Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Worm/Generic_c.ZS

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Herbenni
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 22 dub 2011 10:23

Worm/Generic_c.ZS

#1 Příspěvek od Herbenni »

Zdravím všechny,

po flashce se mi dostal do pc tento virus, byla zasunuta do pc s operačním systémem windows server 2003, kde není antivirus a ted' nejde dostat pryč... antivirus ho nenajde, tváří se, že je všechno v pořádku.
Když strčím flashku do pc s antivirem, najde mi ho rezidentní štít a dá do trezoru, ale nevím jak odstranit virus, pokud už je v pc. Prý jsou na to nástroje na odstranění konkrétního viru, ale nic jsem nenašel :( přidávám log a prosím pomozte... díky





Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-22 11:20:51
Microsoft(R) Windows(R) Server 2003, Standard Edition Service Pack 1
System drive C: has 11 GB (51%) free of 21 GB
Total RAM: 4095 MB (66% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\backupF.job
C:\WINDOWS\tasks\EskoFolderBackup.job
C:\WINDOWS\tasks\Weekly SG-XC 2000 Backup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"bacstray"=C:\Program Files\Broadcom\BACS\BacsTray.exe [2007-02-23 124488]
"openvpn-gui"=C:\Program Files\OpenVPN\bin\openvpn-gui.exe [2005-08-18 99328]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"ShutdownEventCheck"=C:\WINDOWS\system32\dumprep 0 -s []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"=C:\Documents and Settings\Administrator\Desktop\sdsetup_revwire207.exe [2011-04-22 512992]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
Ati2evxx.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
C:\WINDOWS\system32\crypt32.dll [2006-04-04 595968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
C:\WINDOWS\system32\cryptnet.dll [2006-04-04 62464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
C:\WINDOWS\system32\cscdll.dll [2006-04-04 102400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
C:\WINDOWS\system32\dimsntfy.dll [2006-04-04 19456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
C:\WINDOWS\system32\wlnotify.dll [2006-04-04 96768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
C:\WINDOWS\system32\wlnotify.dll [2006-04-04 96768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
C:\WINDOWS\system32\sclgntfy.dll [2006-04-04 19968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
C:\WINDOWS\system32\WlNotify.dll [2006-04-04 96768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
C:\WINDOWS\system32\wlnotify.dll [2006-04-04 96768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
C:\WINDOWS\system32\wlnotify.dll [2006-04-04 96768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\SHELL32.dll [2006-04-04 8379392]
CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\SHELL32.dll [2006-04-04 8379392]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll [2006-04-04 279040]
SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll [2006-04-04 123392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll [2006-04-04 1036800]
Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll [2006-04-04 1036800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=C:\WINDOWS\system32\shell32.dll [2006-04-04 8379392]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=RASSFM
KDCSVC
WDIGEST
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dmadmin]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dmboot.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dmio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dmload.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dmserver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ip6fw.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NtLmSsp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpcdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpwd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdpipe.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdtcp.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\termservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vds]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vgasave.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WZCSVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"disablecad"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=0
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ShowSuperHidden"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"E:\Esko\bg_prog_egscs_v010\bin_ix86\egscssrv.exe"="E:\Esko\bg_prog_egscs_v010\bin_ix86\egscssrv.exe:*:Enabled:EGSCS"
"E:\Esko\bg_prog_egsis_v010\bin_ix86\egsissrv.exe"="E:\Esko\bg_prog_egsis_v010\bin_ix86\egsissrv.exe:*:Enabled:EGSIS"
"E:\Esko\bg_prog_egsis_v010\bin_ix86\EGSystemInfoTool.exe"="E:\Esko\bg_prog_egsis_v010\bin_ix86\EGSystemInfoTool.exe:*:Enabled:EGSISCLT"
"E:\Esko\bg_prog_system_v010\bin_ix86\lmgrd.exe"="E:\Esko\bg_prog_system_v010\bin_ix86\lmgrd.exe:*:Enabled:LMGRD"
"E:\Esko\bg_prog_system_v010\bin_ix86\barco.exe"="E:\Esko\bg_prog_system_v010\bin_ix86\barco.exe:*:Enabled:BARCO"
"C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe"="C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe:*:Enabled:MSSQLSERVER"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\sdbserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\sdbserver.exe:*:Enabled:sdbserver"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\tnsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\tnsrv.exe:*:Enabled:TNServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\goldenretriever.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\goldenretriever.exe:*:Enabled:GoldenRetriever"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\srvlaunch.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\srvlaunch.exe:*:Enabled:ServerLauncher"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\dim_server.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\dim_server.exe:*:Enabled:DIM"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\containerserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\containerserver.exe:*:Enabled:Containerserver"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\ppdsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\ppdsrv.exe:*:Enabled:PpdServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\dpserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\dpserver.exe:*:Enabled:DPServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\configserverget.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\configserverget.exe:*:Enabled:CFSGetServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\ticketsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\ticketsrv.exe:*:Enabled:TicketServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\printsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\printsrv.exe:*:Enabled:PrintServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\prcserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\prcserver.exe:*:Enabled:PRCServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\iplserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\iplserver.exe:*:Enabled:IPLServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\configserverput.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\configserverput.exe:*:Enabled:CFSPutServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\cms.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\cms.exe:*:Enabled:BGCMS"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\screenfiltersrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\screenfiltersrv.exe:*:Enabled:ScreenFilterServer"
