Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
duffx
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 02 kvě 2010 15:55

Prosím o kontrolu logu

#1 Příspěvek od duffx »

Zdravíčko V poslední době se mi něco nezdá na chování systému, občas BSOD apod. Mohl bych Vás poprosit o kontrolu? :)

Logfile of random's system information tool 1.09 (written by random/random)
Run by duff at 2012-07-12 21:06:04
Microsoft Windows 7 Professional
System drive C: has 7 GB (10%) free of 76 GB
Total RAM: 8189 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:07:10, on 12.7.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe
C:\Program Files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe
C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Users\duff\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\syswow64\svchost.exe
C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe
C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\SysWOW64\svchost.exe
C:\Program Files (x86)\foobar2000\foobar2000.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Program Files (x86)\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\Opera\pluginwrapper\opera_plugin_wrapper.exe
C:\Program Files (x86)\Opera\pluginwrapper\opera_plugin_wrapper.exe
C:\Program Files\trend micro\duff.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F3 - REG:win.ini: load=C:\Users\duff\odfMag.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ZyngaGamesAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Users\duff\AppData\Roaming\svchost.exe
O4 - HKLM\..\Run: [NjYwQzUyMTFCMUQyMkM2QT] C:\Users\duff\odfMag.exe
O4 - HKLM\..\Run: [STCAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Gadwin PrintScreen Pro] C:\Program Files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe /nosplash
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\duff\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [iTunesHelper] C:\Users\duff\AppData\Roaming\svchost.exe
O4 - HKCU\..\Run: [Defense] C:\Users\duff\AppData\Roaming\Defense.exe
O4 - HKCU\..\Run: [Task Manager] C:\Users\duff\AppData\Roaming\blackCoin.scr
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKLM\..\Policies\Explorer\Run: [iTunesHelper] C:\Users\duff\AppData\Roaming\svchost.exe
O4 - HKLM\..\Policies\Explorer\Run: [4182] C:\PROGRA~3\LOCALS~1\Temp\msouukzah.exe
O4 - HKCU\..\Policies\Explorer\Run: [Valve] C:\Users\duff\AppData\Roaming\E00B32.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3297901978-2500626200-4254921097-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3297901978-2500626200-4254921097-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: Dropbox.lnk = duff\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: Aura.lnk = C:\Windows\8 Skin Pack\Aura\Aura.exe
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
O4 - Global Startup: TaskbarUserTile.lnk = C:\Windows\8 Skin Pack\TaskbarUserTile\UserTile.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O15 - Trusted Zone: http://cz.qi.dcconcept.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AODService - Unknown owner - C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\httpd.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Splashtop Connect Service (SCBackService) - Splashtop Inc. - C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Splashtop Connect Firefox Software Updater Service (WCUService_STC_FF) - Splashtop Inc. - C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\xampp\service.exe

--
End of file - 12375 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0add4aa9-0eaf-408f-b0ed-4cb0bab80f16 -SystemEventPortName:HostProcess-22145253-0b68-4535-9134-723ae48cf888 -IoCancelEventPortName:HostProcess-ac3651d9-8258-4a4d-8706-11ffb3ecd88c -NonStateChangingEventPortName:HostProcess-f520a072-a3a3-499c-a71d-12bfa0036ce4 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:95831f3e-5101-4170-8ac8-42d210f96094
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\xampp\apache\bin\httpd.exe" -k runservice
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe" -runService:MsDepSvc
"C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS10\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe"
C:\xampp\apache\bin\httpd.exe -d C:/xampp/apache
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_0000073c
\??\C:\Windows\system32\conhost.exe
"C:\Users\duff\odfMag.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" /nosplash
C:\Windows\splwow64.exe 2
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe"
"C:\Users\duff\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE" /tsr
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\syswow64\svchost.exe
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-9115c692-1737-46bc-8450-754416b3d131 -SystemEventPortName:HostProcess-0244b058-d077-462d-9d17-64d3d7835220 -IoCancelEventPortName:HostProcess-36dfcd2b-ba2d-4600-8ad2-4ff610a9616a -NonStateChangingEventPortName:HostProcess-a2282967-c3a4-4140-94fa-368c69ec63ed -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:51b9ab40-951d-493c-b15b-a929c7ae7732
"C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
"C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe" /s
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
svchost.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe" /CFG="C:\ProgramData\Avira\AntiVir Desktop\PROFILES\AVSCAN-20120712-194006-43866662.avp" /GUIMODE=1
"C:\Windows\system32\taskmgr.exe" /4
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" -Embedding
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\foobar2000\foobar2000.exe"
"C:\Program Files (x86)\Last.fm\LastFM.exe" --tray
"C:\Program Files (x86)\totalcmd\TOTALCMD.EXE"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Program Files (x86)\Opera\pluginwrapper\opera_plugin_wrapper.exe" -newprocess "5756 2 0 1 3" -logfolder "C:\Users\duff\AppData\Local\Opera\Opera\logs"
"C:\Program Files (x86)\Opera\pluginwrapper\opera_plugin_wrapper.exe" -newprocess "5756 2 0 1 109" -logfolder "C:\Users\duff\AppData\Local\Opera\Opera\logs"
"G:\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\One-Click Tweak.job

=========Mozilla firefox=========

ProfilePath - C:\Users\duff\AppData\Roaming\Mozilla\Firefox\Profiles\mss3h0eh.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.257 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/wpi,version=1.4]
"Description"=
"Path"=C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.257 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_257.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/wpi,version=1.4]
"Description"=
"Path"=C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-01-03 49440]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-04-12 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-04-12 42272]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-02-24 11780712]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15 499608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"iTunesHelper"=C:\Users\duff\AppData\Roaming\svchost.exe []
"4182"=C:\PROGRA~3\LOCALS~1\Temp\msouukzah.exe [2009-07-14 89600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"Gadwin PrintScreen Pro"=C:\Program Files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe [2011-05-12 1858048]
"Facebook Update"=C:\Users\duff\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11 138096]
"iTunesHelper"=C:\Users\duff\AppData\Roaming\svchost.exe []
"Defense"=C:\Users\duff\AppData\Roaming\Defense.exe []
"Task Manager"=C:\Users\duff\AppData\Roaming\blackCoin.scr [2012-07-12 10240]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Valve"=C:\Users\duff\AppData\Roaming\E00B32.exe [2009-07-14 452096]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ZyngaGamesAgent"=C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe [2010-11-15 841544]
"VirtualCloneDrive"=C:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"AdobeCS5.5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
"iTunesHelper"=C:\Users\duff\AppData\Roaming\svchost.exe []
"NjYwQzUyMTFCMUQyMkM2QT"=C:\Users\duff\odfMag.exe [2012-07-11 301568]
"STCAgent"=C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe []
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2012-05-02 348624]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"iTunesHelper"=C:\Users\duff\AppData\Roaming\svchost.exe []
"4182"=C:\PROGRA~3\LOCALS~1\Temp\msouukzah.exe [2009-07-14 89600]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Aura.lnk - C:\Windows\8 Skin Pack\Aura\Aura.exe
Google Calendar Sync.lnk - C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
TaskbarUserTile.lnk - C:\Windows\8 Skin Pack\TaskbarUserTile\UserTile.exe

C:\Users\duff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\duff\AppData\Roaming\Dropbox\bin\Dropbox.exe
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HideSCAHealth"=1
"NoDriveTypeAutoRun"=145
"DisallowRun"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2012-07-12 21:06:05 ----D---- C:\Program Files\trend micro
2012-07-12 21:06:04 ----D---- C:\rsit
2012-07-12 19:33:25 ----D---- C:\ProgramData\Avira
2012-07-12 19:33:25 ----D---- C:\Program Files (x86)\Avira
2012-07-12 17:53:16 ----D---- C:\ProgramData\ESET
2012-07-12 17:53:16 ----D---- C:\Program Files\ESET
2012-07-12 17:40:29 ----A---- C:\Windows\ntbtlog.txt
2012-07-12 17:22:43 ----H---- C:\Users\duff\AppData\Roaming\1834941334.exe
2012-07-12 17:22:42 ----H---- C:\Users\duff\AppData\Roaming\blackCoin.scr
2012-07-12 02:50:28 ----A---- C:\Users\duff\AppData\Roaming\pcrujs.exe
2012-07-12 01:49:03 ----A---- C:\Users\duff\AppData\Roaming\yschjw.exe
2012-07-12 01:20:18 ----D---- C:\ProgramData\Local Settings
2012-07-11 22:29:42 ----A---- C:\Users\duff\AppData\Roaming\oqyztx.exe
2012-07-11 21:19:11 ----D---- C:\Users\duff\AppData\Roaming\dclogs
2012-07-11 10:01:58 ----SHD---- C:\Windows\system32\%APPDATA%
2012-07-10 22:31:40 ----D---- C:\Program Files\Autoruns
2012-07-10 22:16:10 ----D---- C:\ProgramData\B4CF34E400009249006C6642A6014588
2012-07-10 22:15:59 ----D---- C:\Users\duff\AppData\Roaming\Qii
2012-07-10 22:15:59 ----D---- C:\Users\duff\AppData\Roaming\Mouffi
2012-07-03 20:17:37 ----D---- C:\Users\duff\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-07-03 20:17:37 ----D---- C:\Users\duff\AppData\Roaming\Adobe Mini Bridge CS5
2012-07-03 19:52:39 ----D---- C:\Users\duff\AppData\Roaming\Mozilla
2012-07-03 19:52:37 ----D---- C:\ProgramData\Mozilla
2012-07-03 19:52:36 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-07-03 19:52:35 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-06-27 19:27:17 ----A---- C:\Windows\SYSWOW64\CmdLineExt03.dll
2012-06-27 19:22:28 ----A---- C:\Windows\DIIUnin.dat
2012-06-27 19:22:27 ----A---- C:\Windows\DIIUnin.pif
2012-06-27 19:22:27 ----A---- C:\Windows\DIIUnin.exe
2012-06-27 19:20:37 ----D---- C:\Program Files (x86)\Diablo II
2012-06-21 21:32:57 ----D---- C:\Program Files (x86)\Rockstar Games
2012-06-18 08:31:52 ----A---- C:\SQLEXPRWT_x86_ENU.exe
2012-06-14 17:33:55 ----D---- C:\Program Files (x86)\Diablo III
2012-06-14 16:40:06 ----D---- C:\ProgramData\Battle.net
2012-06-14 16:33:36 ----D---- C:\ProgramData\Blizzard Entertainment

