Některé internetové stránky se nenačtou - podezření na vir
Napsal: 12 črc 2011 09:50
Zdravím, mám problém. Dneska ráno jsem vstal, otevřel si záložky v prohlížeči - Google Chrome a půlka se načetla, tak jsem je po přečtení zavřel a pak zbyla hrstka asi tak 10 záložek které se pořád načítají, ale nikdy se nenačtou. Mám podezření na vir. Udělal jsem po aktualizaci Nortonem Internet Security 2011 úplnou kontrolu PC a vše v pořádku. Žádný ''záhadný'' proces nemám v procesech ve správci úloh spuštěn, všechno vím co je. Tak snad mi pomůžete.
Kód: Vybrat vše
Logfile of random's system information tool 1.09 (written by random/random)
Run by Adam at 2011-07-12 10:46:27
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 11 GB (18%) free of 61 GB
Total RAM: 4087 MB (65% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0c4659e8-11c8-49c2-8ecc-6722a6d44fef -SystemEventPortName:HostProcess-6f0f4e7e-d69b-4559-989a-180e7509d43c -IoCancelEventPortName:HostProcess-1d6e4bfa-dc41-4405-8f4f-071b4abc5d90 -NonStateChangingEventPortName:HostProcess-7ab76f78-8de2-4fa5-b55e-d6b825c2315a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2533b58d-5dfa-4f47-bf87-28813e7eb63a
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-2c76e65b-7f5f-4031-8ff8-c649104e6526 -SystemEventPortName:HostProcess-fd339235-7e15-4524-9e4d-21049b3e9bf9 -IoCancelEventPortName:HostProcess-b15bbae8-6dd5-4808-b568-f85d357053b8 -NonStateChangingEventPortName:HostProcess-a80bf43e-f395-4c54-9c9c-82406b8e1b68 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d29065bf-12c6-489b-b78c-f535dc37abac
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\diMaster.dll" /prefetch:1
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
WLIDSvcM.exe 1456
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"taskhost.exe"
"C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe" /c /a /s UserSession
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
KHALMNPR.EXE /API
"taskhost.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --disable-client-side-phishing-detection --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_8/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_disabled/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ --channel=1796.03EF71A0.1958264170 /prefetch:3 --ignored=" --type=renderer "
C:\Windows\system32\rundll32.exe "C:\Users\Adam\AppData\Local\Google\Chrome\APPLIC~1\120742~1.112\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Adam\AppData\Local\Google\Chrome\Application\12.0.742.112\gcswf32.dll" --lang=cs --channel=1796.04BCECF8.1827136878 /prefetch:4 --flash-broker=3544
"C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --disable-client-side-phishing-detection --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_8/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_disabled/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ --channel=1796.08876B00.1110903535 /prefetch:3
"C:\Users\Adam\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1966872071-2545931226-3853241747-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1966872071-2545931226-3853241747-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-04-18 49440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll [2011-04-29 436152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL [2011-03-31 210872]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll [2011-04-29 436152]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2010-10-29 1680976]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-28 136176]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-05-26 15147400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NUSB3MON]
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-04-27 113288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-06-08 10867816]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-05-24 336384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2010-10-28 66640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-12 10:46:27 ----D---- C:\rsit
2011-07-12 10:46:27 ----D---- C:\Program Files\trend micro
2011-07-10 23:04:08 ----D---- C:\Windows\SYSWOW64\Updates
2011-07-10 23:04:08 ----D---- C:\Windows\SYSWOW64\Data
2011-07-10 11:53:16 ----D---- C:\Users\Adam\AppData\Roaming\Mozilla
2011-07-10 11:44:44 ----D---- C:\Program Files (x86)\Ubisoft
2011-07-09 22:10:10 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-07-09 22:10:10 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-07-09 22:10:10 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-07-09 22:10:10 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-07-09 22:10:10 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-07-09 22:10:09 ----A---- C:\Windows\system32\tquery.dll
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-07-09 22:10:08 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-07-09 22:10:08 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-07-09 22:10:08 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-07-09 22:10:08 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-07-09 22:10:08 ----A---- C:\Windows\system32\mssvp.dll
2011-07-09 22:10:08 ----A---- C:\Windows\system32\mssrch.dll
2011-07-09 22:10:08 ----A---- C:\Windows\system32\mssphtb.dll
2011-07-09 22:10:08 ----A---- C:\Windows\system32\mssph.dll
2011-07-09 22:10:08 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-19 08:11:44 ----D---- C:\ProgramData\ATI
2011-06-19 08:11:42 ----D---- C:\Program Files (x86)\AMD APP
2011-06-15 07:31:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-15 07:31:49 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-15 07:31:48 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-06-15 07:31:48 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-06-15 07:31:48 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-15 07:31:48 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-15 07:31:48 ----A---- C:\Windows\system32\jscript9.dll
2011-06-15 07:31:48 ----A---- C:\Windows\system32\jscript.dll
2011-06-15 07:31:48 ----A---- C:\Windows\system32\ieui.dll
2011-06-15 07:31:48 ----A---- C:\Windows\system32\iertutil.dll
2011-06-15 07:31:47 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-15 07:31:47 ----A---- C:\Windows\system32\urlmon.dll
2011-06-15 07:31:46 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-15 07:31:44 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-15 07:31:44 ----A---- C:\Windows\system32\mshtml.dll
2011-06-15 07:31:44 ----A---- C:\Windows\system32\ieframe.dll
2011-06-15 07:06:46 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-15 07:06:46 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-15 07:06:46 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-15 07:06:46 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-15 07:06:46 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-15 07:06:43 ----A---- C:\Windows\system32\win32k.sys
