Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Podezření na vir - problém se stahováním

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Podezření na vir - problém se stahováním

#1 Příspěvek od Teochi »

Dobrý den,
přítelkyně má problém s virem, který ji nejspíš blokuje stahování z prohlížeče. Neblokuje to však vše, ale jen soubory nad 200MB pak to hodí nějaký crash. Každopádně, Eset hlásí, že jde o nějaký "Mebroot", ale nejde odstranit. Je však možné, že půjde dokonce i o něco jiného. Prosím tědy o kontrolo logu, děkuji :) :

log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Veronika at 2012-08-14 15:55:37
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 27 GB (12%) free of 218 GB
Total RAM: 3062 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:55:44, on 14.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17110)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\xampp\apache\bin\apache.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CardReader2.0\CRBroadCasting.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\WService.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\xampp\apache\bin\apache.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\xampp\mysql\bin\mysqld-nt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CardReader2.0\OTiReader.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PSIService.exe
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\DRIVERS\WtSrv.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe
C:\Documents and Settings\Veronika\Plocha\RSIT.exe
C:\Program Files\trend micro\Veronika.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.centrum.cz/?ms=ge
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/?ms=ge
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 187.4.205.90:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Veronika\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O1 - Hosts: 81.0.254.162 L2authd.Lineage2.com
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: (no name) - {11D54ACE-09A9-11D4-8ACE-00C04F542830} - (no file)
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Veronika\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Microsoft Web Test Recorder 9.0 Helper - {E31CE47F-C268-41ba-897B-B415E613947D} - C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO90.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {FC7D27FB-CA10-4CE3-B312-8A164671FD03} - (no file)
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: Centrum.cz Turbo - {A6890AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - C:\Program Files\NetCentrum\Turbo\Turbo.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [CRBroadCasting] C:\Program Files\CardReader2.0\CRBroadCasting.exe
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\TWINTO~1\MouseElf.EXE
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1390067357-1606980848-725345543-1014\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1390067357-1606980848-725345543-1014\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1390067357-1606980848-725345543-1014\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1390067357-1606980848-725345543-1014\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1390067357-1606980848-725345543-1014\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1390067357-1606980848-725345543-1014\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Philips Device Manager.lnk = C:\Program Files\Philips\SA28XX Device Manager\main.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Bleskově - {141D2E4F-F313-4991-B61A-EE5D6D849361} - http://bleskove.centrum.cz (file missing)
O9 - Extra button: Centrum.cz - {2A5CFB1C-AAA2-4760-8462-1B61CF74B7D8} - http://www.centrum.cz (file missing)
O9 - Extra button: Xchat - {2BCB61BF-DC41-4738-A149-BDAAAD7FF0BD} - http://www.xchat.cz (file missing)
O9 - Extra button: Aktuálně - {2E01031B-AB09-4455-823D-25F1A1C11F48} - http://aktualne.centrum.cz (file missing)
O9 - Extra button: Slovníky - {2F741D0A-150E-40F9-A602-1B2421475F1D} - http://slovniky.centrum.cz (file missing)
O9 - Extra button: Supermapy - {309176E6-E204-40A0-8D13-7F19C0498C40} - http://www.supermapy.cz (file missing)
O9 - Extra button: mp3.centrum.cz - {49681216-5BF4-41A2-AAFA-129A6BD625DA} - http://mp3.centrum.cz/ (file missing)
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Žena - {8B6E8E01-D262-4980-8C27-B8B2802285C1} - http://www.zena.cz (file missing)
O9 - Extra button: Fotoalba - {8FD64249-590C-4FBC-B181-12A6BAF516AF} - http://www.fotoalba.cz (file missing)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
O9 - Extra button: Počasí - {A5050656-2286-454F-A489-C605ED1B461C} - http://pocasi.centrum.cz (file missing)
O9 - Extra button: Sportplus - {BC78516C-9DC9-40C5-A91E-74593222EF89} - http://sportplus.centrum.cz (file missing)
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Veronika\Nabídka Start\Programy\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Digitálně - {DAE865E8-970E-4931-A172-119CB56BBAF5} - http://www.digitalne.cz/ (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Refresher - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Refresher 1.2\Refresher (file missing)
O9 - Extra 'Tools' menuitem: &Refresher - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Refresher 1.2\Refresher (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Stahuj.cz - {FC29EB7D-EDBA-4299-AEE4-D1BDC70EFA15} - http://www.stahuj.cz/ (file missing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 5047380625
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apache2.2 - Apache Software Foundation - c:\xampp\apache\bin\apache.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper® Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: OTi Card Reader Service - Unknown owner - C:\Program Files\CardReader2.0\OTiReader.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: WinTab Service (WinTabService) - Tablet Driver - C:\WINDOWS\system32\DRIVERS\WtSrv.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\xampp\service.exe

--
End of file - 22912 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1606980848-725345543-1012Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1606980848-725345543-1012UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2010-08-25 193888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll [2007-03-16 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11D54ACE-09A9-11D4-8ACE-00C04F542830}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2008-07-16 1266992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\WINDOWS\WebIE.dll [2007-11-19 491520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-08-06 94308]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-01-28 370296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{687578b9-7132-4a7a-80e4-30ee31099e03}]
uTorrentControl2 Toolbar - C:\Program Files\uTorrentControl2\prxtbuTor.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\Veronika\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-12-13 141184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-01-28 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-07-05 4018888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-10-06 842296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C451C08A-EC37-45DF-AAAD-18B51AB5E837}]
PDFCreator Toolbar Helper - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll [2007-11-20 757760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E31CE47F-C268-41ba-897B-B415E613947D}]
Microsoft Web Test Recorder 9.0 Helper - C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO90.dll [2007-11-08 64088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-18 163840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC7D27FB-CA10-4CE3-B312-8A164671FD03}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFEF0-5B30-21D4-945D-000000000000}]
C:\PROGRA~1\STARDO~1\SDIEInt.dll [2004-12-11 135168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll [2007-03-16 118784]
{95188727-288F-4581-A48D-EAB3BD027314} - Zend Studio - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL [2006-11-29 188416]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\WINDOWS\WebIE.dll [2007-11-19 491520]
{31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - PDFCreator Toolbar - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll [2007-11-20 757760]
{A6890AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - Centrum.cz Turbo - C:\Program Files\NetCentrum\Turbo\Turbo.dll [2008-01-27 157696]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-01-28 2403392]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2008-07-16 1266992]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-06-12 958712]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{687578b9-7132-4a7a-80e4-30ee31099e03} - uTorrentControl2 Toolbar - C:\Program Files\uTorrentControl2\prxtbuTor.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"DiskeeperSystray"=C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe [2006-02-24 196709]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"CRBroadCasting"=C:\Program Files\CardReader2.0\CRBroadCasting.exe [2004-02-26 24576]
"CmUsbSound"=RunDll32 cmcnfgu.cpl,CMICtrlWnd []
"mouseElf"=C:\PROGRA~1\TWINTO~1\MouseElf.EXE [2004-11-16 196608]
""= []
"WService"=C:\WINDOWS\system32\WService.EXE [2002-09-07 28672]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-01-10 385024]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-18 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-18 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-09-11 2054360]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2012-05-15 15504192]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2012-05-15 1634112]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2010-04-16 3872080]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-02-24 68856]
"Google Update"=C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
"PlayNC Launcher"= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2008-10-14 623992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM]
C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [2007-03-20 1884160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-02-02 135664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Ahead\InCD\InCD.exe [2005-07-08 1397760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage]
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe [2002-06-03 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayNC Launcher]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-02-24 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-01-28 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2006-10-23 40048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Veronika^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.4.lnk]
C:\PROGRA~1\OPENOF~1.4\program\QUICKS~1.EXE [2008-03-16 393216]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Philips Device Manager.lnk - C:\Program Files\Philips\SA28XX Device Manager\main.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-09-29 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"LegalNoticeText"=
"LegalNoticeCaption"=

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Software602\602SQL11\602gcli11.exe"="C:\Program Files\Software602\602SQL11\602gcli11.exe:*:Enabled:602SQL Management and Development Client"
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe"="C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:*:Enabled:Adobe Version Cue CS3 Server"
"C:\Program Files\Zend\ZendStudio-5.5.0\jre\bin\javaw.exe"="C:\Program Files\Zend\ZendStudio-5.5.0\jre\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\Program Files\Mozilla Firefox 3 Beta 1\firefox.exe"="C:\Program Files\Mozilla Firefox 3 Beta 1\firefox.exe:*:Disabled:Firefox"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Documents and Settings\petr\Plocha\eclipse\eclipse.exe"="C:\Documents and Settings\petr\Plocha\eclipse\eclipse.exe:*:Enabled:eclipse"
"C:\Program Files\phpDesigner 2008\phpDesigner2008.exe"="C:\Program Files\phpDesigner 2008\phpDesigner2008.exe:*:Enabled:phpDesigner2008"
"C:\Program Files\SIM\sim.exe"="C:\Program Files\SIM\sim.exe:*:Enabled:sim"
"C:\Program Files\Apteryx\Apteryx Imaging\DrSuni.exe"="C:\Program Files\Apteryx\Apteryx Imaging\DrSuni.exe:*:Enabled:XVLite"
"C:\xampp\apache\bin\apache.exe"="C:\xampp\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\miranda\miranda32.exe"="C:\Program Files\miranda\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\VPN Anonymizer\privoxy\VPN_Anonymizer_webfilter.exe"="C:\Program Files\VPN Anonymizer\privoxy\VPN_Anonymizer_webfilter.exe:*:Enabled:VPN_Anonymizer_webfilter"
"C:\Program Files\FlashGet\flashget.exe"="C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget"
"C:\Program Files\KVIrc\kvirc.exe"="C:\Program Files\KVIrc\kvirc.exe:*:Enabled:K Visual IRC Client Executable"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Documents and Settings\Veronika\Dokumenty\ICQ\440036354\ReceivedFiles\320411275 좋은 하루 되세요~\오픈캔버스.exe"="C:\Documents and Settings\Veronika\Dokumenty\ICQ\440036354\ReceivedFiles\320411275 좋은 하루 되세요~\오픈캔버스.exe:*:Enabled:오픈캔버스"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray"
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\WINDOWS\system32\rtcshare.exe"="C:\WINDOWS\system32\rtcshare.exe:*:Enabled:Sdílení aplikací RTC"
"C:\Documents and Settings\Veronika\Plocha\오픈캔버스.exe"="C:\Documents and Settings\Veronika\Plocha\오픈캔버스.exe:*:Enabled:오픈캔버스"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\BitLord2\BitLord.exe"="C:\Program Files\BitLord2\BitLord.exe:*:Enabled:Bitlord2"
"C:\Program Files\Warcraft III\Warcraft III.exe"="C:\Program Files\Warcraft III\Warcraft III.exe:*:Disabled:Warcraft III"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Mass Effect 2\Binaries\MassEffect2.exe"="C:\Program Files\Mass Effect 2\Binaries\MassEffect2.exe:*:Enabled:Mass Effect 2 Game"
"C:\Program Files\Mass Effect 2\MassEffect2Launcher.exe"="C:\Program Files\Mass Effect 2\MassEffect2Launcher.exe:*:Enabled:Mass Effect 2 Launcher"
"C:\Documents and Settings\Veronika\Local Settings\Temp\KEY.exe"="C:\Documents and Settings\Veronika\Local Settings\Temp\KEY.exe:*:Enabled:KEY"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\111_Verca\batman\Binaries\ShippingPC-BmGame.exe"="D:\111_Verca\batman\Binaries\ShippingPC-BmGame.exe:*:Enabled:Batman: Arkham Asylum"
"D:\111_Verca\witcher 2\bin\witcher2.exe"="D:\111_Verca\witcher 2\bin\witcher2.exe:*:Enabled:The Witcher 2: Assasins of Kings"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\111_Verca\APB\APB Reloaded\Binaries\APB.exe"="D:\111_Verca\APB\APB Reloaded\Binaries\APB.exe:*:Enabled:APB: APB.exe"
"D:\111_Verca\APB\APB Reloaded\Binaries\VivoxVoiceService.exe"="D:\111_Verca\APB\APB Reloaded\Binaries\VivoxVoiceService.exe:*:Enabled:APB: VivoxVoiceService.exe"
"D:\111_Verca\Anno_1701\Anno1701.exe"="D:\111_Verca\Anno_1701\Anno1701.exe:*:Disabled:Anno 1701"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Disabled:Bonjour"
"N:\Final Fantasy I & II\emulator NDS\DeSmuME_VS2008.exe"="N:\Final Fantasy I & II\emulator NDS\DeSmuME_VS2008.exe:*:Disabled:DeSmuME_VS2008"
"D:\111_Verca\Nintendo hry\ds emulator\DeSmuME_VS2008.exe"="D:\111_Verca\Nintendo hry\ds emulator\DeSmuME_VS2008.exe:*:Disabled:DeSmuME_VS2008"
"D:\111_Verca\atari\nwn2main_amdxp.exe"="D:\111_Verca\atari\nwn2main_amdxp.exe:*:Disabled:Neverwinter Nights 2 AMD"
"D:\111_Verca\atari\nwn2main.exe"="D:\111_Verca\atari\nwn2main.exe:*:Disabled:Neverwinter Nights 2 Main"
"D:\111_Verca\atari\nwn2server.exe"="D:\111_Verca\atari\nwn2server.exe:*:Disabled:Neverwinter Nights 2 Server"
"D:\111_Verca\atari\nwupdate.exe"="D:\111_Verca\atari\nwupdate.exe:*:Disabled:Neverwinter Nights 2 Updater"
"C:\Documents and Settings\All Users\Data aplikací\NexonUS\NGM\NGM.exe"="C:\Documents and Settings\All Users\Data aplikací\NexonUS\NGM\NGM.exe:*:Disabled:Nexon Game Manager"
"D:\111_Verca\vindictus\Vindictus\en-US\NMService.exe"="D:\111_Verca\vindictus\Vindictus\en-US\NMService.exe:*:Disabled:Nexon Messenger Core"
"C:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe"="C:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe:*:Disabled:Zoo Tycoon 2 Executable"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\QIP 2010\qip.exe"="C:\Program Files\QIP 2010\qip.exe:*:Enabled:QIP 2010"
"D:\111_Verca\mum\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="D:\111_Verca\mum\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"D:\111_Verca\m.o.m\WoW-3.2.0-enUS-downloader.exe"="D:\111_Verca\m.o.m\WoW-3.2.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\111_Verca\m.o.m\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"="D:\111_Verca\m.o.m\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\WoW-2.4.2-enGB-downloader.exe"="C:\Program Files\World of Warcraft\WoW-2.4.2-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\111_Verca\StarCraft.II.Wings.of.Liberty-RELOADED\StarCraft II\StarCraft II.exe"="D:\111_Verca\StarCraft.II.Wings.of.Liberty-RELOADED\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher"
"D:\111_Verca\mum\World of Warcraft\Launcher.exe"="D:\111_Verca\mum\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\111_Verca\Bon Jovi - 2001 - Greatest Hits\Bon Jovi\World of Warcraft\Launcher.exe"="D:\111_Verca\Bon Jovi - 2001 - Greatest Hits\Bon Jovi\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\111_Verca\Bon Jovi - 2001 - Greatest Hits\Bon Jovi\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="D:\111_Verca\Bon Jovi - 2001 - Greatest Hits\Bon Jovi\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"D:\111_Verca\Bon Jovi - 2001 - Greatest Hits\Bon Jovi\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"="D:\111_Verca\Bon Jovi - 2001 - Greatest Hits\Bon Jovi\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Documents and Settings\Veronika\Local Settings\Temp\Blizzard Installer Bootstrap - 0e1ee8fe\Installer.exe"="C:\Documents and Settings\Veronika\Local Settings\Temp\Blizzard Installer Bootstrap - 0e1ee8fe\Installer.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Pidgin\pidgin.exe"="C:\Program Files\Pidgin\pidgin.exe:*:Enabled:Pidgin"
"D:\111_Verca\swtor\Star Wars-The Old Republic\launcher.exe"="D:\111_Verca\swtor\Star Wars-The Old Republic\launcher.exe:*:Enabled:Star Wars - The Old Republic"
"D:\Verca\TERA\TERA-Launcher.exe"="D:\Verca\TERA\TERA-Launcher.exe:*:Enabled:TERA"
"D:\Verca\Mass Effect 3\Binaries\Win32\MassEffect3.exe"="D:\Verca\Mass Effect 3\Binaries\Win32\MassEffect3.exe:*:Enabled:Mass Effect(TM) 3"
"D:\Verca\Mass Effect 3 rLD\Mass Effect 3\Binaries\Win32\MassEffect3.exe"="D:\Verca\Mass Effect 3 rLD\Mass Effect 3\Binaries\Win32\MassEffect3.exe:*:Enabled:Mass Effect™ 3"
"C:\Program Files\Origin Games\Mass Effect 3 Demo\Binaries\Win32\MassEffect3Demo.exe"="C:\Program Files\Origin Games\Mass Effect 3 Demo\Binaries\Win32\MassEffect3Demo.exe:*:Enabled:Mass Effect™ 3 Demo"
"D:\Verca\Witcher 2 EE\The Witcher 2 Enhanced Edition\bin\witcher2.exe"="D:\Verca\Witcher 2 EE\The Witcher 2 Enhanced Edition\bin\witcher2.exe:*:Enabled:The Witcher 2: Assasins of Kings"
"D:\Verca\AC2\AssassinsCreedIIGame.exe"="D:\Verca\AC2\AssassinsCreedIIGame.exe:*:Enabled:Assassin's Creed II"
"D:\Verca\AC2\AssassinsCreedII.exe"="D:\Verca\AC2\AssassinsCreedII.exe:*:Enabled:Assassin's Creed II Update"
"D:\Verca\AC2\UPlayBrowser.exe"="D:\Verca\AC2\UPlayBrowser.exe:*:Enabled:Assassin's Creed II Uplay"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"D:\Verca\Secret World\The Secret World\ClientPatcher.exe"="D:\Verca\Secret World\The Secret World\ClientPatcher.exe:*:Enabled:The Secret World Launcher"
"C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe"="C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe:*:Enabled:Opera Internet Browser - Plugin wrapper"
"C:\Documents and Settings\Veronika\Local Settings\Temp\Gw2.exe"="C:\Documents and Settings\Veronika\Local Settings\Temp\Gw2.exe:*:Enabled:Guild Wars 2 Game Client"
"D:\Verca\GW2\Guild Wars 2\Gw2.exe"="D:\Verca\GW2\Guild Wars 2\Gw2.exe:*:Enabled:Guild Wars 2 Game Client"
"C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe"="C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe:*:Enabled:Update Engine"
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"D:\Verca\ACB\ACBSP.exe"="D:\Verca\ACB\ACBSP.exe:*:Enabled:Assassin's Creed Brotherhood"
"D:\Verca\ACB\ACBMP.exe"="D:\Verca\ACB\ACBMP.exe:*:Enabled:Assassin's Creed Brotherhood Multiplayer"
"D:\Verca\ACB\AssassinsCreedBrotherhood.exe"="D:\Verca\ACB\AssassinsCreedBrotherhood.exe:*:Enabled:Assassin's Creed Brotherhood Update"
"D:\Verca\ACB\UPlayBrowser.exe"="D:\Verca\ACB\UPlayBrowser.exe:*:Enabled:Assassin's Creed Brotherhood Uplay"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"D:\111_Verca\swtor\Star Wars-The Old Republic\launcher.exe"="D:\111_Verca\swtor\Star Wars-The Old Republic\launcher.exe:*:Enabled:Star Wars - The Old Republic"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"MSACM.MSNAUDIO"=msnaudio.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"VIDC.ACDV"=ACDV.dll
"msacm.siren"=sirenacm.dll
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.tscc"=tsccvid.dll
"msacm.l3codec"=l3codecp.acm
"VIDC.FFDS"=ff_vfw.dll
"msacm.avis"=ff_acm.acm
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"VIDC.FPS1"=frapsvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.txt - open - "C:\Program Files\PSPad editor\PSPad.exe" "%1"

