Stránka 1 z 2

Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 20:49
od puschpull
Zdravím
Dnes jsem zjistil, že
Microsoft Security Essentials: Ochrana v reálném čase nelze zapnout
Ikonka svítí červeně
Nelze zapnout ochranu v reálném čase
Nepomohl restart ani odinstalace a opětovná instalace programu.
Do včerejška bylo vše v pořádku
Mám podezření zda jsem nechytnul nějaký vir

Mám W7 Ultimate CZ 32-bit

Nemáte někde, prosím, nějaký nápad?
Děkuji

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 20:53
od vyosek
Zdravim :)

:arrow: Jelikoz nevime o Vasem PC nic a z kristalove koule se spatne vesti (i kdyz jsem ji ted od kolegu na srazu dostal), navic v noci neni nic videt :o

:arrow: Ale dosti legracek, kouknem na to :wink: Stahnete RSIT http://forum.viry.cz/viewtopic.php?f=24&t=81939 a dejte log z nej - navod Vas povede...

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 20:58
od puschpull
Jasně už jsem koukal, že bude žádán log
zde je:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Petr at 2012-08-29 21:53:09
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 61 GB (10%) free of 610 GB
Total RAM: 3327 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:53:46, on 29.8.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe
C:\Program Files\ASUS\Drive Xpert\DriveXpert.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\ASUS Xonar Essence STX Audio\Customapp\ASUSAUDIOCENTER.EXE
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\dev\prog\apache2\bin\ApacheMonitor.exe
C:\Program Files\Process Explorer\procexp.exe
C:\Program Files\RealTemp\RealTemp.exe
C:\Program Files\XericDesign\EarthDesk\earthdesk.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Windows\system\HsMgr.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Petr\Downloads\RSIT.exe
C:\Program Files\trend micro\Petr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/?pc=AVBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pravednes.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O1 - Hosts: 82.208.39.97 www.smsbrana.net
O1 - Hosts: 213.61.92.195 support.asus.com
O1 - Hosts: 213.61.92.195 support.asus.com
O1 - Hosts: 95.168.196.41 puschpull.org
O1 - Hosts: 80.67.28.94 www.blockout.de
O1 - Hosts: 217.31.49.88 www.clipboard.cz
O1 - Hosts: 88.86.109.225 dawep.net
O1 - Hosts: 85.112.114.203 driverscollection.com
O1 - Hosts: 208.79.236.24 tools.dynamicdrive.com
O1 - Hosts: 89.190.64.18 www.expos.cz
O1 - Hosts: 81.2.194.80 flop.petrh.org
O1 - Hosts: 81.2.194.80 petrh.org
O1 - Hosts: 65.41.230.24 www.html-kit.com
O1 - Hosts: 81.2.194.80 petrh.org
O1 - Hosts: 217.198.114.135 www.labo.cz
O1 - Hosts: 208.88.224.199 www.giveawayoftheday.com
O1 - Hosts: 74.125.87.113 translate.google.cz
O1 - Hosts: 194.187.177.29 digi-cz.happy-foto.com
O1 - Hosts: 74.125.87.191 hp7-deathlyhallows.blogspot.com
O1 - Hosts: 217.198.114.232 www.helloreality.cz
O1 - Hosts: 74.125.87.191 hp7cz.blogspot.com
O1 - Hosts: 88.86.103.242 free-energy.webpark.cz
O1 - Hosts: 195.146.100.18 home.tiscali.cz
O1 - Hosts: 205.188.251.118 www.icq.com
O1 - Hosts: 85.214.157.79 www.moviemaze.de
O1 - Hosts: 90.183.38.63 mujweb.atlas.cz
O1 - Hosts: 72.32.149.14 www.lavasoft.com
O1 - Hosts: 208.109.14.78 lightroompresets.com
O1 - Hosts: fe80::65ad:5850:fae4:bfde%13
O1 - Hosts: 77.75.76.10 www.mapy.cz
O1 - Hosts: 69.73.166.124 www.nirsoft.net
O1 - Hosts: 93.185.104.29 p-veronesi.com
O1 - Hosts: 88.86.109.131 pas.idif.cz
O1 - Hosts: 209.147.121.98 www.rage3d.com
O1 - Hosts: fe80::65ad:5850:fae4:bfde%13
O1 - Hosts: 217.198.115.20 www.adriadatabanka.com
O1 - Hosts: 69.17.117.207 www.speedtest.net
O1 - Hosts: 89.185.233.244 www.serm-most.websnadno.cz
O1 - Hosts: 90.183.38.63 prepni.atlas.cz
O1 - Hosts: 194.79.52.194 technet.idnes.cz
O1 - Hosts: 69.163.177.221 www.shoecakegames.com
O1 - Hosts: 69.163.177.221 www.shoecakegames.com
O1 - Hosts: 87.236.199.112 www.forum.warez-svet.net
O1 - Hosts: 94.199.40.244 www.mvcr.cz
O1 - Hosts: 93.185.104.30 puschpull.net
O1 - Hosts: 95.168.196.41 puschpull.org
O1 - Hosts: 89.185.231.21 kucharka.jhg.cz
O1 - Hosts: 69.8.125.95 links.epanorama.net
O1 - Hosts: 69.8.125.95 links.epanorama.net
O1 - Hosts: 87.236.198.68 www.audiopro.cz
O1 - Hosts: 82.165.75.233 www.thel-audioworld.de
O1 - Hosts: 209.17.170.127 www.rmbsoft.com
O1 - Hosts: 207.155.252.219 www.tripath.com
O1 - Hosts: 81.95.96.24 gesto.servery.cz
O1 - Hosts: 219.232.243.206 www.9down.com
O1 - Hosts: 91.194.96.4 avicodec.duby.info
O1 - Hosts: 208.76.82.32 www.fourcc.org
O1 - Hosts: 188.40.70.45 darkav.de.vu
O1 - Hosts: 81.0.254.182 www.subtitles.cz
O1 - Hosts: 88.86.120.26 www.sweb.cz
O1 - Hosts: 174.46.224.54 www.divx.com
O1 - Hosts: 85.230.118.163 forum.doom9.org
O1 - Hosts: 188.40.70.45 www.doom9.de.vu
O1 - Hosts: 69.163.193.162 javimoya.com
O1 - Hosts: 88.86.113.143 screw.wz.cz
O1 - Hosts: 217.195.177.10 dspguru.notrace.dk
O1 - Hosts: 74.55.37.231 www.digital-digest.com
O1 - Hosts: 74.54.20.98 www.dvdrhelp.com
O1 - Hosts: 216.92.113.68 www.manifest-tech.com
O1 - Hosts: 86.65.123.103 perso.club-internet.fr
O1 - Hosts: 217.67.30.4 www.dvdspace.sk
O1 - Hosts: 88.86.113.4 cutka.szm.sk
O1 - Hosts: 212.20.96.20 www.volny.cz
O1 - Hosts: 216.194.70.22 kilg0r3.cjb.net
O1 - Hosts: 64.152.34.204 go.to
O1 - Hosts: 74.55.37.231 nickyguides.digital-digest.com
O1 - Hosts: 213.172.16.20 dvdsoft.da.ru
O1 - Hosts: 66.98.145.18 www.riphelp.com
O1 - Hosts: 88.86.113.143 screw.wz.cz
O1 - Hosts: 88.86.113.143 screw.wz.cz
O1 - Hosts: 208.73.210.27 ace.subpage.net
O1 - Hosts: 208.73.210.27 tobias.everwicked.com
O1 - Hosts: 212.20.96.20 www.volny.cz
O1 - Hosts: 212.20.96.20 www.volny.cz
O1 - Hosts: 88.86.113.143 www.subtitles.wz.cz
O1 - Hosts: 202.146.209.16 www.palowireless.com
O1 - Hosts: 81.2.194.75 www.obalycd.cz
O1 - Hosts: 217.70.184.38 www.absolutecover.com
O1 - Hosts: 64.95.64.198 www.cdcovercentral.com
O1 - Hosts: 78.159.102.123 www.cdcovers.cc
O1 - Hosts: 212.69.172.113 www.cover-world.de
O1 - Hosts: 84.16.243.35 covertarget.com
O1 - Hosts: 84.16.243.35 covertarget.com
O1 - Hosts: 88.198.55.175 www.coveruniverse.com
O1 - Hosts: 81.2.194.136 www.kfilmu.net
O1 - Hosts: 81.2.194.136 www.kfilmu.net
O1 - Hosts: 65.60.35.26 ww2.mega-search.net
O1 - Hosts: 72.20.40.25 www.coversite.com
O1 - Hosts: 81.2.194.75 basne.cz
O1 - Hosts: 82.99.173.175 www.svethardware.cz
O1 - Hosts: 63.251.51.15 www.cddb.com
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Drive Xpert] C:\Program Files\ASUS\Drive Xpert\DriveXpert.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe" /LaunchType=Auto /LaunchApps=Common
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Cmaudio8788] RunDll32 cmicnfgp.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: EarthDesk.lnk = C:\Program Files\XericDesign\EarthDesk\earthdesk.exe
O4 - Startup: Translate Client.lnk = C:\Program Files\Translate Client\translateclient.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\dev\prog\apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Process Explorer.lnk = C:\Program Files\Process Explorer\procexp.exe
O4 - Global Startup: RealTemp.lnk = C:\Program Files\RealTemp\RealTemp.exe
O4 - Global Startup: Translate Client.lnk = C:\Program Files\Translate Client\translateclient.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: IEB: Browser: Resize Window - C:\Program Files\IE Booster\window-size.html
O8 - Extra context menu item: IEB: Frame: Open in &New Window - C:\Program Files\IE Booster\frame-open-in-new-window.html
O8 - Extra context menu item: IEB: Frame: Open in &This Window - C:\Program Files\IE Booster\frame-open-in-this-window.html
O8 - Extra context menu item: IEB: Image: Copy Path to Clipboard - C:\Program Files\IE Booster\image-copy-path-to-clipboard.html
O8 - Extra context menu item: IEB: Image: Show Image Data - C:\Program Files\IE Booster\image-view-image-data.html
O8 - Extra context menu item: IEB: Image: Show Server Response - C:\Program Files\IE Booster\link-show-server-response.html
O8 - Extra context menu item: IEB: Link: Copy as <A href="URL">caption</A> - C:\Program Files\IE Booster\link-copy.html
O8 - Extra context menu item: IEB: Link: Open in New Minimized Window - C:\Program Files\IE Booster\link-open-minimized.html
O8 - Extra context menu item: IEB: Link: Show Server Response - C:\Program Files\IE Booster\link-show-server-response.html
O8 - Extra context menu item: IEB: Page: Copy Title as <A href="URL">Title</a> - C:\Program Files\IE Booster\page-copy-title.html
O8 - Extra context menu item: IEB: Page: Show Forms and Applets - C:\Program Files\IE Booster\page-show-forms.html
O8 - Extra context menu item: IEB: Page: Show Hyperlinks - C:\Program Files\IE Booster\page-view-hyperlinks.html
O8 - Extra context menu item: IEB: Page: Show Images - C:\Program Files\IE Booster\page-show-images.html
O8 - Extra context menu item: IEB: Page: Show Source - C:\Program Files\IE Booster\page-view-source.html
O8 - Extra context menu item: IEB: Page: Show Stylesheets - C:\Program Files\IE Booster\page-view-stylesheets.html
O8 - Extra context menu item: IEB: Page: Show TABLE, FORM and DIV Borders - C:\Program Files\IE Booster\page-show-table-structure.htm
O8 - Extra context menu item: IEB: Selection: Copy as plain text - C:\Program Files\IE Booster\selection-copy-plaintext.html
O8 - Extra context menu item: IEB: Selection: Open in Browser - C:\Program Files\IE Booster\selection-open-in-browser.html
O8 - Extra context menu item: IEB: Selection: Show Partial Source - C:\Program Files\IE Booster\selection-show-source.html
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files\Free Download Manager\dlall.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {5C519EC4-2BAE-44CE-B7F5-AD0CCD4BEFBD} (mpeg4 ActiveX Plugin v2) - http://www.starvedia.com/ActiveX/axmpeg4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: 57xx SteelVine (57xx SteelVine Manager) - Unknown owner - C:\Program Files\ASUS\Drive Xpert\SteelVine.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\dev\prog\apache2\bin\httpd.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\Windows\system32\astsrv.exe
O23 - Service: Cobian Backup 10 Volume Shadow Copy service (cbVSCService) - CobianSoft, Luis Cobian - C:\Program Files\Cobian Backup 10\cbVSCService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MySQL5 - Unknown owner - C:\dev\prog\mysql5\bin\mysqld-nt (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\nlssrv32.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Windows\system32\NMSAccessU.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: syshost32 - Unknown owner - C:\Windows\Installer\{D80B0951-7567-9612-91D7-EC4071B11972}\syshost.exe (file missing)

