Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Virus v services.exe a Desktop.ini

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
madeat
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 čer 2007 23:13

Virus v services.exe a Desktop.ini

#1 Příspěvek od madeat »

Dobrý den, před pár dny mi antivir začal vyhazovat hlášku o infiltraci Win32/Sirefef.EZ v Desktop.ini a totéž v services.exe
Soubory nelze smazat ani léčit. Žádné změny v notebooku jsem zatím nezaznamenala, ale chtěla bych poprosit o radu, jak se virů zbavit :)
Přikládám log z RSIT.
Předem děkuji za pomoc.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Slamova at 2012-11-02 13:32:20
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 205 GB (67%) free of 305 GB
Total RAM: 3000 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:32:23, on 2.11.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Slamova\Downloads\RSIT.exe
C:\Users\Slamova\Downloads\RSIT.exe
C:\Program Files\trend micro\Slamova.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Slamova\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: GamePark klient 2.lnk = C:\Program Files\GamePark2\gpcl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 7356 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1431964540-3257949587-1746594197-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1431964540-3257949587-1746594197-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Slamova\AppData\Roaming\Mozilla\Firefox\Profiles\dh6ydvj3.default

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 3080264]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-07-26 2569616]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-09-04 767312]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-10-24 4762496]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-07-13 17418928]
"Facebook Update"=C:\Users\Slamova\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-17 138096]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
GamePark klient 2.lnk - C:\Program Files\GamePark2\gpcl.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2011-05-04 551296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-07-19 113024]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"VIDC.FFDS"=C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-11-02 13:27:21 ----D---- C:\Program Files\trend micro
2012-11-02 13:27:20 ----D---- C:\rsit
2012-11-02 13:13:34 ----ASH---- C:\hiberfil.sys
2012-11-02 13:08:02 ----A---- C:\services.exe
2012-11-02 13:03:38 ----A---- C:\Windows\ntbtlog.txt
2012-10-27 20:56:14 ----D---- C:\Program Files\Mozilla Firefox
2012-10-23 21:43:25 ----D---- C:\ProgramData\vsosdk
2012-10-23 20:49:39 ----D---- C:\Users\Slamova\AppData\Roaming\Vso
2012-10-23 20:49:20 ----A---- C:\Windows\system32\sipr3260.dll
2012-10-23 20:49:20 ----A---- C:\Windows\system32\Pncrt.dll
2012-10-23 20:49:20 ----A---- C:\Windows\system32\drv43260.dll
2012-10-23 20:49:20 ----A---- C:\Windows\system32\drv33260.dll
2012-10-23 20:49:20 ----A---- C:\Windows\system32\drv23260.dll
2012-10-23 20:49:20 ----A---- C:\Windows\system32\cook3260.dll
2012-10-23 20:49:19 ----A---- C:\Windows\system32\wvc1dmod.dll
2012-10-23 20:49:19 ----A---- C:\Windows\system32\vp7vfw.dll
2012-10-23 20:49:17 ----D---- C:\Program Files\VSO
2012-10-10 18:45:04 ----D---- C:\ProgramData\Advanced Chemistry Development
2012-10-10 18:43:40 ----D---- C:\Program Files\ACDFREE12
2012-10-10 18:43:19 ----D---- C:\Users\Slamova\AppData\Roaming\Advanced Chemistry Development
2012-10-10 10:19:22 ----A---- C:\Windows\system32\cryptsvc.dll
2012-10-10 10:19:22 ----A---- C:\Windows\system32\cryptnet.dll
2012-10-10 10:19:22 ----A---- C:\Windows\system32\crypt32.dll
2012-10-10 10:19:14 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-10-10 10:19:13 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-10-10 10:19:05 ----A---- C:\Windows\system32\tzres.dll
2012-10-10 10:18:59 ----A---- C:\Windows\system32\wintrust.dll

======List of files/folders modified in the last 1 month======

2012-11-02 13:32:19 ----D---- C:\Windows\Temp
2012-11-02 13:27:21 ----RD---- C:\Program Files
2012-11-02 13:27:19 ----D---- C:\Windows\Prefetch
2012-11-02 13:20:35 ----D---- C:\Windows\System32
2012-11-02 13:20:35 ----D---- C:\Windows\inf
2012-11-02 13:20:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-11-02 13:15:11 ----D---- C:\Users\Slamova\AppData\Roaming\Skype
2012-11-02 13:13:33 ----D---- C:\Windows\system32\drivers
2012-11-02 13:03:38 ----D---- C:\Windows
2012-11-02 07:07:02 ----SHD---- C:\System Volume Information
2012-11-02 00:22:45 ----D---- C:\Users\Slamova\AppData\Roaming\vlc
2012-10-28 18:04:28 ----A---- C:\Windows\system32\PnkBstrB.exe
2012-10-28 10:53:55 ----D---- C:\Program Files\GamePark2
2012-10-28 09:40:29 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-10-26 09:38:47 ----D---- C:\Windows\system32\catroot2
2012-10-25 18:21:47 ----SHD---- C:\Windows\Installer
2012-10-25 07:55:31 ----D---- C:\Windows\SoftwareDistribution
2012-10-25 07:55:31 ----D---- C:\Windows\Debug
2012-10-24 15:11:34 ----RSD---- C:\Windows\Media
2012-10-24 13:01:56 ----D---- C:\Program Files\SUPERAntiSpyware
2012-10-23 21:43:25 ----HD---- C:\ProgramData
2012-10-16 00:05:41 ----D---- C:\Users\Slamova\AppData\Roaming\SoftGrid Client
2012-10-12 06:15:41 ----D---- C:\Windows\rescache
2012-10-12 06:10:48 ----D---- C:\Windows\winsxs
2012-10-11 08:48:05 ----D---- C:\Windows\system32\catroot
2012-10-11 08:45:33 ----D---- C:\Windows\system32\cs-CZ
2012-10-11 07:04:59 ----D---- C:\ProgramData\Microsoft Help
2012-10-11 07:01:40 ----A---- C:\Windows\system32\mrt.exe
2012-10-08 20:57:06 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-10-03 12:13:07 ----SD---- C:\Users\Slamova\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 50624]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 33656]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2011-08-04 147480]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-11-02 983552]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-27 909824]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 579944]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 194408]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 21864]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 19304]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-02-21 299008]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2009-04-11 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2012-10-24 116608]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2011-09-22 974944]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2008-04-30 815104]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-04-17 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2012-10-28 214520]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2008-04-30 466944]
R2 sftlist;Application Virtualization Client; C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-07 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-08 250808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-07 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-27 115168]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Virus v services.exe a Desktop.ini

#2 Příspěvek od stell »

Zdravim
Takze mas tam pravdepodobne ZeroAccess, uvidime.
1:Spust TDSSKILLER podla tohto navodu.
http://www.viruskasino.com/2010/12/odst ... kitov.html
log.txt vloz sem
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

madeat
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 čer 2007 23:13

Re: Virus v services.exe a Desktop.ini

#3 Příspěvek od madeat »

Našlo to nějaký ten zeroacess, ponechala jsem možnost Cure, eset hlásil uložení do karantény. Log přikládám.