======List of files/folders created in the last 1 month======

2012-08-14 15:55:37 ----D---- C:\rsit
2012-08-14 15:55:37 ----D---- C:\Program Files\trend micro
2012-08-12 02:43:04 ----A---- C:\WINDOWS\system32\stacsv.exe
2012-08-12 01:39:48 ----D---- C:\cabs
2012-08-11 21:31:51 ----D---- C:\Documents and Settings\Veronika\Data aplikací\PunkBuster
2012-08-10 20:54:41 ----D---- C:\Program Files\DIFX
2012-08-10 20:54:02 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2012-08-10 20:53:26 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2012-08-10 20:53:00 ----A---- C:\WINDOWS\system32\WdfCoInstaller01007.dll
2012-08-10 20:53:00 ----A---- C:\WINDOWS\system32\drivers\ggsemc.sys
2012-08-10 20:53:00 ----A---- C:\WINDOWS\system32\drivers\ggflt.sys
2012-08-02 19:34:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony
2012-08-02 19:27:54 ----D---- C:\Program Files\Avanquest update
2012-08-02 19:27:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avanquest
2012-08-02 19:25:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\BVRP Software
2012-07-18 20:10:39 ----D---- C:\Documents and Settings\All Users\Data aplikací\Hi-Rez Studios

======List of files/folders modified in the last 1 month======

2012-08-14 15:55:37 ----D---- C:\WINDOWS\Temp
2012-08-14 15:55:37 ----D---- C:\Program Files
2012-08-14 15:52:01 ----D---- C:\Documents and Settings\Veronika\Data aplikací\.purple
2012-08-14 14:49:32 ----D---- C:\WINDOWS\system32\CatRoot2
2012-08-14 14:47:35 ----D---- C:\WINDOWS
2012-08-14 14:47:35 ----A---- C:\WINDOWS\MAILTRAN.INI
2012-08-14 14:41:14 ----D---- C:\WINDOWS\system32\drivers
2012-08-14 14:39:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-08-14 10:38:25 ----D---- C:\WINDOWS\Prefetch
2012-08-14 10:25:09 ----HD---- C:\WINDOWS\inf
2012-08-13 17:39:53 ----D---- C:\Program Files\AGTH
2012-08-13 12:37:05 ----D---- C:\Downloads
2012-08-13 07:19:40 ----D---- C:\WINDOWS\Minidump
2012-08-12 18:16:34 ----SHD---- C:\WINDOWS\Installer
2012-08-12 18:16:34 ----SHD---- C:\Config.Msi
2012-08-12 18:16:33 ----D---- C:\WINDOWS\WinSxS
2012-08-12 18:13:23 ----D---- C:\WINDOWS\system32\DirectX
2012-08-12 18:10:38 ----RSD---- C:\WINDOWS\assembly
2012-08-12 18:00:03 ----HD---- C:\Program Files\InstallShield Installation Information
2012-08-12 15:46:32 ----D---- C:\Documents and Settings\Veronika\Data aplikací\uTorrent
2012-08-12 02:45:30 ----D---- C:\WINDOWS\system32
2012-08-12 02:43:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-08-12 02:20:04 ----D---- C:\Program Files\Intel Audio Studio
2012-08-12 01:37:25 ----D---- C:\Program Files\NVIDIA Corporation
2012-08-11 21:32:31 ----D---- C:\Documents and Settings\Veronika\Data aplikací\Ubisoft
2012-08-11 21:32:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ubisoft
2012-08-11 21:31:53 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2012-08-11 21:31:53 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2012-08-10 20:54:01 ----D---- C:\Program Files\FlashGet
2012-08-10 20:53:00 ----DC---- C:\WINDOWS\system32\DRVSTORE
2012-08-10 20:39:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson
2012-08-10 20:39:42 ----D---- C:\Program Files\Sony Ericsson
2012-08-05 23:16:51 ----A---- C:\WINDOWS\WDICT32.INI
2012-08-05 12:43:09 ----SD---- C:\WINDOWS\Tasks
2012-08-05 12:42:57 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-08-03 15:29:36 ----D---- C:\Program Files\Opera
2012-08-02 21:18:59 ----D---- C:\Documents and Settings\Veronika\Data aplikací\GetRightToGo
2012-08-02 19:34:53 ----D---- C:\Program Files\Sony
2012-07-31 15:19:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-07-19 20:31:57 ----D---- C:\Documents and Settings\Veronika\Data aplikací\vlc
2012-07-15 22:24:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\PMB Files
2012-07-15 14:29:19 ----A---- C:\WINDOWS\NeroDigital.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2005-08-10 19968]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-07-05 721904]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-09-11 96408]
R1 FsVga;FsVga; C:\WINDOWS\system32\DRIVERS\fsvga.sys [2004-08-18 12160]
R1 InCDPass;InCDPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys [2005-07-08 29696]
R1 incdrm;InCD Reader; C:\WINDOWS\system32\drivers\incdrm.sys [2005-07-08 28672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 mbmiodrvr;mbmiodrvr; \??\C:\WINDOWS\system32\mbmiodrvr.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-11-13 20747]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-04-17 281760]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-04-17 25888]
R3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2006-04-13 203776]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HECI;Intel(R) AMT Management Interface; C:\WINDOWS\system32\DRIVERS\HECI.sys [2006-05-03 43264]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys [2007-09-05 92544]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2012-05-15 14014656]
R3 STHDA;IDT High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2008-04-10 1271032]
R3 tap0901_2gm;VPN Anonymizer Adapter; C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 30720]
R3 TClass2k;Tablet Class Driver; C:\WINDOWS\system32\DRIVERS\TClass2k.sys [2003-03-05 23202]
R3 UCTblHid;HID Tablet Port Driver; C:\WINDOWS\system32\DRIVERS\UCTblHid.sys [2003-03-05 11090]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
R3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
R3 xcpip;Ovladač protokolu TCP/IP; C:\WINDOWS\system32\drivers\xcpip.sys []
R3 xpsec;Ovladač IPSEC; C:\WINDOWS\system32\drivers\xpsec.sys []
R4 InCDfs;InCD File System; C:\WINDOWS\system32\drivers\InCDfs.sys [2005-07-08 99584]
S2 npkcrypt;npkcrypt; \??\C:\Nexon\Mabinogi\npkcrypt.sys []
S3 aoh3xy14;aoh3xy14; C:\WINDOWS\system32\drivers\aoh3xy14.sys []
S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-09-29 2456064]
S3 BCM42RLY;BCM42RLY; \??\C:\WINDOWS\System32\BCM42RLY.SYS []
S3 cmudau;C-Media USB Sound Interface; C:\WINDOWS\system32\drivers\cmudaxu.sys [2005-07-20 1390656]
S3 cpuz130;cpuz130; \??\C:\DOCUME~1\Veronika\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 dj6e8bn0.sys;dj6e8bn0.sys; \??\C:\WINDOWS\system32\drivers\dj6e8bn0.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 genmcmn;Scroll Mouse Driver; C:\WINDOWS\system32\DRIVERS\gmfiltr.sys [2004-09-15 8576]
S3 genmcmnUSB;USB Scroll Mouse Driver; C:\WINDOWS\system32\DRIVERS\gflmouhid.sys [2004-04-19 6656]
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2009-04-06 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2009-04-06 25512]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-08-16 25280]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2008-09-26 101376]
S3 IDMTDI;IDMTDI; C:\WINDOWS\system32\DRIVERS\idmtdi.sys []
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys [2006-03-13 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2006-03-13 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\k750mdm.sys [2006-03-13 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2006-03-13 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\k750obex.sys [2006-03-13 79488]
S3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvw32.sys []
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-06-29 42512]
S3 npkcusb;npkcusb; \??\C:\Nexon\Mabinogi\npkcusb.sys []
S3 RT61;Linksys Wireless-G PCI Adapter Driver(RT61); C:\WINDOWS\system32\DRIVERS\RT61.sys [2005-10-27 356096]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE31bus.sys [2006-11-10 61600]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE31mdfl.sys [2006-11-10 9360]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE31mdm.sys [2006-11-10 97184]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE31mgmt.sys [2006-11-10 88688]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS); C:\WINDOWS\system32\DRIVERS\se31nd5.sys [2006-11-10 18704]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\SE31obex.sys [2006-11-10 86560]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM); C:\WINDOWS\system32\DRIVERS\se31unic.sys [2006-11-10 90800]
S3 sfng32;Sonic Focus Plugin for Sigmatel HDA; C:\WINDOWS\system32\drivers\sfng32.sys [2005-12-02 41728]
S3 Tablet2k;Serial Tablet Port Driver; C:\WINDOWS\System32\Drivers\Tablet2k.sys [2000-06-13 15370]
S3 UfasoftSnifDriver4;Ufasoft Snif Driver v4; \??\C:\Program Files\Ufasoft\Sniffer\usft_sn4.sys []
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\vmnetadapter.sys []
S3 VSPerfDrv90;Performance Tools Driver 9.0; \??\C:\Program Files\Microsoft Visual Studio 9.0\Team Tools\Performance Tools\VSPerfDrv90.sys []
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apache2.2;Apache2.2; c:\xampp\apache\bin\apache.exe [2007-09-21 17408]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-10-31 110592]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 Diskeeper;Diskeeper; C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe [2006-03-09 630905]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-09-11 735960]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-06-10 222456]
R2 InCDsrv;InCD Helper; C:\Program Files\Ahead\InCD\InCDsrv.exe [2005-07-08 871424]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-12-18 73728]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 mysql;mysql; C:\xampp\mysql\bin\mysqld-nt.exe [2007-07-06 5730304]
R2 npkcmsvc;npkcmsvc; C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2012-05-15 164160]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R2 OTi Card Reader Service;OTi Card Reader Service; C:\Program Files\CardReader2.0\OTiReader.exe [2004-03-04 131177]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2012-08-11 75136]
R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2006-11-02 174656]
R2 Skype C2C Service;Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-07-05 3048136]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 WinTabService;WinTab Service; C:\WINDOWS\system32\DRIVERS\WtSrv.exe [2003-09-30 40960]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-09-29 483328]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2007-09-28 593920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-04-05 158856]
S2 WMP54Gv4SVC;WMP54Gv4SVC; C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe [2005-07-04 53307]
S2 XAMPP;XAMPP Service; C:\xampp\service.exe [2006-10-23 60928]
S3 Adobe Version Cue CS3;Adobe Version Cue CS3; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe [2007-03-20 153792]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-09-11 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2007-11-17 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-01-28 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2009-10-06 3401016]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-06-29 92792]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
S4 msvsmon90;Visual Studio 2008 Remote Debugger; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2007-11-07 3004416]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#2 Příspěvek od Teochi »

Omlouvám se za pozdní odpověd, ale už to tady mám :) .

Log z RK:

RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v: Normální režim
Uživatel: Veronika [Práva správce]
Mód: Kontrola -- Datum: 08/14/2012 17:20:49

¤¤¤ Škodlivé procesy: 1 ¤¤¤
[SUSP PATH] c2c_service.exe -- C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe -> KILLED [TermProc]

¤¤¤ Záznamy Registrů: 3 ¤¤¤
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (187.4.205.90:8080) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{5FE07B7D-A137-4BF8-9919-115E06BFC2A3} : NameServer (195.70.130.1,195.70.130.19) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤
SSDT[19] : NtAssignProcessToJobObject @ 0x805D66A0 -> HOOKED (Unknown @ 0x8A74DC90)
SSDT[57] : NtDebugActiveProcess @ 0x80643A1C -> HOOKED (Unknown @ 0x8A74E200)
SSDT[68] : NtDuplicateObject @ 0x805BE010 -> HOOKED (Unknown @ 0x8A74E2F0)
SSDT[122] : NtOpenProcess @ 0x805CB456 -> HOOKED (Unknown @ 0x8A74D590)
SSDT[128] : NtOpenThread @ 0x805CB6E2 -> HOOKED (Unknown @ 0x8A74D800)
SSDT[137] : NtProtectVirtualMemory @ 0x805B8426 -> HOOKED (Unknown @ 0x8A74DFD0)
SSDT[180] : NtQueueApcThread @ 0x805D2756 -> HOOKED (Unknown @ 0x8A74E0E0)
SSDT[213] : NtSetContextThread @ 0x805D2C1A -> HOOKED (Unknown @ 0x8A74DEC0)
SSDT[229] : NtSetInformationThread @ 0x805CC124 -> HOOKED (Unknown @ 0x8A74DD90)
SSDT[237] : NtSetSecurityObject @ 0x805C0636 -> HOOKED (Unknown @ 0x8A74ADA0)
SSDT[253] : NtSuspendProcess @ 0x805D4AE0 -> HOOKED (Unknown @ 0x8A74DB90)
SSDT[254] : NtSuspendThread @ 0x805D4952 -> HOOKED (Unknown @ 0x8A74DA80)
SSDT[257] : NtTerminateProcess @ 0x805D22D8 -> HOOKED (Unknown @ 0x8A74D6E0)
SSDT[258] : NtTerminateThread @ 0x805D24D2 -> HOOKED (Unknown @ 0x8A74DA50)
SSDT[277] : NtWriteVirtualMemory @ 0x805B43D4 -> HOOKED (Unknown @ 0x8A74E6D0)
IRP[IRP_MJ_CREATE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DFBB40)
IRP[IRP_MJ_CLOSE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DFBB40)
IRP[IRP_MJ_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DFBB40)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] sfsync02.sys @ 0xB80E98B4)
IRP[IRP_MJ_SYSTEM_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DFBB40)
IRP[IRP_MJ_DEVICE_CHANGE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DFBB40)

¤¤¤ Nákaza : Root.MBR ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost
216.107.250.194 nprotect.lineage2.com
81.0.254.162 L2authd.Lineage2.com


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST3320620AS +++++
--- User ---
[MBR] a7df3691060dc7573485f124f2dff178
[BSP] 9aa389cafe9440f542c6c17d735bfd24 : Whistler/Sinowal MBR Code!
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 218148 Mo
1 - [XXXXXX] LINUX (0x83) [VISIBLE] Offset (sectors): 446767650 | Size: 83509 Mo
2 - [XXXXXX] EXTEN (0x05) [VISIBLE] Offset (sectors): 617795640 | Size: 3584 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: WDC WD5000AAVS-00ZTB0 +++++
--- User ---
[MBR] bbf28a37d883962f4894234e4ce151fc
[BSP] f745e28fdfbc5dd88a9668f955fee80a : MBR Code unknown
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[1].txt >>
RKreport[1].txt


------------------------------------------------------------------------------------------------------------------


log z Mbrscan:

Kód: Vybrat vše

MBRScan v1.1.1

OS             : Windows XP Home Service Pack 3 (32 bit)
PROCESSOR      : x86 Family 6 Model 15 Stepping 6, GenuineIntel
BOOT           : Normal Boot
DATE           : 2012/08/14 (ISO 8601) at 17:22:46
________________________________________________________________________________

DISK           : Device\Harddisk0\DR0 __ST3320620AS (3.AAD)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : YES
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

DISK           : Device\Harddisk1\DR1 __WDC WD5000AAVS-00ZTB0 (01.01B01)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : YES
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

DISK           : Device\Harddisk6\DR14 __Kingston DataTraveler 2.0 (1.00)
BUS_TYPE       : (0x07)  USB
USE_PIO        : NO
MAX_TRANSFER   : 64 Kb
ALIGNMENT_MASK : byte aligned
________________________________________________________________________________

Device\Harddisk0\DR0	298.1 Go  [Fixed] ==> Unknown MBR Code

MBR_MD5   : A7DF3691060DC7573485F124F2DFF178
MBR_SHA1  : A4A5A8D2B797770BFE8E72A31E5457B2DF0A6C59

Device\Harddisk0\Partition1	213.0 Go  	0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2	81.55 Go  	0x83 Linux 
Device\Harddisk0\Partition3	3.50 Go  	0x82 Linux Swap 
________________________________________________________________________________

Device\Harddisk1\DR1	465.8 Go  [Fixed] ==> Unknown MBR Code

MBR_MD5   : BBF28A37D883962F4894234E4CE151FC
MBR_SHA1  : 4D27F7C19A976B49EDB72DF279148F90E8279955

Device\Harddisk1\Partition1	465.8 Go  	0x07 NTFS / HPFS
________________________________________________________________________________

Device\Harddisk6\DR14	7.51 Go  [Removable] ==> Unknown MBR Code

MBR_MD5   : 2F99BFEBD09C9400DB6595403C4D5B83
MBR_SHA1  : CDE6BD09910BCA5AFD4A7AD1393FADBDDA653D15

Device\Harddisk6\Partition1	7.51 Go
________________________________________________________________________________

############################### Additional scan ################################

DRIVER  : C:\WINDOWS\system32\drivers\xpsec.sys => Invisible on the disk
ADDRESS : 0xB4187000
SIZE    : 76.0 Ko

DRIVER  : C:\WINDOWS\system32\drivers\xcpip.sys => Invisible on the disk
ADDRESS : 0xB412E000
SIZE    : 356.0 Ko

SystemStartOptions : NOEXECUTE=OPTIN  FASTDETECT  USEPMTIMER

________________________________________________________________________________

_______MBR   \Device\Harddisk0\DR0  

0x00000000   33 C0 8E D8 8E C0 8E D0 BC 00 7C BE 1A 7C BF 00   3À.Ø.À.м.|¾.|¿.
0x00000010   06 B9 E6 01 50 57 FC F3 A4 CB BE A4 07 B1 04 90   .¹æ.PWüó¤Ë¾¤.±..
0x00000020   80 3C 80 74 0D 38 2C 0F 85 C0 00 83 C6 10 E2 F0   .<.t.8,..À..Æ.âð
0x00000030   CD 18 66 8B 44 08 8B 14 89 E3 B9 01 00 E8 64 00   Í.f.D....ã¹..èd.
0x00000040   73 0C 8B 4C 02 B8 01 02 CD 13 0F 82 B8 00 B9 55   s..L.¸..Í...¸.¹U
0x00000050   AA 2B 0E FE 7D 0F 85 CF 00 66 B8 00 00 00 00 66   ª+.þ}..Ï.f¸....f
0x00000060   39 44 08 72 08 66 8B 44 08 66 03 44 0C 83 C6 10   9D.r.f.D.f.D..Æ.
0x00000070   81 FE E4 07 72 E9 66 09 C0 74 1E B9 09 00 81 C3   .þä.réf.Àt.¹...Ã
0x00000080   00 02 E8 1F 00 72 12 89 DE 81 C6 0C 02 8D 54 F4   ..è..r..Þ.Æ...Tô
0x00000090   66 81 3C 75 2F F3 A4 74 05 EA 00 7C 00 00 89 DE   f.<u/ó¤t.ê.|...Þ
0x000000A0   FF D2 EB F5 66 60 B2 80 BB AA 55 B4 41 CD 13 73   .Òëõf`².»ªU´AÍ.s
0x000000B0   04 F9 66 61 C3 81 FB 55 AA 75 F6 F6 C1 01 74 F1   .ùfaÃ.ûUªuööÁ.tñ
0x000000C0   66 61 66 60 6A 00 6A 00 66 50 06 53 51 6A 10 B4   faf`j.j.fP.SQj.´
0x000000D0   42 89 E6 CD 13 61 66 61 C3 5E AC 08 C0 74 FC 56   B.æÍ.afaÃ^¬.ÀtüV
0x000000E0   1E BB 07 00 B4 0E CD 10 1F EB EE E8 EB FF 49 6E   .»..´.Í..ëîèë.In
0x000000F0   76 61 6C 69 64 20 70 61 72 74 69 74 69 6F 6E 20   valid partition 
0x00000100   74 61 62 6C 65 00 E8 D0 FF 45 72 72 6F 72 20 6C   table.èÐ.Error l
0x00000110   6F 61 64 69 6E 67 20 6F 70 65 72 61 74 69 6E 67   oading operating
0x00000120   20 73 79 73 74 65 6D 00 E8 AE FF 4D 69 73 73 69    system.è®.Missi
0x00000130   6E 67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73   ng operating sys
0x00000140   74 65 6D 00 00 00 00 00 00 00 00 00 00 00 00 00   tem.............
0x00000150   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000160   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000170   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 00 00 00 FC 02 FC 02 00 00 80 01   ........ü.ü.....
0x000001C0   01 00 07 FE FF FF 3F 00 00 00 E3 21 A1 1A 00 FE   ...þ..?...ã!¡..þ
0x000001D0   FF FF 83 FE FF FF 22 22 A1 1A 16 AE 31 0A 00 FE   ...þ..""¡..®1..þ
0x000001E0   FF FF 05 FE FF FF 38 D0 D2 24 89 06 70 00 00 00   ...þ..8ÐÒ$..p...
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

