Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Virus(Trojský kůň) Nejde lěčit ani odstranit !

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
WiZz_Danny
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 28 úno 2012 14:20

Virus(Trojský kůň) Nejde lěčit ani odstranit !

#1 Příspěvek od WiZz_Danny »

Dobrý den, mám v počítači infiltraci Trojský kůň a nejde vyléčit. Ani nevím jak ho smazat ... Toto mi to píše při kontrole ESETem NODem32 Smart sec. 4 : Operační paměť » C:\Windows\system32\svchost.exe - varianta infiltrace Win32/Agent.OBA trojský kůň - nelze léčit ! Předem děkuji za pomoc

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Stahnete MBRScan http://eric71.geekstogo.com/tools/MbrScan.exe
  • Ulozte nejlepe na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na MBRScan pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Report
  • Po chvilce se objevi log do souboru MBRScan.txt, ten sem vlozte
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte
:arrow: Dejte oba logy (log.txt i info.txt) z RSITu http://forum.viry.cz/viewtopic.php?f=13&t=105895
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

WiZz_Danny
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 28 úno 2012 14:20

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#3 Příspěvek od WiZz_Danny »

Hm,ale klikl jsem na ten odkaz a napsalo to Tento soubor by mol poškodit váš počítač ...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#4 Příspěvek od vyosek »

Ano, jelikoz je to exe soubor a to bude hlasit u kazdeho...zarucuji, ze zavirovany neni...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

WiZz_Danny
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 28 úno 2012 14:20

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#5 Příspěvek od WiZz_Danny »

Kód: Vybrat vše

MBRScan v1.1.1

OS             : Windows 7  (32 bit)
PROCESSOR      : x86 Family 15 Model 67 Stepping 3, AuthenticAMD
BOOT           : Normal Boot
DATE           : 2012/02/28 (ISO 8601) at 16:11:36
________________________________________________________________________________

DISK           : Device\Harddisk0\DR0 __WDC WD32 00AAKS-00VYA (12.0)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : YES
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

Device\Harddisk0\DR0	298.0 Go  [Fixed] ==> 7 MBR Code .

MBR_MD5   : 95A62EA638E6A833E760FE9584AAA0C2
MBR_SHA1  : 7968B3AC88231CE6D13EAEA9A4289F8B5D8BE5FC

Device\Harddisk0\Partition1	100.0 Mo  	0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2	97.56 Go  	0x07 NTFS / HPFS
Device\Harddisk0\Partition3	200.3 Go  	0x07 NTFS / HPFS
________________________________________________________________________________

############################### Additional scan ################################

DRIVER  : C:\Windows\System32\Drivers\spuc.sys => Invisible on the disk
ADDRESS : 0x88E24000
SIZE    : 972.0 Ko

DRIVER  : C:\Windows\System32\Drivers\dump_diskdump.sys => Invisible on the disk
ADDRESS : 0x9019D000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\System32\Drivers\dump_nvstor.sys => Invisible on the disk
ADDRESS : 0x901A7000
SIZE    : 148.0 Ko

DRIVER  : C:\Windows\System32\Drivers\dump_dumpfve.sys => Invisible on the disk
ADDRESS : 0x901CC000
SIZE    : 68.0 Ko

BCD EmsSettings {0CE4991B-E6B3-4B16-B23C-5E0D9250E5D9} => BcdLibraryBoolean_EmsEnabled (16000020)

SystemStartOptions :  NOEXECUTE=OPTIN

________________________________________________________________________________

_______MBR   \Device\Harddisk0\DR0  

0x00000000   33 C0 8E D0 BC 00 7C 8E C0 8E D8 BE 00 7C BF 00   3À.м.|.À.ؾ.|¿.
0x00000010   06 B9 00 02 FC F3 A4 50 68 1C 06 CB FB B9 04 00   .¹..üó¤Ph..Ëû¹..
0x00000020   BD BE 07 80 7E 00 00 7C 0B 0F 85 0E 01 83 C5 10   ½¾..~..|......Å.
0x00000030   E2 F1 CD 18 88 56 00 55 C6 46 11 05 C6 46 10 00   âñÍ..V.UÆF..ÆF..
0x00000040   B4 41 BB AA 55 CD 13 5D 72 0F 81 FB 55 AA 75 09   ´A»ªUÍ.]r..ûUªu.
0x00000050   F7 C1 01 00 74 03 FE 46 10 66 60 80 7E 10 00 74   ÷Á..t.þF.f`.~..t
0x00000060   26 66 68 00 00 00 00 66 FF 76 08 68 00 00 68 00   &fh....f.v.h..h.
0x00000070   7C 68 01 00 68 10 00 B4 42 8A 56 00 8B F4 CD 13   |h..h..´B.V..ôÍ.
0x00000080   9F 83 C4 10 9E EB 14 B8 01 02 BB 00 7C 8A 56 00   ..Ä..ë.¸..».|.V.
0x00000090   8A 76 01 8A 4E 02 8A 6E 03 CD 13 66 61 73 1C FE   .v..N..n.Í.fas.þ
0x000000A0   4E 11 75 0C 80 7E 00 80 0F 84 8A 00 B2 80 EB 84   N.u..~......².ë.
0x000000B0   55 32 E4 8A 56 00 CD 13 5D EB 9E 81 3E FE 7D 55   U2ä.V.Í.]ë..>þ}U
0x000000C0   AA 75 6E FF 76 00 E8 8D 00 75 17 FA B0 D1 E6 64   ªun.v.è..u.ú°Ñæd
0x000000D0   E8 83 00 B0 DF E6 60 E8 7C 00 B0 FF E6 64 E8 75   è..°ßæ`è|.°.ædèu
0x000000E0   00 FB B8 00 BB CD 1A 66 23 C0 75 3B 66 81 FB 54   .û¸.»Í.f#Àu;f.ûT
0x000000F0   43 50 41 75 32 81 F9 02 01 72 2C 66 68 07 BB 00   CPAu2.ù..r,fh.».
0x00000100   00 66 68 00 02 00 00 66 68 08 00 00 00 66 53 66   .fh....fh....fSf
0x00000110   53 66 55 66 68 00 00 00 00 66 68 00 7C 00 00 66   SfUfh....fh.|..f
0x00000120   61 68 00 00 07 CD 1A 5A 32 F6 EA 00 7C 00 00 CD   ah...Í.Z2öê.|..Í
0x00000130   18 A0 B7 07 EB 08 A0 B6 07 EB 03 A0 B5 07 32 E4   ..·.ë..¶.ë..µ.2ä
0x00000140   05 00 07 8B F0 AC 3C 00 74 09 BB 07 00 B4 0E CD   ....ð¬<.t.»..´.Í
0x00000150   10 EB F2 F4 EB FD 2B C9 E4 64 EB 00 24 02 E0 F8   .ëòôëý+Éädë.$.àø
0x00000160   24 02 C3 49 6E 76 61 6C 69 64 20 70 61 72 74 69   $.ÃInvalid parti
0x00000170   74 69 6F 6E 20 74 61 62 6C 65 00 45 72 72 6F 72   tion table.Error
0x00000180   20 6C 6F 61 64 69 6E 67 20 6F 70 65 72 61 74 69    loading operati
0x00000190   6E 67 20 73 79 73 74 65 6D 00 4D 69 73 73 69 6E   ng system.Missin
0x000001A0   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x000001B0   65 6D 00 00 00 63 7B 9A D4 FA D4 FA 00 00 80 20   em...c{.ÔúÔú... 
0x000001C0   21 00 07 A3 13 0D 00 08 00 00 00 20 03 00 00 A3   !..£....... ...£
0x000001D0   14 0D 07 EF FF FF 00 28 03 00 00 E0 31 0C 00 EF   ...ï...(...à1..ï
0x000001E0   FF FF 07 EF FF FF 00 08 35 0C 00 C8 09 19 00 00   ...ï....5..È....
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#6 Příspěvek od vyosek »

OK, jeste poprosim o TDSSKiller a RSIT
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

WiZz_Danny
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 28 úno 2012 14:20

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#7 Příspěvek od WiZz_Danny »