--
End of file - 17823 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GlaryInitialize.job
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2787196091-3245655353-2099626037-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2787196091-3245655353-2099626037-1001UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\6ny88emk.puschpull

prefs.js - "browser.startup.homepage" - "http://pravednes.cz/#!@puschpull"
prefs.js - "keyword.URL" - "http://www.gigabase.ru/search?clid=1&q="

"{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}"=C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.5.1]
"Description"=
"Path"=C:\Windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=14]
"Description"=Google Updater
"Path"=C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448]
"Description"=6.0.12.448
"Path"=C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@research.microsoft.com/HDView]
"Description"=Microsoft Research HD View
"Path"=C:\Program Files\Microsoft Research\HD View\nphdview.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsJSRealPlayerPlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npContribute.dll
nppdf32.dll
nppl3260.dll
nprpjplug.dll
npwachk.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\6ny88emk.puschpull\extensions\
{c75a27d8-4529-449f-b67b-aba65d7a1c0a}

C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\6ny88emk.puschpull\searchplugins\
askcom.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27 164312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-07-05 453544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2011-09-10 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-05-04 1519272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-07-05 157616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27 164312]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-05-04 1519272]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Drive Xpert"=C:\Program Files\ASUS\Drive Xpert\DriveXpert.exe [2009-02-02 10231808]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-09-25 98304]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2009-06-01 1468296]
"StartupDelayer"=C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe [2011-07-29 1068032]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"Cmaudio8788"=RunDll32 cmicnfgp.cpl,CMICtrlWnd []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2012-05-04 1561768]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 931200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"Google Update"=C:\Users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-30 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe -launchedbylogin []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0ENQBO]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FPVProTrialInfo]
C:\Program Files\FastPictureViewer\FPVTrialInfo.exe [2011-12-12 328936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-30 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [2012-01-20 719672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
C:\Program Files\Sandboxie\SbieCtrl.exe [2010-10-18 404200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
C:\Users\Petr\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [2011-12-25 79872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [2009-05-18 3866624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-06-05 1310720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk]
C:\PROGRA~1\MICROS~2\Office14\ONENOTEM.EXE [2011-09-02 227712]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Monitor Apache Servers.lnk - C:\dev\prog\apache2\bin\ApacheMonitor.exe
Process Explorer.lnk - C:\Program Files\Process Explorer\procexp.exe
RealTemp.lnk - C:\Program Files\RealTemp\RealTemp.exe
Translate Client.lnk - C:\Program Files\Translate Client\translateclient.exe

C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
EarthDesk.lnk - C:\Program Files\XericDesign\EarthDesk\earthdesk.exe
Translate Client.lnk - C:\Program Files\Translate Client\translateclient.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2009-05-12 233888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Users\Petr\Downloads\WhiteCap.Platinum.5.0.5.keygen.exe"="C:\Users\Petr\Downloads\WhiteCap.Platinum.5.0.5.keygen.exe:*:Enabled:WhiteCap.Platinum.5.0.5.keygen"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
"Debugger=""C:\PROGRAM FILES\PROCESS EXPLORER\PROCEXP.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"VIDC.ZMBV"=zmbv.dll
"vidc.xvid"=xvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit -
.js - open -

======List of files/folders created in the last 1 month======

2012-08-29 21:53:10 ----D---- C:\Program Files\trend micro
2012-08-29 21:53:09 ----D---- C:\rsit
2012-08-29 21:27:28 ----D---- C:\Program Files\Microsoft Security Client
2012-08-28 22:34:49 ----A---- C:\Windows\system32\drivers\ba8ea32614ef4adc.sys
2012-08-25 15:46:52 ----A---- C:\Windows\system32\mshtmled.dll
2012-08-25 15:46:52 ----A---- C:\Windows\system32\iertutil.dll
2012-08-25 15:46:51 ----A---- C:\Windows\system32\wininet.dll
2012-08-25 15:46:51 ----A---- C:\Windows\system32\jsproxy.dll
2012-08-25 15:46:51 ----A---- C:\Windows\system32\jscript.dll
2012-08-25 15:46:51 ----A---- C:\Windows\system32\ieUnatt.exe
2012-08-25 15:46:51 ----A---- C:\Windows\system32\ieui.dll
2012-08-25 15:46:50 ----A---- C:\Windows\system32\urlmon.dll
2012-08-25 15:46:50 ----A---- C:\Windows\system32\url.dll
2012-08-25 15:46:50 ----A---- C:\Windows\system32\jscript9.dll
2012-08-25 15:46:48 ----A---- C:\Windows\system32\mshtml.dll
2012-08-25 15:46:48 ----A---- C:\Windows\system32\ieframe.dll
2012-08-25 14:54:35 ----A---- C:\Windows\system32\srcore.dll
2012-08-25 14:54:34 ----A---- C:\Windows\system32\win32k.sys
2012-08-25 14:54:32 ----A---- C:\Windows\system32\win32spl.dll
2012-08-25 14:54:32 ----A---- C:\Windows\system32\spoolsv.exe
2012-08-25 14:54:30 ----A---- C:\Windows\system32\netapi32.dll
2012-08-25 14:54:30 ----A---- C:\Windows\system32\browser.dll
2012-08-25 14:54:30 ----A---- C:\Windows\system32\browcli.dll
2012-08-25 14:54:29 ----A---- C:\Windows\system32\localspl.dll
2012-07-31 22:27:24 ----D---- C:\Users\Petr\AppData\Roaming\XBMC
2012-07-31 22:26:01 ----D---- C:\Program Files\XBMC