__________________________16_BIT_ASM_CODE
   
0x0000    33c0            XOR AX, AX   
0x0002    8ed8            MOV DS, AX   
0x0004    8ec0            MOV ES, AX   
0x0006    8ed0            MOV SS, AX   
0x0008    bc 007c         MOV SP, 0x7c00   
0x000B    be 1a7c         MOV SI, 0x7c1a   
0x000E    bf 0006         MOV DI, 0x600   
0x0011    b9 e601         MOV CX, 0x1e6   
0x0014    50              PUSH AX   
0x0015    57              PUSH DI   
0x0016    fc              CLD   
0x0017    f3 a4           REP MOVSB   
0x0019    cb              RETF   
0x001A    be a407         MOV SI, 0x7a4   
0x001D    b1 04           MOV CL, 0x4   
0x001F    90              NOP   
0x0020    803c 80         CMP BYTE [SI], 0x80   
0x0023    74 0d           JZ 0x32   
0x0025    382c            CMP [SI], CH   
0x0027    0f85 c000       JNZ 0xeb   
0x002B    83c6 10         ADD SI, 0x10   
0x002E    e2 f0           LOOP 0x20   
0x0030    cd 18           INT 0x18   
0x0032    66 8b44 08      MOV EAX, [SI+0x8]   
0x0036    8b14            MOV DX, [SI]   
0x0038    89e3            MOV BX, SP   
0x003A    b9 0100         MOV CX, 0x1   
0x003D    e8 6400         CALL 0xa4   
0x0040    73 0c           JAE 0x4e   
0x0042    8b4c 02         MOV CX, [SI+0x2]   
0x0045    b8 0102         MOV AX, 0x201   
0x0048    cd 13           INT 0x13   
0x004A    0f82 b800       JB 0x106   
0x004E    b9 55aa         MOV CX, 0xaa55   
0x0051    2b0e fe7d       SUB CX, [0x7dfe]   
0x0055    0f85 cf00       JNZ 0x128   
0x0059    66 b8 00000000  MOV EAX, 0x0   
0x005F    66 3944 08      CMP [SI+0x8], EAX   
0x0063    72 08           JB 0x6d   
0x0065    66 8b44 08      MOV EAX, [SI+0x8]   
0x0069    66 0344 0c      ADD EAX, [SI+0xc]   
0x006D    83c6 10         ADD SI, 0x10   
0x0070    81fe e407       CMP SI, 0x7e4   
0x0074    72 e9           JB 0x5f   
0x0076    66 09c0         OR EAX, EAX   
0x0079    74 1e           JZ 0x99   
0x007B    b9 0900         MOV CX, 0x9   
0x007E    81c3 0002       ADD BX, 0x200   
0x0082    e8 1f00         CALL 0xa4   
0x0085    72 12           JB 0x99   
0x0087    89de            MOV SI, BX   
0x0089    81c6 0c02       ADD SI, 0x20c   
0x008D    8d54 f4         LEA DX, [SI-0xc]   
0x0090    66 813c 752ff3a4CMP DWORD [SI], 0xa4f32f75   
0x0097    74 05           JZ 0x9e   
0x0099    ea 007c 0000    JMP FAR 0x0:0x7c00   
0x009E    89de            MOV SI, BX   
0x00A0    ffd2            CALL DX   
0x00A2    eb f5           JMP 0x99   
0x00A4    66 60           PUSHAD   
0x00A6    b2 80           MOV DL, 0x80   
0x00A8    bb aa55         MOV BX, 0x55aa   
0x00AB    b4 41           MOV AH, 0x41   
0x00AD    cd 13           INT 0x13   
0x00AF    73 04           JAE 0xb5   
0x00B1    f9              STC   
0x00B2    66 61           POPAD   
0x00B4    c3              RET   
0x00B5    81fb 55aa       CMP BX, 0xaa55   
0x00B9    75 f6           JNZ 0xb1   
0x00BB    f6c1 01         TEST CL, 0x1   
0x00BE    74 f1           JZ 0xb1   
0x00C0    66 61           POPAD   
0x00C2    66 60           PUSHAD   
0x00C4    6a 00           PUSH 0x0   
0x00C6    6a 00           PUSH 0x0   
0x00C8    66 50           PUSH EAX   
0x00CA    06              PUSH ES   
0x00CB    53              PUSH BX   
0x00CC    51              PUSH CX   
0x00CD    6a 10           PUSH 0x10   
0x00CF    b4 42           MOV AH, 0x42   
0x00D1    89e6            MOV SI, SP   
0x00D3    cd 13           INT 0x13   
0x00D5    61              POPA   
0x00D6    66 61           POPAD   
0x00D8    c3              RET   
0x00D9    5e              POP SI   
0x00DA    ac              LODSB   
0x00DB    08c0            OR AL, AL   
0x00DD    74 fc           JZ 0xdb   
0x00DF    56              PUSH SI   
0x00E0    1e              PUSH DS   
0x00E1    bb 0700         MOV BX, 0x7   
0x00E4    b4 0e           MOV AH, 0xe   
0x00E6    cd 10           INT 0x10   
0x00E8    1f              POP DS   
0x00E9    eb ee           JMP 0xd9   
0x00EB    e8 ebff         CALL 0xd9   
0x00EE    49              DEC CX   
0x00EF    6e              OUTSB   
0x00F0    76 61           JBE 0x153   
0x00F2    6c              INSB   
0x00F3    6964 20 7061    IMUL SP, [SI+0x20], 0x6170   
0x00F8    72 74           JB 0x16e   
0x00FA    6974 69 6f6e    IMUL SI, [SI+0x69], 0x6e6f   
0x00FF    2074 61         AND [SI+0x61], DH   
0x0102    626c 65         BOUND BP, [SI+0x65]   
0x0105    00e8            ADD AL, CH   
0x0107    d0ff            SAR BH, 0x1   
0x0109    45              INC BP   
0x010A    72 72           JB 0x17e   
0x010C    6f              OUTSW   
0x010D    72 20           JB 0x12f   
0x010F    6c              INSB   
0x0110    6f              OUTSW   
0x0111    61              POPA   
0x0112    64 696e 67 206f IMUL BP, FS:[BP+0x67], 0x6f20   
0x0118    70 65           JO 0x17f   
0x011A    72 61           JB 0x17d   
0x011C    74 69           JZ 0x187   
0x011E    6e              OUTSB   
0x011F    67 2073 79      AND [EBX+0x79], DH   
0x0123    73 74           JAE 0x199   
0x0125    65 6d           INS WORD GS:[DI], DX   
0x0127    00e8            ADD AL, CH   
0x0129    ae              SCASB   
0x012A    ff4d 69         DEC WORD [DI+0x69]   
0x012D    73 73           JAE 0x1a2   
0x012F    696e 67 206f    IMUL BP, [BP+0x67], 0x6f20   
0x0134    70 65           JO 0x19b   
0x0136    72 61           JB 0x199   
0x0138    74 69           JZ 0x1a3   
0x013A    6e              OUTSB   
0x013B    67 2073 79      AND [EBX+0x79], DH   
0x013F    73 74           JAE 0x1b5   
0x0141    65 6d           INS WORD GS:[DI], DX   
0x0143    0000            ADD [BX+SI], AL   
0x0145    0000            ADD [BX+SI], AL   
0x0147    0000            ADD [BX+SI], AL   
0x0149    0000            ADD [BX+SI], AL   
0x014B    0000            ADD [BX+SI], AL   
0x014D    0000            ADD [BX+SI], AL   
0x014F    0000            ADD [BX+SI], AL   
0x0151    0000            ADD [BX+SI], AL   
0x0153    0000            ADD [BX+SI], AL   
0x0155    0000            ADD [BX+SI], AL   
0x0157    0000            ADD [BX+SI], AL   
0x0159    0000            ADD [BX+SI], AL   
0x015B    0000            ADD [BX+SI], AL   
0x015D    0000            ADD [BX+SI], AL   
0x015F    0000            ADD [BX+SI], AL   
0x0161    0000            ADD [BX+SI], AL   
0x0163    0000            ADD [BX+SI], AL   
0x0165    0000            ADD [BX+SI], AL   
0x0167    0000            ADD [BX+SI], AL   
0x0169    0000            ADD [BX+SI], AL   
0x016B    0000            ADD [BX+SI], AL   
0x016D    0000            ADD [BX+SI], AL   
0x016F    0000            ADD [BX+SI], AL   
0x0171    0000            ADD [BX+SI], AL   
0x0173    0000            ADD [BX+SI], AL   
0x0175    0000            ADD [BX+SI], AL   
0x0177    0000            ADD [BX+SI], AL   
0x0179    0000            ADD [BX+SI], AL   
0x017B    0000            ADD [BX+SI], AL   
0x017D    0000            ADD [BX+SI], AL   
0x017F    0000            ADD [BX+SI], AL   
0x0181    0000            ADD [BX+SI], AL   
0x0183    0000            ADD [BX+SI], AL   
0x0185    0000            ADD [BX+SI], AL   
0x0187    0000            ADD [BX+SI], AL   
0x0189    0000            ADD [BX+SI], AL   
0x018B    0000            ADD [BX+SI], AL   
0x018D    0000            ADD [BX+SI], AL   
0x018F    0000            ADD [BX+SI], AL   
0x0191    0000            ADD [BX+SI], AL   
0x0193    0000            ADD [BX+SI], AL   
0x0195    0000            ADD [BX+SI], AL   
0x0197    0000            ADD [BX+SI], AL   
0x0199    0000            ADD [BX+SI], AL   
0x019B    0000            ADD [BX+SI], AL   
0x019D    0000            ADD [BX+SI], AL   
0x019F    0000            ADD [BX+SI], AL   
0x01A1    0000            ADD [BX+SI], AL   
0x01A3    0000            ADD [BX+SI], AL   
0x01A5    0000            ADD [BX+SI], AL   
0x01A7    0000            ADD [BX+SI], AL   
0x01A9    0000            ADD [BX+SI], AL   
0x01AB    0000            ADD [BX+SI], AL   
0x01AD    0000            ADD [BX+SI], AL   
0x01AF    0000            ADD [BX+SI], AL   
0x01B1    0000            ADD [BX+SI], AL   
0x01B3    0000            ADD [BX+SI], AL   
0x01B5    0000            ADD [BX+SI], AL   
0x01B7    00fc            ADD AH, BH   
0x01B9    02fc            ADD BH, AH   
0x01BB    0200            ADD AL, [BX+SI]   
0x01BD    0080 0101       ADD [BX+SI+0x101], AL   
0x01C1    0007            ADD [BX], AL   
0x01C3    fe              DB 0xfe   
0x01C4    ff              DB 0xff   
0x01C5    ff              DB 0xff   
0x01C6    3f              AAS   
0x01C7    0000            ADD [BX+SI], AL   
0x01C9    00e3            ADD BL, AH   
0x01CB    21a1 1a00       AND [BX+DI+0x1a], SP   
0x01CF    fe              DB 0xfe   
0x01D0    ff              DB 0xff   
0x01D1    ff83 feff       INC WORD [BP+DI-0x2]   
0x01D5    ff22            JMP [BP+SI]   
0x01D7    22a1 1a16       AND AH, [BX+DI+0x161a]   
0x01DB    ae              SCASB   
0x01DC    310a            XOR [BP+SI], CX   
0x01DE    00fe            ADD DH, BH   
0x01E0    ff              DB 0xff   
0x01E1    ff05            INC WORD [DI]   
0x01E3    fe              DB 0xfe   
0x01E4    ff              DB 0xff   
0x01E5    ff              DB 0xff   
0x01E6    38d0            CMP AL, DL   
0x01E8    d224            SHL BYTE [SI], CL   
0x01EA    8906 7000       MOV [0x70], AX   
0x01EE    0000            ADD [BX+SI], AL   
0x01F0    0000            ADD [BX+SI], AL   
0x01F2    0000            ADD [BX+SI], AL   
0x01F4    0000            ADD [BX+SI], AL   
0x01F6    0000            ADD [BX+SI], AL   
0x01F8    0000            ADD [BX+SI], AL   
0x01FA    0000            ADD [BX+SI], AL   
0x01FC    0000            ADD [BX+SI], AL   
0x01FE    55              PUSH BP   
0x01FF    aa              STOSB   


_______MBR   \Device\Harddisk1\DR1  

0x00000000   FA B8 00 10 8E D0 BC 00 B0 B8 00 00 8E D8 8E C0   ú¸...м.°¸...Ø.À
0x00000010   FB BE 00 7C BF 00 06 B9 00 02 F3 A4 EA 21 06 00   û¾.|¿..¹..ó¤ê!..
0x00000020   00 BE BE 07 38 04 75 0B 83 C6 10 81 FE FE 07 75   .¾¾.8.u..Æ..þþ.u
0x00000030   F3 EB 16 B4 02 B0 01 BB 00 7C B2 80 8A 74 01 8B   óë.´.°.».|²..t..
0x00000040   4C 02 CD 13 EA 00 7C 00 00 EB FE 00 00 00 00 00   L.Í.ê.|..ëþ.....
0x00000050   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000060   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000070   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000080   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000090   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000000A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000000B0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000000C0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000000D0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000000E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000000F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000100   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000110   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000120   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000130   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000140   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000150   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000160   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000170   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 00 00 00 67 46 02 00 00 00 00 01   ........gF......
0x000001C0   01 00 07 FE FF FF 3F 00 00 00 02 4C 38 3A 00 00   ...þ..?....L8:..
0x000001D0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

__________________________16_BIT_ASM_CODE
   
0x0000    fa              CLI   
0x0001    b8 0010         MOV AX, 0x1000   
0x0004    8ed0            MOV SS, AX   
0x0006    bc 00b0         MOV SP, 0xb000   
0x0009    b8 0000         MOV AX, 0x0   
0x000C    8ed8            MOV DS, AX   
0x000E    8ec0            MOV ES, AX   
0x0010    fb              STI   
0x0011    be 007c         MOV SI, 0x7c00   
0x0014    bf 0006         MOV DI, 0x600   
0x0017    b9 0002         MOV CX, 0x200   
0x001A    f3 a4           REP MOVSB   
0x001C    ea 2106 0000    JMP FAR 0x0:0x621   
0x0021    be be07         MOV SI, 0x7be   
0x0024    3804            CMP [SI], AL   
0x0026    75 0b           JNZ 0x33   
0x0028    83c6 10         ADD SI, 0x10   
0x002B    81fe fe07       CMP SI, 0x7fe   
0x002F    75 f3           JNZ 0x24   
0x0031    eb 16           JMP 0x49   
0x0033    b4 02           MOV AH, 0x2   
0x0035    b0 01           MOV AL, 0x1   
0x0037    bb 007c         MOV BX, 0x7c00   
0x003A    b2 80           MOV DL, 0x80   
0x003C    8a74 01         MOV DH, [SI+0x1]   
0x003F    8b4c 02         MOV CX, [SI+0x2]   
0x0042    cd 13           INT 0x13   
0x0044    ea 007c 0000    JMP FAR 0x0:0x7c00   
0x0049    eb fe           JMP 0x49   
0x004B    0000            ADD [BX+SI], AL   
0x004D    0000            ADD [BX+SI], AL   
0x004F    0000            ADD [BX+SI], AL   
0x0051    0000            ADD [BX+SI], AL   
0x0053    0000            ADD [BX+SI], AL   
0x0055    0000            ADD [BX+SI], AL   
0x0057    0000            ADD [BX+SI], AL   
0x0059    0000            ADD [BX+SI], AL   
0x005B    0000            ADD [BX+SI], AL   
0x005D    0000            ADD [BX+SI], AL   
0x005F    0000            ADD [BX+SI], AL   
0x0061    0000            ADD [BX+SI], AL   
0x0063    0000            ADD [BX+SI], AL   
0x0065    0000            ADD [BX+SI], AL   
0x0067    0000            ADD [BX+SI], AL   
0x0069    0000            ADD [BX+SI], AL   
0x006B    0000            ADD [BX+SI], AL   
0x006D    0000            ADD [BX+SI], AL   
0x006F    0000            ADD [BX+SI], AL   
0x0071    0000            ADD [BX+SI], AL   
0x0073    0000            ADD [BX+SI], AL   
0x0075    0000            ADD [BX+SI], AL   
0x0077    0000            ADD [BX+SI], AL   
0x0079    0000            ADD [BX+SI], AL   
0x007B    0000            ADD [BX+SI], AL   
0x007D    0000            ADD [BX+SI], AL   
0x007F    0000            ADD [BX+SI], AL   
0x0081    0000            ADD [BX+SI], AL   
0x0083    0000            ADD [BX+SI], AL   
0x0085    0000            ADD [BX+SI], AL   
0x0087    0000            ADD [BX+SI], AL   
0x0089    0000            ADD [BX+SI], AL   
0x008B    0000            ADD [BX+SI], AL   
0x008D    0000            ADD [BX+SI], AL   
0x008F    0000            ADD [BX+SI], AL   
0x0091    0000            ADD [BX+SI], AL   
0x0093    0000            ADD [BX+SI], AL   
0x0095    0000            ADD [BX+SI], AL   
0x0097    0000            ADD [BX+SI], AL   
0x0099    0000            ADD [BX+SI], AL   
0x009B    0000            ADD [BX+SI], AL   
0x009D    0000            ADD [BX+SI], AL   
0x009F    0000            ADD [BX+SI], AL   
0x00A1    0000            ADD [BX+SI], AL   
0x00A3    0000            ADD [BX+SI], AL   
0x00A5    0000            ADD [BX+SI], AL   
0x00A7    0000            ADD [BX+SI], AL   
0x00A9    0000            ADD [BX+SI], AL   
0x00AB    0000            ADD [BX+SI], AL   
0x00AD    0000            ADD [BX+SI], AL   
0x00AF    0000            ADD [BX+SI], AL   
0x00B1    0000            ADD [BX+SI], AL   
0x00B3    0000            ADD [BX+SI], AL   
0x00B5    0000            ADD [BX+SI], AL   
0x00B7    0000            ADD [BX+SI], AL   
0x00B9    0000            ADD [BX+SI], AL   
0x00BB    0000            ADD [BX+SI], AL   
0x00BD    0000            ADD [BX+SI], AL   
0x00BF    0000            ADD [BX+SI], AL   
0x00C1    0000            ADD [BX+SI], AL   
0x00C3    0000            ADD [BX+SI], AL   
0x00C5    0000            ADD [BX+SI], AL   
0x00C7    0000            ADD [BX+SI], AL   
0x00C9    0000            ADD [BX+SI], AL   
0x00CB    0000            ADD [BX+SI], AL   
0x00CD    0000            ADD [BX+SI], AL   
0x00CF    0000            ADD [BX+SI], AL   
0x00D1    0000            ADD [BX+SI], AL   
0x00D3    0000            ADD [BX+SI], AL   
0x00D5    0000            ADD [BX+SI], AL   
0x00D7    0000            ADD [BX+SI], AL   
0x00D9    0000            ADD [BX+SI], AL   
0x00DB    0000            ADD [BX+SI], AL   
0x00DD    0000            ADD [BX+SI], AL   
0x00DF    0000            ADD [BX+SI], AL   
0x00E1    0000            ADD [BX+SI], AL   
0x00E3    0000            ADD [BX+SI], AL   
0x00E5    0000            ADD [BX+SI], AL   
0x00E7    0000            ADD [BX+SI], AL   
0x00E9    0000            ADD [BX+SI], AL   
0x00EB    0000            ADD [BX+SI], AL   
0x00ED    0000            ADD [BX+SI], AL   
0x00EF    0000            ADD [BX+SI], AL   
0x00F1    0000            ADD [BX+SI], AL   
0x00F3    0000            ADD [BX+SI], AL   
0x00F5    0000            ADD [BX+SI], AL   
0x00F7    0000            ADD [BX+SI], AL   
0x00F9    0000            ADD [BX+SI], AL   
0x00FB    0000            ADD [BX+SI], AL   
0x00FD    0000            ADD [BX+SI], AL   
0x00FF    0000            ADD [BX+SI], AL   
0x0101    0000            ADD [BX+SI], AL   
0x0103    0000            ADD [BX+SI], AL   
0x0105    0000            ADD [BX+SI], AL   
0x0107    0000            ADD [BX+SI], AL   
0x0109    0000            ADD [BX+SI], AL   
0x010B    0000            ADD [BX+SI], AL   
0x010D    0000            ADD [BX+SI], AL   
0x010F    0000            ADD [BX+SI], AL   
0x0111    0000            ADD [BX+SI], AL   
0x0113    0000            ADD [BX+SI], AL   
0x0115    0000            ADD [BX+SI], AL   
0x0117    0000            ADD [BX+SI], AL   
0x0119    0000            ADD [BX+SI], AL   
0x011B    0000            ADD [BX+SI], AL   
0x011D    0000            ADD [BX+SI], AL   
0x011F    0000            ADD [BX+SI], AL   
0x0121    0000            ADD [BX+SI], AL   
0x0123    0000            ADD [BX+SI], AL   
0x0125    0000            ADD [BX+SI], AL   
0x0127    0000            ADD [BX+SI], AL   
0x0129    0000            ADD [BX+SI], AL   
0x012B    0000            ADD [BX+SI], AL   
0x012D    0000            ADD [BX+SI], AL   
0x012F    0000            ADD [BX+SI], AL   
0x0131    0000            ADD [BX+SI], AL   
0x0133    0000            ADD [BX+SI], AL   
0x0135    0000            ADD [BX+SI], AL   
0x0137    0000            ADD [BX+SI], AL   
0x0139    0000            ADD [BX+SI], AL   
0x013B    0000            ADD [BX+SI], AL   
0x013D    0000            ADD [BX+SI], AL   
0x013F    0000            ADD [BX+SI], AL   
0x0141    0000            ADD [BX+SI], AL   
0x0143    0000            ADD [BX+SI], AL   
0x0145    0000            ADD [BX+SI], AL   
0x0147    0000            ADD [BX+SI], AL   
0x0149    0000            ADD [BX+SI], AL   
0x014B    0000            ADD [BX+SI], AL   
0x014D    0000            ADD [BX+SI], AL   
0x014F    0000            ADD [BX+SI], AL   
0x0151    0000            ADD [BX+SI], AL   
0x0153    0000            ADD [BX+SI], AL   
0x0155    0000            ADD [BX+SI], AL   
0x0157    0000            ADD [BX+SI], AL   
0x0159    0000            ADD [BX+SI], AL   
0x015B    0000            ADD [BX+SI], AL   
0x015D    0000            ADD [BX+SI], AL   
0x015F    0000            ADD [BX+SI], AL   
0x0161    0000            ADD [BX+SI], AL   
0x0163    0000            ADD [BX+SI], AL   
0x0165    0000            ADD [BX+SI], AL   
0x0167    0000            ADD [BX+SI], AL   
0x0169    0000            ADD [BX+SI], AL   
0x016B    0000            ADD [BX+SI], AL   
0x016D    0000            ADD [BX+SI], AL   
0x016F    0000            ADD [BX+SI], AL   
0x0171    0000            ADD [BX+SI], AL   
0x0173    0000            ADD [BX+SI], AL   
0x0175    0000            ADD [BX+SI], AL   
0x0177    0000            ADD [BX+SI], AL   
0x0179    0000            ADD [BX+SI], AL   
0x017B    0000            ADD [BX+SI], AL   
0x017D    0000            ADD [BX+SI], AL   
0x017F    0000            ADD [BX+SI], AL   
0x0181    0000            ADD [BX+SI], AL   
0x0183    0000            ADD [BX+SI], AL   
0x0185    0000            ADD [BX+SI], AL   
0x0187    0000            ADD [BX+SI], AL   
0x0189    0000            ADD [BX+SI], AL   
0x018B    0000            ADD [BX+SI], AL   
0x018D    0000            ADD [BX+SI], AL   
0x018F    0000            ADD [BX+SI], AL   
0x0191    0000            ADD [BX+SI], AL   
0x0193    0000            ADD [BX+SI], AL   
0x0195    0000            ADD [BX+SI], AL   
0x0197    0000            ADD [BX+SI], AL   
0x0199    0000            ADD [BX+SI], AL   
0x019B    0000            ADD [BX+SI], AL   
0x019D    0000            ADD [BX+SI], AL   
0x019F    0000            ADD [BX+SI], AL   
0x01A1    0000            ADD [BX+SI], AL   
0x01A3    0000            ADD [BX+SI], AL   
0x01A5    0000            ADD [BX+SI], AL   
0x01A7    0000            ADD [BX+SI], AL   
0x01A9    0000            ADD [BX+SI], AL   
0x01AB    0000            ADD [BX+SI], AL   
0x01AD    0000            ADD [BX+SI], AL   
0x01AF    0000            ADD [BX+SI], AL   
0x01B1    0000            ADD [BX+SI], AL   
0x01B3    0000            ADD [BX+SI], AL   
0x01B5    0000            ADD [BX+SI], AL   
0x01B7    0067 46         ADD [BX+0x46], AH   
0x01BA    0200            ADD AL, [BX+SI]   
0x01BC    0000            ADD [BX+SI], AL   
0x01BE    0001            ADD [BX+DI], AL   
0x01C0    0100            ADD [BX+SI], AX   
0x01C2    07              POP ES   
0x01C3    fe              DB 0xfe   
0x01C4    ff              DB 0xff   
0x01C5    ff              DB 0xff   
0x01C6    3f              AAS   
0x01C7    0000            ADD [BX+SI], AL   
0x01C9    0002            ADD [BP+SI], AL   
0x01CB    4c              DEC SP   
0x01CC    383a            CMP [BP+SI], BH   
0x01CE    0000            ADD [BX+SI], AL   
0x01D0    0000            ADD [BX+SI], AL   
0x01D2    0000            ADD [BX+SI], AL   
0x01D4    0000            ADD [BX+SI], AL   
0x01D6    0000            ADD [BX+SI], AL   
0x01D8    0000            ADD [BX+SI], AL   
0x01DA    0000            ADD [BX+SI], AL   
0x01DC    0000            ADD [BX+SI], AL   
0x01DE    0000            ADD [BX+SI], AL   
0x01E0    0000            ADD [BX+SI], AL   
0x01E2    0000            ADD [BX+SI], AL   
0x01E4    0000            ADD [BX+SI], AL   
0x01E6    0000            ADD [BX+SI], AL   
0x01E8    0000            ADD [BX+SI], AL   
0x01EA    0000            ADD [BX+SI], AL   
0x01EC    0000            ADD [BX+SI], AL   
0x01EE    0000            ADD [BX+SI], AL   
0x01F0    0000            ADD [BX+SI], AL   
0x01F2    0000            ADD [BX+SI], AL   
0x01F4    0000            ADD [BX+SI], AL   
0x01F6    0000            ADD [BX+SI], AL   
0x01F8    0000            ADD [BX+SI], AL   
0x01FA    0000            ADD [BX+SI], AL   
0x01FC    0000            ADD [BX+SI], AL   
0x01FE    55              PUSH BP   
0x01FF    aa              STOSB   