======List of files/folders modified in the last 1 month======

2012-07-12 21:06:08 ----D---- C:\Windows\Temp
2012-07-12 21:06:05 ----RD---- C:\Program Files
2012-07-12 21:02:17 ----D---- C:\Users\duff\AppData\Roaming\Skype
2012-07-12 20:57:56 ----D---- C:\Users\duff\AppData\Roaming\Dropbox
2012-07-12 20:11:09 ----SHD---- C:\System Volume Information
2012-07-12 20:05:22 ----D---- C:\Program Files (x86)\foobar2000
2012-07-12 19:45:07 ----D---- C:\Windows\System32
2012-07-12 19:45:07 ----D---- C:\Windows\inf
2012-07-12 19:45:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-07-12 19:40:57 ----D---- C:\ProgramData\NVIDIA
2012-07-12 19:40:10 ----D---- C:\Windows\system32\catroot
2012-07-12 19:33:25 ----RD---- C:\Program Files (x86)
2012-07-12 19:33:25 ----HD---- C:\ProgramData
2012-07-12 19:16:17 ----D---- C:\Windows\system32\drivers\UMDF
2012-07-12 19:16:17 ----D---- C:\Windows\system32\drivers
2012-07-12 18:44:05 ----SHD---- C:\Windows\Installer
2012-07-12 18:25:19 ----D---- C:\Windows\system32\Tasks
2012-07-12 18:03:24 ----HD---- C:\Windows\8 Skin Pack
2012-07-12 18:03:24 ----D---- C:\Windows\SysWOW64
2012-07-12 18:03:24 ----D---- C:\Windows
2012-07-12 17:54:30 ----D---- C:\Windows\system32\DriverStore
2012-07-12 17:49:50 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-07-12 17:49:26 ----D---- C:\Program Files (x86)\YouTubeGet
2012-07-12 17:48:57 ----D---- C:\SHARPIA
2012-07-12 17:47:58 ----D---- C:\Program Files (x86)\Image-Line
2012-07-12 17:47:36 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 10.0
2012-07-12 17:44:34 ----D---- C:\Windows\system32\catroot2
2012-07-12 07:46:39 ----D---- C:\Windows\system32\FxsTmp
2012-07-12 07:19:29 ----D---- C:\Windows\Minidump
2012-07-12 00:57:42 ----D---- C:\Windows\system32\config
2012-07-11 17:41:44 ----D---- C:\Users\duff\AppData\Roaming\uTorrent
2012-07-10 23:35:58 ----D---- C:\Users\duff\AppData\Roaming\vlc
2012-07-10 22:16:01 ----SD---- C:\Users\duff\AppData\Roaming\Microsoft
2012-07-10 18:57:15 ----D---- C:\Users\duff\AppData\Roaming\SumatraPDF
2012-07-02 19:19:15 ----D---- C:\Program Files (x86)\XMind
2012-06-29 09:33:29 ----D---- C:\Users\duff\AppData\Roaming\Adobe
2012-06-25 08:36:07 ----D---- C:\ProgramData\Skype
2012-06-21 22:01:49 ----D---- C:\Program Files (x86)\utorrent
2012-06-21 21:11:49 ----RSD---- C:\Windows\assembly
2012-06-21 20:41:18 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-06-18 23:59:46 ----D---- C:\Windows\Microsoft.NET
2012-06-18 23:59:24 ----D---- C:\Windows\rescache
2012-06-18 20:15:30 ----D---- C:\Windows\winsxs
2012-06-18 20:14:36 ----D---- C:\Windows\SYSWOW64\inetsrv
2012-06-18 20:14:35 ----D---- C:\Windows\system32\inetsrv
2012-06-18 07:14:24 ----D---- C:\Windows\Tasks
2012-06-18 07:14:15 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-06-18 07:00:04 ----D---- C:\Windows\system32\cs-CZ
2012-06-15 06:12:12 ----D---- C:\Program Files (x86)\Opera
2012-06-14 17:34:28 ----D---- C:\Program Files (x86)\Common Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2011-03-18 29592]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2012-04-27 132832]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 40816]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-12-31 360712]
R2 AODDriver4.1;AODDriver4.1; \??\C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [2011-10-14 55936]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2012-04-25 98848]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2012-02-29 43168]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2011-03-07 40832]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2011-03-07 65280]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-02-24 2753512]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-03-03 174184]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-01-13 413800]
R3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2011-03-30 35112]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
R3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2012-02-29 312480]
S3 imhidusb;Immersion's HID USB Driver; C:\Windows\system32\DRIVERS\imhidusb.sys [2007-04-19 23040]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-08-17 9216]
S3 usbser;Nokia USB Serial Port Driver ; C:\Windows\system32\drivers\usbser.sys [2009-07-14 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-08-17 9216]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Realtime Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-05-02 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-02 86224]
R2 Apache2.2;Apache2.2; C:\xampp\apache\bin\httpd.exe [2010-10-18 20549]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MsDepSvc;Web Deployment Agent Service; C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-01 67400]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 57617752]
R2 MSSQLSERVER;SQL Server (MSSQLSERVER); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS10\MSSQL\Binn\sqlservr.exe [2010-04-03 42884448]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-03-20 1012328]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-03-21 2218600]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-01-20 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2012-01-20 107832]
R2 SCBackService;Splashtop Connect Service; C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 146272]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-03-20 378472]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
R2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service; C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 AODService;AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [2011-10-14 136616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-06-05 160944]
S2 XAMPP;XAMPP Service; C:\xampp\service.exe [2007-12-21 60928]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-04-04 1431888]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-15 113120]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-01-06 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-04-03 267616]
S4 SQLSERVERAGENT;SQL Server Agent (MSSQLSERVER); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS10\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 367456]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Zaliskane od sklepa na pudu - cela zoo i s babkou pokladni :arcisit:

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

duffx
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 02 kvě 2010 15:55

Re: Prosím o kontrolu logu

#3 Příspěvek od duffx »

Tak nějak jsem to tušil :?: ... aneb jak se říká - kovářova kobyla... V poslední době nebyl čas to hlídat, tak je oheň na střeše :D

RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows 7 (6.1.7600 ) 64 bits version
Spuštěno v: Normální režim
Uživatel: duff [Práva správce]
Mód: Kontrola -- Datum: 07/12/2012 22:00:41

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 24 ¤¤¤
[HJ NAME] HKCU\[...]\Run : iTunesHelper (C:\Users\duff\AppData\Roaming\svchost.exe) -> FOUND
[SUSP PATH] HKCU\[...]\Run : Defense (C:\Users\duff\AppData\Roaming\Defense.exe) -> FOUND
[SUSP PATH] HKCU\[...]\Run : Task Manager (C:\Users\duff\AppData\Roaming\blackCoin.scr) -> FOUND
[HJ NAME] HKUS\S-1-5-21-3297901978-2500626200-4254921097-1000[...]\Run : iTunesHelper (C:\Users\duff\AppData\Roaming\svchost.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-3297901978-2500626200-4254921097-1000[...]\Run : Defense (C:\Users\duff\AppData\Roaming\Defense.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-3297901978-2500626200-4254921097-1000[...]\Run : Task Manager (C:\Users\duff\AppData\Roaming\blackCoin.scr) -> FOUND
[HJ NAME] HKLM\[...]\Wow6432Node\Run : iTunesHelper (C:\Users\duff\AppData\Roaming\svchost.exe) -> FOUND
[SUSP PATH] HKLM\[...]\Wow6432Node\Run : NjYwQzUyMTFCMUQyMkM2QT (C:\Users\duff\odfMag.exe) -> FOUND
[SUSP PATH] HKCU\[...]\Policies\Explorer\Run : Valve (C:\Users\duff\AppData\Roaming\E00B32.exe) -> FOUND
[HJ NAME] HKLM\[...]\Policies\Explorer\Run : iTunesHelper (C:\Users\duff\AppData\Roaming\svchost.exe) -> FOUND
[ROGUE ST] HKLM\[...]\Policies\Explorer\Run : 4182 (C:\PROGRA~3\LOCALS~1\Temp\msouukzah.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-3297901978-2500626200-4254921097-1000[...]\Policies\Explorer\Run : Valve (C:\Users\duff\AppData\Roaming\E00B32.exe) -> FOUND
[HJ NAME] HKLM\[...]\Wow6432Node\Policies\Explorer\Run : iTunesHelper (C:\Users\duff\AppData\Roaming\svchost.exe) -> FOUND
[ROGUE ST] HKLM\[...]\Wow6432Node\Policies\Explorer\Run : 4182 (C:\PROGRA~3\LOCALS~1\Temp\msouukzah.exe) -> FOUND
[SUSP PATH] HKCU\[...]\Windows : load (C:\Users\duff\odfMag.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-3297901978-2500626200-4254921097-1000[...]\Windows : load (C:\Users\duff\odfMag.exe) -> FOUND
[HJPOL] HKCU\[...]\Policies\Explorer\Explorer : DisallowRun (1) -> FOUND
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\duff\AppData\Local\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\n.) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Zvláštní soubory / Složky: ¤¤¤
[ZeroAccess][FILE] @ : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\@ --> FOUND
[ZeroAccess][FOLDER] U : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\U --> FOUND
[ZeroAccess][FOLDER] L : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\L --> FOUND
[ZeroAccess][FILE] @ : c:\users\duff\appdata\local\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\@ --> FOUND
[ZeroAccess][FOLDER] U : c:\users\duff\appdata\local\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\U --> FOUND
[ZeroAccess][FOLDER] L : c:\users\duff\appdata\local\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\L --> FOUND

¤¤¤ Ovladač: [NENAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ZeroAccess ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 adobe.activate.com
127.0.0.1 adobeereg.com
127.0.0.1 www.adobeereg.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 125.252.224.90
127.0.0.1 125.252.224.91
[...]


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: INTEL SSDSA2CW080G3 ATA Device +++++
--- User ---
[MBR] da4b85b38abbde74f65834b95da32659
[BSP] 0f8211a200273349886382901fb9273e : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 76217 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: TOSHIBA MK2552GSX ATA Device +++++
--- User ---
[MBR] 13c63db0b098218aef34914eafbe4ee0
[BSP] 0c5d1525ade744e211385d1f43dba554 : Windows 7 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 122882048 | Size: 178473 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive2: WDC WD6400AAKS-00A7B0 ATA Device +++++
--- User ---
[MBR] 8ea2ee69e82dc2c60e9a777efd235742
[BSP] b1eb37eabf90a7d30fb0b83e55ac6e75 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive3: Patriot Memory USB Device +++++
--- User ---
[MBR] 8e4d69fb6c8aeace7d6cb628d7fd8096
[BSP] 5c0f2c694a71757c51d8749e647c85db : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 7639 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[1].txt >>
RKreport[1].txt