"E:\Esko\bg_prog_fastserver_v070\jre\bin\java.exe"="E:\Esko\bg_prog_fastserver_v070\jre\bin\java.exe:*:Enabled:TaskManager"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\tcpserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\tcpserver.exe:*:Enabled:TCPServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\fontsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\fontsrv.exe:*:Enabled:FontServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\logonsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\logonsrv.exe:*:Enabled:LogonServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\cadxsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\cadxsrv.exe:*:Enabled:CADXServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\load.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\load.exe:*:Enabled:LoadServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\fileserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\fileserver.exe:*:Enabled:FileServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\eventbroker.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\eventbroker.exe:*:Enabled:EventBroker"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\cfs.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\cfs.exe:*:Enabled:CFS"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\bgmdw.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\bgmdw.exe:*:Enabled:BGMD"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"E:\Esko\bg_prog_fastserver_v070\jre\bin\java.exe"="E:\Esko\bg_prog_fastserver_v070\jre\bin\java.exe:*:Enabled:WFETasks"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\sdbtask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\sdbtask.exe:*:Enabled:stripping"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\artprotopdftask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\artprotopdftask.exe:*:Enabled:ARTPROTOPDFTASK"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\tifwraptask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\tifwraptask.exe:*:Enabled:tifwraptask"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\ipltask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\ipltask.exe:*:Enabled:ipltask"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frcdi_sparktask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frcdi_sparktask.exe:*:Enabled:FlexRIP-CDISpark"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frbtask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frbtask.exe:*:Enabled:FastRIP-B"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\demotask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\demotask.exe:*:Enabled:DemoTask"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\sdbserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\sdbserver.exe:*:Enabled:sdbserver"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\goldenretriever.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\goldenretriever.exe:*:Enabled:GoldenRetriever"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frfile_stask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frfile_stask.exe:*:Enabled:FlexRIP-File_s"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frfile_dcstask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frfile_dcstask.exe:*:Enabled:FlexRIP-Filedcs"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\ACQ2CTTASK.EXE"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\ACQ2CTTASK.EXE:*:Enabled:ACQ2CTTASK"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\tnsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\tnsrv.exe:*:Enabled:TNServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\srvlaunch.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\srvlaunch.exe:*:Enabled:ServerLauncher"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\archive.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\archive.exe:*:Enabled:Archive"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\normppmltask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\normppmltask.exe:*:Enabled:NormalizePPML"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\fripproof_hp_designjet_task.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\fripproof_hp_designjet_task.exe:*:Enabled:FRipProof-ProoferOutput"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frbitask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frbitask.exe:*:Enabled:FlexRIP-BI"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\dim_server.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\dim_server.exe:*:Enabled:DIM"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\containerserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\containerserver.exe:*:Enabled:Containerserver"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frapprovaltask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frapprovaltask.exe:*:Enabled:FastRIP-Approval"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\psprinttask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\psprinttask.exe:*:Enabled:PSPRINTTASK"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frfile_utask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frfile_utask.exe:*:Enabled:FlexRIP-File_u"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\ppdsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\ppdsrv.exe:*:Enabled:PpdServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\DPServer.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\DPServer.exe:*:Enabled:DPServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\configserverget.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\configserverget.exe:*:Enabled:CFSGetServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\ticketsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\ticketsrv.exe:*:Enabled:TicketServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\restore.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\restore.exe:*:Enabled:Restore"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\export.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\export.exe:*:Enabled:JExport"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\SCCTASK.EXE"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\SCCTASK.EXE:*:Enabled:SCCTASK"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\printsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\printsrv.exe:*:Enabled:PrintServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\PRCServer.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\PRCServer.exe:*:Enabled:PRCServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\IPLServer.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\IPLServer.exe:*:Enabled:IPLServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\configserverput.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\configserverput.exe:*:Enabled:CFSPutServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\cms.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\cms.exe:*:Enabled:BGCMS"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\unwrap.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\unwrap.exe:*:Enabled:Unwrap"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\import.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\import.exe:*:Enabled:JImport"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\dim_task.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\dim_task.exe:*:Enabled:DIMTASK"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\screenfiltersrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\screenfiltersrv.exe:*:Enabled:ScreenFilterServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\vardatatask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\vardatatask.exe:*:Enabled:VarDataTask"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frcdi_compacttask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frcdi_compacttask.exe:*:Enabled:FlexRIP-CDICompact"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\TCPServer.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\TCPServer.exe:*:Enabled:TCPServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\fontsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\fontsrv.exe:*:Enabled:FontServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\logonsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\logonsrv.exe:*:Enabled:LogonServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\Burn.