_______MBR   \Device\Harddisk6\DR14  

0x00000000   FA 33 C0 8E D0 BC 00 7C 8B F4 50 07 50 1F FB FC   ú3À.м.|.ôP.P.ûü
0x00000010   BF 00 06 B9 00 01 F2 A5 EA 1D 06 00 00 BE B8 06   ¿..¹..ò¥ê....¾¸.
0x00000020   AC 3C 00 74 0E 56 BB 07 00 B4 0E CD 10 5E EA 20   ¬<.t.V»..´.Í.^ê 
0x00000030   06 00 00 CD 18 00 00 00 00 00 00 00 00 00 00 00   ...Í............
0x00000040   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000050   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000060   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000070   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000080   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000090   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000000A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000000B0   00 00 00 00 00 00 00 00 50 65 6E 20 44 72 69 76   ........Pen Driv
0x000000C0   65 20 57 69 74 68 6F 75 74 20 4F 70 65 72 61 74   e Without Operat
0x000000D0   69 6E 67 20 53 79 73 74 65 6D 2E 52 65 6D 6F 76   ing System.Remov
0x000000E0   65 20 50 65 6E 20 44 72 69 76 65 20 41 6E 64 20   e Pen Drive And 
0x000000F0   52 65 62 6F 6F 74 2E 20 00 00 00 00 00 00 00 00   Reboot. ........
0x00000100   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000110   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000120   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000130   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000140   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000150   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000160   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000170   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 00 00 00 01 02 03 04 00 00 00 21   ...............!
0x000001C0   0A 00 0B 18 19 F4 28 08 00 00 D8 57 F0 00 00 00   .....ô(...ØWð...
0x000001D0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

__________________________16_BIT_ASM_CODE
   
0x0000    fa              CLI   
0x0001    33c0            XOR AX, AX   
0x0003    8ed0            MOV SS, AX   
0x0005    bc 007c         MOV SP, 0x7c00   
0x0008    8bf4            MOV SI, SP   
0x000A    50              PUSH AX   
0x000B    07              POP ES   
0x000C    50              PUSH AX   
0x000D    1f              POP DS   
0x000E    fb              STI   
0x000F    fc              CLD   
0x0010    bf 0006         MOV DI, 0x600   
0x0013    b9 0001         MOV CX, 0x100   
0x0016    f2 a5           REPNZ MOVSW   
0x0018    ea 1d06 0000    JMP FAR 0x0:0x61d   
0x001D    be b806         MOV SI, 0x6b8   
0x0020    ac              LODSB   
0x0021    3c 00           CMP AL, 0x0   
0x0023    74 0e           JZ 0x33   
0x0025    56              PUSH SI   
0x0026    bb 0700         MOV BX, 0x7   
0x0029    b4 0e           MOV AH, 0xe   
0x002B    cd 10           INT 0x10   
0x002D    5e              POP SI   
0x002E    ea 2006 0000    JMP FAR 0x0:0x620   
0x0033    cd 18           INT 0x18   
0x0035    0000            ADD [BX+SI], AL   
0x0037    0000            ADD [BX+SI], AL   
0x0039    0000            ADD [BX+SI], AL   
0x003B    0000            ADD [BX+SI], AL   
0x003D    0000            ADD [BX+SI], AL   
0x003F    0000            ADD [BX+SI], AL   
0x0041    0000            ADD [BX+SI], AL   
0x0043    0000            ADD [BX+SI], AL   
0x0045    0000            ADD [BX+SI], AL   
0x0047    0000            ADD [BX+SI], AL   
0x0049    0000            ADD [BX+SI], AL   
0x004B    0000            ADD [BX+SI], AL   
0x004D    0000            ADD [BX+SI], AL   
0x004F    0000            ADD [BX+SI], AL   
0x0051    0000            ADD [BX+SI], AL   
0x0053    0000            ADD [BX+SI], AL   
0x0055    0000            ADD [BX+SI], AL   
0x0057    0000            ADD [BX+SI], AL   
0x0059    0000            ADD [BX+SI], AL   
0x005B    0000            ADD [BX+SI], AL   
0x005D    0000            ADD [BX+SI], AL   
0x005F    0000            ADD [BX+SI], AL   
0x0061    0000            ADD [BX+SI], AL   
0x0063    0000            ADD [BX+SI], AL   
0x0065    0000            ADD [BX+SI], AL   
0x0067    0000            ADD [BX+SI], AL   
0x0069    0000            ADD [BX+SI], AL   
0x006B    0000            ADD [BX+SI], AL   
0x006D    0000            ADD [BX+SI], AL   
0x006F    0000            ADD [BX+SI], AL   
0x0071    0000            ADD [BX+SI], AL   
0x0073    0000            ADD [BX+SI], AL   
0x0075    0000            ADD [BX+SI], AL   
0x0077    0000            ADD [BX+SI], AL   
0x0079    0000            ADD [BX+SI], AL   
0x007B    0000            ADD [BX+SI], AL   
0x007D    0000            ADD [BX+SI], AL   
0x007F    0000            ADD [BX+SI], AL   
0x0081    0000            ADD [BX+SI], AL   
0x0083    0000            ADD [BX+SI], AL   
0x0085    0000            ADD [BX+SI], AL   
0x0087    0000            ADD [BX+SI], AL   
0x0089    0000            ADD [BX+SI], AL   
0x008B    0000            ADD [BX+SI], AL   
0x008D    0000            ADD [BX+SI], AL   
0x008F    0000            ADD [BX+SI], AL   
0x0091    0000            ADD [BX+SI], AL   
0x0093    0000            ADD [BX+SI], AL   
0x0095    0000            ADD [BX+SI], AL   
0x0097    0000            ADD [BX+SI], AL   
0x0099    0000            ADD [BX+SI], AL   
0x009B    0000            ADD [BX+SI], AL   
0x009D    0000            ADD [BX+SI], AL   
0x009F    0000            ADD [BX+SI], AL   
0x00A1    0000            ADD [BX+SI], AL   
0x00A3    0000            ADD [BX+SI], AL   
0x00A5    0000            ADD [BX+SI], AL   
0x00A7    0000            ADD [BX+SI], AL   
0x00A9    0000            ADD [BX+SI], AL   
0x00AB    0000            ADD [BX+SI], AL   
0x00AD    0000            ADD [BX+SI], AL   
0x00AF    0000            ADD [BX+SI], AL   
0x00B1    0000            ADD [BX+SI], AL   
0x00B3    0000            ADD [BX+SI], AL   
0x00B5    0000            ADD [BX+SI], AL   
0x00B7    0050 65         ADD [BX+SI+0x65], DL   
0x00BA    6e              OUTSB   
0x00BB    2044 72         AND [SI+0x72], AL   
0x00BE    6976 65 2057    IMUL SI, [BP+0x65], 0x5720   
0x00C3    6974 68 6f75    IMUL SI, [SI+0x68], 0x756f   
0x00C8    74 20           JZ 0xea   
0x00CA    4f              DEC DI   
0x00CB    70 65           JO 0x132   
0x00CD    72 61           JB 0x130   
0x00CF    74 69           JZ 0x13a   
0x00D1    6e              OUTSB   
0x00D2    67 2053 79      AND [EBX+0x79], DL   
0x00D6    73 74           JAE 0x14c   
0x00D8    65 6d           INS WORD GS:[DI], DX   
0x00DA    2e              DB 0x2e   
0x00DA    2e 52           PUSH DX   
0x00DC    65 6d           INS WORD GS:[DI], DX   
0x00DE    6f              OUTSW   
0x00DF    76 65           JBE 0x146   
0x00E1    2050 65         AND [BX+SI+0x65], DL   
0x00E4    6e              OUTSB   
0x00E5    2044 72         AND [SI+0x72], AL   
0x00E8    6976 65 2041    IMUL SI, [BP+0x65], 0x4120   
0x00ED    6e              OUTSB   
0x00EE    64 2052 65      AND FS:[BP+SI+0x65], DL   
0x00F2    626f 6f         BOUND BP, [BX+0x6f]   
0x00F5    74 2e           JZ 0x125   
0x00F7    2000            AND [BX+SI], AL   
0x00F9    0000            ADD [BX+SI], AL   
0x00FB    0000            ADD [BX+SI], AL   
0x00FD    0000            ADD [BX+SI], AL   
0x00FF    0000            ADD [BX+SI], AL   
0x0101    0000            ADD [BX+SI], AL   
0x0103    0000            ADD [BX+SI], AL   
0x0105    0000            ADD [BX+SI], AL   
0x0107    0000            ADD [BX+SI], AL   
0x0109    0000            ADD [BX+SI], AL   
0x010B    0000            ADD [BX+SI], AL   
0x010D    0000            ADD [BX+SI], AL   
0x010F    0000            ADD [BX+SI], AL   
0x0111    0000            ADD [BX+SI], AL   
0x0113    0000            ADD [BX+SI], AL   
0x0115    0000            ADD [BX+SI], AL   
0x0117    0000            ADD [BX+SI], AL   
0x0119    0000            ADD [BX+SI], AL   
0x011B    0000            ADD [BX+SI], AL   
0x011D    0000            ADD [BX+SI], AL   
0x011F    0000            ADD [BX+SI], AL   
0x0121    0000            ADD [BX+SI], AL   
0x0123    0000            ADD [BX+SI], AL   
0x0125    0000            ADD [BX+SI], AL   
0x0127    0000            ADD [BX+SI], AL   
0x0129    0000            ADD [BX+SI], AL   
0x012B    0000            ADD [BX+SI], AL   
0x012D    0000            ADD [BX+SI], AL   
0x012F    0000            ADD [BX+SI], AL   
0x0131    0000            ADD [BX+SI], AL   
0x0133    0000            ADD [BX+SI], AL   
0x0135    0000            ADD [BX+SI], AL   
0x0137    0000            ADD [BX+SI], AL   
0x0139    0000            ADD [BX+SI], AL   
0x013B    0000            ADD [BX+SI], AL   
0x013D    0000            ADD [BX+SI], AL   
0x013F    0000            ADD [BX+SI], AL   
0x0141    0000            ADD [BX+SI], AL   
0x0143    0000            ADD [BX+SI], AL   
0x0145    0000            ADD [BX+SI], AL   
0x0147    0000            ADD [BX+SI], AL   
0x0149    0000            ADD [BX+SI], AL   
0x014B    0000            ADD [BX+SI], AL   
0x014D    0000            ADD [BX+SI], AL   
0x014F    0000            ADD [BX+SI], AL   
0x0151    0000            ADD [BX+SI], AL   
0x0153    0000            ADD [BX+SI], AL   
0x0155    0000            ADD [BX+SI], AL   
0x0157    0000            ADD [BX+SI], AL   
0x0159    0000            ADD [BX+SI], AL   
0x015B    0000            ADD [BX+SI], AL   
0x015D    0000            ADD [BX+SI], AL   
0x015F    0000            ADD [BX+SI], AL   
0x0161    0000            ADD [BX+SI], AL   
0x0163    0000            ADD [BX+SI], AL   
0x0165    0000            ADD [BX+SI], AL   
0x0167    0000            ADD [BX+SI], AL   
0x0169    0000            ADD [BX+SI], AL   
0x016B    0000            ADD [BX+SI], AL   
0x016D    0000            ADD [BX+SI], AL   
0x016F    0000            ADD [BX+SI], AL   
0x0171    0000            ADD [BX+SI], AL   
0x0173    0000            ADD [BX+SI], AL   
0x0175    0000            ADD [BX+SI], AL   
0x0177    0000            ADD [BX+SI], AL   
0x0179    0000            ADD [BX+SI], AL   
0x017B    0000            ADD [BX+SI], AL   
0x017D    0000            ADD [BX+SI], AL   
0x017F    0000            ADD [BX+SI], AL   
0x0181    0000            ADD [BX+SI], AL   
0x0183    0000            ADD [BX+SI], AL   
0x0185    0000            ADD [BX+SI], AL   
0x0187    0000            ADD [BX+SI], AL   
0x0189    0000            ADD [BX+SI], AL   
0x018B    0000            ADD [BX+SI], AL   
0x018D    0000            ADD [BX+SI], AL   
0x018F    0000            ADD [BX+SI], AL   
0x0191    0000            ADD [BX+SI], AL   
0x0193    0000            ADD [BX+SI], AL   
0x0195    0000            ADD [BX+SI], AL   
0x0197    0000            ADD [BX+SI], AL   
0x0199    0000            ADD [BX+SI], AL   
0x019B    0000            ADD [BX+SI], AL   
0x019D    0000            ADD [BX+SI], AL   
0x019F    0000            ADD [BX+SI], AL   
0x01A1    0000            ADD [BX+SI], AL   
0x01A3    0000            ADD [BX+SI], AL   
0x01A5    0000            ADD [BX+SI], AL   
0x01A7    0000            ADD [BX+SI], AL   
0x01A9    0000            ADD [BX+SI], AL   
0x01AB    0000            ADD [BX+SI], AL   
0x01AD    0000            ADD [BX+SI], AL   
0x01AF    0000            ADD [BX+SI], AL   
0x01B1    0000            ADD [BX+SI], AL   
0x01B3    0000            ADD [BX+SI], AL   
0x01B5    0000            ADD [BX+SI], AL   
0x01B7    0001            ADD [BX+DI], AL   
0x01B9    0203            ADD AL, [BP+DI]   
0x01BB    04 00           ADD AL, 0x0   
0x01BD    0000            ADD [BX+SI], AL   
0x01BF    210a            AND [BP+SI], CX   
0x01C1    000b            ADD [BP+DI], CL   
0x01C3    1819            SBB [BX+DI], BL   
0x01C5    f4              HLT   
0x01C6    2808            SUB [BX+SI], CL   
0x01C8    0000            ADD [BX+SI], AL   
0x01CA    d857 f0         FCOM DWORD [BX-0x10]   
0x01CD    0000            ADD [BX+SI], AL   
0x01CF    0000            ADD [BX+SI], AL   
0x01D1    0000            ADD [BX+SI], AL   
0x01D3    0000            ADD [BX+SI], AL   
0x01D5    0000            ADD [BX+SI], AL   
0x01D7    0000            ADD [BX+SI], AL   
0x01D9    0000            ADD [BX+SI], AL   
0x01DB    0000            ADD [BX+SI], AL   
0x01DD    0000            ADD [BX+SI], AL   
0x01DF    0000            ADD [BX+SI], AL   
0x01E1    0000            ADD [BX+SI], AL   
0x01E3    0000            ADD [BX+SI], AL   
0x01E5    0000            ADD [BX+SI], AL   
0x01E7    0000            ADD [BX+SI], AL   
0x01E9    0000            ADD [BX+SI], AL   
0x01EB    0000            ADD [BX+SI], AL   
0x01ED    0000            ADD [BX+SI], AL   
0x01EF    0000            ADD [BX+SI], AL   
0x01F1    0000            ADD [BX+SI], AL   
0x01F3    0000            ADD [BX+SI], AL   
0x01F5    0000            ADD [BX+SI], AL   
0x01F7    0000            ADD [BX+SI], AL   
0x01F9    0000            ADD [BX+SI], AL   
0x01FB    0000            ADD [BX+SI], AL   
0x01FD    0055 aa         ADD [DI-0x56], DL   


Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#3 Příspěvek od Teochi »

Posílám log:

17:52:27.0419 5440 TDSS rootkit removing tool 2.8.6.0 Aug 13 2012 17:24:05਍ഀ
17:52:27.0529 5440 ============================================================਍ഀ
17:52:27.0529 5440 Current date / time: 2012/08/14 17:52:27.0529਍ഀ
17:52:27.0529 5440 SystemInfo:਍ഀ
17:52:27.0529 5440 ਍ഀ
17:52:27.0529 5440 OS Version: 5.1.2600 ServicePack: 3.0਍ഀ
17:52:27.0529 5440 Product type: Workstation਍ഀ
17:52:27.0529 5440 ComputerName: PW-EHOUSE਍ഀ
17:52:27.0529 5440 UserName: Veronika਍ഀ
17:52:27.0529 5440 Windows directory: C:\WINDOWS਍ഀ
17:52:27.0529 5440 System windows directory: C:\WINDOWS਍ഀ
17:52:27.0529 5440 Processor architecture: Intel x86਍ഀ
17:52:27.0529 5440 Number of processors: 2਍ഀ
17:52:27.0529 5440 Page size: 0x1000਍ഀ
17:52:27.0529 5440 Boot type: Normal boot਍ഀ
17:52:27.0529 5440 ============================================================਍ഀ
17:52:28.0341 5440 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054਍ഀ
17:52:28.0732 5440 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054਍ഀ
17:52:28.0857 5440 Drive \Device\Harddisk6\DR14 - Size: 0x1E0C00000 (7.51 Gb), SectorSize: 0x200, Cylinders: 0x3D4, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'਍ഀ
17:52:28.0857 5440 Drive \Device\Harddisk7\DR18 - Size: 0xF7D40000 (3.87 Gb), SectorSize: 0x200, Cylinders: 0x1F9, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'਍ഀ
17:52:28.0857 5440 ============================================================਍ഀ
17:52:28.0857 5440 \Device\Harddisk0\DR0:਍ഀ
17:52:28.0857 5440 MBR partitions:਍ഀ
17:52:28.0857 5440 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1AA121E3਍ഀ
17:52:28.0873 5440 \Device\Harddisk1\DR1:਍ഀ
17:52:28.0888 5440 MBR partitions:਍ഀ
17:52:28.0888 5440 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02਍ഀ
17:52:28.0888 5440 \Device\Harddisk6\DR14:਍ഀ
17:52:28.0888 5440 MBR partitions:਍ഀ
17:52:28.0888 5440 \Device\Harddisk6\DR14\Partition1: MBR, Type 0xB, StartLBA 0x828, BlocksNum 0xF057D8਍ഀ
17:52:28.0888 5440 \Device\Harddisk7\DR18:਍ഀ
17:52:28.0888 5440 MBR partitions:਍ഀ
17:52:28.0888 5440 ============================================================਍ഀ
17:52:28.0919 5440 C: <-> \Device\Harddisk0\DR0\Partition1਍ഀ
17:52:28.0935 5440 D: <-> \Device\Harddisk1\DR1\Partition1਍ഀ
17:52:28.0935 5440 ============================================================਍ഀ
17:52:28.0935 5440 Initialize success਍ഀ
17:52:28.0935 5440 ============================================================਍ഀ
17:52:48.0654 1124 ============================================================਍ഀ
17:52:48.0654 1124 Scan started਍ഀ
17:52:48.0654 1124 Mode: Manual; SigCheck; TDLFS; ਍ഀ
17:52:48.0654 1124 ============================================================਍ഀ
17:52:49.0263 1124 ================ Scan services =============================਍ഀ
17:52:49.0341 1124 Abiosdsk - ok਍ഀ
17:52:49.0357 1124 abp480n5 - ok਍ഀ
17:52:49.0373 1124 [ 4fe34f1f3126b61fcc6b2043aa8112c9 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys਍ഀ
17:52:51.0060 1124 ACPI - ok਍ഀ
17:52:51.0091 1124 [ afdff022a01f0b11c776f0860c3b282f ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys਍ഀ
17:52:51.0263 1124 ACPIEC - ok਍ഀ
17:52:51.0404 1124 [ 14c23516c990dcd6052152cf034dde40 ] Adobe Version Cue CS3 C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe਍ഀ
17:52:51.0435 1124 Adobe Version Cue CS3 - ok਍ഀ
17:52:51.0435 1124 adpu160m - ok਍ഀ
17:52:51.0451 1124 [ 8bed39e3c35d6a489438b8141717a557 ] aec C:\WINDOWS\system32\drivers\aec.sys਍ഀ
17:52:51.0591 1124 aec - ok਍ഀ
17:52:51.0623 1124 [ 2f7f3e8da380325866e566f5d5ec23d5 ] AegisP C:\WINDOWS\system32\DRIVERS\AegisP.sys਍ഀ
17:52:51.0638 1124 AegisP ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:51.0638 1124 AegisP - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:51.0669 1124 [ 1e44bc1e83d8fd2305f8d452db109cf9 ] AFD C:\WINDOWS\System32\drivers\afd.sys਍ഀ
17:52:51.0763 1124 AFD - ok਍ഀ
17:52:51.0763 1124 Aha154x - ok਍ഀ
17:52:51.0779 1124 aic78u2 - ok਍ഀ
17:52:51.0779 1124 aic78xx - ok਍ഀ
17:52:51.0810 1124 [ e0a6fa244b8624d78fe5ff6f56a33bae ] Alerter C:\WINDOWS\system32\alrsvc.dll਍ഀ
17:52:51.0919 1124 Alerter - ok਍ഀ
17:52:51.0951 1124 [ 88842de939a827577bf24243699ac80a ] ALG C:\WINDOWS\System32\alg.exe਍ഀ
17:52:52.0076 1124 ALG - ok਍ഀ
17:52:52.0076 1124 AliIde - ok਍ഀ
17:52:52.0107 1124 [ ad8fa28d8ed0d0a689a0559085ce0f18 ] AmdLLD C:\WINDOWS\system32\DRIVERS\AmdLLD.sys਍ഀ
17:52:52.0138 1124 AmdLLD - ok਍ഀ
17:52:52.0154 1124 amsint - ok਍ഀ
17:52:52.0216 1124 [ 8507be2d6a8f9dabfdd8920553596a31 ] Apache2.2 c:\xampp\apache\bin\apache.exe਍ഀ
17:52:52.0232 1124 Apache2.2 ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:52.0232 1124 Apache2.2 - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:52.0310 1124 [ 69da2bb73ac426cdeebdacc68438ba3d ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe਍ഀ
17:52:52.0326 1124 Apple Mobile Device ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:52.0326 1124 Apple Mobile Device - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:52.0357 1124 [ 6b8e7a90e576d4fe308f97c69060a171 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll਍ഀ
17:52:52.0466 1124 AppMgmt - ok਍ഀ
17:52:52.0498 1124 [ b5b8a80875c1dededa8b02765642c32f ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys਍ഀ
17:52:52.0623 1124 Arp1394 - ok਍ഀ
17:52:52.0623 1124 asc - ok਍ഀ
17:52:52.0638 1124 asc3350p - ok਍ഀ
17:52:52.0638 1124 asc3550 - ok਍ഀ
17:52:52.0732 1124 [ 776acefa0ca9df0faa51a5fb2f435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe਍ഀ
17:52:52.0748 1124 aspnet_state - ok਍ഀ
17:52:52.0779 1124 [ b153affac761e7f5fcfa822b9c4e97bc ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys਍ഀ
17:52:52.0888 1124 AsyncMac - ok਍ഀ
17:52:52.0919 1124 [ 9f3a2f5aa6875c72bf062c712cfa2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys਍ഀ
17:52:53.0044 1124 atapi - ok਍ഀ
17:52:53.0044 1124 Atdisk - ok਍ഀ
17:52:53.0091 1124 [ 666e4e583a7cf1233c6425da16ecdc89 ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe਍ഀ
17:52:53.0154 1124 Ati HotKey Poller - ok਍ഀ
17:52:53.0201 1124 [ 3ae69ea1af3d65c362869d6dec0cfa52 ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe਍ഀ
17:52:53.0216 1124 ATI Smart ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:53.0216 1124 ATI Smart - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:53.0279 1124 [ 0c2ca1c294938139829b1983a0c38b31 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys਍ഀ
17:52:53.0357 1124 ati2mtag - ok਍ഀ
17:52:53.0404 1124 [ f0d933b42cd0594048e4d5200ae9e417 ] atksgt C:\WINDOWS\system32\DRIVERS\atksgt.sys਍ഀ
17:52:53.0544 1124 atksgt - ok਍ഀ
17:52:53.0560 1124 [ 9916c1225104ba14794209cfa8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys਍ഀ
17:52:53.0701 1124 Atmarpc - ok਍ഀ
17:52:53.0732 1124 [ de31b88962a8645dba5a37b993e7b0f1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll਍ഀ
17:52:53.0841 1124 AudioSrv - ok਍ഀ
17:52:53.0873 1124 [ d9f724aa26c010a217c97606b160ed68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys਍ഀ
17:52:53.0998 1124 audstub - ok਍ഀ
17:52:54.0029 1124 [ 438179abe9b7a922a21b8d6369ff52ff ] BCM42RLY C:\WINDOWS\System32\BCM42RLY.SYS਍ഀ
17:52:54.0060 1124 BCM42RLY ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:54.0060 1124 BCM42RLY - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:54.0091 1124 [ da1f27d85e0d1525f6621372e7b685e9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys਍ഀ
17:52:54.0201 1124 Beep - ok਍ഀ
17:52:54.0232 1124 [ 19395d092fd85ddc2d9c7729cf5a2ac8 ] BITS C:\WINDOWS\system32\qmgr.dll਍ഀ
17:52:54.0357 1124 BITS - ok਍ഀ
17:52:54.0388 1124 [ 73686fe0b2e0469f89fd2075be724704 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe਍ഀ
17:52:54.0419 1124 Bonjour Service ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:54.0419 1124 Bonjour Service - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:54.0451 1124 [ 249276d3ef1e74b992299cb96099e4d7 ] Browser C:\WINDOWS\System32\browser.dll਍ഀ
17:52:54.0576 1124 Browser - ok਍ഀ
17:52:54.0607 1124 [ 90a673fc8e12a79afbed2576f6a7aaf9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys਍ഀ
17:52:54.0716 1124 cbidf2k - ok਍ഀ
17:52:54.0716 1124 cd20xrnt - ok਍ഀ
17:52:54.0763 1124 [ c1b486a7658353d33a10cc15211a873b ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys਍ഀ
17:52:54.0888 1124 Cdaudio - ok਍ഀ
17:52:54.0919 1124 [ c885b02847f5d2fd45a24e219ed93b32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys਍ഀ
17:52:55.0029 1124 Cdfs - ok਍ഀ
17:52:55.0044 1124 [ 1f4260cc5b42272d71f79e570a27a4fe ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys਍ഀ
17:52:55.0169 1124 Cdrom - ok਍ഀ
17:52:55.0169 1124 Changer - ok਍ഀ
17:52:55.0201 1124 [ e390dc1d7c461d7d56ec53402f329928 ] CiSvc C:\WINDOWS\system32\cisvc.exe਍ഀ
17:52:55.0310 1124 CiSvc - ok਍ഀ
17:52:55.0341 1124 [ 064507a8dfa8c5c7e2ffddd3e6f424fa ] ClipSrv C:\WINDOWS\system32\clipsrv.exe਍ഀ
17:52:55.0451 1124 ClipSrv - ok਍ഀ
17:52:55.0513 1124 [ d87acaed61e417bba546ced5e7e36d9c ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe਍ഀ
17:52:55.0607 1124 clr_optimization_v2.0.50727_32 - ok਍ഀ
17:52:55.0638 1124 [ c5a75eb48e2344abdc162bda79e16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe਍ഀ
17:52:55.0654 1124 clr_optimization_v4.0.30319_32 - ok਍ഀ
17:52:55.0654 1124 CmdIde - ok਍ഀ
17:52:55.0732 1124 [ 25cae5c2fec8c1b3d376ae9fd45278cd ] cmudau C:\WINDOWS\system32\drivers\cmudaxu.sys਍ഀ
17:52:55.0810 1124 cmudau - ok਍ഀ
17:52:55.0826 1124 COMSysApp - ok਍ഀ
17:52:55.0841 1124 Cpqarray - ok਍ഀ
17:52:55.0966 1124 cpuz130 - ok਍ഀ
17:52:55.0998 1124 [ f3ab0933cbd166d271992f411c27ccaf ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll਍ഀ
17:52:56.0107 1124 CryptSvc - ok਍ഀ
17:52:56.0123 1124 dac2w2k - ok਍ഀ
17:52:56.0123 1124 dac960nt - ok਍ഀ
17:52:56.0169 1124 [ be27674d1cbc3214aec84b4336a38bbf ] DcomLaunch C:\WINDOWS\system32\rpcss.dll਍ഀ
17:52:56.0248 1124 DcomLaunch - ok਍ഀ
17:52:56.0279 1124 [ 8c9a53e285ac5e6704844d0459ec85be ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll਍ഀ
17:52:56.0388 1124 Dhcp - ok਍ഀ
17:52:56.0435 1124 [ 044452051f3e02e7963599fc8f4f3e25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys਍ഀ
17:52:56.0544 1124 Disk - ok਍ഀ
17:52:56.0591 1124 [ 3530e2c0b6a0cb3609244f8cfa59e4a4 ] Diskeeper C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe਍ഀ
17:52:56.0638 1124 Diskeeper ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:56.0638 1124 Diskeeper - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:56.0638 1124 dj6e8bn0.sys - ok਍ഀ
17:52:56.0654 1124 dmadmin - ok਍ഀ
17:52:56.0685 1124 [ db5fd2bf5b07dc54bfcb3664ff05bd7c ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys਍ഀ
17:52:56.0841 1124 dmboot - ok਍ഀ
17:52:56.0857 1124 [ fff1720af51171f32f1ead5cf71f2810 ] dmio C:\WINDOWS\system32\drivers\dmio.sys਍ഀ
17:52:56.0966 1124 dmio - ok਍ഀ
17:52:57.0013 1124 [ e9317282a63ca4d188c0df5e09c6ac5f ] dmload C:\WINDOWS\system32\drivers\dmload.sys਍ഀ
17:52:57.0138 1124 dmload - ok਍ഀ
17:52:57.0169 1124 [ 2bfefe9e865655a76982f050450b9591 ] dmserver C:\WINDOWS\System32\dmserver.dll਍ഀ
17:52:57.0279 1124 dmserver - ok਍ഀ
17:52:57.0294 1124 [ 8a208dfcf89792a484e76c40e5f50b45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys਍ഀ
17:52:57.0404 1124 DMusic - ok਍ഀ
17:52:57.0435 1124 [ dfaa406bf19f4ee806a6f8d4342137f7 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll਍ഀ
17:52:57.0513 1124 Dnscache - ok਍ഀ
17:52:57.0544 1124 [ 4a3e2bd20157a0946751229e92eb8621 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll਍ഀ
17:52:57.0654 1124 Dot3svc - ok਍ഀ
17:52:57.0669 1124 dpti2o - ok਍ഀ
17:52:57.0685 1124 [ 8f5fcff8e8848afac920905fbd9d33c8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys਍ഀ
17:52:57.0810 1124 drmkaud - ok਍ഀ
17:52:57.0841 1124 [ 96932765078f5b4e282f7a7931ffc37f ] e1express C:\WINDOWS\system32\DRIVERS\e1e5132.sys਍ഀ
17:52:57.0904 1124 e1express ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:57.0904 1124 e1express - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:57.0904 1124 EagleNT - ok਍ഀ
17:52:57.0951 1124 [ 30372bcc67d63bee538cdfeca755d81c ] eamon C:\WINDOWS\system32\DRIVERS\eamon.sys਍ഀ
17:52:57.0966 1124 eamon - ok਍ഀ
17:52:57.0982 1124 [ 0887d9c2be8d940778cad1e3b85f2a41 ] EapHost C:\WINDOWS\System32\eapsvc.dll਍ഀ
17:52:58.0107 1124 EapHost - ok਍ഀ
17:52:58.0138 1124 [ 6504d6afb75fef830dd99e8c4235d54d ] ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys਍ഀ
17:52:58.0169 1124 ehdrv - ok਍ഀ
17:52:58.0232 1124 [ 7e5c9009d28fe0f2cde2b8df47472a06 ] EhttpSrv C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe਍ഀ
17:52:58.0248 1124 EhttpSrv - ok਍ഀ
17:52:58.0294 1124 [ fddad27e9a20d0dac04facbf67afbfc1 ] ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe਍ഀ
17:52:58.0326 1124 ekrn - ok਍ഀ
17:52:58.0357 1124 [ 16ebd8bf1d5090923694cc972c7ce1b4 ] ENTECH C:\WINDOWS\system32\DRIVERS\ENTECH.sys਍ഀ
17:52:58.0388 1124 ENTECH - ok਍ഀ
17:52:58.0435 1124 [ ad414acda67d3020f7a04fb9c8621f01 ] epfwtdir C:\WINDOWS\system32\DRIVERS\epfwtdir.sys਍ഀ
17:52:58.0451 1124 epfwtdir - ok਍ഀ
17:52:58.0482 1124 [ a2a4912798f2be706abadd3d30800d16 ] ERSvc C:\WINDOWS\System32\ersvc.dll਍ഀ
17:52:58.0591 1124 ERSvc - ok਍ഀ
17:52:58.0701 1124 [ 9ef697af07bb8dd82c3b02ca953a95b7 ] Eventlog C:\WINDOWS\system32\services.exe਍ഀ
17:52:58.0748 1124 Eventlog - ok਍ഀ
17:52:58.0794 1124 [ a371f11ef07653591c8de26afb13ce7f ] EventSystem C:\WINDOWS\system32\es.dll਍ഀ
17:52:58.0810 1124 EventSystem - ok਍ഀ
17:52:58.0857 1124 [ 38d332a6d56af32635675f132548343e ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys਍ഀ
17:52:58.0998 1124 Fastfat - ok਍ഀ
17:52:59.0029 1124 [ ee9a2b9ea968a792a053c9d1a86bf870 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll਍ഀ
17:52:59.0060 1124 FastUserSwitchingCompatibility - ok਍ഀ
17:52:59.0076 1124 [ 92cdd60b6730b9f50f6a1a0c1f8cdc81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys਍ഀ
17:52:59.0232 1124 Fdc - ok਍ഀ
17:52:59.0248 1124 [ ac366695a0796560aa37215ad5762aaf ] Fips C:\WINDOWS\system32\drivers\Fips.sys਍ഀ
17:52:59.0373 1124 Fips - ok਍ഀ
17:52:59.0419 1124 [ 227846995afeefa70d328bf5334a86a5 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe਍ഀ
17:52:59.0435 1124 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:52:59.0435 1124 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:52:59.0482 1124 [ 9d27e7b80bfcdf1cdd9b555862d5e7f0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys਍ഀ
17:52:59.0591 1124 Flpydisk - ok਍ഀ
17:52:59.0623 1124 [ b2cf4b0786f8212cb92ed2b50c6db6b0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys਍ഀ
17:52:59.0748 1124 FltMgr - ok਍ഀ
17:53:00.0029 1124 [ 8ba7c024070f2b7fdd98ed8a4ba41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe਍ഀ
17:53:00.0044 1124 FontCache3.0.0.0 - ok਍ഀ
17:53:00.0091 1124 [ 9996a605d10e8c7daa29a380eaef51ae ] FsVga C:\WINDOWS\system32\DRIVERS\fsvga.sys਍ഀ
17:53:00.0232 1124 FsVga - ok਍ഀ
17:53:00.0248 1124 [ 3e1e2bd4f39b0e2b7dc4f4d2bcc2779a ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys਍ഀ
17:53:00.0373 1124 Fs_Rec - ok਍ഀ
17:53:00.0388 1124 [ 4e664d8541db4a66b73a24257e322e1f ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys਍ഀ
17:53:00.0498 1124 Ftdisk - ok਍ഀ
17:53:00.0529 1124 [ 545c10b51e76affd03821aa3a14fd56e ] genmcmn C:\WINDOWS\system32\DRIVERS\gmfiltr.sys਍ഀ
17:53:00.0607 1124 genmcmn - ok਍ഀ
17:53:00.0623 1124 [ 86f732d2995ada73fd307539ec266d3a ] genmcmnUSB C:\WINDOWS\system32\DRIVERS\gflmouhid.sys਍ഀ
17:53:00.0623 1124 genmcmnUSB - ok਍ഀ
17:53:00.0654 1124 [ 007aea2e06e7cef7372e40c277163959 ] ggflt C:\WINDOWS\system32\DRIVERS\ggflt.sys਍ഀ
17:53:00.0669 1124 ggflt - ok਍ഀ
17:53:00.0685 1124 [ c73de35960ca75c5ab4ae636b127c64e ] ggsemc C:\WINDOWS\system32\DRIVERS\ggsemc.sys਍ഀ
17:53:00.0701 1124 ggsemc - ok਍ഀ
17:53:00.0732 1124 [ 0a02c63c8b144bd8c86b103dee7c86a2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys਍ഀ
17:53:00.0873 1124 Gpc - ok਍ഀ
17:53:00.0935 1124 [ 751c1d2ca2abf4a9f5a6b8d7d45b907c ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe਍ഀ
17:53:00.0951 1124 gusvc - ok਍ഀ
17:53:00.0982 1124 [ 7929a161f9951d173ca9900fe7067391 ] hamachi C:\WINDOWS\system32\DRIVERS\hamachi.sys਍ഀ
17:53:00.0998 1124 hamachi - ok਍ഀ
17:53:01.0029 1124 [ 573c7d0a32852b48f3058cfd8026f511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys਍ഀ
17:53:01.0154 1124 HDAudBus - ok਍ഀ
17:53:01.0169 1124 [ 91109e1f35ce6e4b115490255018c8fc ] HECI C:\WINDOWS\system32\DRIVERS\HECI.sys਍ഀ
17:53:01.0169 1124 HECI ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:01.0169 1124 HECI - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:01.0232 1124 [ fcfe31fb75f8a6295b6b0af87a626282 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll਍ഀ
17:53:01.0341 1124 helpsvc - ok਍ഀ
17:53:01.0373 1124 [ 00e25ee90166b3e1be6e74aebf858306 ] HidServ C:\WINDOWS\System32\hidserv.dll਍ഀ
17:53:01.0482 1124 HidServ - ok਍ഀ
17:53:01.0513 1124 [ ccf82c5ec8a7326c3066de870c06daf1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys਍ഀ
17:53:01.0623 1124 hidusb - ok਍ഀ
17:53:01.0654 1124 [ 7a6b320928f86bc851530d63c82965d9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll਍ഀ
17:53:01.0763 1124 hkmsvc - ok਍ഀ
17:53:01.0779 1124 hpn - ok਍ഀ
17:53:01.0810 1124 [ f80a415ef82cd06ffaf0d971528ead38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys਍ഀ
17:53:01.0841 1124 HTTP - ok਍ഀ
17:53:01.0857 1124 [ 58fe2f2da3bc5573f4a35b3760d3125f ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll਍ഀ
17:53:01.0966 1124 HTTPFilter - ok਍ഀ
17:53:01.0998 1124 [ 008ada74e3028fced5145f4f74230d4b ] hwdatacard C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys਍ഀ
17:53:02.0029 1124 hwdatacard - ok਍ഀ
17:53:02.0044 1124 i2omgmt - ok਍ഀ
17:53:02.0044 1124 i2omp - ok਍ഀ
17:53:02.0076 1124 [ c528e27945367191e7bae364930b6932 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys਍ഀ
17:53:02.0201 1124 i8042prt - ok਍ഀ
17:53:02.0248 1124 [ a4e43a7ab1202356bebeb6b798f15488 ] ICQ Service C:\Program Files\ICQ6Toolbar\ICQ Service.exe਍ഀ
17:53:02.0263 1124 ICQ Service - ok਍ഀ
17:53:02.0263 1124 IDMTDI - ok਍ഀ
17:53:02.0326 1124 [ 1cf03c69b49acb70c722df92755c0c8c ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe਍ഀ
17:53:02.0341 1124 IDriverT ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:02.0341 1124 IDriverT - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:02.0419 1124 [ c01ac32dc5c03076cfb852cb5da5229c ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe਍ഀ
17:53:02.0498 1124 idsvc - ok਍ഀ
17:53:02.0513 1124 [ 083a052659f5310dd8b6a6cb05edcf8e ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys਍ഀ
17:53:02.0654 1124 Imapi - ok਍ഀ
17:53:02.0685 1124 [ f7b93aafad33b2320954c17e26c8d361 ] ImapiService C:\WINDOWS\system32\imapi.exe਍ഀ
17:53:02.0810 1124 ImapiService - ok਍ഀ
17:53:03.0044 1124 [ b87fc7c71632240dac8f4d20e9ce8377 ] InCDfs C:\WINDOWS\system32\drivers\InCDfs.sys਍ഀ
17:53:03.0060 1124 InCDfs ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:03.0060 1124 InCDfs - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:03.0076 1124 [ 2e878405128ec98886eb9c2216ac7bd6 ] InCDPass C:\WINDOWS\system32\DRIVERS\InCDPass.sys਍ഀ
17:53:03.0091 1124 InCDPass ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:03.0091 1124 InCDPass - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:03.0107 1124 [ ddf078917a42f105385d7eb6debb3433 ] InCDrec C:\WINDOWS\system32\drivers\InCDrec.sys਍ഀ
17:53:03.0107 1124 InCDrec ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:03.0107 1124 InCDrec - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:03.0123 1124 [ 7f352360e947ad2cd4ba60de27b1a299 ] incdrm C:\WINDOWS\system32\drivers\incdrm.sys਍ഀ