####################################################################


22:01:22.0657 0592 TDSS rootkit removing tool 2.7.45.0 Jul 9 2012 12:46:35
22:01:22.0824 0592 ============================================================
22:01:22.0824 0592 Current date / time: 2012/07/12 22:01:22.0824
22:01:22.0824 0592 SystemInfo:
22:01:22.0824 0592
22:01:22.0824 0592 OS Version: 6.1.7600 ServicePack: 0.0
22:01:22.0824 0592 Product type: Workstation
22:01:22.0824 0592 ComputerName: PROMETHEUS
22:01:22.0825 0592 UserName: duff
22:01:22.0825 0592 Windows directory: C:\Windows
22:01:22.0825 0592 System windows directory: C:\Windows
22:01:22.0825 0592 Running under WOW64
22:01:22.0825 0592 Processor architecture: Intel x64
22:01:22.0825 0592 Number of processors: 6
22:01:22.0825 0592 Page size: 0x1000
22:01:22.0825 0592 Boot type: Normal boot
22:01:22.0825 0592 ============================================================
22:01:23.0034 0592 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2861, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
22:01:23.0467 0592 Drive \Device\Harddisk1\DR1 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x7E2D, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
22:01:23.0486 0592 Drive \Device\Harddisk2\DR2 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:01:23.0490 0592 Drive \Device\Harddisk3\DR3 - Size: 0x1DD800000 (7.46 Gb), SectorSize: 0x200, Cylinders: 0x3CD, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
22:01:23.0492 0592 ============================================================
22:01:23.0492 0592 \Device\Harddisk0\DR0:
22:01:23.0492 0592 MBR partitions:
22:01:23.0492 0592 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
22:01:23.0492 0592 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x94DC800
22:01:23.0492 0592 \Device\Harddisk1\DR1:
22:01:23.0492 0592 MBR partitions:
22:01:23.0492 0592 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x7530800, BlocksNum 0x15C94800
22:01:23.0492 0592 \Device\Harddisk2\DR2:
22:01:23.0492 0592 MBR partitions:
22:01:23.0492 0592 \Device\Harddisk2\DR2\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4A856E82
22:01:23.0492 0592 \Device\Harddisk3\DR3:
22:01:23.0493 0592 MBR partitions:
22:01:23.0493 0592 \Device\Harddisk3\DR3\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xEEBFC1
22:01:23.0493 0592 ============================================================
22:01:23.0495 0592 C: <-> \Device\Harddisk0\DR0\Partition1
22:01:23.0503 0592 E: <-> \Device\Harddisk2\DR2\Partition0
22:01:23.0553 0592 G: <-> \Device\Harddisk1\DR1\Partition0
22:01:23.0553 0592 ============================================================
22:01:23.0553 0592 Initialize success
22:01:23.0553 0592 ============================================================
22:01:52.0922 5928 ============================================================
22:01:52.0922 5928 Scan started
22:01:52.0922 5928 Mode: Manual; SigCheck; TDLFS;
22:01:52.0922 5928 ============================================================
22:01:53.0987 5928 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:01:54.0024 5928 1394ohci - ok
22:01:54.0038 5928 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:01:54.0049 5928 ACPI - ok
22:01:54.0052 5928 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:01:54.0073 5928 AcpiPmi - ok
22:01:54.0086 5928 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:01:54.0106 5928 adp94xx - ok
22:01:54.0116 5928 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:01:54.0132 5928 adpahci - ok
22:01:54.0142 5928 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:01:54.0156 5928 adpu320 - ok
22:01:54.0169 5928 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:01:54.0219 5928 AeLookupSvc - ok
22:01:54.0238 5928 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
22:01:54.0266 5928 AFD - ok
22:01:54.0277 5928 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:01:54.0286 5928 agp440 - ok
22:01:54.0297 5928 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:01:54.0305 5928 ALG - ok
22:01:54.0308 5928 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:01:54.0316 5928 aliide - ok
22:01:54.0319 5928 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:01:54.0326 5928 amdide - ok
22:01:54.0336 5928 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:01:54.0349 5928 AmdK8 - ok
22:01:54.0359 5928 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:01:54.0367 5928 AmdPPM - ok
22:01:54.0381 5928 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
22:01:54.0391 5928 amdsata - ok
22:01:54.0401 5928 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:01:54.0414 5928 amdsbs - ok
22:01:54.0419 5928 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
22:01:54.0428 5928 amdxata - ok
22:01:54.0438 5928 AntiVirSchedulerService (0a1cc583e8147004e4ad4625d7fbf88c) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:01:54.0446 5928 AntiVirSchedulerService - ok
22:01:54.0454 5928 AntiVirService (c9a36ef935aced86aedf93e97e606911) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:01:54.0458 5928 AntiVirService - ok
22:01:54.0467 5928 AODDriver4.1 (6845a9781ef9d2fa5c494cc684a06b6a) C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver2.sys
22:01:54.0491 5928 AODDriver4.1 - ok
22:01:54.0502 5928 AODService (419dfc4fcf642a3d8d9794c15fca92fd) C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe
22:01:54.0508 5928 AODService - ok
22:01:54.0512 5928 Apache2.2 (53ea061ecc67223a430f153c3682ad54) C:\xampp\apache\bin\httpd.exe
22:01:54.0516 5928 Apache2.2 ( UnsignedFile.Multi.Generic ) - warning
22:01:54.0516 5928 Apache2.2 - detected UnsignedFile.Multi.Generic (1)
22:01:54.0520 5928 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:01:54.0535 5928 AppID - ok
22:01:54.0540 5928 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:01:54.0563 5928 AppIDSvc - ok
22:01:54.0574 5928 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:01:54.0598 5928 Appinfo - ok
22:01:54.0602 5928 AppleCharger (6be11ad81d4527d299f0cb5f3731aabc) C:\Windows\system32\DRIVERS\AppleCharger.sys
22:01:54.0610 5928 AppleCharger - ok
22:01:54.0615 5928 AppleChargerSrv (95ef7247c50c7241fdae39a9b3aff4ae) C:\Windows\system32\AppleChargerSrv.exe
22:01:54.0623 5928 AppleChargerSrv - ok
22:01:54.0638 5928 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
22:01:54.0646 5928 AppMgmt - ok
22:01:54.0657 5928 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:01:54.0667 5928 arc - ok
22:01:54.0675 5928 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:01:54.0686 5928 arcsas - ok
22:01:54.0706 5928 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:01:54.0711 5928 aspnet_state - ok
22:01:54.0715 5928 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:01:54.0741 5928 AsyncMac - ok
22:01:54.0745 5928 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:01:54.0749 5928 atapi - ok
22:01:54.0764 5928 atksgt (09149d03629a44f4773e621c432d1d89) C:\Windows\system32\DRIVERS\atksgt.sys
22:01:54.0779 5928 atksgt - ok
22:01:54.0801 5928 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:01:54.0832 5928 AudioEndpointBuilder - ok
22:01:54.0837 5928 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:01:54.0864 5928 AudioSrv - ok
22:01:54.0874 5928 avgntflt (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
22:01:54.0880 5928 avgntflt - ok
22:01:54.0892 5928 avipbb (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
22:01:54.0898 5928 avipbb - ok
22:01:54.0903 5928 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
22:01:54.0908 5928 avkmgr - ok
22:01:54.0914 5928 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:01:54.0925 5928 AxInstSV - ok
22:01:54.0944 5928 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:01:54.0965 5928 b06bdrv - ok
22:01:54.0979 5928 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:01:54.0995 5928 b57nd60a - ok
22:01:55.0012 5928 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:01:55.0019 5928 BDESVC - ok
22:01:55.0021 5928 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:01:55.0046 5928 Beep - ok
22:01:55.0050 5928 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:01:55.0062 5928 blbdrive - ok
22:01:55.0072 5928 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys
22:01:55.0099 5928 bowser - ok
22:01:55.0103 5928 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:01:55.0114 5928 BrFiltLo - ok
22:01:55.0117 5928 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:01:55.0127 5928 BrFiltUp - ok
22:01:55.0140 5928 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:01:55.0164 5928 Browser - ok
22:01:55.0173 5928 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:01:55.0189 5928 Brserid - ok
22:01:55.0198 5928 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:01:55.0210 5928 BrSerWdm - ok
22:01:55.0213 5928 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:01:55.0225 5928 BrUsbMdm - ok
22:01:55.0228 5928 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:01:55.0237 5928 BrUsbSer - ok
22:01:55.0247 5928 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:01:55.0260 5928 BTHMODEM - ok
22:01:55.0272 5928 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:01:55.0296 5928 bthserv - ok
22:01:55.0307 5928 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:01:55.0333 5928 cdfs - ok
22:01:55.0340 5928 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:01:55.0353 5928 cdrom - ok
22:01:55.0365 5928 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:01:55.0387 5928 CertPropSvc - ok
22:01:55.0394 5928 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:01:55.0407 5928 circlass - ok
22:01:55.0422 5928 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:01:55.0432 5928 CLFS - ok
22:01:55.0445 5928 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:01:55.0450 5928 clr_optimization_v2.0.50727_32 - ok
22:01:55.0461 5928 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:01:55.0466 5928 clr_optimization_v2.0.50727_64 - ok
22:01:55.0488 5928 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:01:55.0494 5928 clr_optimization_v4.0.30319_32 - ok
22:01:55.0513 5928 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:01:55.0519 5928 clr_optimization_v4.0.30319_64 - ok
22:01:55.0523 5928 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:01:55.0532 5928 CmBatt - ok
22:01:55.0536 5928 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:01:55.0543 5928 cmdide - ok
22:01:55.0561 5928 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
22:01:55.0590 5928 CNG - ok
22:01:55.0594 5928 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:01:55.0602 5928 Compbatt - ok
22:01:55.0608 5928 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:01:55.0620 5928 CompositeBus - ok
22:01:55.0622 5928 COMSysApp - ok
22:01:55.0627 5928 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:01:55.0635 5928 crcdisk - ok
22:01:55.0648 5928 CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
22:01:55.0672 5928 CryptSvc - ok
22:01:55.0690 5928 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
22:01:55.0712 5928 CSC - ok
22:01:55.0734 5928 CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
22:01:55.0751 5928 CscService - ok
22:01:55.0770 5928 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:01:55.0801 5928 DcomLaunch - ok
22:01:55.0814 5928 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:01:55.0840 5928 defragsvc - ok
22:01:55.0852 5928 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
22:01:55.0875 5928 DfsC - ok
22:01:55.0890 5928 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:01:55.0915 5928 Dhcp - ok
22:01:55.0921 5928 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:01:55.0944 5928 discache - ok
22:01:55.0955 5928 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:01:55.0965 5928 Disk - ok
22:01:55.0978 5928 Dnscache (676108c4e3aa6f6b34633748bd0bebd9) C:\Windows\System32\dnsrslvr.dll
22:01:56.0010 5928 Dnscache - ok
22:01:56.0022 5928 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:01:56.0047 5928 dot3svc - ok
22:01:56.0059 5928 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:01:56.0089 5928 DPS - ok
22:01:56.0092 5928 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:01:56.0102 5928 drmkaud - ok
22:01:56.0125 5928 DXGKrnl (7cb7d2b73813ce05c7bc0f5f95d27cec) C:\Windows\System32\drivers\dxgkrnl.sys
22:01:56.0167 5928 DXGKrnl - ok
22:01:56.0178 5928 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:01:56.0201 5928 EapHost - ok
22:01:56.0280 5928 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:01:56.0337 5928 ebdrv - ok
22:01:56.0371 5928 EFS (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe
22:01:56.0379 5928 EFS - ok
22:01:56.0402 5928 ehRecvr (b91d81b3b54a54ccafc03733dbc2e29e) C:\Windows\ehome\ehRecvr.exe
22:01:56.0419 5928 ehRecvr - ok
22:01:56.0432 5928 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:01:56.0440 5928 ehSched - ok
22:01:56.0446 5928 ekrn - ok
22:01:56.0458 5928 ElbyCDIO (a05fc7eca0966ebb70e4d17b855a853b) C:\Windows\system32\Drivers\ElbyCDIO.sys
22:01:56.0467 5928 ElbyCDIO - ok
22:01:56.0489 5928 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:01:56.0508 5928 elxstor - ok
22:01:56.0511 5928 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:01:56.0520 5928 ErrDev - ok
22:01:56.0526 5928 EtronHub3 (3663291d0d26001a2bb67678ab61d14c) C:\Windows\system32\Drivers\EtronHub3.sys
22:01:56.0535 5928 EtronHub3 - ok
22:01:56.0540 5928 EtronXHCI (744420d6c062c38f7361870f010d6d4b) C:\Windows\system32\Drivers\EtronXHCI.sys
22:01:56.0548 5928 EtronXHCI - ok
22:01:56.0566 5928 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:01:56.0594 5928 EventSystem - ok
22:01:56.0604 5928 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:01:56.0634 5928 exfat - ok
22:01:56.0642 5928 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:01:56.0674 5928 fastfat - ok
22:01:56.0696 5928 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:01:56.0714 5928 Fax - ok
22:01:56.0719 5928 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:01:56.0729 5928 fdc - ok
22:01:56.0733 5928 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:01:56.0756 5928 fdPHost - ok
22:01:56.0762 5928 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:01:56.0784 5928 FDResPub - ok
22:01:56.0795 5928 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:01:56.0800 5928 FileInfo - ok
22:01:56.0806 5928 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:01:56.0828 5928 Filetrace - ok
22:01:56.0863 5928 FLEXnet Licensing Service 64 (5cee6cd43ae5844c49300ea0b1e557ee) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
22:01:56.0889 5928 FLEXnet Licensing Service 64 - ok
22:01:56.0927 5928 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:01:56.0936 5928 flpydisk - ok
22:01:56.0946 5928 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:01:56.0956 5928 FltMgr - ok
22:01:56.0987 5928 FontCache (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
22:01:57.0023 5928 FontCache - ok
22:01:57.0030 5928 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:01:57.0034 5928 FontCache3.0.0.0 - ok
22:01:57.0047 5928 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:01:57.0051 5928 FsDepends - ok
22:01:57.0055 5928 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
22:01:57.0063 5928 Fs_Rec - ok
22:01:57.0077 5928 fvevol (b8b2a6e1558f8f5de5ce431c5b2c7b09) C:\Windows\system32\DRIVERS\fvevol.sys
22:01:57.0085 5928 fvevol - ok
22:01:57.0090 5928 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:01:57.0099 5928 gagp30kx - ok
22:01:57.0122 5928 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:01:57.0146 5928 gpsvc - ok
22:01:57.0162 5928 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:01:57.0166 5928 gupdate - ok
22:01:57.0169 5928 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:01:57.0173 5928 gupdatem - ok
22:01:57.0178 5928 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:01:57.0188 5928 hcw85cir - ok
22:01:57.0204 5928 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:01:57.0225 5928 HdAudAddService - ok
22:01:57.0237 5928 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:01:57.0248 5928 HDAudBus - ok
22:01:57.0252 5928 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:01:57.0262 5928 HidBatt - ok
22:01:57.0274 5928 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:01:57.0287 5928 HidBth - ok
22:01:57.0294 5928 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:01:57.0307 5928 HidIr - ok
22:01:57.0312 5928 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:01:57.0335 5928 hidserv - ok
22:01:57.0341 5928 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:01:57.0351 5928 HidUsb - ok
22:01:57.0362 5928 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:01:57.0385 5928 hkmsvc - ok
22:01:57.0397 5928 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:01:57.0406 5928 HomeGroupListener - ok
22:01:57.0418 5928 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:01:57.0426 5928 HomeGroupProvider - ok
22:01:57.0437 5928 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:01:57.0447 5928 HpSAMD - ok
22:01:57.0468 5928 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:01:57.0502 5928 HTTP - ok
22:01:57.0506 5928 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:01:57.0511 5928 hwpolicy - ok
22:01:57.0521 5928 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:01:57.0534 5928 i8042prt - ok
22:01:57.0549 5928 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
22:01:57.0566 5928 iaStorV - ok
22:01:57.0593 5928 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:01:57.0612 5928 idsvc - ok
22:01:57.0619 5928 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:01:57.0628 5928 iirsp - ok
22:01:57.0656 5928 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:01:57.0690 5928 IKEEXT - ok
