Stránka 1 z 3

Prosím o pomoc, pomalý a problémový chod PC

Napsal: 10 úno 2012 18:11
od Waler22
Dobrý deň,

Môj PC začal sekať, už od štartu je pomalý a na prehliadačoch aj chybuje, dal som sken virusov cez Avast! a ten mi hlási nazov súboru "MBR:\\.\PHYSICALDRIVE0" a stav "Hrozba:Rootkit:hidden boot-sector". Problem je v tom že to nejde vyliečiť ale ani dať do truhly...
Prosím Vás o pomoc.

Tu je log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by PC at 2012-02-10 18:07:59
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 8 GB (20%) free of 40 GB
Total RAM: 2047 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:08:31, on 10.2.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Connection Manager\sysctrl.exe
C:\Program Files\Connection Manager\SamsungPnPServiceManager.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnp325.exe
C:\WINDOWS\vsnp325.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\PC\Desktop\RSIT.exe
C:\Program Files\trend micro\PC.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [Z810SysStart] C:\Program Files\Connection Manager\sysctrl.exe
O4 - HKLM\..\Run: [Z810PNP] C:\Program Files\Connection Manager\SamsungPnPServiceManager.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnp325] C:\WINDOWS\tsnp325.exe
O4 - HKLM\..\Run: [snp325] C:\WINDOWS\vsnp325.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [CleanSetup] cmd /C rmdir /S /Q "C:\Documents and Settings\PC\Local Settings\temp\nro.tmp\"
O4 - HKCU\..\Run: [Z810SysStart] C:\Program Files\Connection Manager\sysctrl.exe
O4 - HKCU\..\Run: [Z810PNP] C:\Program Files\Connection Manager\SamsungPnPServiceManager.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe (User 'Default user')
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.13\AMVConverter\grab.html
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.13\MediaManager\grab.html
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: xfire_lsp_9028.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_9028.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_9028.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_9028.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_9028.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_9028.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - Unknown owner - C:\WINDOWS\ATKKBService.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 8376 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Driver Robot.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-879983540-725345543-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-879983540-725345543-1004UA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{DB3E36F0-C33E-4F18-93D3-AD784973EBE0}.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\ufv0rxup.default

prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "{20a82645-c095-46ed-80e3-08825760534b}:1.2.1, jqs@sun.com:1.0, {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.4, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94, {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94, wtxpcom@mybrowserbar.com:4.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.4.3&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"wrc@avast.com"=C:\Program Files\Alwil Software\Avast5\WebRep\FF
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ngm.nexoneu.com/NxGame]
"Description"=Nexon Game Controller 1.0.0.1
"Path"=C:\Documents and Settings\All Users\Application Data\NexonEU\NGM\npNxGameeu.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=8]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
yahoo.xml
zoznam-sk.xml

C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\ufv0rxup.default\extensions\
ffxtlbr@babylon.com
{20a82645-c095-46ed-80e3-08825760534b}
{800b5000-a755-47e1-992b-48a1c1357f07}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\ufv0rxup.default\searchplugins\
icqplugin-1.xml
icqplugin-10.xml
icqplugin-11.xml
icqplugin-12.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.gif
icqplugin.src
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-11-28 809040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-30 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-30 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2011-11-28 809040]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Z810SysStart"=C:\Program Files\Connection Manager\sysctrl.exe [2008-09-01 307200]
"Z810PNP"=C:\Program Files\Connection Manager\SamsungPnPServiceManager.exe [2008-09-09 122880]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-12-11 98304]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-11-28 3744552]
"FixCamera"=C:\WINDOWS\FixCamera.exe [2007-02-12 20480]
"tsnp325"=C:\WINDOWS\tsnp325.exe [2007-04-21 270336]
"snp325"=C:\WINDOWS\vsnp325.exe [2007-05-10 835584]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"CleanSetup"=cmd /C rmdir /S /Q C:\Documents and Settings\PC\Local Settings\temp\nro.tmp\ []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Z810SysStart"=C:\Program Files\Connection Manager\sysctrl.exe [2008-09-01 307200]
"Z810PNP"=C:\Program Files\Connection Manager\SamsungPnPServiceManager.exe [2008-09-09 122880]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe [2008-08-12 1159168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CleanSetup]
cmd /C rmdir /S /Q C:\Documents and Settings\PC\Local Settings\temp\nro.tmp\ []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-07-29 1259376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
C:\WINDOWS\FixCamera.exe [2007-02-12 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\PC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-10-04 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ6.5\ICQ.exe silent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe [2009-04-17 54576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-12-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Disabled:Microsoft DirectPlay Helper"
"C:\Program Files\SpamBayes\bin\sb_tray.exe"="C:\Program Files\SpamBayes\bin\sb_tray.exe:*:Disabled:sb_tray"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Medal of Honor Pacific assault\mohpa.exe"="D:\Medal of Honor Pacific assault\mohpa.exe:*:Disabled:Medal of Honor Pacific Assault(tm)"
"D:\Program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe"="D:\Program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32"
"D:\Program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe"="D:\Program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"D:\Program files\Call of Duty 4 - Modern Warfare\iw3mp.exe"="D:\Program files\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Documents and Settings\PC\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe"="C:\Documents and Settings\PC\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe:*:Disabled:Main program for Octoshape client"
"C:\Documents and Settings\All Users\Application Data\NexonEU\NGM\NGM.exe"="C:\Documents and Settings\All Users\Application Data\NexonEU\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java(TM) Platform SE binary"
"D:\Medal of Honor Pacific assault\mohpa_server.exe"="D:\Medal of Honor Pacific assault\mohpa_server.exe:*:Disabled:Medal of Honor Pacific Assault(tm)"
"D:\Program files\Warcraft III\War3.exe"="D:\Program files\Warcraft III\War3.exe:*:Disabled:Warcraft III"
"D:\Program files\Modern Warfare 2\iw4mp.exe"="D:\Program files\Modern Warfare 2\iw4mp.exe:*:Enabled:iw4mp"
"D:\Program files\Modern Warfare 2\iw4sp.exe"="D:\Program files\Modern Warfare 2\iw4sp.exe:*:Disabled:iw4sp"
"D:\Program files\Modern Warfare 2\iw4mp.dat"="D:\Program files\Modern Warfare 2\iw4mp.dat:*:Enabled:iw4mp"
"C:\Program Files\Assasins\Assassin's Creed Brotherhood\ACBSP.exe"="C:\Program Files\Assasins\Assassin's Creed Brotherhood\ACBSP.exe:*:Enabled:ACBSP"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Mozilla Firefox\plugin-container.exe"="C:\Program Files\Mozilla Firefox\plugin-container.exe:*:Disabled:Plugin Container for Firefox"
"D:\Program files\Electronic Arts\Crytek\Crysis 2\bin32\Crysis2.exe"="D:\Program files\Electronic Arts\Crytek\Crysis 2\bin32\Crysis2.exe:*:Disabled:Crysis2"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Goiceasoft Studios\Counter Strike 1.8 Goiceasoft\cstrike.exe"="C:\Program Files\Goiceasoft Studios\Counter Strike 1.8 Goiceasoft\cstrike.exe:*:Enabled:CS 1.8 Goiceasoft"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Program files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="D:\Program files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Documents and Settings\PC\Local Settings\temp\Rar$EX03.453\Celestial World\metin2client.bin"="C:\Documents and Settings\PC\Local Settings\temp\Rar$EX03.453\Celestial World\metin2client.bin:*:Enabled:metin2client"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"MSVideo8"=VfWWDM32.dll
"vidc.asv2"=asusasv2.dll
"msacm.divxa32"=msaud32_divx.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll

======List of files/folders created in the last 1 month======

2012-02-09 21:37:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-02-09 21:36:20 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2012-02-09 19:44:04 ----A---- C:\WINDOWS\ntbtlog.txt
2012-01-24 18:36:43 ----A---- C:\WINDOWS\system32\drivers\PnkBstrK.sys
2012-01-24 18:35:50 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2012-01-24 18:35:26 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2012-01-24 17:19:36 ----D---- C:\Program Files\DirectX 11

======List of files/folders modified in the last 1 month======

2012-02-10 18:08:16 ----D---- C:\Program Files\trend micro
2012-02-10 18:03:17 ----D---- C:\WINDOWS\Prefetch
2012-02-10 17:55:25 ----D---- C:\WINDOWS\Temp
2012-02-10 17:27:27 ----D---- C:\Documents and Settings\PC\Application Data\Skype
2012-02-10 16:47:42 ----D---- C:\Program Files\Connection Manager
2012-02-10 14:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2012-02-09 22:57:09 ----D---- C:\Documents and Settings\All Users\Application Data\DriverGenius
2012-02-09 22:51:32 ----SHD---- C:\System Volume Information
2012-02-09 22:51:32 ----D---- C:\WINDOWS\system32\Restore
2012-02-09 21:40:10 ----D---- C:\WINDOWS\SoftwareDistribution
2012-02-09 21:39:28 ----D---- C:\WINDOWS
2012-02-09 21:38:44 ----D---- C:\WINDOWS\system32\LogFiles
2012-02-09 21:36:20 ----D---- C:\WINDOWS\system32
2012-02-09 19:42:38 ----D---- C:\WINDOWS\Minidump
2012-02-09 18:08:30 ----SHD---- C:\WINDOWS\Installer
2012-02-09 18:08:23 ----D---- C:\WINDOWS\system32\CatRoot2
2012-02-07 21:05:59 ----D---- C:\WINDOWS\system32\config
2012-02-07 14:27:45 ----D---- C:\WINDOWS\Logs
2012-02-07 14:27:45 ----D---- C:\WINDOWS\Debug
2012-02-04 12:54:21 ----D---- C:\Program Files\Valve
2012-02-03 03:18:42 ----D---- C:\Program Files\Mozilla Firefox
2012-01-30 19:29:43 ----AC---- C:\WINDOWS\NeroDigital.ini
2012-01-24 18:36:43 ----D---- C:\WINDOWS\system32\drivers
2012-01-24 18:29:06 ----RSD---- C:\WINDOWS\assembly
2012-01-24 18:28:20 ----D---- C:\WINDOWS\system32\DirectX
2012-01-24 17:28:41 ----HD---- C:\WINDOWS\inf
2012-01-24 17:19:42 ----RD---- C:\Program Files
2012-01-23 12:52:04 ----D---- C:\Config.Msi
2012-01-13 20:32:35 ----D---- C:\Documents and Settings\PC\Application Data\ICQ
2012-01-12 17:53:43 ----D---- C:\WINDOWS\Microsoft.NET
2012-01-12 00:40:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-01-12 00:35:40 ----A---- C:\WINDOWS\system32\MRT.exe
2012-01-12 00:34:41 ----HD---- C:\WINDOWS\$hf_mig$
2012-01-11 13:36:34 ----D---- C:\WINDOWS\system32\CatRoot
2012-01-11 00:14:31 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-01-11 00:13:09 ----D---- C:\WINDOWS\WinSxS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\WINDOWS\system32\DRIVERS\gagp30kx.sys [2008-04-13 46464]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-08-09 114016]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2006-03-26 51200]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-03-13 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2005-08-10 19968]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-11-03 63488]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-02-27 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R0 xmasscsi;xmasscsi; C:\WINDOWS\System32\Drivers\xmasscsi.sys [2003-12-23 5248]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 EIO_XP;EIO_XP; \??\C:\WINDOWS\system32\drivers\EIO_XP.sys []
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-08-09 53920]
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-02-28 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-05-23 271360]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-05-23 18048]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2006-11-10 18688]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-03-20 3960000]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect; C:\WINDOWS\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-05-30 13184]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-12-11 4525056]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-07-02 89600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-02-26 81408]
R3 SNP325;USB PC Camera (SNPSTD325); C:\WINDOWS\system32\DRIVERS\snp325.sys [2007-05-07 10343168]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S0 def;def; C:\WINDOWS\System32\Drivers\def.sys []
S3 a8ct9awu;a8ct9awu; C:\WINDOWS\system32\drivers\a8ct9awu.sys []
S3 ASPI;Advanced SCSI Programming Interface Driver; \??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys []
S3 ASUSVRC;ASUSTeK Virtual Capture Device; C:\WINDOWS\system32\DRIVERS\AsusVRC.sys [2007-01-29 18432]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2008-03-31 223128]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2009-03-19 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2009-03-19 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-01-15 47360]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\WINDOWS\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s117mdfl;Sony Ericsson Device 117 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s117mdfl.sys [2007-06-25 14888]
S3 s117mdm;Sony Ericsson Device 117 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s117mdm.sys [2007-06-25 108456]
S3 s117mgmt;Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s117mgmt.sys [2007-06-25 100264]
S3 s117nd5;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS); C:\WINDOWS\system32\DRIVERS\s117nd5.sys [2007-06-25 22952]
S3 s117obex;Sony Ericsson Device 117 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s117obex.sys [2007-06-25 98344]
S3 s117unic;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM); C:\WINDOWS\system32\DRIVERS\s117unic.sys [2007-06-25 98856]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver; C:\WINDOWS\system32\DRIVERS\ss_bserd.sys [2010-04-27 100224]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2009-10-15 98560]
S3 sscdserd;SAMSUNG Mobile Modem Diagnostic Serial Port (WDM); C:\WINDOWS\system32\DRIVERS\sscdserd.sys [2009-10-15 100352]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys []
S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys []
S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys []
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 xmasbus;xmasbus; C:\WINDOWS\system32\DRIVERS\xmasbus.sys [2003-12-21 140800]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2011-12-13 748440]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-12-11 602112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-11-28 44768]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-07-24 53248]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2012-01-24 66872]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-03-04 621056]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 10 úno 2012 18:16
od vyosek
Zdravim a pekny vecer preji :)