14:17:10.0269 3728 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
14:17:10.0379 3728 ============================================================
14:17:10.0379 3728 Current date / time: 2012/11/02 14:17:10.0379
14:17:10.0379 3728 SystemInfo:
14:17:10.0379 3728
14:17:10.0379 3728 OS Version: 6.0.6002 ServicePack: 2.0
14:17:10.0379 3728 Product type: Workstation
14:17:10.0379 3728 ComputerName: SLAMOVA-PC
14:17:10.0380 3728 UserName: Slamova
14:17:10.0380 3728 Windows directory: C:\Windows
14:17:10.0380 3728 System windows directory: C:\Windows
14:17:10.0380 3728 Processor architecture: Intel x86
14:17:10.0380 3728 Number of processors: 2
14:17:10.0380 3728 Page size: 0x1000
14:17:10.0380 3728 Boot type: Normal boot
14:17:10.0380 3728 ============================================================
14:17:11.0988 3728 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
14:17:11.0998 3728 ============================================================
14:17:11.0999 3728 \Device\Harddisk0\DR0:
14:17:11.0999 3728 MBR partitions:
14:17:11.0999 3728 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x2542D800
14:17:11.0999 3728 ============================================================
14:17:12.0024 3728 C: <-> \Device\Harddisk0\DR0\Partition1
14:17:12.0024 3728 ============================================================
14:17:12.0024 3728 Initialize success
14:17:12.0024 3728 ============================================================
14:17:15.0192 3732 ============================================================
14:17:15.0192 3732 Scan started
14:17:15.0192 3732 Mode: Manual;
14:17:15.0192 3732 ============================================================
14:17:16.0655 3732 ================ Scan system memory ========================
14:17:16.0655 3732 System memory - ok
14:17:16.0656 3732 ================ Scan services =============================
14:17:16.0975 3732 [ 01E81C84AD1D0ACC61CF3CFD06632210 ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
14:17:16.0977 3732 !SASCORE - ok
14:17:17.0348 3732 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
14:17:17.0352 3732 ACPI - ok
14:17:17.0412 3732 [ 11A52CF7B265631DEEB24C6149309EFF ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
14:17:17.0414 3732 AdobeARMservice - ok
14:17:17.0497 3732 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
14:17:17.0500 3732 AdobeFlashPlayerUpdateSvc - ok
14:17:17.0546 3732 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
14:17:17.0553 3732 adp94xx - ok
14:17:17.0601 3732 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
14:17:17.0606 3732 adpahci - ok
14:17:17.0629 3732 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
14:17:17.0631 3732 adpu160m - ok
14:17:17.0748 3732 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
14:17:17.0751 3732 adpu320 - ok
14:17:17.0811 3732 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
14:17:17.0812 3732 AeLookupSvc - ok
14:17:17.0980 3732 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
14:17:17.0982 3732 AFD - ok
14:17:18.0054 3732 [ 5D97943C128ED756D1B0A08302C1B1F8 ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys
14:17:18.0076 3732 AgereSoftModem - ok
14:17:18.0117 3732 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
14:17:18.0118 3732 agp440 - ok
14:17:18.0160 3732 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
14:17:18.0161 3732 aic78xx - ok
14:17:18.0176 3732 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
14:17:18.0177 3732 ALG - ok
14:17:18.0195 3732 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
14:17:18.0195 3732 aliide - ok
14:17:18.0215 3732 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
14:17:18.0216 3732 amdagp - ok
14:17:18.0232 3732 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
14:17:18.0232 3732 amdide - ok
14:17:18.0253 3732 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
14:17:18.0254 3732 AmdK7 - ok
14:17:18.0274 3732 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
14:17:18.0275 3732 AmdK8 - ok
14:17:18.0334 3732 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
14:17:18.0336 3732 Appinfo - ok
14:17:18.0357 3732 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
14:17:18.0359 3732 arc - ok
14:17:18.0405 3732 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
14:17:18.0406 3732 arcsas - ok
14:17:18.0447 3732 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
14:17:18.0447 3732 AsyncMac - ok
14:17:18.0469 3732 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
14:17:18.0469 3732 atapi - ok
14:17:18.0557 3732 [ 600EFE56F37ADBD65A0FB076B50D1B8D ] athr C:\Windows\system32\DRIVERS\athr.sys
14:17:18.0579 3732 athr - ok
14:17:18.0646 3732 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:17:18.0652 3732 AudioEndpointBuilder - ok
14:17:18.0669 3732 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
14:17:18.0672 3732 Audiosrv - ok
14:17:18.0727 3732 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
14:17:18.0728 3732 Beep - ok
14:17:18.0797 3732 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
14:17:18.0805 3732 BFE - ok
14:17:18.0820 3732 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
14:17:18.0821 3732 blbdrive - ok
14:17:18.0873 3732 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
14:17:18.0874 3732 bowser - ok
14:17:18.0923 3732 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
14:17:18.0924 3732 BrFiltLo - ok
14:17:18.0939 3732 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
14:17:18.0939 3732 BrFiltUp - ok
14:17:18.0963 3732 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
14:17:18.0965 3732 Browser - ok
14:17:18.0982 3732 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
14:17:18.0983 3732 Brserid - ok
14:17:18.0999 3732 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
14:17:19.0000 3732 BrSerWdm - ok
14:17:19.0008 3732 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
14:17:19.0009 3732 BrUsbMdm - ok
14:17:19.0042 3732 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
14:17:19.0043 3732 BrUsbSer - ok
14:17:19.0109 3732 [ 6D39C954799B63BA866910234CF7D726 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
14:17:19.0110 3732 BthEnum - ok
14:17:19.0169 3732 [ 9A966A8E86D1771911AE34A20D11BFF3 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
14:17:19.0171 3732 BTHMODEM - ok
14:17:19.0203 3732 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
14:17:19.0205 3732 BthPan - ok
14:17:19.0254 3732 [ 611FF3F2F095C8D4A6D4CFD9DCC09793 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
14:17:19.0265 3732 BTHPORT - ok
14:17:19.0295 3732 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll
14:17:19.0297 3732 BthServ - ok
14:17:19.0325 3732 [ D330803EAB2A15CAEC7F011F1D4CB30E ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
14:17:19.0326 3732 BTHUSB - ok
14:17:19.0414 3732 [ 3EA1A20DC0CA1AD23E7AA8C37A91BCD1 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
14:17:19.0416 3732 btwaudio - ok
14:17:19.0487 3732 [ 195872E48A7FB01F8BC9B800F70F4054 ] btwavdt C:\Windows\system32\drivers\btwavdt.sys
14:17:19.0488 3732 btwavdt - ok
14:17:19.0549 3732 [ 0724E7D6C9B6A289EDDDA33FA8176E80 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
14:17:19.0550 3732 btwrchid - ok
14:17:19.0602 3732 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
14:17:19.0603 3732 cdfs - ok
14:17:19.0658 3732 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
14:17:19.0659 3732 cdrom - ok
14:17:19.0706 3732 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
14:17:19.0710 3732 CertPropSvc - ok
14:17:19.0725 3732 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
14:17:19.0726 3732 circlass - ok
14:17:19.0743 3732 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
14:17:19.0748 3732 CLFS - ok
14:17:19.0809 3732 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:17:19.0813 3732 clr_optimization_v2.0.50727_32 - ok
14:17:19.0919 3732 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:17:20.0017 3732 clr_optimization_v4.0.30319_32 - ok
14:17:20.0190 3732 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
14:17:20.0191 3732 CmBatt - ok
14:17:20.0317 3732 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
14:17:20.0318 3732 cmdide - ok
14:17:20.0339 3732 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
14:17:20.0340 3732 Compbatt - ok
14:17:20.0364 3732 COMSysApp - ok
14:17:20.0375 3732 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
14:17:20.0376 3732 crcdisk - ok
14:17:20.0407 3732 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
14:17:20.0408 3732 Crusoe - ok
14:17:20.0471 3732 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
14:17:20.0473 3732 CryptSvc - ok
14:17:20.0695 3732 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
14:17:20.0702 3732 cvhsvc - ok
14:17:20.0970 3732 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
14:17:20.0982 3732 DcomLaunch - ok
14:17:21.0001 3732 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
14:17:21.0002 3732 DfsC - ok
14:17:21.0206 3732 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
14:17:21.0250 3732 DFSR - ok
14:17:21.0308 3732 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
14:17:21.0312 3732 Dhcp - ok
14:17:21.0331 3732 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
14:17:21.0332 3732 disk - ok
14:17:21.0361 3732 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
14:17:21.0363 3732 Dnscache - ok
14:17:21.0382 3732 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
14:17:21.0385 3732 dot3svc - ok
14:17:21.0425 3732 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
14:17:21.0428 3732 DPS - ok
14:17:21.0499 3732 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
14:17:21.0500 3732 drmkaud - ok
14:17:21.0554 3732 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
14:17:21.0560 3732 DXGKrnl - ok
14:17:21.0640 3732 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
14:17:21.0641 3732 E1G60 - ok
14:17:21.0681 3732 [ 04238864710460C5682E260207D06192 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
14:17:21.0684 3732 eamonm - ok
14:17:21.0725 3732 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
14:17:21.0728 3732 EapHost - ok
14:17:21.0762 3732 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
14:17:21.0764 3732 Ecache - ok
14:17:21.0830 3732 [ DEFF87F04AB5F6DD5EDF2B80853BBE10 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
14:17:21.0831 3732 ehdrv - ok
14:17:21.0887 3732 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
14:17:21.0891 3732 ehRecvr - ok
14:17:21.0915 3732 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
14:17:21.0916 3732 ehSched - ok
14:17:21.0933 3732 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
14:17:21.0935 3732 ehstart - ok
14:17:22.0040 3732 [ C7BB95CF9631AA401E4ADED1648F6AF7 ] ekrn C:\Program Files\ESET\ESET Smart Security\ekrn.exe
14:17:22.0049 3732 ekrn - ok
14:17:22.0105 3732 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
14:17:22.0111 3732 elxstor - ok
14:17:22.0163 3732 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
14:17:22.0175 3732 EMDMgmt - ok
14:17:22.0246 3732 [ 5BA193CA0AE31209AAA39939CE6736B2 ] epfw C:\Windows\system32\DRIVERS\epfw.sys
14:17:22.0248 3732 epfw - ok
14:17:22.0292 3732 [ 9CEFD59C8E5EBFB48165AEF54617F539 ] EpfwLWF C:\Windows\system32\DRIVERS\EpfwLWF.sys
14:17:22.0293 3732 EpfwLWF - ok
14:17:22.0349 3732 [ 7144A06AC105A2A7302944602E415EC1 ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
14:17:22.0350 3732 epfwwfp - ok
14:17:22.0368 3732 [ A81AB23EDDB4693612014D87367D014C ] ErrDev C:\Windows\system32\drivers\errdev.sys
14:17:22.0370 3732 ErrDev - ok
14:17:22.0403 3732 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
