Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomoc-Win32/Kryptik.ASUR trojan

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Pomoc-Win32/Kryptik.ASUR trojan

#1 Příspěvek od Umbos »

Nod mi pri kontrole nasel -Win32/Kryptik.ASUR trojan a dal ho do karanteny, prosim o radu jak ho dat pryc . tady je Hijackhis.log-Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:57:47, on 10.2.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Nero\Tools\InCD\InCDSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\Nero\Tools\InCD\NBHRegInCDSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\TeamViewer\Version7\TeamViewer.exe
C:\Program Files\TeamViewer\Version7\tv_w32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\VibrateGameDeviceDriver\RFPIcon.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Nero\Tools\InCD\NBHGui.exe
C:\Program Files\Nero\Tools\InCD\InCD.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aktualne.cz/?ms=ae
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=112555 ... 1109661c54
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000. ... 1109661C54}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ui.skype.com/ui/0/3.6.0.216/cs/p ... 20Kraskovi
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: MyAshampoo - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\listicka.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Nástroje Lištičky - {1EA00BE1-6E54-4E2A-8099-680300BF23E1} - C:\Program Files\Seznam.cz\toolbar\toolbar.dll
O3 - Toolbar: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [RTBatteryMeter] C:\Program Files\VibrateGameDeviceDriver\RFPIcon.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe
O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NSU_agent] "C:\Program Files\Nokia\Nokia Software Updater\nsu3ui_agent.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NBHGui] C:\Program Files\Nero\Tools\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Tools\InCD\InCD.exe
O4 - HKLM\..\Run: [NBAgent] "C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OEXPRESS] C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [mount.exe] C:\Program Files\GiPo@Utilities\GiPo@FileUtilities\mount.exe /z
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Michal\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Počasí - {12EEAF9D-7DDB-4D18-88CA-8E873FFBCA89} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Supermapy - {32084289-1B63-4ECE-A8EB-7EE9B15E1A87} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Bleskově - {33E3CD19-7FAB-441B-AEB4-B5DFE2BE5C12} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Žena.cz - {4270A860-818E-4E7C-80F7-F760A06429A8} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Slovníky - {553EBA54-D0D9-413E-AB72-615710C49D38} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Xchat.cz - {7783FEA8-37D5-4863-9168-E19743F93EFE} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Stahuj.cz - {98863A22-ADD2-4259-9F26-35774BB54543} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Aktuálně - {9FB60092-E0C4-4383-90F7-400F7EB049AB} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Fotoalba - {A362B8E7-0820-4D1E-AF76-E18F911495F4} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra button: Centrum.cz - {EA9496DB-4EAA-4A1B-9236-D478E890D53F} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} - file:///C:/Program%20Files/AutoCAD%20LT%202000i%20Cz/InstFred.ocx
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - http://cdn.scan.onecare.live.com/resour ... se8942.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0331410328
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos-be ... canner.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} - file:///C:/Program%20Files/AutoCAD%20LT%202000i%20Cz/AcDcToday.ocx
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202000i%20Cz/AcPreview.ocx
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c9aa4c2af4cf40) (gupdate1c9aa4c2af4cf40) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDSrv) - Nero AG - C:\Program Files\Nero\Tools\InCD\InCDSrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Tools\InCD\NBHRegInCDSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: UDP-to-HTTP Proxy (udpproxy) - Unknown owner - C:\Documents and Settings\Michal\Plocha\Invertor\Nová složka\UdpProxy.exe (file missing)

--
End of file - 20738 bytes

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#2 Příspěvek od Umbos »

aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-02-10 10:08:49
-----------------------------
10:08:49.117 OS Version: Windows 5.1.2600 Service Pack 3
10:08:49.117 Number of processors: 1 586 0x801
10:08:49.117 ComputerName: NOBODY-D4E71821 UserName: Michal
10:08:51.648 Initialize success
10:09:16.133 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
10:09:16.133 Disk 0 Vendor: ST3120022A 3.54 Size: 114473MB BusType: 3
10:09:16.164 Disk 0 MBR read successfully
10:09:16.164 Disk 0 MBR scan
10:09:16.164 Disk 0 Windows XP default MBR code
10:09:16.164 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 114463 MB offset 63
10:09:16.164 Disk 0 scanning sectors +234420480
10:09:16.226 Disk 0 scanning C:\WINDOWS\system32\drivers
10:09:41.445 File: C:\WINDOWS\system32\drivers\redbook.sys **SUSPICIOUS**
10:09:50.867 Disk 0 trace - called modules:
10:09:50.898 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x868d0698]<<
10:09:50.898 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f23ab8]
10:09:50.898 3 CLASSPNP.SYS[f754ffd7] -> nt!IofCallDriver -> [0x8694ef08]
10:09:50.898 \Driver\00001794[0x86b35bc0] -> IRP_MJ_CREATE -> 0x868d0698
10:09:51.414 Scan finished successfully
10:10:25.648 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Michal\Plocha\Invertor\Nová složka\MBR.dat"
10:10:25.664 The log file has been saved successfully to "C:\Documents and Settings\Michal\Plocha\Invertor\Nová složka\aswMBR.txt"

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#3 Příspěvek od Umbos »