2011-06-15 07:06:40 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-15 07:06:40 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-15 07:06:40 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-15 07:06:35 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-15 07:06:35 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-15 07:06:35 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-15 07:06:35 ----A---- C:\Windows\system32\inetcomm.dll
======List of files/folders modified in the last 1 month======
2011-07-12 10:46:27 ----RD---- C:\Program Files
2011-07-12 10:46:18 ----D---- C:\Windows\Temp
2011-07-12 10:40:27 ----D---- C:\Users\Adam\AppData\Roaming\Skype
2011-07-12 10:34:37 ----D---- C:\ProgramData\Easybits GO
2011-07-12 09:35:25 ----D---- C:\Windows\system32\config
2011-07-12 09:13:30 ----D---- C:\Windows\system32\NDF
2011-07-12 08:04:53 ----D---- C:\Windows\System32
2011-07-12 08:04:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-12 08:04:52 ----D---- C:\Windows\inf
2011-07-12 08:04:35 ----D---- C:\Users\Adam\AppData\Roaming\go
2011-07-12 08:04:35 ----D---- C:\ProgramData\Skype Extras
2011-07-12 08:00:27 ----SHD---- C:\System Volume Information
2011-07-12 08:00:22 ----D---- C:\Windows
2011-07-11 23:35:03 ----SHD---- C:\Windows\Installer
2011-07-11 21:22:56 ----D---- C:\Users\Adam\AppData\Roaming\Media Player Classic
2011-07-11 17:16:00 ----D---- C:\Windows\SysWOW64
2011-07-11 17:15:40 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-07-11 17:14:38 ----D---- C:\Program Files (x86)\pb
2011-07-11 16:32:53 ----RD---- C:\Program Files (x86)
2011-07-11 16:32:07 ----RSD---- C:\Windows\assembly
2011-07-11 16:30:07 ----D---- C:\Windows\winsxs
2011-07-10 23:05:40 ----D---- C:\ProgramData\Blizzard Entertainment
2011-07-10 12:36:16 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-07-10 11:41:31 ----HD---- C:\ProgramData
2011-07-10 11:04:29 ----RSD---- C:\Windows\Fonts
2011-07-10 00:14:17 ----D---- C:\Windows\system32\catroot2
2011-07-09 22:10:03 ----D---- C:\Windows\system32\catroot
2011-06-19 08:11:31 ----D---- C:\Program Files\ATI Technologies
2011-06-19 08:10:58 ----D---- C:\Windows\system32\drivers
2011-06-19 08:10:56 ----D---- C:\Windows\system32\DriverStore
2011-06-18 21:13:03 ----D---- C:\Users\Adam\AppData\Roaming\Mumble
2011-06-16 00:54:07 ----D---- C:\Windows\debug
2011-06-15 14:23:20 ----D---- C:\Windows\Microsoft.NET
2011-06-15 13:59:37 ----D---- C:\Program Files\Internet Explorer
2011-06-15 13:59:37 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-15 07:35:28 ----A---- C:\Windows\system32\MRT.exe
2011-06-15 07:35:22 ----D---- C:\ProgramData\Microsoft Help
2011-06-15 07:31:24 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-13 07:31:00 ----D---- C:\Program Files (x86)\Common Files
2011-06-13 07:30:51 ----D---- C:\Program Files (x86)\Java
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2009-10-27 22568]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-03-17 302632]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-28 834544]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [2011-01-27 450680]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [2011-03-15 912504]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110701.001\BHDrvx64.sys [2011-05-19 1143416]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2011-05-10 481912]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110712.033\IDSvia64.sys [2011-07-08 488056]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NISx64\1206000.01D\SRTSPX64.SYS [2011-03-31 40568]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [2011-01-27 171128]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [2011-03-22 382584]
R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784]
R3 3xHybr64;WinFast DTV1000 S; C:\Windows\system32\DRIVERS\3xHybr64.sys [2009-08-17 1311616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-05-25 9359872]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-05-25 309760]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2011-03-30 114704]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-10 136824]
R3 EST_BusEnum;Network USB Device Bus; C:\Windows\system32\DRIVERS\GenBus.sys [2009-10-06 29696]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-06-08 2394216]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2009-11-23 22408]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2010-08-24 63568]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2010-08-24 57936]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2010-08-24 41040]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110711.033\ENG64.SYS [2011-05-18 117880]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110711.033\EX64.SYS [2011-05-18 2011768]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\NISx64\1206000.01D\SRTSP64.SYS [2011-03-31 744568]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2011-05-13 174200]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2009-01-13 22024]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2009-01-13 57608]
S2 cpuz134;cpuz134; \??\C:\Windows\system32\drivers\cpuz134_x64.sys []
S3 a7k49gbu;a7k49gbu; C:\Windows\system32\drivers\a7k49gbu.sys []
S3 dump_wmimmc;dump_wmimmc; \??\X:\Hry\Lineage II\system\GameGuard\dump_wmimmc.sys []
S3 EST_Server;Network USB Device; C:\Windows\system32\DRIVERS\GenHC.sys [2009-10-06 199168]
S3 FLASHSYS;FLASHSYS; \??\C:\Program Files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys []
S3 GPU-Z;GPU-Z; \??\C:\Users\Adam\AppData\Local\Temp\GPU-Z.sys []
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2009-11-23 16008]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys []
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys []
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-07-14 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys []
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2009-01-13 34440]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\Windows\system32\drivers\WmHidLo.sys [2009-01-13 36360]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2009-01-13 15752]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-05-25 204288]
R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-03-22 75136]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-10-28 357456]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-11-03 4045280]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-19 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-29 1255736]
-----------------EOF-----------------