======List of files/folders modified in the last 1 month======

2012-08-29 21:53:10 ----RD---- C:\Program Files
2012-08-29 21:52:42 ----D---- C:\Windows\Temp
2012-08-29 21:49:38 ----D---- C:\Users\Petr\AppData\Roaming\foobar2000
2012-08-29 21:27:39 ----SHD---- C:\Windows\Installer
2012-08-29 21:27:31 ----D---- C:\Windows\system32\drivers
2012-08-29 21:27:31 ----D---- C:\Windows\system32\catroot
2012-08-29 21:27:31 ----D---- C:\Windows\System32
2012-08-29 21:27:31 ----D---- C:\Windows\inf
2012-08-29 21:27:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-08-29 21:23:50 ----SHD---- C:\System Volume Information
2012-08-29 21:23:07 ----D---- C:\Users\Petr\AppData\Roaming\Smarty Uninstaller
2012-08-29 21:21:14 ----D---- C:\Users\Petr\AppData\Roaming\translateclient
2012-08-29 21:12:53 ----D---- C:\Windows\Prefetch
2012-08-29 20:55:31 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-08-28 23:12:03 ----D---- C:\Users\Petr\AppData\Roaming\EditPlus 3
2012-08-28 20:57:35 ----A---- C:\Windows\WTRAN32.INI
2012-08-28 20:57:05 ----AD---- C:\Windows
2012-08-28 19:16:21 ----D---- C:\Windows\system32\config
2012-08-28 19:02:35 ----D---- C:\Program Files\Mozilla Firefox
2012-08-26 22:14:50 ----D---- C:\Program Files\foobar2000
2012-08-26 09:29:08 ----D---- C:\Downloads
2012-08-26 08:21:19 ----D---- C:\ProgramData\Adobe
2012-08-26 08:20:51 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-08-26 00:28:22 ----A---- C:\Windows\NeroDigital.ini
2012-08-25 18:36:13 ----D---- C:\Program Files\EditPlus 3
2012-08-25 18:28:36 ----D---- C:\Program Files\jdownloader
2012-08-25 16:18:47 ----D---- C:\Program Files\Calibre2
2012-08-25 15:56:19 ----D---- C:\Windows\winsxs
2012-08-25 15:53:38 ----RSD---- C:\Windows\Fonts
2012-08-25 15:53:38 ----D---- C:\Windows\system32\migration
2012-08-25 15:53:38 ----D---- C:\Program Files\Internet Explorer
2012-08-25 15:53:37 ----D---- C:\Windows\system32\DriverStore
2012-08-25 15:49:26 ----A---- C:\Windows\system32\MRT.exe
2012-08-25 15:49:07 ----D---- C:\ProgramData\Microsoft Help
2012-08-25 15:47:04 ----D---- C:\Windows\system32\catroot2
2012-08-10 22:14:38 ----D---- C:\Users\Petr\AppData\Roaming\FileZilla
2012-08-10 20:20:42 ----D---- C:\Program Files\Avant Browser
2012-08-05 21:48:00 ----D---- C:\Windows\system32\Tasks
2012-08-03 16:30:06 ----D---- C:\Windows\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 ArcSec;archlp; C:\Windows\system32\drivers\ArcSec.sys [2010-09-21 192504]
R1 archlp;archlp; C:\Windows\system32\drivers\archlp.sys [2010-01-13 89728]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS [2011-09-22 21624]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2012-04-14 231760]
R2 cpuz132;cpuz132; \??\C:\Windows\system32\drivers\cpuz132_x32.sys [2009-03-27 12672]
R2 DefragFS;DefragFS; C:\Windows\system32\drivers\DefragFS.sys [2010-04-07 135184]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-09-30 104976]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-09-23 5161472]
R3 cmudaxp;ASUS Xonar Essence STX Audio Interface; C:\Windows\system32\drivers\cmudaxp.sys [2011-03-10 1760256]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point32k.sys [2009-06-01 30088]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2010-10-18 124648]
R3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files\RealTemp\WinRing0.sys [2008-07-26 14416]
S0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2012-03-20 171064]
S0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-11-17 691696]
S1 ehksazhi;ehksazhi; \??\C:\Windows\system32\drivers\ehksazhi.sys []
S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-06-05 380416]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 74112]
S3 PROCEXP151;PROCEXP151; \??\C:\Windows\system32\Drivers\PROCEXP151.SYS []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 57xx SteelVine Manager;57xx SteelVine; C:\Program Files\ASUS\Drive Xpert\SteelVine.exe [2009-02-02 1286144]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe [2011-05-28 353168]
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2009-06-05 90112]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-09-23 172032]
R2 Apache2.2;Apache2.2; C:\dev\prog\apache2\bin\httpd.exe [2008-12-10 24636]
R2 astcc;AST Service; C:\Windows\system32\astsrv.exe [2010-08-03 57344]
R2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service; C:\Program Files\Cobian Backup 10\cbVSCService.exe [2010-09-23 67584]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 11552]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
R2 MySQL5;MySQL5; C:\dev\prog\mysql5\bin\mysqld-nt --defaults-file=C:\dev\prog\mysql5\my.ini MySQL5 []
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\system32\nlssrv32.exe [2011-02-21 66560]
R2 NMSAccess;NMSAccess; C:\Windows\system32\NMSAccessU.exe [2009-01-12 71096]
R2 PDAgent;PDAgent; C:\Program Files\Raxco\PerfectDisk\PDAgent.exe [2010-04-12 1565960]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2010-10-18 75496]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R3 PDEngine;PDEngine; C:\Program Files\Raxco\PerfectDisk\PDEngine.exe [2010-04-12 1471752]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-10 136176]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-09-10 194104]
S2 syshost32;syshost32; C:\Windows\Installer\{D80B0951-7567-9612-91D7-EC4071B11972}\syshost.exe [2012-08-28 364032]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-10 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-08-28 114144]
S3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-03-26 214952]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-22 1343400]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]

-----------------EOF-----------------




prográmek se ale asi seknul, protože stále "běží" ale neposlouvá se dál (na cca 90%)
??

P.S.
tak už RSIT dojel, jen mu to trochu trvalo

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 21:06
od vyosek
:arrow: Odinstalujte Ask Toolbar

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 21:22
od puschpull
obsah Rkill.txt :

Rkill 2.3.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 08/29/2012 10:17:55 PM in x86 mode.
Windows Version: Windows 7 Ultimate Service Pack 1

Checking for Windows services to stop.

* No malware services found to stop.

Checking for processes to terminate.

* C:\Windows\system32\astsrv.exe (PID: 464) [WD-HEUR]
* C:\Windows\system32\IoctlSvc.exe (PID: 2496) [WD-HEUR]
* C:\Windows\system\HsMgr.exe (PID: 4900) [WD-HEUR]

3 proccesses terminated!

Checking Registry for malware related settings.

* taskmgr.exe debugger. [IFEO Debugger Deleted]

Backup Registry file created at:
C:\Users\Petr\Desktop\rkill\rkill-08-29-2012-10-17-59.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
* HKCU\SOFTWARE\Classes\.exe "@" exists and is set to exefile!
* HKCU\SOFTWARE\Classes\.exe has been deleted!
* HKCU\SOFTWARE\Classes\.bat "@" exists and is set to batfile!
* HKCU\SOFTWARE\Classes\.bat has been deleted!
* HKCU\SOFTWARE\Classes\.com "@" exists and is set to comfile!
* HKCU\SOFTWARE\Classes\.com has been deleted!

Performing miscellaneous checks.

* Windows Defender Disabled

[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware" = dword:00000001

Checking Windows Service Integrity:

* Windows Defender (WinDefend) is not Running.
Startup Type set to: Manual

Searching for Missing Digital Signatures:

* C:\Windows\System32\drivers\acpi.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\acpi.inf_x86_neutral_a1f4891fe0de4401\acpi.sys : 274 304 : 11/20/2010 01:29 PM : cea80c80bed809aa0da6febc04733349 [Pos Repl]
+-> C:\Windows\winsxs\x86_acpi.inf_31bf3856ad364e35_6.1.7600.16385_none_225f1a272f5b64b9\acpi.sys : 274 496 : 07/14/2009 00:26 AM : f0e07d144c8685b8774bc32fc8da4df0 [Pos Repl]
+-> C:\Windows\winsxs\x86_acpi.inf_31bf3856ad364e35_6.1.7601.17514_none_24902def2c49e853\acpi.sys : 274 304 : 11/20/2010 01:29 PM : cea80c80bed809aa0da6febc04733349 [Pos Repl]

* C:\Windows\System32\drivers\afd.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_d7be98b5bfc0b4c1\afd.sys : 338 944 : 07/14/2009 01:12 AM : ddc040fdb01ef1712a6b13e52afb104c [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16802_none_d81220b5bf827af7\afd.sys : 338 944 : 04/25/2011 01:35 AM : 0db7a48388d54d154ebec120461a0fcd [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_d864ad9ad8c98d1f\afd.sys : 338 944 : 04/25/2011 01:27 AM : c114ab7a1550d42ea1700ffd4179cf5a [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_d9efac7dbcaf385b\afd.sys : 338 944 : 11/20/2010 01:40 AM : 1151fd4fb0216cfed887bfde29ebd516 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_d9f97e05bca8003a\afd.sys : 338 944 : 04/25/2011 01:18 AM : 9ebbba55060f786f0fcaa3893bfa2806 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_da774a9ad5cea29e\afd.sys : 338 944 : 04/25/2011 01:24 AM : c427f91a748cd342a2b3f9278d9fd6a5 [Pos Repl]

* C:\Windows\System32\drivers\agp440.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys : 53 312 : 07/14/2009 01:26 AM : 507812c3054c21cef746b6ee3d04dd6e [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys : 53 312 : 07/14/2009 01:26 AM : 507812c3054c21cef746b6ee3d04dd6e [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys : 53 312 : 07/14/2009 01:26 AM : 507812c3054c21cef746b6ee3d04dd6e [Pos Repl]

* C:\Windows\System32\drivers\asyncmac.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase-asyncmac_31bf3856ad364e35_6.1.7600.16385_none_242e2506962cd3e0\asyncmac.sys : 17 920 : 07/14/2009 01:54 AM : add2ade1c2b285ab8378d2daaf991481 [Pos Repl]

* C:\Windows\System32\drivers\atapi.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys : 21 584 : 07/14/2009 01:26 AM : 338c86357871c167a96ab976519bf59e [Pos Repl]
+-> C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys : 21 584 : 07/14/2009 01:26 AM : 338c86357871c167a96ab976519bf59e [Pos Repl]
+-> C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys : 21 584 : 07/14/2009 01:26 AM : 338c86357871c167a96ab976519bf59e [Pos Repl]

* C:\Windows\System32\drivers\battc.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\battery.inf_x86_neutral_5752155055c5e2d7\battc.sys : 25 168 : 07/14/2009 01:26 AM : 2b8ee031fd700ab942ebe60665440e83 [Pos Repl]
+-> C:\Windows\winsxs\x86_battery.inf_31bf3856ad364e35_6.1.7600.16385_none_15fde90fb523bb21\battc.sys : 25 168 : 07/14/2009 01:26 AM : 2b8ee031fd700ab942ebe60665440e83 [Pos Repl]

* C:\Windows\System32\drivers\beep.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_c3f6f77668f0ddcc\beep.sys : 6 144 : 07/14/2009 01:45 AM : 505506526a9d467307b3c393dedaf858 [Pos Repl]

* C:\Windows\System32\drivers\bridge.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-networkbridge_31bf3856ad364e35_6.1.7600.16385_none_07c046fe67692e98\bridge.sys : 78 336 : 07/14/2009 01:41 AM : 77361d72a04f18809d0efb6cceb74d4b [Pos Repl]

* C:\Windows\System32\drivers\cdfs.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-cdfs_31bf3856ad364e35_6.1.7600.16385_none_a63de9327e477e37\cdfs.sys : 70 656 : 07/14/2009 01:11 AM : 77ea11b065e0a8ab902d78145ca51e10 [Pos Repl]

* C:\Windows\System32\drivers\cdrom.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.sys : 108 544 : 11/20/2010 01:38 AM : be167ed0fdb9c1fa1133953c18d5a6c9 [Pos Repl]
+-> C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_5f7fb206051affbb\cdrom.sys : 108 544 : 07/14/2009 01:11 AM : ba6e70aa0e6091bc39de29477d866a77 [Pos Repl]
+-> C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_61b0c5ce02098355\cdrom.sys : 108 544 : 11/20/2010 01:38 AM : be167ed0fdb9c1fa1133953c18d5a6c9 [Pos Repl]