16:14:00.0090 5876 TDSS rootkit removing tool 2.7.15.0 Feb 27 2012 12:59:02
16:14:00.0290 5876 ============================================================
16:14:00.0290 5876 Current date / time: 2012/02/28 16:14:00.0290
16:14:00.0290 5876 SystemInfo:
16:14:00.0290 5876
16:14:00.0290 5876 OS Version: 6.1.7600 ServicePack: 0.0
16:14:00.0290 5876 Product type: Workstation
16:14:00.0290 5876 ComputerName: HONZA-PC
16:14:00.0290 5876 UserName: Honza
16:14:00.0290 5876 Windows directory: C:\Windows
16:14:00.0290 5876 System windows directory: C:\Windows
16:14:00.0290 5876 Processor architecture: Intel x86
16:14:00.0290 5876 Number of processors: 2
16:14:00.0290 5876 Page size: 0x1000
16:14:00.0290 5876 Boot type: Normal boot
16:14:00.0290 5876 ============================================================
16:14:01.0550 5876 Drive \Device\Harddisk0\DR0 - Size: 0x4A7DB55400 (297.96 Gb), SectorSize: 0x200, Cylinders: 0xA16F, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050
16:14:01.0560 5876 \Device\Harddisk0\DR0:
16:14:01.0560 5876 MBR used
16:14:01.0560 5876 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
16:14:01.0560 5876 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xC31E000
16:14:01.0560 5876 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC350800, BlocksNum 0x1909C800
16:14:01.0610 5876 Initialize success
16:14:01.0610 5876 ============================================================
16:14:26.0830 4440 ============================================================
16:14:26.0830 4440 Scan started
16:14:26.0830 4440 Mode: Manual; SigCheck; TDLFS;
16:14:26.0830 4440 ============================================================
16:14:28.0970 4440 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
16:14:29.0060 4440 1394ohci - ok
16:14:29.0110 4440 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
16:14:29.0120 4440 ACPI - ok
16:14:29.0130 4440 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
16:14:29.0180 4440 AcpiPmi - ok
16:14:29.0200 4440 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
16:14:29.0250 4440 adp94xx - ok
16:14:29.0380 4440 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
16:14:29.0450 4440 adpahci - ok
16:14:29.0460 4440 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
16:14:29.0500 4440 adpu320 - ok
16:14:29.0560 4440 AFD (0db7a48388d54d154ebec120461a0fcd) C:\Windows\system32\drivers\afd.sys
16:14:29.0600 4440 AFD - ok
16:14:29.0620 4440 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
16:14:29.0640 4440 agp440 - ok
16:14:29.0650 4440 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
16:14:29.0670 4440 aic78xx - ok
16:14:29.0690 4440 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
16:14:29.0710 4440 aliide - ok
16:14:29.0730 4440 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
16:14:29.0750 4440 amdagp - ok
16:14:29.0750 4440 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
16:14:29.0780 4440 amdide - ok
16:14:29.0790 4440 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
16:14:29.0820 4440 AmdK8 - ok
16:14:29.0830 4440 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
16:14:29.0880 4440 AmdPPM - ok
16:14:29.0900 4440 amdsata (19ce906b4cdc11fc4fef5745f33a63b6) C:\Windows\system32\drivers\amdsata.sys
16:14:29.0930 4440 amdsata - ok
16:14:29.0950 4440 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
16:14:29.0980 4440 amdsbs - ok
16:14:30.0000 4440 amdxata (869e67d66be326a5a9159fba8746fa70) C:\Windows\system32\drivers\amdxata.sys
16:14:30.0010 4440 amdxata - ok
16:14:30.0020 4440 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
16:14:30.0050 4440 AppID - ok
16:14:30.0070 4440 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
16:14:30.0090 4440 arc - ok
16:14:30.0100 4440 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
16:14:30.0130 4440 arcsas - ok
16:14:30.0160 4440 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
16:14:30.0290 4440 AsyncMac - ok
16:14:30.0350 4440 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
16:14:30.0360 4440 atapi - ok
16:14:30.0400 4440 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
16:14:30.0460 4440 b06bdrv - ok
16:14:30.0480 4440 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
16:14:30.0530 4440 b57nd60x - ok
16:14:30.0570 4440 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
16:14:30.0600 4440 Beep - ok
16:14:30.0620 4440 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
16:14:30.0640 4440 blbdrive - ok
16:14:30.0680 4440 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys
16:14:30.0710 4440 bowser - ok
16:14:30.0730 4440 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
16:14:30.0750 4440 BrFiltLo - ok
16:14:30.0770 4440 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
16:14:30.0810 4440 BrFiltUp - ok
16:14:30.0830 4440 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
16:14:30.0860 4440 Brserid - ok
16:14:30.0880 4440 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
16:14:30.0900 4440 BrSerWdm - ok
16:14:30.0920 4440 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
16:14:30.0950 4440 BrUsbMdm - ok
16:14:30.0970 4440 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
16:14:30.0990 4440 BrUsbSer - ok
16:14:31.0010 4440 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
16:14:31.0040 4440 BTHMODEM - ok
16:14:31.0080 4440 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
16:14:31.0120 4440 cdfs - ok
16:14:31.0140 4440 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
16:14:31.0150 4440 cdrom - ok
16:14:31.0170 4440 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
16:14:31.0190 4440 circlass - ok
16:14:31.0220 4440 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
16:14:31.0240 4440 CLFS - ok
16:14:31.0260 4440 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
16:14:31.0280 4440 CmBatt - ok
16:14:31.0290 4440 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
16:14:31.0310 4440 cmdide - ok
16:14:31.0350 4440 CNG (36c252e474b2ffa0f0fbbff20d92a640) C:\Windows\system32\Drivers\cng.sys
16:14:31.0370 4440 CNG - ok
16:14:31.0380 4440 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
16:14:31.0400 4440 Compbatt - ok
16:14:31.0420 4440 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
16:14:31.0440 4440 CompositeBus - ok
16:14:31.0470 4440 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
16:14:31.0490 4440 crcdisk - ok
16:14:31.0540 4440 DfsC (83d1ecea8faae75604c0fa49ac7ad996) C:\Windows\system32\Drivers\dfsc.sys
16:14:31.0570 4440 DfsC - ok
16:14:31.0600 4440 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
16:14:31.0630 4440 discache - ok
16:14:31.0670 4440 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
16:14:31.0680 4440 Disk - ok
16:14:31.0710 4440 Dot4 (b5e479eb83707dd698f66953e922042c) C:\Windows\system32\DRIVERS\Dot4.sys
16:14:31.0750 4440 Dot4 - ok
16:14:31.0770 4440 Dot4Print (c25fea07a8e7767e8b89ab96a3b96519) C:\Windows\system32\DRIVERS\Dot4Prt.sys
16:14:31.0800 4440 Dot4Print - ok
16:14:31.0830 4440 dot4usb (cf491ff38d62143203c065260567e2f7) C:\Windows\system32\DRIVERS\dot4usb.sys
16:14:31.0870 4440 dot4usb - ok
16:14:31.0900 4440 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
16:14:31.0960 4440 drmkaud - ok
16:14:32.0010 4440 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\Windows\System32\drivers\dxgkrnl.sys
16:14:32.0080 4440 DXGKrnl - ok
16:14:32.0100 4440 EagleNT - ok
16:14:32.0110 4440 EagleXNt - ok
16:14:32.0140 4440 eamonm (73ce42907cf42bfb91bcd27fe7c7a7af) C:\Windows\system32\DRIVERS\eamonm.sys
16:14:32.0170 4440 eamonm - ok
16:14:32.0250 4440 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
16:14:32.0390 4440 ebdrv - ok
16:14:32.0440 4440 ehdrv (7d300a43a7bd8769e0f901bf9e1ae367) C:\Windows\system32\DRIVERS\ehdrv.sys
16:14:32.0460 4440 ehdrv - ok
16:14:32.0510 4440 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
16:14:32.0560 4440 elxstor - ok
16:14:32.0590 4440 epfw (15bfe00f030ea20955117bb0677e9668) C:\Windows\system32\DRIVERS\epfw.sys
16:14:32.0600 4440 epfw - ok
16:14:32.0620 4440 Epfwndis (52310e0e603d7da79ecca7d764937a91) C:\Windows\system32\DRIVERS\Epfwndis.sys
16:14:32.0630 4440 Epfwndis - ok
16:14:32.0650 4440 epfwwfp (235250a79cf1e16a5a42407cfe3f6a4c) C:\Windows\system32\DRIVERS\epfwwfp.sys
16:14:32.0660 4440 epfwwfp - ok
16:14:32.0670 4440 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
16:14:32.0700 4440 ErrDev - ok
16:14:32.0730 4440 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
16:14:32.0790 4440 exfat - ok
16:14:32.0820 4440 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
16:14:32.0880 4440 fastfat - ok
16:14:32.0900 4440 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
16:14:32.0950 4440 fdc - ok
16:14:32.0990 4440 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
16:14:33.0000 4440 FileInfo - ok
16:14:33.0020 4440 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
16:14:33.0060 4440 Filetrace - ok
16:14:33.0080 4440 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
16:14:33.0120 4440 flpydisk - ok
16:14:33.0140 4440 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
16:14:33.0170 4440 FltMgr - ok
16:14:33.0180 4440 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
16:14:33.0210 4440 FsDepends - ok
16:14:33.0240 4440 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
16:14:33.0260 4440 Fs_Rec - ok
16:14:33.0290 4440 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
16:14:33.0300 4440 fvevol - ok
16:14:33.0320 4440 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
16:14:33.0340 4440 gagp30kx - ok
16:14:33.0410 4440 hamachi (7929a161f9951d173ca9900fe7067391) C:\Windows\system32\DRIVERS\hamachi.sys
16:14:33.0420 4440 hamachi - ok
16:14:33.0440 4440 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
16:14:33.0470 4440 hcw85cir - ok
16:14:33.0500 4440 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
16:14:33.0530 4440 HdAudAddService - ok
16:14:33.0550 4440 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:14:33.0570 4440 HDAudBus - ok
16:14:33.0590 4440 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
16:14:33.0620 4440 HidBatt - ok
16:14:33.0640 4440 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
16:14:33.0680 4440 HidBth - ok
16:14:33.0690 4440 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
16:14:33.0730 4440 HidIr - ok
16:14:33.0750 4440 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
16:14:33.0760 4440 HidUsb - ok
16:14:33.0780 4440 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
16:14:33.0810 4440 HpSAMD - ok