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\Burn.exe:*:Enabled:Burn"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frfilep_task.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frfilep_task.exe:*:Enabled:FlexRIP-Filep"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\frcdi_fullsizetask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\frcdi_fullsizetask.exe:*:Enabled:FlexRIP-CDI"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\dcswraptask.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\dcswraptask.exe:*:Enabled:DCSWRAPTASK"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\cadxsrv.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\cadxsrv.exe:*:Enabled:CADXServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\load.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\load.exe:*:Enabled:LoadServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\fileserver.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\fileserver.exe:*:Enabled:FileServer"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\eventbroker.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\eventbroker.exe:*:Enabled:EventBroker"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\cfs.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\cfs.exe:*:Enabled:CFS"
"E:\Esko\bg_prog_fastserver_v070\bin_ix86\bgmdw.exe"="E:\Esko\bg_prog_fastserver_v070\bin_ix86\bgmdw.exe:*:Enabled:BGMD"
"E:\Esko\bg_prog_egscs_v010\bin_ix86\egscssrv.exe"="E:\Esko\bg_prog_egscs_v010\bin_ix86\egscssrv.exe:*:Enabled:EGSCS"
"E:\Esko\bg_prog_egsis_v010\bin_ix86\egsissrv.exe"="E:\Esko\bg_prog_egsis_v010\bin_ix86\egsissrv.exe:*:Enabled:EGSIS"
"E:\Esko\bg_prog_egsis_v010\bin_ix86\egsysteminfotool.exe"="E:\Esko\bg_prog_egsis_v010\bin_ix86\egsysteminfotool.exe:*:Enabled:EGSISCLT"
"C:\Program Files\NetSupport Manager\client32.exe"="C:\Program Files\NetSupport Manager\client32.exe:*:Enabled:NetSupport Client"
"C:\Program Files\NetSupport Manager\PCICTLUI.EXE"="C:\Program Files\NetSupport Manager\PCICTLUI.EXE:*:Enabled:NetSupport Control"
"E:\Esko\bg_prog_system_v010\bin_ix86\lmgrd.exe"="E:\Esko\bg_prog_system_v010\bin_ix86\lmgrd.exe:*:Enabled:LMGRD"
"E:\Esko\bg_prog_system_v010\bin_ix86\barco.exe"="E:\Esko\bg_prog_system_v010\bin_ix86\barco.exe:*:Enabled:BARCO"
"E:\Esko\bg_prog_system_v010\bin_ix86\esko.exe"="E:\Esko\bg_prog_system_v010\bin_ix86\esko.exe:*:Enabled:ESKO"
"E:\Esko\bg_prog_fastserver_v100\jre\bin\java.exe"="E:\Esko\bg_prog_fastserver_v100\jre\bin\java.exe:*:Enabled:WFETasks"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\sdbtask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\sdbtask.exe:*:Enabled:batchbrix.vrmlexport"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\tifwraptask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\tifwraptask.exe:*:Enabled:tifwraptask"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\ipltask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\ipltask.exe:*:Enabled:ipltask"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\frcdi_sparktask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\frcdi_sparktask.exe:*:Enabled:FlexRIP-CDISpark"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\frbtask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\frbtask.exe:*:Enabled:FastRIP-B"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\demotask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\demotask.exe:*:Enabled:DemoTask"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\artprotopdftask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\artprotopdftask.exe:*:Enabled:ARTPROTOPDFTASK"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\bsshuttlesrv.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\bsshuttlesrv.exe:*:Enabled:ShuttleServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\sdbserver.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\sdbserver.exe:*:Enabled:sdbserver"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\frfile_stask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\frfile_stask.exe:*:Enabled:FlexRIP-File_s"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\frfile_dcstask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\frfile_dcstask.exe:*:Enabled:FlexRIP-Filedcs"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\acq2cttask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\acq2cttask.exe:*:Enabled:ACQ2CTTASK"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\tnsrv.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\tnsrv.exe:*:Enabled:TNServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\goldenretriever.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\goldenretriever.exe:*:Enabled:GoldenRetriever"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\srvlaunch.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\srvlaunch.exe:*:Enabled:ServerLauncher"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\fripproof_hp_designjet_task.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\fripproof_hp_designjet_task.exe:*:Enabled:FRipProof-ProoferOutput"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\frbitask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\frbitask.exe:*:Enabled:FlexRIP-BI"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\archive.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\archive.exe:*:Enabled:Archive"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\dim_server.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\dim_server.exe:*:Enabled:DIM"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\containerserver.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\containerserver.exe:*:Enabled:Containerserver"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\frapprovaltask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\frapprovaltask.exe:*:Enabled:FastRIP-Approval"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\psprinttask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\psprinttask.exe:*:Enabled:PSPRINTTASK"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\frfile_utask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\frfile_utask.exe:*:Enabled:FlexRIP-File_u"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\ppdsrv.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\ppdsrv.exe:*:Enabled:PpdServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\dpserver.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\dpserver.exe:*:Enabled:DPServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\configserverget.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\configserverget.exe:*:Enabled:CFSGetServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\ticketsrv.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\ticketsrv.exe:*:Enabled:TicketServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\scctask.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\scctask.exe:*:Enabled:SCCTASK"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\restore.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\restore.exe:*:Enabled:Restore"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\export.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\export.exe:*:Enabled:JExport"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\printsrv.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\printsrv.exe:*:Enabled:PrintServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\prcserver.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\prcserver.exe:*:Enabled:PRCServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\iplserver.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\iplserver.exe:*:Enabled:IPLServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\configserverput.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\configserverput.exe:*:Enabled:CFSPutServer"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\cms.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\cms.exe:*:Enabled:BGCMS"
"E:\Esko\bg_prog_fastserver_v100\bin_ix86\unwrap.exe"="E:\Esko\bg_prog_fastserver_v100\bin_ix86\unwrap.exe:*:Enabled:Unwrap"