* C:\Windows\System32\drivers\classpnp.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-classpnp_31bf3856ad364e35_6.1.7600.16385_none_155984bf0d656ab3\Classpnp.sys : 140 864 : 07/14/2009 01:26 AM : a6388a5abf92c7927c085db0a958125f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-classpnp_31bf3856ad364e35_6.1.7601.17514_none_178a98870a53ee4d\Classpnp.sys : 140 864 : 07/14/2009 01:26 AM : a6388a5abf92c7927c085db0a958125f [Pos Repl]

* C:\Windows\System32\drivers\CmBatt.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\battery.inf_x86_neutral_5752155055c5e2d7\CmBatt.sys : 14 080 : 07/14/2009 01:19 AM : dea805815e587dad1dd2c502220b5616 [Pos Repl]
+-> C:\Windows\winsxs\x86_battery.inf_31bf3856ad364e35_6.1.7600.16385_none_15fde90fb523bb21\CmBatt.sys : 14 080 : 07/14/2009 01:19 AM : dea805815e587dad1dd2c502220b5616 [Pos Repl]

* C:\Windows\System32\drivers\compbatt.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\battery.inf_x86_neutral_5752155055c5e2d7\compbatt.sys : 19 024 : 07/14/2009 01:26 AM : a6023d3823c37043986713f118a89bee [Pos Repl]
+-> C:\Windows\winsxs\x86_battery.inf_31bf3856ad364e35_6.1.7600.16385_none_15fde90fb523bb21\compbatt.sys : 19 024 : 07/14/2009 01:26 AM : a6023d3823c37043986713f118a89bee [Pos Repl]

* C:\Windows\System32\drivers\diskdump.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-diskdump_31bf3856ad364e35_6.1.7600.16385_none_66948c2ff899c64e\Diskdump.sys : 26 688 : 07/14/2009 01:20 AM : 9e9c3566083e3a152d4d5c5311a852ab [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-diskdump_31bf3856ad364e35_6.1.7600.16634_none_66c9a133f87218b7\Diskdump.sys : 26 504 : 07/13/2010 01:22 AM : 3d8bdf695ba1569995027ad904f847e9 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-diskdump_31bf3856ad364e35_6.1.7600.16800_none_66e6139bf85d59d6\Diskdump.sys : 26 496 : 04/22/2011 09:36 PM : c78ea24ce267eaa6bf67caaeb11c0520 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-diskdump_31bf3856ad364e35_6.1.7600.20753_none_673c9ddd11a0d70c\Diskdump.sys : 26 504 : 07/13/2010 09:13 AM : d222767544650379e5c0385de9b40dbb [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-diskdump_31bf3856ad364e35_6.1.7600.20949_none_674d735111934d73\Diskdump.sys : 26 496 : 04/22/2011 09:17 PM : 36b1f9025f87f385f1af40e8200f6df6 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-diskdump_31bf3856ad364e35_6.1.7601.17514_none_68c59ff7f58849e8\Diskdump.sys : 27 008 : 11/20/2010 01:29 PM : 81773be2b369f54ede42ae62b59bb895 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-diskdump_31bf3856ad364e35_6.1.7601.17601_none_68cd70ebf582df19\Diskdump.sys : 27 008 : 04/22/2011 09:14 PM : d0f0d7a97c90fe72a79732812e65f822 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-diskdump_31bf3856ad364e35_6.1.7601.21710_none_694b3d810ea9817d\Diskdump.sys : 27 008 : 04/22/2011 09:57 PM : 0a49d7de1c0be2aa67fdaf672a369340 [Pos Repl]

* C:\Windows\System32\drivers\disk.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\disk.inf_x86_neutral_b431b61a11f8df6c\disk.sys : 57 424 : 07/14/2009 01:20 AM : 565003f326f99802e68ca78f2a68e9ff [Pos Repl]
+-> C:\Windows\winsxs\x86_disk.inf_31bf3856ad364e35_6.1.7600.16385_none_f99cd807d58018cb\disk.sys : 57 424 : 07/14/2009 09:20 AM : 565003f326f99802e68ca78f2a68e9ff [Pos Repl]

* C:\Windows\System32\drivers\drmkaud.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\wdmaudio.inf_x86_neutral_aed2a4456700dfde\drmkaud.sys : 5 120 : 07/14/2009 01:50 AM : b918e7c5f9bf77202f89e1a9539f2eb4 [Pos Repl]
+-> C:\Windows\winsxs\x86_wdmaudio.inf_31bf3856ad364e35_6.1.7600.16385_none_603daf367b793e32\drmkaud.sys : 5 120 : 07/14/2009 09:50 AM : b918e7c5f9bf77202f89e1a9539f2eb4 [Pos Repl]

* C:\Windows\System32\drivers\drmk.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\wdmaudio.inf_x86_neutral_aed2a4456700dfde\drmk.sys : 80 896 : 07/14/2009 01:41 AM : 27f9288af019e6daca281ede51ff5928 [Pos Repl]
+-> C:\Windows\winsxs\x86_wdmaudio.inf_31bf3856ad364e35_6.1.7600.16385_none_603daf367b793e32\drmk.sys : 80 896 : 07/14/2009 09:41 AM : 27f9288af019e6daca281ede51ff5928 [Pos Repl]

* C:\Windows\System32\drivers\dxapi.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-useros_31bf3856ad364e35_6.1.7600.16385_none_cd450af4ce8086e8\dxapi.sys : 13 312 : 07/14/2009 09:25 AM : 5fcd3320aae71506b43f9e12e4e72172 [Pos Repl]

* C:\Windows\System32\drivers\dxg.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-dxg_31bf3856ad364e35_6.1.7600.16385_none_a8c197c1bc709e3e\dxg.sys : 76 288 : 07/14/2009 09:25 AM : 1b6242b20cb56f85a158e67f09ee84fe [Pos Repl]

* C:\Windows\System32\drivers\fastfat.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-fat_31bf3856ad364e35_6.1.7600.16385_none_ae8981a3b8b7be50\fastfat.sys : 148 480 : 07/14/2009 09:14 AM : 7e0ab74553476622fb6ae36f73d97d35 [Pos Repl]

* C:\Windows\System32\drivers\fdc.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\fdc.inf_x86_neutral_67322cb863995ea8\fdc.sys : 25 088 : 07/14/2009 01:45 AM : e817a017f82df2a1f8cfdbda29388b29 [Pos Repl]
+-> C:\Windows\winsxs\x86_fdc.inf_31bf3856ad364e35_6.1.7600.16385_none_0168099141bb7be7\fdc.sys : 25 088 : 07/14/2009 09:45 AM : e817a017f82df2a1f8cfdbda29388b29 [Pos Repl]

* C:\Windows\System32\drivers\flpydisk.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\flpydisk.inf_x86_neutral_2102f5344367a352\flpydisk.sys : 19 968 : 07/14/2009 01:45 AM : 87907aa70cb3c56600f1c2fb8841579b [Pos Repl]
+-> C:\Windows\winsxs\x86_flpydisk.inf_31bf3856ad364e35_6.1.7600.16385_none_e6e06650dbcf54b4\flpydisk.sys : 19 968 : 07/14/2009 09:45 AM : 87907aa70cb3c56600f1c2fb8841579b [Pos Repl]

* C:\Windows\System32\drivers\fltMgr.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-filtermanager-core_31bf3856ad364e35_6.1.7600.16385_none_10dfc9158c1fa6f6\fltMgr.sys : 198 208 : 07/14/2009 09:20 AM : 7520ec808e0c35e0ee6f841294316653 [Pos Repl]

* C:\Windows\System32\drivers\fs_rec.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.1.7600.16385_none_25289c6a9fa4dca8\fs_rec.sys : 19 536 : 07/14/2009 09:20 AM : a574b4360e438977038aae4bf60d79a2 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.1.7600.16970_none_252e76489fa130ee\fs_rec.sys : 19 312 : 03/01/2012 09:53 AM : 500a9814fd9446a8126858a5a7f7d273 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.1.7600.21160_none_25c2bb21b8b6e809\fs_rec.sys : 19 312 : 03/01/2012 09:34 AM : 4f7b22cd40d4acfb9dd89f1080d3e9fe [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.1.7601.17514_none_2759b0329c936042\fs_rec.sys : 19 536 : 07/14/2009 09:20 AM : a574b4360e438977038aae4bf60d79a2 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.1.7601.17787_none_271105689cc96a2c\fs_rec.sys : 19 824 : 03/01/2012 09:46 AM : 7dae5ebcc80e45d3253f4923dc424d05 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.1.7601.21933_none_27ccb28db5c2160c\fs_rec.sys : 19 824 : 03/01/2012 09:31 AM : d550d49eebe4bf9d351769fd66ca3c8f [Pos Repl]

* C:\Windows\System32\drivers\hidclass.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\input.inf_x86_neutral_9e1eba5724be176f\hidclass.sys : 55 808 : 11/20/2010 01:59 AM : 931a1df1520abc6e84ba4a75e6957025 [Pos Repl]
+-> C:\Windows\winsxs\x86_input.inf_31bf3856ad364e35_6.1.7600.16385_none_2045efea8171454c\hidclass.sys : 55 808 : 07/14/2009 09:51 AM : b682e1cc0fdc7ac04b71d1fa9a07ef21 [Pos Repl]
+-> C:\Windows\winsxs\x86_input.inf_31bf3856ad364e35_6.1.7601.17514_none_227703b27e5fc8e6\hidclass.sys : 55 808 : 11/20/2010 09:59 AM : 931a1df1520abc6e84ba4a75e6957025 [Pos Repl]

* C:\Windows\System32\drivers\hidparse.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\input.inf_x86_neutral_9e1eba5724be176f\hidparse.sys : 25 728 : 07/14/2009 01:51 AM : 6c26122f1931d4d7810240f32ddce890 [Pos Repl]
+-> C:\Windows\winsxs\x86_input.inf_31bf3856ad364e35_6.1.7600.16385_none_2045efea8171454c\hidparse.sys : 25 728 : 07/14/2009 09:51 AM : 6c26122f1931d4d7810240f32ddce890 [Pos Repl]
+-> C:\Windows\winsxs\x86_input.inf_31bf3856ad364e35_6.1.7601.17514_none_227703b27e5fc8e6\hidparse.sys : 25 728 : 07/14/2009 09:51 AM : 6c26122f1931d4d7810240f32ddce890 [Pos Repl]