16:14:33.0840 4440 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
16:14:33.0890 4440 HTTP - ok
16:14:33.0900 4440 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
16:14:33.0910 4440 hwpolicy - ok
16:14:33.0920 4440 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
16:14:33.0950 4440 i8042prt - ok
16:14:34.0000 4440 iaStorV (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\Windows\system32\drivers\iaStorV.sys
16:14:34.0030 4440 iaStorV - ok
16:14:34.0050 4440 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
16:14:34.0080 4440 iirsp - ok
16:14:34.0100 4440 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
16:14:34.0120 4440 intelide - ok
16:14:34.0140 4440 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
16:14:34.0160 4440 intelppm - ok
16:14:34.0180 4440 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:14:34.0220 4440 IpFilterDriver - ok
16:14:34.0230 4440 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
16:14:34.0270 4440 IPMIDRV - ok
16:14:34.0300 4440 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
16:14:34.0410 4440 IPNAT - ok
16:14:34.0440 4440 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
16:14:34.0500 4440 IRENUM - ok
16:14:34.0520 4440 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
16:14:34.0560 4440 isapnp - ok
16:14:34.0580 4440 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
16:14:34.0610 4440 iScsiPrt - ok
16:14:34.0640 4440 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
16:14:34.0660 4440 kbdclass - ok
16:14:34.0670 4440 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
16:14:34.0680 4440 kbdhid - ok
16:14:34.0730 4440 KSecDD (0263364acb9c834ace52fb85c2c064ec) C:\Windows\system32\Drivers\ksecdd.sys
16:14:34.0740 4440 KSecDD - ok
16:14:34.0750 4440 KSecPkg (27391db553be2a4e2b0adeea2873b2af) C:\Windows\system32\Drivers\ksecpkg.sys
16:14:34.0760 4440 KSecPkg - ok
16:14:34.0800 4440 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
16:14:34.0830 4440 lltdio - ok
16:14:34.0850 4440 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
16:14:34.0880 4440 LSI_FC - ok
16:14:34.0890 4440 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
16:14:34.0910 4440 LSI_SAS - ok
16:14:34.0940 4440 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
16:14:34.0970 4440 LSI_SAS2 - ok
16:14:34.0980 4440 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
16:14:35.0000 4440 LSI_SCSI - ok
16:14:35.0030 4440 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
16:14:35.0070 4440 luafv - ok
16:14:35.0090 4440 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
16:14:35.0120 4440 megasas - ok
16:14:35.0140 4440 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
16:14:35.0170 4440 MegaSR - ok
16:14:35.0200 4440 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
16:14:35.0250 4440 Modem - ok
16:14:35.0270 4440 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
16:14:35.0290 4440 monitor - ok
16:14:35.0310 4440 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
16:14:35.0320 4440 mouclass - ok
16:14:35.0330 4440 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
16:14:35.0360 4440 mouhid - ok
16:14:35.0380 4440 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
16:14:35.0380 4440 mountmgr - ok
16:14:35.0400 4440 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
16:14:35.0420 4440 mpio - ok
16:14:35.0470 4440 MpKsl00215c4f - ok
16:14:35.0490 4440 MpKsl0215a254 - ok
16:14:35.0510 4440 MpKsl0554df86 - ok
16:14:35.0520 4440 MpKsl08b0b11e - ok
16:14:35.0550 4440 MpKsl145ef1a9 - ok
16:14:35.0560 4440 MpKsl1a341e34 - ok
16:14:35.0580 4440 MpKsl1deb89a6 - ok
16:14:35.0590 4440 MpKsl1e5e5d8a - ok
16:14:35.0590 4440 MpKsl1e983b74 - ok
16:14:35.0600 4440 MpKsl20389781 - ok
16:14:35.0610 4440 MpKsl28e5964c - ok
16:14:35.0640 4440 MpKsl37fce4db - ok
16:14:35.0640 4440 MpKsl38095993 - ok
16:14:35.0650 4440 MpKsl3d588231 - ok
16:14:35.0660 4440 MpKsl45ca4a35 - ok
16:14:35.0660 4440 MpKsl515b2aac - ok
16:14:35.0680 4440 MpKsl567b2b1a - ok
16:14:35.0680 4440 MpKsl57648952 - ok
16:14:35.0690 4440 MpKsl5feb50df - ok
16:14:35.0690 4440 MpKsl610bcfd5 - ok
16:14:35.0700 4440 MpKsl670667d4 - ok
16:14:35.0710 4440 MpKsl67601bc0 - ok
16:14:35.0710 4440 MpKsl6bb9fc37 - ok
16:14:35.0720 4440 MpKsl732f15f3 - ok
16:14:35.0720 4440 MpKsl789558b2 - ok
16:14:35.0730 4440 MpKsl7a79b034 - ok
16:14:35.0750 4440 MpKsl8160ccac - ok
16:14:35.0750 4440 MpKsl83c8ff75 - ok
16:14:35.0770 4440 MpKsl84d66800 - ok
16:14:35.0770 4440 MpKsl8ce664a4 - ok
16:14:35.0780 4440 MpKsl949cf6a0 - ok
16:14:35.0780 4440 MpKsl96c1125e - ok
16:14:35.0790 4440 MpKsl97201453 - ok
16:14:35.0800 4440 MpKsla49b136b - ok
16:14:35.0800 4440 MpKslaa1b128a - ok
16:14:35.0810 4440 MpKslaaf5b1ba - ok
16:14:35.0820 4440 MpKslaaf81749 - ok
16:14:35.0820 4440 MpKslc89bcdc9 - ok
16:14:35.0830 4440 MpKslcb7aa47c - ok
16:14:35.0830 4440 MpKsld0c0ae7a - ok
16:14:35.0840 4440 MpKsld22e3206 - ok
16:14:35.0840 4440 MpKsld8c18ac4 - ok
16:14:35.0850 4440 MpKsle0026f1f - ok
16:14:35.0860 4440 MpKsle2fe5f59 - ok
16:14:35.0860 4440 MpKsle6aba10b - ok
16:14:35.0870 4440 MpKslebc79c23 - ok
16:14:35.0870 4440 MpKslf7f37787 - ok
16:14:35.0880 4440 MpKslff73b36c - ok
16:14:35.0900 4440 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
16:14:35.0950 4440 mpsdrv - ok
16:14:35.0970 4440 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
16:14:36.0010 4440 MRxDAV - ok
16:14:36.0040 4440 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:14:36.0070 4440 mrxsmb - ok
16:14:36.0100 4440 mrxsmb10 (f965c3ab2b2ae5c378f4562486e35051) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:14:36.0110 4440 mrxsmb10 - ok
16:14:36.0140 4440 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:14:36.0150 4440 mrxsmb20 - ok
16:14:36.0170 4440 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
16:14:36.0190 4440 msahci - ok
16:14:36.0200 4440 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
16:14:36.0220 4440 msdsm - ok
16:14:36.0240 4440 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
16:14:36.0280 4440 Msfs - ok
16:14:36.0290 4440 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
16:14:36.0330 4440 mshidkmdf - ok
16:14:36.0340 4440 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
16:14:36.0360 4440 msisadrv - ok
16:14:36.0380 4440 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
16:14:36.0430 4440 MSKSSRV - ok
16:14:36.0450 4440 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
16:14:36.0490 4440 MSPCLOCK - ok
16:14:36.0500 4440 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
16:14:36.0530 4440 MSPQM - ok
16:14:36.0560 4440 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
16:14:36.0570 4440 MsRPC - ok
16:14:36.0590 4440 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
16:14:36.0590 4440 mssmbios - ok
16:14:36.0600 4440 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
16:14:36.0650 4440 MSTEE - ok
16:14:36.0660 4440 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
16:14:36.0700 4440 MTConfig - ok
16:14:36.0710 4440 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
16:14:36.0720 4440 Mup - ok
16:14:36.0760 4440 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
16:14:36.0790 4440 NativeWifiP - ok
16:14:36.0830 4440 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
16:14:36.0860 4440 NDIS - ok
16:14:36.0880 4440 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
16:14:36.0920 4440 NdisCap - ok
16:14:36.0940 4440 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
16:14:36.0960 4440 NdisTapi - ok
16:14:36.0980 4440 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
16:14:37.0000 4440 Ndisuio - ok
16:14:37.0020 4440 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
16:14:37.0050 4440 NdisWan - ok
16:14:37.0070 4440 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
16:14:37.0100 4440 NDProxy - ok
16:14:37.0130 4440 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
16:14:37.0160 4440 NetBIOS - ok
16:14:37.0190 4440 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
16:14:37.0220 4440 NetBT - ok
16:14:37.0280 4440 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
16:14:37.0310 4440 nfrd960 - ok
16:14:37.0340 4440 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
16:14:37.0370 4440 Npfs - ok
16:14:37.0390 4440 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
16:14:37.0420 4440 nsiproxy - ok
16:14:37.0470 4440 Ntfs (187002ce05693c306f43c873f821381f) C:\Windows\system32\drivers\Ntfs.sys
16:14:37.0510 4440 Ntfs - ok
16:14:37.0530 4440 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
16:14:37.0560 4440 Null - ok
16:14:37.0590 4440 NVENETFD (b5e37e31c053bc9950455a257526514b) C:\Windows\system32\DRIVERS\nvm62x32.sys
16:14:37.0630 4440 NVENETFD - ok
16:14:37.0890 4440 nvlddmkm (6ef47521dce982602a25afb41dd13d4f) C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:14:38.0170 4440 nvlddmkm - ok
16:14:38.0200 4440 NVNET (1de923088878b495cd4219e47ba34eb8) C:\Windows\system32\DRIVERS\nvmf6232.sys
16:14:38.0220 4440 NVNET - ok
16:14:38.0250 4440 nvraid (f1b0bed906f97e16f6d0c3629d2f21c6) C:\Windows\system32\drivers\nvraid.sys
16:14:38.0270 4440 nvraid - ok
16:14:38.0290 4440 nvstor (4520b63899e867f354ee012d34e11536) C:\Windows\system32\drivers\nvstor.sys
16:14:38.0290 4440 nvstor - ok
16:14:38.0310 4440 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
16:14:38.0330 4440 nv_agp - ok
16:14:38.0370 4440 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
16:14:38.0390 4440 ohci1394 - ok
16:14:38.0420 4440 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
16:14:38.0440 4440 Parport - ok
16:14:38.0450 4440 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
16:14:38.0460 4440 partmgr - ok
16:14:38.0470 4440 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
16:14:38.0490 4440 Parvdm - ok
16:14:38.0510 4440 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
16:14:38.0520 4440 pci - ok
16:14:38.0540 4440 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
16:14:38.0550 4440 pciide - ok
16:14:38.0560 4440 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
16:14:38.0600 4440 pcmcia - ok
16:14:38.0620 4440 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
16:14:38.0640 4440 pcw - ok
16:14:38.0670 4440 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
16:14:38.0720 4440 PEAUTH - ok
16:14:38.0790 4440 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
16:14:38.0830 4440 PptpMiniport - ok
16:14:38.0850 4440 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
16:14:38.0880 4440 Processor - ok
16:14:38.0910 4440 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