:arrow: Stahnete aswMBR http://public.avast.com/%7Egmerek/aswMBR.exe a ulozte jej na plochu.
  • Utilitu spustte a prikazte ji, at skenuje - klik na Scan
  • Kliknutim na Save log ulozte log aswMBR na plochu
  • Obsah logu aswMBR mi sem vlozte

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 10 úno 2012 18:55
od Waler22
tu je ten log avšak pc skenuje ďalej ostatné priečinky

aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-02-10 18:20:47
-----------------------------
18:20:47.953 OS Version: Windows 5.1.2600 Service Pack 3
18:20:47.953 Number of processors: 1 586 0x4F02
18:20:47.953 ComputerName: SEMPRON643000 UserName: PC
18:20:50.046 Initialize success
18:20:53.218 AVAST engine defs: 12021000
18:21:11.828 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
18:21:11.828 Disk 0 Vendor: Size: 0MB BusType: 0
18:21:11.828 Disk 0 MBR read successfully
18:21:11.828 Disk 0 MBR scan
18:21:11.828 Disk 0 MBR:Whistler-C [Rtk]
18:21:11.843 Disk 0 Whistler@MBR code has been found
18:21:11.843 Disk 0 MBR hidden
18:21:11.843 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 39997 MB offset 63
18:21:11.843 Disk 0 Partition - 00 0F Extended LBA 74465 MB offset 81915435
18:21:11.859 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 74465 MB offset 81915498
18:21:11.859 Disk 0 MBR [Whistler] **ROOTKIT**
18:21:11.890 Disk 0 scanning C:\WINDOWS\system32\drivers
18:21:48.359 Service scanning
18:21:53.390 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
18:21:54.078 Modules scanning
18:22:28.484 Disk 0 trace - called modules:
18:22:28.500 ntkrnlpa.exe >>UNKNOWN [0x89f9ea0a]<<
18:22:28.500 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a8a8ab8]
18:22:28.500 \Driver\Disk[0x8a81e910] -> IRP_MJ_READ -> 0x89f9ea0a
18:22:31.000 AVAST engine scan C:\WINDOWS
18:22:48.828 AVAST engine scan C:\WINDOWS\system32
18:33:49.796 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\PC\Desktop\MBR.dat"
18:33:49.875 The log file has been saved successfully to "C:\Documents and Settings\PC\Desktop\aswMBR.txt"

Mám radšej počkať a dať log až potom čo mi preskenuje všetky súbory? :)

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 10 úno 2012 18:57
od vyosek
:arrow: Sken muzete ukoncit, tohle staci...

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller ... r_TEST.exe
  • :cap: Jedna se o testovaci verzi prelozeneho RK - proto je v nazvu ten TEST :) v navodu nize jsou i anglicke nazvy prikazu kdyby CZ nefungovala
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 10 úno 2012 19:02
od Waler22
Malo by to byť ono, ukázalo mi to po kliknutí tlačidla "prehľadať", potom "správa"

RogueKiller V7.0.4 [02/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operačný systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spustené v : Normálny režim
Užívateľ: PC [Práva Správcu]
Mode: Kontrola -- Date : 02/10/2012 19:00:31

¤¤¤ Škodlivé procesy: 3 ¤¤¤
[SUSP PATH] FixCamera.exe -- C:\WINDOWS\FixCamera.exe -> KILLED [TermProc]
[SUSP PATH] tsnp325.exe -- C:\WINDOWS\tsnp325.exe -> KILLED [TermProc]
[SUSP PATH] vsnp325.exe -- C:\WINDOWS\vsnp325.exe -> KILLED [TermProc]

¤¤¤ Záznamy Registrov: 7 ¤¤¤
[SUSP PATH] HKLM\[...]\Run : FixCamera (C:\WINDOWS\FixCamera.exe) -> FOUND
[SUSP PATH] HKLM\[...]\Run : tsnp325 (C:\WINDOWS\tsnp325.exe) -> FOUND
[SUSP PATH] HKLM\[...]\Run : snp325 (C:\WINDOWS\vsnp325.exe) -> FOUND
[SUSP PATH] HKLM\[...]\RunOnce : CleanSetup (cmd /C rmdir /S /Q "C:\Documents and Settings\PC\Local Settings\temp\nro.tmp\") -> FOUND
[PROXY IE] HKLM\[...]\Internet Settings : ProxyServer (hxxplocalhost:7171) -> FOUND
[PROXY IE] HKLM\[...]\Internet Settings : ProxyEnable (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Zvláštne súbory / Adresáre: ¤¤¤

¤¤¤ Ovládač: [NAHRATÉ] ¤¤¤

¤¤¤ Nákaza : Root.MBR ¤¤¤

¤¤¤ Súbor HOSTS: ¤¤¤
127.0.0.1 localhost
127.0.0.1 serial.alcohol-soft.com
127.0.0.1 www.alcohol-soft.com
127.0.0.1 images.alcohol-soft.com
127.0.0.1 trial.alcohol-soft.com
127.0.0.1 alcohol-soft.com
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
[...]


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD1200JS-00NCB1 +++++
--- User ---
[MBR] 22c94a85067eb99168c9908807e3a565
[BSP] 27a22ff15a0dd8afa36d9c48d1ee9954 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 39997 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 81915435 | Size: 74465 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] 766f8d680e26f008fb1b404ffa62e372
[BSP] 75a698d5fdbcefc4d3b8dd04508046e4 : Whistler MBR Code!
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 39997 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 81915435 | Size: 74465 Mo

+++++ PhysicalDrive1: Sony USB HS-CF Card USB Device +++++
--- User ---
[MBR] 22c94a85067eb99168c9908807e3a565
[BSP] 27a22ff15a0dd8afa36d9c48d1ee9954 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 39997 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 81915435 | Size: 74465 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive2: Sony USB HS-SM Card USB Device +++++
--- User ---
[MBR] 22c94a85067eb99168c9908807e3a565
[BSP] 27a22ff15a0dd8afa36d9c48d1ee9954 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 39997 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 81915435 | Size: 74465 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive3: Sony USB HS-MS Card USB Device +++++
--- User ---
[MBR] 22c94a85067eb99168c9908807e3a565
[BSP] 27a22ff15a0dd8afa36d9c48d1ee9954 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 39997 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 81915435 | Size: 74465 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive4: Sony USB HS-SD Card USB Device +++++
--- User ---
[MBR] 22c94a85067eb99168c9908807e3a565
[BSP] 27a22ff15a0dd8afa36d9c48d1ee9954 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 39997 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 81915435 | Size: 74465 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončené : << RKreport[1].txt >>
RKreport[1].txt

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 10 úno 2012 19:06
od vyosek
:frusty: Moje chybka, ona je vlastne uz i SK verze, ale tak prelozit CZ do SK uz neni problem :D

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 09:35
od Waler22
Takže tu je ten log, dal som ho až dnes, nebol som doma....