======List of files/folders created in the last 1 months======

2011-04-22 11:19:15 ----D---- C:\Program Files\trend micro
2011-04-22 11:19:14 ----D---- C:\rsit
2011-04-22 10:52:09 ----D---- C:\Documents and Settings\All Users\Application Data\PC Tools

======List of files/folders modified in the last 1 months======

2011-04-22 11:19:15 ----RD---- C:\Program Files
2011-04-22 11:18:52 ----A---- C:\WINDOWS\system32\signal.txt
2011-04-22 11:08:23 ----D---- C:\WINDOWS\Temp
2011-04-22 08:32:20 ----D---- C:\WINDOWS\system32
2011-04-22 08:32:20 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-22 08:28:38 ----D---- C:\WINDOWS
2011-04-22 08:28:34 ----D---- C:\Temp
2011-04-22 08:28:19 ----AD---- C:\Documentation
2011-04-22 08:28:18 ----AD---- C:\Install

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ACPI;Microsoft ACPI Driver; C:\WINDOWS\system32\DRIVERS\ACPI.sys [2006-04-04 194048]
R0 atapi;Standard IDE/ESDI Hard Disk Controller; C:\WINDOWS\system32\DRIVERS\atapi.sys [2005-03-24 95744]
R0 b06bdrv;Broadcom NetXtreme II VBD; C:\WINDOWS\system32\DRIVERS\bxvbdx.sys [2007-01-02 374784]
R0 crcdisk;CRC Disk Filter Driver; C:\WINDOWS\system32\DRIVERS\crcdisk.sys [2005-03-24 17920]
R0 Datascrn;Datascrn; C:\WINDOWS\system32\DRIVERS\datascrn.sys [2005-11-23 48640]
R0 DfsDriver;DfsDriver; C:\WINDOWS\system32\drivers\Dfs.sys [2006-04-04 34816]
R0 Disk;Disk Driver; C:\WINDOWS\system32\DRIVERS\disk.sys [2006-04-04 39936]
R0 dmio;Logical Disk Manager Driver; C:\WINDOWS\System32\drivers\dmio.sys [2006-04-04 150016]
R0 dmload;dmload; C:\WINDOWS\System32\drivers\dmload.sys [2006-04-04 7680]
R0 FltMgr;FltMgr; C:\WINDOWS\system32\DRIVERS\fltMgr.sys [2006-04-04 128512]
R0 Ftdisk;Volume Manager Driver; C:\WINDOWS\system32\DRIVERS\ftdisk.sys [2006-04-04 137216]
R0 isapnp;PnP ISA/EISA Bus Driver; C:\WINDOWS\system32\DRIVERS\isapnp.sys [2006-04-04 37888]
R0 KSecDD;KSecDD; C:\WINDOWS\system32\drivers\KSecDD.sys [2006-04-04 135168]
R0 MountMgr;Mount Point Manager; C:\WINDOWS\system32\drivers\MountMgr.sys [2006-04-04 46592]
R0 Mup;Mup; C:\WINDOWS\system32\drivers\Mup.sys [2006-04-04 102912]
R0 NDIS;NDIS System Driver; C:\WINDOWS\system32\drivers\NDIS.sys [2006-04-04 185856]
R0 PartMgr;Partition Manager; C:\WINDOWS\system32\drivers\PartMgr.sys [2006-04-04 25088]
R0 PCI;PCI Bus Driver; C:\WINDOWS\system32\DRIVERS\pci.sys [2006-04-11 74752]
R0 PCIIde;PCIIde; C:\WINDOWS\system32\DRIVERS\pciide.sys [2003-03-25 5632]
R0 percsas;percsas; C:\WINDOWS\system32\drivers\percsas.sys [2007-03-25 21504]
R0 Quota;Quota; C:\WINDOWS\system32\DRIVERS\quota.sys [2005-11-23 88064]
R0 VolSnap;Storage volumes; C:\WINDOWS\system32\DRIVERS\volsnap.sys [2006-04-04 152576]
R1 AFD;AFD; C:\WINDOWS\System32\drivers\afd.sys [2006-04-04 150528]
R1 Beep;Beep; C:\WINDOWS\system32\drivers\Beep.sys [2006-04-04 6144]
R1 Cdrom;CD-ROM Driver; C:\WINDOWS\system32\DRIVERS\cdrom.sys [2006-04-04 52224]
R1 Fips;Fips; C:\WINDOWS\system32\drivers\Fips.sys [2006-04-04 45056]
R1 IPSec;IPSEC driver; C:\WINDOWS\system32\DRIVERS\ipsec.sys [2006-04-04 81920]
R1 Kbdclass;Keyboard Class Driver; C:\WINDOWS\system32\DRIVERS\kbdclass.sys [2006-04-04 24576]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2006-04-04 15872]
R1 mnmdd;mnmdd; C:\WINDOWS\system32\drivers\mnmdd.sys [2006-04-04 6144]
R1 Mouclass;Mouse Class Driver; C:\WINDOWS\system32\DRIVERS\mouclass.sys [2006-04-04 23040]
R1 MRxSmb;MRXSMB; C:\WINDOWS\system32\DRIVERS\mrxsmb.sys [2006-04-04 438272]
R1 Msfs;Msfs; C:\WINDOWS\system32\drivers\Msfs.sys [2006-04-04 21504]
R1 NetBIOS;NetBIOS Interface; C:\WINDOWS\system32\DRIVERS\netbios.sys [2006-04-04 34816]
R1 NetBT;NetBios over Tcpip; C:\WINDOWS\system32\DRIVERS\netbt.sys [2006-04-04 180736]
R1 Npfs;Npfs; C:\WINDOWS\system32\drivers\Npfs.sys [2006-04-04 32256]
R1 Null;Null; C:\WINDOWS\system32\drivers\Null.sys [2006-04-04 4608]
R1 PCISys;PCISys; C:\WINDOWS\system32\drivers\PCISys.sys [2005-07-27 32823]
R1 RasAcd;Remote Access Auto Connection Driver; C:\WINDOWS\system32\DRIVERS\rasacd.sys [2006-04-04 10752]
R1 Rdbss;Rdbss; C:\WINDOWS\system32\DRIVERS\rdbss.sys [2006-04-04 178688]
R1 RDPCDD;RDPCDD; C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [2006-04-04 6144]
R1 redbook;Digital CD Audio Playback Filter Driver; C:\WINDOWS\system32\DRIVERS\redbook.sys [2005-03-24 60928]
R1 Serial;Serial port driver; C:\WINDOWS\system32\DRIVERS\serial.sys [2006-04-04 65536]
R1 Tcpip;TCP/IP Protocol Driver; C:\WINDOWS\system32\DRIVERS\tcpip.sys [2006-04-04 333312]
R1 TermDD;Terminal Device Driver; C:\WINDOWS\system32\DRIVERS\termdd.sys [2005-03-24 41608]
R1 VgaSave;VGA Display Controller.; C:\WINDOWS\System32\drivers\vga.sys [2006-04-04 23552]
R2 AppleTalk;AppleTalk Protocol; C:\WINDOWS\system32\DRIVERS\sfmatalk.sys [2006-04-04 150528]
R2 BASFND;BASFND; \??\C:\Program Files\Broadcom\SNMP\BASFND.sys []
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2007-04-27 90688]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-03-25 1431040]