16:14:38.0940 4440 Psched - ok
16:14:38.0980 4440 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
16:14:39.0040 4440 ql2300 - ok
16:14:39.0060 4440 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
16:14:39.0080 4440 ql40xx - ok
16:14:39.0100 4440 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
16:14:39.0130 4440 QWAVEdrv - ok
16:14:39.0150 4440 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
16:14:39.0180 4440 RasAcd - ok
16:14:39.0200 4440 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
16:14:39.0230 4440 RasAgileVpn - ok
16:14:39.0250 4440 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:14:39.0290 4440 Rasl2tp - ok
16:14:39.0300 4440 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
16:14:39.0330 4440 RasPppoe - ok
16:14:39.0340 4440 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
16:14:39.0380 4440 RasSstp - ok
16:14:39.0460 4440 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
16:14:39.0550 4440 rdbss - ok
16:14:39.0590 4440 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
16:14:39.0620 4440 rdpbus - ok
16:14:39.0630 4440 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:14:39.0650 4440 RDPCDD - ok
16:14:39.0660 4440 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
16:14:39.0690 4440 RDPENCDD - ok
16:14:39.0710 4440 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
16:14:39.0740 4440 RDPREFMP - ok
16:14:39.0750 4440 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
16:14:39.0810 4440 RDPWD - ok
16:14:39.0830 4440 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
16:14:39.0850 4440 rdyboost - ok
16:14:39.0880 4440 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
16:14:39.0900 4440 rspndr - ok
16:14:39.0950 4440 RTL85n86 (17bb009e31a660b4ccfc061b02de2ef6) C:\Windows\system32\DRIVERS\RTL85n86.sys
16:14:40.0010 4440 RTL85n86 - ok
16:14:40.0020 4440 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
16:14:40.0050 4440 sbp2port - ok
16:14:40.0070 4440 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
16:14:40.0110 4440 scfilter - ok
16:14:40.0120 4440 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
16:14:40.0150 4440 secdrv - ok
16:14:40.0180 4440 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
16:14:40.0200 4440 Serenum - ok
16:14:40.0220 4440 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
16:14:40.0240 4440 Serial - ok
16:14:40.0260 4440 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
16:14:40.0290 4440 sermouse - ok
16:14:40.0330 4440 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
16:14:40.0370 4440 sffdisk - ok
16:14:40.0390 4440 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
16:14:40.0410 4440 sffp_mmc - ok
16:14:40.0430 4440 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\drivers\sffp_sd.sys
16:14:40.0450 4440 sffp_sd - ok
16:14:40.0460 4440 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
16:14:40.0490 4440 sfloppy - ok
16:14:40.0500 4440 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
16:14:40.0530 4440 sisagp - ok
16:14:40.0540 4440 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
16:14:40.0570 4440 SiSRaid2 - ok
16:14:40.0580 4440 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
16:14:40.0610 4440 SiSRaid4 - ok
16:14:40.0630 4440 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
16:14:40.0670 4440 Smb - ok
16:14:40.0700 4440 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
16:14:40.0710 4440 spldr - ok
16:14:40.0750 4440 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
16:14:40.0750 4440 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
16:14:40.0750 4440 sptd ( LockedFile.Multi.Generic ) - warning
16:14:40.0750 4440 sptd - detected LockedFile.Multi.Generic (1)
16:14:40.0790 4440 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\Windows\system32\DRIVERS\srv.sys
16:14:40.0830 4440 srv - ok
16:14:40.0860 4440 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\Windows\system32\DRIVERS\srv2.sys
16:14:40.0890 4440 srv2 - ok
16:14:40.0930 4440 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\Windows\system32\DRIVERS\srvnet.sys
16:14:40.0960 4440 srvnet - ok
16:14:40.0970 4440 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
16:14:40.0990 4440 stexstor - ok
16:14:41.0010 4440 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
16:14:41.0020 4440 swenum - ok
16:14:41.0100 4440 Tcpip (56c198ac82efa622dd93e9e43575f79c) C:\Windows\system32\drivers\tcpip.sys
16:14:41.0180 4440 Tcpip - ok
16:14:41.0210 4440 TCPIP6 (56c198ac82efa622dd93e9e43575f79c) C:\Windows\system32\DRIVERS\tcpip.sys
16:14:41.0250 4440 TCPIP6 - ok
16:14:41.0270 4440 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
16:14:41.0310 4440 tcpipreg - ok
16:14:41.0320 4440 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
16:14:41.0380 4440 TDPIPE - ok
16:14:41.0390 4440 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
16:14:41.0420 4440 TDTCP - ok
16:14:41.0440 4440 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
16:14:41.0470 4440 tdx - ok
16:14:41.0500 4440 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
16:14:41.0510 4440 TermDD - ok
16:14:41.0550 4440 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:14:41.0620 4440 tssecsrv - ok
16:14:41.0640 4440 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
16:14:41.0670 4440 tunnel - ok
16:14:41.0690 4440 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
16:14:41.0710 4440 uagp35 - ok
16:14:41.0730 4440 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
16:14:41.0790 4440 udfs - ok
16:14:41.0820 4440 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
16:14:41.0840 4440 uliagpkx - ok
16:14:41.0860 4440 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
16:14:41.0890 4440 umbus - ok
16:14:41.0900 4440 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
16:14:41.0920 4440 UmPass - ok
16:14:41.0950 4440 usbccgp (c31ae588e403042632dc796cf09e30b0) C:\Windows\system32\DRIVERS\usbccgp.sys
16:14:41.0980 4440 usbccgp - ok
16:14:41.0990 4440 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
16:14:42.0040 4440 usbcir - ok
16:14:42.0060 4440 usbehci (e4c436d914768ce965d5e659ba7eebd8) C:\Windows\system32\DRIVERS\usbehci.sys
16:14:42.0100 4440 usbehci - ok
16:14:42.0130 4440 usbhub (bdcd7156ec37448f08633fd899823620) C:\Windows\system32\DRIVERS\usbhub.sys
16:14:42.0140 4440 usbhub - ok
16:14:42.0170 4440 usbohci (eb2d819a639015253c871cda09d91d58) C:\Windows\system32\DRIVERS\usbohci.sys
16:14:42.0180 4440 usbohci - ok
16:14:42.0200 4440 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
16:14:42.0240 4440 usbprint - ok
16:14:42.0280 4440 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
16:14:42.0350 4440 usbscan - ok
16:14:42.0390 4440 USBSTOR (1c4287739a93594e57e2a9e6a3ed7353) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:14:42.0410 4440 USBSTOR - ok
16:14:42.0430 4440 usbuhci (22480bf4e5a09192e5e30ba4dde79fa4) C:\Windows\system32\drivers\usbuhci.sys
16:14:42.0480 4440 usbuhci - ok
16:14:42.0500 4440 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
16:14:42.0510 4440 vdrvroot - ok
16:14:42.0530 4440 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
16:14:42.0570 4440 vga - ok
16:14:42.0580 4440 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
16:14:42.0610 4440 VgaSave - ok
16:14:42.0630 4440 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
16:14:42.0660 4440 vhdmp - ok
16:14:42.0670 4440 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
16:14:42.0690 4440 viaagp - ok
16:14:42.0710 4440 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
16:14:42.0740 4440 ViaC7 - ok
16:14:42.0760 4440 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
16:14:42.0780 4440 viaide - ok
16:14:42.0800 4440 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
16:14:42.0810 4440 volmgr - ok
16:14:42.0840 4440 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
16:14:42.0850 4440 volmgrx - ok
16:14:42.0870 4440 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
16:14:42.0890 4440 volsnap - ok
16:14:42.0910 4440 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
16:14:42.0930 4440 vsmraid - ok
16:14:42.0950 4440 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
16:14:42.0980 4440 vwifibus - ok
16:14:43.0010 4440 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
16:14:43.0040 4440 WacomPen - ok
16:14:43.0060 4440 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
16:14:43.0090 4440 WANARP - ok
16:14:43.0110 4440 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
16:14:43.0130 4440 Wanarpv6 - ok
16:14:43.0160 4440 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
16:14:43.0180 4440 Wd - ok
16:14:43.0200 4440 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
16:14:43.0220 4440 Wdf01000 - ok
16:14:43.0260 4440 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
16:14:43.0280 4440 WfpLwf - ok
16:14:43.0300 4440 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
16:14:43.0320 4440 WIMMount - ok
16:14:43.0390 4440 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
16:14:43.0440 4440 WinUsb - ok
16:14:43.0470 4440 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
16:14:43.0510 4440 WmiAcpi - ok
16:14:43.0550 4440 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
16:14:43.0600 4440 ws2ifsl - ok
16:14:43.0640 4440 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
16:14:43.0660 4440 WudfPf - ok
16:14:43.0680 4440 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:14:43.0720 4440 WUDFRd - ok
16:14:43.0750 4440 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
16:14:43.0850 4440 \Device\Harddisk0\DR0 - ok
16:14:43.0850 4440 Boot (0x1200) (fc3daf825ce16096a1ba05325a666204) \Device\Harddisk0\DR0\Partition0
16:14:43.0850 4440 \Device\Harddisk0\DR0\Partition0 - ok
16:14:43.0870 4440 Boot (0x1200) (06ebb8c9151a68f95f52bc3faf5c3a1a) \Device\Harddisk0\DR0\Partition1
16:14:43.0870 4440 \Device\Harddisk0\DR0\Partition1 - ok
16:14:43.0890 4440 Boot (0x1200) (16c155ca0b3a780388e22371e0e1df96) \Device\Harddisk0\DR0\Partition2
16:14:43.0890 4440 \Device\Harddisk0\DR0\Partition2 - ok
16:14:43.0890 4440 ============================================================
16:14:43.0890 4440 Scan finished
16:14:43.0890 4440 ============================================================
16:14:43.0910 3900 Detected object count: 1
16:14:43.0910 3900 Actual detected object count: 1
16:15:41.0440 3900 sptd ( LockedFile.Multi.Generic ) - skipped by user
16:15:41.0440 3900 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#8 Příspěvek od vyosek »