22:01:57.0695 5928 imhidusb (7f7313e8bc26ba77440ed1370b613870) C:\Windows\system32\DRIVERS\imhidusb.sys
22:01:57.0703 5928 imhidusb - ok
22:01:57.0771 5928 IntcAzAudAddService (9297bc7fb61f58670ee176dd18f4dd92) C:\Windows\system32\drivers\RTKVHD64.sys
22:01:57.0836 5928 IntcAzAudAddService - ok
22:01:57.0874 5928 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:01:57.0882 5928 intelide - ok
22:01:57.0891 5928 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:01:57.0903 5928 intelppm - ok
22:01:57.0916 5928 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:01:57.0939 5928 IPBusEnum - ok
22:01:57.0950 5928 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:01:57.0977 5928 IpFilterDriver - ok
22:01:57.0989 5928 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:01:58.0001 5928 IPMIDRV - ok
22:01:58.0012 5928 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:01:58.0039 5928 IPNAT - ok
22:01:58.0043 5928 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:01:58.0051 5928 IRENUM - ok
22:01:58.0055 5928 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:01:58.0063 5928 isapnp - ok
22:01:58.0075 5928 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:01:58.0090 5928 iScsiPrt - ok
22:01:58.0099 5928 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:01:58.0109 5928 kbdclass - ok
22:01:58.0114 5928 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:01:58.0125 5928 kbdhid - ok
22:01:58.0130 5928 KeyIso (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:01:58.0137 5928 KeyIso - ok
22:01:58.0147 5928 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
22:01:58.0158 5928 KSecDD - ok
22:01:58.0169 5928 KSecPkg (bbe1bf6d9b661c354d4857d5fadb943b) C:\Windows\system32\Drivers\ksecpkg.sys
22:01:58.0182 5928 KSecPkg - ok
22:01:58.0186 5928 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:01:58.0211 5928 ksthunk - ok
22:01:58.0222 5928 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:01:58.0258 5928 KtmRm - ok
22:01:58.0270 5928 LanmanServer (c926920b8978de6acfe9e15c709e9b57) C:\Windows\system32\srvsvc.dll
22:01:58.0295 5928 LanmanServer - ok
22:01:58.0301 5928 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:01:58.0325 5928 LanmanWorkstation - ok
22:01:58.0334 5928 lirsgt (5ea407821bb3104c31a705175ab4f309) C:\Windows\system32\DRIVERS\lirsgt.sys
22:01:58.0342 5928 lirsgt - ok
22:01:58.0352 5928 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:01:58.0378 5928 lltdio - ok
22:01:58.0394 5928 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:01:58.0427 5928 lltdsvc - ok
22:01:58.0431 5928 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:01:58.0454 5928 lmhosts - ok
22:01:58.0465 5928 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:01:58.0476 5928 LSI_FC - ok
22:01:58.0487 5928 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:01:58.0498 5928 LSI_SAS - ok
22:01:58.0509 5928 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:01:58.0518 5928 LSI_SAS2 - ok
22:01:58.0531 5928 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:01:58.0542 5928 LSI_SCSI - ok
22:01:58.0552 5928 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:01:58.0575 5928 luafv - ok
22:01:58.0589 5928 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:01:58.0601 5928 Mcx2Svc - ok
22:01:58.0607 5928 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:01:58.0615 5928 megasas - ok
22:01:58.0630 5928 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:01:58.0646 5928 MegaSR - ok
22:01:58.0654 5928 Microsoft SharePoint Workspace Audit Service - ok
22:01:58.0678 5928 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:01:58.0701 5928 MMCSS - ok
22:01:58.0707 5928 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:01:58.0733 5928 Modem - ok
22:01:58.0738 5928 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:01:58.0748 5928 monitor - ok
22:01:58.0756 5928 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:01:58.0765 5928 mouclass - ok
22:01:58.0770 5928 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:01:58.0780 5928 mouhid - ok
22:01:58.0789 5928 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:01:58.0795 5928 mountmgr - ok
22:01:58.0810 5928 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:01:58.0816 5928 MozillaMaintenance - ok
22:01:58.0822 5928 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:01:58.0835 5928 mpio - ok
22:01:58.0847 5928 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:01:58.0873 5928 mpsdrv - ok
22:01:58.0884 5928 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:01:58.0901 5928 MRxDAV - ok
22:01:58.0912 5928 mrxsmb (cfdcd8ca87c2a657debc150ac35b5e08) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:01:58.0942 5928 mrxsmb - ok
22:01:58.0956 5928 mrxsmb10 (1bee517b220b7f024f411aec1571dd5a) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:01:58.0989 5928 mrxsmb10 - ok
22:01:59.0001 5928 mrxsmb20 (6b2d5fef385828b6e485c1c90afb8195) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:01:59.0029 5928 mrxsmb20 - ok
22:01:59.0034 5928 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:01:59.0043 5928 msahci - ok
22:01:59.0053 5928 MsDepSvc (aaac4b494de45836121a40aec980b631) C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe
22:01:59.0059 5928 MsDepSvc - ok
22:01:59.0072 5928 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:01:59.0083 5928 msdsm - ok
22:01:59.0099 5928 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:01:59.0113 5928 MSDTC - ok
22:01:59.0121 5928 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:01:59.0146 5928 Msfs - ok
22:01:59.0149 5928 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:01:59.0171 5928 mshidkmdf - ok
22:01:59.0176 5928 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:01:59.0183 5928 msisadrv - ok
22:01:59.0194 5928 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:01:59.0223 5928 MSiSCSI - ok
22:01:59.0226 5928 msiserver - ok
22:01:59.0230 5928 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:01:59.0255 5928 MSKSSRV - ok
22:01:59.0257 5928 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:01:59.0282 5928 MSPCLOCK - ok
22:01:59.0285 5928 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:01:59.0309 5928 MSPQM - ok
22:01:59.0324 5928 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:01:59.0340 5928 MsRPC - ok
22:01:59.0349 5928 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:01:59.0354 5928 mssmbios - ok
22:01:59.0358 5928 MSSQL$SQLEXPRESS - ok
22:01:59.0366 5928 MSSQLSERVER - ok
22:01:59.0372 5928 MSSQLServerADHelper100 (8e8e74c953eb0c4f8828d99d6f27fd6f) C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
22:01:59.0377 5928 MSSQLServerADHelper100 - ok
22:01:59.0380 5928 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:01:59.0404 5928 MSTEE - ok
22:01:59.0408 5928 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:01:59.0422 5928 MTConfig - ok
22:01:59.0432 5928 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:01:59.0436 5928 Mup - ok
22:01:59.0454 5928 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:01:59.0483 5928 napagent - ok
22:01:59.0501 5928 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:01:59.0522 5928 NativeWifiP - ok
22:01:59.0548 5928 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:01:59.0569 5928 NDIS - ok
22:01:59.0575 5928 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:01:59.0601 5928 NdisCap - ok
22:01:59.0605 5928 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:01:59.0631 5928 NdisTapi - ok
22:01:59.0639 5928 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:01:59.0667 5928 Ndisuio - ok
22:01:59.0681 5928 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:01:59.0711 5928 NdisWan - ok
22:01:59.0720 5928 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:01:59.0747 5928 NDProxy - ok
22:01:59.0754 5928 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:01:59.0780 5928 NetBIOS - ok
22:01:59.0792 5928 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:01:59.0817 5928 NetBT - ok
22:01:59.0822 5928 Netlogon (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:01:59.0830 5928 Netlogon - ok
22:01:59.0846 5928 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:01:59.0873 5928 Netman - ok
22:01:59.0890 5928 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:01:59.0896 5928 NetMsmqActivator - ok
22:01:59.0898 5928 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:01:59.0903 5928 NetPipeActivator - ok
22:01:59.0919 5928 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:01:59.0947 5928 netprofm - ok
22:01:59.0950 5928 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:01:59.0955 5928 NetTcpActivator - ok
22:01:59.0957 5928 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:01:59.0962 5928 NetTcpPortSharing - ok
22:01:59.0975 5928 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:01:59.0984 5928 nfrd960 - ok
22:01:59.0998 5928 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:02:00.0024 5928 NlaSvc - ok
22:02:00.0029 5928 nmwcd (907b5e1e4a592e5edc5e4ccbde4863c2) C:\Windows\system32\drivers\ccdcmbx64.sys
22:02:00.0047 5928 nmwcd - ok
22:02:00.0051 5928 nmwcdc (41c1ac1f3613435eb32d67bcb80a5fa5) C:\Windows\system32\drivers\ccdcmbox64.sys
22:02:00.0070 5928 nmwcdc - ok
22:02:00.0077 5928 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:02:00.0103 5928 Npfs - ok
22:02:00.0107 5928 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:02:00.0131 5928 nsi - ok
22:02:00.0134 5928 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:02:00.0157 5928 nsiproxy - ok
22:02:00.0203 5928 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
22:02:00.0234 5928 Ntfs - ok
22:02:00.0271 5928 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:02:00.0296 5928 Null - ok
22:02:00.0303 5928 NVHDA (f2662fdc20518ee8a8eed4f61ba42349) C:\Windows\system32\drivers\nvhda64v.sys
22:02:00.0315 5928 NVHDA - ok
22:02:00.0604 5928 nvlddmkm (d4c1b02d7d5566b5bf29fd3a1177c92b) C:\Windows\system32\DRIVERS\nvlddmkm.sys
22:02:00.0818 5928 nvlddmkm - ok
22:02:00.0864 5928 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
22:02:00.0875 5928 nvraid - ok
22:02:00.0882 5928 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
22:02:00.0894 5928 nvstor - ok
22:02:00.0919 5928 NVSvc (35523e0423a1bc2fae09a4023900d7a0) C:\Windows\system32\nvvsvc.exe
22:02:00.0940 5928 NVSvc - ok
22:02:00.0994 5928 nvUpdatusService (28e70e88a949077c4ee286869262907b) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
22:02:01.0018 5928 nvUpdatusService - ok
22:02:01.0061 5928 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:02:01.0073 5928 nv_agp - ok
22:02:01.0084 5928 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:02:01.0096 5928 ohci1394 - ok
22:02:01.0112 5928 ose64 (4965b005492cba7719e82b71e3245495) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:02:01.0119 5928 ose64 - ok
22:02:01.0235 5928 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
22:02:01.0313 5928 osppsvc - ok
22:02:01.0359 5928 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:02:01.0370 5928 p2pimsvc - ok
22:02:01.0387 5928 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:02:01.0398 5928 p2psvc - ok
22:02:01.0413 5928 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:02:01.0425 5928 Parport - ok
22:02:01.0437 5928 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
22:02:01.0443 5928 partmgr - ok
22:02:01.0456 5928 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:02:01.0468 5928 PcaSvc - ok
22:02:01.0476 5928 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:02:01.0490 5928 pci - ok
22:02:01.0493 5928 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:02:01.0501 5928 pciide - ok
22:02:01.0508 5928 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:02:01.0523 5928 pcmcia - ok
22:02:01.0531 5928 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:02:01.0540 5928 pcw - ok
22:02:01.0557 5928 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:02:01.0599 5928 PEAUTH - ok
22:02:01.0636 5928 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
22:02:01.0661 5928 PeerDistSvc - ok
22:02:01.0699 5928 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:02:01.0707 5928 PerfHost - ok
22:02:01.0779 5928 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:02:01.0820 5928 pla - ok
22:02:01.0836 5928 PlugPlay (23157d583244400e1d7fbaee2e4b31b7) C:\Windows\system32\umpnpmgr.dll
22:02:01.0865 5928 PlugPlay - ok
22:02:01.0868 5928 PnkBstrA - ok
22:02:01.0871 5928 PnkBstrB - ok
22:02:01.0877 5928 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:02:01.0884 5928 PNRPAutoReg - ok
22:02:01.0897 5928 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:02:01.0905 5928 PNRPsvc - ok
22:02:01.0926 5928 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:02:01.0964 5928 PolicyAgent - ok
22:02:01.0977 5928 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:02:02.0002 5928 Power - ok
22:02:02.0016 5928 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:02:02.0046 5928 PptpMiniport - ok
22:02:02.0055 5928 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:02:02.0067 5928 Processor - ok
22:02:02.0081 5928 ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
22:02:02.0107 5928 ProfSvc - ok
22:02:02.0113 5928 ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:02:02.0120 5928 ProtectedStorage - ok
22:02:02.0132 5928 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:02:02.0155 5928 Psched - ok
22:02:02.0197 5928 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:02:02.0235 5928 ql2300 - ok
22:02:02.0282 5928 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:02:02.0294 5928 ql40xx - ok
22:02:02.0307 5928 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:02:02.0319 5928 QWAVE - ok
22:02:02.0326 5928 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:02:02.0335 5928 QWAVEdrv - ok
22:02:02.0338 5928 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:02:02.0364 5928 RasAcd - ok
22:02:02.0374 5928 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:02:02.0400 5928 RasAgileVpn - ok
22:02:02.0412 5928 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:02:02.0435 5928 RasAuto - ok
22:02:02.0448 5928 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:02:02.0477 5928 Rasl2tp - ok
22:02:02.0491 5928 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:02:02.0518 5928 RasMan - ok
22:02:02.0530 5928 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:02:02.0558 5928 RasPppoe - ok
22:02:02.0571 5928 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:02:02.0599 5928 RasSstp - ok
22:02:02.0613 5928 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:02:02.0648 5928 rdbss - ok
22:02:02.0652 5928 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:02:02.0664 5928 rdpbus - ok
22:02:02.0667 5928 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:02:02.0690 5928 RDPCDD - ok
22:02:02.0704 5928 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
22:02:02.0717 5928 RDPDR - ok
22:02:02.0720 5928 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:02:02.0743 5928 RDPENCDD - ok
22:02:02.0747 5928 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:02:02.0769 5928 RDPREFMP - ok
22:02:02.0776 5928 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
22:02:02.0807 5928 RDPWD - ok
22:02:02.0818 5928 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
22:02:02.0833 5928 rdyboost - ok
22:02:02.0845 5928 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:02:02.0869 5928 RemoteAccess - ok
22:02:02.0881 5928 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:02:02.0905 5928 RemoteRegistry - ok
22:02:02.0916 5928 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:02:02.0939 5928 RpcEptMapper - ok
22:02:02.0942 5928 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:02:02.0949 5928 RpcLocator - ok
22:02:02.0967 5928 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:02:02.0993 5928 RpcSs - ok
22:02:03.0008 5928 RsFx0103 (cd553b8633466a6d1c115812f2619f1f) C:\Windows\system32\DRIVERS\RsFx0103.sys
22:02:03.0024 5928 RsFx0103 - ok
22:02:03.0037 5928 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:02:03.0064 5928 rspndr - ok
22:02:03.0079 5928 RTL8167 (6d3c7e7d82d3dc92dc2a8b0df9f20f8a) C:\Windows\system32\DRIVERS\Rt64win7.sys
22:02:03.0094 5928 RTL8167 - ok
22:02:03.0097 5928 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
22:02:03.0105 5928 s3cap - ok
22:02:03.0110 5928 SamSs (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:02:03.0117 5928 SamSs - ok
22:02:03.0129 5928 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:02:03.0140 5928 sbp2port - ok
22:02:03.0154 5928 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:02:03.0179 5928 SCardSvr - ok
22:02:03.0211 5928 SCBackService (8475e746eb72d04f1015e6f091f50e09) C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe
22:02:03.0219 5928 SCBackService - ok
22:02:03.0224 5928 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:02:03.0247 5928 scfilter - ok
22:02:03.0281 5928 Schedule (ec56b171f85c7e855e7b0588ac503eea) C:\Windows\system32\schedsvc.dll
22:02:03.0316 5928 Schedule - ok
22:02:03.0329 5928 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:02:03.0351 5928 SCPolicySvc - ok
22:02:03.0362 5928 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:02:03.0371 5928 SDRSVC - ok
22:02:03.0379 5928 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:02:03.0404 5928 secdrv - ok
22:02:03.0410 5928 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:02:03.0433 5928 seclogon - ok
22:02:03.0442 5928 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:02:03.0466 5928 SENS - ok
22:02:03.0470 5928 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:02:03.0478 5928 SensrSvc - ok