17:53:03.0123 1124 incdrm ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:03.0123 1124 incdrm - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:03.0169 1124 [ e9372a17c22fc4e5c9fd8798a97775fc ] InCDsrv C:\Program Files\Ahead\InCD\InCDsrv.exe਍ഀ
17:53:03.0216 1124 InCDsrv ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:03.0216 1124 InCDsrv - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:03.0232 1124 ini910u - ok਍ഀ
17:53:03.0248 1124 IntelIde - ok਍ഀ
17:53:03.0279 1124 [ 27b290d632af2cf3cf40bfddb7370985 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys਍ഀ
17:53:03.0388 1124 intelppm - ok਍ഀ
17:53:03.0419 1124 [ 3bb22519a194418d5fec05d800a19ad0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys਍ഀ
17:53:03.0560 1124 Ip6Fw - ok਍ഀ
17:53:03.0591 1124 [ 731f22ba402ee4b62748adaf6363c182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys਍ഀ
17:53:03.0748 1124 IpFilterDriver - ok਍ഀ
17:53:03.0763 1124 [ b87ab476dcf76e72010632b5550955f5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys਍ഀ
17:53:03.0873 1124 IpInIp - ok਍ഀ
17:53:03.0873 1124 [ cc748ea12c6effde940ee98098bf96bb ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys਍ഀ
17:53:03.0982 1124 IpNat - ok਍ഀ
17:53:04.0013 1124 [ 23c74d75e36e7158768dd63d92789a91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys਍ഀ
17:53:04.0123 1124 IPSec - ok਍ഀ
17:53:04.0138 1124 [ c93c9ff7b04d772627a3646d89f7bf89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys਍ഀ
17:53:04.0248 1124 IRENUM - ok਍ഀ
17:53:04.0263 1124 [ cc9f8a2d60aed1a51a3ac34c59b987ae ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys਍ഀ
17:53:04.0404 1124 isapnp - ok਍ഀ
17:53:04.0482 1124 [ 381b25dc8e958d905b33130d500bbf29 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe਍ഀ
17:53:04.0498 1124 JavaQuickStarterService - ok਍ഀ
17:53:04.0529 1124 [ fe8300320281d658a7854d5cfc02a63f ] k750bus C:\WINDOWS\system32\DRIVERS\k750bus.sys਍ഀ
17:53:04.0607 1124 k750bus - ok਍ഀ
17:53:04.0638 1124 [ f44521f63c0c00364fa3d59db980de6a ] k750mdfl C:\WINDOWS\system32\DRIVERS\k750mdfl.sys਍ഀ
17:53:04.0794 1124 k750mdfl - ok਍ഀ
17:53:04.0826 1124 [ e93323c3ed5e8923a177740a973c27b2 ] k750mdm C:\WINDOWS\system32\DRIVERS\k750mdm.sys਍ഀ
17:53:04.0841 1124 k750mdm - ok਍ഀ
17:53:04.0888 1124 [ 9d5f5a70ca0b7c428efcd73db50e6ac7 ] k750mgmt C:\WINDOWS\system32\DRIVERS\k750mgmt.sys਍ഀ
17:53:04.0935 1124 k750mgmt - ok਍ഀ
17:53:04.0966 1124 [ 81ca2d57b2c14f76f4ba80846784bb3d ] k750obex C:\WINDOWS\system32\DRIVERS\k750obex.sys਍ഀ
17:53:05.0029 1124 k750obex - ok਍ഀ
17:53:05.0060 1124 [ 1b6162fe7f66b1a71a4b70f941c4aa9b ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys਍ഀ
17:53:05.0169 1124 Kbdclass - ok਍ഀ
17:53:05.0201 1124 [ 86c8f23616c6c6e5b2776901c17b945b ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys਍ഀ
17:53:05.0310 1124 kbdhid - ok਍ഀ
17:53:05.0326 1124 [ 692bcf44383d056aed41b045a323d378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys਍ഀ
17:53:05.0451 1124 kmixer - ok਍ഀ
17:53:05.0498 1124 [ b467646c54cc746128904e1654c750c1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys਍ഀ
17:53:05.0529 1124 KSecDD - ok਍ഀ
17:53:05.0576 1124 [ 3428e8f86f8add36b42fb23542c7b3e4 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll਍ഀ
17:53:05.0607 1124 lanmanserver - ok਍ഀ
17:53:05.0669 1124 [ 936c1d110232d23b621cb0196e4f80f0 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll਍ഀ
17:53:05.0701 1124 lanmanworkstation - ok਍ഀ
17:53:05.0716 1124 lbrtfdc - ok਍ഀ
17:53:05.0763 1124 [ 9696786759c4b43fa5c894747e893ea2 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe਍ഀ
17:53:05.0779 1124 LightScribeService ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:05.0779 1124 LightScribeService - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:05.0810 1124 [ f8a7212d0864ef5e9185fb95e6623f4d ] lirsgt C:\WINDOWS\system32\DRIVERS\lirsgt.sys਍ഀ
17:53:05.0841 1124 lirsgt - ok਍ഀ
17:53:05.0873 1124 [ 0ab159f536e3e8f7f07113702a07cca5 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll਍ഀ
17:53:05.0982 1124 LmHosts - ok਍ഀ
17:53:06.0013 1124 [ 290fb01f7f51eff0960599404a09f8d6 ] mbmiodrvr C:\WINDOWS\system32\mbmiodrvr.sys਍ഀ
17:53:06.0060 1124 mbmiodrvr ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:06.0060 1124 mbmiodrvr - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:06.0091 1124 [ f922b609524cf1ed66a1a109f3ce014f ] mcdbus C:\WINDOWS\system32\DRIVERS\mcdbus.sys਍ഀ
17:53:06.0107 1124 mcdbus ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:06.0107 1124 mcdbus - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:06.0123 1124 [ 221cd1c815b8a6b79389c3f5d1018de8 ] Messenger C:\WINDOWS\System32\msgsvc.dll਍ഀ
17:53:06.0216 1124 Messenger - ok਍ഀ
17:53:06.0248 1124 [ 4ae068242760a1fb6e1a44bf4e16afa6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys਍ഀ
17:53:06.0357 1124 mnmdd - ok਍ഀ
17:53:06.0404 1124 [ 9a57d046f88f4b69751b11fd40088a61 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe਍ഀ
17:53:06.0513 1124 mnmsrvc - ok਍ഀ
17:53:06.0544 1124 [ 44032b0c6d9954d3fd26438330b99ee7 ] Modem C:\WINDOWS\system32\drivers\Modem.sys਍ഀ
17:53:06.0685 1124 Modem - ok਍ഀ
17:53:06.0857 1124 [ 4cb582831dbde63ce43b45d771218374 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys਍ഀ
17:53:07.0029 1124 Mouclass - ok਍ഀ
17:53:07.0076 1124 [ bb269eba740737ab749b214d568b6812 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys਍ഀ
17:53:07.0248 1124 mouhid - ok਍ഀ
17:53:07.0263 1124 [ a80b9a0bad1b73637dbcbba7df72d3fd ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys਍ഀ
17:53:07.0435 1124 MountMgr - ok਍ഀ
17:53:07.0451 1124 mraid35x - ok਍ഀ
17:53:07.0451 1124 [ 11d42bb6206f33fbb3ba0288d3ef81bd ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys਍ഀ
17:53:07.0607 1124 MRxDAV - ok਍ഀ
17:53:07.0638 1124 [ 7d304a5eb4344ebeeab53a2fe3ffb9f0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys਍ഀ
17:53:07.0748 1124 MRxSmb - ok਍ഀ
17:53:07.0779 1124 [ 6db4d1521caba9a5ffab54ade0ae867d ] MSDTC C:\WINDOWS\system32\msdtc.exe਍ഀ
17:53:07.0935 1124 MSDTC - ok਍ഀ
17:53:07.0966 1124 [ c941ea2454ba8350021d774daf0f1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys਍ഀ
17:53:08.0091 1124 Msfs - ok਍ഀ
17:53:08.0107 1124 MSIServer - ok਍ഀ
17:53:08.0123 1124 [ d1575e71568f4d9e14ca56b7b0453bf1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys਍ഀ
17:53:08.0263 1124 MSKSSRV - ok਍ഀ
17:53:08.0279 1124 [ 325bb26842fc7ccc1fcce2c457317f3e ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys਍ഀ
17:53:08.0419 1124 MSPCLOCK - ok਍ഀ
17:53:08.0435 1124 [ bad59648ba099da4a17680b39730cb3d ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys਍ഀ
17:53:08.0576 1124 MSPQM - ok਍ഀ
17:53:08.0607 1124 [ af5f4f3f14a8ea2c26de30f7a1e17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys਍ഀ
17:53:08.0763 1124 mssmbios - ok਍ഀ
17:53:08.0841 1124 MSSQL$SQLEXPRESS - ok਍ഀ
17:53:08.0873 1124 [ 1d89eb4e2a99cabd4e81225f4f4c4b25 ] MSSQLServerADHelper c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe਍ഀ
17:53:08.0888 1124 MSSQLServerADHelper - ok਍ഀ
17:53:09.0091 1124 [ e514d0493c272aecbac7c6c1dac635d1 ] msvsmon90 C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe਍ഀ
17:53:09.0216 1124 msvsmon90 - ok਍ഀ
17:53:09.0248 1124 [ de6a75f5c270e756c5508d94b6cf68f5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys਍ഀ
17:53:09.0294 1124 Mup - ok਍ഀ
17:53:09.0326 1124 mysql - ok਍ഀ
17:53:09.0373 1124 [ 64a957ed6078fc3e1684f1f7f0c26f9d ] NAL C:\WINDOWS\system32\Drivers\iqvw32.sys਍ഀ
17:53:09.0419 1124 NAL ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:09.0419 1124 NAL - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:09.0451 1124 [ 6ea362e9db03d44f6b996f4d8be237e9 ] napagent C:\WINDOWS\System32\qagentrt.dll਍ഀ
17:53:09.0591 1124 napagent - ok਍ഀ
17:53:09.0607 1124 [ 1df7f42665c94b825322fae71721130d ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys਍ഀ
17:53:09.0763 1124 NDIS - ok਍ഀ
17:53:09.0779 1124 [ 0109c4f3850dfbab279542515386ae22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys਍ഀ
17:53:09.0857 1124 NdisTapi - ok਍ഀ
17:53:09.0873 1124 [ f927a4434c5028758a842943ef1a3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys਍ഀ
17:53:10.0013 1124 Ndisuio - ok਍ഀ
17:53:10.0029 1124 [ edc1531a49c80614b2cfda43ca8659ab ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys਍ഀ
17:53:10.0201 1124 NdisWan - ok਍ഀ
17:53:10.0232 1124 [ 9282bd12dfb069d3889eb3fcc1000a9b ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys਍ഀ
17:53:10.0310 1124 NDProxy - ok਍ഀ
17:53:10.0341 1124 [ 5d81cf9a2f1a3a756b66cf684911cdf0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys਍ഀ
17:53:10.0482 1124 NetBIOS - ok਍ഀ
17:53:10.0498 1124 [ 74b2b2f5bea5e9a3dc021d685551bd3d ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys਍ഀ
17:53:10.0654 1124 NetBT - ok਍ഀ
17:53:10.0685 1124 [ 933de774986ec85e48210c44ab431de6 ] NetDDE C:\WINDOWS\system32\netdde.exe਍ഀ
17:53:10.0826 1124 NetDDE - ok਍ഀ
17:53:11.0044 1124 [ 933de774986ec85e48210c44ab431de6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe਍ഀ
17:53:11.0185 1124 NetDDEdsdm - ok਍ഀ
17:53:11.0216 1124 [ ed0a176354487ceed65b80a7148ab739 ] Netlogon C:\WINDOWS\system32\lsass.exe਍ഀ
17:53:11.0373 1124 Netlogon - ok਍ഀ
17:53:11.0404 1124 [ 72e1e9e2977be08bdeedb6d8fd9d4d40 ] Netman C:\WINDOWS\System32\netman.dll਍ഀ
17:53:11.0560 1124 Netman - ok਍ഀ
17:53:11.0591 1124 [ d34612c5d02d026535b3095d620626ae ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe਍ഀ
17:53:11.0607 1124 NetTcpPortSharing - ok਍ഀ
17:53:11.0623 1124 [ e9e47cfb2d461fa0fc75b7a74c6383ea ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys਍ഀ
17:53:11.0794 1124 NIC1394 - ok਍ഀ
17:53:11.0826 1124 [ 39ee7c3bfbc64ba87cc8cf67386e814c ] Nla C:\WINDOWS\System32\mswsock.dll਍ഀ
17:53:11.0857 1124 Nla - ok਍ഀ
17:53:11.0873 1124 [ 1e421a6bcf2203cc61b821ada9de878b ] nm C:\WINDOWS\system32\DRIVERS\NMnt.sys਍ഀ
17:53:12.0044 1124 nm - ok਍ഀ
17:53:12.0060 1124 [ 243126da7ba441d7c7c3262dcf435a9c ] NPF C:\WINDOWS\system32\drivers\npf.sys਍ഀ
17:53:12.0076 1124 NPF - ok਍ഀ
17:53:12.0123 1124 [ 3182d64ae053d6fb034f44b6def8034a ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys਍ഀ
17:53:12.0279 1124 Npfs - ok਍ഀ
17:53:12.0279 1124 npggsvc - ok਍ഀ
17:53:12.0326 1124 [ b28873f1a04dffd29d03d6eb201f9e49 ] npkcmsvc C:\Nexon\Mabinogi\npkcmsvc.exe਍ഀ
17:53:12.0341 1124 npkcmsvc - ok਍ഀ
17:53:12.0341 1124 npkcrypt - ok਍ഀ
17:53:12.0357 1124 npkcusb - ok਍ഀ
17:53:12.0388 1124 [ 78a08dd6a8d65e697c18e1db01c5cdca ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys਍ഀ
17:53:12.0544 1124 Ntfs - ok਍ഀ
17:53:12.0560 1124 [ ed0a176354487ceed65b80a7148ab739 ] NtLmSsp C:\WINDOWS\system32\lsass.exe਍ഀ
17:53:12.0701 1124 NtLmSsp - ok਍ഀ
17:53:12.0748 1124 [ 023dd70573d644f3d9c8b1258a7bfd08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll਍ഀ
17:53:12.0904 1124 NtmsSvc - ok਍ഀ
17:53:12.0919 1124 [ 73c1e1f395918bc2c6dd67af7591a3ad ] Null C:\WINDOWS\system32\drivers\Null.sys਍ഀ
17:53:13.0060 1124 Null - ok਍ഀ
17:53:13.0451 1124 [ 7b5a17bd54bb9142843dbe99a1caaed8 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys਍ഀ
17:53:14.0248 1124 nv - ok਍ഀ
17:53:14.0294 1124 [ 5150b108ea88831e1c599603d8b89621 ] NVSvc C:\WINDOWS\system32\nvsvc32.exe਍ഀ
17:53:14.0310 1124 NVSvc - ok਍ഀ
17:53:14.0404 1124 [ 83e8ab7bb3c8956c53fec071c94f0bbb ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe਍ഀ
17:53:14.0466 1124 nvUpdatusService - ok਍ഀ
17:53:14.0513 1124 [ b305f3fad35083837ef46a0bbce2fc57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys਍ഀ
17:53:14.0685 1124 NwlnkFlt - ok਍ഀ
17:53:14.0716 1124 [ c99b3415198d1aab7227f2c88fd664b9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys਍ഀ
17:53:14.0888 1124 NwlnkFwd - ok਍ഀ
17:53:14.0919 1124 [ ca33832df41afb202ee7aeb05145922f ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys਍ഀ
17:53:15.0091 1124 ohci1394 - ok਍ഀ
17:53:15.0138 1124 [ 5a432a042dae460abe7199b758e8606c ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE਍ഀ
17:53:15.0169 1124 ose - ok਍ഀ
17:53:15.0216 1124 OTi Card Reader Service - ok਍ഀ
17:53:15.0248 1124 [ 46f8db73b4a53e543f8e371dc7c75bae ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys਍ഀ
17:53:15.0435 1124 Parport - ok਍ഀ
17:53:15.0435 1124 [ beb3ba25197665d82ec7065b724171c6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys਍ഀ
17:53:15.0638 1124 PartMgr - ok਍ഀ
17:53:15.0654 1124 [ 1fae19d0457176318bba4a8795656ebc ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys਍ഀ
17:53:15.0826 1124 ParVdm - ok਍ഀ
17:53:15.0873 1124 [ 6ce351d149cb4befc702951e471e1730 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys਍ഀ
17:53:16.0013 1124 PCI - ok਍ഀ
17:53:16.0029 1124 PCIDump - ok਍ഀ
17:53:16.0060 1124 [ 2da4ec85e0ea7a45c6b2a05820492d5a ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys਍ഀ
17:53:16.0248 1124 PCIIde - ok਍ഀ
17:53:16.0263 1124 [ 4fc31e6c19a5ce5198b1abff94cae758 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys਍ഀ
17:53:16.0466 1124 Pcmcia - ok਍ഀ
17:53:16.0482 1124 PDCOMP - ok਍ഀ
17:53:16.0482 1124 PDFRAME - ok਍ഀ
17:53:16.0513 1124 PDRELI - ok਍ഀ
17:53:16.0513 1124 PDRFRAME - ok਍ഀ
17:53:16.0529 1124 perc2 - ok਍ഀ
17:53:16.0544 1124 perc2hib - ok਍ഀ
17:53:16.0576 1124 [ 9ef697af07bb8dd82c3b02ca953a95b7 ] PlugPlay C:\WINDOWS\system32\services.exe਍ഀ
17:53:16.0638 1124 PlugPlay - ok਍ഀ
17:53:16.0669 1124 [ 1713d9de407313138118d501b0e3c05b ] PnkBstrA C:\WINDOWS\system32\PnkBstrA.exe਍ഀ
17:53:16.0685 1124 PnkBstrA - ok਍ഀ
17:53:16.0701 1124 [ ed0a176354487ceed65b80a7148ab739 ] PolicyAgent C:\WINDOWS\system32\lsass.exe਍ഀ
17:53:16.0826 1124 PolicyAgent - ok਍ഀ
17:53:16.0857 1124 [ efeec01b1d3cf84f16ddd24d9d9d8f99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys਍ഀ
17:53:17.0029 1124 PptpMiniport - ok਍ഀ
17:53:17.0044 1124 [ ed0a176354487ceed65b80a7148ab739 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe਍ഀ
17:53:17.0185 1124 ProtectedStorage - ok਍ഀ
17:53:17.0232 1124 [ 64e413ba0c529aa40c3924bbcc4153db ] ProtexisLicensing C:\WINDOWS\system32\PSIService.exe਍ഀ
17:53:17.0248 1124 ProtexisLicensing ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:17.0248 1124 ProtexisLicensing - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:17.0263 1124 [ 09298ec810b07e5d582cb3a3f9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys਍ഀ
17:53:17.0466 1124 PSched - ok਍ഀ
17:53:17.0498 1124 [ 80d317bd1c3dbc5d4fe7b1678c60cadd ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys਍ഀ
17:53:17.0669 1124 Ptilink - ok਍ഀ
17:53:17.0701 1124 [ e42e3433dbb4cffe8fdd91eab29aea8e ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys਍ഀ
17:53:17.0748 1124 PxHelp20 - ok਍ഀ
17:53:17.0748 1124 ql1080 - ok਍ഀ
17:53:17.0748 1124 Ql10wnt - ok਍ഀ
17:53:17.0763 1124 ql12160 - ok਍ഀ
17:53:17.0763 1124 ql1240 - ok਍ഀ
17:53:17.0779 1124 ql1280 - ok਍ഀ
17:53:17.0794 1124 [ fe0d99d6f31e4fad8159f690d68ded9c ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys਍ഀ
17:53:17.0982 1124 RasAcd - ok਍ഀ
17:53:18.0013 1124 [ 2b5e44ea009f2f374b980e1e9a70635d ] RasAuto C:\WINDOWS\System32\rasauto.dll਍ഀ
17:53:18.0169 1124 RasAuto - ok਍ഀ
17:53:18.0201 1124 [ 11b4a627bc9614b885c4969bfa5ff8a6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys਍ഀ
17:53:18.0373 1124 Rasl2tp - ok਍ഀ
17:53:18.0404 1124 [ d57554c664b64604bd1ee13ea2c07e77 ] RasMan C:\WINDOWS\System32\rasmans.dll਍ഀ
17:53:18.0576 1124 RasMan - ok਍ഀ
17:53:18.0607 1124 [ 5bc962f2654137c9909c3d4603587dee ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys਍ഀ
17:53:18.0779 1124 RasPppoe - ok਍ഀ
17:53:18.0779 1124 [ fdbb1d60066fcfbb7452fd8f9829b242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys਍ഀ
17:53:18.0951 1124 Raspti - ok਍ഀ
17:53:18.0951 1124 [ 7ad224ad1a1437fe28d89cf22b17780a ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys਍ഀ
17:53:19.0185 1124 Rdbss - ok਍ഀ
17:53:19.0185 1124 [ 4912d5b403614ce99c28420f75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys਍ഀ
17:53:19.0341 1124 RDPCDD - ok਍ഀ
17:53:19.0373 1124 [ 15cabd0f7c00c47c70124907916af3f1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys਍ഀ
17:53:19.0560 1124 rdpdr - ok਍ഀ
17:53:19.0607 1124 [ 6589db6e5969f8eee594cf71171c5028 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys਍ഀ
17:53:19.0685 1124 RDPWD - ok਍ഀ
17:53:19.0716 1124 [ c0d9d9711cb74ee9bc66353d8cbdab0e ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe਍ഀ
17:53:19.0857 1124 RDSessMgr - ok਍ഀ
17:53:19.0888 1124 [ 611bfd220305be3a85ae876ea47d4aa5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys਍ഀ
17:53:20.0029 1124 redbook - ok਍ഀ
17:53:20.0076 1124 [ 127c26b5371651043450e52542099aba ] RemoteAccess C:\WINDOWS\System32\mprdim.dll਍ഀ
17:53:20.0232 1124 RemoteAccess - ok਍ഀ
17:53:20.0248 1124 [ 8f31505484a190d5b22274708799f4ec ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll਍ഀ
17:53:20.0388 1124 RemoteRegistry - ok਍ഀ
17:53:20.0419 1124 [ 8738cad3f5d285d544a4d6553ff61bcc ] rpcapd C:\Program Files\WinPcap\rpcapd.exe਍ഀ
17:53:20.0435 1124 rpcapd - ok਍ഀ
17:53:20.0466 1124 [ 718b3bdc0bc3c2f7d065a53d26202af9 ] RpcLocator C:\WINDOWS\system32\locator.exe਍ഀ
17:53:20.0607 1124 RpcLocator - ok਍ഀ
17:53:20.0638 1124 [ be27674d1cbc3214aec84b4336a38bbf ] RpcSs C:\WINDOWS\system32\rpcss.dll਍ഀ
17:53:20.0716 1124 RpcSs - ok਍ഀ
17:53:20.0748 1124 [ 09ab2e71e58b078038e3bfdba7ffc984 ] RSVP C:\WINDOWS\system32\rsvp.exe਍ഀ
17:53:20.0904 1124 RSVP - ok਍ഀ
17:53:21.0107 1124 [ 581e74880aeb1dba1cb5ac8e6e6c0a69 ] RT61 C:\WINDOWS\system32\DRIVERS\RT61.sys਍ഀ
17:53:21.0154 1124 RT61 - ok਍ഀ
17:53:21.0185 1124 [ ed0a176354487ceed65b80a7148ab739 ] SamSs C:\WINDOWS\system32\lsass.exe਍ഀ
17:53:21.0310 1124 SamSs - ok਍ഀ
17:53:21.0357 1124 [ 410046e401eb11e1e6749e9deea41d4a ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe਍ഀ
17:53:21.0498 1124 SCardSvr - ok਍ഀ
17:53:21.0529 1124 [ 3ff232a7731621b8902d81d42418c93c ] Schedule C:\WINDOWS\system32\schedsvc.dll਍ഀ
17:53:21.0685 1124 Schedule - ok਍ഀ
17:53:21.0716 1124 [ 6d15e382bf5dcb6ee2d871aaa02ee815 ] SE31bus C:\WINDOWS\system32\DRIVERS\SE31bus.sys਍ഀ
17:53:22.0013 1124 SE31bus - ok਍ഀ
17:53:22.0029 1124 [ 585b242f3f549813b63887d823a2cf44 ] SE31mdfl C:\WINDOWS\system32\DRIVERS\SE31mdfl.sys਍ഀ
17:53:22.0076 1124 SE31mdfl - ok਍ഀ
17:53:22.0091 1124 [ 441dc38eaf3fff763c96b1d34e0f977c ] SE31mdm C:\WINDOWS\system32\DRIVERS\SE31mdm.sys਍ഀ
17:53:22.0138 1124 SE31mdm - ok਍ഀ
17:53:22.0185 1124 [ cfdf624eaeaf8eabf5fddfdecdb2fd61 ] SE31mgmt C:\WINDOWS\system32\DRIVERS\SE31mgmt.sys਍ഀ
17:53:22.0248 1124 SE31mgmt - ok਍ഀ
17:53:22.0279 1124 [ d04314def53b410d251e39efd7da0138 ] se31nd5 C:\WINDOWS\system32\DRIVERS\se31nd5.sys਍ഀ
17:53:22.0294 1124 se31nd5 - ok਍ഀ
17:53:22.0310 1124 [ a8173a2baa0fd1486e7c79760e7b81b2 ] SE31obex C:\WINDOWS\system32\DRIVERS\SE31obex.sys਍ഀ
17:53:22.0341 1124 SE31obex - ok਍ഀ
17:53:22.0373 1124 [ 359331f55482a92214b1cb1771810e7f ] se31unic C:\WINDOWS\system32\DRIVERS\se31unic.sys਍ഀ
17:53:22.0404 1124 se31unic - ok਍ഀ
17:53:22.0419 1124 [ 90a3935d05b494a5a39d37e71f09a677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys਍ഀ
17:53:22.0560 1124 Secdrv - ok਍ഀ
17:53:22.0591 1124 [ 477e2c3cc5e4a0d635bcb0ea8dcac3c6 ] seclogon C:\WINDOWS\System32\seclogon.dll਍ഀ
17:53:22.0748 1124 seclogon - ok਍ഀ
17:53:22.0763 1124 [ a530b75c10c23c9ab28fdb6ce719e21f ] SENS C:\WINDOWS\system32\sens.dll਍ഀ
17:53:22.0919 1124 SENS - ok਍ഀ
17:53:22.0966 1124 [ 0f29512ccd6bead730039fb4bd2c85ce ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys਍ഀ
17:53:23.0107 1124 serenum - ok਍ഀ