R3 audstub;Audio Stub Driver; C:\WINDOWS\system32\DRIVERS\audstub.sys [2003-03-25 5120]
R3 dcdbas;System Management Driver; C:\WINDOWS\system32\DRIVERS\dcdbas32.sys [2007-02-27 31480]
R3 Fdc;Floppy Disk Controller Driver; C:\WINDOWS\system32\DRIVERS\fdc.sys [2006-04-04 24576]
R3 gdihook5;gdihook5; C:\WINDOWS\system32\DRIVERS\gdihook5.sys [2005-07-27 24633]
R3 Gpc;Generic Packet Classifier; C:\WINDOWS\system32\DRIVERS\msgpc.sys [2006-04-04 39424]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2006-04-04 11776]
R3 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-04-04 36864]
R3 l2nd;Broadcom NetXtreme II BXND; C:\WINDOWS\system32\DRIVERS\bxnd52x.sys [2006-12-22 50688]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-04-04 13312]
R3 MRxDAV;WebDav Client Redirector; C:\WINDOWS\system32\DRIVERS\mrxdav.sys [2006-04-04 189952]
R3 mssmbios;Microsoft System Management BIOS Driver; C:\WINDOWS\system32\DRIVERS\mssmbios.sys [2006-04-04 19968]
R3 NdisTapi;Remote Access NDIS TAPI Driver; C:\WINDOWS\system32\DRIVERS\ndistapi.sys [2006-04-04 12288]
R3 Ndisuio;NDIS Usermode I/O Protocol; C:\WINDOWS\system32\DRIVERS\ndisuio.sys [2006-04-04 14848]
R3 NdisWan;Remote Access NDIS WAN Driver; C:\WINDOWS\system32\DRIVERS\ndiswan.sys [2006-04-04 93184]
R3 NDProxy;NDIS Proxy; C:\WINDOWS\system32\drivers\NDProxy.sys [2006-04-04 40448]
R3 PptpMiniport;WAN Miniport (PPTP); C:\WINDOWS\system32\DRIVERS\raspptp.sys [2006-04-04 62464]
R3 Ptilink;Direct Parallel Link Driver; C:\WINDOWS\system32\DRIVERS\ptilink.sys [2006-04-04 20480]
R3 Rasl2tp;WAN Miniport (L2TP); C:\WINDOWS\system32\DRIVERS\rasl2tp.sys [2006-04-04 67584]
R3 RasPppoe;Remote Access PPPOE Driver; C:\WINDOWS\system32\DRIVERS\raspppoe.sys [2006-04-04 40960]
R3 Raspti;Direct Parallel; C:\WINDOWS\system32\DRIVERS\raspti.sys [2006-04-04 19968]
R3 rdpdr;Terminal Server Device Redirector Driver; C:\WINDOWS\system32\DRIVERS\rdpdr.sys [2005-03-24 201216]
R3 RDPWD;RDPWD; C:\WINDOWS\system32\drivers\RDPWD.sys [2006-04-04 152200]
R3 serenum;Serenum Filter Driver; C:\WINDOWS\system32\DRIVERS\serenum.sys [2006-04-04 17920]
R3 Srv;Srv; C:\WINDOWS\system32\DRIVERS\srv.sys [2006-04-04 360448]
R3 swenum;Software Bus Driver; C:\WINDOWS\system32\DRIVERS\swenum.sys [2006-04-04 4736]
R3 tap0801;TAP-Win32 Adapter V8; C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
R3 TDTCP;TDTCP; C:\WINDOWS\system32\drivers\TDTCP.sys [2006-04-04 23688]
R3 Update;Microcode Update Driver; C:\WINDOWS\system32\DRIVERS\update.sys [2006-04-04 236544]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-03-24 27136]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2005-03-24 59392]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2005-03-24 28160]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-04-04 20864]
R3 Wanarp;Remote Access IP ARP Driver; C:\WINDOWS\system32\DRIVERS\wanarp.sys [2006-04-04 36352]
R4 Cdfs;Cdfs; C:\WINDOWS\system32\drivers\Cdfs.sys [2006-04-04 65536]
R4 Fastfat;Fastfat; C:\WINDOWS\system32\drivers\Fastfat.sys [2006-04-04 151040]
R4 Ntfs;Ntfs; C:\WINDOWS\system32\drivers\Ntfs.sys [2006-04-04 589312]
S1 Changer;Changer; C:\WINDOWS\system32\drivers\Changer.sys []
S1 Flpydisk;Flpydisk; C:\WINDOWS\system32\drivers\Flpydisk.sys [2006-04-04 18432]
S1 i2omgmt;i2omgmt; C:\WINDOWS\system32\drivers\i2omgmt.sys []
S1 imapi;CD-Burning Filter Driver; C:\WINDOWS\system32\DRIVERS\imapi.sys [2006-04-04 43520]
S1 Sfloppy;Sfloppy; C:\WINDOWS\system32\drivers\Sfloppy.sys [2006-04-04 12288]
S3 akshasp;Aladdin HASP Key; C:\WINDOWS\system32\DRIVERS\akshasp.sys [2006-11-22 327168]
S3 aksusb;Aladdin USB Key; C:\WINDOWS\system32\DRIVERS\aksusb.sys [2006-11-22 100096]
S3 AsyncMac;RAS Asynchronous Media Driver; C:\WINDOWS\system32\DRIVERS\asyncmac.sys [2006-04-04 16384]
S3 Atmarpc;ATM ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\atmarpc.sys [2006-04-04 59392]
S3 Blfp;Broadcom Advanced Server Program Driver; C:\WINDOWS\system32\DRIVERS\baspxp32.sys [2007-01-26 96768]
S3 HTTP;HTTP; C:\WINDOWS\System32\Drivers\HTTP.sys [2006-04-04 289280]
S3 Ip6Fw;IPv6 Windows Firewall Driver; C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys [2006-04-04 29184]
S3 IpFilterDriver;IP Traffic Filter Driver; C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys [2006-04-04 32768]
S3 IpInIp;IP in IP Tunnel Driver; C:\WINDOWS\system32\DRIVERS\ipinip.sys []
S3 IpNat;IP Network Address Translator; C:\WINDOWS\system32\DRIVERS\ipnat.sys [2006-04-04 102400]
S3 IRENUM;IR Enumerator Service; C:\WINDOWS\system32\DRIVERS\irenum.sys [2005-03-24 12800]
S3 MACSRV;SFM Kernel Driver; C:\WINDOWS\system32\DRIVERS\sfmsrv.sys [2006-04-04 165376]
S3 Modem;Modem; C:\WINDOWS\system32\drivers\Modem.sys [2006-04-04 30208]
S3 Parport;Parport; C:\WINDOWS\system32\drivers\Parport.sys [2006-04-04 81408]
S3 PDCOMP;PDCOMP; C:\WINDOWS\system32\drivers\PDCOMP.sys []