14:17:22.0408 3732 EventSystem - ok
14:17:22.0462 3732 [ 306AC856622864C761CBDB5E816BB9D8 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
14:17:22.0469 3732 EvtEng - ok
14:17:22.0499 3732 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
14:17:22.0501 3732 exfat - ok
14:17:22.0515 3732 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
14:17:22.0520 3732 fastfat - ok
14:17:22.0558 3732 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
14:17:22.0559 3732 fdc - ok
14:17:22.0590 3732 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
14:17:22.0591 3732 fdPHost - ok
14:17:22.0610 3732 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
14:17:22.0612 3732 FDResPub - ok
14:17:22.0651 3732 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
14:17:22.0652 3732 FileInfo - ok
14:17:22.0681 3732 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
14:17:22.0682 3732 Filetrace - ok
14:17:22.0709 3732 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
14:17:22.0709 3732 flpydisk - ok
14:17:22.0734 3732 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
14:17:22.0739 3732 FltMgr - ok
14:17:22.0835 3732 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
14:17:22.0842 3732 FontCache - ok
14:17:22.0895 3732 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
14:17:22.0896 3732 FontCache3.0.0.0 - ok
14:17:22.0924 3732 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
14:17:22.0925 3732 Fs_Rec - ok
14:17:22.0944 3732 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
14:17:22.0945 3732 gagp30kx - ok
14:17:22.0985 3732 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
14:17:22.0996 3732 gpsvc - ok
14:17:23.0067 3732 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
14:17:23.0068 3732 gupdate - ok
14:17:23.0075 3732 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
14:17:23.0077 3732 gupdatem - ok
14:17:23.0138 3732 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:17:23.0142 3732 HdAudAddService - ok
14:17:23.0168 3732 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
14:17:23.0179 3732 HDAudBus - ok
14:17:23.0239 3732 [ FCB3F4BE408F72C1BD81BCABA87FC22F ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
14:17:23.0240 3732 HidBth - ok
14:17:23.0270 3732 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
14:17:23.0271 3732 HidIr - ok
14:17:23.0311 3732 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
14:17:23.0313 3732 hidserv - ok
14:17:23.0329 3732 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
14:17:23.0329 3732 HidUsb - ok
14:17:23.0365 3732 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
14:17:23.0368 3732 hkmsvc - ok
14:17:23.0385 3732 [ 7EBEC5EB56B90ED65A8BBD91464E5CFB ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
14:17:23.0386 3732 HpCISSs - ok
14:17:23.0436 3732 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
14:17:23.0444 3732 HTTP - ok
14:17:23.0486 3732 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
14:17:23.0487 3732 i2omp - ok
14:17:23.0545 3732 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
14:17:23.0546 3732 i8042prt - ok
14:17:23.0573 3732 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
14:17:23.0577 3732 iaStorV - ok
14:17:23.0630 3732 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:17:23.0651 3732 idsvc - ok
14:17:23.0957 3732 [ DCE0B53570703CCE580D066F89EF58CD ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
14:17:24.0144 3732 igfx - ok
14:17:24.0160 3732 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
14:17:24.0161 3732 iirsp - ok
14:17:24.0239 3732 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
14:17:24.0248 3732 IKEEXT - ok
14:17:24.0304 3732 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
14:17:24.0305 3732 intelide - ok
14:17:24.0350 3732 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
14:17:24.0351 3732 intelppm - ok
14:17:24.0367 3732 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
14:17:24.0369 3732 IPBusEnum - ok
14:17:24.0399 3732 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:17:24.0400 3732 IpFilterDriver - ok
14:17:24.0410 3732 IpInIp - ok
14:17:24.0455 3732 [ 4B9C0F4D4A3ACC535F9771039ECD6365 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
14:17:24.0456 3732 IPMIDRV - ok
14:17:24.0484 3732 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
14:17:24.0486 3732 IPNAT - ok
14:17:24.0503 3732 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
14:17:24.0504 3732 IRENUM - ok
14:17:24.0528 3732 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
14:17:24.0530 3732 isapnp - ok
14:17:24.0566 3732 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
14:17:24.0569 3732 iScsiPrt - ok
14:17:24.0589 3732 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
14:17:24.0591 3732 iteatapi - ok
14:17:24.0615 3732 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
14:17:24.0616 3732 iteraid - ok
14:17:24.0635 3732 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
14:17:24.0636 3732 kbdclass - ok
14:17:24.0649 3732 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
14:17:24.0651 3732 kbdhid - ok
14:17:24.0692 3732 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
14:17:24.0695 3732 KeyIso - ok
14:17:24.0753 3732 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
14:17:24.0764 3732 KSecDD - ok
14:17:24.0831 3732 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
14:17:24.0838 3732 KtmRm - ok
14:17:24.0890 3732 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll
14:17:24.0896 3732 LanmanServer - ok
14:17:24.0945 3732 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:17:24.0952 3732 LanmanWorkstation - ok
14:17:25.0007 3732 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
14:17:25.0008 3732 lltdio - ok
14:17:25.0047 3732 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
14:17:25.0052 3732 lltdsvc - ok
14:17:25.0068 3732 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
14:17:25.0071 3732 lmhosts - ok
14:17:25.0097 3732 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
14:17:25.0098 3732 LSI_FC - ok
14:17:25.0121 3732 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
14:17:25.0123 3732 LSI_SAS - ok
14:17:25.0183 3732 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
14:17:25.0184 3732 LSI_SCSI - ok
14:17:25.0200 3732 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
14:17:25.0201 3732 luafv - ok
14:17:25.0256 3732 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
14:17:25.0259 3732 Mcx2Svc - ok
14:17:25.0276 3732 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
14:17:25.0277 3732 megasas - ok
14:17:25.0378 3732 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
14:17:25.0384 3732 MegaSR - ok
14:17:25.0505 3732 Microsoft SharePoint Workspace Audit Service - ok
14:17:25.0545 3732 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
14:17:25.0548 3732 MMCSS - ok
14:17:25.0560 3732 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
14:17:25.0561 3732 Modem - ok
14:17:25.0583 3732 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
14:17:25.0584 3732 monitor - ok
14:17:25.0595 3732 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
14:17:25.0596 3732 mouclass - ok
14:17:25.0608 3732 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
14:17:25.0609 3732 mouhid - ok
14:17:25.0630 3732 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
14:17:25.0631 3732 MountMgr - ok
14:17:25.0720 3732 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
14:17:25.0722 3732 MozillaMaintenance - ok
14:17:25.0744 3732 [ 5DA347912FD3AF24D7BFB3DE519D4BD0 ] mpio C:\Windows\system32\drivers\mpio.sys
14:17:25.0745 3732 mpio - ok
14:17:25.0763 3732 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
14:17:25.0765 3732 mpsdrv - ok
14:17:25.0806 3732 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
14:17:25.0816 3732 MpsSvc - ok
14:17:25.0828 3732 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
14:17:25.0829 3732 Mraid35x - ok
14:17:25.0849 3732 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
14:17:25.0851 3732 MRxDAV - ok
14:17:25.0879 3732 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
14:17:25.0882 3732 mrxsmb - ok
14:17:25.0892 3732 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:17:25.0895 3732 mrxsmb10 - ok
14:17:25.0904 3732 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:17:25.0906 3732 mrxsmb20 - ok
14:17:25.0967 3732 [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci C:\Windows\system32\drivers\msahci.sys
14:17:25.0968 3732 msahci - ok
14:17:25.0990 3732 [ 2C563AEF15B8D0014C36C5F27742AC7B ] msdsm C:\Windows\system32\drivers\msdsm.sys
14:17:25.0992 3732 msdsm - ok
14:17:26.0014 3732 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
14:17:26.0017 3732 MSDTC - ok
14:17:26.0031 3732 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
14:17:26.0032 3732 Msfs - ok
14:17:26.0083 3732 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
14:17:26.0084 3732 msisadrv - ok
14:17:26.0116 3732 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
14:17:26.0120 3732 MSiSCSI - ok
14:17:26.0126 3732 msiserver - ok
14:17:26.0161 3732 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
14:17:26.0162 3732 MSKSSRV - ok
14:17:26.0212 3732 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
14:17:26.0213 3732 MSPCLOCK - ok
14:17:26.0232 3732 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
14:17:26.0232 3732 MSPQM - ok
14:17:26.0258 3732 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
14:17:26.0260 3732 MsRPC - ok
14:17:26.0281 3732 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
14:17:26.0282 3732 mssmbios - ok
14:17:26.0305 3732 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
14:17:26.0306 3732 MSTEE - ok
14:17:26.0330 3732 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
14:17:26.0331 3732 Mup - ok
14:17:26.0367 3732 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
14:17:26.0376 3732 napagent - ok
14:17:26.0419 3732 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
14:17:26.0421 3732 NativeWifiP - ok
14:17:26.0435 3732 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
14:17:26.0446 3732 NDIS - ok
14:17:26.0463 3732 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
14:17:26.0464 3732 NdisTapi - ok
14:17:26.0483 3732 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
14:17:26.0483 3732 Ndisuio - ok
14:17:26.0498 3732 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
14:17:26.0500 3732 NdisWan - ok
14:17:26.0520 3732 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
14:17:26.0522 3732 NDProxy - ok
14:17:26.0541 3732 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
14:17:26.0542 3732 NetBIOS - ok
14:17:26.0566 3732 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
14:17:26.0570 3732 netbt - ok
14:17:26.0580 3732 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
14:17:26.0583 3732 Netlogon - ok
14:17:26.0618 3732 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
14:17:26.0624 3732 Netman - ok
14:17:26.0649 3732 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
14:17:26.0657 3732 netprofm - ok
14:17:26.0682 3732 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:17:26.0686 3732 NetTcpPortSharing - ok
14:17:26.0700 3732 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
14:17:26.0701 3732 nfrd960 - ok
14:17:26.0726 3732 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
14:17:26.0733 3732 NlaSvc - ok
14:17:26.0740 3732 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
14:17:26.0742 3732 Npfs - ok
14:17:26.0796 3732 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
14:17:26.0800 3732 nsi - ok
14:17:26.0817 3732 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
