Problémy s PC
Napsal: 19 čer 2010 10:44
Zdravím, Windows Firewall sa mi sám vypína, Firefox neustále mrzne...
Pred dvomi dňami som dostal Yv1.exe . Zabil som proces cez Správcu úloh, odstránil z MS Config a zmazal nositeľa vírusu a aj Yv1 z temp. Potom som to ešte prebehol MBAM ktorí ešte odstránil sráča .dll . Ale niekde tam ešte musí byť. V logu z Hijack This nevidím nič. Ten je už ale zastaralý. Prikladám RSIT:
Logfile of random's system information tool 1.07 (written by random/random)
Run by michal at 2010-06-19 11:38:19
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 49 GB (26%) free of 187 GB
Total RAM: 2047 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:38:25, on 19. 6. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\msconfig.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\michal\Downloads\RSIT.exe
C:\Program Files\trend micro\michal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/ ... ch/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\michal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/stati ... 0.36.0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/f ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: eRecovery Service (eRecoveryService) - Unknown owner - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
--
End of file - 5586 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Crysis Wars(R) Updates.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2552291509-578217736-3520049274-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2552291509-578217736-3520049274-1000UA.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-02-15 4390912]
"eRecoveryService"= []
"Malwarebytes' Anti-Malware"=D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-10-01 718688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"Google Update"=C:\Users\michal\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-26 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Empowering Technology Monitor]
C:\Acer\Empowering Technology\SysMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\michal\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-26 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
D:\Program Files\ICQ7.0\ICQ.exe silent loginmode=4 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M5T8QL3YW3]
C:\Users\michal\AppData\Local\Temp\Yv1.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
D:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"ShutdownWithoutLogon"=1
"NoDispCPL"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=
"NoViewContextMenu"=
"NoFileAssociate"=
"NoFind"=
"NoRun"=
"NoClose"=
"StartMenuLogoff"=
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-06-19 11:38:19 ----D---- C:\rsit
2010-06-18 21:08:17 ----D---- C:\Program Files\Trend Micro
2010-06-18 15:11:43 ----D---- C:\Program Files\VirtualBus
2010-06-12 13:15:11 ----D---- C:\Program Files\Adobe
2010-06-12 08:22:55 ----D---- C:\Program Files\Mozilla Developer Preview 3.7 Alpha 5
2010-06-10 16:48:13 ----SHD---- C:\ProgramData\SecuROM
2010-06-10 16:46:12 ----D---- C:\Windows\system32\xlive
2010-06-10 16:46:12 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2010-06-07 14:08:35 ----D---- C:\ProgramData\Solidshield
2010-06-07 14:05:16 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-06-04 21:12:14 ----A---- C:\GF_Excpt.txt
2010-06-01 20:21:00 ----HDC---- C:\ProgramData\{7451F7D5-591C-4490-8D3B-C73A69A0E782}
2010-06-01 16:27:15 ----HDC---- C:\ProgramData\{5794CDCB-FAB7-4C15-9069-4D8AC02592DE}
2010-06-01 15:31:40 ----HDC---- C:\ProgramData\{0151C9FC-719D-4459-B1E2-4685CC6E62A8}
2010-06-01 15:03:19 ----D---- C:\ProgramData\Electronic Arts
2010-06-01 15:03:10 ----D---- C:\ProgramData\Adobe
2010-06-01 15:03:07 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-06-01 14:06:51 ----RHD---- C:\Users\michal\AppData\Roaming\SecuROM
2010-06-01 14:04:52 ----A---- C:\Windows\system32\CmdLineExt.dll
2010-06-01 14:04:36 ----HDC---- C:\ProgramData\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2010-05-31 11:11:50 ----D---- C:\Program Files\Common Files\Blizzard Entertainment.de367bea.temp
2010-05-31 11:02:28 ----D---- C:\Program Files\Common Files\Blizzard Entertainment.7a8f8d35.temp
2010-05-30 16:46:14 ----D---- C:\Program Files\Common Files\Blizzard Entertainment.temp
2010-05-30 16:45:43 ----D---- C:\ProgramData\Blizzard
2010-05-30 10:13:50 ----D---- C:\ProgramData\NVIDIA Corporation
2010-05-30 10:11:55 ----A---- C:\Windows\system32\OpenCL.dll
2010-05-30 10:11:55 ----A---- C:\Windows\system32\nvwgf2um.dll
2010-05-30 10:11:53 ----A---- C:\Windows\system32\nvoglv32.dll
2010-05-30 10:11:51 ----A---- C:\Windows\system32\nvd3dum.dll