10:20:51.0925 2864 ============================================================
10:20:51.0925 2864 Current date / time: 2013/02/10 10:20:51.0925
10:20:51.0925 2864 SystemInfo:
10:20:51.0925 2864
10:20:51.0925 2864 OS Version: 5.1.2600 ServicePack: 3.0
10:20:51.0925 2864 Product type: Workstation
10:20:51.0925 2864 ComputerName: NOBODY-D4E71821
10:20:51.0925 2864 UserName: Michal
10:20:51.0925 2864 Windows directory: C:\WINDOWS
10:20:51.0925 2864 System windows directory: C:\WINDOWS
10:20:51.0925 2864 Processor architecture: Intel x86
10:20:51.0925 2864 Number of processors: 1
10:20:51.0925 2864 Page size: 0x1000
10:20:51.0925 2864 Boot type: Normal boot
10:20:51.0925 2864 ============================================================
10:20:53.0488 2864 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
10:20:53.0488 2864 ============================================================
10:20:53.0488 2864 \Device\Harddisk0\DR0:
10:20:53.0488 2864 MBR partitions:
10:20:53.0488 2864 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xDF8F8C1
10:20:53.0488 2864 ============================================================
10:20:53.0519 2864 C: <-> \Device\Harddisk0\DR0\Partition1
10:20:53.0519 2864 ============================================================
10:20:53.0519 2864 Initialize success
10:20:53.0519 2864 ============================================================
10:21:27.0158 2828 ============================================================
10:21:27.0158 2828 Scan started
10:21:27.0158 2828 Mode: Manual; SigCheck; TDLFS;
10:21:27.0158 2828 ============================================================
10:21:28.0174 2828 ================ Scan system memory ========================
10:21:28.0174 2828 System memory - ok
10:21:28.0189 2828 ================ Scan services =============================
10:21:28.0392 2828 [ 0629361FAC4576BA48AB39F4903DCE9E ] aawservice C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
10:21:28.0658 2828 aawservice - ok
10:21:28.0783 2828 Abiosdsk - ok
10:21:28.0814 2828 abp480n5 - ok
10:21:28.0892 2828 [ 4FE34F1F3126B61FCC6B2043AA8112C9 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:21:30.0314 2828 ACPI - ok
10:21:30.0377 2828 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
10:21:30.0627 2828 ACPIEC - ok
10:21:30.0642 2828 [ 05BDD706A847BBFA9FD5948CD636EB1A ] Ad-Watch Connect Filter C:\WINDOWS\system32\drivers\NSDriver.sys
10:21:30.0673 2828 Ad-Watch Connect Filter ( UnsignedFile.Multi.Generic ) - warning
10:21:30.0673 2828 Ad-Watch Connect Filter - detected UnsignedFile.Multi.Generic (1)
10:21:30.0720 2828 [ EC018602809B28520CAA132CD616BB2A ] Ad-Watch Real-Time Scanner C:\WINDOWS\system32\drivers\AWRTPD.sys
10:21:30.0752 2828 Ad-Watch Real-Time Scanner ( UnsignedFile.Multi.Generic ) - warning
10:21:30.0752 2828 Ad-Watch Real-Time Scanner - detected UnsignedFile.Multi.Generic (1)
10:21:30.0798 2828 [ 10D3F81B955CD10D6464B1B922E5AC68 ] Ad-Watch Registry Filter C:\WINDOWS\system32\drivers\AWRTRD.sys
10:21:30.0830 2828 Ad-Watch Registry Filter ( UnsignedFile.Multi.Generic ) - warning
10:21:30.0830 2828 Ad-Watch Registry Filter - detected UnsignedFile.Multi.Generic (1)
10:21:30.0939 2828 [ EC807244904FA170C299AB06D87FBDBE ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
10:21:30.0986 2828 AdobeFlashPlayerUpdateSvc - ok
10:21:31.0002 2828 adpu160m - ok
10:21:31.0048 2828 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
10:21:31.0298 2828 aec - ok
10:21:31.0345 2828 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
10:21:31.0455 2828 AFD - ok
10:21:31.0470 2828 Aha154x - ok
10:21:31.0486 2828 aic78u2 - ok
10:21:31.0517 2828 aic78xx - ok
10:21:31.0595 2828 [ FBBCB95F677CBAA924140B6EA2D9A97B ] ALCXSENS C:\WINDOWS\system32\drivers\ALCXSENS.SYS
10:21:31.0798 2828 ALCXSENS - ok
10:21:31.0845 2828 [ BC5C55B49C4BD1FDFAAA128FE21F9FEA ] ALCXWDM C:\WINDOWS\system32\drivers\ALCXWDM.SYS
10:21:32.0048 2828 ALCXWDM - ok
10:21:32.0127 2828 [ E0A6FA244B8624D78FE5FF6F56A33BAE ] Alerter C:\WINDOWS\system32\alrsvc.dll
10:21:32.0345 2828 Alerter - ok
10:21:32.0392 2828 [ 88842DE939A827577BF24243699AC80A ] ALG C:\WINDOWS\System32\alg.exe
10:21:32.0502 2828 ALG - ok
10:21:32.0533 2828 AliIde - ok
10:21:32.0580 2828 [ 3980814F8027D27EA003E2E3D9D4F604 ] AmdK7 C:\WINDOWS\system32\DRIVERS\amdk7.sys
10:21:32.0845 2828 AmdK7 - ok
10:21:32.0861 2828 amsint - ok
10:21:32.0923 2828 [ 6B8E7A90E576D4FE308F97C69060A171 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
10:21:33.0033 2828 AppMgmt - ok
10:21:33.0095 2828 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
10:21:33.0330 2828 Arp1394 - ok
10:21:33.0345 2828 asc - ok
10:21:33.0376 2828 asc3350p - ok
10:21:33.0408 2828 asc3550 - ok
10:21:33.0595 2828 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
10:21:33.0611 2828 aspnet_state - ok
10:21:33.0658 2828 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:21:33.0923 2828 AsyncMac - ok
10:21:33.0970 2828 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
10:21:34.0236 2828 atapi - ok
10:21:34.0267 2828 Atdisk - ok
10:21:34.0330 2828 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:21:34.0642 2828 Atmarpc - ok
10:21:34.0705 2828 [ DE31B88962A8645DBA5A37B993E7B0F1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
10:21:34.0970 2828 AudioSrv - ok
10:21:35.0033 2828 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
10:21:35.0298 2828 audstub - ok
10:21:35.0361 2828 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
10:21:35.0611 2828 Beep - ok
10:21:35.0705 2828 [ 89E739BBA5F636297EA5B5F811189E06 ] Browser C:\WINDOWS\System32\browser.dll
10:21:35.0861 2828 Browser - ok
10:21:35.0939 2828 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
10:21:36.0345 2828 cbidf2k - ok
10:21:36.0376 2828 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:21:36.0642 2828 CCDECODE - ok
10:21:36.0658 2828 cd20xrnt - ok
10:21:36.0720 2828 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
10:21:37.0017 2828 Cdaudio - ok
10:21:37.0064 2828 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
10:21:37.0361 2828 Cdfs - ok
10:21:37.0439 2828 [ 351735695E9EAD93DE6AF85D8BEB1CA8 ] cdrbsdrv C:\WINDOWS\system32\drivers\cdrbsdrv.sys
10:21:37.0470 2828 cdrbsdrv ( UnsignedFile.Multi.Generic ) - warning
10:21:37.0470 2828 cdrbsdrv - detected UnsignedFile.Multi.Generic (1)
10:21:37.0533 2828 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:21:37.0845 2828 Cdrom - ok
10:21:37.0861 2828 Changer - ok
10:21:37.0908 2828 [ E390DC1D7C461D7D56EC53402F329928 ] CiSvc C:\WINDOWS\system32\cisvc.exe
10:21:38.0158 2828 CiSvc - ok
10:21:38.0220 2828 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
10:21:38.0501 2828 ClipSrv - ok
10:21:38.0658 2828 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:21:39.0204 2828 clr_optimization_v2.0.50727_32 - ok
10:21:39.0298 2828 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:21:39.0970 2828 clr_optimization_v4.0.30319_32 - ok
10:21:39.0986 2828 CmdIde - ok
10:21:40.0017 2828 COMSysApp - ok
10:21:40.0064 2828 Cpqarray - ok
10:21:40.0079 2828 Crypkey License - ok
10:21:40.0142 2828 [ F3AB0933CBD166D271992F411C27CCAF ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
10:21:40.0376 2828 CryptSvc - ok
10:21:40.0423 2828 CrystalSysInfo - ok
10:21:40.0454 2828 dac2w2k - ok
10:21:40.0486 2828 dac960nt - ok
10:21:40.0548 2828 [ BE27674D1CBC3214AEC84B4336A38BBF ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
10:21:40.0689 2828 DcomLaunch - ok
10:21:40.0751 2828 [ 8C9A53E285AC5E6704844D0459EC85BE ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
10:21:41.0048 2828 Dhcp - ok
10:21:41.0095 2828 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
10:21:41.0423 2828 Disk - ok
10:21:41.0439 2828 dmadmin - ok
10:21:41.0517 2828 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
10:21:41.0892 2828 dmboot - ok
10:21:41.0923 2828 [ FFF1720AF51171F32F1EAD5CF71F2810 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