22:02:03.0482 5928 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:02:03.0492 5928 Serenum - ok
22:02:03.0501 5928 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:02:03.0513 5928 Serial - ok
22:02:03.0517 5928 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:02:03.0527 5928 sermouse - ok
22:02:03.0545 5928 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:02:03.0569 5928 SessionEnv - ok
22:02:03.0573 5928 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:02:03.0583 5928 sffdisk - ok
22:02:03.0586 5928 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:02:03.0598 5928 sffp_mmc - ok
22:02:03.0601 5928 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:02:03.0612 5928 sffp_sd - ok
22:02:03.0615 5928 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:02:03.0624 5928 sfloppy - ok
22:02:03.0641 5928 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:02:03.0654 5928 ShellHWDetection - ok
22:02:03.0661 5928 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:02:03.0670 5928 SiSRaid2 - ok
22:02:03.0680 5928 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:02:03.0690 5928 SiSRaid4 - ok
22:02:03.0702 5928 SkypeUpdate (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:02:03.0708 5928 SkypeUpdate - ok
22:02:03.0720 5928 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:02:03.0748 5928 Smb - ok
22:02:03.0754 5928 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:02:03.0762 5928 SNMPTRAP - ok
22:02:03.0797 5928 speedfan (12583af6cbe0050651eaf2723b3ad7b3) C:\Windows\syswow64\speedfan.sys
22:02:03.0805 5928 speedfan - ok
22:02:03.0809 5928 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:02:03.0817 5928 spldr - ok
22:02:03.0835 5928 Spooler (89e8550c5862999fcf482ea562b0e98e) C:\Windows\System32\spoolsv.exe
22:02:03.0851 5928 Spooler - ok
22:02:03.0933 5928 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:02:03.0984 5928 sppsvc - ok
22:02:04.0021 5928 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:02:04.0044 5928 sppuinotify - ok
22:02:04.0064 5928 SQLAgent$SQLEXPRESS (12e6d95cde974b131defaa44bab8b056) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
22:02:04.0076 5928 SQLAgent$SQLEXPRESS - ok
22:02:04.0091 5928 SQLBrowser (7d67c07c63796775cc5492bcfeaff125) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
22:02:04.0100 5928 SQLBrowser - ok
22:02:04.0116 5928 SQLSERVERAGENT (37761f6be2ebaed72cc0d43bd4c8c2a6) C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS10\MSSQL\Binn\SQLAGENT.EXE
22:02:04.0127 5928 SQLSERVERAGENT - ok
22:02:04.0133 5928 SQLWriter (f98ddfbfe0ee66d4c4b00693512b9527) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
22:02:04.0140 5928 SQLWriter - ok
22:02:04.0190 5928 srv (ec8f67289105bf270498095f14963464) C:\Windows\system32\DRIVERS\srv.sys
22:02:04.0225 5928 srv - ok
22:02:04.0242 5928 srv2 (f773d2ed090b7baa1c1a034f3ca476c8) C:\Windows\system32\DRIVERS\srv2.sys
22:02:04.0280 5928 srv2 - ok
22:02:04.0292 5928 srvnet (26e84d3649019c3244622e654dfcd75b) C:\Windows\system32\DRIVERS\srvnet.sys
22:02:04.0323 5928 srvnet - ok
22:02:04.0336 5928 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:02:04.0361 5928 SSDPSRV - ok
22:02:04.0373 5928 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:02:04.0396 5928 SstpSvc - ok
22:02:04.0412 5928 Stereo Service (284303d0b36d7825851a8ad752439e3b) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
22:02:04.0418 5928 Stereo Service - ok
22:02:04.0423 5928 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:02:04.0431 5928 stexstor - ok
22:02:04.0452 5928 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:02:04.0481 5928 stisvc - ok
22:02:04.0489 5928 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
22:02:04.0498 5928 storflt - ok
22:02:04.0502 5928 StorSvc (c40841817ef57d491f22eb103da587cc) C:\Windows\system32\storsvc.dll
22:02:04.0509 5928 StorSvc - ok
22:02:04.0515 5928 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
22:02:04.0524 5928 storvsc - ok
22:02:04.0527 5928 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:02:04.0534 5928 swenum - ok
22:02:04.0552 5928 SwitchBoard (f577910a133a592234ebaad3f3afa258) C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
22:02:04.0566 5928 SwitchBoard ( UnsignedFile.Multi.Generic ) - warning
22:02:04.0566 5928 SwitchBoard - detected UnsignedFile.Multi.Generic (1)
22:02:04.0581 5928 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:02:04.0610 5928 swprv - ok
22:02:04.0656 5928 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:02:04.0686 5928 SysMain - ok
22:02:04.0727 5928 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:02:04.0738 5928 TabletInputService - ok
22:02:04.0753 5928 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:02:04.0780 5928 TapiSrv - ok
22:02:04.0791 5928 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:02:04.0814 5928 TBS - ok
22:02:04.0866 5928 Tcpip (7fc877a25796d8adf539e64703fca7e1) C:\Windows\system32\drivers\tcpip.sys
22:02:04.0898 5928 Tcpip - ok
22:02:04.0979 5928 TCPIP6 (7fc877a25796d8adf539e64703fca7e1) C:\Windows\system32\DRIVERS\tcpip.sys
22:02:05.0002 5928 TCPIP6 - ok
22:02:05.0047 5928 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:02:05.0073 5928 tcpipreg - ok
22:02:05.0078 5928 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:02:05.0103 5928 TDPIPE - ok
22:02:05.0107 5928 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
22:02:05.0132 5928 TDTCP - ok
22:02:05.0144 5928 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:02:05.0171 5928 tdx - ok
22:02:05.0239 5928 TeamViewer6 (01a402d34732ca3da91786adcc765069) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
22:02:05.0267 5928 TeamViewer6 - ok
22:02:05.0306 5928 teamviewervpn (f5520dbb47c60ee83024b38720abda24) C:\Windows\system32\DRIVERS\teamviewervpn.sys
22:02:05.0314 5928 teamviewervpn - ok
22:02:05.0323 5928 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:02:05.0332 5928 TermDD - ok
22:02:05.0355 5928 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:02:05.0389 5928 TermService - ok
22:02:05.0394 5928 Themes (9201be2bab8a9ff8e20d8439ae3bb04d) C:\Windows\system32\themeservice.dll
22:02:05.0397 5928 Themes ( UnsignedFile.Multi.Generic ) - warning
22:02:05.0397 5928 Themes - detected UnsignedFile.Multi.Generic (1)
22:02:05.0407 5928 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:02:05.0430 5928 THREADORDER - ok
22:02:05.0441 5928 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:02:05.0465 5928 TrkWks - ok
22:02:05.0475 5928 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:02:05.0484 5928 TrustedInstaller - ok
22:02:05.0492 5928 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:02:05.0515 5928 tssecsrv - ok
22:02:05.0527 5928 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:02:05.0556 5928 tunnel - ok
22:02:05.0566 5928 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:02:05.0576 5928 uagp35 - ok
22:02:05.0590 5928 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:02:05.0623 5928 udfs - ok
22:02:05.0630 5928 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:02:05.0638 5928 UI0Detect - ok
22:02:05.0648 5928 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:02:05.0658 5928 uliagpkx - ok
22:02:05.0665 5928 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:02:05.0677 5928 umbus - ok
22:02:05.0680 5928 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:02:05.0689 5928 UmPass - ok
22:02:05.0700 5928 UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
22:02:05.0710 5928 UmRdpService - ok
22:02:05.0725 5928 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:02:05.0752 5928 upnphost - ok
22:02:05.0756 5928 upperdev (4e93c8496359e97830c75ac36393654d) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
22:02:05.0773 5928 upperdev - ok
22:02:05.0788 5928 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:02:05.0799 5928 usbccgp - ok
22:02:05.0812 5928 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:02:05.0827 5928 usbcir - ok
22:02:05.0835 5928 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
22:02:05.0845 5928 usbehci - ok
22:02:05.0860 5928 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
22:02:05.0879 5928 usbhub - ok
22:02:05.0884 5928 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:02:05.0894 5928 usbohci - ok
22:02:05.0898 5928 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:02:05.0910 5928 usbprint - ok
22:02:05.0913 5928 usbser (0f0c72a657c622286013788b886968ad) C:\Windows\system32\drivers\usbser.sys
22:02:05.0924 5928 usbser - ok
22:02:05.0927 5928 UsbserFilt (8844cb19a37b65e27049d4a7786726a9) C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
22:02:05.0944 5928 UsbserFilt - ok
22:02:05.0956 5928 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:02:05.0968 5928 USBSTOR - ok
22:02:05.0973 5928 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:02:05.0982 5928 usbuhci - ok
22:02:05.0988 5928 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:02:06.0016 5928 UxSms - ok
22:02:06.0021 5928 VaultSvc (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:02:06.0028 5928 VaultSvc - ok
22:02:06.0042 5928 VBoxDrv (c30f3d43ceb6f79ade9b805387e5f63c) C:\Windows\system32\DRIVERS\VBoxDrv.sys
22:02:06.0058 5928 VBoxDrv - ok
22:02:06.0071 5928 VBoxNetAdp (8acf22b86ce4e85c23e3e9513bf45c37) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
22:02:06.0082 5928 VBoxNetAdp - ok
22:02:06.0089 5928 VBoxNetFlt (7b657669c53a0e6583f07ebaa303d9ea) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys
22:02:06.0101 5928 VBoxNetFlt - ok
22:02:06.0112 5928 VBoxUSBMon (cf3ee68cd9723e9f21e3198a0f690400) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
22:02:06.0123 5928 VBoxUSBMon - ok
22:02:06.0129 5928 VClone (fd911873c0bb6945fa38c16e9a2b58f9) C:\Windows\system32\DRIVERS\VClone.sys
22:02:06.0139 5928 VClone - ok
22:02:06.0146 5928 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:02:06.0155 5928 vdrvroot - ok
22:02:06.0169 5928 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:02:06.0185 5928 vds - ok
22:02:06.0190 5928 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:02:06.0201 5928 vga - ok
22:02:06.0206 5928 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:02:06.0232 5928 VgaSave - ok
22:02:06.0246 5928 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:02:06.0262 5928 vhdmp - ok
22:02:06.0265 5928 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:02:06.0273 5928 viaide - ok
22:02:06.0281 5928 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
22:02:06.0295 5928 vmbus - ok
22:02:06.0299 5928 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
22:02:06.0309 5928 VMBusHID - ok
22:02:06.0319 5928 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:02:06.0329 5928 volmgr - ok
22:02:06.0344 5928 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:02:06.0353 5928 volmgrx - ok
22:02:06.0368 5928 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:02:06.0379 5928 volsnap - ok
22:02:06.0386 5928 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\Windows\system32\DRIVERS\vpchbus.sys
22:02:06.0400 5928 vpcbus - ok
22:02:06.0405 5928 vpcnfltr (8acda395841538ce9713a67fe8b2a3eb) C:\Windows\system32\DRIVERS\vpcnfltr.sys
22:02:06.0415 5928 vpcnfltr - ok
22:02:06.0425 5928 vpcusb (31924e31bc315773e6d149b157db46d5) C:\Windows\system32\DRIVERS\vpcusb.sys
22:02:06.0437 5928 vpcusb - ok
22:02:06.0454 5928 vpcvmm (510d250a08c09850f5c78ca2011b3b62) C:\Windows\system32\drivers\vpcvmm.sys
22:02:06.0465 5928 vpcvmm - ok
22:02:06.0479 5928 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:02:06.0491 5928 vsmraid - ok
22:02:06.0534 5928 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:02:06.0563 5928 VSS - ok
22:02:06.0602 5928 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
22:02:06.0610 5928 vwifibus - ok
22:02:06.0624 5928 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:02:06.0653 5928 W32Time - ok
22:02:06.0663 5928 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:02:06.0675 5928 WacomPen - ok
22:02:06.0686 5928 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:02:06.0714 5928 WANARP - ok
22:02:06.0716 5928 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:02:06.0740 5928 Wanarpv6 - ok
22:02:06.0771 5928 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
22:02:06.0813 5928 WatAdminSvc - ok
22:02:06.0852 5928 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:02:06.0878 5928 wbengine - ok
22:02:06.0921 5928 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:02:06.0933 5928 WbioSrvc - ok
22:02:06.0947 5928 wcncsvc (8321c2ca3b62b61b293cda3451984468) C:\Windows\System32\wcncsvc.dll
22:02:06.0962 5928 wcncsvc - ok
22:02:06.0966 5928 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:02:06.0973 5928 WcsPlugInService - ok
22:02:07.0000 5928 WCUService_STC_FF (e47e66538692b1cfd6cc8021546fcc83) C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe
22:02:07.0008 5928 WCUService_STC_FF - ok
22:02:07.0017 5928 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:02:07.0025 5928 Wd - ok
22:02:07.0042 5928 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:02:07.0066 5928 Wdf01000 - ok
22:02:07.0077 5928 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:02:07.0088 5928 WdiServiceHost - ok
22:02:07.0090 5928 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:02:07.0101 5928 WdiSystemHost - ok
22:02:07.0114 5928 WebClient (8a438cbb8c032a0c798b0c642ffbe572) C:\Windows\System32\webclnt.dll
22:02:07.0127 5928 WebClient - ok
22:02:07.0135 5928 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:02:07.0160 5928 Wecsvc - ok
22:02:07.0171 5928 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:02:07.0195 5928 wercplsupport - ok
22:02:07.0208 5928 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:02:07.0232 5928 WerSvc - ok
22:02:07.0239 5928 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:02:07.0264 5928 WfpLwf - ok
22:02:07.0268 5928 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:02:07.0277 5928 WIMMount - ok
22:02:07.0282 5928 WinHttpAutoProxySvc - ok
22:02:07.0301 5928 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:02:07.0326 5928 Winmgmt - ok
22:02:07.0377 5928 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:02:07.0426 5928 WinRM - ok
22:02:07.0470 5928 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
22:02:07.0483 5928 WinUsb - ok
22:02:07.0509 5928 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:02:07.0532 5928 Wlansvc - ok
22:02:07.0536 5928 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:02:07.0543 5928 WmiAcpi - ok
22:02:07.0560 5928 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:02:07.0568 5928 wmiApSrv - ok
22:02:07.0573 5928 WMPNetworkSvc - ok
22:02:07.0577 5928 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:02:07.0583 5928 WPCSvc - ok
22:02:07.0597 5928 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:02:07.0611 5928 WPDBusEnum - ok
22:02:07.0615 5928 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:02:07.0637 5928 ws2ifsl - ok
22:02:07.0639 5928 WSearch - ok
22:02:07.0651 5928 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:02:07.0679 5928 WudfPf - ok
22:02:07.0692 5928 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:02:07.0722 5928 WUDFRd - ok
22:02:07.0736 5928 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:02:07.0760 5928 wudfsvc - ok
22:02:07.0771 5928 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:02:07.0783 5928 WwanSvc - ok
22:02:07.0789 5928 XAMPP (16a004d355467e44d217dc4df62ec1e4) C:\xampp\service.exe
22:02:07.0794 5928 XAMPP ( UnsignedFile.Multi.Generic ) - warning
22:02:07.0794 5928 XAMPP - detected UnsignedFile.Multi.Generic (1)
22:02:07.0802 5928 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:02:07.0867 5928 \Device\Harddisk0\DR0 - ok
22:02:07.0906 5928 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
22:02:07.0992 5928 \Device\Harddisk1\DR1 - ok
22:02:08.0003 5928 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
22:02:08.0056 5928 \Device\Harddisk2\DR2 - ok
22:02:08.0060 5928 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk3\DR3
22:02:08.0192 5928 \Device\Harddisk3\DR3 - ok
22:02:08.0194 5928 Boot (0x1200) (858e99e0bbb0edb8f0c88550b513c785) \Device\Harddisk0\DR0\Partition0
22:02:08.0195 5928 \Device\Harddisk0\DR0\Partition0 - ok
22:02:08.0197 5928 Boot (0x1200) (30593599102b2f629d43b9ce5b67a843) \Device\Harddisk0\DR0\Partition1
22:02:08.0198 5928 \Device\Harddisk0\DR0\Partition1 - ok
22:02:08.0241 5928 Boot (0x1200) (41240eec7aa8554a2251ed95ed9db7c7) \Device\Harddisk1\DR1\Partition0
22:02:08.0242 5928 \Device\Harddisk1\DR1\Partition0 - ok
22:02:08.0244 5928 Boot (0x1200) (c0f83ebd658f504503f6095899f41aa8) \Device\Harddisk2\DR2\Partition0
22:02:08.0245 5928 \Device\Harddisk2\DR2\Partition0 - ok
22:02:08.0249 5928 Boot (0x1200) (364f8f42e5f38179215e6c503531360f) \Device\Harddisk3\DR3\Partition0
22:02:08.0251 5928 \Device\Harddisk3\DR3\Partition0 - ok
22:02:08.0251 5928 ============================================================
22:02:08.0251 5928 Scan finished
22:02:08.0251 5928 ============================================================
22:02:08.0258 5632 Detected object count: 4
22:02:08.0258 5632 Actual detected object count: 4
22:02:10.0817 5632 Apache2.2 ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:10.0817 5632 Apache2.2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:10.0818 5632 SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:10.0818 5632 SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:10.0819 5632 Themes ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:10.0819 5632 Themes ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:10.0820 5632 XAMPP ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:10.0820 5632 XAMPP ( UnsignedFile.Multi.Generic ) - User select action: Skip