S3 PDFRAME;PDFRAME; C:\WINDOWS\system32\drivers\PDFRAME.sys []
S3 PDRELI;PDRELI; C:\WINDOWS\system32\drivers\PDRELI.sys []
S3 PDRFRAME;PDRFRAME; C:\WINDOWS\system32\drivers\PDRFRAME.sys []
S3 Secdrv;Secdrv; C:\WINDOWS\system32\DRIVERS\secdrv.sys [2006-04-04 163644]
S3 TDPIPE;TDPIPE; C:\WINDOWS\system32\drivers\TDPIPE.sys [2006-04-04 12424]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2005-03-24 32000]
S3 WDICA;WDICA; C:\WINDOWS\system32\drivers\WDICA.sys []
S3 WLBS;Network Load Balancing; C:\WINDOWS\system32\DRIVERS\wlbs.sys [2006-04-04 169984]
S4 Abiosdsk;Abiosdsk; C:\WINDOWS\system32\drivers\Abiosdsk.sys []
S4 ACPIEC;ACPIEC; C:\WINDOWS\system32\drivers\ACPIEC.sys [2006-04-04 12800]
S4 adpu160m;adpu160m; C:\WINDOWS\system32\drivers\adpu160m.sys []
S4 adpu320;adpu320; C:\WINDOWS\system32\drivers\adpu320.sys []
S4 afcnt;afcnt; C:\WINDOWS\system32\drivers\afcnt.sys []
S4 aic78u2;aic78u2; C:\WINDOWS\system32\drivers\aic78u2.sys []
S4 aic78xx;aic78xx; C:\WINDOWS\system32\drivers\aic78xx.sys []
S4 AliIde;AliIde; C:\WINDOWS\system32\drivers\AliIde.sys []
S4 AmdIde;AmdIde; C:\WINDOWS\system32\drivers\AmdIde.sys []
S4 arc;arc; C:\WINDOWS\system32\drivers\arc.sys []
S4 Atdisk;Atdisk; C:\WINDOWS\system32\drivers\Atdisk.sys []
S4 cbidf2k;cbidf2k; C:\WINDOWS\system32\drivers\cbidf2k.sys [2006-04-04 15360]
S4 cd20xrnt;cd20xrnt; C:\WINDOWS\system32\drivers\cd20xrnt.sys []
S4 ClusDisk;Cluster Disk Driver; C:\WINDOWS\system32\DRIVERS\ClusDisk.sys [2006-04-04 68608]
S4 CmdIde;CmdIde; C:\WINDOWS\system32\drivers\CmdIde.sys []
S4 Cpqarray;Cpqarray; C:\WINDOWS\system32\drivers\Cpqarray.sys []
S4 cpqarry2;cpqarry2; C:\WINDOWS\system32\drivers\cpqarry2.sys []
S4 cpqcissm;cpqcissm; C:\WINDOWS\system32\drivers\cpqcissm.sys []
S4 cpqfcalm;cpqfcalm; C:\WINDOWS\system32\drivers\cpqfcalm.sys []
S4 dac2w2k;dac2w2k; C:\WINDOWS\system32\drivers\dac2w2k.sys []
S4 dac960nt;dac960nt; C:\WINDOWS\system32\drivers\dac960nt.sys []
S4 dellcerc;dellcerc; C:\WINDOWS\system32\drivers\dellcerc.sys []
S4 dmboot;dmboot; C:\WINDOWS\System32\drivers\dmboot.sys [2006-04-04 268288]
S4 dpti2o;dpti2o; C:\WINDOWS\system32\drivers\dpti2o.sys []
S4 elxstor;elxstor; C:\WINDOWS\system32\drivers\elxstor.sys []
S4 hpcisss;hpcisss; C:\WINDOWS\system32\drivers\hpcisss.sys []
S4 hpn;hpn; C:\WINDOWS\system32\drivers\hpn.sys []
S4 hpt3xx;hpt3xx; C:\WINDOWS\system32\drivers\hpt3xx.sys []
S4 i2omp;i2omp; C:\WINDOWS\system32\drivers\i2omp.sys []
S4 iirsp;iirsp; C:\WINDOWS\system32\drivers\iirsp.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 ipsraidn;ipsraidn; C:\WINDOWS\system32\drivers\ipsraidn.sys []
S4 lp6nds35;lp6nds35; C:\WINDOWS\system32\drivers\lp6nds35.sys []
S4 mraid35x;mraid35x; C:\WINDOWS\system32\drivers\mraid35x.sys []
S4 nfrd960;nfrd960; C:\WINDOWS\system32\drivers\nfrd960.sys []
S4 Pcmcia;Pcmcia; C:\WINDOWS\system32\drivers\Pcmcia.sys [2006-04-04 121856]
S4 perc2;perc2; C:\WINDOWS\system32\drivers\perc2.sys []
S4 perc2hib;perc2hib; C:\WINDOWS\system32\drivers\perc2hib.sys []
S4 ql1080;ql1080; C:\WINDOWS\system32\drivers\ql1080.sys []
S4 Ql10wnt;Ql10wnt; C:\WINDOWS\system32\drivers\Ql10wnt.sys []
S4 ql12160;ql12160; C:\WINDOWS\system32\drivers\ql12160.sys []
S4 ql1240;ql1240; C:\WINDOWS\system32\drivers\ql1240.sys []
S4 ql1280;ql1280; C:\WINDOWS\system32\drivers\ql1280.sys []
S4 ql2100;ql2100; C:\WINDOWS\system32\drivers\ql2100.sys []
S4 ql2200;ql2200; C:\WINDOWS\system32\drivers\ql2200.sys []
S4 ql2300;ql2300; C:\WINDOWS\system32\drivers\ql2300.sys []
S4 Simbad;Simbad; C:\WINDOWS\system32\drivers\Simbad.sys []
S4 sym_hi;sym_hi; C:\WINDOWS\system32\drivers\sym_hi.sys []
S4 sym_u3;sym_u3; C:\WINDOWS\system32\drivers\sym_u3.sys []
S4 symc810;symc810; C:\WINDOWS\system32\drivers\symc810.sys []
S4 symc8xx;symc8xx; C:\WINDOWS\system32\drivers\symc8xx.sys []
S4 symmpi;symmpi; C:\WINDOWS\system32\drivers\symmpi.sys []
S4 TosIde;TosIde; C:\WINDOWS\system32\drivers\TosIde.sys []
S4 Udfs;Udfs; C:\WINDOWS\system32\drivers\Udfs.sys [2006-04-04 67584]
S4 ultra;ultra; C:\WINDOWS\system32\drivers\ultra.sys []
S4 ViaIde;ViaIde; C:\WINDOWS\system32\drivers\ViaIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AbyssWebServer;Abyss Web Server; C:\Program Files\Abyss Web Server\abyssws.exe [2008-04-11 506425]
R2 AeLookupSvc;Application Experience Lookup Service; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 Alerter;Alerter; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 Apcupsd;Apcupsd UPS Monitor; C:\apcupsd\bin\apcupsd.exe [2007-05-26 694272]
R2 AudioSrv;Windows Audio; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R2 BGMD;BGMD; E:\Esko\bg_prog_fastserver_v100\bin_ix86\bgmdw.exe [2010-10-07 208896]
R2 Browser;Computer Browser; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 Client32;Client32; C:\PROGRA~1\NETSUP~1\client32.exe [2005-07-27 16447]