10:21:42.0220 2828 dmio - ok
10:21:42.0267 2828 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
10:21:42.0548 2828 dmload - ok
10:21:42.0579 2828 [ 2BFEFE9E865655A76982F050450B9591 ] dmserver C:\WINDOWS\System32\dmserver.dll
10:21:42.0907 2828 dmserver - ok
10:21:42.0954 2828 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
10:21:43.0251 2828 DMusic - ok
10:21:43.0298 2828 [ DFAA406BF19F4EE806A6F8D4342137F7 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
10:21:43.0423 2828 Dnscache - ok
10:21:43.0485 2828 [ 4A3E2BD20157A0946751229E92EB8621 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
10:21:43.0782 2828 Dot3svc - ok
10:21:43.0798 2828 dpti2o - ok
10:21:43.0845 2828 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
10:21:44.0110 2828 drmkaud - ok
10:21:44.0173 2828 [ F61D9EBD57E5B767C3F7573941A46238 ] DynCal C:\WINDOWS\system32\drivers\Dyncal.sys
10:21:44.0189 2828 DynCal ( UnsignedFile.Multi.Generic ) - warning
10:21:44.0189 2828 DynCal - detected UnsignedFile.Multi.Generic (1)
10:21:44.0251 2828 [ 14EA0C26137744636EB25B3FF1F2B02E ] eamon C:\WINDOWS\system32\DRIVERS\eamon.sys
10:21:44.0485 2828 eamon - ok
10:21:44.0563 2828 [ 0887D9C2BE8D940778CAD1E3B85F2A41 ] EapHost C:\WINDOWS\System32\eapsvc.dll
10:21:44.0923 2828 EapHost - ok
10:21:44.0970 2828 [ 366369746D1818FDD8589D1F2C8A6D03 ] ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys
10:21:45.0001 2828 ehdrv - ok
10:21:45.0173 2828 [ 501C1787CA4FAC7F6E9F585E96EB2FAC ] ekrn C:\Program Files\ESET\ESET Smart Security\ekrn.exe
10:21:45.0298 2828 ekrn - ok
10:21:45.0360 2828 [ FD9FC82F134B1C91004FFC76A5AE494B ] ENTECH C:\WINDOWS\system32\DRIVERS\ENTECH.sys
10:21:45.0360 2828 ENTECH ( UnsignedFile.Multi.Generic ) - warning
10:21:45.0360 2828 ENTECH - detected UnsignedFile.Multi.Generic (1)
10:21:45.0407 2828 [ 5F08103444A1B5B2A38EAB729DE0A1A3 ] epfw C:\WINDOWS\system32\DRIVERS\epfw.sys
10:21:45.0438 2828 epfw - ok
10:21:45.0485 2828 [ 03C6C226BC364D23682A8A5AE136F038 ] Epfwndis C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
10:21:45.0501 2828 Epfwndis - ok
10:21:45.0579 2828 [ F3B1BBE8798E3898C031C2F53EECDD93 ] epfwtdi C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
10:21:45.0595 2828 epfwtdi - ok
10:21:45.0642 2828 [ A2A4912798F2BE706ABADD3D30800D16 ] ERSvc C:\WINDOWS\System32\ersvc.dll
10:21:45.0954 2828 ERSvc - ok
10:21:46.0017 2828 [ F7955F5273F7CA5DA13EBEEF4F736C44 ] eusk2par C:\WINDOWS\system32\Drivers\eusk2par.sys
10:21:46.0048 2828 eusk2par ( UnsignedFile.Multi.Generic ) - warning
10:21:46.0048 2828 eusk2par - detected UnsignedFile.Multi.Generic (1)
10:21:46.0095 2828 [ 315FE3219404A7B88E2D35DABC4A085E ] eusk3usb C:\WINDOWS\system32\Drivers\eusk3usb.sys
10:21:46.0188 2828 eusk3usb - ok
10:21:46.0267 2828 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] Eventlog C:\WINDOWS\system32\services.exe
10:21:46.0313 2828 Eventlog - ok
10:21:46.0376 2828 [ A371F11EF07653591C8DE26AFB13CE7F ] EventSystem C:\WINDOWS\system32\es.dll
10:21:46.0470 2828 EventSystem - ok
10:21:46.0485 2828 EverestDriver - ok
10:21:46.0563 2828 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
10:21:46.0813 2828 Fastfat - ok
10:21:46.0860 2828 [ EE9A2B9EA968A792A053C9D1A86BF870 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
10:21:46.0954 2828 FastUserSwitchingCompatibility - ok
10:21:47.0001 2828 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
10:21:47.0266 2828 Fdc - ok
10:21:47.0345 2828 [ E7072827D0B5F9BD99D6961571A38973 ] FET5X86V C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
10:21:47.0423 2828 FET5X86V - ok
10:21:47.0485 2828 [ E9648254056BCE81A85380C0C3647DC4 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5.sys
10:21:47.0751 2828 FETNDIS - ok
10:21:47.0813 2828 [ D3B19A8BAE6C20B4D305C7A72E255EB9 ] FETNDISB C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
10:21:47.0860 2828 FETNDISB - ok
10:21:47.0907 2828 [ AC366695A0796560AA37215AD5762AAF ] Fips C:\WINDOWS\system32\drivers\Fips.sys
10:21:48.0173 2828 Fips - ok
10:21:48.0298 2828 [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
10:21:48.0376 2828 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning
10:21:48.0376 2828 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1)
10:21:48.0423 2828 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:21:48.0641 2828 Flpydisk - ok
10:21:48.0704 2828 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
10:21:48.0923 2828 FltMgr - ok
10:21:49.0032 2828 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
10:21:49.0048 2828 FontCache3.0.0.0 - ok
10:21:49.0079 2828 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:21:49.0345 2828 Fs_Rec - ok
10:21:49.0376 2828 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:21:49.0626 2828 Ftdisk - ok
10:21:49.0673 2828 [ 35A1F815962F3552066C6BE4C969D297 ] getPlus(R) Helper C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
10:21:49.0704 2828 getPlus(R) Helper - ok
10:21:49.0720 2828 GMSIPCI - ok
10:21:49.0798 2828 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:21:50.0048 2828 Gpc - ok
10:21:50.0141 2828 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate1c9aa4c2af4cf40 C:\Program Files\Google\Update\GoogleUpdate.exe
10:21:50.0173 2828 gupdate1c9aa4c2af4cf40 - ok
10:21:50.0188 2828 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
10:21:50.0204 2828 gupdatem - ok
10:21:50.0313 2828 [ FCFE31FB75F8A6295B6B0AF87A626282 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
10:21:50.0563 2828 helpsvc - ok
10:21:50.0579 2828 HidServ - ok
10:21:50.0626 2828 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:21:50.0860 2828 HidUsb - ok
10:21:50.0923 2828 [ 7A6B320928F86BC851530D63C82965D9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
10:21:51.0157 2828 hkmsvc - ok
10:21:51.0188 2828 hpn - ok
10:21:51.0266 2828 [ 287A63BD8509BD78E7978823B38AFA81 ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys
10:21:51.0344 2828 HPZid412 - ok
10:21:51.0391 2828 [ 0B4FDA2657C3E0315EAA57F9C6D4FD1F ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
10:21:51.0438 2828 HPZipr12 - ok
10:21:51.0454 2828 [ 29559DB25258B60510A60C4E470FCE32 ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys
10:21:51.0548 2828 HPZius12 - ok
10:21:51.0594 2828 [ CBD09ED9CF6822177EE85AEA4D8816A2 ] HTCAND32 C:\WINDOWS\system32\Drivers\ANDROIDUSB.sys
10:21:51.0641 2828 HTCAND32 - ok
10:21:51.0719 2828 [ 5C8BC8A28798FD010E7ABC4E0D588CAA ] HTCMonitorService C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
10:21:51.0735 2828 HTCMonitorService - ok
10:21:51.0798 2828 [ 04E3B3554076B8192A668EFE88A682A1 ] htcnprot C:\WINDOWS\system32\DRIVERS\htcnprot.sys
10:21:51.0860 2828 htcnprot - ok
10:21:51.0938 2828 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
10:21:52.0016 2828 HTTP - ok
10:21:52.0079 2828 [ 58FE2F2DA3BC5573F4A35B3760D3125F ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
10:21:52.0329 2828 HTTPFilter - ok
10:21:52.0360 2828 i2omgmt - ok
10:21:52.0376 2828 i2omp - ok
10:21:52.0423 2828 [ C528E27945367191E7BAE364930B6932 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:21:52.0626 2828 i8042prt - ok
10:21:52.0719 2828 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
10:21:52.0735 2828 IDriverT ( UnsignedFile.Multi.Generic ) - warning
10:21:52.0735 2828 IDriverT - detected UnsignedFile.Multi.Generic (1)
10:21:52.0876 2828 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
10:21:52.0985 2828 idsvc - ok
10:21:53.0032 2828 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
10:21:53.0235 2828 Imapi - ok
10:21:53.0297 2828 [ F7B93AAFAD33B2320954C17E26C8D361 ] ImapiService C:\WINDOWS\system32\imapi.exe
10:21:53.0516 2828 ImapiService - ok
10:21:53.0579 2828 [ 26F2D2AA8C5942EBC5F4C626C4B37794 ] InCDFs C:\WINDOWS\system32\DRIVERS\InCDFs.sys
10:21:53.0594 2828 InCDFs - ok
10:21:53.0641 2828 [ 4C5E4899D0FDA39292D8E6E13A7148EE ] InCDPass C:\WINDOWS\system32\DRIVERS\InCDPass.sys