Sjupr, ceho jsem se obavat tam neni...ted poprosim o logy z RSIT a pak budem mazat
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

WiZz_Danny
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 28 úno 2012 14:20

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#9 Příspěvek od WiZz_Danny »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Honza at 2012-02-28 16:19:04
Microsoft Windows 7 Home Premium
System drive C: has 3 GB (3%) free of 100 GB
Total RAM: 2048 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:19:13, on 28.2.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Honza\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\BitTorrent\BitTorrent.exe
C:\Users\Public\mdm.exe
C:\Program Files\OSCAR Editor X7\OscarEditor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\Honza\AppData\Local\Akamai\netsession_win.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Honza\Desktop\RSIT.exe
C:\Program Files\trend micro\Honza.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2790392
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: BitTorrentBar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
O3 - Toolbar: CrowdStar Gamebar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [4StoryPrePatch] C:\Program Files\Gameforge4D\4Story_CZ\PrePatch.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ExpressFiles] "C:\Program Files\ExpressFiles\ExpressFiles.exe" -tray
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [EADM] "C:\Program Files\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Honza\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Microsoft Firevall Engine] c:\users\public\mdm.exe
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [MSConfig] "C:\Users\Honza\hywm.exe" /r
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - http://www.battlefieldheroes.com/static ... .127.0.cab
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} (Battlefield Play4Free Updater) - https://battlefield.play4free.com/stati ... 0.66.2.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe

--
End of file - 10129 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
BitTorrentBar Toolbar - C:\Program Files\BitTorrentBar\prxtbBitT.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-02-26 192112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
CrowdStar Gamebar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-01-03 1514152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-01 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - BitTorrentBar Toolbar - C:\Program Files\BitTorrentBar\prxtbBitT.dll [2011-05-09 176936]
{D4027C7F-154A-4066-A1AD-4243D8127440} - CrowdStar Gamebar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-01-03 1514152]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-02-26 192112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe []
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
""= []
"4StoryPrePatch"=C:\Program Files\Gameforge4D\4Story_CZ\PrePatch.exe [2012-02-02 327680]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-08-12 2215064]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"ExpressFiles"=C:\Program Files\ExpressFiles\ExpressFiles.exe [2012-01-07 326776]
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2012-01-03 1391272]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"KPeerNexonEU"=C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe [2011-12-27 438272]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-05-26 15147400]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe /MINIMIZED []
"RGSC"=C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent []
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-11-20 39408]
"EADM"=C:\Program Files\Origin\Origin.exe [2012-01-12 28201096]
"Akamai NetSession Interface"=C:\Users\Honza\AppData\Local\Akamai\netsession_win.exe [2011-12-23 3334432]
"BitTorrent"=C:\Program Files\BitTorrent\BitTorrent.exe [2012-02-14 6061424]
"Microsoft Firevall Engine"=c:\users\public\mdm.exe [2012-02-20 196096]
"OscarEditor"=C:\Program Files\OSCAR Editor X7\OscarEditor.exe [2010-07-22 2636800]
"MSConfig"=C:\Users\Honza\hywm.exe [2012-02-27 116224]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
"VIDC.FPS1"=frapsvid.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-02-28 16:19:05 ----D---- C:\Program Files\trend micro
2012-02-28 16:19:04 ----D---- C:\rsit
2012-02-28 16:14:00 ----A---- C:\TDSSKiller.2.7.15.0_28.02.2012_16.14.00_log.txt
2012-02-27 19:54:42 ----D---- C:\Users\Honza\AppData\Roaming\Hamachi
2012-02-27 19:54:26 ----A---- C:\Windows\system32\drivers\hamachi.sys
2012-02-27 19:54:25 ----D---- C:\Program Files\Hamachi
2012-02-26 17:49:30 ----D---- C:\Program Files\OSCAR Editor X7
2012-02-26 17:48:46 ----D---- C:\Program Files\OscarX7
2012-02-26 00:58:15 ----D---- C:\Users\Honza\AppData\Roaming\vlc
2012-02-26 00:57:53 ----D---- C:\Program Files\VideoLAN
2012-02-25 22:45:07 ----D---- C:\Program Files\Ask.com
2012-02-20 14:59:41 ----ASH---- C:\pagefile.sys
2012-02-15 15:31:48 ----D---- C:\Program Files\Heat
2012-02-15 15:22:11 ----D---- C:\ProgramData\EA Logs
2012-02-15 10:11:49 ----A---- C:\Windows\system32\mshtmled.dll
2012-02-15 10:11:43 ----A---- C:\Windows\system32\jsproxy.dll
2012-02-15 10:11:43 ----A---- C:\Windows\system32\jscript9.dll
2012-02-15 10:11:43 ----A---- C:\Windows\system32\jscript.dll
2012-02-15 10:11:43 ----A---- C:\Windows\system32\iertutil.dll
2012-02-15 10:11:42 ----A---- C:\Windows\system32\wininet.dll
2012-02-15 10:11:42 ----A---- C:\Windows\system32\url.dll
2012-02-15 10:11:42 ----A---- C:\Windows\system32\ieui.dll
2012-02-15 10:11:41 ----A---- C:\Windows\system32\mshtml.dll
2012-02-15 10:11:40 ----A---- C:\Windows\system32\ieframe.dll
2012-02-15 10:11:39 ----A---- C:\Windows\system32\urlmon.dll
2012-02-15 10:11:01 ----A---- C:\Windows\system32\msvcrt.dll
2012-02-15 10:10:51 ----A---- C:\Windows\system32\shell32.dll
2012-02-15 10:10:49 ----A---- C:\Windows\system32\ntshrui.dll
2012-02-15 10:10:47 ----A---- C:\Windows\system32\win32k.sys
2012-02-14 18:12:47 ----D---- C:\Users\Honza\AppData\Roaming\Mozilla
2012-02-14 18:12:44 ----D---- C:\Program Files\BitTorrentBar
2012-02-14 18:12:15 ----D---- C:\Program Files\BitTorrent
2012-02-14 18:11:34 ----D---- C:\Users\Honza\AppData\Roaming\BitTorrent
2012-02-13 21:27:50 ----D---- C:\Perfect World Entertainment
2012-02-13 20:48:35 ----A---- C:\Windows\system32\unicows.dll
2012-02-13 20:17:09 ----A---- C:\Windows\system32\tmp_u_07_02_18.dat
2012-02-13 20:13:30 ----D---- C:\Windows\system32\fmv
2012-02-13 20:13:30 ----A---- C:\Windows\system32\tmp_u_07_01_94.dat
2012-02-13 20:13:30 ----A---- C:\Windows\system32\DFEngine.dll
2012-02-13 20:13:29 ----D---- C:\Windows\system32\music
2012-02-13 20:13:29 ----A---- C:\Windows\system32\tmp_u_06_00_111.dat
2012-02-13 20:13:25 ----D---- C:\Windows\system32\packages
2012-02-13 20:13:25 ----A---- C:\Windows\system32\SpeedTreeRT.dll
2012-02-13 20:13:25 ----A---- C:\Windows\system32\fmod_event.dll
2012-02-13 20:13:24 ----A---- C:\Windows\system32\fmodex.dll
2012-02-13 20:12:37 ----A---- C:\Windows\system32\tmp_u_02_00_01.dat
2012-02-13 20:12:37 ----A---- C:\Windows\system32\tmp_u_01_00_01.dat
2012-02-13 20:12:36 ----A---- C:\Windows\system32\levelr.dat
2012-02-13 20:12:36 ----A---- C:\Windows\system32\FTPFileList.txt
2012-02-13 20:12:26 ----A---- C:\Windows\system32\levelr.exe
2012-02-13 18:18:42 ----D---- C:\ProgramData\PMB Files
2012-02-13 11:05:19 ----D---- C:\Users\Honza\AppData\Roaming\IObit
2012-02-13 11:03:43 ----D---- C:\ProgramData\IObit
2012-02-13 11:03:43 ----D---- C:\Program Files\IObit
2012-02-13 01:01:03 ----D---- C:\Users\Honza\AppData\Roaming\Iminent
2012-02-13 01:00:59 ----D---- C:\ProgramData\Iminent
2012-02-13 01:00:50 ----D---- C:\Program Files\IMinent Toolbar
2012-02-13 01:00:16 ----D---- C:\Program Files\Iminent
2012-02-13 00:45:59 ----D---- C:\Program Files\Microsoft Silverlight
2012-02-12 19:45:38 ----D---- C:\Program Files\gamigo
2012-02-12 10:47:08 ----D---- C:\Program Files\CCleaner
2012-02-09 18:26:51 ----D---- C:\Stranded II
2012-02-03 18:57:35 ----D---- C:\Users\Honza\AppData\Roaming\.minecraft
2012-01-31 20:53:13 ----A---- C:\Windows\system32\npptNT2.sys
2012-01-31 20:53:12 ----D---- C:\Program Files\Common Files\INCA Shared
2012-01-31 19:34:10 ----D---- C:\AeriaGames