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#4 Příspěvek od vyosek »

:arrow: Spustte znovu RogueKiller
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost Prohledat a pote Smazat a nasledne Zprava - otevre se log, ten sem vlozte
  • Pak kliknete na Oprava Host a Zprava - otevre se log, ten sem vlozte
  • Pak kliknete na Oprava Proxy a Zprava - otevre se log, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

duffx
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 02 kvě 2010 15:55

Re: Prosím o kontrolu logu

#5 Příspěvek od duffx »

RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows 7 (6.1.7600 ) 64 bits version
Spuštěno v: Normální režim
Uživatel: duff [Práva správce]
Mód: Odebrat -- Datum: 07/12/2012 22:11:35

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 17 ¤¤¤
[HJ NAME] HKCU\[...]\Run : iTunesHelper (C:\Users\duff\AppData\Roaming\svchost.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Run : Defense (C:\Users\duff\AppData\Roaming\Defense.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Run : Task Manager (C:\Users\duff\AppData\Roaming\blackCoin.scr) -> DELETED
[HJ NAME] HKLM\[...]\Wow6432Node\Run : iTunesHelper (C:\Users\duff\AppData\Roaming\svchost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Wow6432Node\Run : NjYwQzUyMTFCMUQyMkM2QT (C:\Users\duff\odfMag.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Policies\Explorer\Run : Valve (C:\Users\duff\AppData\Roaming\E00B32.exe) -> DELETED
[HJ NAME] HKLM\[...]\Policies\Explorer\Run : iTunesHelper (C:\Users\duff\AppData\Roaming\svchost.exe) -> DELETED
[ROGUE ST] HKLM\[...]\Policies\Explorer\Run : 4182 (C:\PROGRA~3\LOCALS~1\Temp\msouukzah.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Windows : load (C:\Users\duff\odfMag.exe) -> DELETED
[HJPOL] HKCU\[...]\Policies\Explorer\Explorer : DisallowRun (1) -> DELETED
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\duff\AppData\Local\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\n.) -> REPLACED (c:\windows\system32\shell32.dll)
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Zvláštní soubory / Složky: ¤¤¤
[ZeroAccess][FILE] @ : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\@ --> REMOVED AT REBOOT
[Del.Parent][FILE] 00000001.@ : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\U\00000001.@ --> REMOVED
[Del.Parent][FILE] 80000000.@ : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\U\80000000.@ --> REMOVED
[Del.Parent][FILE] 800000cb.@ : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\U\800000cb.@ --> REMOVED
[ZeroAccess][FOLDER] U : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\U --> REMOVED
[ZeroAccess][FOLDER] L : c:\windows\installer\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\L --> REMOVED
[ZeroAccess][FILE] @ : c:\users\duff\appdata\local\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\@ --> REMOVED
[ZeroAccess][FOLDER] U : c:\users\duff\appdata\local\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\U --> REMOVED
[ZeroAccess][FOLDER] L : c:\users\duff\appdata\local\{63a31f40-ea38-a4cb-0f1b-edc5fd1fcecd}\L --> REMOVED

¤¤¤ Ovladač: [NENAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ZeroAccess ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤

[...]


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: INTEL SSDSA2CW080G3 ATA Device +++++
--- User ---
[MBR] da4b85b38abbde74f65834b95da32659
[BSP] 0f8211a200273349886382901fb9273e : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 76217 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: TOSHIBA MK2552GSX ATA Device +++++
--- User ---
[MBR] 13c63db0b098218aef34914eafbe4ee0
[BSP] 0c5d1525ade744e211385d1f43dba554 : Windows 7 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 122882048 | Size: 178473 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive2: WDC WD6400AAKS-00A7B0 ATA Device +++++
--- User ---
[MBR] 8ea2ee69e82dc2c60e9a777efd235742
[BSP] b1eb37eabf90a7d30fb0b83e55ac6e75 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive3: Patriot Memory USB Device +++++
--- User ---
[MBR] 8e4d69fb6c8aeace7d6cb628d7fd8096
[BSP] 5c0f2c694a71757c51d8749e647c85db : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 7639 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

#######################################

RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows 7 (6.1.7600 ) 64 bits version
Spuštěno v: Normální režim
Uživatel: duff [Práva správce]
Mód: Oprava HOSTS -- Datum: 07/12/2012 22:12:25

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Ovladač: [NENAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤

[...]

¤¤¤ Resetovaný HOSTS: ¤¤¤


Dokončeno : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt

#######################################

RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows 7 (6.1.7600 ) 64 bits version
Spuštěno v: Normální režim
Uživatel: duff [Práva správce]
Mód: Oprava Proxy -- Datum: 07/12/2012 22:14:18

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Ovladač: [NENAHRÁNO] ¤¤¤

¤¤¤ Záznamy Registrů: 0 ¤¤¤

Dokončeno : << RKreport[5].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt
Naposledy upravil(a) duffx dne 12 črc 2012 21:24, celkem upraveno 2 x.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#6 Příspěvek od vyosek »

:arrow: Super, jdeme dale :James008:

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

duffx
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 02 kvě 2010 15:55

Re: Prosím o kontrolu logu

#7 Příspěvek od duffx »

Tak tady to bude chvilku trvat, nedaří se mi shodit Aviru :), hned jak to bude, edituju...
Naposledy upravil(a) duffx dne 12 črc 2012 21:50, celkem upraveno 2 x.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#8 Příspěvek od vyosek »

Needitujte :!:

Dejte to jako novy prispevek, jinak se mi to nezobrazi

Navod jak na disable bezp. SW je zde http://www.bleepingcomputer.com/forums/topic114351.html
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

duffx
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 02 kvě 2010 15:55

Re: Prosím o kontrolu logu

#9 Příspěvek od duffx »

Už jsem si to uvědomil :) sice se mi podařilo shodit aviru přes autoruns a po startu nenabíhá, ale pořád hlásí rezidentní štít. i tak jsem combofix pustil, tady je log. ještě vyzkouším, jestli najdu v tom odkaze něco a pustím znovu. Díky!