10:21:53.0657 2828 InCDPass - ok
10:21:53.0735 2828 [ A08D75215A7852F7D496B6FC0DF30361 ] InCDRec C:\WINDOWS\system32\DRIVERS\InCDRec.sys
10:21:53.0751 2828 InCDRec - ok
10:21:53.0938 2828 [ 4F1FFD438750EBEF6B93F326E29759B6 ] InCDSrv C:\Program Files\Nero\Tools\InCD\InCDSrv.exe
10:21:54.0079 2828 InCDSrv - ok
10:21:54.0110 2828 ini910u - ok
10:21:54.0157 2828 IntelIde - ok
10:21:54.0235 2828 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
10:21:54.0454 2828 Ip6Fw - ok
10:21:54.0516 2828 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:21:54.0719 2828 IpFilterDriver - ok
10:21:54.0751 2828 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:21:54.0954 2828 IpInIp - ok
10:21:55.0001 2828 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:21:55.0204 2828 IpNat - ok
10:21:55.0251 2828 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:21:55.0454 2828 IPSec - ok
10:21:55.0516 2828 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
10:21:55.0625 2828 IRENUM - ok
10:21:55.0688 2828 [ CC9F8A2D60AED1A51A3AC34C59B987AE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:21:55.0891 2828 isapnp - ok
10:21:56.0016 2828 [ 691B9B7C0CC1653732717D292D6B305D ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe
10:21:56.0063 2828 JavaQuickStarterService - ok
10:21:56.0079 2828 [ 1B6162FE7F66B1A71A4B70F941C4AA9B ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:21:56.0282 2828 Kbdclass - ok
10:21:56.0313 2828 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
10:21:56.0516 2828 kmixer - ok
10:21:56.0594 2828 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
10:21:56.0688 2828 KSecDD - ok
10:21:56.0750 2828 [ 3428E8F86F8ADD36B42FB23542C7B3E4 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
10:21:56.0813 2828 lanmanserver - ok
10:21:56.0891 2828 [ 936C1D110232D23B621CB0196E4F80F0 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
10:21:56.0969 2828 lanmanworkstation - ok
10:21:57.0125 2828 [ 55AFD4A9D5ED4AD40D5215CCDF4D65F3 ] Lavasoft Ad-Aware Service C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
10:21:57.0313 2828 Lavasoft Ad-Aware Service - ok
10:21:57.0360 2828 [ 6C4A3804510AD8E0F0C07B5BE3D44DDB ] Lavasoft Kernexplorer C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
10:21:57.0391 2828 Lavasoft Kernexplorer - ok
10:21:57.0422 2828 [ 336ABE8721CBC3110F1C6426DA633417 ] Lbd C:\WINDOWS\system32\DRIVERS\Lbd.sys
10:21:57.0454 2828 Lbd - ok
10:21:57.0469 2828 lbrtfdc - ok
10:21:57.0563 2828 [ 0AB159F536E3E8F7F07113702A07CCA5 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
10:21:57.0766 2828 LmHosts - ok
10:21:57.0844 2828 [ A3E700D78EEC390F1208098CDCA5C6B6 ] MarvinBus C:\WINDOWS\system32\DRIVERS\MarvinBus.sys
10:21:57.0860 2828 MarvinBus ( UnsignedFile.Multi.Generic ) - warning
10:21:57.0860 2828 MarvinBus - detected UnsignedFile.Multi.Generic (1)
10:21:57.0922 2828 [ FB097BBC1A18F044BD17BD2FCCF97865 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
10:21:57.0938 2828 MBAMProtector - ok
10:21:58.0063 2828 [ BA400ED640BCA1EAE5C727AE17C10207 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
10:21:58.0141 2828 MBAMService - ok
10:21:58.0235 2828 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
10:21:58.0266 2828 MDM - ok
10:21:58.0344 2828 [ 221CD1C815B8A6B79389C3F5D1018DE8 ] Messenger C:\WINDOWS\System32\msgsvc.dll
10:21:58.0563 2828 Messenger - ok
10:21:58.0594 2828 [ A7DA20AB18A1BDAE28B0F349E57DA0D1 ] mf C:\WINDOWS\system32\DRIVERS\mf.sys
10:21:58.0813 2828 mf - ok
10:21:58.0875 2828 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
10:21:59.0063 2828 mnmdd - ok
10:21:59.0110 2828 [ 9A57D046F88F4B69751B11FD40088A61 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
10:21:59.0313 2828 mnmsrvc - ok
10:21:59.0344 2828 [ 44032B0C6D9954D3FD26438330B99EE7 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
10:21:59.0563 2828 Modem - ok
10:21:59.0610 2828 [ 4CB582831DBDE63CE43B45D771218374 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:21:59.0828 2828 Mouclass - ok
10:21:59.0860 2828 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
10:22:00.0047 2828 MountMgr - ok
10:22:00.0110 2828 [ 51A84B690DF519DCF656F780243D953E ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
10:22:00.0141 2828 MozillaMaintenance - ok
10:22:00.0157 2828 mraid35x - ok
10:22:00.0203 2828 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:22:00.0375 2828 MRxDAV - ok
10:22:00.0438 2828 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:22:00.0547 2828 MRxSmb - ok
10:22:00.0594 2828 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D ] MSDTC C:\WINDOWS\system32\msdtc.exe
10:22:00.0797 2828 MSDTC - ok
10:22:00.0860 2828 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
10:22:01.0047 2828 Msfs - ok
10:22:01.0078 2828 MSIServer - ok
10:22:01.0110 2828 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:22:01.0313 2828 MSKSSRV - ok
10:22:01.0360 2828 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:22:01.0578 2828 MSPCLOCK - ok
10:22:01.0610 2828 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
10:22:01.0813 2828 MSPQM - ok
10:22:01.0891 2828 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:22:02.0094 2828 mssmbios - ok
10:22:02.0156 2828 MSSQL$SPZSQL2012 - ok
10:22:02.0266 2828 [ CB7524C21727404BD3140DCA32DEB7DE ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe
10:22:02.0281 2828 MSSQLServerADHelper ( UnsignedFile.Multi.Generic ) - warning
10:22:02.0281 2828 MSSQLServerADHelper - detected UnsignedFile.Multi.Generic (1)
10:22:02.0328 2828 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
10:22:02.0531 2828 MSTEE - ok
10:22:02.0594 2828 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
10:22:02.0641 2828 Mup - ok
10:22:02.0672 2828 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:22:02.0860 2828 NABTSFEC - ok
10:22:02.0938 2828 [ 6EA362E9DB03D44F6B996F4D8BE237E9 ] napagent C:\WINDOWS\System32\qagentrt.dll
10:22:03.0125 2828 napagent - ok
10:22:03.0219 2828 [ 9D1CCE440552500DED3A62F9D779CDB4 ] NAUpdate C:\Program Files\Nero\Update\NASvc.exe
10:22:03.0266 2828 NAUpdate - ok
10:22:03.0406 2828 [ 3BAE2BFCB6D69E19C8373F635DD544DC ] NBService C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
10:22:03.0516 2828 NBService - ok
10:22:03.0563 2828 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
10:22:03.0766 2828 NDIS - ok
10:22:03.0797 2828 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:22:04.0000 2828 NdisIP - ok
10:22:04.0031 2828 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:22:04.0109 2828 NdisTapi - ok
10:22:04.0125 2828 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:22:04.0328 2828 Ndisuio - ok
10:22:04.0406 2828 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:22:04.0594 2828 NdisWan - ok
10:22:04.0641 2828 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
10:22:04.0719 2828 NDProxy - ok
10:22:04.0734 2828 [ 917A6788B6054CBA5BCD5C8C8BADEF74 ] NeroRegInCDSrv C:\Program Files\Nero\Tools\InCD\NBHRegInCDSrv.exe
10:22:04.0766 2828 NeroRegInCDSrv - ok
10:22:04.0797 2828 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
10:22:04.0969 2828 NetBIOS - ok
10:22:05.0000 2828 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
10:22:05.0188 2828 NetBT - ok
10:22:05.0281 2828 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDE C:\WINDOWS\system32\netdde.exe
10:22:05.0469 2828 NetDDE - ok
10:22:05.0500 2828 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
10:22:05.0672 2828 NetDDEdsdm - ok
10:22:05.0703 2828 [ ED0A176354487CEED65B80A7148AB739 ] Netlogon C:\WINDOWS\system32\lsass.exe
10:22:05.0906 2828 Netlogon - ok
10:22:05.0938 2828 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40 ] Netman C:\WINDOWS\System32\netman.dll
10:22:06.0141 2828 Netman - ok
10:22:06.0203 2828 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:22:06.0344 2828 NetTcpPortSharing - ok