ComboFix 12-02-10.03 - PC 10.02.2012 23:23:30.8.1 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1350 [GMT 1:00]
Running from: c:\documents and settings\PC\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\PC\Application Data\vso_ts_preview.xml
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\FF\chrome.manifest
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.xul
c:\program files\Dealio Toolbar\FF\chrome\content\JSWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\login.js
c:\program files\Dealio Toolbar\FF\chrome\content\login.xul
c:\program files\Dealio Toolbar\FF\chrome\content\parser.js
c:\program files\Dealio Toolbar\FF\chrome\content\RadioWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\RadioWidget.xul
c:\program files\Dealio Toolbar\FF\chrome\content\RssTickerWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.xul
c:\program files\Dealio Toolbar\FF\chrome\content\utils.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgicomm.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgihandling.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgichevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgilisteners.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgiui.js
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
c:\program files\Dealio Toolbar\FF\chrome\skin\amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\apple.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\barnes.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\bestbuy.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\facebook.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\googleplus.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\icon_settings.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\macys.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\newegg.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\overstock.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radio-close.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radio-minimize.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radiobeta.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-baidu.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-yandex.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_baidu.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_dealio.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yandex.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\searchbox.css
c:\program files\Dealio Toolbar\FF\chrome\skin\splitter.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\target.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\twitter.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\walmart.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\widgitoolbarplugin.css
c:\program files\Dealio Toolbar\FF\install.rdf
c:\program files\Dealio Toolbar\IE\4.9\config.ini
c:\program files\Dealio Toolbar\IE\4.9\dealioToolbarIE.dll
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\facebook.gif
c:\program files\Dealio Toolbar\Res\googleplus.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\Lang\res1031.ini
c:\program files\Dealio Toolbar\Res\Lang\res1033.ini
c:\program files\Dealio Toolbar\Res\Lang\res1034.ini
c:\program files\Dealio Toolbar\Res\Lang\res1036.ini
c:\program files\Dealio Toolbar\Res\Lang\res1040.ini
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\radio-close.gif
c:\program files\Dealio Toolbar\Res\radio-minimize.gif
c:\program files\Dealio Toolbar\Res\radiobeta.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_baidu.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\search_yandex.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\twitter.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\program files\VVSN
c:\windows\system32\CF23592.exe
c:\windows\system32\CF26436.exe
c:\windows\system32\kabaker.dll
c:\windows\system32\SET3A.tmp
c:\windows\system32\SET4D.tmp
c:\windows\system32\SETA.tmp
c:\windows\vb.jpg
.
.
((((((((((((((((((((((((( Files Created from 2012-01-10 to 2012-02-10 )))))))))))))))))))))))))))))))
.
.
2012-01-24 17:36 . 2012-01-27 21:49 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-01-24 17:35 . 2012-01-27 21:48 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-01-24 17:35 . 2012-01-24 17:35 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-01-24 16:19 . 2012-01-24 16:21 -------- d-----w- c:\program files\DirectX 11
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-28 18:01 . 2011-01-30 23:13 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2009-11-15 18:55 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-05-16 08:39 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2009-11-15 18:55 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2009-11-15 18:55 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2009-11-15 18:55 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2009-11-15 18:55 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2009-11-15 18:55 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2009-11-15 18:55 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2009-11-15 18:55 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2006-02-28 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 15:23 . 2011-11-23 15:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25 . 2006-02-28 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2006-02-28 12:00 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2006-02-28 12:00 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2006-02-28 12:00 152064 ----a-w- c:\windows\system32\schannel.dll
2012-02-03 02:17 . 2011-05-08 00:02 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Z810SysStart"="c:\program files\Connection Manager\sysctrl.exe" [2008-09-01 307200]
"Z810PNP"="c:\program files\Connection Manager\SamsungPnPServiceManager.exe" [2008-09-09 122880]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Z810SysStart"="c:\program files\Connection Manager\sysctrl.exe" [2008-09-01 307200]
"Z810PNP"="c:\program files\Connection Manager\SamsungPnPServiceManager.exe" [2008-09-09 122880]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-11 98304]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-12 20480]
"tsnp325"="c:\windows\tsnp325.exe" [2007-04-21 270336]
"snp325"="c:\windows\vsnp325.exe" [2007-05-10 835584]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"CleanSetup"="rmdir" [X]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10b.exe" [2009-02-03 240544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CleanSetup]
rmdir [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2009-04-24 03:21 203928 ----a-w- c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
2008-08-12 10:03 1159168 ----a-w- c:\program files\ASUS\SmartDoctor\SmartDoctor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
2007-02-12 13:50 20480 ----a-w- c:\windows\FixCamera.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-10-04 21:41 136176 ----atw- c:\documents and settings\PC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2009-04-17 13:33 54576 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\SpamBayes\\bin\\sb_tray.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Program files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"d:\\Program files\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\PC\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonEU\\NGM\\NGM.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\Program files\\Warcraft III\\War3.exe"=
"d:\\Program files\\Modern Warfare 2\\iw4mp.exe"=
"d:\\Program files\\Modern Warfare 2\\iw4sp.exe"=
"d:\\Program files\\Modern Warfare 2\\iw4mp.dat"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"d:\\Program files\\Electronic Arts\\Crytek\\Crysis 2\\bin32\\Crysis2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"d:\\Program files\\World of Warcraft\\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
.
R0 def;def;c:\windows\System32\Drivers\def.sys [x]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 16512]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-12-22 36640]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-03-19 136704]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-03-19 8320]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2010-01-15 47360]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
R3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\DRIVERS\ss_bserd.sys [2010-04-27 100224]
R4 xmasbus;xmasbus;c:\windows\system32\DRIVERS\xmasbus.sys [2003-12-21 140800]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-27 691696]
S0 xmasscsi;xmasscsi;c:\windows\System32\Drivers\xmasscsi.sys [2003-12-23 5248]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2011-12-13 748440]
S2 aswFsBlk;aswFsBlk; [x]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-05-30 13184]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\DRIVERS\snp325.sys [2007-05-07 10343168]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - TRUESIGHT
*Deregistered* - TrueSight
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-879983540-725345543-1004Core.job
- c:\documents and settings\PC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-10-04 21:41]
.
2012-02-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-879983540-725345543-1004UA.job
- c:\documents and settings\PC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-10-04 21:41]
.
2012-02-10 c:\windows\Tasks\User_Feed_Synchronization-{DB3E36F0-C33E-4F18-93D3-AD784973EBE0}.job
- c:\windows\system32\msfeedssync.exe [2009-05-14 02:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Connection Wizard,ShellNext = iexplore
IE: Add to AMV Converter... - c:\program files\MP3 Player Utilities 4.13\AMVConverter\grab.html
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.13\MediaManager\grab.html
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
LSP: xfire_lsp_9028.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\PC\Application Data\Mozilla\Firefox\Profiles\ufv0rxup.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q=
pref('extensions.shownSelectionUI',true); pref('extensions.autoDisableScopes',0);
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-Wdf01000.sys
MSConfigStartUp-ArcSoft Connection Service - c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
MSConfigStartUp-ICQ - c:\program files\ICQ6.5\ICQ.exe
AddRemove-01_Simmental - c:\program files\SAMSUNG\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\SAMSUNG\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\SAMSUNG\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\SAMSUNG\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\SAMSUNG\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\SAMSUNG\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\SAMSUNG\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\SAMSUNG\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\SAMSUNG\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\SAMSUNG\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\SAMSUNG\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\SAMSUNG\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\SAMSUNG\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\SAMSUNG\USB Drivers\20_NXP_Driver\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-11 00:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
c:\program files\Internet Explorer\iexplore.exe [3776] 0x89890B98
c:\program files\Internet Explorer\iexplore.exe [2264] 0x897E5368
c:\program files\Internet Explorer\iexplore.exe [1564] 0x89779610
c:\program files\Internet Explorer\iexplore.exe [624] 0x89666180
c:\program files\Internet Explorer\iexplore.exe [816] 0x89A0FBE8
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Z810SysStart = c:\program files\Connection Manager\sysctrl.exe?HC???????????????9?Z}??????Z????????????59?ZXC??HC??<?A?I:?Z????<?A?????????????<?A?????4?A~????}??????????????????????????????? ?B~??A~????????Z?A~@???*?A~???????????????????????????????????????????????????
Z810PNP = c:\program files\Connection Manager\SamsungPnPServiceManager.exe???????|????h???????6??|????????@???`???x???`???|??|????????????????????????????????????????????????d??????????|p???0???A??||??????????|????H???A??|????]??|???????????|????????=??w????????????
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Z810SysStart = c:\program files\Connection Manager\sysctrl.exe?HC???????????????9?Z}??????Z????????????59?ZXC??HC??<?A?I:?Z????<?A?????????????<?A?????4?A~????}??????????????????????????????? ?B~??A~????????Z?A~@???*?A~???????????????????????????????????????????????????
Z810PNP = c:\program files\Connection Manager\SamsungPnPServiceManager.exe???????|????h???????6??|????????@???`???x???`???|??|????????????????????????????????????????????????d??????????|p???0???A??||??????????|????H???A??|????]??|???????????|????????=??w????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): Proces nemôže získať prístup k súboru, pretože daný súbor práve používa iný proces.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,61,db,18,93,ea,ed,43,be,00,ad,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,61,db,18,93,ea,ed,43,be,00,ad,\
.
[HKEY_USERS\S-1-5-21-1801674531-879983540-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1801674531-879983540-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:1c,c9,ed,ef,b5,be,93,eb,05,ef,be,c2,a6,ac,dc,ca,d2,53,cd,99,cc,3a,ed,
78,23,5d,62,90,b9,48,e5,cd,e1,39,c1,c3,1c,df,4f,dc,2b,ae,8a,d4,62,73,c7,c6,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49
.
[HKEY_USERS\S-1-5-21-1801674531-879983540-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:1d,ab,6d,8d,06,c2,68,f4,42,89,52,9f,20,84,11,8b,f6,6b,54,87,10,
0b,c2,fc,ca,bb,8e,d7,51,85,66,5e,8b,7c,c4,29,73,51,af,24,c6,90,cc,d4,be,68,\
"rkeysecu"=hex:55,e4,61,e0,34,b1,fc,45,9a,f9,f3,30,a5,b5,6c,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\]*‘|8~*]
"DisplayName"="?\11???"
"DeviceDesc"="?\11???"
"ProviderName"=""
"MFG"="? ? ?"
"ReinstallString"="c:\\WINDOWS\\System32\\ReinstallBackups\\]??\15\\DriverFiles\\.INF"
"DeviceInstanceIds"=multi:"\0c\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(604)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(676)
c:\windows\system32\xfire_lsp_9028.dll
.
Completion time: 2012-02-11 00:34:34
ComboFix-quarantined-files.txt 2012-02-10 23:34
.
Pre-Run: 7 893 037 056 bytes free
Post-Run: 8 705 462 272 voľných bajtov
.
- - End Of File - - 767E1355A063F31554480FAAF19324E3

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 17:09
od cernohous13
Zdravím, aby ses při čekání nenudil, můžeš sem dát kolegovi log podle návodu :wink:
Naughty píše: :arrow: Po stažení http://support.kaspersky.com/downloads/ ... killer.exe na plochu.

- spusť
- klik na volbu change parameters
- označ ve spodním okně obě možnosti (klik do čtverečku) -> OK
- klik na Start scan
- po ukončení kontroly objeví se okno, kde zkontroluj, zda se nachází všude volby Skip
- pokud ano klik na Continue
- pokud ne, v řádcích kde není uprav na Skip, nyní klik na Continue
- na disku C se objeví textový soubor majicí přibližně tvar TDSSKiller.2.6.2.0_27.09.2011_10.16.46_log
- obsah logu vlož do příspěvku.

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 18:13
od Waler22
takže tu je ten log od programu kaspersky