======List of files/folders modified in the last 1 month======

2012-02-28 16:19:13 ----D---- C:\Windows\Temp
2012-02-28 16:19:05 ----RD---- C:\Program Files
2012-02-28 16:14:01 ----D---- C:\Windows\system32\drivers
2012-02-28 16:10:51 ----D---- C:\Users\Honza\AppData\Roaming\Skype
2012-02-28 16:09:48 ----D---- C:\Users\Honza\AppData\Roaming\skypePM
2012-02-28 15:43:08 ----D---- C:\Windows\system32\config
2012-02-28 14:56:21 ----D---- C:\Windows\System32
2012-02-28 14:56:15 ----A---- C:\Windows\system32\PnkBstrB.exe
2012-02-28 14:48:32 ----D---- C:\Windows\Prefetch
2012-02-28 14:42:06 ----SHD---- C:\Windows\Installer
2012-02-28 14:42:06 ----HD---- C:\Config.Msi
2012-02-28 10:25:16 ----SHD---- C:\System Volume Information
2012-02-27 15:21:53 ----D---- C:\ProgramData\Skype Extras
2012-02-26 17:49:37 ----D---- C:\Program Files\InstallShield Installation Information
2012-02-26 16:16:29 ----D---- C:\Windows
2012-02-26 16:14:43 ----D---- C:\Windows\Minidump
2012-02-26 10:37:02 ----D---- C:\Windows\system32\catroot2
2012-02-25 23:19:11 ----A---- C:\LoaderLog.txt
2012-02-25 22:45:35 ----D---- C:\Windows\system32\Tasks
2012-02-25 12:25:03 ----D---- C:\Windows\inf
2012-02-25 12:25:03 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-02-24 17:27:07 ----RD---- C:\Program Files\Skype
2012-02-20 18:45:03 ----A---- C:\Windows\system32\PnkBstrA.exe
2012-02-15 17:21:46 ----RSD---- C:\Windows\assembly
2012-02-15 17:21:46 ----D---- C:\Windows\Microsoft.NET
2012-02-15 15:37:00 ----D---- C:\Windows\debug
2012-02-15 15:22:11 ----HD---- C:\ProgramData
2012-02-15 10:20:51 ----D---- C:\Windows\winsxs
2012-02-15 10:18:29 ----D---- C:\Windows\system32\migration
2012-02-15 10:18:29 ----D---- C:\Program Files\Internet Explorer
2012-02-15 10:15:32 ----A---- C:\Windows\system32\MRT.exe
2012-02-15 10:12:21 ----D---- C:\ProgramData\Microsoft Help
2012-02-15 10:11:57 ----D---- C:\Windows\system32\catroot
2012-02-14 10:33:42 ----D---- C:\Windows\Logs
2012-02-14 10:30:14 ----D---- C:\Users\Honza\AppData\Roaming\inkscape
2012-02-14 10:29:35 ----D---- C:\ProgramData\NexonEU
2012-02-13 18:18:25 ----D---- C:\Program Files\Pando Networks
2012-02-13 12:05:49 ----D---- C:\Windows\Tasks
2012-02-13 12:05:49 ----D---- C:\Windows\system32\wfp
2012-02-13 12:05:47 ----D---- C:\Windows\system32\wbem
2012-02-13 12:04:42 ----D---- C:\Windows\twain_32
2012-02-13 12:04:42 ----D---- C:\Windows\system32\DriverStore
2012-02-13 12:04:42 ----D---- C:\Windows\system32\CodeIntegrity
2012-02-13 12:04:38 ----D---- C:\ProgramData\Origin
2012-02-13 12:04:29 ----D---- C:\Windows\registration
2012-02-13 12:02:29 ----SD---- C:\ProgramData\Microsoft
2012-02-12 10:56:24 ----D---- C:\Users\Honza\AppData\Roaming\Media Player Classic
2012-02-12 10:56:24 ----D---- C:\Users\Honza\AppData\Roaming\DAEMON Tools Lite
2012-02-12 10:56:16 ----D---- C:\Windows\Panther
2012-02-12 10:32:53 ----D---- C:\Program Files\Common Files\Skype
2012-02-12 10:32:53 ----D---- C:\Program Files\Common Files
2012-02-12 10:32:46 ----D---- C:\ProgramData\Skype
2012-02-06 18:57:26 ----D---- C:\Nexon
2012-02-01 20:50:29 ----D---- C:\Program Files\Gameforge4D
2012-02-01 07:24:18 ----D---- C:\Program Files\Battlelog Web Plugins
2012-01-31 19:41:44 ----RSD---- C:\Windows\Fonts
2012-01-31 19:36:43 ----D---- C:\Users\Honza\AppData\Roaming\GHISLER
2012-01-30 15:36:29 ----D---- C:\Program Files\EA Games
2012-01-30 15:35:57 ----D---- C:\Windows\Downloaded Program Files
2012-01-29 05:10:42 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-05-01 691696]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-07-29 134512]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-07-29 32608]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2012-02-27 25280]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6232.sys [2010-08-12 298216]
R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver; C:\Windows\system32\DRIVERS\RTL85n86.sys [2010-03-23 1812512]
S1 MpKsl00215c4f;MpKsl00215c4f; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{86E477F8-2EEA-48BF-ACF7-34A490B67D7F}\MpKsl00215c4f.sys []
S1 MpKsl0215a254;MpKsl0215a254; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{936AC0F0-C68C-498C-9245-5976DEF5CD62}\MpKsl0215a254.sys []
S1 MpKsl0554df86;MpKsl0554df86; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{85887FE8-2E70-4C81-AA6A-79D280B662E3}\MpKsl0554df86.sys []
S1 MpKsl08b0b11e;MpKsl08b0b11e; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5EE4BE0-F010-417D-9135-88C9DBEC3434}\MpKsl08b0b11e.sys []
S1 MpKsl145ef1a9;MpKsl145ef1a9; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{16321EEC-6A3E-4978-AD29-3B818217A0C3}\MpKsl145ef1a9.sys []
S1 MpKsl1a341e34;MpKsl1a341e34; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5EE4BE0-F010-417D-9135-88C9DBEC3434}\MpKsl1a341e34.sys []
S1 MpKsl1deb89a6;MpKsl1deb89a6; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{86E477F8-2EEA-48BF-ACF7-34A490B67D7F}\MpKsl1deb89a6.sys []
S1 MpKsl1e5e5d8a;MpKsl1e5e5d8a; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DCF00C2A-B7C1-4506-AC91-3060739A9140}\MpKsl1e5e5d8a.sys []
S1 MpKsl1e983b74;MpKsl1e983b74; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{339B86EF-3964-4C49-B34D-27EEC27F76A7}\MpKsl1e983b74.sys []
S1 MpKsl20389781;MpKsl20389781; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{90ED2F73-6758-485D-9B16-FD17AD8F4F43}\MpKsl20389781.sys []
S1 MpKsl28e5964c;MpKsl28e5964c; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{52D4B32F-98E1-442B-93CC-6353D04F2C85}\MpKsl28e5964c.sys []
S1 MpKsl37fce4db;MpKsl37fce4db; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B67B216C-A186-4988-A259-273367F34558}\MpKsl37fce4db.sys []
S1 MpKsl38095993;MpKsl38095993; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5EE4BE0-F010-417D-9135-88C9DBEC3434}\MpKsl38095993.sys []