10:22:06.0391 2828 [ 53267E3EF363C9938A1790BBB3D55B12 ] NetworkX C:\WINDOWS\system32\ckldrv.sys
10:22:06.0406 2828 NetworkX ( UnsignedFile.Multi.Generic ) - warning
10:22:06.0406 2828 NetworkX - detected UnsignedFile.Multi.Generic (1)
10:22:06.0469 2828 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
10:22:06.0672 2828 NIC1394 - ok
10:22:06.0719 2828 [ 39EE7C3BFBC64BA87CC8CF67386E814C ] Nla C:\WINDOWS\System32\mswsock.dll
10:22:06.0766 2828 Nla - ok
10:22:06.0875 2828 [ 193FA51DDDD0BFFDED1C340F0434999A ] NMIndexingService C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
10:22:06.0906 2828 NMIndexingService - ok
10:22:06.0969 2828 [ 79EA5A1B343DB2F5187758E00195D9BD ] NmPar C:\WINDOWS\system32\DRIVERS\NmPar.sys
10:22:06.0984 2828 NmPar ( UnsignedFile.Multi.Generic ) - warning
10:22:06.0984 2828 NmPar - detected UnsignedFile.Multi.Generic (1)
10:22:07.0031 2828 [ 27F715B99867D1C19D83327800976719 ] nmserial C:\WINDOWS\system32\DRIVERS\nmserial.sys
10:22:07.0047 2828 nmserial ( UnsignedFile.Multi.Generic ) - warning
10:22:07.0047 2828 nmserial - detected UnsignedFile.Multi.Generic (1)
10:22:07.0094 2828 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\WINDOWS\system32\drivers\ccdcmb.sys
10:22:07.0344 2828 nmwcd - ok
10:22:07.0391 2828 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\WINDOWS\system32\drivers\ccdcmbo.sys
10:22:07.0516 2828 nmwcdc - ok
10:22:07.0562 2828 [ B9730495E0CF674680121E34BD95A73B ] npf C:\WINDOWS\system32\drivers\npf.sys
10:22:07.0578 2828 npf - ok
10:22:07.0625 2828 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
10:22:07.0812 2828 Npfs - ok
10:22:07.0812 2828 NTACCESS - ok
10:22:07.0875 2828 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
10:22:08.0125 2828 Ntfs - ok
10:22:08.0156 2828 [ ED0A176354487CEED65B80A7148AB739 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
10:22:08.0359 2828 NtLmSsp - ok
10:22:08.0453 2828 [ 023DD70573D644F3D9C8B1258A7BFD08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
10:22:08.0719 2828 NtmsSvc - ok
10:22:08.0766 2828 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
10:22:08.0969 2828 Null - ok
10:22:09.0109 2828 [ 971CC632A2F4152BF295864D4AA55782 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:22:09.0328 2828 nv - ok
10:22:09.0359 2828 [ 8FB3996085D399475BACE196CA981A0A ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
10:22:09.0406 2828 NVSvc - ok
10:22:09.0469 2828 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:22:09.0656 2828 NwlnkFlt - ok
10:22:09.0719 2828 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:22:09.0906 2828 NwlnkFwd - ok
10:22:09.0984 2828 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
10:22:10.0203 2828 ohci1394 - ok
10:22:10.0234 2828 [ 46F8DB73B4A53E543F8E371DC7C75BAE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
10:22:10.0437 2828 Parport - ok
10:22:10.0547 2828 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
10:22:10.0750 2828 PartMgr - ok
10:22:10.0828 2828 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
10:22:11.0015 2828 ParVdm - ok
10:22:11.0078 2828 [ 9987ABA0E5DD0D46C95076B157B38C06 ] PassThru Service C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
10:22:11.0109 2828 PassThru Service ( UnsignedFile.Multi.Generic ) - warning
10:22:11.0109 2828 PassThru Service - detected UnsignedFile.Multi.Generic (1)
10:22:11.0172 2828 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
10:22:11.0265 2828 pccsmcfd - ok
10:22:11.0297 2828 [ 6CE351D149CB4BEFC702951E471E1730 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
10:22:11.0500 2828 PCI - ok
10:22:11.0531 2828 PCIDump - ok
10:22:11.0562 2828 PCIIde - ok
10:22:11.0625 2828 [ 4FC31E6C19A5CE5198B1ABFF94CAE758 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
10:22:11.0828 2828 Pcmcia - ok
10:22:11.0890 2828 [ 5B6C11DE7E839C05248CED8825470FEF ] pcouffin C:\WINDOWS\system32\Drivers\pcouffin.sys
10:22:11.0922 2828 pcouffin ( UnsignedFile.Multi.Generic ) - warning
10:22:11.0922 2828 pcouffin - detected UnsignedFile.Multi.Generic (1)
10:22:11.0953 2828 PDCOMP - ok
10:22:11.0984 2828 PDFRAME - ok
10:22:12.0000 2828 PDRELI - ok
10:22:12.0031 2828 PDRFRAME - ok
10:22:12.0047 2828 perc2 - ok
10:22:12.0078 2828 perc2hib - ok
10:22:12.0219 2828 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\WINDOWS\system32\IoctlSvc.exe
10:22:12.0250 2828 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - warning
10:22:12.0250 2828 PLFlash DeviceIoControl Service - detected UnsignedFile.Multi.Generic (1)
10:22:12.0297 2828 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] PlugPlay C:\WINDOWS\system32\services.exe
10:22:12.0343 2828 PlugPlay - ok
10:22:12.0390 2828 [ 5C1CADD1CB67C0B9D8A84EC6E4D6B5CC ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.exe
10:22:12.0437 2828 Pml Driver HPZ12 - ok
10:22:12.0515 2828 [ A9D6B1E7EF097C7F3B5DC4F56C0E7386 ] PnkBstrA C:\WINDOWS\system32\PnkBstrA.exe
10:22:12.0547 2828 PnkBstrA - ok
10:22:12.0578 2828 [ ED0A176354487CEED65B80A7148AB739 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
10:22:12.0781 2828 PolicyAgent - ok
10:22:12.0859 2828 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:22:13.0062 2828 PptpMiniport - ok
10:22:13.0078 2828 [ ED0A176354487CEED65B80A7148AB739 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
10:22:13.0281 2828 ProtectedStorage - ok
10:22:13.0328 2828 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
10:22:13.0547 2828 PSched - ok
10:22:13.0625 2828 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:22:13.0812 2828 Ptilink - ok
10:22:13.0843 2828 ql1080 - ok
10:22:13.0859 2828 Ql10wnt - ok
10:22:13.0875 2828 ql12160 - ok
10:22:13.0906 2828 ql1240 - ok
10:22:13.0937 2828 ql1280 - ok
10:22:13.0968 2828 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:22:14.0172 2828 RasAcd - ok
10:22:14.0250 2828 [ 2B5E44EA009F2F374B980E1E9A70635D ] RasAuto C:\WINDOWS\System32\rasauto.dll
10:22:14.0468 2828 RasAuto - ok
10:22:14.0500 2828 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:22:14.0703 2828 Rasl2tp - ok
10:22:14.0812 2828 [ D57554C664B64604BD1EE13EA2C07E77 ] RasMan C:\WINDOWS\System32\rasmans.dll
10:22:15.0031 2828 RasMan - ok
10:22:15.0062 2828 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:22:15.0265 2828 RasPppoe - ok
10:22:15.0312 2828 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
10:22:15.0500 2828 Raspti - ok
10:22:15.0593 2828 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:22:15.0859 2828 Rdbss - ok
10:22:15.0906 2828 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:22:16.0093 2828 RDPCDD - ok
10:22:16.0187 2828 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
10:22:16.0468 2828 rdpdr - ok
10:22:16.0609 2828 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
10:22:16.0734 2828 RDPWD - ok
10:22:16.0843 2828 [ C0D9D9711CB74EE9BC66353D8CBDAB0E ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
10:22:17.0078 2828 RDSessMgr - ok
10:22:17.0140 2828 [ 58F6DD6484B0A6F83AAD78295E39E702 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
10:22:17.0156 2828 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\redbook.sys. Real md5: 58F6DD6484B0A6F83AAD78295E39E702, Fake md5: 611BFD220305BE3A85AE876EA47D4AA5
10:22:17.0156 2828 redbook ( Virus.Win32.ZAccess.aml ) - infected
10:22:17.0156 2828 redbook - detected Virus.Win32.ZAccess.aml (0)
10:22:17.0218 2828 [ 127C26B5371651043450E52542099ABA ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
10:22:17.0406 2828 RemoteAccess - ok
10:22:17.0484 2828 [ 8F31505484A190D5B22274708799F4EC ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
10:22:17.0656 2828 RemoteRegistry - ok
10:22:17.0718 2828 [ 718B3BDC0BC3C2F7D065A53D26202AF9 ] RpcLocator C:\WINDOWS\system32\locator.exe
10:22:17.0921 2828 RpcLocator - ok
10:22:17.0968 2828 [ BE27674D1CBC3214AEC84B4336A38BBF ] RpcSs C:\WINDOWS\system32\rpcss.dll
10:22:18.0015 2828 RpcSs - ok
10:22:18.0078 2828 [ 09AB2E71E58B078038E3BFDBA7FFC984 ] RSVP C:\WINDOWS\system32\rsvp.exe