18:06:39.0984 3852 TDSS rootkit removing tool 2.7.11.0 Feb 9 2012 10:12:57
18:06:40.0359 3852 ============================================================
18:06:40.0359 3852 Current date / time: 2012/02/11 18:06:40.0359
18:06:40.0359 3852 SystemInfo:
18:06:40.0359 3852
18:06:40.0359 3852 OS Version: 5.1.2600 ServicePack: 3.0
18:06:40.0359 3852 Product type: Workstation
18:06:40.0359 3852 ComputerName: SEMPRON643000
18:06:40.0359 3852 UserName: PC
18:06:40.0359 3852 Windows directory: C:\WINDOWS
18:06:40.0359 3852 System windows directory: C:\WINDOWS
18:06:40.0359 3852 Processor architecture: Intel x86
18:06:40.0359 3852 Number of processors: 1
18:06:40.0359 3852 Page size: 0x1000
18:06:40.0359 3852 Boot type: Normal boot
18:06:40.0359 3852 ============================================================
18:06:48.0562 3852 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
18:06:48.0625 3852 \Device\Harddisk0\DR0:
18:06:48.0625 3852 MBR used
18:06:48.0625 3852 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4E1EDEC
18:06:48.0625 3852 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x4E1EE6A, BlocksNum 0x9170A96
18:06:48.0703 3852 Initialize success
18:06:48.0703 3852 ============================================================
18:07:26.0640 0348 ============================================================
18:07:26.0640 0348 Scan started
18:07:26.0640 0348 Mode: Manual; SigCheck; TDLFS;
18:07:26.0640 0348 ============================================================
18:07:27.0218 0348 Aavmker4 (b6de0336f9f4b687b4ff57939f7b657a) C:\WINDOWS\system32\drivers\Aavmker4.sys
18:07:27.0453 0348 Aavmker4 - ok
18:07:27.0718 0348 Abiosdsk - ok
18:07:27.0984 0348 abp480n5 - ok
18:07:28.0375 0348 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:07:36.0578 0348 ACPI - ok
18:07:37.0109 0348 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
18:07:37.0781 0348 ACPIEC - ok
18:07:38.0125 0348 adpu160m - ok
18:07:38.0500 0348 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
18:07:39.0015 0348 aec - ok
18:07:39.0562 0348 Afc (fe3ea6e9afc1a78e6edca121e006afb7) C:\WINDOWS\system32\drivers\Afc.sys
18:07:44.0062 0348 Afc - ok
18:07:44.0421 0348 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
18:07:45.0437 0348 AFD - ok
18:07:45.0750 0348 Aha154x - ok
18:07:46.0062 0348 aic78u2 - ok
18:07:46.0406 0348 aic78xx - ok
18:07:48.0359 0348 ALCXWDM (706aa8374b4fc02d8a42493f16d5c3a4) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
18:08:06.0140 0348 ALCXWDM - ok
18:08:07.0406 0348 AliIde - ok
18:08:07.0781 0348 amsint - ok
18:08:08.0406 0348 ArcSoftKsUFilter (bf8470e29873dd3f725f18709928c85f) C:\WINDOWS\system32\DRIVERS\ArcSoftKsUFilter.sys
18:08:10.0609 0348 ArcSoftKsUFilter - ok
18:08:10.0890 0348 asc - ok
18:08:11.0187 0348 asc3350p - ok
18:08:11.0546 0348 asc3550 - ok
18:08:11.0937 0348 ASPI (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\System32\DRIVERS\ASPI32.sys
18:08:12.0093 0348 ASPI ( UnsignedFile.Multi.Generic ) - warning
18:08:12.0093 0348 ASPI - detected UnsignedFile.Multi.Generic (1)
18:08:12.0625 0348 asuskbnt (f5c2ccdb273a546e9c3a15250f1d9165) C:\WINDOWS\system32\drivers\atkkbnt.sys
18:08:12.0796 0348 asuskbnt ( UnsignedFile.Multi.Generic ) - warning
18:08:12.0796 0348 asuskbnt - detected UnsignedFile.Multi.Generic (1)
18:08:13.0093 0348 ASUSVRC (94442e3029ff6c9f08140fe6718af4fb) C:\WINDOWS\system32\DRIVERS\AsusVRC.sys
18:08:13.0250 0348 ASUSVRC ( UnsignedFile.Multi.Generic ) - warning
18:08:13.0265 0348 ASUSVRC - detected UnsignedFile.Multi.Generic (1)
18:08:13.0750 0348 aswFsBlk (054df24c92b55427e0757cfff160e4f2) C:\WINDOWS\system32\drivers\aswFsBlk.sys
18:08:13.0859 0348 aswFsBlk - ok
18:08:14.0187 0348 aswMon2 (ef0e9ad83380724bd6fbbb51d2d0f5b8) C:\WINDOWS\system32\drivers\aswMon2.sys
18:08:14.0328 0348 aswMon2 - ok
18:08:14.0671 0348 aswRdr (352d5a48ebab35a7693b048679304831) C:\WINDOWS\system32\drivers\aswRdr.sys
18:08:14.0750 0348 aswRdr - ok
18:08:15.0187 0348 aswSnx (8d34d2b24297e27d93e847319abfdec4) C:\WINDOWS\system32\drivers\aswSnx.sys
18:08:15.0703 0348 aswSnx - ok
18:08:16.0125 0348 aswSP (010012597333da1f46c3243f33f8409e) C:\WINDOWS\system32\drivers\aswSP.sys
18:08:16.0312 0348 aswSP - ok
18:08:16.0625 0348 aswTdi (f9f84364416658e9786235904d448d37) C:\WINDOWS\system32\drivers\aswTdi.sys
18:08:16.0781 0348 aswTdi - ok
18:08:17.0078 0348 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:08:17.0546 0348 AsyncMac - ok
18:08:17.0906 0348 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
18:08:18.0609 0348 atapi - ok
18:08:19.0859 0348 Atdisk - ok
18:08:22.0812 0348 ati2mtag (323b30faae1f544a549ebbbd837ed625) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
18:08:34.0578 0348 ati2mtag - ok
18:08:35.0031 0348 AtiHdmiService (591a9eabb5ef5168e435c2f18b05dd76) C:\WINDOWS\system32\drivers\AtiHdmi.sys
18:08:35.0234 0348 AtiHdmiService - ok
18:08:35.0625 0348 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\WINDOWS\system32\DRIVERS\atksgt.sys
18:08:35.0750 0348 atksgt ( UnsignedFile.Multi.Generic ) - warning
18:08:35.0750 0348 atksgt - detected UnsignedFile.Multi.Generic (1)
18:08:36.0046 0348 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
18:08:36.0281 0348 audstub - ok
18:08:36.0640 0348 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
18:08:36.0875 0348 Beep - ok
18:08:36.0937 0348 catchme - ok
18:08:37.0234 0348 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
18:08:37.0453 0348 cbidf2k - ok
18:08:37.0781 0348 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
18:08:37.0984 0348 CCDECODE - ok
18:08:38.0265 0348 cd20xrnt - ok
18:08:38.0609 0348 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
18:08:38.0828 0348 Cdfs - ok
18:08:39.0140 0348 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:08:39.0390 0348 Cdrom - ok
18:08:39.0671 0348 CmdIde - ok
18:08:39.0953 0348 Cpqarray - ok
18:08:40.0218 0348 dac2w2k - ok
18:08:40.0500 0348 dac960nt - ok
18:08:40.0765 0348 def - ok
18:08:41.0031 0348 dgderdrv - ok
18:08:41.0343 0348 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
18:08:41.0578 0348 Disk - ok
18:08:42.0187 0348 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
18:08:43.0625 0348 dmboot - ok
18:08:44.0000 0348 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
18:08:44.0281 0348 dmio - ok
18:08:44.0578 0348 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
18:08:44.0796 0348 dmload - ok
18:08:45.0109 0348 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
18:08:45.0343 0348 DMusic - ok
18:08:45.0625 0348 dpti2o - ok
18:08:45.0906 0348 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
18:08:46.0125 0348 drmkaud - ok
18:08:46.0500 0348 dtscsi (12aca694b50ea53563c1e7c99e7bb27d) C:\WINDOWS\System32\Drivers\dtscsi.sys
18:08:46.0656 0348 dtscsi - ok
18:08:46.0937 0348 EagleNT - ok
18:08:47.0218 0348 EIO_XP (0daf3544804650526751c478aeccce63) C:\WINDOWS\system32\drivers\EIO_XP.sys
18:08:47.0250 0348 EIO_XP ( UnsignedFile.Multi.Generic ) - warning
18:08:47.0250 0348 EIO_XP - detected UnsignedFile.Multi.Generic (1)
18:08:47.0640 0348 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
18:08:47.0906 0348 Fastfat - ok
18:08:48.0234 0348 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
18:08:48.0468 0348 Fdc - ok
18:08:48.0781 0348 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
18:08:49.0000 0348 Fips - ok
18:08:49.0312 0348 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:08:49.0593 0348 Flpydisk - ok
18:08:49.0953 0348 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
18:08:50.0203 0348 FltMgr - ok
18:08:50.0468 0348 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\WINDOWS\system32\FsUsbExDisk.SYS
18:08:50.0593 0348 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
18:08:50.0593 0348 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
18:08:50.0906 0348 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:08:51.0125 0348 Fs_Rec - ok
18:08:51.0468 0348 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:08:51.0765 0348 Ftdisk - ok
18:08:52.0062 0348 gagp30kx (3a74c423cf6bcca6982715878f450a3b) C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
18:08:52.0296 0348 gagp30kx - ok
18:08:52.0609 0348 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:08:52.0859 0348 Gpc - ok
18:08:53.0203 0348 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:08:53.0484 0348 HDAudBus - ok
18:08:53.0781 0348 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:08:54.0000 0348 HidUsb - ok
18:08:54.0265 0348 hpn - ok
18:08:54.0671 0348 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
18:08:54.0859 0348 HTTP - ok
18:08:55.0125 0348 i2omp - ok
18:08:55.0437 0348 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:08:55.0671 0348 i8042prt - ok
18:08:55.0984 0348 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
18:08:56.0218 0348 Imapi - ok
18:08:56.0500 0348 ini910u - ok
18:08:56.0796 0348 IntelIde - ok
18:08:57.0093 0348 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
18:08:57.0343 0348 Ip6Fw - ok
18:08:57.0656 0348 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:08:57.0890 0348 IpFilterDriver - ok
18:08:58.0187 0348 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:08:58.0421 0348 IpInIp - ok
18:08:58.0765 0348 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:08:59.0046 0348 IpNat - ok
18:08:59.0453 0348 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:08:59.0687 0348 IPSec - ok
18:08:59.0968 0348 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
18:09:00.0062 0348 IRENUM - ok
18:09:00.0375 0348 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:09:00.0609 0348 isapnp - ok
18:09:00.0906 0348 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:09:01.0109 0348 Kbdclass - ok
18:09:01.0406 0348 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:09:01.0640 0348 kbdhid - ok
18:09:02.0000 0348 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
18:09:02.0296 0348 kmixer - ok
18:09:02.0609 0348 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
18:09:02.0750 0348 KSecDD - ok
18:09:03.0078 0348 lbrtfdc (406598827a1b5f77954de11dde115ced) C:\WINDOWS\system32\drivers\lbrtfdc.sys
18:09:03.0296 0348 lbrtfdc - ok
18:09:03.0593 0348 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
18:09:03.0625 0348 lirsgt ( UnsignedFile.Multi.Generic ) - warning
18:09:03.0625 0348 lirsgt - detected UnsignedFile.Multi.Generic (1)
18:09:03.0921 0348 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
18:09:04.0140 0348 mnmdd - ok
18:09:04.0562 0348 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:09:04.0781 0348 Mouclass - ok
18:09:05.0078 0348 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
18:09:05.0312 0348 MountMgr - ok
18:09:05.0578 0348 mraid35x - ok
18:09:05.0984 0348 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:09:06.0265 0348 MRxDAV - ok
18:09:06.0734 0348 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:09:07.0531 0348 MRxSmb - ok
18:09:07.0828 0348 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
18:09:08.0078 0348 Msfs - ok
18:09:08.0390 0348 MSKSSRV (85736f804191cb420a31aca2a7f0674f) C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:09:08.0453 0348 MSKSSRV - ok
18:09:08.0781 0348 MSPCLOCK (e943adb93d83c5cbc0ca3f53f53b48cc) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:09:08.0843 0348 MSPCLOCK - ok
18:09:09.0140 0348 MSPQM (f6a726b8832db1f88326b8be98b11981) C:\WINDOWS\system32\drivers\MSPQM.sys
18:09:09.0218 0348 MSPQM - ok
18:09:09.0546 0348 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:09:09.0781 0348 mssmbios - ok
18:09:10.0078 0348 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
18:09:10.0296 0348 MSTEE - ok
18:09:10.0625 0348 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
18:09:10.0703 0348 Mup - ok
18:09:11.0031 0348 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
18:09:11.0281 0348 NABTSFEC - ok
18:09:11.0656 0348 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
18:09:11.0953 0348 NDIS - ok
18:09:12.0250 0348 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
18:09:12.0453 0348 NdisIP - ok
18:09:12.0750 0348 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:09:12.0812 0348 NdisTapi - ok
18:09:13.0109 0348 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:09:13.0328 0348 Ndisuio - ok
18:09:13.0656 0348 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:09:13.0906 0348 NdisWan - ok
18:09:14.0234 0348 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
18:09:14.0312 0348 NDProxy - ok
18:09:14.0640 0348 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
18:09:14.0875 0348 NetBIOS - ok
18:09:15.0234 0348 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
18:09:15.0515 0348 NetBT - ok
18:09:15.0843 0348 nmwcd (4a8a2aa0706b659175169decf198e9d7) C:\WINDOWS\system32\drivers\ccdcmb.sys
18:09:16.0250 0348 nmwcd - ok
18:09:16.0546 0348 nmwcdc (fd3e61831095ac62e6840d986b5a2016) C:\WINDOWS\system32\drivers\ccdcmbo.sys
18:09:16.0625 0348 nmwcdc - ok
18:09:16.0953 0348 nmwcdnsu (02e96113511171ba7559386d10d3daea) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
18:09:17.0125 0348 nmwcdnsu - ok
18:09:17.0406 0348 nmwcdnsuc (fb09150cfc7a499a53c308d04841a3bd) C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
18:09:17.0484 0348 nmwcdnsuc - ok
18:09:17.0781 0348 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
18:09:17.0968 0348 Npfs - ok
18:09:18.0468 0348 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
18:09:19.0312 0348 Ntfs - ok
18:09:19.0687 0348 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
18:09:19.0890 0348 Null - ok
18:09:20.0187 0348 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:09:20.0406 0348 NwlnkFlt - ok
18:09:20.0718 0348 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:09:20.0953 0348 NwlnkFwd - ok
18:09:21.0296 0348 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
18:09:21.0546 0348 Parport - ok
18:09:21.0843 0348 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
18:09:22.0093 0348 PartMgr - ok
18:09:22.0375 0348 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
18:09:22.0578 0348 ParVdm - ok
18:09:22.0875 0348 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
18:09:22.0937 0348 pccsmcfd - ok
18:09:23.0250 0348 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
18:09:23.0500 0348 PCI - ok
18:09:23.0765 0348 PCIDump - ok
18:09:24.0046 0348 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
18:09:24.0312 0348 PCIIde - ok
18:09:24.0640 0348 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
18:09:24.0906 0348 Pcmcia - ok
18:09:25.0218 0348 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
18:09:25.0250 0348 pcouffin ( UnsignedFile.Multi.Generic ) - warning