2010-05-30 10:11:51 ----A---- C:\Windows\system32\nvcuvid.dll
2010-05-30 10:11:51 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-05-30 10:11:50 ----A---- C:\Windows\system32\nvcuda.dll
2010-05-30 10:11:48 ----A---- C:\Windows\system32\nvcompiler.dll
2010-05-30 10:11:48 ----A---- C:\Windows\system32\nvcod1920.dll
2010-05-30 10:11:48 ----A---- C:\Windows\system32\nvcod.dll
2010-05-29 18:45:50 ----D---- C:\Windows\Minidump
2010-05-21 18:57:26 ----A---- C:\Windows\system32\nvvsvc.exe
2010-05-21 18:57:26 ----A---- C:\Windows\system32\nvmctray.dll
2010-05-21 18:57:26 ----A---- C:\Windows\system32\nvcpl.dll
2010-05-21 18:57:24 ----A---- C:\Windows\system32\nvsvc.dll
2010-05-21 16:15:03 ----D---- C:\Users\michal\AppData\Roaming\GHISLER
======List of files/folders modified in the last 1 months======
2010-06-19 11:38:25 ----D---- C:\Windows\Temp
2010-06-19 11:21:39 ----D---- C:\Users\michal\AppData\Roaming\Skype
2010-06-19 09:41:06 ----D---- C:\Users\michal\AppData\Roaming\skypePM
2010-06-19 07:11:02 ----D---- C:\ProgramData\NVIDIA
2010-06-18 22:14:12 ----D---- C:\Users\michal\AppData\Roaming\vlc
2010-06-18 21:14:15 ----D---- C:\Windows\system32\Tasks
2010-06-18 21:14:14 ----D---- C:\Windows\Tasks
2010-06-18 21:11:13 ----SD---- C:\Windows\Downloaded Program Files
2010-06-18 21:08:17 ----RD---- C:\Program Files
2010-06-18 18:17:50 ----SHD---- C:\Windows\Installer
2010-06-18 17:02:54 ----D---- C:\Users\michal\AppData\Roaming\dvdcss
2010-06-11 06:15:02 ----D---- C:\Windows
2010-06-10 16:56:26 ----SHD---- C:\System Volume Information
2010-06-10 16:48:13 ----HD---- C:\ProgramData
2010-06-10 16:46:54 ----D---- C:\Windows\System32
2010-06-10 10:58:48 ----SD---- C:\Users\michal\AppData\Roaming\Microsoft
2010-06-07 14:05:24 ----RSD---- C:\Windows\assembly
2010-06-07 13:59:16 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-06 07:57:48 ----D---- C:\Windows\system32\LogFiles
2010-06-04 21:48:27 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-06-04 19:07:35 ----D---- C:\Windows\system32\catroot2
2010-06-04 16:04:05 ----D---- C:\Windows\Prefetch
2010-06-03 14:16:49 ----A---- C:\Windows\system32\pbsvc_heroes.exe
2010-06-03 12:43:02 ----D---- C:\Windows\system32\drivers
2010-06-01 15:31:50 ----A---- C:\Windows\system32\pbsvc.exe
2010-06-01 15:03:10 ----D---- C:\Users\michal\AppData\Roaming\Adobe
2010-06-01 15:03:07 ----D---- C:\Program Files\Common Files
2010-06-01 13:54:51 ----D---- C:\Program Files\Electronic Arts
2010-06-01 13:50:06 ----D---- C:\ProgramData\Media Center Programs
2010-05-30 10:14:54 ----D---- C:\Windows\inf
2010-05-30 10:13:31 ----D---- C:\Program Files\NVIDIA Corporation
2010-05-30 10:13:12 ----D---- C:\Windows\system32\catroot
2010-05-30 10:11:38 ----D---- C:\NVIDIA
2010-05-30 10:07:33 ----D---- C:\Windows\Help
2010-05-25 20:27:25 ----D---- C:\Windows\Panther
2010-05-22 03:04:00 ----A---- C:\Windows\system32\nvapi.dll
2010-05-21 16:24:44 ----D---- C:\Program Files\WinRAR
2010-05-20 19:37:00 ----D---- C:\Windows\system32\directx
2010-05-20 19:36:53 ----HD---- C:\Windows\msdownld.tmp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 SBRE;SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [2010-05-12 95024]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-02-14 1740904]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2010-04-29 20952]
R3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2007-05-03 6144]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-05-22 10887624]
R3 Ph3xIB32;Philips 713x VU PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 194560]
S2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys []
S3 aatkjhms;aatkjhms; C:\Windows\system32\drivers\aatkjhms.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-18 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-18 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-18 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-03-27 25280]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-18 35328]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-09-10 62424]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-12-14 61440]
R2 MBAMService;MBAMService; D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 NMSAccess;NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2010-03-04 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-05-21 129640]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-02-02 75064]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-05-21 240232]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe []
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-29 31048]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2006-04-14 87840]