10:22:18.0265 2828 RSVP - ok
10:22:18.0312 2828 [ ED0A176354487CEED65B80A7148AB739 ] SamSs C:\WINDOWS\system32\lsass.exe
10:22:18.0484 2828 SamSs - ok
10:22:18.0531 2828 [ EB4A2B5FAA3DECD33ED682A5569E287F ] SbFw C:\WINDOWS\system32\drivers\SbFw.sys
10:22:18.0578 2828 SbFw - ok
10:22:18.0624 2828 [ F27B38D70B7621378161D6F48BE04D2C ] SBFWIMCL C:\WINDOWS\system32\DRIVERS\sbfwim.sys
10:22:18.0640 2828 SBFWIMCL - ok
10:22:18.0656 2828 [ F27B38D70B7621378161D6F48BE04D2C ] SBFWIMCLMP C:\WINDOWS\system32\DRIVERS\SBFWIM.sys
10:22:18.0687 2828 SBFWIMCLMP - ok
10:22:18.0734 2828 [ 53E5E7DC26BB920B97F258BBD52ABFDC ] sbhips C:\WINDOWS\system32\drivers\sbhips.sys
10:22:18.0749 2828 sbhips - ok
10:22:18.0796 2828 [ 0505DA5D357F18A5D42FC5DEDE6BC9A0 ] SBRE C:\WINDOWS\system32\drivers\SBREdrv.sys
10:22:18.0812 2828 SBRE - ok
10:22:18.0874 2828 [ 44062A740434B7C3946096D615AAA91C ] SbTis C:\WINDOWS\system32\drivers\sbtis.sys
10:22:18.0906 2828 SbTis - ok
10:22:18.0968 2828 [ 410046E401EB11E1E6749E9DEEA41D4A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
10:22:19.0156 2828 SCardSvr - ok
10:22:19.0218 2828 [ 3FF232A7731621B8902D81D42418C93C ] Schedule C:\WINDOWS\system32\schedsvc.dll
10:22:19.0421 2828 Schedule - ok
10:22:19.0499 2828 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:22:19.0624 2828 Secdrv - ok
10:22:19.0671 2828 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6 ] seclogon C:\WINDOWS\System32\seclogon.dll
10:22:19.0874 2828 seclogon - ok
10:22:19.0953 2828 [ A530B75C10C23C9AB28FDB6CE719E21F ] SENS C:\WINDOWS\system32\sens.dll
10:22:20.0140 2828 SENS - ok
10:22:20.0203 2828 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
10:22:20.0421 2828 serenum - ok
10:22:20.0484 2828 [ B842729337C9B921615C40D3C1A1AF96 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
10:22:20.0671 2828 Serial - ok
10:22:20.0718 2828 [ 61490899036B14DEDC24BABD847D7001 ] sermouse C:\WINDOWS\system32\DRIVERS\sermouse.sys
10:22:20.0906 2828 sermouse - ok
10:22:20.0999 2828 [ F31E9531AF225CA25350D5E87E999B31 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
10:22:21.0093 2828 ServiceLayer - ok
10:22:21.0171 2828 SetupNTGLM7X - ok
10:22:21.0218 2828 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
10:22:21.0421 2828 Sfloppy - ok
10:22:21.0468 2828 [ EE9A2B9EA968A792A053C9D1A86BF870 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
10:22:21.0499 2828 ShellHWDetection - ok
10:22:21.0531 2828 Simbad - ok
10:22:21.0890 2828 [ 23E3C83DFF7B09A97B01A85ED8A44478 ] Skype C2C Service C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
10:22:22.0234 2828 Skype C2C Service - ok
10:22:22.0312 2828 [ 8C4F0DCC6A5100D48F9B2F950CDD220F ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
10:22:22.0343 2828 SkypeUpdate - ok
10:22:22.0406 2828 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:22:22.0609 2828 SLIP - ok
10:22:22.0640 2828 Sparrow - ok
10:22:22.0702 2828 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
10:22:22.0874 2828 splitter - ok
10:22:22.0921 2828 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
10:22:22.0984 2828 Spooler - ok
10:22:23.0062 2828 [ 71E276F6D189413266EA22171806597B ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
10:22:23.0062 2828 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 71E276F6D189413266EA22171806597B
10:22:23.0062 2828 sptd ( LockedFile.Multi.Generic ) - warning
10:22:23.0062 2828 sptd - detected LockedFile.Multi.Generic (1)
10:22:23.0093 2828 SQLAgent$SPZSQL2012 - ok
10:22:23.0124 2828 [ 94610C8653635E4459316A0050D55CE7 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
10:22:23.0218 2828 sr - ok
10:22:23.0281 2828 [ 35B91147124F64AC8081A2EDB9EA4DEE ] srservice C:\WINDOWS\system32\srsvc.dll
10:22:23.0390 2828 srservice - ok
10:22:23.0468 2828 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
10:22:23.0609 2828 Srv - ok
10:22:23.0671 2828 [ BECD5271DC4E3B7C3D035F790FCBC1E5 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
10:22:23.0765 2828 SSDPSRV - ok
10:22:23.0859 2828 [ C1CDD9275F6A115BB0AE1D55D8D27BA6 ] stisvc C:\WINDOWS\system32\wiaservc.dll
10:22:24.0093 2828 stisvc - ok
10:22:24.0140 2828 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:22:24.0327 2828 streamip - ok
10:22:24.0374 2828 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
10:22:24.0562 2828 swenum - ok
10:22:24.0640 2828 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
10:22:24.0796 2828 swmidi - ok
10:22:24.0812 2828 SwPrv - ok
10:22:24.0843 2828 symc810 - ok
10:22:24.0890 2828 symc8xx - ok
10:22:24.0905 2828 sym_hi - ok
10:22:24.0937 2828 sym_u3 - ok
10:22:24.0984 2828 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
10:22:25.0171 2828 sysaudio - ok
10:22:25.0234 2828 [ CE06F01B88ACE199A1BF460CAC29C110 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
10:22:25.0421 2828 SysmonLog - ok
10:22:25.0484 2828 [ 846B7C0E3F6370CDCCE157A5B36E70CD ] tap0801 C:\WINDOWS\system32\DRIVERS\tap0801.sys
10:22:25.0515 2828 tap0801 ( UnsignedFile.Multi.Generic ) - warning
10:22:25.0515 2828 tap0801 - detected UnsignedFile.Multi.Generic (1)
10:22:25.0593 2828 [ C2546CD7A398476F9DF5614B2AE160E8 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
10:22:25.0780 2828 TapiSrv - ok
10:22:25.0859 2828 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:22:25.0937 2828 Tcpip - ok
10:22:25.0984 2828 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
10:22:26.0171 2828 TDPIPE - ok
10:22:26.0218 2828 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
10:22:26.0390 2828 TDTCP - ok
10:22:26.0562 2828 [ C9B9373A0A430C11F0213E359D0772B2 ] TeamViewer7 C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
10:22:26.0796 2828 TeamViewer7 - ok
10:22:26.0843 2828 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
10:22:27.0062 2828 TermDD - ok
10:22:27.0124 2828 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E ] TermService C:\WINDOWS\System32\termsrv.dll
10:22:27.0327 2828 TermService - ok
10:22:27.0358 2828 [ EE9A2B9EA968A792A053C9D1A86BF870 ] Themes C:\WINDOWS\System32\shsvcs.dll
10:22:27.0374 2828 Themes - ok
10:22:27.0437 2828 [ CD0CC7B167D78043A41C98D4921EFB54 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
10:22:27.0546 2828 TlntSvr - ok
10:22:27.0562 2828 TosIde - ok
10:22:27.0624 2828 [ 38853304CCB938D30E0C4CDE8D2C2A8A ] TrkWks C:\WINDOWS\system32\trkwks.dll
10:22:27.0812 2828 TrkWks - ok
10:22:27.0843 2828 [ D85938F272D1BCF3DB3A31FC0A048928 ] uagp35 C:\WINDOWS\system32\DRIVERS\uagp35.sys
10:22:28.0030 2828 uagp35 - ok
10:22:28.0062 2828 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
10:22:28.0265 2828 Udfs - ok
10:22:28.0390 2828 udpproxy - ok
10:22:28.0437 2828 ultra - ok
10:22:28.0499 2828 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
10:22:28.0733 2828 Update - ok
10:22:28.0812 2828 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E ] upnphost C:\WINDOWS\System32\upnphost.dll
10:22:28.0921 2828 upnphost - ok
10:22:28.0983 2828 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
10:22:29.0093 2828 upperdev - ok
10:22:29.0140 2828 [ 20A0F6A11959E92908717D09E87D670D ] UPS C:\WINDOWS\System32\ups.exe
10:22:29.0327 2828 UPS - ok
10:22:29.0405 2828 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:22:29.0593 2828 usbccgp - ok
10:22:29.0655 2828 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:22:29.0843 2828 usbehci - ok
10:22:29.0874 2828 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:22:30.0061 2828 usbhub - ok
10:22:30.0124 2828 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:22:30.0296 2828 usbprint - ok
10:22:30.0343 2828 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:22:30.0530 2828 usbscan - ok
10:22:30.0577 2828 [ 1C888B000C2F9492F4B15B5B6B84873E ] usbser C:\WINDOWS\system32\drivers\usbser.sys
10:22:30.0749 2828 usbser - ok
10:22:30.0811 2828 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
10:22:30.0921 2828 UsbserFilt - ok