14:17:26.0818 3732 nsiproxy - ok
14:17:26.0869 3732 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
14:17:26.0901 3732 Ntfs - ok
14:17:26.0916 3732 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
14:17:26.0917 3732 ntrigdigi - ok
14:17:26.0926 3732 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
14:17:26.0928 3732 Null - ok
14:17:26.0953 3732 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
14:17:26.0955 3732 nvraid - ok
14:17:26.0970 3732 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
14:17:26.0972 3732 nvstor - ok
14:17:26.0986 3732 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
14:17:26.0989 3732 nv_agp - ok
14:17:26.0996 3732 NwlnkFlt - ok
14:17:27.0005 3732 NwlnkFwd - ok
14:17:27.0061 3732 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
14:17:27.0063 3732 ohci1394 - ok
14:17:27.0124 3732 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:17:27.0126 3732 ose - ok
14:17:27.0254 3732 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
14:17:27.0295 3732 osppsvc - ok
14:17:27.0359 3732 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
14:17:27.0372 3732 p2pimsvc - ok
14:17:27.0415 3732 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
14:17:27.0422 3732 p2psvc - ok
14:17:27.0453 3732 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
14:17:27.0454 3732 Parport - ok
14:17:27.0493 3732 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
14:17:27.0494 3732 partmgr - ok
14:17:27.0516 3732 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
14:17:27.0516 3732 Parvdm - ok
14:17:27.0534 3732 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
14:17:27.0538 3732 PcaSvc - ok
14:17:27.0552 3732 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
14:17:27.0554 3732 pci - ok
14:17:27.0567 3732 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys
14:17:27.0568 3732 pciide - ok
14:17:27.0587 3732 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
14:17:27.0589 3732 pcmcia - ok
14:17:27.0653 3732 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
14:17:27.0674 3732 PEAUTH - ok
14:17:27.0784 3732 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
14:17:27.0816 3732 pla - ok
14:17:27.0844 3732 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
14:17:27.0849 3732 PlugPlay - ok
14:17:27.0917 3732 [ A1DD33D16F277CE34124EE52AB2C0F14 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
14:17:27.0920 3732 PnkBstrA - ok
14:17:27.0984 3732 [ 7C01817ADF3207FB65A4B56E6D5AD833 ] PnkBstrB C:\Windows\system32\PnkBstrB.exe
14:17:27.0988 3732 PnkBstrB - ok
14:17:28.0014 3732 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
14:17:28.0021 3732 PNRPAutoReg - ok
14:17:28.0049 3732 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
14:17:28.0055 3732 PNRPsvc - ok
14:17:28.0087 3732 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
14:17:28.0091 3732 PolicyAgent - ok
14:17:28.0131 3732 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
14:17:28.0132 3732 PptpMiniport - ok
14:17:28.0157 3732 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
14:17:28.0159 3732 Processor - ok
14:17:28.0186 3732 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
14:17:28.0192 3732 ProfSvc - ok
14:17:28.0202 3732 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
14:17:28.0205 3732 ProtectedStorage - ok
14:17:28.0218 3732 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
14:17:28.0219 3732 PSched - ok
14:17:28.0295 3732 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
14:17:28.0326 3732 ql2300 - ok
14:17:28.0348 3732 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
14:17:28.0350 3732 ql40xx - ok
14:17:28.0369 3732 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
14:17:28.0376 3732 QWAVE - ok
14:17:28.0383 3732 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
14:17:28.0385 3732 QWAVEdrv - ok
14:17:28.0400 3732 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
14:17:28.0401 3732 RasAcd - ok
14:17:28.0420 3732 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
14:17:28.0424 3732 RasAuto - ok
14:17:28.0441 3732 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
14:17:28.0443 3732 Rasl2tp - ok
14:17:28.0465 3732 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
14:17:28.0472 3732 RasMan - ok
14:17:28.0485 3732 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
14:17:28.0486 3732 RasPppoe - ok
14:17:28.0522 3732 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
14:17:28.0524 3732 RasSstp - ok
14:17:28.0540 3732 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
14:17:28.0544 3732 rdbss - ok
14:17:28.0561 3732 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
14:17:28.0562 3732 RDPCDD - ok
14:17:28.0587 3732 [ 943B18305EAE3935598A9B4A3D560B4C ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
14:17:28.0593 3732 rdpdr - ok
14:17:28.0599 3732 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
14:17:28.0600 3732 RDPENCDD - ok
14:17:28.0660 3732 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
14:17:28.0663 3732 RDPWD - ok
14:17:28.0747 3732 [ B33C88DF3588ACF250B87A004526C31A ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
14:17:28.0753 3732 RegSrvc - ok
14:17:28.0788 3732 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
14:17:28.0790 3732 RemoteAccess - ok
14:17:28.0816 3732 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
14:17:28.0820 3732 RemoteRegistry - ok
14:17:28.0854 3732 [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
14:17:28.0855 3732 RFCOMM - ok
14:17:28.0882 3732 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
14:17:28.0884 3732 RpcLocator - ok
14:17:28.0914 3732 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
14:17:28.0920 3732 RpcSs - ok
14:17:28.0939 3732 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
14:17:28.0940 3732 rspndr - ok
14:17:28.0948 3732 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
14:17:28.0950 3732 SamSs - ok
14:17:29.0016 3732 [ 39763504067962108505BFF25F024345 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
14:17:29.0017 3732 SASDIFSV - ok
14:17:29.0062 3732 [ 77B9FC20084B48408AD3E87570EB4A85 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
14:17:29.0063 3732 SASKUTIL - ok
14:17:29.0078 3732 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
14:17:29.0079 3732 sbp2port - ok
14:17:29.0130 3732 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
14:17:29.0133 3732 SCardSvr - ok
14:17:29.0169 3732 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
14:17:29.0180 3732 Schedule - ok
14:17:29.0238 3732 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
14:17:29.0239 3732 SCPolicySvc - ok
14:17:29.0262 3732 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
14:17:29.0266 3732 SDRSVC - ok
14:17:29.0277 3732 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
14:17:29.0279 3732 secdrv - ok
14:17:29.0291 3732 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
14:17:29.0295 3732 seclogon - ok
14:17:29.0308 3732 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
14:17:29.0312 3732 SENS - ok
14:17:29.0331 3732 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
14:17:29.0332 3732 Serenum - ok
14:17:29.0349 3732 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
14:17:29.0351 3732 Serial - ok
14:17:29.0374 3732 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
14:17:29.0375 3732 sermouse - ok
14:17:29.0417 3732 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
14:17:29.0421 3732 SessionEnv - ok
14:17:29.0438 3732 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
14:17:29.0439 3732 sffdisk - ok
14:17:29.0452 3732 [ E5EAFE85815BD89095FEF3144A09AB68 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
14:17:29.0453 3732 sffp_mmc - ok
14:17:29.0464 3732 [ 9F66A46C55D6F1CCABC79BB7AFCCC545 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
14:17:29.0465 3732 sffp_sd - ok
14:17:29.0483 3732 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
14:17:29.0484 3732 sfloppy - ok
14:17:29.0538 3732 [ D9B734638DD8DBA9D59AAD3189CD0FAD ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
14:17:29.0550 3732 Sftfs - ok
14:17:29.0614 3732 [ CB73BC422C07FB611F194DA18D1E7F36 ] sftlist C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
14:17:29.0620 3732 sftlist - ok
14:17:29.0668 3732 [ 2F61BD46C0BFF4EB36E1E359CA17BFC5 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
14:17:29.0672 3732 Sftplay - ok
14:17:29.0689 3732 [ 518BAC0179F94304F422696B47C0EC12 ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
14:17:29.0690 3732 Sftredir - ok
14:17:29.0703 3732 [ 747325236D88B3F05FFD27FF9EC711C5 ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
14:17:29.0705 3732 Sftvol - ok
14:17:29.0714 3732 [ A5812F0281CA5081BF696626F9BF324D ] sftvsa C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
14:17:29.0717 3732 sftvsa - ok
14:17:29.0826 3732 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
14:17:29.0833 3732 SharedAccess - ok
14:17:29.0883 3732 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:17:29.0889 3732 ShellHWDetection - ok
14:17:29.0921 3732 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
14:17:29.0922 3732 sisagp - ok
14:17:29.0941 3732 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
14:17:29.0943 3732 SiSRaid2 - ok
14:17:29.0963 3732 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
14:17:29.0965 3732 SiSRaid4 - ok
14:17:30.0047 3732 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
14:17:30.0049 3732 SkypeUpdate - ok
14:17:30.0148 3732 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
14:17:30.0226 3732 slsvc - ok
14:17:30.0276 3732 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
14:17:30.0280 3732 SLUINotify - ok
14:17:30.0301 3732 [ 367459DC8A3C0B883E643606B983D49C ] Smb C:\Windows\system32\DRIVERS\smb.sys
14:17:30.0302 3732 Suspicious file (Forged): C:\Windows\system32\DRIVERS\smb.sys. Real md5: 367459DC8A3C0B883E643606B983D49C, Fake md5: 7B75299A4D201D6A6533603D6914AB04
14:17:30.0302 3732 Smb ( Virus.Win32.ZAccess.k ) - infected
14:17:30.0302 3732 Smb - detected Virus.Win32.ZAccess.k (0)
14:17:30.0324 3732 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
14:17:30.0327 3732 SNMPTRAP - ok
14:17:30.0345 3732 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
14:17:30.0346 3732 spldr - ok
14:17:30.0398 3732 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
14:17:30.0401 3732 Spooler - ok
14:17:30.0455 3732 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
14:17:30.0461 3732 srv - ok
14:17:30.0483 3732 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
14:17:30.0487 3732 srv2 - ok
14:17:30.0495 3732 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
14:17:30.0496 3732 srvnet - ok
14:17:30.0522 3732 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
14:17:30.0529 3732 SSDPSRV - ok
14:17:30.0571 3732 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
14:17:30.0575 3732 SstpSvc - ok
14:17:30.0630 3732 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
14:17:30.0641 3732 stisvc - ok
14:17:30.0661 3732 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
14:17:30.0661 3732 swenum - ok
14:17:30.0682 3732 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
14:17:30.0691 3732 swprv - ok
14:17:30.0705 3732 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
14:17:30.0706 3732 Symc8xx - ok
14:17:30.0717 3732 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
14:17:30.0719 3732 Sym_hi - ok
14:17:30.0738 3732 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
14:17:30.0739 3732 Sym_u3 - ok
14:17:30.0775 3732 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
14:17:30.0795 3732 SysMain - ok