-----------------EOF-----------------
Pred dvomi dňami som dostal Yv1.exe . Zabil som proces cez Správcu úloh, odstránil z MS Config a zmazal nositeľa vírusu a aj Yv1 z temp. Potom som to ešte prebehol MBAM ktorí ešte odstránil sráča .dll . Ale niekde tam ešte musí byť. V logu z Hijack This nevidím nič. Ten je už ale zastaralý. Prikladám RSIT:
Logfile of random's system information tool 1.07 (written by random/random)
Run by michal at 2010-06-19 11:38:19
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 49 GB (26%) free of 187 GB
Total RAM: 2047 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:38:25, on 19. 6. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\msconfig.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\michal\Downloads\RSIT.exe
C:\Program Files\trend micro\michal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/ ... ch/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\michal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/stati ... 0.36.0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/f ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: eRecovery Service (eRecoveryService) - Unknown owner - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
--
End of file - 5586 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Crysis Wars(R) Updates.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2552291509-578217736-3520049274-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2552291509-578217736-3520049274-1000UA.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-02-15 4390912]
"eRecoveryService"= []
"Malwarebytes' Anti-Malware"=D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-10-01 718688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"Google Update"=C:\Users\michal\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-26 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Empowering Technology Monitor]
C:\Acer\Empowering Technology\SysMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\michal\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-26 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
D:\Program Files\ICQ7.0\ICQ.exe silent loginmode=4 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M5T8QL3YW3]
C:\Users\michal\AppData\Local\Temp\Yv1.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
D:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"ShutdownWithoutLogon"=1
"NoDispCPL"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=
"NoViewContextMenu"=
"NoFileAssociate"=
"NoFind"=
"NoRun"=
"NoClose"=
"StartMenuLogoff"=
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-06-19 11:38:19 ----D---- C:\rsit
2010-06-18 21:08:17 ----D---- C:\Program Files\Trend Micro
2010-06-18 15:11:43 ----D---- C:\Program Files\VirtualBus
2010-06-12 13:15:11 ----D---- C:\Program Files\Adobe
2010-06-12 08:22:55 ----D---- C:\Program Files\Mozilla Developer Preview 3.7 Alpha 5
2010-06-10 16:48:13 ----SHD---- C:\ProgramData\SecuROM
2010-06-10 16:46:12 ----D---- C:\Windows\system32\xlive
2010-06-10 16:46:12 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2010-06-07 14:08:35 ----D---- C:\ProgramData\Solidshield
2010-06-07 14:05:16 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-06-04 21:12:14 ----A---- C:\GF_Excpt.txt
2010-06-01 20:21:00 ----HDC---- C:\ProgramData\{7451F7D5-591C-4490-8D3B-C73A69A0E782}
2010-06-01 16:27:15 ----HDC---- C:\ProgramData\{5794CDCB-FAB7-4C15-9069-4D8AC02592DE}
2010-06-01 15:31:40 ----HDC---- C:\ProgramData\{0151C9FC-719D-4459-B1E2-4685CC6E62A8}
2010-06-01 15:03:19 ----D---- C:\ProgramData\Electronic Arts
2010-06-01 15:03:10 ----D---- C:\ProgramData\Adobe
2010-06-01 15:03:07 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-06-01 14:06:51 ----RHD---- C:\Users\michal\AppData\Roaming\SecuROM
2010-06-01 14:04:52 ----A---- C:\Windows\system32\CmdLineExt.dll
2010-06-01 14:04:36 ----HDC---- C:\ProgramData\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2010-05-31 11:11:50 ----D---- C:\Program Files\Common Files\Blizzard Entertainment.de367bea.temp
2010-05-31 11:02:28 ----D---- C:\Program Files\Common Files\Blizzard Entertainment.7a8f8d35.temp
2010-05-30 16:46:14 ----D---- C:\Program Files\Common Files\Blizzard Entertainment.temp
2010-05-30 16:45:43 ----D---- C:\ProgramData\Blizzard
2010-05-30 10:13:50 ----D---- C:\ProgramData\NVIDIA Corporation
2010-05-30 10:11:55 ----A---- C:\Windows\system32\OpenCL.dll
2010-05-30 10:11:55 ----A---- C:\Windows\system32\nvwgf2um.dll
2010-05-30 10:11:53 ----A---- C:\Windows\system32\nvoglv32.dll
2010-05-30 10:11:51 ----A---- C:\Windows\system32\nvd3dum.dll
2010-05-30 10:11:51 ----A---- C:\Windows\system32\nvcuvid.dll