* C:\Windows\System32\drivers\hidusb.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\input.inf_x86_neutral_9e1eba5724be176f\hidusb.sys : 24 064 : 11/20/2010 01:59 AM : 10c19f8290891af023eaec0832e1eb4d [Pos Repl]
+-> C:\Windows\winsxs\x86_input.inf_31bf3856ad364e35_6.1.7600.16385_none_2045efea8171454c\hidusb.sys : 24 064 : 07/14/2009 09:51 AM : 25072fb35ac90b25f9e4e3bacf774102 [Pos Repl]
+-> C:\Windows\winsxs\x86_input.inf_31bf3856ad364e35_6.1.7601.17514_none_227703b27e5fc8e6\hidusb.sys : 24 064 : 11/20/2010 09:59 AM : 10c19f8290891af023eaec0832e1eb4d [Pos Repl]

* C:\Windows\System32\drivers\http.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-http_31bf3856ad364e35_6.1.7600.16385_none_ac97526c7a2e8289\http.sys : 513 024 : 07/14/2009 09:12 AM : c531c7fd9e8b62021112787c4e2c5a5a [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-http_31bf3856ad364e35_6.1.7601.17514_none_aec86634771d0623\http.sys : 513 536 : 11/20/2010 09:40 AM : 871917b07a141bff43d76d8844d48106 [Pos Repl]

* C:\Windows\System32\drivers\i8042prt.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_x86_neutral_50ad659974198591\i8042prt.sys : 80 896 : 07/14/2009 01:11 AM : f151f0bdc47f4a28b1b20a0818ea36d6 [Pos Repl]
+-> C:\Windows\System32\DriverStore\FileRepository\msmouse.inf_x86_neutral_7a9084e0177406eb\i8042prt.sys : 80 896 : 07/14/2009 01:11 AM : f151f0bdc47f4a28b1b20a0818ea36d6 [Pos Repl]
+-> C:\Windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.1.7600.16385_none_9724c3fc3a4c81ef\i8042prt.sys : 80 896 : 07/14/2009 09:11 AM : f151f0bdc47f4a28b1b20a0818ea36d6 [Pos Repl]
+-> C:\Windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.1.7601.17514_none_9955d7c4373b0589\i8042prt.sys : 80 896 : 07/14/2009 09:11 AM : f151f0bdc47f4a28b1b20a0818ea36d6 [Pos Repl]
+-> C:\Windows\winsxs\x86_msmouse.inf_31bf3856ad364e35_6.1.7600.16385_none_4e0a61a033aec8c3\i8042prt.sys : 80 896 : 07/14/2009 09:11 AM : f151f0bdc47f4a28b1b20a0818ea36d6 [Pos Repl]

* C:\Windows\System32\drivers\intelide.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\intelide.sys : 15 424 : 07/14/2009 01:20 AM : a0f12f2c9ba6c72f3987ce780e77c130 [Pos Repl]
+-> C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\intelide.sys : 15 424 : 07/14/2009 09:20 AM : a0f12f2c9ba6c72f3987ce780e77c130 [Pos Repl]
+-> C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\intelide.sys : 15 424 : 07/14/2009 09:20 AM : a0f12f2c9ba6c72f3987ce780e77c130 [Pos Repl]

* C:\Windows\System32\drivers\intelppm.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\cpu.inf_x86_neutral_729b871528391032\intelppm.sys : 53 760 : 07/14/2009 01:11 AM : 3b514d27bfc4accb4037bc6685f766e0 [Pos Repl]
+-> C:\Windows\winsxs\x86_cpu.inf_31bf3856ad364e35_6.1.7600.16385_none_5d20b0c250b4b524\intelppm.sys : 53 760 : 07/14/2009 09:11 AM : 3b514d27bfc4accb4037bc6685f766e0 [Pos Repl]

* C:\Windows\System32\drivers\ipfltdrv.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasipfilter_31bf3856ad364e35_6.1.7600.16385_none_e73fda0c2083052a\ipfltdrv.sys : 58 880 : 07/14/2009 09:54 AM : 709d1761d3b19a932ff0238ea6d50200 [Pos Repl]

* C:\Windows\System32\drivers\ipnat.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-ipnat_31bf3856ad364e35_6.1.7600.16385_none_5aee6dbbdcaf7199\ipnat.sys : 101 888 : 07/14/2009 09:54 AM : a5fa468d67abcdaa36264e463a7bb0cd [Pos Repl]

* C:\Windows\System32\drivers\irenum.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-irdaircomm_31bf3856ad364e35_6.1.7600.16385_none_2867d22e85fcfdfa\irenum.sys : 13 824 : 07/14/2009 09:53 AM : 42996cff20a3084a56017b7902307e9f [Pos Repl]

* C:\Windows\System32\drivers\isapnp.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\isapnp.sys : 46 656 : 07/14/2009 01:20 AM : 1f32bb6b38f62f7df1a7ab7292638a35 [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\isapnp.sys : 46 656 : 07/14/2009 09:20 AM : 1f32bb6b38f62f7df1a7ab7292638a35 [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\isapnp.sys : 46 656 : 07/14/2009 09:20 AM : 1f32bb6b38f62f7df1a7ab7292638a35 [Pos Repl]

* C:\Windows\System32\drivers\kbdclass.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_x86_neutral_50ad659974198591\kbdclass.sys : 42 576 : 07/14/2009 01:20 AM : adef52ca1aeae82b50df86b56413107e [Pos Repl]
+-> C:\Windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.1.7600.16385_none_9724c3fc3a4c81ef\kbdclass.sys : 42 576 : 07/14/2009 09:20 AM : adef52ca1aeae82b50df86b56413107e [Pos Repl]
+-> C:\Windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.1.7601.17514_none_9955d7c4373b0589\kbdclass.sys : 42 576 : 07/14/2009 09:20 AM : adef52ca1aeae82b50df86b56413107e [Pos Repl]

* C:\Windows\System32\drivers\ksecdd.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_a620e0e5be1ecda7\ksecdd.sys : 67 664 : 07/14/2009 09:20 AM : e36a061ec11b373826905b21be10948f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16484_none_a61fe281be1fb177\ksecdd.sys : 67 664 : 07/14/2009 09:20 AM : e36a061ec11b373826905b21be10948f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16915_none_a66c9bbdbde5f8fa\ksecdd.sys : 67 440 : 11/17/2011 09:48 AM : 0263364acb9c834ace52fb85c2c064ec [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.17035_none_a656d407bdf6641e\ksecdd.sys : 67 440 : 06/02/2012 09:51 AM : 52fc17c8589f11747d01d3cf592673d0 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.20594_none_a69eaf60d7456d32\ksecdd.sys : 67 664 : 07/14/2009 09:20 AM : e36a061ec11b373826905b21be10948f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.21092_none_a69c8e86d7476262\ksecdd.sys : 67 440 : 11/17/2011 09:20 AM : eb58ce9c7291ae1917eecf25543b3a9d [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.21225_none_a6eb42a4d70be51e\ksecdd.sys : 67 440 : 06/02/2012 09:50 AM : 5a07985c21039e42ac014853b7cd5a05 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_a851f4adbb0d5141\ksecdd.sys : 67 456 : 11/20/2010 01:30 PM : 412cea1aa78cc02a447f5c9e62b32ff1 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_a84828d7bb1480d7\ksecdd.sys : 67 440 : 11/17/2011 01:41 AM : f4647bb23db9038a7536cf6b68f4207f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17856_none_a828bb43bb2beb28\ksecdd.sys : 67 440 : 06/02/2012 01:45 AM : b7895b4182c0d16f6efadeb8081e8d36 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_a8a284cad4562b09\ksecdd.sys : 67 440 : 11/17/2011 01:35 AM : 91beb3c853eb11ab8363f2f261875fea [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22010_none_a8d76e24d42eb666\ksecdd.sys : 67 440 : 06/02/2012 01:57 AM : 1cb63b575adbd14a7216f6c4716816bb [Pos Repl]

* C:\Windows\System32\drivers\ks.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-kernelstreaming_31bf3856ad364e35_6.1.7600.16385_none_5757187af737b0be\ks.sys : 190 976 : 07/14/2009 01:45 AM : f762edd3acca095f5af4d719f3b8ae3d [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-kernelstreaming_31bf3856ad364e35_6.1.7600.16543_none_57805b62f719089a\ks.sys : 190 976 : 03/04/2010 01:57 AM : 9e79e2354301783d5e0d48411c2a7466 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-kernelstreaming_31bf3856ad364e35_6.1.7600.20659_none_580529fe10395c5f\ks.sys : 190 976 : 03/04/2010 01:53 AM : 5a5c40af44df5fac634b6c3555aa8808 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-kernelstreaming_31bf3856ad364e35_6.1.7601.17514_none_59882c42f4263458\ks.sys : 190 976 : 11/20/2010 01:50 AM : 5dcef0c32be0f33277326586fa503689 [Pos Repl]

* C:\Windows\System32\drivers\mcd.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft.windows.h..changer-driverclass_31bf3856ad364e35_6.1.7600.16385_none_c87bc13e280dd10a\mcd.sys : 18 432 : 07/14/2009 01:45 AM : ef08d2ebe3eabba43cc57eee001027b6 [Pos Repl]

* C:\Windows\System32\drivers\modem.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-u..em-core-classdriver_31bf3856ad364e35_6.1.7600.16385_none_2fdad9144fff701e\modem.sys : 31 744 : 07/14/2009 01:55 AM : f001861e5700ee84e2d4e52c712f4964 [Pos Repl]

* C:\Windows\System32\drivers\mouclass.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\msmouse.inf_x86_neutral_7a9084e0177406eb\mouclass.sys : 41 552 : 07/14/2009 01:20 AM : fb18cc1d4c2e716b6b903b0ac0cc0609 [Pos Repl]
+-> C:\Windows\winsxs\x86_msmouse.inf_31bf3856ad364e35_6.1.7600.16385_none_4e0a61a033aec8c3\mouclass.sys : 41 552 : 07/14/2009 01:20 AM : fb18cc1d4c2e716b6b903b0ac0cc0609 [Pos Repl]

* C:\Windows\System32\drivers\mouhid.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\msmouse.inf_x86_neutral_7a9084e0177406eb\mouhid.sys : 26 112 : 07/14/2009 01:45 AM : 2c388d2cd01c9042596cf3c8f3c7b24d [Pos Repl]
+-> C:\Windows\winsxs\x86_msmouse.inf_31bf3856ad364e35_6.1.7600.16385_none_4e0a61a033aec8c3\mouhid.sys : 26 112 : 07/14/2009 01:45 AM : 2c388d2cd01c9042596cf3c8f3c7b24d [Pos Repl]

* C:\Windows\System32\drivers\mountmgr.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-mountpointmanager_31bf3856ad364e35_6.1.7600.16385_none_f26e7ae968595905\mountmgr.sys : 78 416 : 07/14/2009 01:20 AM : 921c18727c5920d6c0300736646931c2 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-mountpointmanager_31bf3856ad364e35_6.1.7601.17514_none_f49f8eb16547dc9f\mountmgr.sys : 78 208 : 11/20/2010 01:30 PM : fc8771f45ecccfd89684e38842539b9b [Pos Repl]

* C:\Windows\System32\drivers\mrxdav.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-webdavredir-mrxdav_31bf3856ad364e35_6.1.7600.16385_none_14813b5b270f3a0b\mrxdav.sys : 115 712 : 07/14/2009 01:14 AM : b1be47008d20e43da3adc37c24cdb89d [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-webdavredir-mrxdav_31bf3856ad364e35_6.1.7601.17514_none_16b24f2323fdbda5\mrxdav.sys : 115 712 : 11/20/2010 01:42 AM : ceb46ab7c01c9f825f8cc6babc18166a [Pos Repl]

* C:\Windows\System32\drivers\mrxsmb.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16385_none_7f67c358b2710494\mrxsmb.sys : 123 392 : 07/14/2009 01:14 AM : f4a054be78af7f410129c4b64b07dc9b [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16499_none_7f60f67ab2758308\mrxsmb.sys : 123 392 : 01/08/2010 01:17 AM : 9e5dd4ef01aed723abf5342ef23ff012 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16539_none_7fa1d7e8b244d889\mrxsmb.sys : 123 392 : 02/27/2010 01:32 AM : f1b6aa08497ea86ca6ef6f7a08b0bfb8 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16765_none_7f7d6ac8b260c14e\mrxsmb.sys : 123 392 : 02/23/2011 01:05 AM : b4c76ef46322a9711c7b0f4e21ef6ea5 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.16808_none_7fc14d14b22d62d4\mrxsmb.sys : 123 392 : 05/04/2011 01:43 AM : ca7570e42522e24324a12161db14ec02 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.20612_none_803a1285cb588f10\mrxsmb.sys : 123 392 : 01/08/2010 01:18 AM : f7fcc6528d5b55c38cc436eb64d0d045 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.20655_none_8011d3b3cb764ad9\mrxsmb.sys : 123 392 : 02/27/2010 01:33 AM : dd364c196f822edc52217e8e819c8664 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.20907_none_8049e995cb4be947\mrxsmb.sys : 123 904 : 02/23/2011 01:37 AM : 5dc06ceb9aa4b65e724376766eb410ab [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7600.20959_none_8015da8dcb72a7aa\mrxsmb.sys : 123 904 : 05/04/2011 01:23 AM : ae6248d356c6c1de1623f0610b7fb0a3 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.17514_none_8198d720af5f882e\mrxsmb.sys : 123 904 : 11/20/2010 01:42 AM : b272b4c3e085ea860c12f2e4faf2ffa2 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.17565_none_8163c7ceaf872d3a\mrxsmb.sys : 123 904 : 02/23/2011 01:47 AM : ed3d3419b064f28d812995ed8cadc541 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.17605_none_81a4a93caf5682bb\mrxsmb.sys : 123 904 : 04/27/2011 01:17 AM : 5d16c921e3671636c0eba3bbaac5fd25 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.21666_none_81ee64e3c8a3e65b\mrxsmb.sys : 123 904 : 02/23/2011 01:09 AM : c76fd653db8b90da85ead12b12fffc9f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.1.7601.21714_none_822275d1c87d251f\mrxsmb.sys : 123 904 : 04/27/2011 01:15 AM : 39a8ff477b3f5d0edfe814155841c735 [Pos Repl]

* C:\Windows\System32\drivers\msfs.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-msfs_31bf3856ad364e35_6.1.7600.16385_none_a646965e7e3ffc0c\msfs.sys : 22 528 : 07/14/2009 01:11 AM : daefb28e3af5a76abcc2c3078c07327f [Pos Repl]

* C:\Windows\System32\drivers\MSKSSRV.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-kernelstreamingsupport_31bf3856ad364e35_6.1.7600.16385_none_61cb11453c0f45a5\mskssrv.sys : 8 320 : 07/14/2009 01:45 AM : 8c0860d6366aaffb6c5bb9df9448e631 [Pos Repl]

* C:\Windows\System32\drivers\MSPCLOCK.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-kernelstreamingsupport_31bf3856ad364e35_6.1.7600.16385_none_61cb11453c0f45a5\mspclock.sys : 5 888 : 07/14/2009 01:45 AM : 3ea8b949f963562cedbb549eac0c11ce [Pos Repl]

* C:\Windows\System32\drivers\MSPQM.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-kernelstreamingsupport_31bf3856ad364e35_6.1.7600.16385_none_61cb11453c0f45a5\mspqm.sys : 5 504 : 07/14/2009 01:45 AM : f456e973590d663b1073e9c463b40932 [Pos Repl]

* C:\Windows\System32\drivers\mssmbios.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\mssmbios.sys : 28 240 : 07/14/2009 01:20 AM : fc6b9ff600cc585ea38b12589bd4e246 [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\mssmbios.sys : 28 240 : 07/14/2009 01:20 AM : fc6b9ff600cc585ea38b12589bd4e246 [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\mssmbios.sys : 28 240 : 07/14/2009 01:20 AM : fc6b9ff600cc585ea38b12589bd4e246 [Pos Repl]

* C:\Windows\System32\drivers\mup.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-mup_31bf3856ad364e35_6.1.7600.16385_none_acc89f51b9d75e29\mup.sys : 49 728 : 07/14/2009 01:20 AM : 159fad02f64e6381758c990f753bcc80 [Pos Repl]

* C:\Windows\System32\drivers\ndis.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_a79d81ea7d62a289\ndis.sys : 710 720 : 07/14/2009 01:20 AM : 23759d175a0a9baaf04d05047bc135a8 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_a9ce95b27a512623\ndis.sys : 712 576 : 11/20/2010 01:30 PM : e7c54812a2aaf43316eb6930c1ffa108 [Pos Repl]

* C:\Windows\System32\drivers\ndistapi.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase_31bf3856ad364e35_6.1.7600.16385_none_0db6be04dbc2da8a\ndistapi.sys : 20 992 : 07/14/2009 01:54 AM : e4a8aec125a2e43a9e32afeea7c9c888 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase_31bf3856ad364e35_6.1.7601.17514_none_0fe7d1ccd8b15e24\ndistapi.sys : 20 992 : 07/14/2009 01:54 AM : e4a8aec125a2e43a9e32afeea7c9c888 [Pos Repl]

* C:\Windows\System32\drivers\ndisuio.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-ndisuio_31bf3856ad364e35_6.1.7600.16385_none_6bc75de74831b352\ndisuio.sys : 45 568 : 07/14/2009 01:53 AM : b30ae7f2b6d7e343b0df32e6c08fce75 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-ndisuio_31bf3856ad364e35_6.1.7601.17514_none_6df871af452036ec\ndisuio.sys : 46 080 : 11/20/2010 01:06 AM : d8a65dafb3eb41cbb622745676fcd072 [Pos Repl]

* C:\Windows\System32\drivers\ndiswan.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase-ndiswan_31bf3856ad364e35_6.1.7600.16385_none_f30ee6e4b89e5dbf\ndiswan.sys : 118 784 : 07/14/2009 01:54 AM : 267c415eadcbe53c9ca873dee39cf3a4 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase-ndiswan_31bf3856ad364e35_6.1.7601.17514_none_f53ffaacb58ce159\ndiswan.sys : 118 784 : 11/20/2010 01:07 AM : 38fbe267e7e6983311179230facb1017 [Pos Repl]

* C:\Windows\System32\drivers\ndproxy.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase_31bf3856ad364e35_6.1.7600.16385_none_0db6be04dbc2da8a\ndproxy.sys : 48 128 : 07/14/2009 01:54 AM : af7e7c63dcef3f8772726f86039d6eb4 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase_31bf3856ad364e35_6.1.7601.17514_none_0fe7d1ccd8b15e24\ndproxy.sys : 48 640 : 11/20/2010 01:07 AM : a4bdc541e69674fbff1a8ff00be913f2 [Pos Repl]

* C:\Windows\System32\drivers\netbios.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-netbios_31bf3856ad364e35_6.1.7600.16385_none_59b80e4dcc72e431\netbios.sys : 36 352 : 07/14/2009 01:53 AM : 80b275b1ce3b0e79909db7b39af74d51 [Pos Repl]

* C:\Windows\System32\drivers\netbt.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7600.16385_none_603b1e855897bcd6\netbt.sys : 187 904 : 07/14/2009 01:12 AM : dd52a733bf4ca5af84562a5e2f963b91 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7601.17514_none_626c324d55864070\netbt.sys : 187 904 : 11/20/2010 01:39 AM : 280122ddcf04b378edd1ad54d71c1e54 [Pos Repl]

* C:\Windows\System32\drivers\npfs.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-npfs_31bf3856ad364e35_6.1.7600.16385_none_a647db007e3ec880\npfs.sys : 35 328 : 07/14/2009 01:11 AM : 1db262a9f8c087e8153d89bef3d2235f [Pos Repl]

* C:\Windows\System32\drivers\ntfs.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7600.16385_none_a6477fe07e3f2f04\ntfs.sys : 1 210 432 : 07/14/2009 01:20 AM : 3795dcd21f740ee799fb7223234215af [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7600.16778_none_a65558427e3453b4\ntfs.sys : 1 210 240 : 03/11/2011 01:44 AM : 187002ce05693c306f43c873f821381f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7600.20921_none_a70e0489972fb38f\ntfs.sys : 1 210 752 : 03/11/2011 01:52 AM : a7266d82db9675afbded39695b69edac [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7601.17514_none_a87893a87b2db29e\ntfs.sys : 1 211 264 : 11/20/2010 01:30 PM : 33c3093d09017cfe2e219f2472bff6eb [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7601.17577_none_a83ab4fe7b5ba649\ntfs.sys : 1 211 264 : 03/11/2011 01:39 AM : 81189c3d7763838e55c397759d49007a [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7601.21680_none_a8b27fd79487b0a3\ntfs.sys : 1 211 264 : 03/11/2011 01:28 AM : e2ede3f02f95b896a1c7c6f0cc0c4083 [Pos Repl]

* C:\Windows\System32\drivers\null.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-null_31bf3856ad364e35_6.1.7600.16385_none_a93c43a07c50a038\null.sys : 4 608 : 07/14/2009 01:11 AM : f9756a98d69098dca8945d62858a812c [Pos Repl]

* C:\Windows\System32\drivers\parport.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\parport.sys : 79 360 : 07/14/2009 01:45 AM : 2ea877ed5dd9713c5ac74e8ea7348d14 [Pos Repl]
+-> C:\Windows\winsxs\x86_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_f86e06d519b1d9a4\parport.sys : 79 360 : 07/14/2009 01:45 AM : 2ea877ed5dd9713c5ac74e8ea7348d14 [Pos Repl]

* C:\Windows\System32\drivers\partmgr.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-partitionmanager_31bf3856ad364e35_6.1.7600.16385_none_e17269af1bc32604\partmgr.sys : 56 912 : 07/14/2009 01:20 AM : ff4218952b51de44fe910953a3e686b9 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-partitionmanager_31bf3856ad364e35_6.1.7600.16979_none_e18146271bb75e59\partmgr.sys : 56 688 : 03/17/2012 01:20 AM : 66d3415c159741ade7038a277efff99f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-partitionmanager_31bf3856ad364e35_6.1.7600.21172_none_e203b90e34db8004\partmgr.sys : 56 176 : 03/17/2012 01:25 AM : 58916826a13a721e7f73f454daa6c9c8 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-partitionmanager_31bf3856ad364e35_6.1.7601.17514_none_e3a37d7718b1a99e\partmgr.sys : 56 192 : 11/20/2010 01:30 PM : bf8f6af06da75b336f07e23aef97d93b [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-partitionmanager_31bf3856ad364e35_6.1.7601.17796_none_e34f027718f0b622\partmgr.sys : 56 176 : 03/17/2012 01:27 AM : 3f34a1b4c5f6475f320c275e63afce9b [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-partitionmanager_31bf3856ad364e35_6.1.7601.21946_none_e40eb0c431e5c75e\partmgr.sys : 56 176 : 03/17/2012 01:05 AM : 2dbfa1d13f039e222d18bc7b36ac6cdb [Pos Repl]

* C:\Windows\System32\drivers\parvdm.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\parvdm.sys : 8 704 : 07/14/2009 01:45 AM : eb0a59f29c19b86479d36b35983daadc [Pos Repl]
+-> C:\Windows\winsxs\x86_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_f86e06d519b1d9a4\parvdm.sys : 8 704 : 07/14/2009 01:45 AM : eb0a59f29c19b86479d36b35983daadc [Pos Repl]

* C:\Windows\System32\drivers\pciidex.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\pciidex.sys : 42 560 : 07/14/2009 01:19 AM : ede040d666ff81bf1978d0f19f799e7a [Pos Repl]
+-> C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\pciidex.sys : 42 560 : 07/14/2009 01:19 AM : ede040d666ff81bf1978d0f19f799e7a [Pos Repl]
+-> C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\pciidex.sys : 42 560 : 07/14/2009 01:19 AM : ede040d666ff81bf1978d0f19f799e7a [Pos Repl]

* C:\Windows\System32\drivers\pci.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\pci.sys : 153 984 : 11/20/2010 01:30 PM : 673e55c3498eb970088e812ea820aa8f [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\pci.sys : 153 680 : 07/14/2009 01:20 AM : c858cb77c577780ecc456a892e7e7d0f [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\pci.sys : 153 984 : 11/20/2010 01:30 PM : 673e55c3498eb970088e812ea820aa8f [Pos Repl]

* C:\Windows\System32\drivers\pcmcia.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\pcmcia.inf_x86_neutral_42dda5eb5768a3df\pcmcia.sys : 180 288 : 07/14/2009 01:19 AM : f396431b31693e71e8a80687ef523506 [Pos Repl]
+-> C:\Windows\winsxs\x86_pcmcia.inf_31bf3856ad364e35_6.1.7600.16385_none_85a22802fc99e371\pcmcia.sys : 180 288 : 07/14/2009 01:19 AM : f396431b31693e71e8a80687ef523506 [Pos Repl]

* C:\Windows\System32\drivers\portcls.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\wdmaudio.inf_x86_neutral_aed2a4456700dfde\portcls.sys : 177 152 : 07/14/2009 01:51 AM : d72708c9f49500c13d7d067e169b7715 [Pos Repl]
+-> C:\Windows\winsxs\x86_wdmaudio.inf_31bf3856ad364e35_6.1.7600.16385_none_603daf367b793e32\portcls.sys : 177 152 : 07/14/2009 01:51 AM : d72708c9f49500c13d7d067e169b7715 [Pos Repl]

* C:\Windows\System32\drivers\processr.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\cpu.inf_x86_neutral_729b871528391032\processr.sys : 52 224 : 07/14/2009 01:11 AM : 85b1e3a0c7585bc4aae6899ec6fcf011 [Pos Repl]
+-> C:\Windows\winsxs\x86_cpu.inf_31bf3856ad364e35_6.1.7600.16385_none_5d20b0c250b4b524\processr.sys : 52 224 : 07/14/2009 01:11 AM : 85b1e3a0c7585bc4aae6899ec6fcf011 [Pos Repl]

* C:\Windows\System32\drivers\rasacd.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasautodial_31bf3856ad364e35_6.1.7600.16385_none_0fb054d9c6a6b4d4\rasacd.sys : 11 776 : 07/14/2009 01:54 AM : 30a81b53c766d0133bb86d234e5556ab [Pos Repl]

* C:\Windows\System32\drivers\rasl2tp.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase-rasl2tp_31bf3856ad364e35_6.1.7600.16385_none_99b2a2c04941dfb7\rasl2tp.sys : 78 848 : 07/14/2009 01:54 AM : d9f91eafec2815365cbe6d167e4e332a [Pos Repl]

* C:\Windows\System32\drivers\raspppoe.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase-raspppoe_31bf3856ad364e35_6.1.7600.16385_none_5609da43fbeb6e85\raspppoe.sys : 77 824 : 07/14/2009 01:54 AM : 0fe8b15916307a6ac12bfb6a63e45507 [Pos Repl]

* C:\Windows\System32\drivers\raspptp.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rasbase-raspptp_31bf3856ad364e35_6.1.7600.16385_none_99c574fc492a728d\raspptp.sys : 73 728 : 07/14/2009 01:54 AM : 631e3e205ad6d86f2aed6a4a8e69f2db [Pos Repl]

* C:\Windows\System32\drivers\rdbss.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rdbss_31bf3856ad364e35_6.1.7600.16385_none_59ab2defc2bd0505\rdbss.sys : 241 664 : 07/14/2009 01:14 AM : 835d7e81bf517a3b72384bdcc85e1ce6 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-rdbss_31bf3856ad364e35_6.1.7601.17514_none_5bdc41b7bfab889f\rdbss.sys : 242 688 : 11/20/2010 01:44 AM : d528bc58a489409ba40334ebf96a311b [Pos Repl]

* C:\Windows\System32\drivers\rdpcdd.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..niportdisplaydriver_31bf3856ad364e35_6.1.7600.16385_none_d4b17a3e9f928d55\RDPCDD.sys : 6 656 : 07/14/2009 01:01 AM : 1e016846895b15a99f9a176a05029075 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..niportdisplaydriver_31bf3856ad364e35_6.1.7601.17514_none_d6e28e069c8110ef\RDPCDD.sys : 6 656 : 11/20/2010 01:22 AM : 23dae03f29d253ae74c44f99e515f9a1 [Pos Repl]

* C:\Windows\System32\drivers\rdpdr.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-terminalservices-rdpdr_31bf3856ad364e35_6.1.7600.16385_none_011065d1aa5ad954\rdpdr.sys : 133 120 : 07/14/2009 01:02 AM : c5ff95883ffef704d50c40d21cfb3ab5 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-terminalservices-rdpdr_31bf3856ad364e35_6.1.7601.17514_none_03417999a7495cee\rdpdr.sys : 133 632 : 11/20/2010 01:24 AM : b973fcfc50dc1434e1970a146f7e3885 [Pos Repl]

* C:\Windows\System32\drivers\rdpwd.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7600.16385_none_4b4bde6b36561dcb\rdpwd.sys : 177 152 : 07/14/2009 01:01 AM : 801371ba9782282892d00aadb08ee367 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7600.16963_none_4b5f89133647a225\rdpwd.sys : 177 152 : 02/15/2012 01:22 AM : 0399c725a9c95a6f1862b93f008ddf4a [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7600.17011_none_4b93703d36211704\rdpwd.sys : 177 152 : 04/28/2012 01:19 AM : c5b8d47a4688de9d335204ea757c2240 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7600.21151_none_4bf1cd584f5f2692\rdpwd.sys : 178 176 : 02/17/2012 01:16 AM : 9abed8c1607153bb89488187529c3db5 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7600.21202_none_4c28df244f35b15b\rdpwd.sys : 178 176 : 04/28/2012 01:19 AM : 9a67f7b4939f6a3ec7464c07737682f6 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7601.17514_none_4d7cf2333344a165\rdpwd.sys : 183 808 : 11/20/2010 01:22 AM : 288b06960d78428ff89e811632684e20 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7601.17779_none_4d4117e93370c20c\rdpwd.sys : 183 808 : 02/17/2012 01:14 AM : 244c83332f44589ae98fc347f11b2693 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7601.17830_none_4d6356e533586b60\rdpwd.sys : 183 808 : 04/28/2012 01:17 AM : f031683e6d1fea157abb2ff260b51e61 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7601.21924_none_4dfbc4c44c6a5495\rdpwd.sys : 183 808 : 02/17/2012 01:09 AM : 2570d1f85c0ce1096e075f2de96d11d9 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-t..dp-winstationdriver_31bf3856ad364e35_6.1.7601.21982_none_4db8e4a84c9cc98d\rdpwd.sys : 183 808 : 04/28/2012 01:08 AM : f665adb892f8002248274d9a22dddb00 [Pos Repl]

* C:\Windows\System32\drivers\rmcast.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.1.7600.16385_none_54542254e93e94e1\rmcast.sys : 117 248 : 07/14/2009 01:53 AM : b4090006a82eeb608c358ab5d37de85a [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.1.7601.17514_none_5685361ce62d187b\rmcast.sys : 117 760 : 11/20/2010 01:06 AM : 906dcfc5ebf4ec0433f8d4fffb0ba334 [Pos Repl]