14:17:30.0862 3732 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
14:17:30.0867 3732 TabletInputService - ok
14:17:30.0886 3732 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
14:17:30.0892 3732 TapiSrv - ok
14:17:30.0904 3732 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
14:17:30.0908 3732 TBS - ok
14:17:30.0986 3732 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
14:17:31.0007 3732 Tcpip - ok
14:17:31.0038 3732 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
14:17:31.0047 3732 Tcpip6 - ok
14:17:31.0094 3732 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
14:17:31.0095 3732 tcpipreg - ok
14:17:31.0140 3732 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
14:17:31.0141 3732 TDPIPE - ok
14:17:31.0164 3732 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
14:17:31.0166 3732 TDTCP - ok
14:17:31.0191 3732 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
14:17:31.0192 3732 tdx - ok
14:17:31.0206 3732 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
14:17:31.0208 3732 TermDD - ok
14:17:31.0234 3732 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
14:17:31.0247 3732 TermService - ok
14:17:31.0272 3732 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
14:17:31.0278 3732 Themes - ok
14:17:31.0289 3732 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
14:17:31.0293 3732 THREADORDER - ok
14:17:31.0315 3732 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
14:17:31.0321 3732 TrkWks - ok
14:17:31.0377 3732 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:17:31.0378 3732 TrustedInstaller - ok
14:17:31.0405 3732 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
14:17:31.0407 3732 tssecsrv - ok
14:17:31.0439 3732 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
14:17:31.0440 3732 tunmp - ok
14:17:31.0505 3732 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
14:17:31.0506 3732 tunnel - ok
14:17:31.0521 3732 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
14:17:31.0522 3732 uagp35 - ok
14:17:31.0550 3732 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
14:17:31.0554 3732 udfs - ok
14:17:31.0590 3732 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
14:17:31.0593 3732 UI0Detect - ok
14:17:31.0609 3732 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
14:17:31.0610 3732 uliagpkx - ok
14:17:31.0629 3732 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
14:17:31.0633 3732 uliahci - ok
14:17:31.0648 3732 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
14:17:31.0650 3732 UlSata - ok
14:17:31.0676 3732 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
14:17:31.0677 3732 ulsata2 - ok
14:17:31.0697 3732 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
14:17:31.0698 3732 umbus - ok
14:17:31.0721 3732 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
14:17:31.0728 3732 upnphost - ok
14:17:31.0753 3732 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
14:17:31.0754 3732 usbccgp - ok
14:17:31.0775 3732 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
14:17:31.0776 3732 usbcir - ok
14:17:31.0823 3732 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
14:17:31.0825 3732 usbehci - ok
14:17:31.0840 3732 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
14:17:31.0843 3732 usbhub - ok
14:17:31.0860 3732 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
14:17:31.0862 3732 usbohci - ok
14:17:31.0908 3732 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
14:17:31.0908 3732 usbprint - ok
14:17:31.0961 3732 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
14:17:31.0962 3732 usbscan - ok
14:17:31.0979 3732 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:17:31.0980 3732 USBSTOR - ok
14:17:31.0995 3732 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
14:17:31.0997 3732 usbuhci - ok
14:17:32.0042 3732 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
14:17:32.0043 3732 usbvideo - ok
14:17:32.0079 3732 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
14:17:32.0083 3732 UxSms - ok
14:17:32.0101 3732 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
14:17:32.0108 3732 vds - ok
14:17:32.0144 3732 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
14:17:32.0144 3732 vga - ok
14:17:32.0150 3732 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
14:17:32.0152 3732 VgaSave - ok
14:17:32.0175 3732 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
14:17:32.0177 3732 viaagp - ok
14:17:32.0188 3732 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
14:17:32.0189 3732 ViaC7 - ok
14:17:32.0209 3732 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
14:17:32.0211 3732 viaide - ok
14:17:32.0235 3732 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
14:17:32.0236 3732 volmgr - ok
14:17:32.0248 3732 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
14:17:32.0252 3732 volmgrx - ok
14:17:32.0320 3732 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
14:17:32.0324 3732 volsnap - ok
14:17:32.0339 3732 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
14:17:32.0343 3732 vsmraid - ok
14:17:32.0392 3732 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
14:17:32.0425 3732 VSS - ok
14:17:32.0493 3732 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
14:17:32.0501 3732 W32Time - ok
14:17:32.0523 3732 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
14:17:32.0524 3732 WacomPen - ok
14:17:32.0543 3732 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
14:17:32.0545 3732 Wanarp - ok
14:17:32.0553 3732 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
14:17:32.0554 3732 Wanarpv6 - ok
14:17:32.0620 3732 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
14:17:32.0627 3732 wcncsvc - ok
14:17:32.0639 3732 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:17:32.0643 3732 WcsPlugInService - ok
14:17:32.0676 3732 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
14:17:32.0677 3732 Wd - ok
14:17:32.0704 3732 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
14:17:32.0712 3732 Wdf01000 - ok
14:17:32.0724 3732 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
14:17:32.0727 3732 WdiServiceHost - ok
14:17:32.0732 3732 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
14:17:32.0737 3732 WdiSystemHost - ok
14:17:32.0805 3732 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
14:17:32.0812 3732 WebClient - ok
14:17:32.0870 3732 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
14:17:32.0875 3732 Wecsvc - ok
14:17:32.0895 3732 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
14:17:32.0900 3732 wercplsupport - ok
14:17:32.0919 3732 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
14:17:32.0923 3732 WerSvc - ok
14:17:33.0040 3732 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
14:17:33.0047 3732 WinDefend - ok
14:17:33.0055 3732 WinHttpAutoProxySvc - ok
14:17:33.0122 3732 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
14:17:33.0124 3732 Winmgmt - ok
14:17:33.0192 3732 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
14:17:33.0205 3732 WinRM - ok
14:17:33.0263 3732 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
14:17:33.0276 3732 Wlansvc - ok
14:17:33.0303 3732 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
14:17:33.0304 3732 WmiAcpi - ok
14:17:33.0329 3732 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
14:17:33.0331 3732 wmiApSrv - ok
14:17:33.0410 3732 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
14:17:33.0418 3732 WMPNetworkSvc - ok
14:17:33.0460 3732 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
14:17:33.0465 3732 WPCSvc - ok
14:17:33.0513 3732 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
14:17:33.0518 3732 WPDBusEnum - ok
14:17:33.0592 3732 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
14:17:33.0593 3732 WpdUsb - ok
14:17:33.0769 3732 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
14:17:33.0783 3732 WPFFontCache_v0400 - ok
14:17:33.0881 3732 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
14:17:33.0882 3732 ws2ifsl - ok
14:17:33.0916 3732 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll
14:17:33.0920 3732 wscsvc - ok
14:17:33.0925 3732 WSearch - ok
14:17:33.0979 3732 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
14:17:33.0981 3732 WUDFRd - ok
14:17:33.0993 3732 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
14:17:33.0997 3732 wudfsvc - ok
14:17:34.0038 3732 [ 3E1C915C6291AB5D1CFCA680E1BD6BAD ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
14:17:34.0045 3732 yukonwlh - ok
14:17:34.0058 3732 ================ Scan global ===============================
14:17:34.0089 3732 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
14:17:34.0119 3732 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
14:17:34.0141 3732 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
14:17:34.0176 3732 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
14:17:34.0181 3732 [Global] - ok
14:17:34.0181 3732 ================ Scan MBR ==================================
14:17:34.0197 3732 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
14:17:34.0587 3732 \Device\Harddisk0\DR0 - ok
14:17:34.0588 3732 ================ Scan VBR ==================================
14:17:34.0592 3732 [ F4D669FBE84D8292DA17C3736F327924 ] \Device\Harddisk0\DR0\Partition1
14:17:34.0594 3732 \Device\Harddisk0\DR0\Partition1 - ok
14:17:34.0595 3732 ============================================================
14:17:34.0595 3732 Scan finished
14:17:34.0595 3732 ============================================================
14:17:34.0611 4424 Detected object count: 1
14:17:34.0611 4424 Actual detected object count: 1
14:18:08.0091 4424 C:\Windows\system32\DRIVERS\smb.sys - copied to quarantine
14:18:10.0961 4424 C:\Windows\$NtUninstallKB34006$\4228217043\@ - copied to quarantine
14:18:10.0961 4424 C:\Windows\$NtUninstallKB34006$\4228217043\Desktop.ini - copied to quarantine
14:18:11.0411 4424 C:\Windows\$NtUninstallKB34006$\4228217043\L\00000004.@ - copied to quarantine
14:18:11.0421 4424 C:\Windows\$NtUninstallKB34006$\4228217043\L\201d3dde - copied to quarantine
14:18:11.0471 4424 C:\Windows\$NtUninstallKB34006$\4228217043\L\qnbwvoto - copied to quarantine
14:18:11.0481 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\00000004.@ - copied to quarantine
14:18:11.0931 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\00000008.@ - copied to quarantine
14:18:12.0421 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\000000cb.@ - copied to quarantine
14:18:12.0901 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\80000000.@ - copied to quarantine
14:18:13.0401 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\80000032.@ - copied to quarantine
14:18:14.0131 4424 Backup copy found, using it..
14:18:14.0181 4424 C:\Windows\system32\DRIVERS\smb.sys - will be cured on reboot
14:18:14.0281 4424 C:\Windows\$NtUninstallKB34006$\3581031780 - will be deleted on reboot
14:18:14.0281 4424 C:\Windows\$NtUninstallKB34006$\4228217043\@ - will be deleted on reboot
14:18:14.0291 4424 C:\Windows\$NtUninstallKB34006$\4228217043\Desktop.ini - will be deleted on reboot
14:18:14.0301 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\00000004.@ - will be deleted on reboot
14:18:14.0301 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\00000008.@ - will be deleted on reboot
14:18:14.0301 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\000000cb.@ - will be deleted on reboot
14:18:14.0301 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\80000000.@ - will be deleted on reboot
14:18:14.0301 4424 C:\Windows\$NtUninstallKB34006$\4228217043\U\80000032.@ - will be deleted on reboot
14:18:14.0301 4424 Smb ( Virus.Win32.ZAccess.k ) - User select action: Cure
14:18:22.0431 4732 Deinitialize success