17:53:23.0123 1124 [ b842729337c9b921615c40d3c1a1af96 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys਍ഀ
17:53:23.0341 1124 Serial - ok਍ഀ
17:53:23.0404 1124 [ 4c0d673281178cb496011a2e28571fc8 ] sfdrv01 C:\WINDOWS\system32\drivers\sfdrv01.sys਍ഀ
17:53:23.0404 1124 sfdrv01 ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:23.0404 1124 sfdrv01 - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:23.0419 1124 [ 15be2b5e4dc5b8623cf167720682abc9 ] sfhlp02 C:\WINDOWS\system32\drivers\sfhlp02.sys਍ഀ
17:53:23.0451 1124 sfhlp02 ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:23.0451 1124 sfhlp02 - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:23.0466 1124 [ 8e6b8c671615d126fdc553d1e2de5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys਍ഀ
17:53:23.0623 1124 Sfloppy - ok਍ഀ
17:53:23.0654 1124 [ 5fe18fff6fbcf218290042009eab023d ] sfng32 C:\WINDOWS\system32\drivers\sfng32.sys਍ഀ
17:53:23.0701 1124 sfng32 - ok਍ഀ
17:53:23.0716 1124 [ efebbc1d13fdb77a6af4eddfc7232edf ] sfsync02 C:\WINDOWS\system32\drivers\sfsync02.sys਍ഀ
17:53:23.0732 1124 sfsync02 ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:23.0732 1124 sfsync02 - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:23.0779 1124 [ f58faca9621d2db01bd0927d9a0a208e ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll਍ഀ
17:53:23.0919 1124 SharedAccess - ok਍ഀ
17:53:23.0935 1124 [ ee9a2b9ea968a792a053c9d1a86bf870 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll਍ഀ
17:53:23.0966 1124 ShellHWDetection - ok਍ഀ
17:53:23.0966 1124 Simbad - ok਍ഀ
17:53:24.0154 1124 [ 0f97e7a47a52f4a36969f0fc319654c2 ] Skype C2C Service C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe਍ഀ
17:53:24.0326 1124 Skype C2C Service - ok਍ഀ
17:53:24.0373 1124 [ 68ea68d03bf58389fe6ad2b38fad798c ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe਍ഀ
17:53:24.0404 1124 SkypeUpdate - ok਍ഀ
17:53:24.0482 1124 [ 5177d14a78e60fd61dcfc6b388e7e971 ] Sony PC Companion C:\Program Files\Sony\Sony PC Companion\PCCService.exe਍ഀ
17:53:24.0498 1124 Sony PC Companion - ok਍ഀ
17:53:24.0513 1124 Sparrow - ok਍ഀ
17:53:24.0544 1124 [ ab8b92451ecb048a4d1de7c3ffcb4a9f ] splitter C:\WINDOWS\system32\drivers\splitter.sys਍ഀ
17:53:24.0716 1124 splitter - ok਍ഀ
17:53:24.0841 1124 [ 60784f891563fb1b767f70117fc2428f ] Spooler C:\WINDOWS\system32\spoolsv.exe਍ഀ
17:53:24.0888 1124 Spooler - ok਍ഀ
17:53:24.0935 1124 [ d15da1ba189770d93eea2d7e18f95af9 ] sptd C:\WINDOWS\system32\Drivers\sptd.sys਍ഀ
17:53:24.0935 1124 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9਍ഀ
17:53:24.0935 1124 sptd ( LockedFile.Multi.Generic ) - warning਍ഀ
17:53:24.0935 1124 sptd - detected LockedFile.Multi.Generic (1)਍ഀ
17:53:24.0951 1124 [ 86ebd8b1f23e743aad21f4d5b4d40985 ] SQLBrowser c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe਍ഀ
17:53:24.0982 1124 SQLBrowser - ok਍ഀ
17:53:25.0013 1124 [ d89083c4eb02daca8f944b0e05e57f9d ] SQLWriter c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe਍ഀ
17:53:25.0029 1124 SQLWriter - ok਍ഀ
17:53:25.0044 1124 [ 94610c8653635e4459316a0050d55ce7 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys਍ഀ
17:53:25.0185 1124 sr - ok਍ഀ
17:53:25.0294 1124 [ 35b91147124f64ac8081a2edb9ea4dee ] srservice C:\WINDOWS\system32\srsvc.dll਍ഀ
17:53:25.0451 1124 srservice - ok਍ഀ
17:53:25.0498 1124 [ 47ddfc2f003f7f9f0592c6874962a2e7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys਍ഀ
17:53:25.0654 1124 Srv - ok਍ഀ
17:53:25.0654 1124 [ becd5271dc4e3b7c3d035f790fcbc1e5 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll਍ഀ
17:53:25.0810 1124 SSDPSRV - ok਍ഀ
17:53:25.0888 1124 [ 6ad7569cc5e40b94932ec56097c5dccd ] STHDA C:\WINDOWS\system32\drivers\sthda.sys਍ഀ
17:53:26.0029 1124 STHDA - ok਍ഀ
17:53:26.0060 1124 [ c1cdd9275f6a115bb0ae1d55d8d27ba6 ] stisvc C:\WINDOWS\system32\wiaservc.dll਍ഀ
17:53:26.0201 1124 stisvc - ok਍ഀ
17:53:26.0232 1124 [ 3941d127aef12e93addf6fe6ee027e0f ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys਍ഀ
17:53:26.0388 1124 swenum - ok਍ഀ
17:53:26.0607 1124 [ 8ce882bcc6cf8a62f2b2323d95cb3d01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys਍ഀ
17:53:26.0794 1124 swmidi - ok਍ഀ
17:53:26.0810 1124 SwPrv - ok਍ഀ
17:53:26.0826 1124 symc810 - ok਍ഀ
17:53:26.0841 1124 symc8xx - ok਍ഀ
17:53:26.0841 1124 sym_hi - ok਍ഀ
17:53:26.0857 1124 sym_u3 - ok਍ഀ
17:53:26.0888 1124 [ 8b83f3ed0f1688b4958f77cd6d2bf290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys਍ഀ
17:53:27.0029 1124 sysaudio - ok਍ഀ
17:53:27.0076 1124 [ ce06f01b88ace199a1bf460cac29c110 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe਍ഀ
17:53:27.0216 1124 SysmonLog - ok਍ഀ
17:53:27.0263 1124 [ 0f5381f47ab59dd1cd5d12db3089c882 ] Tablet2k C:\WINDOWS\System32\Drivers\Tablet2k.sys਍ഀ
17:53:27.0263 1124 Tablet2k ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:27.0263 1124 Tablet2k - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:27.0310 1124 [ 9d9feffa791cedebeec2725590e6024f ] tap0901_2gm C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys਍ഀ
17:53:27.0341 1124 tap0901_2gm ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:27.0341 1124 tap0901_2gm - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:27.0357 1124 [ c2546cd7a398476f9df5614b2ae160e8 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll਍ഀ
17:53:27.0529 1124 TapiSrv - ok਍ഀ
17:53:27.0576 1124 [ 535fb6fe9b756b4e3203de3e3842fa04 ] TClass2k C:\WINDOWS\system32\DRIVERS\TClass2k.sys਍ഀ
17:53:27.0638 1124 TClass2k ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:27.0638 1124 TClass2k - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:27.0685 1124 [ 9aefa14bd6b182d61e3119fa5f436d3d ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys਍ഀ
17:53:27.0763 1124 Tcpip - ok਍ഀ
17:53:27.0810 1124 [ 6471a66807f5e104e4885f5b67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys਍ഀ
17:53:27.0966 1124 TDPIPE - ok਍ഀ
17:53:27.0998 1124 [ c56b6d0402371cf3700eb322ef3aaf61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys਍ഀ
17:53:28.0138 1124 TDTCP - ok਍ഀ
17:53:28.0169 1124 [ 88155247177638048422893737429d9e ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys਍ഀ
17:53:28.0357 1124 TermDD - ok਍ഀ
17:53:28.0404 1124 [ a75dd6fc3dbee4fff5ebc9f2c28bb66e ] TermService C:\WINDOWS\System32\termsrv.dll਍ഀ
17:53:28.0529 1124 TermService - ok਍ഀ
17:53:28.0560 1124 [ ee9a2b9ea968a792a053c9d1a86bf870 ] Themes C:\WINDOWS\System32\shsvcs.dll਍ഀ
17:53:28.0576 1124 Themes - ok਍ഀ
17:53:28.0607 1124 [ cd0cc7b167d78043a41c98d4921efb54 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe਍ഀ
17:53:28.0794 1124 TlntSvr - ok਍ഀ
17:53:28.0794 1124 TosIde - ok਍ഀ
17:53:28.0826 1124 [ 38853304ccb938d30e0c4cde8d2c2a8a ] TrkWks C:\WINDOWS\system32\trkwks.dll਍ഀ
17:53:28.0966 1124 TrkWks - ok਍ഀ
17:53:29.0013 1124 [ 019d314a69789e377a92b8b279c8e12b ] UCTblHid C:\WINDOWS\system32\DRIVERS\UCTblHid.sys਍ഀ
17:53:29.0044 1124 UCTblHid ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:29.0044 1124 UCTblHid - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:29.0091 1124 [ 5787b80c2e3c5e2f56c2a233d91fa2c9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys਍ഀ
17:53:29.0232 1124 Udfs - ok਍ഀ
17:53:29.0279 1124 [ b646bb5cbeb60771b96efb6da14c7509 ] UfasoftSnifDriver4 C:\Program Files\Ufasoft\Sniffer\usft_sn4.sys਍ഀ
17:53:29.0294 1124 UfasoftSnifDriver4 ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:29.0294 1124 UfasoftSnifDriver4 - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:29.0294 1124 ultra - ok਍ഀ
17:53:29.0341 1124 [ 402ddc88356b1bac0ee3dd1580c76a31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys਍ഀ
17:53:29.0513 1124 Update - ok਍ഀ
17:53:29.0544 1124 [ 651bd90dcee5b7bdc74a2eb7c9266f9e ] upnphost C:\WINDOWS\System32\upnphost.dll਍ഀ
17:53:29.0716 1124 upnphost - ok਍ഀ
17:53:29.0732 1124 [ 20a0f6a11959e92908717d09e87d670d ] UPS C:\WINDOWS\System32\ups.exe਍ഀ
17:53:29.0873 1124 UPS - ok਍ഀ
17:53:29.0919 1124 [ e919708db44ed8543a7c017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys਍ഀ
17:53:30.0060 1124 usbaudio - ok਍ഀ
17:53:30.0107 1124 [ 173f317ce0db8e21322e71b7e60a27e8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys਍ഀ
17:53:30.0248 1124 usbccgp - ok਍ഀ
17:53:30.0263 1124 [ 65dcf09d0e37d4c6b11b5b0b76d470a7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys਍ഀ
17:53:30.0435 1124 usbehci - ok਍ഀ
17:53:30.0451 1124 [ 1ab3cdde553b6e064d2e754efe20285c ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys਍ഀ
17:53:30.0623 1124 usbhub - ok਍ഀ
17:53:30.0669 1124 [ a717c8721046828520c9edf31288fc00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys਍ഀ
17:53:30.0794 1124 usbprint - ok਍ഀ
17:53:30.0826 1124 [ a0b8cf9deb1184fbdd20784a58fa75d4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys਍ഀ
17:53:30.0966 1124 usbscan - ok਍ഀ
17:53:30.0998 1124 [ a32426d9b14a089eaa1d922e0c5801a9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS਍ഀ
17:53:31.0123 1124 usbstor - ok਍ഀ
17:53:31.0154 1124 [ 26496f9dee2d787fc3e61ad54821ffe6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys਍ഀ
17:53:31.0341 1124 usbuhci - ok਍ഀ
17:53:31.0373 1124 [ 0d3a8fafceacd8b7625cd549757a7df1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys਍ഀ
17:53:31.0513 1124 VgaSave - ok਍ഀ
17:53:31.0513 1124 ViaIde - ok਍ഀ
17:53:31.0529 1124 VMnetAdapter - ok਍ഀ
17:53:31.0576 1124 [ 28a4b296b47782173c346e376cb374d1 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys਍ഀ
17:53:31.0748 1124 VolSnap - ok਍ഀ
17:53:31.0810 1124 [ 0bd123313159cb8963d7a0404f7d96a5 ] VSPerfDrv90 C:\Program Files\Microsoft Visual Studio 9.0\Team Tools\Performance Tools\VSPerfDrv90.sys਍ഀ
17:53:31.0841 1124 VSPerfDrv90 - ok਍ഀ
17:53:31.0873 1124 [ d6ba1a63d9e00933f1cd2a885573afb2 ] VSS C:\WINDOWS\System32\vssvc.exe਍ഀ
17:53:32.0029 1124 VSS - ok਍ഀ
17:53:32.0060 1124 [ fa4e1cdba256787f2149f4aad07bc91f ] W32Time C:\WINDOWS\system32\w32time.dll਍ഀ
17:53:32.0201 1124 W32Time - ok਍ഀ
17:53:32.0263 1124 [ e20b95baedb550f32dd489265c1da1f6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys਍ഀ
17:53:32.0404 1124 Wanarp - ok਍ഀ
17:53:32.0451 1124 [ bbcfeab7e871cddac2d397ee7fa91fdc ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys਍ഀ
17:53:32.0482 1124 Wdf01000 - ok਍ഀ
17:53:32.0498 1124 WDICA - ok਍ഀ
17:53:32.0529 1124 [ 6768acf64b18196494413695f0c3a00f ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys਍ഀ
17:53:32.0685 1124 wdmaud - ok਍ഀ
17:53:32.0716 1124 [ 47ae51048a82dfa1cd6b51d369f7e169 ] WebClient C:\WINDOWS\System32\webclnt.dll਍ഀ
17:53:32.0857 1124 WebClient - ok਍ഀ
17:53:32.0935 1124 [ e488332126e3b1182d2b8a0c35408ec6 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll਍ഀ
17:53:33.0076 1124 winmgmt - ok਍ഀ
17:53:33.0138 1124 [ 7d8570c2bc1c04582ba4712746a32604 ] WinTabService C:\WINDOWS\system32\DRIVERS\WtSrv.exe਍ഀ
17:53:33.0138 1124 WinTabService ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:33.0138 1124 WinTabService - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:33.0185 1124 [ c51b4a5c05a5475708e3c81c7765b71d ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll਍ഀ
17:53:33.0216 1124 WmdmPmSN - ok਍ഀ
17:53:33.0248 1124 [ 0171cff34bba8c5977f18c48d8aef8c6 ] Wmi C:\WINDOWS\System32\advapi32.dll਍ഀ
17:53:33.0326 1124 Wmi - ok਍ഀ
17:53:33.0341 1124 [ 23f6f03272f7e5679f1f050aed5acee6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe਍ഀ
17:53:33.0482 1124 WmiApSrv - ok਍ഀ
17:53:33.0560 1124 [ ccfdecd6060ea8eb0f8466782a97ff21 ] WMP54Gv4SVC C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe਍ഀ
17:53:33.0560 1124 WMP54Gv4SVC ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:33.0560 1124 WMP54Gv4SVC - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:33.0638 1124 [ 3739866d20abd42f26a7b85f9e2560af ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe਍ഀ
17:53:33.0732 1124 WMPNetworkSvc - ok਍ഀ
17:53:33.0763 1124 [ cf4def1bf66f06964dc0d91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys਍ഀ
17:53:33.0779 1124 WpdUsb - ok਍ഀ
17:53:33.0888 1124 [ dcf3e3edf5109ee8bc02fe6e1f045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe਍ഀ
17:53:33.0935 1124 WPFFontCache_v0400 - ok਍ഀ
17:53:33.0966 1124 [ 4c86d5faf78194995af9cc1075f65dd3 ] wscsvc C:\WINDOWS\system32\wscsvc.dll਍ഀ
17:53:34.0107 1124 wscsvc - ok਍ഀ
17:53:34.0138 1124 [ c1364564800ee9784192145324a23308 ] wuauserv C:\WINDOWS\system32\wuauserv.dll਍ഀ
17:53:34.0294 1124 wuauserv - ok਍ഀ
17:53:34.0326 1124 [ f15feafffbb3644ccc80c5da584e6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys਍ഀ
17:53:34.0373 1124 WudfPf - ok਍ഀ
17:53:34.0388 1124 [ 28b524262bce6de1f7ef9f510ba3985b ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys਍ഀ
17:53:34.0419 1124 WudfRd - ok਍ഀ
17:53:34.0451 1124 [ 05231c04253c5bc30b26cbaae680ed89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll਍ഀ
17:53:34.0466 1124 WudfSvc - ok਍ഀ
17:53:34.0513 1124 [ a27d4ba7264c0bf52f32d10405bea1d4 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll਍ഀ
17:53:34.0685 1124 WZCSVC - ok਍ഀ
17:53:34.0701 1124 [ 16a004d355467e44d217dc4df62ec1e4 ] XAMPP C:\xampp\service.exe਍ഀ
17:53:34.0732 1124 XAMPP ( UnsignedFile.Multi.Generic ) - warning਍ഀ
17:53:34.0732 1124 XAMPP - detected UnsignedFile.Multi.Generic (1)਍ഀ
17:53:34.0732 1124 xcpip - ok਍ഀ
17:53:34.0904 1124 [ eaa4bb9edb3fb10cf8979fe65e63658f ] xmlprov C:\WINDOWS\System32\xmlprov.dll਍ഀ
17:53:35.0076 1124 xmlprov - ok਍ഀ
17:53:35.0076 1124 xpsec - ok਍ഀ
17:53:35.0107 1124 ================ Scan global ===============================਍ഀ
17:53:35.0138 1124 (f36278e42c8c5df03ce17dac8231c91c) C:\WINDOWS\system32\basesrv.dll਍ഀ
17:53:35.0185 1124 (f3fa14a297bc687d0b51289d034033c9) C:\WINDOWS\system32\winsrv.dll਍ഀ
17:53:35.0201 1124 (f3fa14a297bc687d0b51289d034033c9) C:\WINDOWS\system32\winsrv.dll਍ഀ
17:53:35.0216 1124 (9ef697af07bb8dd82c3b02ca953a95b7) C:\WINDOWS\system32\services.exe਍ഀ
17:53:35.0232 1124 [Global] - ok਍ഀ
17:53:35.0232 1124 ================ Scan MBR ==================================਍ഀ
17:53:35.0248 1124 MBR (0x1B8) (1fd04ab709cba1dac89f3074ab6f9420) \Device\Harddisk0\DR0਍ഀ
17:53:35.0248 1124 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - infected਍ഀ
17:53:35.0248 1124 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Sinowal.b (0)਍ഀ
17:53:35.0357 1124 MBR (0x1B8) (0792f22bcc85cfd3b28324561fffcabb) \Device\Harddisk1\DR1਍ഀ
17:53:38.0732 1124 \Device\Harddisk1\DR1 - ok਍ഀ
17:53:38.0732 1124 MBR (0x1B8) (66d0b28c8b44e531d0c19f436252abaa) \Device\Harddisk6\DR14਍ഀ
17:53:39.0107 1124 \Device\Harddisk6\DR14 - ok਍ഀ
17:53:39.0123 1124 MBR (0x1B8) (0e74569aa85a7b7bc34fb78b81c228fd) \Device\Harddisk7\DR18਍ഀ
17:53:42.0326 1124 \Device\Harddisk7\DR18 - ok਍ഀ
17:53:42.0326 1124 ================ Scan VBR ==================================਍ഀ
17:53:42.0341 1124 Boot (0x1200) (2643a34c8738cb7b42c39c4605334542) \Device\Harddisk0\DR0\Partition1਍ഀ
17:53:42.0341 1124 \Device\Harddisk0\DR0\Partition1 - ok਍ഀ
17:53:42.0341 1124 Boot (0x1200) (71b5fd190cecb8886e80eb79e21b2516) \Device\Harddisk1\DR1\Partition1਍ഀ
17:53:42.0357 1124 \Device\Harddisk1\DR1\Partition1 - ok਍ഀ
17:53:42.0357 1124 Boot (0x1200) (04c3a6d24447875ae4247178e1ac6748) \Device\Harddisk6\DR14\Partition1਍ഀ
17:53:42.0357 1124 \Device\Harddisk6\DR14\Partition1 - ok਍ഀ
17:53:42.0357 1124 ============================================================਍ഀ
17:53:42.0357 1124 Scan finished਍ഀ
17:53:42.0357 1124 ============================================================਍ഀ
17:53:42.0498 0900 Detected object count: 34਍ഀ
17:53:42.0498 0900 Actual detected object count: 34਍ഀ
17:54:09.0357 0900 AegisP ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0357 0900 AegisP ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0357 0900 Apache2.2 ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0357 0900 Apache2.2 ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 Apple Mobile Device ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 Apple Mobile Device ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 ATI Smart ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 ATI Smart ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 BCM42RLY ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 BCM42RLY ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 Bonjour Service ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 Bonjour Service ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 Diskeeper ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 Diskeeper ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 e1express ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 e1express ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 HECI ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 HECI ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0373 0900 InCDfs ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0373 0900 InCDfs ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 InCDPass ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 InCDPass ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 InCDrec ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 InCDrec ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 incdrm ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 incdrm ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 InCDsrv ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 InCDsrv ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 mbmiodrvr ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 mbmiodrvr ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 mcdbus ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 mcdbus ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 NAL ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 NAL ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 ProtexisLicensing ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 ProtexisLicensing ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0388 0900 sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0388 0900 sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 sfsync02 ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 sfsync02 ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 sptd ( LockedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 sptd ( LockedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 Tablet2k ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 Tablet2k ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 tap0901_2gm ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 tap0901_2gm ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 TClass2k ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 TClass2k ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 UCTblHid ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 UCTblHid ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 UfasoftSnifDriver4 ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 UfasoftSnifDriver4 ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 WinTabService ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 WinTabService ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0404 0900 WMP54Gv4SVC ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0404 0900 WMP54Gv4SVC ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0419 0900 XAMPP ( UnsignedFile.Multi.Generic ) - skipped by user਍ഀ
17:54:09.0419 0900 XAMPP ( UnsignedFile.Multi.Generic ) - User select action: Skip ਍ഀ
17:54:09.0419 0900 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - skipped by user਍ഀ
17:54:09.0419 0900 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - User select action: Skip ਍ഀ