ComboFix 12-07-12.02 - duff 12.07.2012 22:39:30.1.6 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.8189.5902 [GMT 2:00]
Spuštěný z: c:\users\duff\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\users\duff\AppData\Local\assembly\tmp
c:\users\duff\AppData\Roaming\1834941334.exe
c:\users\duff\AppData\Roaming\blackCoin.scr
c:\users\duff\AppData\Roaming\Defense.zgy
c:\users\duff\AppData\Roaming\E00B32.exe
c:\users\duff\AppData\Roaming\oqyztx.exe
c:\users\duff\AppData\Roaming\pcrujs.exe
c:\users\duff\AppData\Roaming\yschjw.exe
c:\users\duff\nonapi.exe
c:\users\duff\odfMag.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\DEBUG.log
c:\windows\SysWow64\themeui.dll.tmp
c:\windows\SysWow64\tmpEF8D.tmp
c:\windows\SysWow64\tmpEF8E.tmp
c:\windows\SysWow64\uxtheme.dll.tmp
.
c:\windows\system32\Services.exe . . . je infikován!!
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-12 do 2012-07-12 )))))))))))))))))))))))))))))))
.
.
2012-07-12 20:42 . 2012-07-12 20:42 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-07-12 20:42 . 2012-07-12 20:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-12 19:06 . 2012-07-12 19:07 -------- d-----w- c:\program files\trend micro
2012-07-12 19:06 . 2012-07-12 19:07 -------- d-----w- C:\rsit
2012-07-12 17:33 . 2012-07-12 17:33 -------- d-----w- c:\programdata\Avira
2012-07-12 17:33 . 2012-07-12 17:33 -------- d-----w- c:\program files (x86)\Avira
2012-07-12 15:53 . 2012-07-12 15:53 -------- d-----w- c:\program files\ESET
2012-07-11 23:20 . 2012-07-11 23:20 -------- d-----w- c:\programdata\Local Settings
2012-07-11 20:31 . 2009-07-14 01:14 452096 --sha-w- C:\.exeFalse
2012-07-11 19:19 . 2012-07-11 19:19 -------- d-----w- c:\users\duff\AppData\Roaming\dclogs
2012-07-11 08:01 . 2012-07-11 08:01 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-07-10 20:31 . 2012-07-10 20:31 -------- d-----w- c:\program files\Autoruns
2012-07-10 20:16 . 2012-07-10 20:22 -------- d-----w- c:\programdata\B4CF34E400009249006C6642A6014588
2012-07-10 20:15 . 2012-07-12 17:37 -------- d-----w- c:\users\duff\AppData\Roaming\Mouffi
2012-07-10 20:15 . 2012-07-11 15:41 -------- d-----w- c:\users\duff\AppData\Roaming\Qii
2012-07-03 18:17 . 2012-07-03 18:17 -------- d-----w- c:\users\duff\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-07-03 18:17 . 2012-07-03 18:17 -------- d-----w- c:\users\duff\AppData\Roaming\Adobe Mini Bridge CS5
2012-07-03 17:52 . 2012-07-03 17:52 -------- d-----w- c:\users\duff\AppData\Local\Mozilla
2012-07-03 17:52 . 2012-07-03 17:52 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-06-27 17:27 . 2012-06-27 17:27 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll
2012-06-27 17:22 . 2012-06-27 17:22 94208 ----a-w- c:\windows\DIIUnin.exe
2012-06-27 17:22 . 2012-06-27 17:22 2829 ----a-w- c:\windows\DIIUnin.pif
2012-06-27 17:20 . 2012-06-27 21:01 -------- d-----w- c:\program files (x86)\Diablo II
2012-06-24 22:06 . 2009-07-14 01:40 39424 ----a-w- c:\windows\system32\Spool\prtprocs\x64\EP0LPP00.DLL
2012-06-21 20:27 . 2012-06-21 20:27 -------- d-----w- c:\users\duff\AppData\Local\Chromium
2012-06-21 19:32 . 2012-07-12 15:48 -------- d-----w- c:\program files (x86)\Rockstar Games
2012-06-18 06:31 . 2012-06-18 06:32 246929248 ----a-w- C:\SQLEXPRWT_x86_ENU.exe
2012-06-14 15:33 . 2012-06-14 15:34 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2012-06-14 14:40 . 2012-06-14 14:40 -------- d-----w- c:\programdata\Battle.net
2012-06-14 14:33 . 2012-06-14 15:34 -------- d-----w- c:\programdata\Blizzard Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 16:41 . 2012-07-12 16:41 13704676 ----a-w- C:\ZKV.ZIP
2012-06-18 05:14 . 2012-05-06 21:56 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-18 05:14 . 2012-01-03 17:15 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-02 22:19 . 2012-06-08 23:36 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-08 23:36 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-08 23:36 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-08 23:36 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-08 23:36 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-08 23:36 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-08 23:36 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-08 23:36 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-08 23:36 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-07 14:44 . 2012-05-07 14:44 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2012-05-07 14:44 . 2012-05-07 14:44 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2012-05-07 14:44 . 2012-05-07 14:44 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll
2012-05-02 13:24 . 2012-05-01 19:25 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-04-27 08:20 . 2012-05-01 19:25 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-04-24 22:32 . 2012-05-01 19:25 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-07-14 . 24ACB7E5BE595468E3B9AA488B9B4FCB . 328704 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[-] 2009-07-14 . 014A9CB92514E27C0107614DF764BC06 . 328704 . . [6.1.7600.16385] .. c:\windows\system32\services.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Gadwin PrintScreen Pro"="c:\program files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" [2011-05-12 1858048]
"Facebook Update"="c:\users\duff\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 841544]
"VirtualCloneDrive"="c:\program files (x86)\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\duff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\duff\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 245120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Aura.lnk - c:\windows\8 Skin Pack\Aura\Aura.exe [N/A]
Google Calendar Sync.lnk - c:\program files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
TaskbarUserTile.lnk - c:\windows\8 Skin Pack\TaskbarUserTile\UserTile.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 AODService;AODService;c:\program files (x86)\AMD\OverDrive\AODAssist.exe [2011-10-13 136616]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 136176]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-03-21 2218600]
R2 XAMPP;XAMPP Service;c:\xampp\service.exe [2007-12-21 60928]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-04-04 1431888]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 136176]
R3 imhidusb;Immersion's HID USB Driver;c:\windows\system32\DRIVERS\imhidusb.sys [2007-04-19 23040]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-14 113120]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-06 1255736]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-01 86224]
S2 AODDriver4.1;AODDriver4.1;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [2011-10-13 55936]
S2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2010-10-18 20549]
S2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-01 67400]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-05 160944]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-03-20 378472]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
S2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-03-07 40832]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-03-07 65280]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-03-03 174184]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-01-13 413800]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-03-30 35112]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-07-11 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000Core.job
- c:\users\duff\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-05-12 21:30]
.
2012-07-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000UA.job
- c:\users\duff\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-05-12 21:30]
.
2012-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 18:34]
.
2012-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 18:34]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-24 11780712]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: dcconcept.com\cz.qi
TCP: DhcpNameServer = 192.168.84.1
FF - ProfilePath - c:\users\duff\AppData\Roaming\Mozilla\Firefox\Profiles\mss3h0eh.default\
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-STCAgent - c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe
AddRemove-BattlEye for OA - c:\program files (x86)\Bohemia Interactive\ArmAExpansion\BattlEye\UnInstallBE.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS10\MSSQL\Binn\sqlservr.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe
.
**************************************************************************
.
Celkový čas: 2012-07-12 22:45:44 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-07-12 20:45
.
Před spuštěním: 7 156 273 152
Po spuštění: 9 070 243 840
.
- - End Of File - - D602FE61CEE390A0D5A086EE500D1BFA

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#10 Příspěvek od vyosek »

Znovu nic nespoustejte...

Delejte prosim kroky jen co pisu, jinak to pujde slozite, na prd a nikam to nepovede

:arrow: Stahnete SytemLook http://jpshortstuff.247fixes.com/SystemLook.exe a ulozte jej na plochu
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :filefind
    Services.exe
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

duffx
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 02 kvě 2010 15:55

Re: Prosím o kontrolu logu

#11 Příspěvek od duffx »

ok, omlouvám se :)

SystemLook 30.07.11 by jpshortstuff
Log created at 22:56 on 12/07/2012 by duff
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.

========== filefind ==========

Searching for "Services.exe"
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe --a---- 328704 bytes [23:19 13/07/2009] [01:39 14/07/2009] 24ACB7E5BE595468E3B9AA488B9B4FCB

-= EOF =-

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#12 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Restore::
    c:\windows\system32\Services.exe
    
    Folder::
    c:\program files\ESET
    c:\programdata\B4CF34E400009249006C6642A6014588
    
    File::
    C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000Core.job
    C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000UA.job
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\One-Click Tweak.job
    
    DirLook::
    c:\windows\system32\%APPDATA%
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Facebook Update"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "ZyngaGamesAgent"=-
    "VirtualCloneDrive"=-
    "SwitchBoard"=-
    "AdobeCS5ServiceManager"=-
    "AdobeCS5.5ServiceManager"=-
    "SunJavaUpdateSched"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000000
    "FirewallOverride"=dword:00000000
    
    Driver::
    gupdate
    gupdatem
    ekrn
    
    DDS::
    Trusted Zone: dcconcept.com\cz.qi
    
    Firefox::
    FF - ProfilePath - c:\users\duff\AppData\Roaming\Mozilla\Firefox\Profiles\mss3h0eh.default\
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

duffx
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 02 kvě 2010 15:55

Re: Prosím o kontrolu logu

#13 Příspěvek od duffx »

ComboFix 12-07-12.02 - duff 12.07.2012 23:11:03.2.6 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.8189.5443 [GMT 2:00]
Spuštěný z: c:\users\duff\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\duff\Desktop\CFScript.txt
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000Core.job"
"c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000UA.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\One-Click Tweak.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ESET
c:\program files\ESET\ESET Smart Security\em000_32.dat
c:\program files\ESET\ESET Smart Security\em000_64.dat
c:\program files\ESET\ESET Smart Security\em001_32.dat
c:\program files\ESET\ESET Smart Security\em002_32.dat
c:\program files\ESET\ESET Smart Security\em003_32.dat
c:\program files\ESET\ESET Smart Security\em004_32.dat
c:\program files\ESET\ESET Smart Security\em005_32.dat
c:\program files\ESET\ESET Smart Security\em006_32.dat
c:\program files\ESET\ESET Smart Security\em006_64.dat
c:\program files\ESET\ESET Smart Security\em008_32.dat
c:\program files\ESET\ESET Smart Security\em008_64.dat
c:\program files\ESET\ESET Smart Security\em009_32.dat
c:\program files\ESET\ESET Smart Security\em009_64.dat
c:\program files\ESET\ESET Smart Security\em010_32.dat
c:\program files\ESET\ESET Smart Security\em015_64.dat
c:\program files\ESET\ESET Smart Security\em017_32.dat
c:\program files\ESET\ESET Smart Security\em017_64.dat
c:\program files\ESET\ESET Smart Security\em018_32.dat
c:\program files\ESET\ESET Smart Security\em018_64.dat
c:\program files\ESET\ESET Smart Security\em019_32.dat
c:\program files\ESET\ESET Smart Security\em020_32.dat
c:\program files\ESET\ESET Smart Security\em021_32.dat
c:\program files\ESET\ESET Smart Security\em022_32.dat
c:\programdata\B4CF34E400009249006C6642A6014588
c:\programdata\B4CF34E400009249006C6642A6014588\B4CF34E400009249006C6642A6014588
c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000Core.job
c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-3297901978-2500626200-4254921097-1000UA.job
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
.
c:\windows\system32\Services.exe . . . je infikován!!
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ekrn
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-12 do 2012-07-12 )))))))))))))))))))))))))))))))
.
.
2012-07-12 21:14 . 2012-07-12 21:14 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-07-12 21:14 . 2012-07-12 21:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-12 19:06 . 2012-07-12 19:07 -------- d-----w- c:\program files\trend micro
2012-07-12 19:06 . 2012-07-12 19:07 -------- d-----w- C:\rsit
2012-07-12 17:33 . 2012-07-12 17:33 -------- d-----w- c:\programdata\Avira
2012-07-12 17:33 . 2012-07-12 17:33 -------- d-----w- c:\program files (x86)\Avira
2012-07-11 23:20 . 2012-07-11 23:20 -------- d-----w- c:\programdata\Local Settings
2012-07-11 20:31 . 2009-07-14 01:14 452096 --sha-w- C:\.exeFalse
2012-07-11 19:19 . 2012-07-11 19:19 -------- d-----w- c:\users\duff\AppData\Roaming\dclogs
2012-07-11 08:01 . 2012-07-11 08:01 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-07-10 20:31 . 2012-07-10 20:31 -------- d-----w- c:\program files\Autoruns
2012-07-10 20:15 . 2012-07-12 17:37 -------- d-----w- c:\users\duff\AppData\Roaming\Mouffi
2012-07-10 20:15 . 2012-07-11 15:41 -------- d-----w- c:\users\duff\AppData\Roaming\Qii
2012-07-03 18:17 . 2012-07-03 18:17 -------- d-----w- c:\users\duff\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-07-03 18:17 . 2012-07-03 18:17 -------- d-----w- c:\users\duff\AppData\Roaming\Adobe Mini Bridge CS5
2012-07-03 17:52 . 2012-07-03 17:52 -------- d-----w- c:\users\duff\AppData\Local\Mozilla
2012-07-03 17:52 . 2012-07-03 17:52 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-06-27 17:27 . 2012-06-27 17:27 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll
2012-06-27 17:22 . 2012-06-27 17:22 94208 ----a-w- c:\windows\DIIUnin.exe
2012-06-27 17:22 . 2012-06-27 17:22 2829 ----a-w- c:\windows\DIIUnin.pif
2012-06-27 17:20 . 2012-06-27 21:01 -------- d-----w- c:\program files (x86)\Diablo II
2012-06-24 22:06 . 2009-07-14 01:40 39424 ----a-w- c:\windows\system32\Spool\prtprocs\x64\EP0LPP00.DLL
2012-06-21 20:27 . 2012-06-21 20:27 -------- d-----w- c:\users\duff\AppData\Local\Chromium
2012-06-21 19:32 . 2012-07-12 15:48 -------- d-----w- c:\program files (x86)\Rockstar Games
2012-06-18 06:31 . 2012-06-18 06:32 246929248 ----a-w- C:\SQLEXPRWT_x86_ENU.exe
2012-06-14 15:33 . 2012-06-14 15:34 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2012-06-14 14:40 . 2012-06-14 14:40 -------- d-----w- c:\programdata\Battle.net
2012-06-14 14:33 . 2012-06-14 15:34 -------- d-----w- c:\programdata\Blizzard Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 16:41 . 2012-07-12 16:41 13704676 ----a-w- C:\ZKV.ZIP
2012-06-18 05:14 . 2012-05-06 21:56 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-18 05:14 . 2012-01-03 17:15 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-02 22:19 . 2012-06-08 23:36 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-08 23:36 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-08 23:36 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-08 23:36 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-08 23:36 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-08 23:36 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-08 23:36 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-08 23:36 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-08 23:36 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-07 14:44 . 2012-05-07 14:44 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2012-05-07 14:44 . 2012-05-07 14:44 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2012-05-07 14:44 . 2012-05-07 14:44 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll
2012-05-02 13:24 . 2012-05-01 19:25 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-04-27 08:20 . 2012-05-01 19:25 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-04-24 22:32 . 2012-05-01 19:25 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\system32\%APPDATA% ----
.
1601-01-01 00:00 . 1601-01-01 00:00 0 --sha-w- c:\windows\system32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-07-14 01:39 . !HASH: COULD NOT OPEN FILE !!!!! . 328704 . . [------] .. c:\windows\system32\services.exe
.
((((((((((((((((((((((((((((( SnapShot@2012-07-12_20.43.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-03 23:57 . 2012-07-12 20:55 38342 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-07-12 20:55 32972 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2012-01-03 23:47 . 2012-07-12 17:20 65536 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-01-03 23:47 . 2012-07-12 20:54 65536 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-07-12 17:20 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-12 20:54 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-03 17:02 . 2012-07-12 20:54 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-01-03 17:02 . 2012-07-12 20:54 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-01-03 17:02 . 2012-07-12 20:54 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-03 17:02 . 2012-07-12 20:54 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-03 17:02 . 2012-07-12 20:54 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-03 23:54 . 2012-07-12 20:55 9596 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3297901978-2500626200-4254921097-1000_UserData.bin
- 2012-07-12 20:43 . 2012-07-12 20:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-07-12 21:15 . 2012-07-12 21:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2012-07-12 20:41 815200 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-07-12 20:58 815200 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-07-12 20:58 833292 c:\windows\system32\perfh005.dat
- 2009-07-14 15:18 . 2012-07-12 20:41 833292 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-07-12 20:58 178964 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-07-12 20:41 178964 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2012-07-12 20:58 200626 c:\windows\system32\perfc005.dat
- 2009-07-14 15:18 . 2012-07-12 20:41 200626 c:\windows\system32\perfc005.dat
- 2009-07-14 05:12 . 2012-07-10 20:24 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2012-07-12 20:54 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2012-01-03 23:47 . 2012-07-12 20:54 737280 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-01-03 23:47 . 2012-07-12 17:20 737280 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Gadwin PrintScreen Pro"="c:\program files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" [2011-05-12 1858048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [BU]
.
c:\users\duff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\duff\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 245120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Aura.lnk - c:\windows\8 Skin Pack\Aura\Aura.exe [N/A]
Google Calendar Sync.lnk - c:\program files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
TaskbarUserTile.lnk - c:\windows\8 Skin Pack\TaskbarUserTile\UserTile.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
R2 AODService;AODService;c:\program files (x86)\AMD\OverDrive\AODAssist.exe [2011-10-13 136616]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-03-21 2218600]
R2 XAMPP;XAMPP Service;c:\xampp\service.exe [2007-12-21 60928]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-04-04 1431888]
R3 imhidusb;Immersion's HID USB Driver;c:\windows\system32\DRIVERS\imhidusb.sys [2007-04-19 23040]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-14 113120]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-06 1255736]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-01 86224]
S2 AODDriver4.1;AODDriver4.1;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [2011-10-13 55936]
S2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2010-10-18 20549]
S2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-01 67400]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-05 160944]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-03-20 378472]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
S2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-03-07 40832]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-03-07 65280]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-03-03 174184]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-01-13 413800]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-03-30 35112]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-24 11780712]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"combofix"="c:\combofix\CF4927.3XE" [2009-07-14 344576]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.84.1
FF - ProfilePath - c:\users\duff\AppData\Roaming\Mozilla\Firefox\Profiles\mss3h0eh.default\
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS10\MSSQL\Binn\sqlservr.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe
.
**************************************************************************
.
Celkový čas: 2012-07-12 23:16:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-07-12 21:16
ComboFix2.txt 2012-07-12 20:45
.
Před spuštěním: 8 720 633 856
Po spuštění: 8 220 319 744
.
- - End Of File - - 571BBFD4054623E3151E209ED939C4F8