18:09:25.0250 0348 pcouffin - detected UnsignedFile.Multi.Generic (1)
18:09:25.0515 0348 PDCOMP - ok
18:09:25.0781 0348 PDFRAME - ok
18:09:26.0046 0348 PDRELI - ok
18:09:26.0359 0348 PDRFRAME - ok
18:09:26.0625 0348 perc2 - ok
18:09:26.0890 0348 perc2hib - ok
18:09:27.0234 0348 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:09:27.0484 0348 PptpMiniport - ok
18:09:27.0781 0348 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
18:09:28.0031 0348 Processor - ok
18:09:28.0421 0348 prodrv06 (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys
18:09:28.0484 0348 prodrv06 ( UnsignedFile.Multi.Generic ) - warning
18:09:28.0484 0348 prodrv06 - detected UnsignedFile.Multi.Generic (1)
18:09:28.0828 0348 prohlp02 (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys
18:09:28.0890 0348 prohlp02 ( UnsignedFile.Multi.Generic ) - warning
18:09:28.0890 0348 prohlp02 - detected UnsignedFile.Multi.Generic (1)
18:09:29.0187 0348 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys
18:09:29.0203 0348 prosync1 ( UnsignedFile.Multi.Generic ) - warning
18:09:29.0203 0348 prosync1 - detected UnsignedFile.Multi.Generic (1)
18:09:29.0531 0348 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
18:09:29.0812 0348 PSched - ok
18:09:30.0093 0348 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:09:30.0359 0348 Ptilink - ok
18:09:30.0671 0348 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
18:09:30.0718 0348 PxHelp20 - ok
18:09:30.0984 0348 ql1080 - ok
18:09:31.0281 0348 Ql10wnt - ok
18:09:31.0562 0348 ql12160 - ok
18:09:31.0828 0348 ql1240 - ok
18:09:32.0109 0348 ql1280 - ok
18:09:32.0390 0348 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:09:32.0640 0348 RasAcd - ok
18:09:32.0953 0348 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:09:33.0250 0348 Rasl2tp - ok
18:09:33.0546 0348 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:09:33.0796 0348 RasPppoe - ok
18:09:34.0078 0348 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
18:09:34.0375 0348 Raspti - ok
18:09:34.0750 0348 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:09:35.0062 0348 Rdbss - ok
18:09:35.0359 0348 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:09:35.0578 0348 RDPCDD - ok
18:09:35.0921 0348 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
18:09:36.0046 0348 RDPWD - ok
18:09:36.0375 0348 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
18:09:36.0625 0348 redbook - ok
18:09:36.0968 0348 RTL8023xp (8e34400ffc7d647946d9c820678775af) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys
18:09:37.0125 0348 RTL8023xp - ok
18:09:37.0453 0348 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
18:09:37.0671 0348 rtl8139 - ok
18:09:38.0015 0348 s117bus (1f561844318914e7eb6e54673a4cc54c) C:\WINDOWS\system32\DRIVERS\s117bus.sys
18:09:38.0062 0348 s117bus - ok
18:09:38.0359 0348 s117mdfl (ba93eec3cdf6a63b77ae66221aa4f902) C:\WINDOWS\system32\DRIVERS\s117mdfl.sys
18:09:38.0375 0348 s117mdfl - ok
18:09:38.0906 0348 s117mdm (cba12fd8a8ee5b5cdfbbae2381cd6703) C:\WINDOWS\system32\DRIVERS\s117mdm.sys
18:09:38.0984 0348 s117mdm - ok
18:09:39.0312 0348 s117mgmt (bd6483e64b1da17e812b34bcdefd9459) C:\WINDOWS\system32\DRIVERS\s117mgmt.sys
18:09:39.0375 0348 s117mgmt - ok
18:09:39.0734 0348 s117nd5 (c7ca36c3054b4cd47a1f6611b046e2f9) C:\WINDOWS\system32\DRIVERS\s117nd5.sys
18:09:39.0765 0348 s117nd5 - ok
18:09:40.0078 0348 s117obex (e290b3a6b58fb72ca97dd48d64e4fc1c) C:\WINDOWS\system32\DRIVERS\s117obex.sys
18:09:40.0140 0348 s117obex - ok
18:09:40.0453 0348 s117unic (5c4d1ba23c7511ac880e8ba7baa80dba) C:\WINDOWS\system32\DRIVERS\s117unic.sys
18:09:40.0515 0348 s117unic - ok
18:09:40.0828 0348 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:09:40.0937 0348 Secdrv - ok
18:09:41.0234 0348 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
18:09:41.0453 0348 serenum - ok
18:09:41.0765 0348 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
18:09:42.0015 0348 Serial - ok
18:09:42.0375 0348 sfdrv01 (9e7dee11fd5a4355941a45f13c0ed59a) C:\WINDOWS\system32\drivers\sfdrv01.sys
18:09:42.0390 0348 sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
18:09:42.0390 0348 sfdrv01 - detected UnsignedFile.Multi.Generic (1)
18:09:42.0703 0348 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
18:09:42.0734 0348 sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
18:09:42.0734 0348 sfhlp01 - detected UnsignedFile.Multi.Generic (1)
18:09:43.0015 0348 sfhlp02 (ecefb59d2206d281e6d317af0ea0d8bd) C:\WINDOWS\system32\drivers\sfhlp02.sys
18:09:43.0046 0348 sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
18:09:43.0046 0348 sfhlp02 - detected UnsignedFile.Multi.Generic (1)
18:09:43.0343 0348 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
18:09:43.0562 0348 Sfloppy - ok
18:09:43.0859 0348 sfsync02 (efebbc1d13fdb77a6af4eddfc7232edf) C:\WINDOWS\system32\drivers\sfsync02.sys
18:09:43.0890 0348 sfsync02 ( UnsignedFile.Multi.Generic ) - warning
18:09:43.0890 0348 sfsync02 - detected UnsignedFile.Multi.Generic (1)
18:09:44.0203 0348 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) C:\WINDOWS\system32\drivers\sfvfs02.sys
18:09:44.0250 0348 sfvfs02 ( UnsignedFile.Multi.Generic ) - warning
18:09:44.0250 0348 sfvfs02 - detected UnsignedFile.Multi.Generic (1)
18:09:44.0531 0348 Simbad - ok
18:09:44.0843 0348 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
18:09:45.0062 0348 SLIP - ok
18:09:49.0500 0348 SNP325 (a12be6b3f784bd66110efc649f31038b) C:\WINDOWS\system32\DRIVERS\snp325.sys
18:10:12.0390 0348 SNP325 ( UnsignedFile.Multi.Generic ) - warning
18:10:12.0390 0348 SNP325 - detected UnsignedFile.Multi.Generic (1)
18:10:12.0750 0348 Sparrow - ok
18:10:13.0046 0348 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
18:10:13.0250 0348 splitter - ok
18:10:13.0843 0348 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
18:10:13.0875 0348 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
18:10:13.0875 0348 sptd ( LockedFile.Multi.Generic ) - warning
18:10:13.0875 0348 sptd - detected LockedFile.Multi.Generic (1)
18:10:14.0203 0348 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
18:10:14.0328 0348 sr - ok
18:10:14.0765 0348 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
18:10:15.0359 0348 Srv - ok
18:10:15.0718 0348 sscdbus (86b6905742d77775b558ab19c091d181) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
18:10:15.0781 0348 sscdbus - ok
18:10:16.0109 0348 sscdserd (5474b4391cf52ade2801841afb77e099) C:\WINDOWS\system32\DRIVERS\sscdserd.sys
18:10:16.0156 0348 sscdserd - ok
18:10:16.0484 0348 ss_bbus (3f0164fbc0bd1adbd02df9759181451a) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys
18:10:16.0531 0348 ss_bbus - ok
18:10:16.0890 0348 ss_bserd (994d2e5378cc337ec7dd73c1e04fcaa4) C:\WINDOWS\system32\DRIVERS\ss_bserd.sys
18:10:16.0937 0348 ss_bserd - ok
18:10:17.0250 0348 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
18:10:17.0453 0348 streamip - ok
18:10:17.0718 0348 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
18:10:17.0937 0348 swenum - ok
18:10:18.0250 0348 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
18:10:18.0468 0348 swmidi - ok
18:10:18.0750 0348 symc810 - ok
18:10:19.0015 0348 symc8xx - ok
18:10:19.0281 0348 sym_hi - ok
18:10:19.0546 0348 sym_u3 - ok
18:10:19.0859 0348 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
18:10:20.0109 0348 sysaudio - ok
18:10:20.0546 0348 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:10:21.0218 0348 Tcpip - ok
18:10:21.0609 0348 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
18:10:21.0828 0348 TDPIPE - ok
18:10:22.0109 0348 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
18:10:22.0343 0348 TDTCP - ok
18:10:22.0656 0348 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
18:10:22.0890 0348 TermDD - ok
18:10:23.0171 0348 TosIde - ok
18:10:23.0500 0348 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
18:10:23.0750 0348 Udfs - ok
18:10:24.0015 0348 ultra - ok
18:10:24.0453 0348 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
18:10:25.0296 0348 Update - ok
18:10:25.0671 0348 upperdev (587e643a4e2ffd9a00f114b057ceb773) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
18:10:26.0031 0348 upperdev - ok
18:10:26.0500 0348 usbbus - ok
18:10:27.0390 0348 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:10:27.0937 0348 usbccgp - ok
18:10:28.0203 0348 UsbDiag - ok
18:10:28.0515 0348 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:10:28.0812 0348 usbehci - ok
18:10:37.0421 0348 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:10:37.0828 0348 usbhub - ok
18:10:38.0093 0348 USBModem - ok
18:10:38.0390 0348 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
18:10:38.0625 0348 usbprint - ok
18:10:38.0921 0348 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:10:39.0171 0348 usbscan - ok
18:10:39.0500 0348 UsbserFilt (fca6a196d47cb972a0e4adc0db9cd17c) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
18:10:39.0625 0348 UsbserFilt - ok
18:10:40.0421 0348 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:10:40.0593 0348 usbstor - ok
18:10:40.0890 0348 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:10:41.0093 0348 usbuhci - ok
18:10:41.0390 0348 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
18:10:41.0656 0348 VgaSave - ok
18:10:41.0937 0348 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
18:10:42.0156 0348 ViaIde - ok
18:10:42.0546 0348 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
18:10:42.0796 0348 VolSnap - ok
18:10:43.0109 0348 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:10:43.0328 0348 Wanarp - ok
18:10:43.0812 0348 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
18:10:44.0156 0348 Wdf01000 - ok
18:10:44.0421 0348 WDICA - ok
18:10:44.0734 0348 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
18:10:45.0031 0348 wdmaud - ok
18:10:45.0359 0348 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys
18:10:45.0484 0348 WpdUsb - ok
18:10:45.0875 0348 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:10:46.0125 0348 WS2IFSL - ok
18:10:46.0421 0348 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
18:10:46.0671 0348 WSTCODEC - ok
18:10:47.0015 0348 WudfPf (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:10:47.0281 0348 WudfPf - ok
18:10:47.0593 0348 WudfRd (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:10:47.0671 0348 WudfRd - ok
18:10:48.0062 0348 xmasbus (ddd8286b88fe764ad2a8bd171e7b569a) C:\WINDOWS\system32\DRIVERS\xmasbus.sys
18:10:48.0156 0348 xmasbus ( UnsignedFile.Multi.Generic ) - warning
18:10:48.0171 0348 xmasbus - detected UnsignedFile.Multi.Generic (1)
18:10:48.0484 0348 xmasscsi (4059ad5e639fa47e334304cbe82e9572) C:\WINDOWS\system32\Drivers\xmasscsi.sys
18:10:48.0515 0348 xmasscsi ( UnsignedFile.Multi.Generic ) - warning
18:10:48.0515 0348 xmasscsi - detected UnsignedFile.Multi.Generic (1)
18:10:48.0546 0348 MBR (0x1B8) (9c603bc3977968c891de319283e1e7af) \Device\Harddisk0\DR0
18:10:48.0578 0348 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - infected
18:10:48.0578 0348 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Wistler.a (0)
18:10:48.0781 0348 Boot (0x1200) (7192dc0ca5d6d9cf6f2a8b6e26342dc9) \Device\Harddisk0\DR0\Partition0
18:10:48.0781 0348 \Device\Harddisk0\DR0\Partition0 - ok
18:10:48.0796 0348 Boot (0x1200) (53c90969ca60f1a2c64e804d40564dae) \Device\Harddisk0\DR0\Partition1
18:10:48.0812 0348 \Device\Harddisk0\DR0\Partition1 - ok
18:10:48.0812 0348 ============================================================
18:10:48.0812 0348 Scan finished
18:10:48.0812 0348 ============================================================
18:10:48.0937 1776 Detected object count: 21
18:10:48.0937 1776 Actual detected object count: 21
18:11:41.0203 1776 ASPI ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0203 1776 ASPI ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0203 1776 asuskbnt ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0203 1776 asuskbnt ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0203 1776 ASUSVRC ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0203 1776 ASUSVRC ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0203 1776 atksgt ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0203 1776 atksgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0203 1776 EIO_XP ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0203 1776 EIO_XP ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0218 1776 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0218 1776 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0218 1776 lirsgt ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0218 1776 lirsgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0218 1776 pcouffin ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0218 1776 pcouffin ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0218 1776 prodrv06 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0218 1776 prodrv06 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0218 1776 prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0218 1776 prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0218 1776 prosync1 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0218 1776 prosync1 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0234 1776 sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0234 1776 sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0234 1776 sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0234 1776 sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0234 1776 sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0234 1776 sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0234 1776 sfsync02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0234 1776 sfsync02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0234 1776 sfvfs02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0234 1776 sfvfs02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0234 1776 SNP325 ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0234 1776 SNP325 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0250 1776 sptd ( LockedFile.Multi.Generic ) - skipped by user
18:11:41.0250 1776 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
18:11:41.0250 1776 xmasbus ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0250 1776 xmasbus ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0250 1776 xmasscsi ( UnsignedFile.Multi.Generic ) - skipped by user
18:11:41.0250 1776 xmasscsi ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:11:41.0250 1776 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - skipped by user
18:11:41.0250 1776 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - User select action: Skip

