:46.0454 4956 upperdev (4e93c8496359e97830c75ac36393654d) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
23:51:46.0516 4956 upperdev - ok
23:51:46.0627 4956 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
23:51:46.0666 4956 usbccgp - ok
23:51:46.0799 4956 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
23:51:46.0854 4956 usbcir - ok
23:51:46.0961 4956 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
23:51:46.0994 4956 usbehci - ok
23:51:47.0125 4956 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
23:51:47.0172 4956 usbhub - ok
23:51:47.0288 4956 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
23:51:47.0304 4956 usbohci - ok
23:51:47.0402 4956 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
23:51:47.0434 4956 usbprint - ok
23:51:47.0541 4956 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
23:51:47.0597 4956 usbscan - ok
23:51:47.0748 4956 usbser (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\drivers\usbser.sys
23:51:47.0796 4956 usbser - ok
23:51:47.0940 4956 UsbserFilt (8844cb19a37b65e27049d4a7786726a9) C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
23:51:47.0981 4956 UsbserFilt - ok
23:51:48.0104 4956 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
23:51:48.0168 4956 USBSTOR - ok
23:51:48.0270 4956 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
23:51:48.0339 4956 usbuhci - ok
23:51:48.0504 4956 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
23:51:48.0554 4956 usbvideo - ok
23:51:48.0693 4956 usb_rndisx (70d05ee263568a742d14e1876df80532) C:\Windows\system32\DRIVERS\usb8023x.sys
23:51:48.0743 4956 usb_rndisx - ok
23:51:48.0889 4956 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
23:51:48.0904 4956 vdrvroot - ok
23:51:49.0033 4956 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
23:51:49.0082 4956 vga - ok
23:51:49.0196 4956 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
23:51:49.0257 4956 VgaSave - ok
23:51:49.0385 4956 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
23:51:49.0406 4956 vhdmp - ok
23:51:49.0533 4956 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
23:51:49.0547 4956 viaide - ok
23:51:49.0665 4956 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
23:51:49.0684 4956 volmgr - ok
23:51:49.0804 4956 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
23:51:49.0833 4956 volmgrx - ok
23:51:49.0960 4956 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
23:51:49.0979 4956 volsnap - ok
23:51:50.0115 4956 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
23:51:50.0147 4956 vsmraid - ok
23:51:50.0264 4956 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
23:51:50.0319 4956 vwifibus - ok
23:51:50.0469 4956 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
23:51:50.0523 4956 vwififlt - ok
23:51:50.0680 4956 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
23:51:50.0725 4956 vwifimp - ok
23:51:50.0845 4956 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
23:51:50.0888 4956 WacomPen - ok
23:51:51.0030 4956 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
23:51:51.0119 4956 WANARP - ok
23:51:51.0124 4956 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
23:51:51.0163 4956 Wanarpv6 - ok
23:51:51.0312 4956 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
23:51:51.0328 4956 Wd - ok
23:51:51.0438 4956 WDC_SAM (a3d04ebf5227886029b4532f20d026f7) C:\Windows\system32\DRIVERS\wdcsam64.sys
23:51:51.0480 4956 WDC_SAM - ok
23:51:51.0603 4956 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
23:51:51.0628 4956 Wdf01000 - ok
23:51:51.0799 4956 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
23:51:51.0855 4956 WfpLwf - ok
23:51:51.0967 4956 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
23:51:51.0983 4956 WIMMount - ok
23:51:52.0204 4956 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
23:51:52.0259 4956 WinUsb - ok
23:51:52.0395 4956 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
23:51:52.0438 4956 WmiAcpi - ok
23:51:52.0586 4956 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
23:51:52.0661 4956 ws2ifsl - ok
23:51:52.0786 4956 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
23:51:52.0835 4956 WSDPrintDevice - ok
23:51:52.0983 4956 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
23:51:53.0035 4956 WudfPf - ok
23:51:53.0155 4956 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
23:51:53.0206 4956 WUDFRd - ok
23:51:53.0384 4956 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
23:51:54.0325 4956 \Device\Harddisk0\DR0 - ok
23:51:54.0353 4956 Boot (0x1200) (c243e4f99b0640b477310b6bb910309e) \Device\Harddisk0\DR0\Partition0
23:51:54.0355 4956 \Device\Harddisk0\DR0\Partition0 - ok
23:51:54.0384 4956 Boot (0x1200) (cce3921483ecd5c67bd9dc6cff575c04) \Device\Harddisk0\DR0\Partition1
23:51:54.0385 4956 \Device\Harddisk0\DR0\Partition1 - ok
23:51:54.0387 4956 ============================================================
23:51:54.0387 4956 Scan finished
23:51:54.0387 4956 ============================================================
23:51:54.0401 4568 Detected object count: 2
23:51:54.0401 4568 Actual detected object count: 2
23:52:19.0054 4568 ATE_PROCMON ( UnsignedFile.Multi.Generic ) - skipped by user
23:52:19.0054 4568 ATE_PROCMON ( UnsignedFile.Multi.Generic ) - User select action: Skip
23:52:19.0057 4568 sptd ( LockedFile.Multi.Generic ) - skipped by user
23:52:19.0057 4568 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Mám tedy dát ty dve detekce odstranit? protoze to je nejaky sptd proces a ma si myslim neco spolecneho s virtualni mechanikou?daemon napr.?tak jestli tomu neuskodim...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o shlédnutí logu