R2 CryptSvc;Cryptographic Services; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 dcevt32;DSM SA Event Manager; C:\Program Files\Dell\SysMgt\dataeng\bin\dsm_sa_eventmgr32.exe [2007-02-01 153848]
R2 DcomLaunch;DCOM Server Process Launcher; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 dcstor32;DSM SA Data Manager; C:\Program Files\Dell\SysMgt\dataeng\bin\dsm_sa_datamgr32.exe [2007-02-01 198904]
R2 Dhcp;DHCP Client; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 dmserver;Logical Disk Manager; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R2 Dnscache;DNS Client; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 EG Data Transfer Client Service;EG Data Transfer Client Service; E:\Esko\bg_prog_egdtc_v010\bin_ix86\egdtcsrv.exe [2008-03-20 114688]
R2 EG Scope Configuration Service;EG Scope Configuration Service; E:\Esko\bg_prog_egscs_v010\bin_ix86\egscssrv.exe [2010-01-27 569344]
R2 EG Station Information Service;EG Station Information Service; E:\Esko\bg_prog_egsis_v010\bin_ix86\egsissrv.exe [2010-08-31 45056]
R2 Eventlog;Event Log; C:\WINDOWS\system32\services.exe [2006-04-04 110080]
R2 EventSystem;COM+ Event System; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 ExtremeZ-IP;ExtremeZ-IP File and Print Server for Macintosh [BACKSTAGE]; C:\Program Files\Group Logic\ExtremeZ-IP\ExtremeZ-IP.EXE [2007-07-05 1937408]
R2 FLEXlm License Manager;FLEXlm License Manager; E:\Esko\bg_prog_system_v010\bin_ix86\lmgrd.exe [2008-11-06 1500424]
R2 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-01-13 867080]
R2 helpsvc;Help and Support; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R2 lanmanserver;Server; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 lanmanworkstation;Workstation; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 LmHosts;TCP/IP NetBIOS Helper; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 mr2kserv;mr2kserv; C:\Program Files\Dell\SysMgt\sm\mr2kserv.exe [2007-03-09 69632]
R2 MSDTC;Distributed Transaction Coordinator; C:\WINDOWS\system32\msdtc.exe [2006-04-04 6144]
R2 MSSQLSERVER;MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [2005-05-04 9150464]
R2 Netlogon;Net Logon; C:\WINDOWS\system32\lsass.exe [2006-04-04 13312]
R2 omsad;DSM SA Shared Services; C:\Program Files\Dell\SysMgt\oma\bin\dsm_om_shrsvc32.exe [2007-03-07 22776]
R2 PlugPlay;Plug and Play; C:\WINDOWS\system32\services.exe [2006-04-04 110080]
R2 PolicyAgent;IPSEC Services; C:\WINDOWS\system32\lsass.exe [2006-04-04 13312]
R2 ProtectedStorage;Protected Storage; C:\WINDOWS\system32\lsass.exe [2006-04-04 13312]
R2 RemoteRegistry;Remote Registry; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 RpcSs;Remote Procedure Call (RPC); C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 SamSs;Security Accounts Manager; C:\WINDOWS\system32\lsass.exe [2006-04-04 13312]
R2 Schedule;Task Scheduler; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R2 seclogon;Secondary Logon; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R2 SENS;System Event Notification; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 Server Administrator;DSM SA Connection Service; C:\Program Files\Dell\SysMgt\iws\bin\win32\dsm_om_connsvc32.exe [2007-03-07 55544]
R2 SGD;System Guardian/XC 2000; C:\WINDOWS\system32\sgd.exe [2003-05-28 184320]
R2 ShellHWDetection;Shell Hardware Detection; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2006-04-04 40960]
R2 Spooler;Print Spooler; C:\WINDOWS\system32\spoolsv.exe [2006-04-04 58368]
R2 SQLSERVERAGENT;SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [2005-05-03 323584]
R2 SrmSvc;File Server Resource Manager; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 TrkWks;Distributed Link Tracking Client; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 W32Time;Windows Time; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R2 winmgmt;Windows Management Instrumentation; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R2 WZCSVC;Wireless Configuration; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R3 Netman;Network Connections; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
R3 Nla;Network Location Awareness (NLA); C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
R3 TermService;Terminal Services; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S2 SysmonLog;Performance Logs and Alerts; C:\WINDOWS\system32\smlogsvc.exe [2006-04-04 96256]
S3 ALG;Application Layer Gateway Service; C:\WINDOWS\System32\alg.exe [2006-04-04 45056]
S3 AppMgmt;Application Management; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 COMSysApp;COM+ System Application; C:\WINDOWS\system32\dllhost.exe [2006-04-04 5632]
S3 Dfs;Distributed File System; C:\WINDOWS\system32\Dfssvc.exe [2006-04-04 164352]
S3 dmadmin;Logical Disk Manager Administrative Service; C:\WINDOWS\System32\dmadmin.exe [2006-04-04 233984]