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Virus v services.exe a Desktop.ini

#4 Příspěvek od stell »

Našlo to nějaký ten zeroacess
To nie je len nejaky zeroaccess,ale je to tvrdy oriesok, a velmi odolny Rootkit. :D
ok.
Stiahni priamo na USB-kluc tento program.
http://download.bleepingcomputer.com/farbar/FRST.exe

2{Usb kluc nechaj pripojene.
3:Reštartuje počítač, pri reštartovaní počítača stlačte kláves F8 a podržte ho stlačený.Kláves F8 musíte stlačiť predtým, než sa zobrazí logo systému Windows.

4:Pomocou klávesov so šípkami vyberte možnosť Opraviť tento počítač .
Vyberte nastavenie jazyka klávesnice , a potom kliknite na tlačidlo Ďalej.
Vyberte operačný systém, ktorý chcete opraviť, a potom kliknite na tlačidlo Ďalej.
Vyberte svoj užívateľský účet za tlačidlo Ďalej
V ponuke Možnosti obnovenia systému budete mať nasledujúce možnosti:

oprava spustenia
obnovenie systému
Windows Complete PC Restore
Windows Memory Diagnostic Tool
príkazový riadok

Vyber Príkazový riadok

;Spust prikazovy riadok
a napis prikaz notepad [enter]
kliknu subor>>otvorit>.najdi tento pocitac a otvor USB kluc, kde mas ulozeny FRST.exe.
Pozri sa ze ake pismenko ma USB, a ak napriklad ma F:/
Tak zatvor notepad a do prikazoveho riadku zadaj prikaz
F:\FRST.exe a stlac enter, a stlac Scan>>o chvilku sa ti na USB sa ulozi log s nazvom FRST.txt>.obsah vloz sem.

vloz sem.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

madeat
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 čer 2007 23:13

Re: Virus v services.exe a Desktop.ini

#5 Příspěvek od madeat »

Hotovo

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-10-2012
Ran by SYSTEM at 02-11-2012 14:49:55
Running from F:\
Windows Vista (TM) Home Premium (X86) OS Language: Czech
The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice [3080264 2011-09-22] (ESET)
HKLM\...\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [2569616 2010-07-26] (CANON INC.)
HKLM\...\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon [767312 2009-09-04] (CANON INC.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKU\Slamova\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [4762496 2012-10-24] (SUPERAntiSpyware.com)
HKU\Slamova\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\Slamova\...\Run: [Facebook Update] "C:\Users\Slamova\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-09-17] (Facebook Inc.)
Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\GamePark klient 2.lnk
ShortcutTarget: GamePark klient 2.lnk -> C:\Program Files\GamePark2\gpcl.exe (Allstar Group, s.r.o.)

==================== Services (Whitelisted) ===================

2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE.EXE" [116608 2012-10-24] (SUPERAntiSpyware.com)
2 ekrn; "C:\Program Files\ESET\ESET Smart Security\ekrn.exe" [974944 2011-09-22] (ESET)
2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75064 2012-04-17] ()
2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [214520 2012-10-28] ()

==================== Drivers (Whitelisted) ====================

2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163424 2011-08-09] (ESET)
1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [118104 2011-08-04] (ESET)
2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [147480 2011-08-04] (ESET)
1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [33656 2011-08-04] (ESET)
0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50624 2011-08-04] (ESET)
0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1083880 2009-04-11] (Společnost Microsoft)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2012-11-02 14:49 - 2012-11-02 14:49 - 00000000 ____D C:\FRST
2012-11-02 14:39 - 2012-11-02 14:39 - 00000400 ____A C:\Windows\PFRO.log
2012-11-02 14:18 - 2012-11-02 14:18 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-11-02 14:16 - 2012-11-02 14:16 - 02213976 ____A (Kaspersky Lab ZAO) C:\Users\Slamova\Downloads\tdsskiller.exe
2012-11-02 13:27 - 2012-11-02 13:32 - 00000000 ____D C:\Program Files\trend micro
2012-11-02 13:27 - 2012-11-02 13:28 - 00000000 ____D C:\rsit
2012-11-02 13:26 - 2012-11-02 13:26 - 00781383 ____A C:\Users\Slamova\Downloads\RSIT.exe
2012-11-02 13:08 - 2009-04-11 14:18 - 00279552 ____A (Microsoft Corporation) C:\services.exe
2012-11-01 20:59 - 2012-11-01 21:03 - 777555968 ____A C:\Users\Slamova\Downloads\Drive CZ (2011).avi
2012-10-30 12:08 - 2012-10-30 12:08 - 00000000 ____D C:\Users\Slamova\Desktop\2012_10_30
2012-10-30 10:08 - 2012-10-30 10:15 - 1323203918 ____A C:\Users\Slamova\Downloads\MasterChef - Díl 9. Tv. NOVA ( 26.10.2012.).avi
2012-10-30 10:06 - 2012-10-30 10:17 - 186049078 ____A C:\Users\Slamova\Downloads\Bluetooth_Atheros_7.4.0000.0095_W7x86_A.zip
2012-10-30 10:06 - 2012-10-30 10:17 - 185606759 ____A C:\Users\Slamova\Downloads\TouchPad_ELANTECH_11.6.2.1_W7x86_A.zip
2012-10-30 10:06 - 2012-10-30 10:09 - 46974192 ____A C:\Users\Slamova\Downloads\Wireless LAN_Atheros_9.2.0.469_W7x86_A.zip
2012-10-30 10:06 - 2012-10-30 10:07 - 18021840 ____A C:\Users\Slamova\Downloads\VGA_Intel_8.14.8.1075_W7x86_A.zip
2012-10-30 10:06 - 2012-10-30 10:06 - 10660521 ____A C:\Users\Slamova\Downloads\CardReader_Realtek_6.1.7601.83_W7x86_A.zip
2012-10-30 10:06 - 2012-10-30 10:06 - 05849614 ____A C:\Users\Slamova\Downloads\Lan_Realtek_7.049.927.2011_W7x86_A.zip
2012-10-30 10:05 - 2012-10-30 10:16 - 157158823 ____A C:\Users\Slamova\Downloads\Audio_Realtek_6.0.1.6374_W7x86_A.zip
2012-10-30 10:05 - 2012-10-30 10:06 - 10845105 ____A C:\Users\Slamova\Downloads\AHCI_Intel_10.1.0.1008_W7x86_A.zip
2012-10-30 10:05 - 2012-10-30 10:05 - 02853001 ____A C:\Users\Slamova\Downloads\Chipset_Intel_9.2.2.1034_W7x86_A.zip
2012-10-30 10:05 - 2012-10-30 10:05 - 02695344 ____A C:\Users\Slamova\Downloads\3G_Huawei_6.0.1.289_W7x86_A.zip
2012-10-28 22:26 - 2012-10-28 22:26 - 181135360 ____A C:\Users\Slamova\Desktop\South Park 6x07 - To už bylo v Simpsonech CZ.avi
2012-10-27 20:56 - 2012-10-27 20:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2012-10-26 09:35 - 2012-10-26 09:35 - 01480280 ____A (ESET) C:\Users\Slamova\Downloads\ESETSirefefEVCleaner(1).exe
2012-10-25 17:58 - 2012-11-02 14:26 - 00026491 ____A C:\Windows\WindowsUpdate.log
2012-10-24 13:09 - 2012-10-24 13:09 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2012-10-24 13:08 - 2012-10-24 13:08 - 01480280 ____A (ESET) C:\Users\Slamova\Downloads\ESETSirefefEVCleaner.exe
2012-10-23 21:43 - 2012-10-23 21:43 - 00000000 ____D C:\Users\All Users\vsosdk
2012-10-23 21:00 - 2012-10-23 21:56 - 00000000 ____D C:\Users\Slamova\Documents\ConvertXToDVD
2012-10-23 20:57 - 2012-10-23 20:58 - 19749661 ____A C:\Users\Slamova\Downloads\ConvertXtoDVD-4.1.19.365.rar
2012-10-23 20:49 - 2012-10-25 07:55 - 00000000 ____D C:\Users\Slamova\AppData\Roaming\Vso
2012-10-23 20:49 - 2012-10-23 21:56 - 00001057 ____A C:\Users\Slamova\AppData\Roaming\vso_ts_preview.xml
2012-10-23 20:49 - 2012-10-23 20:49 - 00001017 ____A C:\Users\Slamova\Desktop\ConvertXtoDVD 4.lnk
2012-10-23 20:49 - 2012-10-23 20:49 - 00000000 ____D C:\Program Files\VSO
2012-10-23 20:49 - 2009-09-02 12:44 - 01184984 ____A (Microsoft Corporation) C:\Windows\System32\wvc1dmod.dll
2012-10-23 20:49 - 2009-09-02 12:44 - 00626688 ____A (On2.com) C:\Windows\System32\vp7vfw.dll
2012-10-23 20:49 - 2009-09-02 12:44 - 00273408 ____A (RealNetworks, Inc.) C:\Windows\System32\Pncrt.dll
2012-10-23 20:49 - 2009-09-02 12:44 - 00217127 ____A (RealNetworks, Inc.) C:\Windows\System32\drv43260.dll
2012-10-23 20:49 - 2009-09-02 12:44 - 00208935 ____A (RealNetworks, Inc.) C:\Windows\System32\drv33260.dll
2012-10-23 20:49 - 2009-09-02 12:44 - 00176165 ____A (RealNetworks, Inc.) C:\Windows\System32\drv23260.dll
2012-10-23 20:49 - 2009-09-02 12:44 - 00102439 ____A (RealNetworks, Inc.) C:\Windows\System32\sipr3260.dll
2012-10-23 20:49 - 2009-09-02 12:44 - 00065602 ____A (RealNetworks, Inc.) C:\Windows\System32\cook3260.dll
2012-10-23 20:47 - 2012-10-23 20:48 - 19788784 ____A (VSO-Software ) C:\Users\Slamova\Downloads\vsoConvertXtoDVD4_setup.exe
2012-10-20 15:00 - 2012-10-20 15:00 - 00000000 ____D C:\Users\Slamova\Documents\Adventure Game Files
2012-10-20 14:59 - 2012-10-20 15:00 - 12546581 ____A (Blit Inc. ) C:\Users\Slamova\Downloads\JungleReporter.exe
2012-10-10 20:28 - 2012-10-10 20:28 - 00034983 ____A C:\Users\Slamova\Desktop\test - smesi.pptx
2012-10-10 20:12 - 2012-10-10 20:12 - 00000584 ____A C:\Users\Slamova\Documents\grstyles.stl
2012-10-10 18:47 - 2012-10-10 19:03 - 00000009 ____A C:\Users\Slamova\Documents\LastLab.sk
2012-10-10 18:47 - 2012-10-10 18:47 - 00000203 ____A C:\Users\Slamova\Documents\BasicLab.sk
2012-10-10 18:47 - 2012-10-10 18:47 - 00000000 ____A C:\Users\Slamova\Documents\UserLab.sk
2012-10-10 18:45 - 2012-10-10 18:45 - 00001927 ____A C:\Users\Slamova\Documents\template.cfg
2012-10-10 18:45 - 2012-10-10 18:45 - 00000012 ____A C:\Users\Slamova\Documents\UserStl.sk
2012-10-10 18:45 - 2012-10-10 18:45 - 00000000 ____D C:\Users\All Users\Advanced Chemistry Development
2012-10-10 18:43 - 2012-10-10 18:45 - 00000000 ____D C:\Users\Slamova\AppData\Roaming\Advanced Chemistry Development
2012-10-10 18:43 - 2012-10-10 18:44 - 00000000 ____D C:\Program Files\ACDFREE12
2012-10-10 10:19 - 2012-09-13 14:28 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-10-10 10:19 - 2012-08-29 12:27 - 03602816 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2012-10-10 10:19 - 2012-08-29 12:27 - 03550080 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-10-10 10:19 - 2012-06-02 01:02 - 00985088 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-10-10 10:19 - 2012-06-02 01:02 - 00133120 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-10-10 10:19 - 2012-06-02 01:02 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-10-10 10:18 - 2012-08-24 16:53 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2012-10-08 13:04 - 2012-10-08 13:04 - 00000318 ____A C:\Users\Slamova\Desktop\CZShare Manager.appref-ms
2012-10-08 13:03 - 2012-10-23 06:29 - 00000000 ____D C:\Users\Slamova\AppData\Local\Deployment
2012-10-08 13:03 - 2012-10-08 13:03 - 00000000 ____D C:\Users\Slamova\AppData\Local\Apps\2.0
2012-10-04 08:32 - 2012-10-04 08:32 - 02762434 ____A C:\Users\Slamova\Downloads\Základy+organické+chemie.pptx
2012-10-03 12:45 - 2012-10-10 20:03 - 00381595 ____A C:\Users\Slamova\Desktop\Názvosloví uhlovodíků.pptx