10:22:30.0999 2828 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:22:31.0186 2828 USBSTOR - ok
10:22:31.0233 2828 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:22:31.0421 2828 usbuhci - ok
10:22:31.0452 2828 [ 63BBFCA7F390F4C49ED4B96BFB1633E0 ] usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys
10:22:31.0640 2828 usbvideo - ok
10:22:31.0686 2828 [ B6CC50279D6CD28E090A5D33244ADC9A ] usb_rndisx C:\WINDOWS\system32\DRIVERS\usb8023x.sys
10:22:31.0874 2828 usb_rndisx - ok
10:22:31.0921 2828 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
10:22:32.0108 2828 VgaSave - ok
10:22:32.0171 2828 [ 4B039BBD037B01F5DB5A144C837F283A ] viaagp1 C:\WINDOWS\system32\DRIVERS\viaagp1.sys
10:22:32.0218 2828 viaagp1 - ok
10:22:32.0280 2828 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
10:22:32.0452 2828 ViaIde - ok
10:22:32.0530 2828 [ EBE101C01D80A42868F57B327BE1B564 ] viasraid C:\WINDOWS\system32\DRIVERS\viasraid.sys
10:22:32.0608 2828 viasraid - ok
10:22:32.0655 2828 [ 28A4B296B47782173C346E376CB374D1 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
10:22:32.0843 2828 VolSnap - ok
10:22:32.0905 2828 [ D6BA1A63D9E00933F1CD2A885573AFB2 ] VSS C:\WINDOWS\System32\vssvc.exe
10:22:33.0030 2828 VSS - ok
10:22:33.0077 2828 [ FA4E1CDBA256787F2149F4AAD07BC91F ] W32Time C:\WINDOWS\system32\w32time.dll
10:22:33.0249 2828 W32Time - ok
10:22:33.0296 2828 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:22:33.0499 2828 Wanarp - ok
10:22:33.0608 2828 [ D918617B46457B9AC28027722E30F647 ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys
10:22:33.0686 2828 Wdf01000 - ok
10:22:33.0718 2828 WDICA - ok
10:22:33.0764 2828 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
10:22:33.0952 2828 wdmaud - ok
10:22:34.0030 2828 [ 47AE51048A82DFA1CD6B51D369F7E169 ] WebClient C:\WINDOWS\System32\webclnt.dll
10:22:34.0218 2828 WebClient - ok
10:22:34.0264 2828 WFIOCTL - ok
10:22:34.0389 2828 [ E488332126E3B1182D2B8A0C35408EC6 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
10:22:34.0577 2828 winmgmt - ok
10:22:34.0686 2828 [ 4D34CEDD74BDBF2B6A935EAE3BF80543 ] WinRM C:\WINDOWS\system32\WsmSvc.dll
10:22:34.0842 2828 WinRM - ok
10:22:34.0936 2828 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
10:22:35.0092 2828 WmdmPmSN - ok
10:22:35.0171 2828 [ 0171CFF34BBA8C5977F18C48D8AEF8C6 ] Wmi C:\WINDOWS\System32\advapi32.dll
10:22:35.0249 2828 Wmi - ok
10:22:35.0342 2828 [ 23F6F03272F7E5679F1F050AED5ACEE6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
10:22:35.0530 2828 WmiApSrv - ok
10:22:35.0624 2828 [ 3739866D20ABD42F26A7B85F9E2560AF ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
10:22:35.0733 2828 WMPNetworkSvc - ok
10:22:35.0780 2828 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
10:22:35.0796 2828 WpdUsb - ok
10:22:35.0905 2828 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
10:22:35.0983 2828 WPFFontCache_v0400 - ok
10:22:36.0030 2828 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
10:22:36.0233 2828 WS2IFSL - ok
10:22:36.0264 2828 WSearch - ok
10:22:36.0342 2828 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:22:36.0530 2828 WSTCODEC - ok
10:22:36.0592 2828 [ EAA6324F51214D2F6718977EC9CE0DEF ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:22:36.0655 2828 WudfPf - ok
10:22:36.0717 2828 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:22:36.0764 2828 WudfRd - ok
10:22:36.0827 2828 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
10:22:36.0889 2828 WudfSvc - ok
10:22:36.0967 2828 [ A27D4BA7264C0BF52F32D10405BEA1D4 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
10:22:37.0249 2828 WZCSVC - ok
10:22:37.0311 2828 [ EAA4BB9EDB3FB10CF8979FE65E63658F ] xmlprov C:\WINDOWS\System32\xmlprov.dll
10:22:37.0514 2828 xmlprov - ok
10:22:37.0577 2828 ================ Scan global ===============================
10:22:37.0639 2828 [ F36278E42C8C5DF03CE17DAC8231C91C ] C:\WINDOWS\system32\basesrv.dll
10:22:37.0702 2828 [ F3FA14A297BC687D0B51289D034033C9 ] C:\WINDOWS\system32\winsrv.dll
10:22:37.0749 2828 [ F3FA14A297BC687D0B51289D034033C9 ] C:\WINDOWS\system32\winsrv.dll
10:22:37.0780 2828 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] C:\WINDOWS\system32\services.exe
10:22:37.0780 2828 [Global] - ok
10:22:37.0780 2828 ================ Scan MBR ==================================
10:22:37.0811 2828 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
10:22:38.0092 2828 \Device\Harddisk0\DR0 - ok
10:22:38.0092 2828 ================ Scan VBR ==================================
10:22:38.0124 2828 [ 719068D06DF77F727E6F2FD5BA6232B4 ] \Device\Harddisk0\DR0\Partition1
10:22:38.0124 2828 \Device\Harddisk0\DR0\Partition1 - ok
10:22:38.0124 2828 ============================================================
10:22:38.0124 2828 Scan finished
10:22:38.0124 2828 ============================================================
10:22:38.0295 1140 Detected object count: 20
10:22:38.0295 1140 Actual detected object count: 20
10:23:26.0871 1140 Ad-Watch Connect Filter ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0871 1140 Ad-Watch Connect Filter ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0871 1140 Ad-Watch Real-Time Scanner ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0871 1140 Ad-Watch Real-Time Scanner ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0871 1140 Ad-Watch Registry Filter ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0871 1140 Ad-Watch Registry Filter ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0871 1140 cdrbsdrv ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0871 1140 cdrbsdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0871 1140 DynCal ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0871 1140 DynCal ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0871 1140 ENTECH ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0871 1140 ENTECH ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0887 1140 eusk2par ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0887 1140 eusk2par ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0887 1140 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0887 1140 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0903 1140 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0903 1140 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0903 1140 MarvinBus ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0903 1140 MarvinBus ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0918 1140 MSSQLServerADHelper ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0918 1140 MSSQLServerADHelper ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0918 1140 NetworkX ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0918 1140 NetworkX ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0918 1140 NmPar ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0918 1140 NmPar ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0918 1140 nmserial ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0918 1140 nmserial ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0918 1140 PassThru Service ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0918 1140 PassThru Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0918 1140 pcouffin ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0918 1140 pcouffin ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0918 1140 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0918 1140 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:26.0918 1140 redbook ( Virus.Win32.ZAccess.aml ) - skipped by user
10:23:26.0918 1140 redbook ( Virus.Win32.ZAccess.aml ) - User select action: Skip
10:23:26.0934 1140 sptd ( LockedFile.Multi.Generic ) - skipped by user
10:23:26.0934 1140 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
10:23:26.0934 1140 tap0801 ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:26.0934 1140 tap0801 ( UnsignedFile.Multi.Generic ) - User select action: Skip

