Stránka 1 z 3

Prosím o preventivku po nákaze

Napsal: 28 lis 2011 21:25
od raskar89
Nákaza win32 něco... nevzpomínám si :( odstranil avast. Prosím o preventivku jesli je vše ok. Díky moc

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:24:16, on 28.11.2011
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Home\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA2527AB-DADD-4CBC-80C3-E5CF0392AF2D}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{DBB461A5-3A64-464D-9B14-96961794DF7A}: NameServer = 156.154.70.25,156.154.71.25
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

--
End of file - 6448 bytes

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 10:03
od Márty84
Zdravim :)

Pokud znate tyto ip adresy 156.154.70.25, 156.154.71.25 (podle google patri USA :?: ), vypada log az na par zbytecnosti OK. Ale lepsi by bylo, kdybyste poslal log z RSIT, ktery je podrobnejsi. Navod je zde http://www.viry.cz/forum/viewtopic.php?f=30&t=82744

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 12:21
od raskar89
IP adresy vubec neznam :(

Logfile of random's system information tool 1.09 (written by random/random)
Run by Home at 2011-11-29 12:20:54
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 148 GB (64%) free of 230 GB
Total RAM: 3071 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:21:28, on 29.11.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Home\Desktop\RSIT.exe
C:\Program Files\trend micro\Home.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA2527AB-DADD-4CBC-80C3-E5CF0392AF2D}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{DBB461A5-3A64-464D-9B14-96961794DF7A}: NameServer = 156.154.70.25,156.154.71.25
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVMSLVRNBHFNECS - Sysinternals - www.sysinternals.com - C:\Users\Home\AppData\Local\Temp\NVMSLVRNBHFNECS.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

--
End of file - 6577 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\njqu423u.default

prefs.js - "browser.startup.homepage" - "http://news.google.cz/nwshp?client=fire ... =cs&tab=wn"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9, {582195F5-92E7-40a0-A127-DB71295901D7}:0.6.4, {c50ca3c4-5656-43c2-a061-13e717f73fc8}:4.0.1, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"

"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\njqu423u.default\extensions\
staged

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20 509496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2011-10-20 2497352]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-09-06 3722416]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2007-10-17 7737344]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-01-15 4874240]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1029416]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2007-03-20 36864]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-04 186904]
"IaNvSrv"=C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe [2009-07-13 33304]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApplePhotoStreams]
C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2011-10-06 59240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Home\AppData\Local\Google\Update\GoogleUpdate.exe /c []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iCloudServices]
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2011-11-13 421736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerForPhone]
C:\Program Files\P4P\P4P.exe [2007-08-02 778240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2011-10-24 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
C:\Windows\Skytel.exe [2007-11-20 1826816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2009-05-05 1466368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2009-09-20 270336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Home^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^_uninst_44276743.lnk]
C:\Users\Home\AppData\Local\Temp\_uninst_44276743.bat []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Home^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^_uninst_80387875.lnk]
C:\Users\Home\AppData\Local\Temp\_uninst_80387875.bat []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-09-05 113024]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\34897157.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\34897157.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=serwvdrv.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-11-21 21:52:02 ----A---- C:\XoristDecryptor.2.2.16.0_21.11.2011_21.52.02_log.txt
2011-11-21 20:03:07 ----A---- C:\Windows\system32\drivers\80387875.sys
2011-11-21 18:22:03 ----D---- C:\TDSSKiller_Quarantine
2011-11-20 19:45:37 ----D---- C:\Users\Home\AppData\Roaming\Day 1 Studios
2011-11-20 19:37:21 ----A---- C:\Windows\system32\d3dcompiler_43.dll
2011-11-20 19:34:53 ----A---- C:\Windows\system32\xinput1_3.dll
2011-11-20 19:27:28 ----D---- C:\Program Files\WB Games
2011-11-19 21:52:18 ----A---- C:\Windows\system32\x3daudio1_5.dll
2011-11-17 13:23:35 ----D---- C:\Program Files\iPod
2011-11-17 13:23:27 ----D---- C:\Program Files\iTunes
2011-11-14 16:40:19 ----A---- C:\Windows\system32\CmdLineExt.dll
2011-11-14 15:41:38 ----D---- C:\ProgramData\Malwarebytes
2011-11-14 15:41:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-11-14 15:41:34 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-11-14 01:32:23 ----SHD---- C:\Windows\system32\%APPDATA%
2011-11-14 01:27:05 ----A---- C:\Windows\system32\shell32.dll
2011-11-13 22:51:56 ----D---- C:\ProgramData\Trymedia
2011-11-13 22:44:19 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-11-13 22:42:37 ----A---- C:\Windows\system32\dffsetup_d3dx9_27.exe
2011-11-13 21:18:22 ----D---- C:\Program Files\Sierra
2011-11-13 15:31:19 ----D---- C:\Users\Home\AppData\Roaming\HpUpdate
2011-11-12 23:56:45 ----SHD---- C:\Windows\ftpcache
2011-11-12 18:30:45 ----D---- C:\Program Files\Common Files\Java
2011-11-12 18:30:32 ----A---- C:\Windows\system32\javaws.exe
2011-11-12 18:30:32 ----A---- C:\Windows\system32\javaw.exe
2011-11-12 18:30:32 ----A---- C:\Windows\system32\java.exe
2011-11-12 18:28:34 ----D---- C:\Program Files\SystemRequirementsLab
2011-11-12 13:21:39 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-11-12 13:21:19 ----D---- C:\Program Files\DAEMON Tools Lite
2011-11-12 00:07:44 ----D---- C:\Users\Home\AppData\Roaming\DAEMON Tools Lite
2011-11-12 00:07:37 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-11-11 20:00:35 ----RASH---- C:\MSDOS.SYS
2011-11-11 20:00:35 ----RASH---- C:\IO.SYS
2011-11-09 18:26:33 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-11-09 18:26:31 ----A---- C:\Windows\system32\win32k.sys
2011-11-05 20:09:12 ----D---- C:\Program Files\uTorrent
2011-11-05 20:08:46 ----D---- C:\Users\Home\AppData\Roaming\uTorrent

======List of files/folders modified in the last 1 month======

2011-11-29 12:21:28 ----D---- C:\Windows\Prefetch
2011-11-29 12:21:26 ----D---- C:\Windows\Temp
2011-11-29 12:21:01 ----D---- C:\Program Files\trend micro
2011-11-28 18:54:38 ----D---- C:\Users\Home\AppData\Roaming\vlc
2011-11-28 18:32:17 ----D---- C:\Windows\system32\config
2011-11-27 18:54:33 ----D---- C:\Windows\System32
2011-11-27 18:54:33 ----D---- C:\Windows\inf
2011-11-27 18:54:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-11-27 12:29:05 ----A---- C:\Windows\system32\acovcnt.exe
2011-11-25 12:58:13 ----SHD---- C:\System Volume Information
2011-11-24 11:59:13 ----D---- C:\Windows
2011-11-23 18:47:47 ----HD---- C:\ProgramData
2011-11-23 18:47:31 ----RD---- C:\Program Files
2011-11-23 18:44:11 ----SHD---- C:\Windows\Installer
2011-11-23 18:44:11 ----SHD---- C:\Config.Msi
2011-11-23 18:44:10 ----D---- C:\Users\Home\AppData\Roaming\Apple Computer
2011-11-23 18:44:10 ----D---- C:\Program Files\Common Files\Apple
2011-11-23 17:35:19 ----D---- C:\Windows\pss
2011-11-22 18:53:51 ----D---- C:\Windows\system32\drivers
2011-11-20 17:30:32 ----D---- C:\Windows\system32\Tasks
2011-11-20 17:30:31 ----D---- C:\Windows\Tasks
2011-11-17 14:52:29 ----D---- C:\Windows\system32\catroot
2011-11-14 01:40:00 ----D---- C:\Windows\winsxs
2011-11-14 01:36:07 ----D---- C:\ProgramData\Microsoft Help
2011-11-14 01:36:05 ----RSD---- C:\Windows\assembly
2011-11-14 01:35:01 ----D---- C:\Program Files\Common Files\microsoft shared
2011-11-14 01:25:25 ----D---- C:\Windows\system32\catroot2
2011-11-14 00:47:34 ----D---- C:\Windows\system32\drivers\etc
2011-11-13 15:53:52 ----D---- C:\Windows\twain_32
2011-11-13 14:51:22 ----HD---- C:\Program Files\InstallShield Installation Information
2011-11-12 23:51:13 ----D---- C:\Program Files\Common Files\InstallShield
2011-11-12 18:30:45 ----D---- C:\Program Files\Common Files
2011-11-12 18:30:13 ----D---- C:\Program Files\Java
2011-11-12 13:21:53 ----D---- C:\Windows\system32\DriverStore
2011-11-12 00:30:44 ----D---- C:\Windows\debug
2011-11-11 21:02:39 ----D---- C:\Program Files\SUPERAntiSpyware
2011-11-10 10:34:01 ----D---- C:\Program Files\Common Files\System
2011-11-09 19:38:39 ----A---- C:\Windows\system32\MRT.exe
2011-11-09 19:33:37 ----D---- C:\Program Files\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 58594522;58594522; C:\Windows\system32\DRIVERS\58594522.sys [2011-09-25 133208]
R0 80387875;80387875; C:\Windows\system32\DRIVERS\80387875.sys [2011-11-13 133208]
R0 iaNvStor;Intel(R) Turbo Memory Controller; C:\Windows\system32\DRIVERS\iaNvStor.sys [2009-07-01 232472]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 330264]
R0 JGOGO;JMicron Hot-Plug Driver; C:\Windows\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2007-04-12 48000]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2011-10-07 488208]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2011-10-07 39640]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-11-12 239168]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2011-10-07 82400]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2011-09-05 12880]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2011-09-05 67664]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-08 45568]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-01-15 2047576]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2007-06-20 49664]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2009-07-14 18432]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 84992]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-05-05 1095808]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-10-01 1769984]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-06 196400]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot4Prt.sys [2010-11-20 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2011-05-10 42496]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2011-09-05 116608]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-24 55144]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-02 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-09-06 44768]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2011-10-07 1883328]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-04 354840]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-07-02 211488]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-11-13 821608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 NVMSLVRNBHFNECS;NVMSLVRNBHFNECS; C:\Users\Home\AppData\Local\Temp\NVMSLVRNBHFNECS.exe [2011-11-28 387968]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-08 1343400]

-----------------EOF-----------------

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 12:33
od Márty84
A ve smlove s poskytovatelem internetu je nemate? Jsou jinak s pc nejake problemy?

Log samozrejme zkontroluju, ale bude to nejakou dobu trvat. Za chvili odchazim do prace a prijdu kolem 18:00. Pak se na to vrhnem poradne :wink:

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 12:36
od raskar89
nikdy to nedelalo, uz jsem tady na foru resil nejake problemy driv, asi rok zpet a toto tam nebylo. Takze je to nove. Jinak zadne problemy nejsou, krome toho ze jsem chtel met po te jedne nakaze, jakou hned zlikvidoval (?) avast jistotu, ze je to ok.

Mockrat dekuju :)

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 12:40
od Márty84
No bylo to tam i predtim, jen jsem si to chtel overit, kdyz to google odkazuje do USA. Nerikam ze je to spatne, jen divne :D A v te smlouve mate tedy jine IP adresy?

A neni zac samozrejme :wink:

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 12:42
od raskar89
bohuzel nedokazu odpovedet, nevim... :( smlouvu nemam k dispozici

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 12:46
od Márty84
Tak to vecer prohlidnem a uvidime. Jestli ji mezitim najdete a schvalne se podivate, bylo by to fajn :) Jistota je jistota. Kdybych to odpalil, mohl by prestat fungovat internet a musel byste tam zadat prave udaje z te smlouvy. Takze proto se na ni porad ptam :)

Ale vzhledem k tomu, ze to tam bylo i drive a nic se nedelo, bude to na 99% v poradku. To jen ja jsem uz paranoik :lol:

Takze pokracovani vecer. Zatim se mejte :)

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 12:48
od raskar89
dekuju, vy take

(smlouva je asi 150km daleko, takze to bohuzel nezvladnu overit)

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 12:52
od Márty84
To je problem? Sednete na vrtulnik a je to :lol:
Tak vecer :)

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 19:07
od Márty84
Dobrej vecir :wink:

Par veci se mi tam nelibi, takze to radeji proverime poradne. Zacneme TDSSKillerem

:arrow: Stahnete TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe a ulozte ho na plochu
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Kliknete na Start scan
Dale postupujte podle navodu kolegy Vyoska
Pokud utilita najde infikekci, bude ji chtit lecit (Cure), povolte leceni kliknutim na Continue
Pokud utilita najde podezrely soubor (suspicious), bude jej chtit preskocit (Skip), povolte preskoceni kliknutim na Continue
Po dokonceni skenu bude mozna nutny restart PC, povolte jej kliknutim na Reboot now
Po restartu na Vas vyskoci log, pokud se tak nestane, najdete jej primo na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt - jeho obsah sem vlozte
Pokud restart nebude vyzadovan, kliknete na Close a nasledne na Report - vytvori se log - jeho obsah sem vlozte
:arrow: Potom se podivejte zde http://www.viry.cz/forum/viewtopic.php?f=29&t=62878 a oba logy sem opet zkopirujte

Podle vysledku pak budeme pokracovat :)

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 19:17
od raskar89
19:15:58.0923 4448 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
19:16:00.0064 4448 ============================================================
19:16:00.0064 4448 Current date / time: 2011/11/29 19:16:00.0064
19:16:00.0064 4448 SystemInfo:
19:16:00.0064 4448
19:16:00.0064 4448 OS Version: 6.1.7601 ServicePack: 1.0
19:16:00.0064 4448 Product type: Workstation
19:16:00.0064 4448 ComputerName: HOME-PC
19:16:00.0064 4448 UserName: Home
19:16:00.0064 4448 Windows directory: C:\Windows
19:16:00.0064 4448 System windows directory: C:\Windows
19:16:00.0064 4448 Processor architecture: Intel x86
19:16:00.0064 4448 Number of processors: 2
19:16:00.0064 4448 Page size: 0x1000
19:16:00.0064 4448 Boot type: Normal boot
19:16:00.0064 4448 ============================================================
19:16:00.0576 4448 Initialize success
19:16:08.0225 1980 ============================================================
19:16:08.0225 1980 Scan started
19:16:08.0225 1980 Mode: Manual; SigCheck; TDLFS;
19:16:08.0225 1980 ============================================================
19:16:08.0609 1980 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
19:16:08.0776 1980 1394ohci - ok
19:16:08.0818 1980 58594522 (186b54479d98e48aee0e9ada4b3c4d31) C:\Windows\system32\DRIVERS\58594522.sys
19:16:09.0304 1980 58594522 - ok
19:16:09.0332 1980 80387875 (186b54479d98e48aee0e9ada4b3c4d31) C:\Windows\system32\DRIVERS\80387875.sys
19:16:09.0360 1980 80387875 - ok
19:16:09.0391 1980 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
19:16:09.0423 1980 ACPI - ok
19:16:09.0502 1980 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
19:16:09.0552 1980 AcpiPmi - ok
19:16:09.0615 1980 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
19:16:09.0652 1980 adp94xx - ok
19:16:09.0680 1980 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
19:16:09.0714 1980 adpahci - ok
19:16:09.0741 1980 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
19:16:09.0777 1980 adpu320 - ok
19:16:09.0821 1980 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
19:16:09.0879 1980 AFD - ok
19:16:09.0920 1980 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
19:16:09.0942 1980 agp440 - ok
19:16:09.0981 1980 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
19:16:10.0005 1980 aic78xx - ok
19:16:10.0052 1980 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
19:16:10.0073 1980 aliide - ok
19:16:10.0112 1980 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
19:16:10.0134 1980 amdagp - ok
19:16:10.0169 1980 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
19:16:10.0189 1980 amdide - ok
19:16:10.0240 1980 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
19:16:10.0285 1980 AmdK8 - ok
19:16:10.0328 1980 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
19:16:10.0377 1980 AmdPPM - ok
19:16:10.0412 1980 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
19:16:10.0433 1980 amdsata - ok
19:16:10.0482 1980 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
19:16:10.0508 1980 amdsbs - ok
19:16:10.0533 1980 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
19:16:10.0554 1980 amdxata - ok
19:16:10.0596 1980 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
19:16:10.0656 1980 AppID - ok
19:16:10.0710 1980 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
19:16:10.0732 1980 arc - ok
19:16:10.0774 1980 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
19:16:10.0797 1980 arcsas - ok
19:16:10.0804 1980 ASMMAP (7b4d08d2017ac06689d422e06c43f0aa) C:\Program Files\ATKGFNEX\ASMMAP.sys
19:16:10.0825 1980 ASMMAP - ok
19:16:10.0854 1980 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\Windows\system32\drivers\aswFsBlk.sys
19:16:10.0878 1980 aswFsBlk - ok
19:16:10.0969 1980 aswMonFlt (4804753a4ec7d67cc22d226bffd1c1e3) C:\Windows\system32\drivers\aswMonFlt.sys
19:16:10.0989 1980 aswMonFlt - ok
19:16:11.0015 1980 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\Windows\system32\drivers\aswRdr.sys
19:16:11.0037 1980 aswRdr - ok
19:16:11.0077 1980 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\Windows\system32\drivers\aswSnx.sys
19:16:11.0118 1980 aswSnx - ok
19:16:11.0153 1980 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\Windows\system32\drivers\aswSP.sys
19:16:11.0191 1980 aswSP - ok
19:16:11.0218 1980 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\Windows\system32\drivers\aswTdi.sys
19:16:11.0240 1980 aswTdi - ok
19:16:11.0325 1980 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
19:16:11.0380 1980 AsyncMac - ok
19:16:11.0409 1980 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
19:16:11.0431 1980 atapi - ok
19:16:11.0493 1980 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
19:16:11.0548 1980 b06bdrv - ok
19:16:11.0588 1980 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
19:16:11.0632 1980 b57nd60x - ok
19:16:11.0662 1980 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
19:16:11.0714 1980 Beep - ok
19:16:11.0744 1980 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
19:16:11.0780 1980 blbdrive - ok
19:16:11.0811 1980 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
19:16:11.0840 1980 bowser - ok
19:16:11.0886 1980 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
19:16:11.0936 1980 BrFiltLo - ok
19:16:11.0974 1980 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
19:16:12.0013 1980 BrFiltUp - ok
19:16:12.0070 1980 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
19:16:12.0122 1980 Brserid - ok
19:16:12.0158 1980 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
19:16:12.0197 1980 BrSerWdm - ok
19:16:12.0241 1980 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
19:16:12.0282 1980 BrUsbMdm - ok
19:16:12.0308 1980 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
19:16:12.0346 1980 BrUsbSer - ok
19:16:12.0396 1980 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\DRIVERS\BthEnum.sys
19:16:12.0463 1980 BthEnum - ok
19:16:12.0510 1980 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
19:16:12.0540 1980 BTHMODEM - ok
19:16:12.0581 1980 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys
19:16:12.0618 1980 BthPan - ok
19:16:12.0673 1980 BTHPORT (c2fbf6d271d9a94d839c416bf186ead9) C:\Windows\System32\Drivers\BTHport.sys
19:16:12.0726 1980 BTHPORT - ok
19:16:12.0770 1980 BTHUSB (c81e9413a25a439f436b1d4b6a0cf9e9) C:\Windows\System32\Drivers\BTHUSB.sys
19:16:12.0801 1980 BTHUSB - ok
19:16:12.0854 1980 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
19:16:12.0909 1980 cdfs - ok
19:16:12.0940 1980 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys
19:16:12.0988 1980 cdrom - ok
19:16:13.0018 1980 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
19:16:13.0055 1980 circlass - ok
19:16:13.0084 1980 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
19:16:13.0113 1980 CLFS - ok
19:16:13.0147 1980 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
19:16:13.0175 1980 CmBatt - ok
19:16:13.0218 1980 cmdGuard (544747035c7fa83d9e9d0a13f6e58bc4) C:\Windows\system32\DRIVERS\cmdguard.sys
19:16:13.0249 1980 cmdGuard - ok
19:16:13.0274 1980 cmdHlp (7faba2d3b4912b8762d1fec63ad12525) C:\Windows\system32\DRIVERS\cmdhlp.sys
19:16:13.0294 1980 cmdHlp - ok
19:16:13.0377 1980 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
19:16:13.0397 1980 cmdide - ok
19:16:13.0435 1980 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
19:16:13.0469 1980 CNG - ok
19:16:13.0495 1980 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
19:16:13.0516 1980 Compbatt - ok
19:16:13.0542 1980 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
19:16:13.0620 1980 CompositeBus - ok
19:16:13.0659 1980 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
19:16:13.0679 1980 crcdisk - ok
19:16:13.0718 1980 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
19:16:13.0760 1980 DfsC - ok
19:16:13.0790 1980 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
19:16:13.0848 1980 discache - ok
19:16:13.0874 1980 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
19:16:13.0896 1980 Disk - ok
19:16:13.0949 1980 Dot4 (b5e479eb83707dd698f66953e922042c) C:\Windows\system32\DRIVERS\Dot4.sys
19:16:13.0983 1980 Dot4 - ok
19:16:14.0027 1980 Dot4Print (caefd09b6a6249c53a67d55a9a9fcabf) C:\Windows\system32\drivers\Dot4Prt.sys
19:16:14.0059 1980 Dot4Print - ok
19:16:14.0098 1980 dot4usb (cf491ff38d62143203c065260567e2f7) C:\Windows\system32\DRIVERS\dot4usb.sys
19:16:14.0139 1980 dot4usb - ok
19:16:14.0185 1980 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
19:16:14.0224 1980 drmkaud - ok
19:16:14.0257 1980 dtsoftbus01 (fb38473835476a6fb272215a1d972af9) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
19:16:14.0281 1980 dtsoftbus01 - ok
19:16:14.0331 1980 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
19:16:14.0371 1980 DXGKrnl - ok
19:16:14.0518 1980 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
19:16:14.0637 1980 ebdrv - ok
19:16:14.0709 1980 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
19:16:14.0741 1980 elxstor - ok
19:16:14.0777 1980 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
19:16:14.0818 1980 ErrDev - ok
19:16:14.0869 1980 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
19:16:14.0928 1980 exfat - ok
19:16:14.0959 1980 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
19:16:15.0018 1980 fastfat - ok
19:16:15.0064 1980 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
19:16:15.0107 1980 fdc - ok
19:16:15.0137 1980 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
19:16:15.0160 1980 FileInfo - ok
19:16:15.0185 1980 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
19:16:15.0247 1980 Filetrace - ok
19:16:15.0282 1980 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
19:16:15.0318 1980 flpydisk - ok
19:16:15.0350 1980 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
19:16:15.0376 1980 FltMgr - ok
19:16:15.0418 1980 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
19:16:15.0439 1980 FsDepends - ok
19:16:15.0466 1980 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
19:16:15.0487 1980 Fs_Rec - ok
19:16:15.0520 1980 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
19:16:15.0548 1980 fvevol - ok
19:16:15.0652 1980 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
19:16:15.0673 1980 gagp30kx - ok
19:16:15.0700 1980 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
19:16:15.0720 1980 GEARAspiWDM - ok
19:16:15.0776 1980 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
19:16:15.0823 1980 hcw85cir - ok
19:16:15.0875 1980 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
19:16:15.0930 1980 HdAudAddService - ok
19:16:15.0959 1980 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
19:16:15.0998 1980 HDAudBus - ok
19:16:16.0050 1980 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
19:16:16.0086 1980 HidBatt - ok
19:16:16.0132 1980 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
19:16:16.0161 1980 HidBth - ok
19:16:16.0187 1980 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
19:16:16.0231 1980 HidIr - ok
19:16:16.0266 1980 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys
19:16:16.0292 1980 HidUsb - ok
19:16:16.0346 1980 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
19:16:16.0368 1980 HpSAMD - ok
19:16:16.0409 1980 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
19:16:16.0476 1980 HTTP - ok
19:16:16.0503 1980 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
19:16:16.0524 1980 hwpolicy - ok
19:16:16.0552 1980 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
19:16:16.0586 1980 i8042prt - ok
19:16:16.0624 1980 iaNvStor (3db9f6f69b8bb99d241b15c7b52e3a3d) C:\Windows\system32\DRIVERS\iaNvStor.sys
19:16:16.0653 1980 iaNvStor - ok
19:16:16.0690 1980 iaStor (d483687eace0c065ee772481a96e05f5) C:\Windows\system32\DRIVERS\iaStor.sys
19:16:16.0717 1980 iaStor - ok
19:16:16.0801 1980 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
19:16:16.0838 1980 iaStorV - ok
19:16:16.0893 1980 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
19:16:16.0915 1980 iirsp - ok
19:16:16.0949 1980 inspect (aa686b40a4f837bc66ad3183b2bbd981) C:\Windows\system32\DRIVERS\inspect.sys
19:16:16.0969 1980 inspect - ok
19:16:17.0062 1980 IntcAzAudAddService (edc37b918e583a5a813c53d4f5588255) C:\Windows\system32\drivers\RTKVHDA.sys
19:16:17.0155 1980 IntcAzAudAddService - ok
19:16:17.0189 1980 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
19:16:17.0211 1980 intelide - ok
19:16:17.0239 1980 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
19:16:17.0316 1980 intelppm - ok
19:16:17.0364 1980 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:16:17.0420 1980 IpFilterDriver - ok
19:16:17.0473 1980 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
19:16:17.0500 1980 IPMIDRV - ok
19:16:17.0543 1980 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
19:16:17.0603 1980 IPNAT - ok
19:16:17.0650 1980 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
19:16:17.0697 1980 IRENUM - ok
19:16:17.0754 1980 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
19:16:17.0775 1980 isapnp - ok
19:16:17.0817 1980 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
19:16:17.0850 1980 iScsiPrt - ok
19:16:17.0877 1980 itecir (eb6f7c665d7b5b4d79573b7cb950f2d4) C:\Windows\system32\DRIVERS\itecir.sys
19:16:17.0926 1980 itecir - ok
19:16:17.0952 1980 JGOGO (c995c0e8b4503fac38793bb0236ad246) C:\Windows\system32\DRIVERS\JGOGO.sys
19:16:17.0982 1980 JGOGO - ok
19:16:18.0008 1980 JRAID (f5bf72eabc7e160bb6624168aad52dfe) C:\Windows\system32\DRIVERS\jraid.sys
19:16:18.0044 1980 JRAID - ok
19:16:18.0071 1980 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
19:16:18.0095 1980 kbdclass - ok
19:16:18.0121 1980 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
19:16:18.0157 1980 kbdhid - ok
19:16:18.0244 1980 kbfiltr (cc2a86d7bbf14977340dca61bbcba771) C:\Windows\system32\DRIVERS\kbfiltr.sys
19:16:18.0275 1980 kbfiltr - ok
19:16:18.0310 1980 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
19:16:18.0335 1980 KSecDD - ok
19:16:18.0364 1980 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
19:16:18.0388 1980 KSecPkg - ok
19:16:18.0429 1980 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
19:16:18.0522 1980 lltdio - ok
19:16:18.0577 1980 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
19:16:18.0601 1980 LSI_FC - ok
19:16:18.0641 1980 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
19:16:18.0665 1980 LSI_SAS - ok
19:16:18.0702 1980 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
19:16:18.0723 1980 LSI_SAS2 - ok
19:16:18.0752 1980 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
19:16:18.0775 1980 LSI_SCSI - ok
19:16:18.0805 1980 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
19:16:18.0864 1980 luafv - ok
19:16:18.0906 1980 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
19:16:18.0927 1980 megasas - ok
19:16:18.0966 1980 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
19:16:18.0993 1980 MegaSR - ok
19:16:19.0024 1980 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
19:16:19.0089 1980 Modem - ok
19:16:19.0119 1980 MODEMCSA (25483f9d590d5f00bd951e1181453ec2) C:\Windows\system32\drivers\MODEMCSA.sys
19:16:19.0150 1980 MODEMCSA - ok
19:16:19.0177 1980 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
19:16:19.0222 1980 monitor - ok
19:16:19.0252 1980 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
19:16:19.0274 1980 mouclass - ok
19:16:19.0301 1980 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
19:16:19.0338 1980 mouhid - ok
19:16:19.0370 1980 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
19:16:19.0393 1980 mountmgr - ok
19:16:19.0451 1980 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
19:16:19.0475 1980 mpio - ok
19:16:19.0503 1980 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
19:16:19.0543 1980 mpsdrv - ok
19:16:19.0593 1980 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
19:16:19.0628 1980 MRxDAV - ok
19:16:19.0660 1980 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:16:19.0698 1980 mrxsmb - ok
19:16:19.0731 1980 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:16:19.0761 1980 mrxsmb10 - ok
19:16:19.0791 1980 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:16:19.0824 1980 mrxsmb20 - ok
19:16:19.0852 1980 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
19:16:19.0875 1980 msahci - ok
19:16:19.0927 1980 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
19:16:19.0951 1980 msdsm - ok
19:16:19.0986 1980 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
19:16:20.0028 1980 Msfs - ok
19:16:20.0061 1980 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
19:16:20.0121 1980 mshidkmdf - ok
19:16:20.0150 1980 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
19:16:20.0173 1980 msisadrv - ok
19:16:20.0215 1980 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
19:16:20.0276 1980 MSKSSRV - ok
19:16:20.0320 1980 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
19:16:20.0379 1980 MSPCLOCK - ok
19:16:20.0416 1980 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
19:16:20.0468 1980 MSPQM - ok
19:16:20.0498 1980 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
19:16:20.0528 1980 MsRPC - ok
19:16:20.0557 1980 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
19:16:20.0579 1980 mssmbios - ok
19:16:20.0610 1980 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
19:16:20.0698 1980 MSTEE - ok
19:16:20.0732 1980 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
19:16:20.0771 1980 MTConfig - ok
19:16:20.0799 1980 MTsensor (97affa9d95ffe20eee6229bc6be166cf) C:\Windows\system32\DRIVERS\ATKACPI.sys
19:16:20.0826 1980 MTsensor - ok
19:16:20.0856 1980 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
19:16:20.0878 1980 Mup - ok
19:16:20.0920 1980 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
19:16:20.0956 1980 NativeWifiP - ok
19:16:21.0005 1980 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
19:16:21.0047 1980 NDIS - ok
19:16:21.0085 1980 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
19:16:21.0126 1980 NdisCap - ok
19:16:21.0158 1980 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
19:16:21.0204 1980 NdisTapi - ok
19:16:21.0232 1980 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
19:16:21.0271 1980 Ndisuio - ok
19:16:21.0301 1980 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
19:16:21.0348 1980 NdisWan - ok
19:16:21.0376 1980 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
19:16:21.0422 1980 NDProxy - ok
19:16:21.0453 1980 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
19:16:21.0495 1980 NetBIOS - ok
19:16:21.0526 1980 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
19:16:21.0571 1980 NetBT - ok
19:16:21.0744 1980 netw5v32 (58218ec6b61b1169cf54aab0d00f5fe2) C:\Windows\system32\DRIVERS\netw5v32.sys
19:16:21.0949 1980 netw5v32 - ok
19:16:21.0994 1980 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
19:16:22.0015 1980 nfrd960 - ok
19:16:22.0047 1980 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
19:16:22.0102 1980 Npfs - ok
19:16:22.0133 1980 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
19:16:22.0174 1980 nsiproxy - ok
19:16:22.0243 1980 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
19:16:22.0329 1980 Ntfs - ok
19:16:22.0356 1980 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
19:16:22.0398 1980 Null - ok
19:16:22.0753 1980 nvlddmkm (5ce5b23855262acabaecce156f48dd88) C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:16:23.0078 1980 nvlddmkm - ok
19:16:23.0165 1980 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
19:16:23.0189 1980 nvraid - ok
19:16:23.0236 1980 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
19:16:23.0261 1980 nvstor - ok
19:16:23.0317 1980 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
19:16:23.0340 1980 nv_agp - ok
19:16:23.0378 1980 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
19:16:23.0418 1980 ohci1394 - ok
19:16:23.0460 1980 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
19:16:23.0492 1980 Parport - ok
19:16:23.0519 1980 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
19:16:23.0542 1980 partmgr - ok
19:16:23.0609 1980 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
19:16:23.0647 1980 Parvdm - ok
19:16:23.0683 1980 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
19:16:23.0708 1980 pci - ok
19:16:23.0736 1980 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
19:16:23.0757 1980 pciide - ok
19:16:23.0808 1980 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
19:16:23.0834 1980 pcmcia - ok
19:16:23.0862 1980 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
19:16:23.0884 1980 pcw - ok
19:16:23.0931 1980 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
19:16:24.0003 1980 PEAUTH - ok
19:16:24.0079 1980 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
19:16:24.0124 1980 PptpMiniport - ok
19:16:24.0161 1980 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
19:16:24.0198 1980 Processor - ok
19:16:24.0237 1980 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
19:16:24.0289 1980 Psched - ok
19:16:24.0362 1980 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
19:16:24.0418 1980 ql2300 - ok
19:16:24.0455 1980 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
19:16:24.0479 1980 ql40xx - ok
19:16:24.0529 1980 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
19:16:24.0560 1980 QWAVEdrv - ok
19:16:24.0599 1980 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
19:16:24.0656 1980 RasAcd - ok
19:16:24.0684 1980 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
19:16:24.0723 1980 RasAgileVpn - ok
19:16:24.0756 1980 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
19:16:24.0809 1980 Rasl2tp - ok
19:16:24.0850 1980 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
19:16:24.0917 1980 RasPppoe - ok
19:16:24.0948 1980 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
19:16:25.0000 1980 RasSstp - ok
19:16:25.0033 1980 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
19:16:25.0079 1980 rdbss - ok
19:16:25.0118 1980 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
19:16:25.0147 1980 rdpbus - ok
19:16:25.0173 1980 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
19:16:25.0222 1980 RDPCDD - ok
19:16:25.0254 1980 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
19:16:25.0305 1980 RDPENCDD - ok
19:16:25.0335 1980 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
19:16:25.0376 1980 RDPREFMP - ok
19:16:25.0413 1980 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
19:16:25.0468 1980 RDPWD - ok
19:16:25.0500 1980 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
19:16:25.0528 1980 rdyboost - ok
19:16:25.0593 1980 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys
19:16:25.0643 1980 RFCOMM - ok
19:16:25.0672 1980 rimmptsk (c35ca13d3627ebd9dd12a23ce781bc3d) C:\Windows\system32\DRIVERS\rimmptsk.sys
19:16:25.0710 1980 rimmptsk - ok
19:16:25.0742 1980 rimsptsk (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys
19:16:25.0769 1980 rimsptsk - ok
19:16:25.0798 1980 rismxdp (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys
19:16:25.0837 1980 rismxdp - ok
19:16:25.0882 1980 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
19:16:25.0924 1980 rspndr - ok
19:16:25.0937 1980 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
19:16:25.0960 1980 SASDIFSV - ok
19:16:25.0974 1980 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
19:16:25.0995 1980 SASKUTIL - ok
19:16:26.0033 1980 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
19:16:26.0057 1980 sbp2port - ok
19:16:26.0102 1980 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
19:16:26.0143 1980 scfilter - ok
19:16:26.0183 1980 sdbus (0328be1c7f1cba23848179f8762e391c) C:\Windows\system32\drivers\sdbus.sys
19:16:26.0222 1980 sdbus - ok
19:16:26.0253 1980 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
19:16:26.0310 1980 secdrv - ok
19:16:26.0371 1980 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
19:16:26.0413 1980 Serenum - ok
19:16:26.0450 1980 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
19:16:26.0493 1980 Serial - ok
19:16:26.0532 1980 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
19:16:26.0560 1980 sermouse - ok
19:16:26.0612 1980 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
19:16:26.0646 1980 sffdisk - ok
19:16:26.0698 1980 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
19:16:26.0733 1980 sffp_mmc - ok
19:16:26.0760 1980 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
19:16:26.0795 1980 sffp_sd - ok
19:16:26.0839 1980 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
19:16:26.0877 1980 sfloppy - ok
19:16:26.0941 1980 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
19:16:26.0963 1980 sisagp - ok
19:16:27.0009 1980 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
19:16:27.0030 1980 SiSRaid2 - ok
19:16:27.0060 1980 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
19:16:27.0083 1980 SiSRaid4 - ok
19:16:27.0117 1980 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
19:16:27.0160 1980 Smb - ok
19:16:27.0223 1980 smserial (7e6628d18d30f14a56c0d9116310ab8a) C:\Windows\system32\DRIVERS\smserial.sys
19:16:27.0277 1980 smserial - ok
19:16:27.0431 1980 SNP2UVC (0302bc619d4a723317e7f8eb0c362bd3) C:\Windows\system32\DRIVERS\snp2uvc.sys
19:16:27.0502 1980 SNP2UVC - ok
19:16:27.0532 1980 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
19:16:27.0554 1980 spldr - ok
19:16:27.0605 1980 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
19:16:27.0643 1980 srv - ok
19:16:27.0685 1980 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
19:16:27.0730 1980 srv2 - ok
19:16:27.0760 1980 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
19:16:27.0788 1980 srvnet - ok
19:16:27.0848 1980 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
19:16:27.0869 1980 stexstor - ok
19:16:27.0901 1980 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
19:16:27.0926 1980 swenum - ok
19:16:27.0964 1980 SynTP (55f6e55cc2430ca8713387106fa79817) C:\Windows\system32\DRIVERS\SynTP.sys
19:16:27.0992 1980 SynTP - ok
19:16:28.0080 1980 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
19:16:28.0134 1980 Tcpip - ok
19:16:28.0202 1980 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
19:16:28.0239 1980 TCPIP6 - ok
19:16:28.0274 1980 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
19:16:28.0313 1980 tcpipreg - ok
19:16:28.0394 1980 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
19:16:28.0432 1980 TDPIPE - ok
19:16:28.0481 1980 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
19:16:28.0530 1980 TDTCP - ok
19:16:28.0560 1980 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
19:16:28.0603 1980 tdx - ok
19:16:28.0632 1980 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
19:16:28.0654 1980 TermDD - ok
19:16:28.0729 1980 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
19:16:28.0771 1980 tssecsrv - ok
19:16:28.0806 1980 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
19:16:28.0856 1980 TsUsbFlt - ok
19:16:28.0887 1980 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
19:16:28.0945 1980 tunnel - ok
19:16:28.0990 1980 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
19:16:29.0013 1980 uagp35 - ok
19:16:29.0059 1980 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
19:16:29.0111 1980 udfs - ok
19:16:29.0199 1980 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
19:16:29.0221 1980 uliagpkx - ok
19:16:29.0253 1980 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
19:16:29.0295 1980 umbus - ok
19:16:29.0344 1980 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
19:16:29.0388 1980 UmPass - ok
19:16:29.0439 1980 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
19:16:29.0474 1980 USBAAPL - ok
19:16:29.0524 1980 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
19:16:29.0552 1980 usbccgp - ok
19:16:29.0602 1980 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
19:16:29.0654 1980 usbcir - ok
19:16:29.0684 1980 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\drivers\usbehci.sys
19:16:29.0710 1980 usbehci - ok
19:16:29.0747 1980 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
19:16:29.0795 1980 usbhub - ok
19:16:29.0850 1980 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys
19:16:29.0887 1980 usbohci - ok
19:16:29.0924 1980 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
19:16:29.0966 1980 usbprint - ok
19:16:30.0003 1980 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
19:16:30.0033 1980 usbscan - ok
19:16:30.0088 1980 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:16:30.0117 1980 USBSTOR - ok
19:16:30.0146 1980 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
19:16:30.0188 1980 usbuhci - ok
19:16:30.0236 1980 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys
19:16:30.0281 1980 usbvideo - ok
19:16:30.0341 1980 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
19:16:30.0364 1980 vdrvroot - ok
19:16:30.0412 1980 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
19:16:30.0458 1980 vga - ok
19:16:30.0487 1980 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
19:16:30.0529 1980 VgaSave - ok
19:16:30.0572 1980 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
19:16:30.0597 1980 vhdmp - ok
19:16:30.0660 1980 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
19:16:30.0682 1980 viaagp - ok
19:16:30.0736 1980 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
19:16:30.0778 1980 ViaC7 - ok
19:16:30.0837 1980 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
19:16:30.0858 1980 viaide - ok
19:16:30.0887 1980 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
19:16:30.0909 1980 volmgr - ok
19:16:30.0946 1980 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
19:16:30.0974 1980 volmgrx - ok
19:16:31.0014 1980 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
19:16:31.0045 1980 volsnap - ok
19:16:31.0121 1980 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
19:16:31.0148 1980 vsmraid - ok
19:16:31.0189 1980 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
19:16:31.0228 1980 vwifibus - ok
19:16:31.0267 1980 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
19:16:31.0295 1980 WacomPen - ok
19:16:31.0326 1980 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
19:16:31.0366 1980 WANARP - ok
19:16:31.0374 1980 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
19:16:31.0412 1980 Wanarpv6 - ok
19:16:31.0514 1980 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
19:16:31.0535 1980 Wd - ok
19:16:31.0579 1980 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
19:16:31.0613 1980 Wdf01000 - ok
19:16:31.0679 1980 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
19:16:31.0722 1980 WfpLwf - ok
19:16:31.0801 1980 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
19:16:31.0821 1980 WIMMount - ok
19:16:31.0941 1980 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
19:16:31.0991 1980 WinUsb - ok
19:16:32.0042 1980 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
19:16:32.0085 1980 WmiAcpi - ok
19:16:32.0156 1980 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
19:16:32.0214 1980 ws2ifsl - ok
19:16:32.0269 1980 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
19:16:32.0314 1980 WudfPf - ok
19:16:32.0346 1980 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
19:16:32.0391 1980 WUDFRd - ok
19:16:32.0447 1980 yukonw7 (30b73eb97218a16cbc6de535782a1b35) C:\Windows\system32\DRIVERS\yk62x86.sys
19:16:32.0531 1980 yukonw7 - ok
19:16:32.0568 1980 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
19:16:32.0594 1980 \Device\Harddisk0\DR0 - ok
19:16:32.0597 1980 Boot (0x1200) (c7209228f0b028edb18abee68fb01af0) \Device\Harddisk0\DR0\Partition0
19:16:32.0598 1980 \Device\Harddisk0\DR0\Partition0 - ok
19:16:32.0602 1980 Boot (0x1200) (96cdad90cc7898c118d40f0e9ba259cd) \Device\Harddisk0\DR0\Partition1
19:16:32.0603 1980 \Device\Harddisk0\DR0\Partition1 - ok
19:16:32.0604 1980 ============================================================
19:16:32.0604 1980 Scan finished
19:16:32.0604 1980 ============================================================
19:16:32.0619 5704 Detected object count: 0
19:16:32.0619 5704 Actual detected object count: 0

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 19:24
od Márty84
Toto je v poradku. Ted ten GMER (oba logy) :)

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 20:03
od raskar89
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-11-29 19:42:02
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 rev.
Running: gmer.exe; Driver: C:\Users\Home\AppData\Local\Temp\kxldipow.sys


---- Disk sectors - GMER 1.0.15 ----

Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior

---- System - GMER 1.0.15 ----

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x9562E9A6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

Re: Prosím o preventivku po nákaze

Napsal: 29 lis 2011 20:08
od raskar89
ta druha cast je strasne velka, tak posilam takto

http://www.nahraj.cz/content/download/d ... ce5a865796