==================== 3 Months Modified Files ==================

2012-11-02 14:45 - 2012-03-28 09:34 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-11-02 14:45 - 2006-11-02 14:01 - 00032626 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-11-02 14:45 - 2006-11-02 14:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-11-02 14:42 - 2012-04-07 18:36 - 00000938 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-11-02 14:39 - 2012-11-02 14:39 - 00000400 ____A C:\Windows\PFRO.log
2012-11-02 14:39 - 2006-11-02 13:47 - 00003760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-11-02 14:39 - 2006-11-02 13:47 - 00003760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-11-02 14:36 - 2009-04-13 10:32 - 01419568 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-02 14:35 - 2012-04-03 20:13 - 00112640 ____A C:\Users\Slamova\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-11-02 14:30 - 2012-04-07 18:36 - 00000942 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-11-02 14:26 - 2012-10-25 17:58 - 00026491 ____A C:\Windows\WindowsUpdate.log
2012-11-02 14:19 - 2009-04-11 14:18 - 00066560 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\smb.sys
2012-11-02 14:16 - 2012-11-02 14:16 - 02213976 ____A (Kaspersky Lab ZAO) C:\Users\Slamova\Downloads\tdsskiller.exe
2012-11-02 13:57 - 2012-03-28 12:42 - 00000914 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-11-02 13:26 - 2012-11-02 13:26 - 00781383 ____A C:\Users\Slamova\Downloads\RSIT.exe
2012-11-02 13:21 - 2012-09-17 12:16 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1431964540-3257949587-1746594197-1000UA.job
2012-11-02 13:21 - 2012-09-17 12:16 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1431964540-3257949587-1746594197-1000Core.job
2012-11-02 13:13 - 2006-11-02 13:47 - 00369864 ____A C:\Windows\System32\FNTCACHE.DAT
2012-11-01 21:03 - 2012-11-01 20:59 - 777555968 ____A C:\Users\Slamova\Downloads\Drive CZ (2011).avi
2012-10-30 10:17 - 2012-10-30 10:06 - 186049078 ____A C:\Users\Slamova\Downloads\Bluetooth_Atheros_7.4.0000.0095_W7x86_A.zip
2012-10-30 10:17 - 2012-10-30 10:06 - 185606759 ____A C:\Users\Slamova\Downloads\TouchPad_ELANTECH_11.6.2.1_W7x86_A.zip
2012-10-30 10:16 - 2012-10-30 10:05 - 157158823 ____A C:\Users\Slamova\Downloads\Audio_Realtek_6.0.1.6374_W7x86_A.zip
2012-10-30 10:15 - 2012-10-30 10:08 - 1323203918 ____A C:\Users\Slamova\Downloads\MasterChef - Díl 9. Tv. NOVA ( 26.10.2012.).avi
2012-10-30 10:09 - 2012-10-30 10:06 - 46974192 ____A C:\Users\Slamova\Downloads\Wireless LAN_Atheros_9.2.0.469_W7x86_A.zip
2012-10-30 10:07 - 2012-10-30 10:06 - 18021840 ____A C:\Users\Slamova\Downloads\VGA_Intel_8.14.8.1075_W7x86_A.zip
2012-10-30 10:06 - 2012-10-30 10:06 - 10660521 ____A C:\Users\Slamova\Downloads\CardReader_Realtek_6.1.7601.83_W7x86_A.zip
2012-10-30 10:06 - 2012-10-30 10:06 - 05849614 ____A C:\Users\Slamova\Downloads\Lan_Realtek_7.049.927.2011_W7x86_A.zip
2012-10-30 10:06 - 2012-10-30 10:05 - 10845105 ____A C:\Users\Slamova\Downloads\AHCI_Intel_10.1.0.1008_W7x86_A.zip
2012-10-30 10:05 - 2012-10-30 10:05 - 02853001 ____A C:\Users\Slamova\Downloads\Chipset_Intel_9.2.2.1034_W7x86_A.zip
2012-10-30 10:05 - 2012-10-30 10:05 - 02695344 ____A C:\Users\Slamova\Downloads\3G_Huawei_6.0.1.289_W7x86_A.zip
2012-10-28 22:26 - 2012-10-28 22:26 - 181135360 ____A C:\Users\Slamova\Desktop\South Park 6x07 - To už bylo v Simpsonech CZ.avi
2012-10-28 18:04 - 2012-04-17 10:47 - 00214520 ____A C:\Windows\System32\PnkBstrB.xtr
2012-10-28 18:04 - 2012-04-17 10:47 - 00214520 ____A C:\Windows\System32\PnkBstrB.exe
2012-10-28 18:04 - 2012-04-17 10:47 - 00137464 ____A C:\Windows\System32\Drivers\PnkBstrK.sys
2012-10-28 10:53 - 2012-04-16 21:20 - 00000787 ____A C:\Users\Slamova\Desktop\GamePark klient 2.lnk
2012-10-26 09:35 - 2012-10-26 09:35 - 01480280 ____A (ESET) C:\Users\Slamova\Downloads\ESETSirefefEVCleaner(1).exe
2012-10-24 13:08 - 2012-10-24 13:08 - 01480280 ____A (ESET) C:\Users\Slamova\Downloads\ESETSirefefEVCleaner.exe
2012-10-23 21:56 - 2012-10-23 20:49 - 00001057 ____A C:\Users\Slamova\AppData\Roaming\vso_ts_preview.xml
2012-10-23 20:58 - 2012-10-23 20:57 - 19749661 ____A C:\Users\Slamova\Downloads\ConvertXtoDVD-4.1.19.365.rar
2012-10-23 20:49 - 2012-10-23 20:49 - 00001017 ____A C:\Users\Slamova\Desktop\ConvertXtoDVD 4.lnk
2012-10-23 20:48 - 2012-10-23 20:47 - 19788784 ____A (VSO-Software ) C:\Users\Slamova\Downloads\vsoConvertXtoDVD4_setup.exe
2012-10-20 15:00 - 2012-10-20 14:59 - 12546581 ____A (Blit Inc. ) C:\Users\Slamova\Downloads\JungleReporter.exe
2012-10-11 07:33 - 2012-04-07 18:37 - 00001971 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-10-11 07:01 - 2006-11-02 11:24 - 62968832 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-10-10 20:28 - 2012-10-10 20:28 - 00034983 ____A C:\Users\Slamova\Desktop\test - smesi.pptx
2012-10-10 20:12 - 2012-10-10 20:12 - 00000584 ____A C:\Users\Slamova\Documents\grstyles.stl
2012-10-10 20:03 - 2012-10-03 12:45 - 00381595 ____A C:\Users\Slamova\Desktop\Názvosloví uhlovodíků.pptx
2012-10-10 19:03 - 2012-10-10 18:47 - 00000009 ____A C:\Users\Slamova\Documents\LastLab.sk
2012-10-10 18:47 - 2012-10-10 18:47 - 00000203 ____A C:\Users\Slamova\Documents\BasicLab.sk
2012-10-10 18:47 - 2012-10-10 18:47 - 00000000 ____A C:\Users\Slamova\Documents\UserLab.sk
2012-10-10 18:45 - 2012-10-10 18:45 - 00001927 ____A C:\Users\Slamova\Documents\template.cfg
2012-10-10 18:45 - 2012-10-10 18:45 - 00000012 ____A C:\Users\Slamova\Documents\UserStl.sk
2012-10-08 20:57 - 2012-03-28 12:42 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-10-08 20:57 - 2012-03-28 12:42 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-10-08 13:04 - 2012-10-08 13:04 - 00000318 ____A C:\Users\Slamova\Desktop\CZShare Manager.appref-ms
2012-10-04 08:32 - 2012-10-04 08:32 - 02762434 ____A C:\Users\Slamova\Downloads\Základy+organické+chemie.pptx
2012-10-02 15:44 - 2012-10-02 15:44 - 00393649 ____A C:\Users\Slamova\Desktop\Chemické výpočty.pptx
2012-10-01 12:16 - 2012-10-01 12:16 - 00466432 ____A C:\Users\Slamova\Desktop\Lipidy.ppt
2012-09-27 20:27 - 2012-09-27 20:27 - 00513865 ____A C:\Users\Slamova\Desktop\Metody oddělování složek směsí.pptx
2012-09-27 08:03 - 2012-09-27 08:03 - 00313280 ____A C:\Users\Slamova\Downloads\Kurzy_CBV.zip
2012-09-19 11:59 - 2012-09-19 11:59 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2012-09-13 14:28 - 2012-10-10 10:19 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-08-29 12:27 - 2012-10-10 10:19 - 03602816 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
2012-08-29 12:27 - 2012-10-10 10:19 - 03550080 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-08-24 22:06 - 2012-08-24 22:01 - 733812736 ____A C:\Users\Slamova\Desktop\Somrak s brokarnou Hobo with a Shotgun 2011 ENdub DVDrip.avi
2012-08-24 16:53 - 2012-10-10 10:18 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2012-08-24 08:27 - 2012-09-22 14:37 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-24 08:03 - 2012-09-22 14:37 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-24 07:59 - 2012-09-22 14:37 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-24 07:51 - 2012-09-22 14:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-24 07:51 - 2012-09-22 14:37 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-24 07:51 - 2012-09-22 14:37 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-24 07:49 - 2012-09-22 14:37 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-24 07:48 - 2012-09-22 14:37 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-24 07:47 - 2012-09-22 14:37 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-24 07:47 - 2012-09-22 14:37 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-24 07:47 - 2012-09-22 14:37 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-24 07:45 - 2012-09-22 14:37 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-24 07:44 - 2012-09-22 14:37 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-24 07:44 - 2012-09-22 14:37 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-24 07:43 - 2012-09-22 14:37 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-24 07:40 - 2012-09-22 14:37 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-16 16:35 - 2012-08-16 16:31 - 731004344 ____A C:\Users\Slamova\Desktop\Millerova krizovatka.avi