S1 MpKsl3d588231;MpKsl3d588231; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{16321EEC-6A3E-4978-AD29-3B818217A0C3}\MpKsl3d588231.sys []
S1 MpKsl45ca4a35;MpKsl45ca4a35; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{160AFFE2-61B6-42C3-A5F4-A4228B2F43CB}\MpKsl45ca4a35.sys []
S1 MpKsl515b2aac;MpKsl515b2aac; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{465024FD-B427-43E4-87C8-62DD47EA07EE}\MpKsl515b2aac.sys []
S1 MpKsl567b2b1a;MpKsl567b2b1a; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F6C5EA3D-F4E3-4DA5-B347-9B06D40562C1}\MpKsl567b2b1a.sys []
S1 MpKsl57648952;MpKsl57648952; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{160AFFE2-61B6-42C3-A5F4-A4228B2F43CB}\MpKsl57648952.sys []
S1 MpKsl5feb50df;MpKsl5feb50df; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{03595538-9183-4954-AFEA-09EB6B45BDDC}\MpKsl5feb50df.sys []
S1 MpKsl610bcfd5;MpKsl610bcfd5; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3A39C183-58AD-43C3-9E0C-99CD2819F59F}\MpKsl610bcfd5.sys []
S1 MpKsl670667d4;MpKsl670667d4; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5EE4BE0-F010-417D-9135-88C9DBEC3434}\MpKsl670667d4.sys []
S1 MpKsl67601bc0;MpKsl67601bc0; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{160AFFE2-61B6-42C3-A5F4-A4228B2F43CB}\MpKsl67601bc0.sys []
S1 MpKsl6bb9fc37;MpKsl6bb9fc37; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D8856797-4722-478F-B61F-50E9856A3955}\MpKsl6bb9fc37.sys []
S1 MpKsl732f15f3;MpKsl732f15f3; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2E3E90B1-9691-4F97-B3F1-26CF91B06147}\MpKsl732f15f3.sys []
S1 MpKsl789558b2;MpKsl789558b2; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{160AFFE2-61B6-42C3-A5F4-A4228B2F43CB}\MpKsl789558b2.sys []
S1 MpKsl7a79b034;MpKsl7a79b034; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F0E1DCB6-0C1F-4C97-9DA9-3D9E40B389C8}\MpKsl7a79b034.sys []
S1 MpKsl8160ccac;MpKsl8160ccac; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1EC8599A-EDBF-46E7-8F03-5112E3A156B5}\MpKsl8160ccac.sys []
S1 MpKsl83c8ff75;MpKsl83c8ff75; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{86E477F8-2EEA-48BF-ACF7-34A490B67D7F}\MpKsl83c8ff75.sys []
S1 MpKsl84d66800;MpKsl84d66800; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6DF163D7-EEE6-455A-AC6E-12DACA6A9585}\MpKsl84d66800.sys []
S1 MpKsl8ce664a4;MpKsl8ce664a4; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{40E1EEFA-7ACB-4FC6-ACF0-FFE520F8610B}\MpKsl8ce664a4.sys []
S1 MpKsl949cf6a0;MpKsl949cf6a0; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{12C23CCA-4316-4E0D-8656-3AE86746D12B}\MpKsl949cf6a0.sys []
S1 MpKsl96c1125e;MpKsl96c1125e; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5C15F9E1-86D9-472A-998C-97E2C9F7FFA2}\MpKsl96c1125e.sys []
S1 MpKsl97201453;MpKsl97201453; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AD3160E3-DDD7-44CF-AF15-4B85B06FFF2B}\MpKsl97201453.sys []
S1 MpKsla49b136b;MpKsla49b136b; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A832E21A-241A-4874-87C5-C9DEF5CC093A}\MpKsla49b136b.sys []
S1 MpKslaa1b128a;MpKslaa1b128a; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B6EF3039-93BF-4A15-A0B5-BA08B3061781}\MpKslaa1b128a.sys []
S1 MpKslaaf5b1ba;MpKslaaf5b1ba; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4FFA8701-ABF5-4DE1-9BB5-09DBBF2AEC99}\MpKslaaf5b1ba.sys []
S1 MpKslaaf81749;MpKslaaf81749; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{160AFFE2-61B6-42C3-A5F4-A4228B2F43CB}\MpKslaaf81749.sys []
S1 MpKslc89bcdc9;MpKslc89bcdc9; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{49F44E90-2B94-49A4-BE3E-8DE662A562AA}\MpKslc89bcdc9.sys []
S1 MpKslcb7aa47c;MpKslcb7aa47c; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5EE4BE0-F010-417D-9135-88C9DBEC3434}\MpKslcb7aa47c.sys []
S1 MpKsld0c0ae7a;MpKsld0c0ae7a; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2E3E90B1-9691-4F97-B3F1-26CF91B06147}\MpKsld0c0ae7a.sys []
S1 MpKsld22e3206;MpKsld22e3206; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5E7F6AC1-9E28-4F1A-9967-42471E20C897}\MpKsld22e3206.sys []
S1 MpKsld8c18ac4;MpKsld8c18ac4; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C3530678-E8E2-4E2A-84F2-CEBD31FE0AC9}\MpKsld8c18ac4.sys []
S1 MpKsle0026f1f;MpKsle0026f1f; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5EE4BE0-F010-417D-9135-88C9DBEC3434}\MpKsle0026f1f.sys []
S1 MpKsle2fe5f59;MpKsle2fe5f59; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CD77FED8-098A-4E4E-9A05-05673220D003}\MpKsle2fe5f59.sys []
S1 MpKsle6aba10b;MpKsle6aba10b; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{324A6E3E-FF71-4979-9F5B-F67AD5B8AE5F}\MpKsle6aba10b.sys []
S1 MpKslebc79c23;MpKslebc79c23; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A016EC32-8DEC-4676-B888-B67148B079B4}\MpKslebc79c23.sys []
S1 MpKslf7f37787;MpKslf7f37787; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F15DEBB9-481D-4A4F-A404-F454AA216F50}\MpKslf7f37787.sys []
S1 MpKslff73b36c;MpKslff73b36c; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5EE4BE0-F010-417D-9135-88C9DBEC3434}\MpKslff73b36c.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2009-07-14 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-13 347264]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-02-20 76888]
R2 TeamViewer6;TeamViewer 6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-17 2358656]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-01 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-08-12 33584]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-01 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-11-20 182768]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2011-08-08 4865496]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#10 Příspěvek od vyosek »