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#4 Příspěvek od Umbos »

re:
Přílohy
TDSSKiller.2.8.15.0_10.02.2013_11.26.48_log.rar
(18.1 KiB) Staženo 11 x

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#5 Příspěvek od Umbos »

re:
Přílohy
kontrola.rar
(60.06 KiB) Staženo 15 x

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#6 Příspěvek od Umbos »

re:
Přílohy
log.rar
(14.15 KiB) Staženo 17 x

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#7 Příspěvek od Umbos »

nod uz nic po kontrole nenasel.

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#8 Příspěvek od Umbos »

re:
Přílohy
AdwCleaner[R1].rar
(3.13 KiB) Staženo 13 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119524
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomoc-Win32/Kryptik.ASUR trojan

#9 Příspěvek od Rudy »

Omluva za vstup. Toto vlákno patří do jiné sekce. Pro příště žádám uživatele, aby věnoval více pozornosti umísťování svých příspěvků. Děkuji a přesouvám do správné sekce.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#10 Příspěvek od Umbos »

myslim ze je vse jak ma byt, jsem rad ze to slo vyresit, Díky moc rádci -Naughty-. :closed:

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#11 Příspěvek od Umbos »

omlouvam se ,asi jsem to prehlidl,posilam ted.
Přílohy
TDSSKiller.2.8.15.0_10.02.2013_18.23.01_log.rar
(18.14 KiB) Staženo 12 x

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#12 Příspěvek od Umbos »

promin,ja jsem amater.
Přílohy
TDSSKiller_Quarantine.rar
(47.93 KiB) Staženo 13 x

Umbos
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 10 úno 2013 09:09

Re: Pomoc-Win32/Kryptik.ASUR trojan

#13 Příspěvek od Umbos »

Jeste jednou ti děkuji ! :thumbsup:

Zamčeno