==================== Known DLLs (Whitelisted) =================


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2012-10-21 10:37:14
Restore point made on: 2012-10-22 06:07:32
Restore point made on: 2012-10-23 05:49:43
Restore point made on: 2012-10-23 19:04:23
Restore point made on: 2012-10-24 07:50:45
Restore point made on: 2012-10-26 07:58:13
Restore point made on: 2012-10-27 13:24:50
Restore point made on: 2012-10-28 20:33:26
Restore point made on: 2012-10-29 09:26:05
Restore point made on: 2012-10-30 07:56:04
Restore point made on: 2012-10-31 21:43:38
Restore point made on: 2012-11-01 14:56:53
Restore point made on: 2012-11-02 07:07:02

==================== Memory info ===========================

Percentage of memory in use: 16%
Total physical RAM: 3000.86 MB
Available physical RAM: 2506.14 MB
Total Pagefile: 2999.14 MB
Available Pagefile: 2512.8 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.7 MB

==================== Partitions =============================

1 Drive c: () (Fixed) (Total:298.09 GB) (Free:201.53 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (GRMC(X)FREOEM_CS_DVD) (CDROM) (Total:3.71 GB) (Free:0 GB) UDF
4 Drive f: () (Removable) (Total:3.75 GB) (Free:3.21 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

Disk ### Stav Velikost Voln‚ Dyn Gpt
-------- ------------- -------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 ¦ dn‚ m‚dium 0 B 0 B
Disk 2 Online 3840 MB 0 B

Probˇh  ukonźenˇ programu DiskPart...

Partitions of Disk 0:
===============

Nynˇ je vybr n disk 0.

Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- -------- --------
Oddˇl 1 Prim rnˇ 298 GB 1024 KB

Probˇh  ukonźenˇ programu DiskPart...

=========================================================

Partitions of Disk 2:
===============

Nynˇ je vybr n disk 2.

Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- -------- --------
Oddˇl 1 Prim rnˇ 3839 MB 16 KB

Probˇh  ukonźenˇ programu DiskPart...

=========================================================

Last Boot: 2012-11-02 14:25

==================== End Of Log ============================

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Virus v services.exe a Desktop.ini

#6 Příspěvek od stell »

Dobre, zda sa ze TDSSKiller znicil vsetko.
Pokracuj takto.
2:Stiahnite si AdwCleaner
Ulož ho na plochu.

Zatvorte všetky otvorené programy a internetové prehliadače.
Dvakrát kliknite na AdwCleaner.exe na spustenie nástroja.
Klikni na Delete.
Potvrďte zakaždým s Ok.
Počítač sa automaticky reštartuje.
Textový súbor sa otvorí po reštarte.
Ak nie nájsť logfile na C: \ AdwCleaner [S1] txt .
Obsah vloz sem.

3: Stiahni RogueKiller . RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe

Zatvor vsetky programy
Ak pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dajte Run As Administrator ci Spustiť ako správca
Pockaj na dokončení PreScan
Vyber polozku Prehľadať (scan)
Pockas kym prebehne (scan)
Potom klikni na ""Zmazať"" - vykoná zmazanie nálezov.
Po dokončení klikni na Správa (Report) - otvorí sa log, ten sem vloz
Detailný postup http://forum.viry.cz/viewtopic.php?f=24 ... 1#p1097961
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

madeat
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 čer 2007 23:13

Re: Virus v services.exe a Desktop.ini

#7 Příspěvek od madeat »

AdwCleaner

# AdwCleaner v2.006 - Logfile created 11/02/2012 at 15:04:13
# Updated 30/10/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : Slamova - SLAMOVA-PC
# Boot Mode : Normal
# Running from : C:\Users\Slamova\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v16.0.2 (cs)

Profile name : default
File : C:\Users\Slamova\AppData\Roaming\Mozilla\Firefox\Profiles\dh6ydvj3.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Slamova\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [1000 octets] - [02/11/2012 15:04:13]

########## EOF - C:\AdwCleaner[S1].txt - [1060 octets] ##########

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Virus v services.exe a Desktop.ini

#8 Příspěvek od stell »

Este aj ten druhy vloz,log z RogueKiller.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

madeat
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 čer 2007 23:13

Re: Virus v services.exe a Desktop.ini

#9 Příspěvek od madeat »

RogueKiller

RogueKiller V8.2.1 [10/29/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Operační systém: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Slamova [Práva správce]
Mód : Odebrat -- Datum : 11/02/2012 15:09:46

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost
::1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD3200BPVT-00HXZT3 ATA Device +++++
--- User ---
[MBR] 13877b1b99e33ca72c9d929c33f698b6
[BSP] 66124740fbc7dcc3da2fb74d63fa6f6f : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 305243 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: Sony Storage Media USB Device +++++
--- User ---
[MBR] 5158d268b9cacdf9b3ca37d145b471a1
[BSP] f2e920cbb348efa659923a6ba441194e : MBR Code unknown
Partition table:
0 - [ACTIVE] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 32 | Size: 3839 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Virus v services.exe a Desktop.ini

#10 Příspěvek od stell »

Ok, v poriadku,
Este jeden log a uvidime
4: Stiahneme OTL exe na plochu a spustime.
http://oldtimer.geekstogo.com/OTL.exe
zafajkneme pro vsechny uzivatele,purity,loop
Nastavenie necháme tak ako je, dole do okna vložte tento skript.
Klikni na gombik OPRAVIT, log vloz sem.

Kód: Vybrat vše

:Files
ipconfig /flushdns /c
:Commands
[resethosts]
[clearallrestorepoints]
[emptytemp] 
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

madeat
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 čer 2007 23:13

Re: Virus v services.exe a Desktop.ini

#11 Příspěvek od madeat »

All processes killed
========== FILES ==========
< ipconfig /flushdns /c >
Konfigurace protokolu IP syst‚mu Windows
MezipamŘś pýekl d nˇ DNS byla ŁspŘçnŘ vypr zdnŘna.
C:\Users\Slamova\Downloads\cmd.bat deleted successfully.
C:\Users\Slamova\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Slamova
->Temp folder emptied: 2973024 bytes
->Temporary Internet Files folder emptied: 18427903 bytes
->FireFox cache emptied: 278249429 bytes
->Google Chrome cache emptied: 6735802 bytes
->Flash cache emptied: 5768 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 90347360 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 378,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 11022012_151601

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Virus v services.exe a Desktop.ini

#12 Příspěvek od stell »

1:Spust ADWCleaner a klikni na tlacito UNINSTALL,
Adwcleaner sa odinstaluje.
2:Pozri sa ci je TDSSKILLER >tu>.start>.ovladacie panely >>/pridat/odobrat programy, ak ano odinstaluj, ak ni tak zmaz.

3:Odskusaj pocitac, ci Antivirusak bude este nieco hlasit, a napis.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

madeat
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 čer 2007 23:13

Re: Virus v services.exe a Desktop.ini

#13 Příspěvek od madeat »

Tak po celodenním provozu vše v pořádku. Antivir nic nehlásí a vše šlape jak má.

Velice moc děkuji za pomoc!! :thumbsup:

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Virus v services.exe a Desktop.ini

#14 Příspěvek od stell »

ok,
Nemas zaco.
Temu zatvaram.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Zamčeno