#10 Příspěvek od Rudy »

Odinstalujte SaemonTools a Antitrojan Elite. Pak udělejte nový sken.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Re: Prosím o shlédnutí logu

#11 Příspěvek od freeacer »

NO takze jsem odinstaloval elite plus daemon tools...samozrejme v programy a funkce uz daemon tools moznost neni,jelikoz trojan silent manager install infikoval jeho odinstalacni soubor uninstall,kam se predevcirem nakopiroval pri cisteni programem elite a ten ho vymazal a takhle vlastne elite nasel 35 detekci z toho 14 vycistil(tri dny zpatky) a stale by pokracoval dal kdybych ho neukoncil,takze jsem tomu mozna i prihorsil,protoze se timpadem rozlezl dal.tak jsem najel do start nabidky dal odinstalovat primo v programy-daemon tools...to se povedlo,nejspis...pak jsem nasel ve spravci zarizeni driver sptd nepodporujici plug play a odstranil ho.ted restartuju...a spoustim scan opet...

freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Re: Prosím o shlédnutí logu

#12 Příspěvek od freeacer »

...screen pred testem
Přílohy
screen
screen
sptd.jpg (128.44 KiB) Zobrazeno 1615 x

freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Re: Prosím o shlédnutí logu

#13 Příspěvek od freeacer »

hmm....takze stejny screen bych ted poslal i po testu...stale je tam sptd...


P.s.:dal jsem vymazat ne dat do karanteny,a ted to najednou procistilo 3 threads a primo ten program chce restart...takze nejaka zmena...uvidime...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o shlédnutí logu

#14 Příspěvek od Rudy »

Sptd je ovladač daemon tools. DT je sice svinstvo v PC (chová se jako rootkit), ale nepovažuje se za virus.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

freeacer
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 led 2012 17:39

Re: Prosím o shlédnutí logu

#15 Příspěvek od freeacer »

takze ted to vypada ze je to ciste....sptd byl odstranen kdyz jsem dal volbu delete a ne dat do karanteny...takze co ted?mam zkusit aviru?vapada to ale ze vir napachal dost skody...zatim sice neznatelne,ale myslim ze ze spravce programy a funkce zmizelo par programu,ktere jsou samozrejme instalovany...takze jejich odinstalacni soubory byly nejspis napadeny a elite je natvrdo odstranil....jako velky problem to zas nevidim,ale stejne...
Přílohy
screen
screen
sptd.jpg (167.64 KiB) Zobrazeno 1614 x

Odpovědět