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#4 Příspěvek od Teochi »

Tak, konečně uděláno, bylo zde nějaké zdržení, ale máme to snad vše. Log Vám nakopíruju přímo a ty rary, vzhledem k jejich velikosti, posílám jako přílohu :).

PS: nemůžu poslat více jak jednu přílohu, takže vám druhý rar pošlu v dalším postu, doufám, že to nebude vadit. :(

log

CREATERESTOREPOINT
netsvcs
drivers32
safebootminimal
safebootnetwork
savembr:0
DRIVES

/md5start
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
hal.dll
netlogon.dll
KR10N.dll
scecli.dll
user32.dll
winsrv.dll
ws2_32.dll
autochk.exe
cmd.exe
csrss.exe
explorer.exe
lsass.exe
ntkrnlpa.exe
ntoskrnl.exe
services.exe
smss.exe
spoolsv.exe
svchost.exe
regedit.exe
userinit.exe
winlogon.exe
wscript.exe
afd.sys
adp3132.sys
acpi.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
cdrom.sys
Changer.sys
fastfat.sys
i8042prt.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
kbdclass.sys
KR10N.sys
mv61xx.sys
ndis.sys
ntfs.sys
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
symmpi.sys
tcpip.sys
tdx.sys
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
Win32k.sys
Wdf01000.sys
xpsec.sys
xcpip.sys
/md5stop

%systemroot%\system32\logevent.dll /md5
%systemroot%\system32\sceclt.dll /md5
%systemroot%\system32\ntelogon.dll /md5
%systemroot%\system32\consrv.dll /md5

%systemroot%\system32\logevent.dll /md5 /64
%systemroot%\system32\sceclt.dll /md5 /64
%systemroot%\system32\ntelogon.dll /md5 /64
%systemroot%\system32\consrv.dll /md5 /64

%systemroot%\system32\drivers\*.sys /md5
%systemroot%\system32\*.sys /md5
%systemroot%\system32\*.dll /md5

%systemroot%\system32\drivers\*.sys /md5 /64
%systemroot%\system32\*.sys /md5 /64

%SystemDrive%\PhysicalMBR.bin /md5
%PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
%PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
%PROGRAMFILES%\Opera\opera.exe /md5
%PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5

%systemroot%\system32\Spool\prtprocs\*.* /s
%systemroot%\system32\drivers\*.sys /10
%systemroot%\system32\drivers\*.sys /X
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\*.* /10
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.* /lockedfiles
%systemroot%\system32\config\*.sav



%systemroot%\Tasks\*.job
%systemroot%\*.* /U /s
%systemroot%\Documents and Settings\Veronika\Dokumenty\*.* /U /s
%systemroot%\*. /rp /s
%ALLUSERSPROFILE%\Data Aplikací\*.*
%ALLUSERSPROFILE%\Data Aplikací\*.exe /s
%ALLUSERSPROFILE%\Nabídka Start\*.lnk /x
%ALLUSERSPROFILE%\Data Aplikácií\*.*
%ALLUSERSPROFILE%\Data Aplikácií\*.exe /s
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%APPDATA%\*.
%APPDATA%\*.*
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
%systemroot%\system32|bak;true;false;false /fp
%PROGRAMFILES%|bak;true;false;false /fp

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems" /v Windows /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs" /c

type c:\boot.ini >> test.txt /c
bcdedit /enum all /v >C:\boot.txt /c
type C:\boot.txt >> test1.txt /c
echo list vol > C:\prikaz.txt | diskpart /s C:\prikaz.txt > C:\test2.txt /c
Přílohy
MBR-Dump.rar
(510 bajtů) Staženo 83 x

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#5 Příspěvek od Teochi »

Další příloha.
Přílohy
RK_Quarantine.rar
(976.01 KiB) Staženo 77 x

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#6 Příspěvek od Teochi »

Vše hotovo, až na jeden krok, na který se opomnělo, tak nám dejte chvilku, at to máme kompletní :) .

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#7 Příspěvek od Teochi »

Právě šlo o krok č. 4 a ukázalo se, že jsme poslali špatný OTL log, tak ho posíláme tedy nově:
PS: je to nějak psycho dlouhé, tak to přikládám jako přílohu ve wordu, nezlobte se prosím :shock:
Přílohy
OTLv2.zip
(161.75 KiB) Staženo 90 x

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#8 Příspěvek od Teochi »

Jo, tak to musíme udělat znovu, abychom dostali i to extra.txt. Každopádně se omlouvám s tím logem, já myslel, že to je právě chyba, protože mi to házelo asijštinu, tak jsem to hodil takhle. Omlouvám se, a po další kontrole s extra registry, Vám přiložím oba logy :) .

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#9 Příspěvek od Teochi »

Dobře, omlouvám se, byla to má chyba :) . Posílám tedy zipa s logy. Tak tedy zase zítra :)
Přílohy
OTL.zip
(148.54 KiB) Staženo 80 x

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#10 Příspěvek od Teochi »

.
Přílohy
Extras.zip
(20.54 KiB) Staženo 77 x

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#11 Příspěvek od Teochi »

Tak, posílám ty logy v příloze :)

EDIT: Ohledně toho, kde Verča chytla toho vira, tak to fakt chudák neví :?:
Přílohy
logy_mbr_kombo_avenger.zip
(21.2 KiB) Staženo 80 x

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#12 Příspěvek od Teochi »

To velice rád slyším a sám Eset to zatím potvrdil :thumbsup: . Prozatím sosáme, ale ještě to necháme radši dojed do konce a uvidíme. Vypadá to však slibně a zatím žádný crash :) . Jak se to dostahuje dám vědět, ale chvíli to potrvá jde to pomalu.

Teochi
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 05 čer 2009 10:29

Re: Podezření na vir - problém se stahováním

#13 Příspěvek od Teochi »

Tak staženo, vše v pořádku! Mám vyřídit od Verči velké díky a já samozřejmě také děkuji za zabití monstra, jenž sužoval PC mojí přítelkyně :idea: . Skvělá práce a jak se říká: "Mrtvý vir, dobrý vir."

Zamčeno