Jeste poprosim o log s nazvem info.txt, je ulozen v c:\rsit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

WiZz_Danny
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 28 úno 2012 14:20

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#11 Příspěvek od WiZz_Danny »

info.txt logfile of random's system information tool 1.09 2012-02-28 16:19:15

======Uninstall list======

Update for Microsoft Office 2007 (KB2508958)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
-->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
-->C:\Windows\UNNeroShowTime.exe /UNINSTALL
-->C:\Windows\UNNeroVision.exe /UNINSTALL
-->C:\Windows\UNRecode.exe /UNINSTALL
-->MsiExec /X{DEA314C4-0929-4250-BC92-98E4C105F28D}
32 Bit HP CIO Components Installer-->MsiExec.exe /I{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}
4Story CZ 3.6.66-->"C:\Program Files\Gameforge4D\4Story_CZ\unins000.exe"
Adobe Flash Player 11 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe -maintain activex
Adobe Reader 9.4.7 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0405-0000-0000000FF1CE} /uninstall {0A1FAC46-B899-421D-B1A2-470896DC45DB}
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0405-0000-0000000FF1CE} /uninstall {5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0405-0000-0000000FF1CE} /uninstall {E68DD413-B834-4923-8181-0A03B7555187}
Ask Toolbar-->MsiExec.exe /X{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Battlefield 3™-->"C:\Program Files\Common Files\EAInstaller\Battlefield 3\Cleanup.exe" uninstall_game -autologging
Battlelog Web Plugins-->C:\Program Files\Battlelog Web Plugins\uninstall.exe
BitTorrent-->"C:\Program Files\BitTorrent\BitTorrent.exe" /UNINSTALL
BitTorrentBar Toolbar-->C:\Program Files\BitTorrentBar\uninstall.exe toolbar
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
ESN Sonar-->C:\Program Files\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe
Google Chrome-->"C:\Program Files\Google\Chrome\Application\17.0.963.56\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_50D4EF115F20A18E.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Hamachi 1.0.3.0-->C:\Program Files\Hamachi\uninstall.exe
Heat Online-->C:\Program Files\Heat\uninstall.exe
HP Customer Participation Program 14.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat -forcereboot
HP Imaging Device Functions 14.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart B010 All-In-One Driver Software 14.0 Rel. 7-->C:\Program Files\HP\Digital Imaging\{98DC1DDF-1263-4F12-9BE1-E3286CBF2B02}\setup\hpzscr01.exe -datfile hposcr51.dat -onestop -forcereboot
HP Smart Web Printing 4.60-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
HP Solution Center 14.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat -forcereboot
HP Update-->MsiExec.exe /X{74DC0593-6BC6-4001-AD5F-D810AFB68D86}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
K-Lite Mega Codec Pack 6.7.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft .NET Framework 4 Extended CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ExtendedLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ExtendedLP
Microsoft .NET Framework 4 Extended CSY Language Pack-->MsiExec.exe /X{A2DE62D8-EF1B-36CB-B461-B1E221ED8608}
Microsoft .NET Framework 4 Extended-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{0A0CADCF-78DA-33C4-A350-CD51849B9702}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{F2508213-9989-4E85-A078-72BE483917EF}
Microsoft Games for Windows Marketplace-->MsiExec.exe /X{4CB0307C-565E-4441-86BE-0DF2E4FB828C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0405-0000-0000000FF1CE} /uninstall {E12F9D31-4025-4BC6-B1B2-AB262C5580B0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0405-0000-0000000FF1CE} /uninstall {294B4278-CF7B-40B9-86A1-2D3FF0C2C524}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-041B-0000-0000000FF1CE} /uninstall {10EC59E5-9BCE-4884-BB1A-E28627220232}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft XNA Framework Redistributable 4.0-->MsiExec.exe /I{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Need For Speed™ World-->"C:\Program Files\Electronic Arts\Need For Speed World\unins000.exe"
Nero 7 Ultra Edition-->MsiExec.exe /I{ACE0935B-2B99-4D0A-B173-8CACC6051029}
NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
NVIDIA PhysX-->MsiExec.exe /X{DEA314C4-0929-4250-BC92-98E4C105F28D}
Origin-->C:\Program Files\Origin\OriginUninstall.exe
OSCAR Editor-->MsiExec.exe /I{0F3BEAD5-4368-4CBC-9876-11B8475DE285}
Pando Media Booster-->C:\Program Files\Pando Networks\Media Booster\uninst.exe
PunkBuster Services-->C:\Program Files\Origin Games\Battlefield 3\pbsvc.exe -u
Repulse-->C:\AeriaGames\Repulse\Uninst.exe
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2288931)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CD769337-C8AC-46DB-A7DC-643E50089263}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB2553074)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5729F1AE-5895-468F-9165-BAD161C9E982}
Security Update for 2007 Microsoft Office System (KB2553089)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {01D4CA59-7070-4420-9BCC-0EFA7C5D76BE}
Security Update for 2007 Microsoft Office System (KB2553090)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {643C12A2-AF9A-4712-B8BE-3B7650AFE00A}
Security Update for 2007 Microsoft Office System (KB2584063)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BF3F1CBD-B05C-4644-AE43-6EE0FCC227A4}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {3E0806DB-3085-378A-840A-F0D3AE3609D1} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7E97AB83-C1FE-38DE-B848-877E0A4BD81E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {DB31DEDD-BF95-31E7-A9B7-5480561CEFF3} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {8DDEFC7E-0C61-3D11-AFC6-5414F2DAFD01} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {4952F442-5C1A-38EB-8C23-B18EFE77E20C} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {7A2C18A1-D2A2-3177-82F1-5FE9CC08ECB0} /parameterfolder Extended
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {42A3562E-8B4E-39A4-B82D-CC12F82889E3} /parameterfolder Extended
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {4952F442-5C1A-38EB-8C23-B18EFE77E20C} /parameterfolder Extended
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5A4E43D5-858F-49BD-BA72-8F30E1793060}
Security Update for Microsoft Office Excel 2007 (KB2553073)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {65EA4836-B5A3-4C1D-8883-0C35E471003A}
Security Update for Microsoft Office Groove 2007 (KB2552997)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3A1CBF7D-4704-40BC-B31C-AA761884A3E4}
Security Update for Microsoft Office InfoPath 2007 (KB2510061)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5D930261-AA5B-48D1-931F-425C9D767490}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8588DD11-6BD7-4400-B55C-DD5AB74B43E1}
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
Security Update for Microsoft Office Publisher 2007 (KB2284697)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3A4CDE54-2403-483D-8D9A-15E3264410DF}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
Skype Toolbars-->MsiExec.exe /I{B6CF2967-C81E-40C0-9815-C05774FEF120}
Skype™ 5.3-->MsiExec.exe /X{5335DADB-34BA-4AE8-A519-648D78498846}
Stranded II 1.0.0.1-->"C:\Stranded II\unins000.exe"
TeamViewer 6-->C:\Program Files\TeamViewer\Version6\uninstall.exe
TNod User & Password Finder-->"C:\Program Files\TNod User & Password Finder\uninst-TNod.exe"
Traktor 2-->"C:\TopCD\Traktor 2\unins000.exe"
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {5E9CF3A4-ADB3-3080-A8BF-976A28340758} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD988F49-E1C8-3C84-9683-0448B6BB8E20} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {81EBB9D7-173C-32E3-B477-149C8DE075E4} /parameterfolder Client
Update for Microsoft .NET Framework 4 Extended (KB2468871)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {5E9CF3A4-ADB3-3080-A8BF-976A28340758} /parameterfolder Extended
Update for Microsoft .NET Framework 4 Extended (KB2533523)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {81EBB9D7-173C-32E3-B477-149C8DE075E4} /parameterfolder Extended
Update for Microsoft Office 2007 suites (KB2597998) 32-Bit Edition-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {97FF6C46-CE3A-47F6-BA6B-3D743ACA4054}
Update for Microsoft Office 2007 System (KB2539530)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B4CEEAE-AA88-490C-BCB2-AAC3421981A4}
Update for Microsoft Office OneNote 2007 (KB980729)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {329050A9-EF80-40F9-B633-74508F54C1FF}
Update for Microsoft Office Outlook 2007 (KB2583910)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BDC21583-5601-4B2B-88F3-7919F6DE8FB1}
VLC media player 2.0.0-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live ID Sign-in Assistant-->MsiExec.exe /X{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
X7 Oscar Editor-->"C:\Program Files\InstallShield Installation Information\{0F3BEAD5-4368-4CBC-9876-11B8475DE285}\setup.exe" -runfromtemp -l0x0409 -removeonly

======System event log======

Computer Name: Honza-PC
Event Code: 7036
Message: Stav služby Prohledávání počítačů byl změněn na: Spuštěno
Record Number: 62381
Source Name: Service Control Manager
Time Written: 20110920144255.264000-000
Event Type: Informace
User:

Computer Name: Honza-PC
Event Code: 7036
Message: Stav služby Funkčnost aplikací byl změněn na: Zastaveno
Record Number: 62380
Source Name: Service Control Manager
Time Written: 20110920143901.307000-000
Event Type: Informace
User:

Computer Name: Honza-PC
Event Code: 7036
Message: Stav služby Prohledávání počítačů byl změněn na: Zastaveno
Record Number: 62379
Source Name: Service Control Manager
Time Written: 20110920143805.335000-000
Event Type: Informace
User:

Computer Name: Honza-PC
Event Code: 7036
Message: Stav služby Prohledávání počítačů byl změněn na: Spuštěno
Record Number: 62378
Source Name: Service Control Manager
Time Written: 20110920143759.255000-000
Event Type: Informace
User:

Computer Name: Honza-PC
Event Code: 7036
Message: Stav služby Instalační služba modulů systému Windows byl změněn na: Zastaveno
Record Number: 62377
Source Name: Service Control Manager
Time Written: 20110920143701.361000-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247D28-05
Event Code: 1001
Message: Chybný blok , typ 0
Název události: PnPRequestAdditionalSoftware
Reakce: Není k dispozici
ID souboru CAB: 0

Podpis problému:
P1: x86
P2: USB\VID_09DA&PID_0080&REV_020<
P3: 6.1.0.0
P4: 0405
P5: input.inf
P6: *
P7:
P8:
P9:
P10:

Připojené soubory:

Tyto soubory mohou být k dispozici zde:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_20ccc1c7aa7eb542bf396185c98ef3510105758_cab_06269942

Symbol analýzy:
Opětovné hledání řešení: 0
ID hlášení: 389ec060-7407-11e0-a369-adf5959d2e4d
Stav hlášení: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20110501152519.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20110501152325.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20110501152322.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20110501152319.593200-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20110501152319.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: Honza-PC
Event Code: 5037
Message: Ovladač brány Windows Firewall zjistil kritickou chybu za běhu. Probíhá ukončení.

Kód chyby: 45
Record Number: 9813
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110611102732.721400-000
Event Type: Neúspěšný audit
User:

Computer Name: Honza-PC
Event Code: 5037
Message: Ovladač brány Windows Firewall zjistil kritickou chybu za běhu. Probíhá ukončení.

Kód chyby: 45
Record Number: 9812
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110611102732.721400-000
Event Type: Neúspěšný audit
User:

Computer Name: Honza-PC
Event Code: 5037
Message: Ovladač brány Windows Firewall zjistil kritickou chybu za běhu. Probíhá ukončení.

Kód chyby: 45
Record Number: 9811
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110611102732.721400-000
Event Type: Neúspěšný audit
User:

Computer Name: Honza-PC
Event Code: 5037
Message: Ovladač brány Windows Firewall zjistil kritickou chybu za běhu. Probíhá ukončení.

Kód chyby: 45
Record Number: 9810
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110611102731.769400-000
Event Type: Neúspěšný audit
User:

Computer Name: Honza-PC
Event Code: 5037
Message: Ovladač brány Windows Firewall zjistil kritickou chybu za běhu. Probíhá ukončení.

Kód chyby: 45
Record Number: 9809
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110611102731.769400-000
Event Type: Neúspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;C:\Program Files\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 67 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=4303

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#12 Příspěvek od vyosek »

Co udelame s tim nelegalnim ESETEm? Pravidla fora hovori o moznosti pomoci jasne!

Uvedomte si, ze jste na bezpecnostnim foru - podpora warezu (zvlaste bezpecnostnich programu) by byla zcela proti logice fora :!:

Takze jej zmenime na free reseni - Avast, Avira ci MSE?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

WiZz_Danny
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 28 úno 2012 14:20

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#13 Příspěvek od WiZz_Danny »

WTF ? Nelegální ? O tom nevím, platí mi to otec, je mi totiž 16 let ! O tom nevím, že je nelegální !

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#14 Příspěvek od vyosek »

Tak tohle TNod User & Password Finder asi nebude generator pohybu akvarijnich rybicek :?: Ale je to crack (resp. hledac) licencnich klicu na ESET...

Udelame domluvu, polecime havet a vy pritom zjistite jak je to s tim ESETem a pripadne ze bude nelegalni (coz si myslim), tak tam dame free reseni jak jsem psal vyse, souhlas?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

WiZz_Danny
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 28 úno 2012 14:20

Re: Virus(Trojský kůň) Nejde lěčit ani odstranit !

#15 Příspěvek od WiZz_Danny »

Děkuji.Ale jak pak pořešit ten Antivir ?

Odpovědět