S3 HTTPFilter;HTTP SSL; C:\WINDOWS\System32\lsass.exe [2006-04-04 13312]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MSIServer;Windows Installer; C:\WINDOWS\system32\msiexec.exe [2006-04-04 78848]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2005-05-03 73728]
S3 NtFrs;File Replication; C:\WINDOWS\system32\ntfrs.exe [2006-04-04 791552]
S3 NtLmSsp;NT LM Security Support Provider; C:\WINDOWS\system32\lsass.exe [2006-04-04 13312]
S3 NtmsSvc;Removable Storage; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2006-10-01 16384]
S3 RasAuto;Remote Access Auto Connection Manager; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S3 RasMan;Remote Access Connection Manager; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S3 RDSessMgr;Remote Desktop Help Session Manager; C:\WINDOWS\system32\sessmgr.exe [2006-04-04 124928]
S3 RpcLocator;Remote Procedure Call (RPC) Locator; C:\WINDOWS\system32\locator.exe [2006-04-04 71680]
S3 RSoPProv;Resultant Set of Policy Provider; C:\WINDOWS\system32\RSoPProv.exe [2006-04-04 67072]
S3 sacsvr;Special Administration Console Helper; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S3 SCardSvr;Smart Card; C:\WINDOWS\System32\SCardSvr.exe [2006-04-04 90112]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2006-04-04 8704]
S3 SrmReports;File Server Storage Reports Manager; C:\WINDOWS\system32\srmhost.exe [2005-11-23 10752]
S3 swprv;Microsoft Software Shadow Copy Provider; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S3 TapiSrv;Telephony; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2006-04-04 39424]
S3 UPS;Uninterruptible Power Supply; C:\WINDOWS\System32\ups.exe [2006-04-04 16896]
S3 vds;Virtual Disk Service; C:\WINDOWS\System32\vds.exe [2006-04-04 208384]
S3 VSS;Volume Shadow Copy; C:\WINDOWS\System32\vssvc.exe [2006-04-04 823808]
S3 WinHttpAutoProxySvc;WinHTTP Web Proxy Auto-Discovery Service; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S3 WmdmPmSN;Portable Media Serial Number Service; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S3 Wmi;Windows Management Instrumentation Driver Extensions; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S3 WmiApSrv;WMI Performance Adapter; C:\WINDOWS\system32\wbem\wmiapsrv.exe [2006-04-04 127488]
S3 xmlprov;Network Provisioning Service; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S4 BITS;Background Intelligent Transfer Service; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S4 CiSvc;Indexing Service; C:\WINDOWS\system32\cisvc.exe [2006-04-04 6656]
S4 ClipSrv;ClipBook; C:\WINDOWS\system32\clipsrv.exe [2006-04-04 32256]
S4 ERSvc;Error Reporting Service; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S4 HidServ;Human Interface Device Access; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S4 ImapiService;IMAPI CD-Burning COM Service; C:\WINDOWS\system32\imapi.exe [2006-04-04 157184]
S4 IsmServ;Intersite Messaging; C:\WINDOWS\System32\ismserv.exe [2006-04-04 36352]
S4 kdc;Kerberos Key Distribution Center; C:\WINDOWS\System32\lsass.exe [2006-04-04 13312]
S4 LicenseService;License Logging; C:\WINDOWS\System32\llssrv.exe [2006-04-04 94720]
S4 MacFile;File Server for Macintosh; C:\WINDOWS\system32\sfmsvc.exe [2006-04-04 65024]
S4 Messenger;Messenger; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S4 mnmsrvc;NetMeeting Remote Desktop Sharing; C:\WINDOWS\system32\mnmsrvc.exe [2006-04-04 32768]
S4 NetDDE;Network DDE; C:\WINDOWS\system32\netdde.exe [2006-04-04 110080]
S4 NetDDEdsdm;Network DDE DSDM; C:\WINDOWS\system32\netdde.exe [2006-04-04 110080]
S4 RemoteAccess;Routing and Remote Access; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S4 SharedAccess;Windows Firewall/Internet Connection Sharing (ICS); C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S4 stisvc;Windows Image Acquisition (WIA); C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S4 Themes;Themes; C:\WINDOWS\System32\svchost.exe [2006-04-04 14336]
S4 TlntSvr;Telnet; C:\WINDOWS\system32\tlntsvr.exe [2006-04-04 75776]
S4 TrkSvr;Distributed Link Tracking Server; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S4 Tssdis;Terminal Services Session Directory; C:\WINDOWS\System32\tssdis.exe [2006-04-04 71168]
S4 WebClient;WebClient; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]
S4 wuauserv;Automatic Updates; C:\WINDOWS\system32\svchost.exe [2006-04-04 14336]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Worm/Generic_c.ZS

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: V obou nasledujicich krocich mejte flash disk v PC zapojeny

:arrow: USBFix PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Herbenni
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 22 dub 2011 10:23

Re: Worm/Generic_c.ZS

#3 Příspěvek od Herbenni »

Tak ComboFix nejde na Windows server 2003, je jiná možnost? :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Worm/Generic_c.ZS

#4 Příspěvek od vyosek »

:arrow: Udelejte ten USBFix a pak pujdem dale :James008:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět