Stránka 1 z 2

Kontrola logu-8 infiltrácií

Napsal: 29 črc 2012 00:44
od Royksopp
ESS mi hlásil 8 infiltrácií nejakého trójskeho koňa, tak chcem vedieť či mám v pc čisto:

Logfile of random's system information tool 1.09 (written by random/random)
Run by peter1 at 2012-07-29 00:30:01
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 30 GB (58%) free of 51 GB
Total RAM: 1023 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:30:13, on 29.7.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\Explorer.EXE
C:\WINDOWS1\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS1\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS1\system32\wuauclt.exe
C:\WINDOWS1\system32\SearchIndexer.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS1\system32\SearchProtocolHost.exe
C:\WINDOWS1\system32\SearchProtocolHost.exe
C:\Documents and Settings\peter1\Desktop\RSIT.exe
C:\Program Files\trend micro\peter1.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Complitly - {D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - C:\Documents and Settings\peter1\Application Data\Complitly\Complitly.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS1\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS1\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows1\system32\nwprovau.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 0746885015
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0747847109
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS1\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS1\system32\browseui.dll
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS1\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/peter1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

--
End of file - 5689 bytes

======Scheduled tasks folder======

C:\WINDOWS1\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS1\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\peter1\Application Data\Mozilla\Firefox\Profiles\3b6bt19t.default

prefs.js - "browser.startup.homepage" - "www.google.sk"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS1\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.265 Plugin
"Path"=C:\WINDOWS1\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS1\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.4.0]
"Description"=
"Path"=C:\WINDOWS1\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.4.0]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS1\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
avg-secure-search.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
SearchResults.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Documents and Settings\peter1\Application Data\Mozilla\Firefox\Profiles\3b6bt19t.default\extensions\
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{33e0daa6-3af3-d8b5-6752-10e949c61516}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-06-25 453064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D27FC31C-6E3D-4305-8D53-ACDAEFA5F862}]
Complitly - C:\Documents and Settings\peter1\Application Data\Complitly\Complitly.dll [2011-04-13 139768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-06-25 157640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS1\system32\NvCpl.dll [2012-05-15 15504192]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2012-03-07 3117344]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS1\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS1\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS1\system32\NvCpl.dll [2012-05-15 15504192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2012-05-15 1634112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Alerter"=2
"lanmanworkstation"=2
"W32Time"=2
"upnphost"=3
"seclogon"=2
"RDSessMgr"=3
"WmdmPmSN"=3
"mnmsrvc"=3
"CiSvc"=3
"PolicyAgent"=3
"helpsvc"=2
"FastUserSwitchingCompatibility"=3
"TrkWks"=2
"Browser"=2
"ClipSrv"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS1\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"
"C:\WINDOWS1\system32\muzapp.exe"="C:\WINDOWS1\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"C:\WINDOWS1\system32\msiexec.exe"="C:\WINDOWS1\system32\msiexec.exe:*:Enabled:UpdateManagerSetup"
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"E:\EasySetupAssistant\EasySetupAssistant.exe"="E:\EasySetupAssistant\EasySetupAssistant.exe:*:Enabled:TP-LINK Easy Setup Assistant"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS1\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=l3codecp.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer4"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-07-29 00:30:01 ----D---- C:\rsit
2012-07-25 21:35:31 ----D---- C:\Documents and Settings\peter1\Application Data\vlc
2012-07-25 21:34:45 ----D---- C:\Program Files\VideoLAN
2012-07-25 21:32:33 ----D---- C:\Program Files\Complitly
2012-07-25 21:32:33 ----D---- C:\Documents and Settings\peter1\Application Data\Complitly
2012-07-24 23:31:25 ----D---- C:\Program Files\Google
2012-07-17 16:49:43 ----D---- C:\Program Files\Defraggler
2012-07-15 23:47:08 ----D---- C:\Program Files\trend micro
2012-07-13 18:29:26 ----D---- C:\Documents and Settings\All Users.WINDOWS1\Application Data\ESET
2012-07-12 21:43:47 ----A---- C:\WINDOWS1\system32\FlashPlayerInstaller.exe
2012-07-11 00:17:32 ----HDC---- C:\WINDOWS1\$NtUninstallKB2698365$
2012-07-11 00:14:30 ----HDC---- C:\WINDOWS1\$NtUninstallKB2719985$
2012-07-11 00:12:59 ----HDC---- C:\WINDOWS1\$NtUninstallKB2655992$
2012-07-11 00:12:52 ----HDC---- C:\WINDOWS1\$NtUninstallKB2691442$
2012-07-11 00:12:40 ----HDC---- C:\WINDOWS1\$NtUninstallKB2718523$
2012-07-02 22:42:36 ----D---- C:\Documents and Settings\peter1\Application Data\SUPERAntiSpyware.com
2012-07-02 22:42:36 ----D---- C:\Documents and Settings\All Users.WINDOWS1\Application Data\SUPERAntiSpyware.com

======List of files/folders modified in the last 1 month======

2012-07-29 00:28:35 ----D---- C:\WINDOWS1\temp
2012-07-28 16:49:03 ----A---- C:\WINDOWS1\SchedLgU.Txt
2012-07-28 14:19:27 ----D---- C:\WINDOWS1\Prefetch
2012-07-28 00:43:58 ----SHD---- C:\WINDOWS1\Installer
2012-07-27 18:13:09 ----D---- C:\WINDOWS1\system32\CatRoot2
2012-07-27 01:51:38 ----D---- C:\Program Files
2012-07-25 21:29:34 ----D---- C:\Program Files\The KMPlayer
2012-07-25 21:00:27 ----ASH---- C:\boot.ini
2012-07-25 15:44:04 ----D---- C:\Program Files\Mozilla Firefox
2012-07-24 23:31:27 ----SD---- C:\WINDOWS1\Tasks
2012-07-23 22:31:31 ----D---- C:\WINDOWS1\system32\ReinstallBackups
2012-07-23 20:57:56 ----D---- C:\WINDOWS1
2012-07-17 21:06:53 ----D---- C:\WINDOWS1\Debug
2012-07-17 19:23:13 ----D---- C:\Documents and Settings\peter1\Application Data\Winamp
2012-07-17 16:46:05 ----D---- C:\Program Files\CCleaner
2012-07-16 12:50:50 ----D---- C:\WINDOWS1\system32\drivers\etc
2012-07-15 21:59:52 ----A---- C:\WINDOWS1\system32\FlashPlayerApp.exe
2012-07-13 18:30:06 ----HD---- C:\WINDOWS1\inf
2012-07-13 18:30:06 ----D---- C:\WINDOWS1\system32\drivers
2012-07-13 17:55:05 ----A---- C:\WINDOWS1\win.ini
2012-07-13 17:55:05 ----A---- C:\WINDOWS1\system.ini
2012-07-12 21:43:47 ----D---- C:\WINDOWS1\system32
2012-07-11 00:17:34 ----RSHDC---- C:\WINDOWS1\system32\dllcache
2012-07-11 00:17:28 ----HD---- C:\WINDOWS1\$hf_mig$
2012-07-11 00:14:49 ----A---- C:\WINDOWS1\system32\MRT.exe
2012-07-11 00:14:23 ----D---- C:\Documents and Settings\All Users.WINDOWS1\Application Data\Microsoft Help
2012-07-10 11:26:56 ----D---- C:\Program Files\NVIDIA Corporation

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvata;nvata; C:\WINDOWS1\system32\DRIVERS\nvata.sys [2005-05-17 92800]
R0 PxHelp20;PxHelp20; C:\WINDOWS1\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS1\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS1\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 eamon;eamon; C:\WINDOWS1\system32\DRIVERS\eamon.sys [2012-03-14 160816]
R1 ehdrv;ehdrv; C:\WINDOWS1\system32\DRIVERS\ehdrv.sys [2012-03-14 120152]
R1 epfwtdi;epfwtdi; C:\WINDOWS1\system32\DRIVERS\epfwtdi.sys [2012-03-14 61936]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS1\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 epfw;epfw; C:\WINDOWS1\system32\DRIVERS\epfw.sys [2012-03-14 148504]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS1\system32\drivers\ALCXWDM.SYS [2005-04-19 2317504]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS1\system32\DRIVERS\Epfwndis.sys [2012-03-14 40336]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS1\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS1\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS1\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS1\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS1\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS1\system32\DRIVERS\nv4_mini.sys [2012-05-15 14014656]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\WINDOWS1\system32\DRIVERS\NVENETFD.sys [2008-08-01 54784]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS1\system32\drivers\nvhda32.sys [2012-04-18 123840]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS1\system32\DRIVERS\nvnetbus.sys [2008-08-01 22016]
S1 SASDIFSV;SASDIFSV; \??\C:\DOCUME~1\peter1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\DOCUME~1\peter1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS []
S3 anvsnddrv;AnvSoft Virtual Sound Device; C:\WINDOWS1\system32\drivers\anvsnddrv.sys []
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS1\system32\drivers\btaudio.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS1\system32\DRIVERS\btport.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS1\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BTHMODEM;Bluetooth Modem Communications Driver; C:\WINDOWS1\system32\DRIVERS\bthmodem.sys [2008-04-13 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS1\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS1\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS1\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS1\system32\DRIVERS\btkrnl.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS1\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS1\System32\Drivers\btwusb.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS1\system32\DRIVERS\ewusbmdm.sys [2006-10-30 88960]
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 n558;N558 Bluetooth USB Filter Driver; C:\WINDOWS1\System32\Drivers\n558.sys [2007-08-15 9600]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS1\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS1\system32\drivers\ccdcmbo.sys [2011-08-17 23168]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS1\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 upperdev;upperdev; C:\WINDOWS1\system32\DRIVERS\usbser_lowerflt.sys [2011-08-17 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS1\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS1\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS1\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS1\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS1\system32\DRIVERS\usbser_lowerfltj.sys [2011-08-17 8192]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS1\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS1\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WinUSB;SAMSUNG Android USB Driver; C:\WINDOWS1\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WpdUsb;WpdUsb; C:\WINDOWS1\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS1\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BthServ;Bluetooth Support Service; C:\WINDOWS1\system32\svchost.exe [2008-04-14 14336]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2012-03-07 913144]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe [2005-04-29 139264]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2004-11-30 20543]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2005-04-29 131136]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2005-04-29 57412]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS1\system32\nvsvc32.exe [2012-05-15 164160]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R2 WSearch;Windows Search; C:\WINDOWS1\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS1\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS1\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-07-24 116648]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS1\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS1\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-07-24 116648]
S3 idsvc;Windows CardSpace; C:\WINDOWS1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS1\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS1\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS1\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Kontrola logu-8 infiltrácií

Napsal: 29 črc 2012 09:03
od vyosek
Zdravim :)

:arrow: Co s nimi ESS udelal? Pripadne dejte screen karanteny nebo pokud hlasky stale skacou tak screen hlasek

Re: Kontrola logu-8 infiltrácií

Napsal: 29 črc 2012 10:57
od Royksopp
ESS ich vyliečil a zmazal som to potom aj z karantény, takže už neviem aká to bola háveď...len som chcel vedieť, či niečo v pc nezostalo, či ich ESS dostatočne odstánil.

Re: Kontrola logu-8 infiltrácií

Napsal: 29 črc 2012 11:14
od vyosek
:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni

Re: Kontrola logu-8 infiltrácií

Napsal: 29 črc 2012 18:01
od Royksopp
Ešte medzi tým by som sa chcel spýtať, či sa nedá nejako zistiť, či nemám niečo s internetom, pretože už viac ako mesiac mi ide strašne pomaly a väčšinou sa mi niektoré stránky ani nenačítajú. Písal som aj to Telekomu a tam mi písali, že nevidia žiadnu závadu. Aj na notebooku tak isto a aj s mobilom, keď sa pripojím ide pomaly. Takže možnože mám niekde niečo zle nastavené. Vedeli by ste mi s tým neako pomôcť?

Log:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Verzia databázy: v2012.07.29.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
peter1 :: PETER [administrátor]

29.7.2012 19:08:58
mbam-log-2012-07-29 (19-08-58).txt

Typ kontroly: Úplná kontrola (A:\|C:\|D:\|E:\|)
Možnosti kontroly zapnuté: Pamäť | Po spustení | Registre | Systémové súbory | Heuristika/Extra | Heuristika/Shuriken | PUP | PUM
Možnosti kontroly vypnuté: P2P
Objektov kontrolovaných: 399886
Uplynutý čas: 43 min, 26 sek

Detegované služby pamäte: 0
(Škodlivé položky neboli zistené)

Detegované moduly pamäte: 0
(Škodlivé položky neboli zistené)

Detegované registračné kľúče: 0
(Škodlivé položky neboli zistené)

Detegované registračné hodnoty: 0
(Škodlivé položky neboli zistené)

Detegované položky registračných dát: 0
(Škodlivé položky neboli zistené)

Detegované priečinky: 0
(Škodlivé položky neboli zistené)

Detegované súbory: 0
(Škodlivé položky neboli zistené)

(koniec)

Re: Kontrola logu-8 infiltrácií

Napsal: 29 črc 2012 20:00
od vyosek
:arrow: Mobil, ntb i PC se pripojuji pres ten samy router? zkuste jeho restart (na par minut odpojit ze site)

:arrow: Pokud nepomuze, tak bude chyba na strane providera, nesmite se nechat jen tak odbyt a znovu otravovat

Re: Kontrola logu-8 infiltrácií

Napsal: 30 črc 2012 23:30
od Royksopp
Nie nepomohlo to, lebo to som už robil dávno a aj bol vypnutý 5 dní.

My máme v bytovke 2 linky a písal, že sú obe v poriadku a nikto sa z bytovky nesťažoval, žeby mu išiel pomaly internet. Mám dojem akoby som mal niečo niekde zle nastavené, ono to tak ako keby brzdilo ten internet.

Re: Kontrola logu-8 infiltrácií

Napsal: 31 črc 2012 17:32
od vyosek
:arrow: Pak leda zkontrolovat nastaveni parametru pripojeni k internetu dle smlouvy ci pokynu operatora

Re: Kontrola logu-8 infiltrácií

Napsal: 31 črc 2012 20:46
od Royksopp
Takže problém nebude len u mňa, lebo som počul, že to robí aj druhým už. Ďakujem aj tak

Re: Kontrola logu-8 infiltrácií

Napsal: 31 črc 2012 20:48
od vyosek
Takze kontaktovat poskytovatele a stale "otravovat" a domahat se reseni...

Nemate zac, rado se stalo :worship:

Re: Kontrola logu-8 infiltrácií

Napsal: 07 srp 2012 00:03
od Royksopp
Musím sa vrátiť k tejto téme, pretože sa mi zdá, že mi ide akosi pomalšie pc.... keď sa nič nenájde, tak dala by sa spraviť hlbšia kontrola?

Logfile of random's system information tool 1.09 (written by random/random)
Run by peter1 at 2012-08-07 00:59:49
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 30 GB (58%) free of 51 GB
Total RAM: 1023 MB (36% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:59:54, on 7.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\Explorer.EXE
C:\WINDOWS1\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS1\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS1\system32\SearchIndexer.exe
C:\WINDOWS1\system32\wuauclt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS1\system32\SearchProtocolHost.exe
C:\Documents and Settings\peter1\Desktop\RSIT.exe
C:\Program Files\trend micro\peter1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Complitly - {D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - C:\Documents and Settings\peter1\Application Data\Complitly\Complitly.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS1\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS1\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows1\system32\nwprovau.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 0746885015
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0747847109
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS1\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS1\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS1\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS1\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/peter1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

--
End of file - 5995 bytes

======Scheduled tasks folder======

C:\WINDOWS1\tasks\Adobe Flash Player Updater.job
C:\WINDOWS1\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS1\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\peter1\Application Data\Mozilla\Firefox\Profiles\3b6bt19t.default

prefs.js - "browser.startup.homepage" - "www.google.sk"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS1\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.270 Plugin
"Path"=C:\WINDOWS1\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS1\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.4.0]
"Description"=
"Path"=C:\WINDOWS1\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.4.0]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS1\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
avg-secure-search.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
SearchResults.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Documents and Settings\peter1\Application Data\Mozilla\Firefox\Profiles\3b6bt19t.default\extensions\
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{33e0daa6-3af3-d8b5-6752-10e949c61516}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-06-25 453064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D27FC31C-6E3D-4305-8D53-ACDAEFA5F862}]
Complitly - C:\Documents and Settings\peter1\Application Data\Complitly\Complitly.dll [2011-04-13 139768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-06-25 157640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS1\system32\NvCpl.dll [2012-05-15 15504192]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2012-03-07 3117344]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS1\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
bthprops.cpl,,BluetoothAuthenticationAgent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS1\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2012-07-03 462920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS1\system32\NvCpl.dll [2012-05-15 15504192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS1\SOUNDMAN.EXE [2005-04-15 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Alerter"=2
"lanmanworkstation"=2
"W32Time"=2
"upnphost"=3
"seclogon"=2
"RDSessMgr"=3
"WmdmPmSN"=3
"mnmsrvc"=3
"CiSvc"=3
"PolicyAgent"=3
"helpsvc"=2
"FastUserSwitchingCompatibility"=3
"TrkWks"=2
"Browser"=2
"ClipSrv"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS1\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS1\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=l3codecp.acm
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-08-07 00:59:49 ----D---- C:\rsit
2012-08-07 00:59:49 ----D---- C:\Program Files\trend micro
2012-08-06 00:13:50 ----D---- C:\Documents and Settings\peter1\Application Data\Free Sound Recorder
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTWMAFile2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTTextToAudio2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTAudioVisualization2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTAudioTransform2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTAudioRecord2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTAudioPlayer2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTAudioInformation2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTAudioFile2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTAudioEditor2.dll
2012-08-06 00:13:42 ----A---- C:\WINDOWS1\system32\NCTAudioCDGrabber2.dll
2012-08-06 00:13:41 ----D---- C:\Program Files\Free Sound Recorder
2012-08-05 15:37:11 ----A---- C:\WINDOWS1\system32\drivers\mbamswissarmy.sys
2012-07-29 23:24:05 ----N---- C:\WINDOWS1\system32\spmsg.dll
2012-07-29 23:23:36 ----HDC---- C:\WINDOWS1\$NtUninstallwmp11$
2012-07-29 21:40:08 ----D---- C:\Program Files\Realtek Sound Manager
2012-07-29 21:40:06 ----N---- C:\WINDOWS1\avrack.ini
2012-07-29 21:40:06 ----D---- C:\Program Files\AvRack
2012-07-29 19:06:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-07-29 19:06:03 ----A---- C:\WINDOWS1\system32\drivers\mbam.sys
2012-07-29 01:33:46 ----A---- C:\WINDOWS1\system32\wmpns.dll
2012-07-25 21:35:31 ----D---- C:\Documents and Settings\peter1\Application Data\vlc
2012-07-25 21:34:45 ----D---- C:\Program Files\VideoLAN
2012-07-25 21:32:33 ----D---- C:\Program Files\Complitly
2012-07-25 21:32:33 ----D---- C:\Documents and Settings\peter1\Application Data\Complitly
2012-07-24 23:31:25 ----D---- C:\Program Files\Google
2012-07-17 16:49:43 ----D---- C:\Program Files\Defraggler
2012-07-13 18:29:26 ----D---- C:\Documents and Settings\All Users.WINDOWS1\Application Data\ESET
2012-07-11 00:17:32 ----HDC---- C:\WINDOWS1\$NtUninstallKB2698365$
2012-07-11 00:14:30 ----HDC---- C:\WINDOWS1\$NtUninstallKB2719985$
2012-07-11 00:12:59 ----HDC---- C:\WINDOWS1\$NtUninstallKB2655992$
2012-07-11 00:12:52 ----HDC---- C:\WINDOWS1\$NtUninstallKB2691442$
2012-07-11 00:12:40 ----HDC---- C:\WINDOWS1\$NtUninstallKB2718523$

======List of files/folders modified in the last 1 month======

2012-08-07 00:59:49 ----D---- C:\Program Files
2012-08-07 00:53:28 ----D---- C:\WINDOWS1\temp
2012-08-06 15:23:48 ----A---- C:\WINDOWS1\SchedLgU.Txt
2012-08-06 02:20:21 ----D---- C:\WINDOWS1\system32\CatRoot2
2012-08-06 00:16:53 ----D---- C:\WINDOWS1\Prefetch
2012-08-06 00:13:47 ----D---- C:\WINDOWS1
2012-08-06 00:13:42 ----D---- C:\WINDOWS1\system32
2012-08-06 00:09:13 ----SHD---- C:\WINDOWS1\Installer
2012-08-05 15:37:47 ----D---- C:\WINDOWS1\system32\drivers
2012-08-05 00:18:29 ----D---- C:\Documents and Settings\peter1\Application Data\Winamp
2012-08-04 01:25:58 ----D---- C:\Program Files\CCleaner
2012-08-04 01:09:21 ----ASH---- C:\boot.ini
2012-08-04 01:09:21 ----A---- C:\WINDOWS1\win.ini
2012-08-04 01:09:21 ----A---- C:\WINDOWS1\system.ini
2012-08-03 21:49:49 ----A---- C:\WINDOWS1\system32\FlashPlayerApp.exe
2012-08-01 17:00:39 ----SD---- C:\WINDOWS1\Tasks
2012-08-01 01:56:51 ----D---- C:\WINDOWS1\Debug
2012-07-30 21:46:20 ----A---- C:\WINDOWS1\RtlRack.ini
2012-07-30 14:12:35 ----D---- C:\WINDOWS1\system32\CatRoot
2012-07-30 14:10:42 ----RSHDC---- C:\WINDOWS1\system32\dllcache
2012-07-30 14:10:42 ----HD---- C:\WINDOWS1\inf
2012-07-29 23:23:44 ----D---- C:\Program Files\Windows Media Connect 2
2012-07-29 23:23:43 ----D---- C:\Program Files\Windows Media Player
2012-07-29 23:23:40 ----D---- C:\WINDOWS1\Help
2012-07-29 23:22:41 ----D---- C:\WINDOWS1\system32\drivers\UMDF
2012-07-29 21:49:17 ----D---- C:\WINDOWS1\system32\ReinstallBackups
2012-07-25 15:44:04 ----D---- C:\Program Files\Mozilla Firefox
2012-07-16 12:50:50 ----D---- C:\WINDOWS1\system32\drivers\etc
2012-07-11 00:17:28 ----HD---- C:\WINDOWS1\$hf_mig$
2012-07-11 00:14:49 ----A---- C:\WINDOWS1\system32\MRT.exe
2012-07-11 00:14:23 ----D---- C:\Documents and Settings\All Users.WINDOWS1\Application Data\Microsoft Help
2012-07-10 11:26:56 ----D---- C:\Program Files\NVIDIA Corporation

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvata;nvata; C:\WINDOWS1\system32\DRIVERS\nvata.sys [2005-05-17 92800]
R0 PxHelp20;PxHelp20; C:\WINDOWS1\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS1\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS1\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 eamon;eamon; C:\WINDOWS1\system32\DRIVERS\eamon.sys [2012-03-14 160816]
R1 ehdrv;ehdrv; C:\WINDOWS1\system32\DRIVERS\ehdrv.sys [2012-03-14 120152]
R1 epfwtdi;epfwtdi; C:\WINDOWS1\system32\DRIVERS\epfwtdi.sys [2012-03-14 61936]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS1\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 epfw;epfw; C:\WINDOWS1\system32\DRIVERS\epfw.sys [2012-03-14 148504]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS1\system32\drivers\ALCXWDM.SYS [2005-04-19 2317504]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS1\system32\DRIVERS\Epfwndis.sys [2012-03-14 40336]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS1\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS1\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS1\system32\drivers\mbam.sys []
R3 mouhid;Mouse HID Driver; C:\WINDOWS1\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS1\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS1\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS1\system32\DRIVERS\nv4_mini.sys [2012-05-15 14014656]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\WINDOWS1\system32\DRIVERS\NVENETFD.sys [2008-08-01 54784]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS1\system32\drivers\nvhda32.sys [2012-04-18 123840]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS1\system32\DRIVERS\nvnetbus.sys [2008-08-01 22016]
S1 SASDIFSV;SASDIFSV; \??\C:\DOCUME~1\peter1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\DOCUME~1\peter1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS []
S3 anvsnddrv;AnvSoft Virtual Sound Device; C:\WINDOWS1\system32\drivers\anvsnddrv.sys []
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS1\system32\drivers\btaudio.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS1\system32\DRIVERS\btport.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS1\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BTHMODEM;Bluetooth Modem Communications Driver; C:\WINDOWS1\system32\DRIVERS\bthmodem.sys [2008-04-13 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS1\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS1\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS1\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS1\system32\DRIVERS\btkrnl.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS1\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS1\System32\Drivers\btwusb.sys []
S3 cpuz135;cpuz135; \??\C:\DOCUME~1\peter1\LOCALS~1\Temp\cpuz135\cpuz135_x32.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS1\system32\DRIVERS\ewusbmdm.sys [2006-10-30 88960]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS1\system32\drivers\mbamswissarmy.sys []
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 n558;N558 Bluetooth USB Filter Driver; C:\WINDOWS1\System32\Drivers\n558.sys [2007-08-15 9600]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS1\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS1\system32\drivers\ccdcmbo.sys [2011-08-17 23168]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS1\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 speccy;speccy; \??\C:\DOCUME~1\peter1\LOCALS~1\Temp\d38d48ec-105e-486a-a3c5-339c3df6699f []
S3 upperdev;upperdev; C:\WINDOWS1\system32\DRIVERS\usbser_lowerflt.sys [2011-08-17 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS1\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS1\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS1\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS1\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS1\system32\DRIVERS\usbser_lowerfltj.sys [2011-08-17 8192]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS1\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS1\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WinUSB;SAMSUNG Android USB Driver; C:\WINDOWS1\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WpdUsb;WpdUsb; C:\WINDOWS1\system32\DRIVERS\wpdusb.sys [2009-01-30 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS1\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BthServ;Bluetooth Support Service; C:\WINDOWS1\system32\svchost.exe [2008-04-14 14336]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2012-03-07 913144]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe [2005-04-29 139264]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2004-11-30 20543]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2005-04-29 131136]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2005-04-29 57412]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS1\system32\nvsvc32.exe [2012-05-15 164160]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R2 WSearch;Windows Search; C:\WINDOWS1\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS1\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS1\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-07-24 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS1\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-03 250056]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS1\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS1\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-07-24 116648]
S3 idsvc;Windows CardSpace; C:\WINDOWS1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS1\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-01-30 913408]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS1\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS1\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Kontrola logu-8 infiltrácií

Napsal: 07 srp 2012 08:00
od vyosek
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte
:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
  • Detailni postup vc. obrazku mate zde http://forum.viry.cz/viewtopic.php?f=24&t=120452

Re: Kontrola logu-8 infiltrácií

Napsal: 07 srp 2012 22:36
od Royksopp
TDSSKiller

23:33:40.0515 2708 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
23:33:40.0640 2708 ============================================================
23:33:40.0640 2708 Current date / time: 2012/08/07 23:33:40.0640
23:33:40.0640 2708 SystemInfo:
23:33:40.0640 2708
23:33:40.0640 2708 OS Version: 5.1.2600 ServicePack: 3.0
23:33:40.0640 2708 Product type: Workstation
23:33:40.0640 2708 ComputerName: PETER
23:33:40.0640 2708 UserName: peter1
23:33:40.0640 2708 Windows directory: C:\WINDOWS1
23:33:40.0640 2708 System windows directory: C:\WINDOWS1
23:33:40.0640 2708 Processor architecture: Intel x86
23:33:40.0640 2708 Number of processors: 1
23:33:40.0640 2708 Page size: 0x1000
23:33:40.0640 2708 Boot type: Normal boot
23:33:40.0640 2708 ============================================================
23:33:42.0140 2708 Drive \Device\Harddisk0\DR0 - Size: 0x2F7B100000 (189.92 Gb), SectorSize: 0x200, Cylinders: 0x60D8, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
23:33:42.0171 2708 ============================================================
23:33:42.0171 2708 \Device\Harddisk0\DR0:
23:33:42.0171 2708 MBR partitions:
23:33:42.0171 2708 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x640B6C3
23:33:42.0203 2708 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x640B741, BlocksNum 0x117C5CD6
23:33:42.0203 2708 ============================================================
23:33:42.0250 2708 C: <-> \Device\Harddisk0\DR0\Partition0
23:33:42.0312 2708 D: <-> \Device\Harddisk0\DR0\Partition1
23:33:42.0312 2708 ============================================================
23:33:42.0312 2708 Initialize success
23:33:42.0312 2708 ============================================================
23:34:25.0140 3908 ============================================================
23:34:25.0140 3908 Scan started
23:34:25.0140 3908 Mode: Manual; SigCheck; TDLFS;
23:34:25.0140 3908 ============================================================
23:34:25.0750 3908 Abiosdsk - ok
23:34:25.0750 3908 abp480n5 - ok
23:34:25.0812 3908 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS1\system32\DRIVERS\ACPI.sys
23:34:26.0781 3908 ACPI - ok
23:34:26.0812 3908 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS1\system32\drivers\ACPIEC.sys
23:34:26.0953 3908 ACPIEC - ok
23:34:27.0000 3908 AdobeFlashPlayerUpdateSvc (f19c98ad81d2c0e1bbfd8153d2c80ee8) C:\WINDOWS1\system32\Macromed\Flash\FlashPlayerUpdateService.exe
23:34:27.0031 3908 AdobeFlashPlayerUpdateSvc - ok
23:34:27.0031 3908 adpu160m - ok
23:34:27.0062 3908 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS1\system32\drivers\aec.sys
23:34:27.0234 3908 aec - ok
23:34:27.0250 3908 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS1\System32\drivers\afd.sys
23:34:27.0312 3908 AFD - ok
23:34:27.0312 3908 Aha154x - ok
23:34:27.0328 3908 aic78u2 - ok
23:34:27.0328 3908 aic78xx - ok
23:34:27.0421 3908 ALCXWDM (95aa37bec6c72c277c2caeaee736dd2d) C:\WINDOWS1\system32\drivers\ALCXWDM.SYS
23:34:27.0640 3908 ALCXWDM - ok
23:34:27.0734 3908 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS1\system32\alrsvc.dll
23:34:27.0875 3908 Alerter - ok
23:34:27.0890 3908 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS1\System32\alg.exe
23:34:27.0968 3908 ALG - ok
23:34:27.0984 3908 AliIde - ok
23:34:28.0046 3908 AmdPPM (033448d435e65c4bd72e70521fd05c76) C:\WINDOWS1\system32\DRIVERS\AmdPPM.sys
23:34:28.0093 3908 AmdPPM - ok
23:34:28.0093 3908 amsint - ok
23:34:28.0093 3908 anvsnddrv - ok
23:34:28.0109 3908 AppMgmt - ok
23:34:28.0109 3908 asc - ok
23:34:28.0125 3908 asc3350p - ok
23:34:28.0125 3908 asc3550 - ok
23:34:28.0203 3908 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS1\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
23:34:28.0265 3908 aspnet_state - ok
23:34:28.0312 3908 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS1\system32\DRIVERS\asyncmac.sys
23:34:28.0453 3908 AsyncMac - ok
23:34:28.0468 3908 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS1\system32\DRIVERS\atapi.sys
23:34:28.0593 3908 atapi - ok
23:34:28.0609 3908 Atdisk - ok
23:34:28.0640 3908 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS1\system32\DRIVERS\atmarpc.sys
23:34:28.0812 3908 Atmarpc - ok
23:34:28.0843 3908 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS1\System32\audiosrv.dll
23:34:29.0000 3908 AudioSrv - ok
23:34:29.0031 3908 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS1\system32\DRIVERS\audstub.sys
23:34:29.0171 3908 audstub - ok
23:34:29.0203 3908 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS1\system32\drivers\Beep.sys
23:34:29.0375 3908 Beep - ok
23:34:29.0406 3908 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS1\system32\qmgr.dll
23:34:29.0609 3908 BITS - ok
23:34:29.0625 3908 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS1\System32\browser.dll
23:34:29.0812 3908 Browser - ok
23:34:29.0828 3908 btaudio - ok
23:34:29.0828 3908 BTDriver - ok
23:34:29.0875 3908 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS1\system32\DRIVERS\BthEnum.sys
23:34:30.0015 3908 BthEnum - ok
23:34:30.0031 3908 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS1\system32\DRIVERS\bthmodem.sys
23:34:30.0218 3908 BTHMODEM - ok
23:34:30.0234 3908 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS1\system32\DRIVERS\bthpan.sys
23:34:30.0406 3908 BthPan - ok
23:34:30.0453 3908 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS1\system32\Drivers\BTHport.sys
23:34:30.0515 3908 BTHPORT - ok
23:34:30.0546 3908 BthServ (f4c43c66471b87996d95db7a3a664a37) C:\WINDOWS1\System32\bthserv.dll
23:34:30.0687 3908 BthServ - ok
23:34:30.0750 3908 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS1\system32\Drivers\BTHUSB.sys
23:34:30.0906 3908 BTHUSB - ok
23:34:30.0921 3908 BTKRNL - ok
23:34:30.0921 3908 BTWDNDIS - ok
23:34:30.0937 3908 BTWUSB - ok
23:34:30.0953 3908 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS1\system32\drivers\cbidf2k.sys
23:34:31.0109 3908 cbidf2k - ok
23:34:31.0125 3908 cd20xrnt - ok
23:34:31.0156 3908 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS1\system32\drivers\Cdaudio.sys
23:34:31.0312 3908 Cdaudio - ok
23:34:31.0343 3908 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS1\system32\drivers\Cdfs.sys
23:34:31.0500 3908 Cdfs - ok
23:34:31.0531 3908 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS1\system32\DRIVERS\cdrom.sys
23:34:31.0718 3908 Cdrom - ok
23:34:31.0734 3908 Changer - ok
23:34:31.0765 3908 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS1\system32\cisvc.exe
23:34:31.0906 3908 CiSvc - ok
23:34:31.0921 3908 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS1\system32\clipsrv.exe
23:34:32.0093 3908 ClipSrv - ok
23:34:32.0171 3908 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS1\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
23:34:32.0250 3908 clr_optimization_v2.0.50727_32 - ok
23:34:32.0296 3908 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\WINDOWS1\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
23:34:32.0328 3908 clr_optimization_v4.0.30319_32 - ok
23:34:32.0328 3908 CmdIde - ok
23:34:32.0343 3908 COMSysApp - ok
23:34:32.0359 3908 Cpqarray - ok
23:34:32.0453 3908 cpuz135 - ok
23:34:32.0468 3908 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS1\System32\cryptsvc.dll
23:34:32.0640 3908 CryptSvc - ok
23:34:32.0640 3908 dac2w2k - ok
23:34:32.0656 3908 dac960nt - ok
23:34:32.0687 3908 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS1\system32\rpcss.dll
23:34:32.0796 3908 DcomLaunch - ok
23:34:32.0859 3908 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS1\System32\dhcpcsvc.dll
23:34:33.0046 3908 Dhcp - ok
23:34:33.0078 3908 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS1\system32\DRIVERS\disk.sys
23:34:33.0234 3908 Disk - ok
23:34:33.0234 3908 dmadmin - ok
23:34:33.0296 3908 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS1\system32\drivers\dmboot.sys
23:34:33.0515 3908 dmboot - ok
23:34:33.0546 3908 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS1\system32\drivers\dmio.sys
23:34:33.0687 3908 dmio - ok
23:34:33.0734 3908 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS1\system32\drivers\dmload.sys
23:34:33.0875 3908 dmload - ok
23:34:33.0906 3908 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS1\System32\dmserver.dll
23:34:34.0062 3908 dmserver - ok
23:34:34.0078 3908 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS1\system32\drivers\DMusic.sys
23:34:34.0250 3908 DMusic - ok
23:34:34.0265 3908 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS1\System32\dnsrslvr.dll
23:34:34.0343 3908 Dnscache - ok
23:34:34.0390 3908 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS1\System32\dot3svc.dll
23:34:34.0546 3908 Dot3svc - ok
23:34:34.0562 3908 dpti2o - ok
23:34:34.0593 3908 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS1\system32\drivers\drmkaud.sys
23:34:34.0734 3908 drmkaud - ok
23:34:34.0781 3908 eamon (8c2b6bbc82ad12cd9a2e73e5dcbba705) C:\WINDOWS1\system32\DRIVERS\eamon.sys
23:34:34.0828 3908 eamon - ok
23:34:34.0859 3908 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS1\System32\eapsvc.dll
23:34:35.0062 3908 EapHost - ok
23:34:35.0093 3908 ehdrv (5412ed24fffca64e2f0168399b86c952) C:\WINDOWS1\system32\DRIVERS\ehdrv.sys
23:34:35.0109 3908 ehdrv - ok
23:34:35.0218 3908 ekrn (ad4faade819e0da9933bea7c01d2c763) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
23:34:35.0281 3908 ekrn - ok
23:34:35.0312 3908 epfw (774babcb1144513dc86992003740b774) C:\WINDOWS1\system32\DRIVERS\epfw.sys
23:34:35.0328 3908 epfw - ok
23:34:35.0343 3908 Epfwndis (4b86da2c58063b647577cd669cffaeeb) C:\WINDOWS1\system32\DRIVERS\Epfwndis.sys
23:34:35.0359 3908 Epfwndis - ok
23:34:35.0406 3908 epfwtdi (1b36748ea9e25549ebe5d8ea105bd981) C:\WINDOWS1\system32\DRIVERS\epfwtdi.sys
23:34:35.0421 3908 epfwtdi - ok
23:34:35.0453 3908 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS1\System32\ersvc.dll
23:34:35.0640 3908 ERSvc - ok
23:34:35.0671 3908 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS1\system32\services.exe
23:34:35.0703 3908 Eventlog - ok
23:34:35.0750 3908 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS1\system32\es.dll
23:34:35.0812 3908 EventSystem - ok
23:34:35.0875 3908 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS1\system32\drivers\Fastfat.sys
23:34:36.0187 3908 Fastfat - ok
23:34:36.0218 3908 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS1\System32\shsvcs.dll
23:34:36.0265 3908 FastUserSwitchingCompatibility - ok
23:34:36.0296 3908 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS1\system32\DRIVERS\fdc.sys
23:34:36.0453 3908 Fdc - ok
23:34:36.0468 3908 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS1\system32\drivers\Fips.sys
23:34:36.0625 3908 Fips - ok
23:34:36.0640 3908 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS1\system32\DRIVERS\flpydisk.sys
23:34:36.0828 3908 Flpydisk - ok
23:34:36.0859 3908 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS1\system32\drivers\fltmgr.sys
23:34:37.0031 3908 FltMgr - ok
23:34:37.0125 3908 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) C:\WINDOWS1\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
23:34:37.0140 3908 FontCache3.0.0.0 - ok
23:34:37.0218 3908 ForceWare Intelligent Application Manager (IAM) (b47576825f0a397e1c807c7ec23e1560) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
23:34:37.0234 3908 ForceWare Intelligent Application Manager (IAM) ( UnsignedFile.Multi.Generic ) - warning
23:34:37.0234 3908 ForceWare Intelligent Application Manager (IAM) - detected UnsignedFile.Multi.Generic (1)
23:34:37.0281 3908 ForcewareWebInterface (b81f8778f5bb485f3b75114f0c99a49f) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
23:34:37.0296 3908 ForcewareWebInterface ( UnsignedFile.Multi.Generic ) - warning
23:34:37.0296 3908 ForcewareWebInterface - detected UnsignedFile.Multi.Generic (1)
23:34:37.0328 3908 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS1\system32\drivers\Fs_Rec.sys
23:34:37.0484 3908 Fs_Rec - ok
23:34:37.0500 3908 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS1\system32\DRIVERS\ftdisk.sys
23:34:37.0656 3908 Ftdisk - ok
23:34:37.0671 3908 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS1\system32\DRIVERS\gameenum.sys
23:34:37.0843 3908 gameenum - ok
23:34:37.0843 3908 GMSIPCI - ok
23:34:37.0859 3908 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS1\system32\DRIVERS\msgpc.sys
23:34:38.0046 3908 Gpc - ok
23:34:38.0078 3908 gupdate (506708142bc63daba64f2d3ad1dcd5bf) C:\Program Files\Google\Update\GoogleUpdate.exe
23:34:38.0109 3908 gupdate - ok
23:34:38.0109 3908 gupdatem (506708142bc63daba64f2d3ad1dcd5bf) C:\Program Files\Google\Update\GoogleUpdate.exe
23:34:38.0140 3908 gupdatem - ok
23:34:38.0171 3908 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS1\system32\DRIVERS\HDAudBus.sys
23:34:38.0343 3908 HDAudBus - ok
23:34:38.0390 3908 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS1\PCHealth\HelpCtr\Binaries\pchsvc.dll
23:34:38.0531 3908 helpsvc - ok
23:34:38.0546 3908 HidServ - ok
23:34:38.0578 3908 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS1\system32\DRIVERS\hidusb.sys
23:34:38.0718 3908 hidusb - ok
23:34:38.0750 3908 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS1\System32\kmsvc.dll
23:34:38.0921 3908 hkmsvc - ok
23:34:38.0937 3908 hpn - ok
23:34:38.0968 3908 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS1\system32\Drivers\HTTP.sys
23:34:39.0000 3908 HTTP - ok
23:34:39.0046 3908 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS1\System32\w3ssl.dll
23:34:39.0187 3908 HTTPFilter - ok
23:34:39.0250 3908 hwdatacard (200ab8daf659c7324601fcc824d7f910) C:\WINDOWS1\system32\DRIVERS\ewusbmdm.sys
23:34:39.0265 3908 hwdatacard ( UnsignedFile.Multi.Generic ) - warning
23:34:39.0265 3908 hwdatacard - detected UnsignedFile.Multi.Generic (1)
23:34:39.0281 3908 i2omgmt - ok
23:34:39.0281 3908 i2omp - ok
23:34:39.0296 3908 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS1\system32\DRIVERS\i8042prt.sys
23:34:39.0468 3908 i8042prt - ok
23:34:39.0578 3908 idsvc (c01ac32dc5c03076cfb852cb5da5229c) C:\WINDOWS1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
23:34:39.0640 3908 idsvc - ok
23:34:39.0656 3908 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS1\system32\DRIVERS\imapi.sys
23:34:39.0843 3908 Imapi - ok
23:34:39.0890 3908 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS1\system32\imapi.exe
23:34:40.0062 3908 ImapiService - ok
23:34:40.0078 3908 ini910u - ok
23:34:40.0093 3908 IntelIde - ok
23:34:40.0125 3908 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS1\system32\drivers\ip6fw.sys
23:34:40.0296 3908 Ip6Fw - ok
23:34:40.0328 3908 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS1\system32\DRIVERS\ipfltdrv.sys
23:34:40.0453 3908 IpFilterDriver - ok
23:34:40.0484 3908 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS1\system32\DRIVERS\ipinip.sys
23:34:40.0656 3908 IpInIp - ok
23:34:40.0671 3908 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS1\system32\DRIVERS\ipnat.sys
23:34:40.0843 3908 IpNat - ok
23:34:40.0890 3908 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS1\system32\DRIVERS\ipsec.sys
23:34:41.0078 3908 IPSec - ok
23:34:41.0109 3908 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS1\system32\DRIVERS\irenum.sys
23:34:41.0171 3908 IRENUM - ok
23:34:41.0203 3908 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS1\system32\DRIVERS\isapnp.sys
23:34:41.0343 3908 isapnp - ok
23:34:41.0468 3908 JavaQuickStarterService (8c5c59e1921eca3607390a1f641556df) C:\Program Files\Java\jre7\bin\jqs.exe
23:34:41.0484 3908 JavaQuickStarterService - ok
23:34:41.0515 3908 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS1\system32\DRIVERS\kbdclass.sys
23:34:41.0671 3908 Kbdclass - ok
23:34:41.0687 3908 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS1\system32\drivers\kmixer.sys
23:34:41.0859 3908 kmixer - ok
23:34:41.0906 3908 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS1\system32\drivers\KSecDD.sys
23:34:42.0015 3908 KSecDD - ok
23:34:42.0062 3908 lanmanserver (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS1\System32\srvsvc.dll
23:34:42.0093 3908 lanmanserver - ok
23:34:42.0125 3908 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS1\System32\wkssvc.dll
23:34:42.0171 3908 lanmanworkstation - ok
23:34:42.0187 3908 lbrtfdc - ok
23:34:42.0218 3908 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS1\System32\lmhsvc.dll
23:34:42.0359 3908 LmHosts - ok
23:34:42.0390 3908 MBAMProtector (6dfe7f2e8e8a337263aa5c92a215f161) C:\WINDOWS1\system32\drivers\mbam.sys
23:34:42.0406 3908 MBAMProtector - ok
23:34:42.0453 3908 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
23:34:42.0484 3908 MBAMService - ok
23:34:42.0500 3908 MBAMSwissArmy (0db7527db188c7d967a37bb51bbf3963) C:\WINDOWS1\system32\drivers\mbamswissarmy.sys
23:34:42.0515 3908 MBAMSwissArmy - ok
23:34:42.0546 3908 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS1\System32\msgsvc.dll
23:34:42.0718 3908 Messenger - ok
23:34:42.0750 3908 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS1\system32\drivers\mnmdd.sys
23:34:42.0875 3908 mnmdd - ok
23:34:42.0921 3908 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS1\system32\mnmsrvc.exe
23:34:43.0093 3908 mnmsrvc - ok
23:34:43.0125 3908 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS1\system32\drivers\Modem.sys
23:34:43.0312 3908 Modem - ok
23:34:43.0328 3908 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS1\system32\DRIVERS\mouclass.sys
23:34:43.0468 3908 Mouclass - ok
23:34:43.0500 3908 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS1\system32\DRIVERS\mouhid.sys
23:34:43.0671 3908 mouhid - ok
23:34:43.0703 3908 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS1\system32\drivers\MountMgr.sys
23:34:43.0875 3908 MountMgr - ok
23:34:43.0875 3908 mraid35x - ok
23:34:43.0906 3908 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS1\system32\DRIVERS\mrxdav.sys
23:34:44.0078 3908 MRxDAV - ok
23:34:44.0109 3908 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS1\system32\DRIVERS\mrxsmb.sys
23:34:44.0171 3908 MRxSmb - ok
23:34:44.0203 3908 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS1\system32\msdtc.exe
23:34:44.0328 3908 MSDTC - ok
23:34:44.0343 3908 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS1\system32\drivers\Msfs.sys
23:34:44.0484 3908 Msfs - ok
23:34:44.0484 3908 MSICPL - ok
23:34:44.0500 3908 MSIServer - ok
23:34:44.0531 3908 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS1\system32\drivers\MSKSSRV.sys
23:34:44.0671 3908 MSKSSRV - ok
23:34:44.0687 3908 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS1\system32\drivers\MSPCLOCK.sys
23:34:44.0828 3908 MSPCLOCK - ok
23:34:44.0828 3908 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS1\system32\drivers\MSPQM.sys
23:34:44.0984 3908 MSPQM - ok
23:34:45.0031 3908 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS1\system32\DRIVERS\mssmbios.sys
23:34:45.0171 3908 mssmbios - ok
23:34:45.0203 3908 ms_mpu401 (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS1\system32\drivers\msmpu401.sys
23:34:45.0343 3908 ms_mpu401 - ok
23:34:45.0375 3908 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS1\system32\DRIVERS\ASACPI.sys
23:34:45.0406 3908 MTsensor - ok
23:34:45.0437 3908 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS1\system32\drivers\Mup.sys
23:34:45.0500 3908 Mup - ok
23:34:45.0515 3908 n558 (88705dc61b9275b82e48904d53031f5b) C:\WINDOWS1\system32\Drivers\n558.sys
23:34:45.0562 3908 n558 - ok
23:34:45.0609 3908 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS1\System32\qagentrt.dll
23:34:45.0750 3908 napagent - ok
23:34:45.0796 3908 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS1\system32\drivers\NDIS.sys
23:34:45.0937 3908 NDIS - ok
23:34:45.0984 3908 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS1\system32\DRIVERS\ndistapi.sys
23:34:46.0015 3908 NdisTapi - ok
23:34:46.0031 3908 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS1\system32\DRIVERS\ndisuio.sys
23:34:46.0171 3908 Ndisuio - ok
23:34:46.0187 3908 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS1\system32\DRIVERS\ndiswan.sys
23:34:46.0343 3908 NdisWan - ok
23:34:46.0406 3908 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS1\system32\drivers\NDProxy.sys
23:34:46.0468 3908 NDProxy - ok
23:34:46.0484 3908 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS1\system32\DRIVERS\netbios.sys
23:34:46.0656 3908 NetBIOS - ok
23:34:46.0687 3908 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS1\system32\DRIVERS\netbt.sys
23:34:46.0828 3908 NetBT - ok
23:34:46.0859 3908 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS1\system32\netdde.exe
23:34:47.0031 3908 NetDDE - ok
23:34:47.0046 3908 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS1\system32\netdde.exe
23:34:47.0187 3908 NetDDEdsdm - ok
23:34:47.0218 3908 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS1\system32\lsass.exe
23:34:47.0359 3908 Netlogon - ok
23:34:47.0406 3908 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS1\System32\netman.dll
23:34:47.0562 3908 Netman - ok
23:34:47.0640 3908 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) C:\WINDOWS1\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
23:34:47.0671 3908 NetTcpPortSharing - ok
23:34:47.0703 3908 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS1\System32\mswsock.dll
23:34:47.0750 3908 Nla - ok
23:34:47.0765 3908 nmwcd (b0a67de1a128389aea4d42c5a56215fd) C:\WINDOWS1\system32\drivers\ccdcmb.sys
23:34:48.0109 3908 nmwcd - ok
23:34:48.0156 3908 nmwcdc (025c54f9f8c8bc1894ea38529c742c54) C:\WINDOWS1\system32\drivers\ccdcmbo.sys
23:34:48.0250 3908 nmwcdc - ok
23:34:48.0281 3908 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS1\system32\drivers\Npfs.sys
23:34:48.0437 3908 Npfs - ok
23:34:48.0515 3908 nSvcIp (cf0fa7f8366002692bf7e46805f531b9) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
23:34:48.0515 3908 nSvcIp ( UnsignedFile.Multi.Generic ) - warning
23:34:48.0515 3908 nSvcIp - detected UnsignedFile.Multi.Generic (1)
23:34:48.0546 3908 nSvcLog (ace9c161b76c066288a17fea4bb7bffc) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
23:34:48.0562 3908 nSvcLog ( UnsignedFile.Multi.Generic ) - warning
23:34:48.0562 3908 nSvcLog - detected UnsignedFile.Multi.Generic (1)
23:34:48.0562 3908 NTACCESS - ok
23:34:48.0609 3908 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS1\system32\drivers\Ntfs.sys
23:34:48.0796 3908 Ntfs - ok
23:34:48.0812 3908 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS1\system32\lsass.exe
23:34:48.0953 3908 NtLmSsp - ok
23:34:49.0015 3908 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS1\system32\ntmssvc.dll
23:34:49.0187 3908 NtmsSvc - ok
23:34:49.0218 3908 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS1\system32\drivers\Null.sys
23:34:49.0390 3908 Null - ok
23:34:49.0703 3908 nv (7b5a17bd54bb9142843dbe99a1caaed8) C:\WINDOWS1\system32\DRIVERS\nv4_mini.sys
23:34:50.0500 3908 nv - ok
23:34:50.0609 3908 nvata (dce353985c988bfb7e84fd942068151f) C:\WINDOWS1\system32\DRIVERS\nvata.sys
23:34:50.0640 3908 nvata - ok
23:34:50.0671 3908 NVENETFD (7d275ecda4628318912f6c945d5cf963) C:\WINDOWS1\system32\DRIVERS\NVENETFD.sys
23:34:50.0718 3908 NVENETFD - ok
23:34:50.0734 3908 NVHDA (fb61db41abb47ff893a35dca09628d12) C:\WINDOWS1\system32\drivers\nvhda32.sys
23:34:50.0781 3908 NVHDA - ok
23:34:50.0812 3908 nvnetbus (b64aacefad2be5bff5353fe681253c67) C:\WINDOWS1\system32\DRIVERS\nvnetbus.sys
23:34:50.0875 3908 nvnetbus - ok
23:34:50.0921 3908 NVSvc (5150b108ea88831e1c599603d8b89621) C:\WINDOWS1\system32\nvsvc32.exe
23:34:50.0937 3908 NVSvc - ok
23:34:51.0093 3908 nvUpdatusService (83e8ab7bb3c8956c53fec071c94f0bbb) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
23:34:51.0156 3908 nvUpdatusService - ok
23:34:51.0250 3908 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS1\system32\DRIVERS\nwlnkflt.sys
23:34:51.0406 3908 NwlnkFlt - ok
23:34:51.0437 3908 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS1\system32\DRIVERS\nwlnkfwd.sys
23:34:51.0609 3908 NwlnkFwd - ok
23:34:51.0703 3908 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
23:34:51.0734 3908 odserv - ok
23:34:51.0781 3908 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:34:51.0812 3908 ose - ok
23:34:51.0843 3908 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS1\system32\DRIVERS\parport.sys
23:34:52.0078 3908 Parport - ok
23:34:52.0109 3908 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS1\system32\drivers\PartMgr.sys
23:34:52.0265 3908 PartMgr - ok
23:34:52.0296 3908 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS1\system32\drivers\ParVdm.sys
23:34:52.0437 3908 ParVdm - ok
23:34:52.0468 3908 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS1\system32\DRIVERS\pci.sys
23:34:52.0656 3908 PCI - ok
23:34:52.0656 3908 PCIDump - ok
23:34:52.0671 3908 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS1\system32\DRIVERS\pciide.sys
23:34:52.0812 3908 PCIIde - ok
23:34:52.0953 3908 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS1\system32\drivers\Pcmcia.sys
23:34:53.0109 3908 Pcmcia - ok
23:34:53.0125 3908 PDCOMP - ok
23:34:53.0125 3908 PDFRAME - ok
23:34:53.0140 3908 PDRELI - ok
23:34:53.0140 3908 PDRFRAME - ok
23:34:53.0156 3908 perc2 - ok
23:34:53.0171 3908 perc2hib - ok
23:34:53.0218 3908 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS1\system32\services.exe
23:34:53.0234 3908 PlugPlay - ok
23:34:53.0265 3908 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS1\system32\lsass.exe
23:34:53.0406 3908 PolicyAgent - ok
23:34:53.0437 3908 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS1\system32\DRIVERS\raspptp.sys
23:34:53.0593 3908 PptpMiniport - ok
23:34:53.0640 3908 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS1\system32\DRIVERS\processr.sys
23:34:53.0796 3908 Processor - ok
23:34:53.0796 3908 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS1\system32\lsass.exe
23:34:53.0953 3908 ProtectedStorage - ok
23:34:54.0000 3908 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS1\system32\DRIVERS\psched.sys
23:34:54.0140 3908 PSched - ok
23:34:54.0171 3908 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS1\system32\DRIVERS\ptilink.sys
23:34:54.0328 3908 Ptilink - ok
23:34:54.0375 3908 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS1\system32\Drivers\PxHelp20.sys
23:34:54.0390 3908 PxHelp20 - ok
23:34:54.0390 3908 ql1080 - ok
23:34:54.0406 3908 Ql10wnt - ok
23:34:54.0406 3908 ql12160 - ok
23:34:54.0421 3908 ql1240 - ok
23:34:54.0437 3908 ql1280 - ok
23:34:54.0453 3908 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS1\system32\DRIVERS\rasacd.sys
23:34:54.0625 3908 RasAcd - ok
23:34:54.0656 3908 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS1\System32\rasauto.dll
23:34:54.0796 3908 RasAuto - ok
23:34:54.0828 3908 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS1\system32\DRIVERS\rasl2tp.sys
23:34:55.0031 3908 Rasl2tp - ok
23:34:55.0078 3908 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS1\System32\rasmans.dll
23:34:55.0218 3908 RasMan - ok
23:34:55.0265 3908 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS1\system32\DRIVERS\raspppoe.sys
23:34:55.0406 3908 RasPppoe - ok
23:34:55.0421 3908 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS1\system32\DRIVERS\raspti.sys
23:34:55.0546 3908 Raspti - ok
23:34:55.0593 3908 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS1\system32\DRIVERS\rdbss.sys
23:34:55.0750 3908 Rdbss - ok
23:34:55.0781 3908 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS1\system32\DRIVERS\RDPCDD.sys
23:34:55.0921 3908 RDPCDD - ok
23:34:55.0968 3908 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS1\system32\drivers\RDPWD.sys
23:34:56.0093 3908 RDPWD - ok
23:34:56.0125 3908 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS1\system32\sessmgr.exe
23:34:56.0296 3908 RDSessMgr - ok
23:34:56.0328 3908 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS1\system32\DRIVERS\redbook.sys
23:34:56.0484 3908 redbook - ok
23:34:56.0515 3908 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS1\System32\mprdim.dll
23:34:56.0656 3908 RemoteAccess - ok
23:34:56.0687 3908 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS1\system32\DRIVERS\rfcomm.sys
23:34:56.0843 3908 RFCOMM - ok
23:34:56.0921 3908 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS1\system32\locator.exe
23:34:57.0078 3908 RpcLocator - ok
23:34:57.0125 3908 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS1\System32\rpcss.dll
23:34:57.0187 3908 RpcSs - ok
23:34:57.0218 3908 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS1\system32\rsvp.exe
23:34:57.0375 3908 RSVP - ok
23:34:57.0406 3908 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS1\system32\lsass.exe
23:34:57.0531 3908 SamSs - ok
23:34:57.0625 3908 SASDIFSV - ok
23:34:57.0640 3908 SASKUTIL - ok
23:34:57.0671 3908 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS1\System32\SCardSvr.exe
23:34:57.0812 3908 SCardSvr - ok
23:34:57.0906 3908 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS1\system32\schedsvc.dll
23:34:58.0031 3908 Schedule - ok
23:34:58.0062 3908 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS1\system32\DRIVERS\secdrv.sys
23:34:58.0171 3908 Secdrv - ok
23:34:58.0203 3908 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS1\System32\seclogon.dll
23:34:58.0328 3908 seclogon - ok
23:34:58.0343 3908 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS1\system32\sens.dll
23:34:58.0500 3908 SENS - ok
23:34:58.0515 3908 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS1\system32\DRIVERS\serenum.sys
23:34:58.0656 3908 serenum - ok
23:34:58.0671 3908 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS1\system32\DRIVERS\serial.sys
23:34:58.0812 3908 Serial - ok
23:34:58.0843 3908 SetupNTGLM7X - ok
23:34:58.0843 3908 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS1\system32\drivers\Sfloppy.sys
23:34:58.0984 3908 Sfloppy - ok
23:34:59.0015 3908 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS1\System32\ipnathlp.dll
23:34:59.0187 3908 SharedAccess - ok
23:34:59.0250 3908 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS1\System32\shsvcs.dll
23:34:59.0296 3908 ShellHWDetection - ok
23:34:59.0312 3908 Simbad - ok
23:34:59.0328 3908 Sparrow - ok
23:34:59.0359 3908 speccy (f7b5efca3bdc48dbe9aacb9482c1c21c) C:\DOCUME~1\peter1\LOCALS~1\Temp\d38d48ec-105e-486a-a3c5-339c3df6699f
23:34:59.0375 3908 speccy ( UnsignedFile.Multi.Generic ) - warning
23:34:59.0375 3908 speccy - detected UnsignedFile.Multi.Generic (1)
23:34:59.0453 3908 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS1\system32\drivers\splitter.sys
23:34:59.0578 3908 splitter - ok
23:34:59.0609 3908 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS1\system32\spoolsv.exe
23:34:59.0656 3908 Spooler - ok
23:34:59.0687 3908 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS1\system32\DRIVERS\sr.sys
23:34:59.0750 3908 sr - ok
23:34:59.0796 3908 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS1\system32\srsvc.dll
23:34:59.0859 3908 srservice - ok
23:34:59.0906 3908 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS1\system32\DRIVERS\srv.sys
23:34:59.0968 3908 Srv - ok
23:35:00.0000 3908 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS1\System32\ssdpsrv.dll
23:35:00.0046 3908 SSDPSRV - ok
23:35:00.0078 3908 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS1\system32\wiaservc.dll
23:35:00.0234 3908 stisvc - ok
23:35:00.0281 3908 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS1\system32\DRIVERS\swenum.sys
23:35:00.0437 3908 swenum - ok
23:35:00.0453 3908 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS1\system32\drivers\swmidi.sys
23:35:00.0578 3908 swmidi - ok
23:35:00.0593 3908 SwPrv - ok
23:35:00.0593 3908 symc810 - ok
23:35:00.0609 3908 symc8xx - ok
23:35:00.0625 3908 sym_hi - ok
23:35:00.0625 3908 sym_u3 - ok
23:35:00.0671 3908 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS1\system32\drivers\sysaudio.sys
23:35:00.0812 3908 sysaudio - ok
23:35:00.0843 3908 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS1\system32\smlogsvc.exe
23:35:01.0015 3908 SysmonLog - ok
23:35:01.0031 3908 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS1\System32\tapisrv.dll
23:35:01.0203 3908 TapiSrv - ok
23:35:01.0265 3908 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS1\system32\DRIVERS\tcpip.sys
23:35:01.0312 3908 Tcpip - ok
23:35:01.0328 3908 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS1\system32\drivers\TDPIPE.sys
23:35:01.0484 3908 TDPIPE - ok
23:35:01.0515 3908 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS1\system32\drivers\TDTCP.sys
23:35:01.0687 3908 TDTCP - ok
23:35:01.0734 3908 TermDD (88155247177638048422893737429d9e) C:\WINDOWS1\system32\DRIVERS\termdd.sys
23:35:01.0890 3908 TermDD - ok
23:35:01.0921 3908 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS1\System32\termsrv.dll
23:35:02.0078 3908 TermService - ok
23:35:02.0125 3908 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS1\System32\shsvcs.dll
23:35:02.0140 3908 Themes - ok
23:35:02.0156 3908 TosIde - ok
23:35:02.0187 3908 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS1\system32\trkwks.dll
23:35:02.0343 3908 TrkWks - ok
23:35:02.0359 3908 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS1\system32\drivers\Udfs.sys
23:35:02.0515 3908 Udfs - ok
23:35:02.0546 3908 ultra - ok
23:35:02.0578 3908 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS1\system32\DRIVERS\update.sys
23:35:02.0765 3908 Update - ok
23:35:02.0796 3908 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS1\System32\upnphost.dll
23:35:02.0890 3908 upnphost - ok
23:35:02.0921 3908 upperdev (78b74af8727a28c128e164e9b53a5413) C:\WINDOWS1\system32\DRIVERS\usbser_lowerflt.sys
23:35:02.0984 3908 upperdev - ok
23:35:03.0046 3908 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS1\System32\ups.exe
23:35:03.0156 3908 UPS - ok
23:35:03.0187 3908 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS1\system32\DRIVERS\usbccgp.sys
23:35:03.0406 3908 usbccgp - ok
23:35:03.0453 3908 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS1\system32\DRIVERS\usbehci.sys
23:35:03.0609 3908 usbehci - ok
23:35:03.0640 3908 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS1\system32\DRIVERS\usbhub.sys
23:35:03.0781 3908 usbhub - ok
23:35:03.0796 3908 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS1\system32\DRIVERS\usbohci.sys
23:35:03.0953 3908 usbohci - ok
23:35:03.0984 3908 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS1\system32\DRIVERS\usbprint.sys
23:35:04.0156 3908 usbprint - ok
23:35:04.0187 3908 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS1\system32\DRIVERS\usbscan.sys
23:35:04.0343 3908 usbscan - ok
23:35:04.0375 3908 UsbserFilt (4f8fbc51a1c0a17310846b417a447f91) C:\WINDOWS1\system32\DRIVERS\usbser_lowerfltj.sys
23:35:04.0453 3908 UsbserFilt - ok
23:35:04.0468 3908 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS1\system32\DRIVERS\USBSTOR.SYS
23:35:04.0625 3908 USBSTOR - ok
23:35:04.0656 3908 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS1\system32\DRIVERS\usb8023x.sys
23:35:04.0812 3908 usb_rndisx - ok
23:35:04.0859 3908 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS1\System32\drivers\vga.sys
23:35:05.0015 3908 VgaSave - ok
23:35:05.0015 3908 ViaIde - ok
23:35:05.0062 3908 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS1\system32\drivers\VolSnap.sys
23:35:05.0203 3908 VolSnap - ok
23:35:05.0281 3908 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS1\System32\vssvc.exe
23:35:05.0359 3908 VSS - ok
23:35:05.0390 3908 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS1\system32\w32time.dll
23:35:05.0515 3908 W32Time - ok
23:35:05.0546 3908 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS1\system32\DRIVERS\wanarp.sys
23:35:05.0687 3908 Wanarp - ok
23:35:05.0718 3908 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS1\system32\Drivers\wdf01000.sys
23:35:05.0765 3908 Wdf01000 - ok
23:35:05.0765 3908 WDICA - ok
23:35:05.0781 3908 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS1\system32\drivers\wdmaud.sys
23:35:05.0937 3908 wdmaud - ok
23:35:05.0968 3908 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS1\System32\webclnt.dll
23:35:06.0125 3908 WebClient - ok
23:35:06.0171 3908 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS1\system32\wbem\WMIsvc.dll
23:35:06.0343 3908 winmgmt - ok
23:35:06.0406 3908 WinRM (18f347402da544a780949b8fdf83351b) C:\WINDOWS1\system32\WsmSvc.dll
23:35:06.0515 3908 WinRM - ok
23:35:06.0578 3908 WinUSB (fd600b032e741eb6aab509fc630f7c42) C:\WINDOWS1\system32\DRIVERS\WinUSB.sys
23:35:06.0609 3908 WinUSB - ok
23:35:06.0640 3908 WmdmPmSN (051b1bdecd6dee18c771b5d5ec7f044d) C:\WINDOWS1\system32\MsPMSNSv.dll
23:35:06.0687 3908 WmdmPmSN - ok
23:35:06.0718 3908 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS1\system32\wbem\wmiapsrv.exe
23:35:06.0875 3908 WmiApSrv - ok
23:35:06.0953 3908 WMPNetworkSvc (6bab4dc65515a098505f8b3d01fb6fe5) C:\Program Files\Windows Media Player\WMPNetwk.exe
23:35:07.0031 3908 WMPNetworkSvc - ok
23:35:07.0062 3908 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS1\system32\DRIVERS\wpdusb.sys
23:35:07.0093 3908 WpdUsb - ok
23:35:07.0203 3908 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\WINDOWS1\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
23:35:07.0328 3908 WPFFontCache_v0400 - ok
23:35:07.0359 3908 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS1\System32\drivers\ws2ifsl.sys
23:35:07.0500 3908 WS2IFSL - ok
23:35:07.0531 3908 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS1\system32\wscsvc.dll
23:35:07.0671 3908 wscsvc - ok
23:35:07.0671 3908 WSearch - ok
23:35:07.0703 3908 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS1\system32\wuauserv.dll
23:35:07.0843 3908 wuauserv - ok
23:35:07.0875 3908 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS1\system32\DRIVERS\WudfPf.sys
23:35:07.0921 3908 WudfPf - ok
23:35:07.0937 3908 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS1\system32\DRIVERS\wudfrd.sys
23:35:07.0968 3908 WudfRd - ok
23:35:08.0000 3908 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS1\System32\WUDFSvc.dll
23:35:08.0031 3908 WudfSvc - ok
23:35:08.0093 3908 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS1\System32\wzcsvc.dll
23:35:08.0265 3908 WZCSVC - ok
23:35:08.0296 3908 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS1\System32\xmlprov.dll
23:35:08.0437 3908 xmlprov - ok
23:35:08.0468 3908 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
23:35:08.0875 3908 \Device\Harddisk0\DR0 - ok
23:35:08.0890 3908 Boot (0x1200) (705a4e2e16148086fae4cfc912379907) \Device\Harddisk0\DR0\Partition0
23:35:08.0890 3908 \Device\Harddisk0\DR0\Partition0 - ok
23:35:08.0890 3908 Boot (0x1200) (ad859a7781354f2716112a44662bfd8e) \Device\Harddisk0\DR0\Partition1
23:35:08.0906 3908 \Device\Harddisk0\DR0\Partition1 - ok
23:35:08.0906 3908 ============================================================
23:35:08.0906 3908 Scan finished
23:35:08.0906 3908 ============================================================
23:35:09.0031 3884 Detected object count: 6
23:35:09.0031 3884 Actual detected object count: 6
23:35:28.0359 3884 ForceWare Intelligent Application Manager (IAM) ( UnsignedFile.Multi.Generic ) - skipped by user
23:35:28.0359 3884 ForceWare Intelligent Application Manager (IAM) ( UnsignedFile.Multi.Generic ) - User select action: Skip
23:35:28.0359 3884 ForcewareWebInterface ( UnsignedFile.Multi.Generic ) - skipped by user
23:35:28.0359 3884 ForcewareWebInterface ( UnsignedFile.Multi.Generic ) - User select action: Skip
23:35:28.0390 3884 hwdatacard ( UnsignedFile.Multi.Generic ) - skipped by user
23:35:28.0390 3884 hwdatacard ( UnsignedFile.Multi.Generic ) - User select action: Skip
23:35:28.0390 3884 nSvcIp ( UnsignedFile.Multi.Generic ) - skipped by user
23:35:28.0390 3884 nSvcIp ( UnsignedFile.Multi.Generic ) - User select action: Skip
23:35:28.0390 3884 nSvcLog ( UnsignedFile.Multi.Generic ) - skipped by user
23:35:28.0390 3884 nSvcLog ( UnsignedFile.Multi.Generic ) - User select action: Skip
23:35:28.0421 3884 speccy ( UnsignedFile.Multi.Generic ) - skipped by user
23:35:28.0421 3884 speccy ( UnsignedFile.Multi.Generic ) - User select action: Skip

Re: Kontrola logu-8 infiltrácií

Napsal: 07 srp 2012 22:41
od Royksopp
RogueKiller

RogueKiller V7.6.5 [08/03/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operačný systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spustené v : Normálny režim
Užívateľ: peter1 [Práva Správcu]
Režim: Kontrola -- Dátum: 08/07/2012 23:39:39

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrov: 4 ¤¤¤
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Zvláštne súbory / Adresáre: ¤¤¤

¤¤¤ Ovládač: [NAHRATÉ] ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Súbor HOSTS: ¤¤¤
ÿþ1

¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: Maxtor 6V200E0 +++++
--- User ---
[MBR] c2d2335f137be7d1d6a91f2fcac9d434
[BSP] 197f119e8eeb35037e2e868e7a704b56 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 51222 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 104904450 | Size: 143243 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončené : << RKreport[1].txt >>
RKreport[1].txt

Re: Kontrola logu-8 infiltrácií

Napsal: 08 srp 2012 07:48
od vyosek
:arrow: Spustte znovu RogueKiller
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost Prohledat a pote Smazat a nasledne Zprava - otevre se log, ten sem vlozte
  • Pak kliknete na Oprava Host a Zprava - otevre se log, ten sem vlozte