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 18:16
od vyosek
Zdravim :)

:arrow: Mel jsem dneska nejake pracovni povinnosti a nedostal jsem se k PC

:arrow: Dekuji kolegovi za zaskok :worship:

:arrow: Spustte znovu TDSSKiller a u polozky \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) dejte volbu Cure (mela by byt automaticky predvolena). pak bude zrejme nutny restart PC a pak udelejte znovu sken pomoci TDSSKileru tak jak kolega psal

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 18:47
od Waler22
Zdravím, všimol som si že ste tu nebol ale tak nevadí :) takže ten log...


18:37:46.0750 3680 TDSS rootkit removing tool 2.7.11.0 Feb 9 2012 10:12:57
18:37:49.0578 3680 ============================================================
18:37:49.0578 3680 Current date / time: 2012/02/11 18:37:49.0578
18:37:49.0578 3680 SystemInfo:
18:37:49.0578 3680
18:37:49.0578 3680 OS Version: 5.1.2600 ServicePack: 3.0
18:37:49.0578 3680 Product type: Workstation
18:37:49.0578 3680 ComputerName: SEMPRON643000
18:37:49.0578 3680 UserName: PC
18:37:49.0578 3680 Windows directory: C:\WINDOWS
18:37:49.0578 3680 System windows directory: C:\WINDOWS
18:37:49.0578 3680 Processor architecture: Intel x86
18:37:49.0578 3680 Number of processors: 1
18:37:49.0578 3680 Page size: 0x1000
18:37:49.0578 3680 Boot type: Normal boot
18:37:49.0578 3680 ============================================================
18:38:01.0875 3680 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
18:38:01.0937 3680 \Device\Harddisk0\DR0:
18:38:01.0937 3680 MBR used
18:38:01.0937 3680 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4E1EDEC
18:38:01.0953 3680 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x4E1EE6A, BlocksNum 0x9170A96
18:38:02.0062 3680 Initialize success
18:38:02.0062 3680 ============================================================
18:38:14.0187 3772 ============================================================
18:38:14.0187 3772 Scan started
18:38:14.0187 3772 Mode: Manual; SigCheck; TDLFS;
18:38:14.0187 3772 ============================================================
18:38:15.0000 3772 Aavmker4 (b6de0336f9f4b687b4ff57939f7b657a) C:\WINDOWS\system32\drivers\Aavmker4.sys
18:38:15.0203 3772 Aavmker4 - ok
18:38:15.0515 3772 Abiosdsk - ok
18:38:15.0796 3772 abp480n5 - ok
18:38:16.0203 3772 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:38:33.0734 3772 ACPI - ok
18:38:35.0968 3772 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
18:38:36.0359 3772 ACPIEC - ok
18:38:36.0671 3772 adpu160m - ok
18:38:37.0109 3772 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
18:38:37.0625 3772 aec - ok
18:38:38.0453 3772 Afc (fe3ea6e9afc1a78e6edca121e006afb7) C:\WINDOWS\system32\drivers\Afc.sys
18:38:38.0500 3772 Afc - ok
18:38:38.0953 3772 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
18:38:39.0140 3772 AFD - ok
18:38:39.0562 3772 Aha154x - ok
18:38:39.0875 3772 aic78u2 - ok
18:38:40.0140 3772 aic78xx - ok
18:38:42.0093 3772 ALCXWDM (706aa8374b4fc02d8a42493f16d5c3a4) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
18:39:00.0968 3772 ALCXWDM - ok
18:39:01.0671 3772 AliIde - ok
18:39:02.0015 3772 amsint - ok
18:39:02.0500 3772 ArcSoftKsUFilter (bf8470e29873dd3f725f18709928c85f) C:\WINDOWS\system32\DRIVERS\ArcSoftKsUFilter.sys
18:39:02.0515 3772 ArcSoftKsUFilter - ok
18:39:02.0875 3772 asc - ok
18:39:03.0187 3772 asc3350p - ok
18:39:03.0484 3772 asc3550 - ok
18:39:03.0890 3772 ASPI (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\System32\DRIVERS\ASPI32.sys
18:39:03.0921 3772 ASPI ( UnsignedFile.Multi.Generic ) - warning
18:39:03.0921 3772 ASPI - detected UnsignedFile.Multi.Generic (1)
18:39:04.0250 3772 asuskbnt (f5c2ccdb273a546e9c3a15250f1d9165) C:\WINDOWS\system32\drivers\atkkbnt.sys
18:39:04.0281 3772 asuskbnt ( UnsignedFile.Multi.Generic ) - warning
18:39:04.0281 3772 asuskbnt - detected UnsignedFile.Multi.Generic (1)
18:39:04.0625 3772 ASUSVRC (94442e3029ff6c9f08140fe6718af4fb) C:\WINDOWS\system32\DRIVERS\AsusVRC.sys
18:39:04.0656 3772 ASUSVRC ( UnsignedFile.Multi.Generic ) - warning
18:39:04.0656 3772 ASUSVRC - detected UnsignedFile.Multi.Generic (1)
18:39:05.0296 3772 aswFsBlk (054df24c92b55427e0757cfff160e4f2) C:\WINDOWS\system32\drivers\aswFsBlk.sys
18:39:05.0312 3772 aswFsBlk - ok
18:39:05.0703 3772 aswMon2 (ef0e9ad83380724bd6fbbb51d2d0f5b8) C:\WINDOWS\system32\drivers\aswMon2.sys
18:39:05.0718 3772 aswMon2 - ok
18:39:06.0203 3772 aswRdr (352d5a48ebab35a7693b048679304831) C:\WINDOWS\system32\drivers\aswRdr.sys
18:39:06.0218 3772 aswRdr - ok
18:39:06.0734 3772 aswSnx (8d34d2b24297e27d93e847319abfdec4) C:\WINDOWS\system32\drivers\aswSnx.sys
18:39:07.0109 3772 aswSnx - ok
18:39:08.0390 3772 aswSP (010012597333da1f46c3243f33f8409e) C:\WINDOWS\system32\drivers\aswSP.sys
18:39:08.0421 3772 aswSP - ok
18:39:09.0921 3772 aswTdi (f9f84364416658e9786235904d448d37) C:\WINDOWS\system32\drivers\aswTdi.sys
18:39:09.0937 3772 aswTdi - ok
18:39:10.0359 3772 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:39:10.0625 3772 AsyncMac - ok
18:39:11.0015 3772 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
18:39:11.0390 3772 atapi - ok
18:39:11.0687 3772 Atdisk - ok
18:39:14.0187 3772 ati2mtag (323b30faae1f544a549ebbbd837ed625) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
18:39:22.0250 3772 ati2mtag - ok
18:39:24.0875 3772 AtiHdmiService (591a9eabb5ef5168e435c2f18b05dd76) C:\WINDOWS\system32\drivers\AtiHdmi.sys
18:39:24.0953 3772 AtiHdmiService - ok
18:39:25.0421 3772 atksgt (6e996cf8459a2594e0e9609d0e34d41f) C:\WINDOWS\system32\DRIVERS\atksgt.sys
18:39:25.0515 3772 atksgt ( UnsignedFile.Multi.Generic ) - warning
18:39:25.0515 3772 atksgt - detected UnsignedFile.Multi.Generic (1)
18:39:25.0843 3772 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
18:39:26.0093 3772 audstub - ok
18:39:26.0484 3772 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
18:39:26.0718 3772 Beep - ok
18:39:26.0796 3772 catchme - ok
18:39:27.0125 3772 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
18:39:27.0375 3772 cbidf2k - ok
18:39:27.0812 3772 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
18:39:28.0046 3772 CCDECODE - ok
18:39:28.0515 3772 cd20xrnt - ok
18:39:28.0875 3772 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
18:39:29.0125 3772 Cdfs - ok
18:39:29.0515 3772 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:39:29.0796 3772 Cdrom - ok
18:39:30.0109 3772 CmdIde - ok
18:39:30.0468 3772 Cpqarray - ok
18:39:30.0765 3772 dac2w2k - ok
18:39:31.0078 3772 dac960nt - ok
18:39:31.0406 3772 def - ok
18:39:31.0812 3772 dgderdrv - ok
18:39:32.0140 3772 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
18:39:32.0406 3772 Disk - ok
18:39:33.0109 3772 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
18:39:34.0750 3772 dmboot - ok
18:39:36.0765 3772 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
18:39:37.0203 3772 dmio - ok
18:39:37.0546 3772 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
18:39:37.0781 3772 dmload - ok
18:39:38.0156 3772 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
18:39:38.0437 3772 DMusic - ok
18:39:38.0750 3772 dpti2o - ok
18:39:39.0078 3772 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
18:39:39.0312 3772 drmkaud - ok
18:39:39.0765 3772 dtscsi (12aca694b50ea53563c1e7c99e7bb27d) C:\WINDOWS\System32\Drivers\dtscsi.sys
18:39:39.0875 3772 dtscsi - ok
18:39:40.0203 3772 EagleNT - ok
18:39:40.0609 3772 EIO_XP (0daf3544804650526751c478aeccce63) C:\WINDOWS\system32\drivers\EIO_XP.sys
18:39:40.0640 3772 EIO_XP ( UnsignedFile.Multi.Generic ) - warning
18:39:40.0640 3772 EIO_XP - detected UnsignedFile.Multi.Generic (1)
18:39:41.0062 3772 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
18:39:41.0375 3772 Fastfat - ok
18:39:41.0750 3772 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
18:39:42.0015 3772 Fdc - ok
18:39:42.0359 3772 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
18:39:42.0625 3772 Fips - ok
18:39:42.0953 3772 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:39:43.0218 3772 Flpydisk - ok
18:39:43.0734 3772 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
18:39:44.0046 3772 FltMgr - ok
18:39:44.0343 3772 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\WINDOWS\system32\FsUsbExDisk.SYS
18:39:44.0484 3772 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
18:39:44.0484 3772 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
18:39:44.0828 3772 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:39:45.0078 3772 Fs_Rec - ok
18:39:45.0453 3772 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:39:45.0781 3772 Ftdisk - ok
18:39:46.0125 3772 gagp30kx (3a74c423cf6bcca6982715878f450a3b) C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
18:39:46.0390 3772 gagp30kx - ok
18:39:46.0843 3772 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:39:47.0140 3772 Gpc - ok
18:39:47.0593 3772 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:39:47.0921 3772 HDAudBus - ok
18:39:48.0281 3772 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:39:48.0515 3772 HidUsb - ok
18:39:48.0843 3772 hpn - ok
18:39:49.0296 3772 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
18:39:49.0500 3772 HTTP - ok
18:39:49.0812 3772 i2omp - ok
18:39:50.0156 3772 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:39:50.0421 3772 i8042prt - ok
18:39:50.0796 3772 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
18:39:51.0062 3772 Imapi - ok
18:39:51.0406 3772 ini910u - ok
18:39:51.0750 3772 IntelIde - ok
18:39:52.0093 3772 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
18:39:52.0343 3772 Ip6Fw - ok
18:39:52.0703 3772 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:39:52.0953 3772 IpFilterDriver - ok
18:39:53.0281 3772 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:39:53.0515 3772 IpInIp - ok
18:39:53.0921 3772 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:39:54.0281 3772 IpNat - ok
18:39:54.0656 3772 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:39:54.0984 3772 IPSec - ok
18:39:55.0328 3772 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
18:39:55.0437 3772 IRENUM - ok
18:39:55.0843 3772 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:39:56.0687 3772 isapnp - ok
18:39:58.0000 3772 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:39:58.0343 3772 Kbdclass - ok
18:39:58.0796 3772 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:39:59.0031 3772 kbdhid - ok
18:39:59.0578 3772 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
18:40:00.0015 3772 kmixer - ok
18:40:00.0375 3772 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
18:40:00.0546 3772 KSecDD - ok
18:40:00.0890 3772 lbrtfdc (406598827a1b5f77954de11dde115ced) C:\WINDOWS\system32\drivers\lbrtfdc.sys
18:40:01.0125 3772 lbrtfdc - ok
18:40:01.0468 3772 lirsgt (975b6cf65f44e95883f3855bae8cecaf) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
18:40:01.0500 3772 lirsgt ( UnsignedFile.Multi.Generic ) - warning
18:40:01.0500 3772 lirsgt - detected UnsignedFile.Multi.Generic (1)
18:40:01.0812 3772 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
18:40:02.0031 3772 mnmdd - ok
18:40:02.0375 3772 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:40:02.0609 3772 Mouclass - ok
18:40:02.0937 3772 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
18:40:03.0296 3772 MountMgr - ok
18:40:04.0453 3772 mraid35x - ok
18:40:05.0000 3772 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:40:05.0921 3772 MRxDAV - ok
18:40:06.0546 3772 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:40:09.0328 3772 MRxSmb - ok
18:40:17.0875 3772 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
18:40:18.0625 3772 Msfs - ok
18:40:18.0953 3772 MSKSSRV (85736f804191cb420a31aca2a7f0674f) C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:40:19.0281 3772 MSKSSRV - ok
18:40:20.0000 3772 MSPCLOCK (e943adb93d83c5cbc0ca3f53f53b48cc) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:40:22.0750 3772 MSPCLOCK - ok
18:40:50.0203 3772 MSPQM (f6a726b8832db1f88326b8be98b11981) C:\WINDOWS\system32\drivers\MSPQM.sys
18:40:52.0484 3772 MSPQM - ok
18:40:59.0421 3772 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:41:00.0453 3772 mssmbios - ok
18:41:00.0968 3772 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
18:41:01.0328 3772 MSTEE - ok
18:41:01.0984 3772 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
18:41:02.0312 3772 Mup - ok
18:41:02.0671 3772 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
18:41:02.0921 3772 NABTSFEC - ok
18:41:03.0375 3772 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
18:41:03.0656 3772 NDIS - ok
18:41:03.0984 3772 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
18:41:04.0218 3772 NdisIP - ok
18:41:04.0640 3772 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:41:04.0703 3772 NdisTapi - ok
18:41:05.0000 3772 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:41:05.0250 3772 Ndisuio - ok
18:41:05.0593 3772 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:41:05.0843 3772 NdisWan - ok
18:41:06.0875 3772 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
18:41:06.0953 3772 NDProxy - ok
18:41:07.0281 3772 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
18:41:07.0531 3772 NetBIOS - ok
18:41:07.0875 3772 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
18:41:08.0125 3772 NetBT - ok
18:41:08.0546 3772 nmwcd (4a8a2aa0706b659175169decf198e9d7) C:\WINDOWS\system32\drivers\ccdcmb.sys
18:41:08.0953 3772 nmwcd - ok
18:41:09.0296 3772 nmwcdc (fd3e61831095ac62e6840d986b5a2016) C:\WINDOWS\system32\drivers\ccdcmbo.sys
18:41:09.0359 3772 nmwcdc - ok
18:41:09.0734 3772 nmwcdnsu (02e96113511171ba7559386d10d3daea) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
18:41:09.0859 3772 nmwcdnsu - ok
18:41:10.0187 3772 nmwcdnsuc (fb09150cfc7a499a53c308d04841a3bd) C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
18:41:10.0281 3772 nmwcdnsuc - ok
18:41:10.0593 3772 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
18:41:10.0781 3772 Npfs - ok
18:41:11.0312 3772 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
18:41:12.0328 3772 Ntfs - ok
18:41:12.0781 3772 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
18:41:12.0984 3772 Null - ok
18:41:13.0437 3772 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:41:13.0656 3772 NwlnkFlt - ok
18:41:13.0953 3772 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:41:14.0187 3772 NwlnkFwd - ok
18:41:14.0625 3772 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
18:41:14.0859 3772 Parport - ok
18:41:15.0203 3772 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
18:41:15.0500 3772 PartMgr - ok
18:41:15.0890 3772 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
18:41:16.0140 3772 ParVdm - ok
18:41:16.0484 3772 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
18:41:16.0546 3772 pccsmcfd - ok
18:41:17.0093 3772 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
18:41:17.0546 3772 PCI - ok
18:41:17.0921 3772 PCIDump - ok
18:41:18.0406 3772 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
18:41:19.0875 3772 PCIIde - ok
18:41:20.0359 3772 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
18:41:20.0859 3772 Pcmcia - ok
18:41:21.0390 3772 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
18:41:21.0437 3772 pcouffin ( UnsignedFile.Multi.Generic ) - warning
18:41:21.0437 3772 pcouffin - detected UnsignedFile.Multi.Generic (1)
18:41:21.0859 3772 PDCOMP - ok
18:41:22.0140 3772 PDFRAME - ok
18:41:22.0437 3772 PDRELI - ok
18:41:22.0718 3772 PDRFRAME - ok
18:41:23.0000 3772 perc2 - ok
18:41:23.0296 3772 perc2hib - ok
18:41:23.0640 3772 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:41:23.0859 3772 PptpMiniport - ok
18:41:24.0296 3772 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
18:41:24.0515 3772 Processor - ok
18:41:24.0937 3772 prodrv06 (18d9789a4664bf417eea944d2776091a) C:\WINDOWS\System32\drivers\prodrv06.sys
18:41:24.0984 3772 prodrv06 ( UnsignedFile.Multi.Generic ) - warning
18:41:24.0984 3772 prodrv06 - detected UnsignedFile.Multi.Generic (1)
18:41:25.0359 3772 prohlp02 (8cc9671a7ed2902e747ee0892e1c8575) C:\WINDOWS\system32\drivers\prohlp02.sys
18:41:25.0437 3772 prohlp02 ( UnsignedFile.Multi.Generic ) - warning
18:41:25.0437 3772 prohlp02 - detected UnsignedFile.Multi.Generic (1)
18:41:25.0734 3772 prosync1 (960bce3ed38761b446aabac06c76badf) C:\WINDOWS\system32\drivers\prosync1.sys
18:41:25.0750 3772 prosync1 ( UnsignedFile.Multi.Generic ) - warning
18:41:25.0750 3772 prosync1 - detected UnsignedFile.Multi.Generic (1)
18:41:26.0062 3772 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
18:41:26.0328 3772 PSched - ok
18:41:26.0640 3772 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:41:26.0843 3772 Ptilink - ok
18:41:27.0156 3772 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
18:41:27.0203 3772 PxHelp20 - ok
18:41:27.0531 3772 ql1080 - ok
18:41:27.0890 3772 Ql10wnt - ok
18:41:28.0218 3772 ql12160 - ok
18:41:28.0484 3772 ql1240 - ok
18:41:28.0812 3772 ql1280 - ok
18:41:29.0468 3772 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:41:29.0656 3772 RasAcd - ok
18:41:30.0031 3772 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:41:30.0390 3772 Rasl2tp - ok
18:41:30.0703 3772 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:41:31.0078 3772 RasPppoe - ok
18:41:31.0453 3772 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
18:41:31.0765 3772 Raspti - ok
18:41:32.0265 3772 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:41:32.0515 3772 Rdbss - ok
18:41:32.0906 3772 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:41:33.0125 3772 RDPCDD - ok
18:41:33.0500 3772 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
18:41:33.0609 3772 RDPWD - ok
18:41:34.0109 3772 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
18:41:35.0734 3772 redbook - ok
18:41:36.0437 3772 RTL8023xp (8e34400ffc7d647946d9c820678775af) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys
18:41:37.0000 3772 RTL8023xp - ok
18:41:37.0375 3772 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
18:41:37.0687 3772 rtl8139 - ok
18:41:38.0187 3772 s117bus (1f561844318914e7eb6e54673a4cc54c) C:\WINDOWS\system32\DRIVERS\s117bus.sys
18:41:38.0468 3772 s117bus - ok
18:41:38.0812 3772 s117mdfl (ba93eec3cdf6a63b77ae66221aa4f902) C:\WINDOWS\system32\DRIVERS\s117mdfl.sys
18:41:38.0828 3772 s117mdfl - ok
18:41:39.0203 3772 s117mdm (cba12fd8a8ee5b5cdfbbae2381cd6703) C:\WINDOWS\system32\DRIVERS\s117mdm.sys
18:41:39.0265 3772 s117mdm - ok
18:41:39.0796 3772 s117mgmt (bd6483e64b1da17e812b34bcdefd9459) C:\WINDOWS\system32\DRIVERS\s117mgmt.sys
18:41:39.0890 3772 s117mgmt - ok
18:41:40.0187 3772 s117nd5 (c7ca36c3054b4cd47a1f6611b046e2f9) C:\WINDOWS\system32\DRIVERS\s117nd5.sys
18:41:40.0203 3772 s117nd5 - ok
18:41:40.0562 3772 s117obex (e290b3a6b58fb72ca97dd48d64e4fc1c) C:\WINDOWS\system32\DRIVERS\s117obex.sys
18:41:40.0609 3772 s117obex - ok
18:41:40.0937 3772 s117unic (5c4d1ba23c7511ac880e8ba7baa80dba) C:\WINDOWS\system32\DRIVERS\s117unic.sys
18:41:41.0000 3772 s117unic - ok
18:41:41.0328 3772 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:41:41.0421 3772 Secdrv - ok
18:41:41.0734 3772 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
18:41:41.0921 3772 serenum - ok
18:41:42.0250 3772 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
18:41:42.0468 3772 Serial - ok
18:41:42.0828 3772 sfdrv01 (9e7dee11fd5a4355941a45f13c0ed59a) C:\WINDOWS\system32\drivers\sfdrv01.sys
18:41:42.0859 3772 sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
18:41:42.0859 3772 sfdrv01 - detected UnsignedFile.Multi.Generic (1)
18:41:43.0140 3772 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
18:41:43.0171 3772 sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
18:41:43.0171 3772 sfhlp01 - detected UnsignedFile.Multi.Generic (1)
18:41:43.0515 3772 sfhlp02 (ecefb59d2206d281e6d317af0ea0d8bd) C:\WINDOWS\system32\drivers\sfhlp02.sys
18:41:43.0531 3772 sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
18:41:43.0531 3772 sfhlp02 - detected UnsignedFile.Multi.Generic (1)
18:41:43.0828 3772 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
18:41:44.0031 3772 Sfloppy - ok
18:41:44.0390 3772 sfsync02 (efebbc1d13fdb77a6af4eddfc7232edf) C:\WINDOWS\system32\drivers\sfsync02.sys
18:41:44.0453 3772 sfsync02 ( UnsignedFile.Multi.Generic ) - warning
18:41:44.0453 3772 sfsync02 - detected UnsignedFile.Multi.Generic (1)
18:41:45.0468 3772 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) C:\WINDOWS\system32\drivers\sfvfs02.sys
18:41:45.0515 3772 sfvfs02 ( UnsignedFile.Multi.Generic ) - warning
18:41:45.0515 3772 sfvfs02 - detected UnsignedFile.Multi.Generic (1)
18:41:45.0812 3772 Simbad - ok
18:41:46.0109 3772 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
18:41:46.0328 3772 SLIP - ok
18:41:51.0921 3772 SNP325 (a12be6b3f784bd66110efc649f31038b) C:\WINDOWS\system32\DRIVERS\snp325.sys
18:42:20.0515 3772 SNP325 ( UnsignedFile.Multi.Generic ) - warning
18:42:20.0515 3772 SNP325 - detected UnsignedFile.Multi.Generic (1)
18:42:21.0578 3772 Sparrow - ok
18:42:21.0953 3772 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
18:42:22.0359 3772 splitter - ok
18:42:23.0390 3772 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
18:42:23.0515 3772 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
18:42:23.0656 3772 sptd ( LockedFile.Multi.Generic ) - warning
18:42:23.0656 3772 sptd - detected LockedFile.Multi.Generic (1)
18:42:24.0375 3772 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
18:42:24.0937 3772 sr - ok
18:42:25.0421 3772 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
18:42:26.0359 3772 Srv - ok
18:42:26.0984 3772 sscdbus (86b6905742d77775b558ab19c091d181) C:\WINDOWS\system32\DRIVERS\sscdbus.sys
18:42:27.0171 3772 sscdbus - ok
18:42:27.0953 3772 sscdserd (5474b4391cf52ade2801841afb77e099) C:\WINDOWS\system32\DRIVERS\sscdserd.sys
18:42:28.0406 3772 sscdserd - ok
18:42:28.0921 3772 ss_bbus (3f0164fbc0bd1adbd02df9759181451a) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys
18:42:29.0171 3772 ss_bbus - ok
18:42:29.0968 3772 ss_bserd (994d2e5378cc337ec7dd73c1e04fcaa4) C:\WINDOWS\system32\DRIVERS\ss_bserd.sys
18:42:30.0343 3772 ss_bserd - ok
18:42:31.0171 3772 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
18:42:31.0687 3772 streamip - ok
18:42:32.0734 3772 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
18:42:34.0593 3772 swenum - ok
18:42:36.0859 3772 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
18:42:38.0421 3772 swmidi - ok
18:42:39.0843 3772 symc810 - ok
18:42:40.0171 3772 symc8xx - ok
18:42:40.0640 3772 sym_hi - ok
18:42:41.0187 3772 sym_u3 - ok
18:42:42.0015 3772 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
18:42:42.0531 3772 sysaudio - ok
18:42:43.0125 3772 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:42:44.0140 3772 Tcpip - ok
18:42:44.0515 3772 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
18:42:44.0875 3772 TDPIPE - ok
18:42:45.0187 3772 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
18:42:45.0406 3772 TDTCP - ok
18:42:45.0734 3772 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
18:42:45.0953 3772 TermDD - ok
18:42:46.0250 3772 TosIde - ok
18:42:46.0671 3772 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
18:42:46.0890 3772 Udfs - ok
18:42:47.0171 3772 ultra - ok
18:42:47.0750 3772 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
18:42:48.0656 3772 Update - ok
18:42:48.0984 3772 upperdev (587e643a4e2ffd9a00f114b057ceb773) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
18:42:49.0062 3772 upperdev - ok
18:42:49.0937 3772 usbbus - ok
18:42:50.0250 3772 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:42:50.0453 3772 usbccgp - ok
18:42:50.0750 3772 UsbDiag - ok
18:42:51.0078 3772 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:42:51.0343 3772 usbehci - ok
18:42:51.0656 3772 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:42:51.0890 3772 usbhub - ok
18:42:52.0171 3772 USBModem - ok
18:42:52.0500 3772 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
18:42:52.0703 3772 usbprint - ok
18:42:53.0031 3772 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:42:53.0234 3772 usbscan - ok
18:42:53.0562 3772 UsbserFilt (fca6a196d47cb972a0e4adc0db9cd17c) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
18:42:53.0640 3772 UsbserFilt - ok
18:42:54.0031 3772 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:42:54.0250 3772 usbstor - ok
18:42:54.0656 3772 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:42:54.0906 3772 usbuhci - ok
18:42:55.0234 3772 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
18:42:55.0453 3772 VgaSave - ok
18:42:55.0765 3772 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
18:42:55.0953 3772 ViaIde - ok
18:42:56.0312 3772 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
18:42:56.0546 3772 VolSnap - ok
18:42:56.0875 3772 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:42:57.0171 3772 Wanarp - ok
18:42:57.0765 3772 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
18:42:58.0062 3772 Wdf01000 - ok
18:42:58.0390 3772 WDICA - ok
18:42:58.0796 3772 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
18:42:59.0046 3772 wdmaud - ok
18:42:59.0406 3772 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys
18:42:59.0484 3772 WpdUsb - ok
18:42:59.0812 3772 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:43:00.0031 3772 WS2IFSL - ok
18:43:00.0359 3772 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
18:43:00.0609 3772 WSTCODEC - ok
18:43:00.0984 3772 WudfPf (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:43:01.0093 3772 WudfPf - ok
18:43:01.0484 3772 WudfRd (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:43:01.0546 3772 WudfRd - ok
18:43:02.0031 3772 xmasbus (ddd8286b88fe764ad2a8bd171e7b569a) C:\WINDOWS\system32\DRIVERS\xmasbus.sys
18:43:02.0203 3772 xmasbus ( UnsignedFile.Multi.Generic ) - warning
18:43:02.0203 3772 xmasbus - detected UnsignedFile.Multi.Generic (1)
18:43:02.0812 3772 xmasscsi (4059ad5e639fa47e334304cbe82e9572) C:\WINDOWS\system32\Drivers\xmasscsi.sys
18:43:03.0390 3772 xmasscsi ( UnsignedFile.Multi.Generic ) - warning
18:43:03.0390 3772 xmasscsi - detected UnsignedFile.Multi.Generic (1)
18:43:03.0578 3772 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
18:43:07.0531 3772 \Device\Harddisk0\DR0 - ok
18:43:07.0546 3772 Boot (0x1200) (7192dc0ca5d6d9cf6f2a8b6e26342dc9) \Device\Harddisk0\DR0\Partition0
18:43:07.0546 3772 \Device\Harddisk0\DR0\Partition0 - ok
18:43:07.0546 3772 Boot (0x1200) (53c90969ca60f1a2c64e804d40564dae) \Device\Harddisk0\DR0\Partition1
18:43:07.0546 3772 \Device\Harddisk0\DR0\Partition1 - ok
18:43:07.0546 3772 ============================================================
18:43:07.0546 3772 Scan finished
18:43:07.0546 3772 ============================================================
18:43:07.0687 3764 Detected object count: 20
18:43:07.0687 3764 Actual detected object count: 20
18:43:33.0093 3764 ASPI ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0093 3764 ASPI ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0093 3764 asuskbnt ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0093 3764 asuskbnt ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0093 3764 ASUSVRC ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0093 3764 ASUSVRC ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0109 3764 atksgt ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0109 3764 atksgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0109 3764 EIO_XP ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0109 3764 EIO_XP ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0109 3764 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0109 3764 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0109 3764 lirsgt ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0109 3764 lirsgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0109 3764 pcouffin ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0109 3764 pcouffin ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0109 3764 prodrv06 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0109 3764 prodrv06 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0125 3764 prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0125 3764 prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0125 3764 prosync1 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0125 3764 prosync1 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0125 3764 sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0125 3764 sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0125 3764 sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0125 3764 sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0125 3764 sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0125 3764 sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0125 3764 sfsync02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0125 3764 sfsync02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0140 3764 sfvfs02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0140 3764 sfvfs02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0140 3764 SNP325 ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0140 3764 SNP325 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0140 3764 sptd ( LockedFile.Multi.Generic ) - skipped by user
18:43:33.0140 3764 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
18:43:33.0140 3764 xmasbus ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0140 3764 xmasbus ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:33.0140 3764 xmasscsi ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:33.0140 3764 xmasscsi ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:43:43.0234 3676 Deinitialize success

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 19:05
od vyosek
:arrow: Jsme tu ve svem volnem case :)

:arrow: Stahnete aswMBR http://public.avast.com/%7Egmerek/aswMBR.exe a ulozte jej na plochu.
  • Utilitu spustte a prikazte ji, at skenuje - klik na Scan
  • Kliknutim na Save log ulozte log aswMBR na plochu
  • Obsah logu aswMBR mi sem vlozte

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 19:37
od Waler22
A som rád že ste tu lebo pomáhate užívateľom počas svojho voľného času, čo je super :)

No takže s tým aswMBR... dal som scan a po tom, čo to scanovalo najprv mi to len reštartlo pc, potom ale keď som to skúsil 2. krát bez otvorenej mozilly tak mi dokonca vyhodilo blue screen of death, niečo ako na tomto linku: http://hackspc.com/how-to-fix-blue-screen-of-death/ neviem presnejšie ako to vyzeralo...

Okrem toho mám na ploche nejaký MBR súbor s príponou .doc a má 512 bajtov a bol vytvorený 10.2.2012 o 18:33

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 19:45
od vyosek
Ten soubor mi nekam prosim uploadnete

:arrow: Stahnete MBRScan http://eric71.geekstogo.com/tools/MbrScan.exe
  • Ulozte nejlepe na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na MBRScan pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Report
  • Po chvilce se objevi log do souboru MBRScan.txt, ten sem vlozte

Re: Prosím o pomoc, pomalý a problémový chod PC

Napsal: 11 úno 2012 19:52
od Waler22
takže link na stiahnutie súboru: http://www.upnito.sk/subor/0b1b39415273 ... 8e01c.html

a ten log:

Kód: Vybrat vše

MBRScan v1.1.1

OS             : Windows XP Home Service Pack 3 (32 bit)
PROCESSOR      : x86 Family 15 Model 79 Stepping 2, AuthenticAMD
BOOT           : Normal Boot
DATE           : 2012/02/11 (ISO 8601) at 19:51:45
________________________________________________________________________________

DISK           : Device\Harddisk0\DR0 __WDC WD1200JS-00NCB1 (10.02E02)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : YES
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

Device\Harddisk0\DR0	111.8 Go  [Fixed] ==> XP MBR Code

MBR_MD5   : 22C94A85067EB99168C9908807E3A565
MBR_SHA1  : F59A3AA2C78193E5E53987479DA9A9185900F943

Device\Harddisk0\Partition1	39.06 Go  	0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2	72.72 Go  	0x07 NTFS / HPFS
________________________________________________________________________________

############################### Additional scan ################################

DRIVER  : C:\WINDOWS\System32\Drivers\dump_atapi.sys => Invisible on the disk
ADDRESS : 0xA2DAE000
SIZE    : 96.0 Ko

DRIVER  : C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS => Invisible on the disk
ADDRESS : 0xF79A3000
SIZE    : 8.0 Ko

DRIVER  : C:\DOCUME~1\PC\LOCALS~1\Temp\aswMBR.sys => Invisible on the disk
ADDRESS : 0x9FAB6000
SIZE    : 48.0 Ko

SystemStartOptions : NOEXECUTE=OPTIN  FASTDETECT

________________________________________________________________________________

_______MBR   \Device\Harddisk0\DR0  

0x00000000   33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C   3À.м.|ûP.P.ü¾.|
0x00000010   BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04   ¿..PW¹å.ó¤Ë½¾.±.
0x00000020   38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5   8n.|.u..Å.âôÍ..õ
0x00000030   83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B   .Æ.It.8,tö.µ.´..
0x00000040   F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88   ð¬<.tü»..´.Í.ëò.
0x00000050   4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B   N.èF.s*þF..~..t.
0x00000060   80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83   .~..t..¶.uÒ.F...
0x00000070   46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB   F...V..è!.s..¶.ë
0x00000080   BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0   ¼.>þ}Uªt..~..tÈ.
0x00000090   B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56   ·.ë©.ü.W.õË¿...V
0x000000A0   00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC   .´.Í.r#.Á$?..Þ.ü
0x000000B0   43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56   C÷ã.Ñ.Ö±.ÒîB÷â9V
0x000000C0   0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C   .w#r.9F.s.¸..».|
0x000000D0   8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A   .N..V.Í.sQOtN2ä.
0x000000E0   56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD   V.Í.ëä.V.`»ªU´AÍ
0x000000F0   13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60   .r6.ûUªu0öÁ.t+a`
0x00000100   6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A   j.j..v..v.j.h.|j
0x00000110   01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B   .j.´B.ôÍ.aas.Ot.
0x00000120   32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 49 6E 76 61   2ä.V.Í.ëÖaùÃInva
0x00000130   6C 69 64 20 70 61 72 74 69 74 69 6F 6E 20 74 61   lid partition ta
0x00000140   62 6C 65 00 45 72 72 6F 72 20 6C 6F 61 64 69 6E   ble.Error loadin
0x00000150   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x00000160   65 6D 00 4D 69 73 73 69 6E 67 20 6F 70 65 72 61   em.Missing opera
0x00000170   74 69 6E 67 20 73 79 73 74 65 6D 00 00 00 00 00   ting system.....
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 2C 44 63 9C 09 9D 09 00 00 80 01   .....,Dc........
0x000001C0   01 00 07 FE FF FF 3F 00 00 00 EC ED E1 04 00 00   ...þ..?...ìíá...
0x000001D0   C1 FF 0F FE FF FF 2B EE E1 04 D5 0A 17 09 00 00   Á..þ..+îá.Õ.....
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

+vyhodilo mi na plochu nejaký súbor Dump_Hdd0_DR0.mbr