2010-05-30 10:11:51 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-05-30 10:11:50 ----A---- C:\Windows\system32\nvcuda.dll
2010-05-30 10:11:48 ----A---- C:\Windows\system32\nvcompiler.dll
2010-05-30 10:11:48 ----A---- C:\Windows\system32\nvcod1920.dll
2010-05-30 10:11:48 ----A---- C:\Windows\system32\nvcod.dll
2010-05-29 18:45:50 ----D---- C:\Windows\Minidump
2010-05-21 18:57:26 ----A---- C:\Windows\system32\nvvsvc.exe
2010-05-21 18:57:26 ----A---- C:\Windows\system32\nvmctray.dll
2010-05-21 18:57:26 ----A---- C:\Windows\system32\nvcpl.dll
2010-05-21 18:57:24 ----A---- C:\Windows\system32\nvsvc.dll
2010-05-21 16:15:03 ----D---- C:\Users\michal\AppData\Roaming\GHISLER
======List of files/folders modified in the last 1 months======
2010-06-19 11:38:25 ----D---- C:\Windows\Temp
2010-06-19 11:21:39 ----D---- C:\Users\michal\AppData\Roaming\Skype
2010-06-19 09:41:06 ----D---- C:\Users\michal\AppData\Roaming\skypePM
2010-06-19 07:11:02 ----D---- C:\ProgramData\NVIDIA
2010-06-18 22:14:12 ----D---- C:\Users\michal\AppData\Roaming\vlc
2010-06-18 21:14:15 ----D---- C:\Windows\system32\Tasks
2010-06-18 21:14:14 ----D---- C:\Windows\Tasks
2010-06-18 21:11:13 ----SD---- C:\Windows\Downloaded Program Files
2010-06-18 21:08:17 ----RD---- C:\Program Files
2010-06-18 18:17:50 ----SHD---- C:\Windows\Installer
2010-06-18 17:02:54 ----D---- C:\Users\michal\AppData\Roaming\dvdcss
2010-06-11 06:15:02 ----D---- C:\Windows
2010-06-10 16:56:26 ----SHD---- C:\System Volume Information
2010-06-10 16:48:13 ----HD---- C:\ProgramData
2010-06-10 16:46:54 ----D---- C:\Windows\System32
2010-06-10 10:58:48 ----SD---- C:\Users\michal\AppData\Roaming\Microsoft
2010-06-07 14:05:24 ----RSD---- C:\Windows\assembly
2010-06-07 13:59:16 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-06 07:57:48 ----D---- C:\Windows\system32\LogFiles
2010-06-04 21:48:27 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-06-04 19:07:35 ----D---- C:\Windows\system32\catroot2
2010-06-04 16:04:05 ----D---- C:\Windows\Prefetch
2010-06-03 14:16:49 ----A---- C:\Windows\system32\pbsvc_heroes.exe
2010-06-03 12:43:02 ----D---- C:\Windows\system32\drivers
2010-06-01 15:31:50 ----A---- C:\Windows\system32\pbsvc.exe
2010-06-01 15:03:10 ----D---- C:\Users\michal\AppData\Roaming\Adobe
2010-06-01 15:03:07 ----D---- C:\Program Files\Common Files
2010-06-01 13:54:51 ----D---- C:\Program Files\Electronic Arts
2010-06-01 13:50:06 ----D---- C:\ProgramData\Media Center Programs
2010-05-30 10:14:54 ----D---- C:\Windows\inf
2010-05-30 10:13:31 ----D---- C:\Program Files\NVIDIA Corporation
2010-05-30 10:13:12 ----D---- C:\Windows\system32\catroot
2010-05-30 10:11:38 ----D---- C:\NVIDIA
2010-05-30 10:07:33 ----D---- C:\Windows\Help
2010-05-25 20:27:25 ----D---- C:\Windows\Panther
2010-05-22 03:04:00 ----A---- C:\Windows\system32\nvapi.dll
2010-05-21 16:24:44 ----D---- C:\Program Files\WinRAR
2010-05-20 19:37:00 ----D---- C:\Windows\system32\directx
2010-05-20 19:36:53 ----HD---- C:\Windows\msdownld.tmp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 SBRE;SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [2010-05-12 95024]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-02-14 1740904]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2010-04-29 20952]
R3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2007-05-03 6144]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-05-22 10887624]
R3 Ph3xIB32;Philips 713x VU PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 194560]
S2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys []
S3 aatkjhms;aatkjhms; C:\Windows\system32\drivers\aatkjhms.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-18 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-18 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-18 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-03-27 25280]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-18 35328]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-09-10 62424]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-12-14 61440]
R2 MBAMService;MBAMService; D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 NMSAccess;NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2010-03-04 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-05-21 129640]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-02-02 75064]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-05-21 240232]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe []
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-29 31048]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2006-04-14 87840]
-----------------EOF-----------------