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#14 Příspěvek od vyosek »

:arrow: Jeste jeden skript pro CF, postup stejny

Kód: Vybrat vše

KillAll::

FCopy::
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe | c:\windows\system32\Services.exe

DirLook::
C:\.exeFalse

Folder::
c:\windows\system32\%APPDATA%

Reboot::
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

duffx
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 02 kvě 2010 15:55

Re: Prosím o kontrolu logu

#15 Příspěvek od duffx »

ComboFix 12-07-12.02 - duff 13.07.2012 9:23.3.6 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.8189.6200 [GMT 2:00]
Spuštěný z: c:\users\duff\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\duff\Desktop\CFScript.txt
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-13 do 2012-07-13 )))))))))))))))))))))))))))))))
.
.
2012-07-13 07:26 . 2012-07-13 07:26 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-07-13 07:26 . 2012-07-13 07:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-12 19:06 . 2012-07-12 19:07 -------- d-----w- c:\program files\trend micro
2012-07-12 19:06 . 2012-07-12 19:07 -------- d-----w- C:\rsit
2012-07-12 17:33 . 2012-07-12 17:33 -------- d-----w- c:\programdata\Avira
2012-07-12 17:33 . 2012-07-12 17:33 -------- d-----w- c:\program files (x86)\Avira
2012-07-11 23:20 . 2012-07-11 23:20 -------- d-----w- c:\programdata\Local Settings
2012-07-11 20:31 . 2009-07-14 01:14 452096 --sha-w- C:\.exeFalse
2012-07-11 19:19 . 2012-07-11 19:19 -------- d-----w- c:\users\duff\AppData\Roaming\dclogs
2012-07-11 08:01 . 2012-07-11 08:01 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-07-10 20:31 . 2012-07-10 20:31 -------- d-----w- c:\program files\Autoruns
2012-07-10 20:15 . 2012-07-12 17:37 -------- d-----w- c:\users\duff\AppData\Roaming\Mouffi
2012-07-10 20:15 . 2012-07-11 15:41 -------- d-----w- c:\users\duff\AppData\Roaming\Qii
2012-07-03 18:17 . 2012-07-03 18:17 -------- d-----w- c:\users\duff\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-07-03 18:17 . 2012-07-03 18:17 -------- d-----w- c:\users\duff\AppData\Roaming\Adobe Mini Bridge CS5
2012-07-03 17:52 . 2012-07-03 17:52 -------- d-----w- c:\users\duff\AppData\Local\Mozilla
2012-07-03 17:52 . 2012-07-03 17:52 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-06-27 17:27 . 2012-06-27 17:27 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll
2012-06-27 17:22 . 2012-06-27 17:22 94208 ----a-w- c:\windows\DIIUnin.exe
2012-06-27 17:22 . 2012-06-27 17:22 2829 ----a-w- c:\windows\DIIUnin.pif
2012-06-27 17:20 . 2012-06-27 21:01 -------- d-----w- c:\program files (x86)\Diablo II
2012-06-24 22:06 . 2009-07-14 01:40 39424 ----a-w- c:\windows\system32\Spool\prtprocs\x64\EP0LPP00.DLL
2012-06-21 20:27 . 2012-06-21 20:27 -------- d-----w- c:\users\duff\AppData\Local\Chromium
2012-06-21 19:32 . 2012-07-12 15:48 -------- d-----w- c:\program files (x86)\Rockstar Games
2012-06-18 06:31 . 2012-06-18 06:32 246929248 ----a-w- C:\SQLEXPRWT_x86_ENU.exe
2012-06-14 15:33 . 2012-06-14 15:34 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2012-06-14 14:40 . 2012-06-14 14:40 -------- d-----w- c:\programdata\Battle.net
2012-06-14 14:33 . 2012-06-14 15:34 -------- d-----w- c:\programdata\Blizzard Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 16:41 . 2012-07-12 16:41 13704676 ----a-w- C:\ZKV.ZIP
2012-06-18 05:14 . 2012-05-06 21:56 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-18 05:14 . 2012-01-03 17:15 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-02 22:19 . 2012-06-08 23:36 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-08 23:36 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-08 23:36 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-08 23:36 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-08 23:36 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-08 23:36 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-08 23:36 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-08 23:36 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-08 23:36 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-07 14:44 . 2012-05-07 14:44 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2012-05-07 14:44 . 2012-05-07 14:44 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2012-05-07 14:44 . 2012-05-07 14:44 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll
2012-05-02 13:24 . 2012-05-01 19:25 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-04-27 08:20 . 2012-05-01 19:25 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-04-24 22:32 . 2012-05-01 19:25 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-07-14 01:39 . !HASH: COULD NOT OPEN FILE !!!!! . 328704 . . [------] .. c:\windows\system32\services.exe
.
((((((((((((((((((((((((((((( SnapShot@2012-07-12_20.43.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-03 23:57 . 2012-07-12 20:55 38342 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-07-12 21:16 33004 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2012-01-03 23:47 . 2012-07-12 17:20 65536 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-01-03 23:47 . 2012-07-12 21:15 65536 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-07-12 21:15 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-12 17:20 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-01-03 17:02 . 2012-07-12 21:15 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:46 . 2012-07-13 01:42 84576 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2012-01-03 17:02 . 2012-07-12 21:15 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-01-03 17:02 . 2012-07-12 21:15 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-01-03 17:02 . 2012-07-12 21:15 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-01-03 17:02 . 2012-07-12 21:15 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-01-03 17:02 . 2012-07-12 20:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-03 23:54 . 2012-07-12 21:16 9858 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3297901978-2500626200-4254921097-1000_UserData.bin
+ 2012-07-13 07:27 . 2012-07-13 07:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-13 07:27 . 2012-07-13 07:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-07-12 20:43 . 2012-07-12 20:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2012-07-12 20:41 815200 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-07-12 21:19 815200 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-07-12 21:19 833292 c:\windows\system32\perfh005.dat
- 2009-07-14 15:18 . 2012-07-12 20:41 833292 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-07-12 21:19 178964 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-07-12 20:41 178964 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2012-07-12 21:19 200626 c:\windows\system32\perfc005.dat
- 2009-07-14 15:18 . 2012-07-12 20:41 200626 c:\windows\system32\perfc005.dat
- 2009-07-14 05:12 . 2012-07-10 20:24 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2012-07-12 21:15 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2012-01-03 23:47 . 2012-07-12 21:15 737280 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-01-03 23:47 . 2012-07-12 17:20 737280 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 02:34 . 2012-07-11 23:07 9437184 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-07-13 01:51 9437184 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Gadwin PrintScreen Pro"="c:\program files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" [2011-05-12 1858048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [BU]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 841544]
.
c:\users\duff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\duff\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 245120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Aura.lnk - c:\windows\8 Skin Pack\Aura\Aura.exe [N/A]
Google Calendar Sync.lnk - c:\program files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
TaskbarUserTile.lnk - c:\windows\8 Skin Pack\TaskbarUserTile\UserTile.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
R2 AODService;AODService;c:\program files (x86)\AMD\OverDrive\AODAssist.exe [2011-10-13 136616]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-03-21 2218600]
R2 XAMPP;XAMPP Service;c:\xampp\service.exe [2007-12-21 60928]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-04-04 1431888]
R3 imhidusb;Immersion's HID USB Driver;c:\windows\system32\DRIVERS\imhidusb.sys [2007-04-19 23040]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-14 113120]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-06 1255736]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-01 86224]
S2 AODDriver4.1;AODDriver4.1;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [2011-10-13 55936]
S2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2010-10-18 20549]
S2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-01 67400]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-05 160944]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-03-20 378472]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
S2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-03-07 40832]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-03-07 65280]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-03-03 174184]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-01-13 413800]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-03-30 35112]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 ----a-w- c:\users\duff\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-24 11780712]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.84.1
FF - ProfilePath - c:\users\duff\AppData\Roaming\Mozilla\Firefox\Profiles\mss3h0eh.default\
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS10\MSSQL\Binn\sqlservr.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe
.
**************************************************************************
.
Celkový čas: 2012-07-13 09:29:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-07-13 07:29
ComboFix2.txt 2012-07-12 21:16
ComboFix3.txt 2012-07-12 20:45
.
Před spuštěním: 7 911 202 816
Po spuštění: 7 975 247 872
.
- - End Of File - - C2EA41B8D45D4161073636E2F0E33E5D

Odpovědět