* C:\Windows\System32\drivers\rndismp.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-rndis-miniport_31bf3856ad364e35_6.1.7600.16385_none_e10505d0ed38f22a\RNDISMP.sys : 33 280 : 07/14/2009 01:54 AM : 7400cfab5cf36f2294e80b3f3bda3ebc [Pos Repl]

* C:\Windows\System32\drivers\rootmdm.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-unimodem-core_31bf3856ad364e35_6.1.7600.16385_none_946e88ef35e184db\rootmdm.sys : 8 192 : 07/14/2009 01:55 AM : 564297827d213f52c7a3a2ff749568ca [Pos Repl]

* C:\Windows\System32\drivers\scsiport.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft.windows.s..se.scsi_port_driver_31bf3856ad364e35_6.1.7600.16385_none_e55684068b7262bb\scsiport.sys : 140 368 : 07/14/2009 01:19 AM : f9882099e58ecf8b0e1c7afa5d2cc56d [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft.windows.s..se.scsi_port_driver_31bf3856ad364e35_6.1.7601.17514_none_e78797ce8860e655\scsiport.sys : 140 160 : 11/20/2010 01:30 PM : 099972e1faf4950d3994fbab9dd21253 [Pos Repl]

* C:\Windows\System32\drivers\serenum.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\serenum.sys : 17 920 : 07/14/2009 01:45 AM : 9ad8b8b515e3df6acd4212ef465de2d1 [Pos Repl]
+-> C:\Windows\winsxs\x86_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_f86e06d519b1d9a4\serenum.sys : 17 920 : 07/14/2009 01:45 AM : 9ad8b8b515e3df6acd4212ef465de2d1 [Pos Repl]

* C:\Windows\System32\drivers\serial.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\serial.sys : 83 456 : 07/14/2009 01:45 AM : 5fb7fcea0490d821f26f39cc5ea3d1e2 [Pos Repl]
+-> C:\Windows\winsxs\x86_msports.inf_31bf3856ad364e35_6.1.7600.16385_none_f86e06d519b1d9a4\serial.sys : 83 456 : 07/14/2009 01:45 AM : 5fb7fcea0490d821f26f39cc5ea3d1e2 [Pos Repl]

* C:\Windows\System32\drivers\sffdisk.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\sffdisk.inf_x86_neutral_7e5210507f8fc265\sffdisk.sys : 11 264 : 07/14/2009 01:45 AM : 9f976e1eb233df46fce808d9dea3eb9c [Pos Repl]
+-> C:\Windows\winsxs\x86_sffdisk.inf_31bf3856ad364e35_6.1.7600.16385_none_a411df264b3d893a\sffdisk.sys : 11 264 : 07/14/2009 01:45 AM : 9f976e1eb233df46fce808d9dea3eb9c [Pos Repl]
+-> C:\Windows\winsxs\x86_sffdisk.inf_31bf3856ad364e35_6.1.7600.16438_none_a44af1864b1246b1\sffdisk.sys : 11 264 : 07/14/2009 01:45 AM : 9f976e1eb233df46fce808d9dea3eb9c [Pos Repl]
+-> C:\Windows\winsxs\x86_sffdisk.inf_31bf3856ad364e35_6.1.7600.20546_none_a4c7bdd16439cfbe\sffdisk.sys : 11 264 : 07/14/2009 01:45 AM : 9f976e1eb233df46fce808d9dea3eb9c [Pos Repl]
+-> C:\Windows\winsxs\x86_sffdisk.inf_31bf3856ad364e35_6.1.7601.17514_none_a642f2ee482c0cd4\sffdisk.sys : 11 264 : 07/14/2009 01:45 AM : 9f976e1eb233df46fce808d9dea3eb9c [Pos Repl]

* C:\Windows\System32\drivers\sffp_sd.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\sffdisk.inf_x86_neutral_7e5210507f8fc265\sffp_sd.sys : 12 800 : 11/20/2010 01:50 AM : 6d4ccaedc018f1cf52866bbbaa235982 [Pos Repl]
+-> C:\Windows\winsxs\x86_sffdisk.inf_31bf3856ad364e35_6.1.7600.16385_none_a411df264b3d893a\sffp_sd.sys : 12 800 : 07/14/2009 01:45 AM : 4f1e5b0fe7c8050668dbfade8999aefb [Pos Repl]
+-> C:\Windows\winsxs\x86_sffdisk.inf_31bf3856ad364e35_6.1.7600.16438_none_a44af1864b1246b1\sffp_sd.sys : 12 800 : 10/10/2009 01:57 AM : a0708bbd07d245c06ff9de549ca47185 [Pos Repl]
+-> C:\Windows\winsxs\x86_sffdisk.inf_31bf3856ad364e35_6.1.7600.20546_none_a4c7bdd16439cfbe\sffp_sd.sys : 12 800 : 10/10/2009 01:55 AM : 6790a1c44bdafdbf7fbebcba95fc1a32 [Pos Repl]
+-> C:\Windows\winsxs\x86_sffdisk.inf_31bf3856ad364e35_6.1.7601.17514_none_a642f2ee482c0cd4\sffp_sd.sys : 12 800 : 11/20/2010 01:50 AM : 6d4ccaedc018f1cf52866bbbaa235982 [Pos Repl]

* C:\Windows\System32\drivers\sfloppy.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\flpydisk.inf_x86_neutral_2102f5344367a352\sfloppy.sys : 13 824 : 07/14/2009 01:45 AM : db96666cc8312ebc45032f30b007a547 [Pos Repl]
+-> C:\Windows\winsxs\x86_flpydisk.inf_31bf3856ad364e35_6.1.7600.16385_none_e6e06650dbcf54b4\sfloppy.sys : 13 824 : 07/14/2009 01:45 AM : db96666cc8312ebc45032f30b007a547 [Pos Repl]

* C:\Windows\System32\drivers\smclib.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft.windows.s...smart_card_library_31bf3856ad364e35_6.1.7600.16385_none_f9da031b490b1c8a\smclib.sys : 17 408 : 07/14/2009 01:45 AM : 2e467e6ca8e0a140c08011844c0d3936 [Pos Repl]

* C:\Windows\System32\drivers\srv.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.16385_none_d9cdbf7e57c72d46\srv.sys : 309 760 : 07/14/2009 01:15 AM : 2ba4ebc7dfba845a1edbe1f75913be33 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.16481_none_d9c9c03c57cac511\srv.sys : 310 784 : 12/08/2009 01:05 AM : 50a83ca406c808bd35ac9141a0c7618f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.16619_none_da1d75cc578ac680\srv.sys : 310 784 : 06/22/2010 01:47 AM : dd0dd124d95390fdffa7fb6283923ed4 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.16664_none_d9e264be57b7d382\srv.sys : 310 784 : 08/27/2010 01:31 AM : 2dbedfb1853f06110ec2aa7f3213c89f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.16765_none_d9e366ee57b6ea00\srv.sys : 311 296 : 02/23/2011 01:06 AM : 4a9b0f215de2519e2363f91df25c1e97 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.16806_none_da2548a6578558d8\srv.sys : 311 296 : 04/29/2011 01:57 AM : c4a027b8c0bd3fc0699f41fa5e9e0c87 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.20591_none_da488d1b70f080cc\srv.sys : 310 784 : 12/08/2009 01:01 AM : 71f9ccbdd88e42360d0e782492f37a6a [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.20740_none_da7da03970c8d60e\srv.sys : 311 296 : 06/22/2010 01:45 AM : 1610437b099a40d18a8975edab98a301 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.20789_none_da5b632370e129e1\srv.sys : 311 296 : 08/27/2010 01:28 AM : f28094971cd10dd0c09930fb654ada0b [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.20907_none_daafe5bb70a211f9\srv.sys : 311 808 : 02/23/2011 01:38 AM : d0806dbfe08ab1a11b673c1e43d70efb [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7600.20956_none_da78d5d570cb8457\srv.sys : 311 808 : 04/29/2011 01:49 AM : 110ad8cd36f173e917b1145950042b79 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7601.17514_none_dbfed34654b5b0e0\srv.sys : 311 296 : 11/20/2010 01:45 AM : 112127c3b2e64d7680cc39cd0a39dd7e [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7601.17565_none_dbc9c3f454dd55ec\srv.sys : 311 808 : 02/23/2011 01:48 AM : 4e636465a8653ba3bf29f929aa578e6f [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7601.17608_none_dc0da64054a9f772\srv.sys : 311 808 : 04/29/2011 01:46 AM : e4c2764065d66ea1d2d3ebc28fe99c46 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7601.21666_none_dc5461096dfa0f0d\srv.sys : 311 808 : 02/23/2011 01:10 AM : 52c2b8f7dbb796954a98cf7bc8753766 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.1.7601.21717_none_dc8b72d56dd099d6\srv.sys : 311 808 : 04/29/2011 01:19 AM : b9526afe58b0eb537a391dfa925a1e40 [Pos Repl]

* C:\Windows\System32\drivers\swenum.sys [NoSig]
+-> C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\swenum.sys : 12 240 : 07/14/2009 01:19 AM : e58c78a848add9610a4db6d214af5224 [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\swenum.sys : 12 240 : 07/14/2009 01:19 AM : e58c78a848add9610a4db6d214af5224 [Pos Repl]
+-> C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\swenum.sys : 12 240 : 07/14/2009 01:19 AM : e58c78a848add9610a4db6d214af5224 [Pos Repl]

* C:\Windows\System32\drivers\tape.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft.windows.h..pedrive-driverclass_31bf3856ad364e35_6.1.7600.16385_none_9200269b1ea20fd1\tape.sys : 24 576 : 07/14/2009 01:45 AM : 949c35bf4ae6c110a924ab5e2175dda7 [Pos Repl]

* C:\Windows\System32\Drivers\tcpip.sys [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_b2f46875c7b9d667\tcpip.sys : 1 285 712 : 07/14/2009 01:19 AM : 2cc3d75488abd3ec628bbb9a4fc84efc [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_b33b1c29c7858b92\tcpip.sys : 1 286 016 : 06/14/2010 01:12 AM : bb7f39c31c4a4417fd318e7cd184e225 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_b347f075c77b9c9d\tcpip.sys : 1 286 016 : 04/25/2011 01:56 AM : 0158d5e9982e9d6a90dfc802f618e130 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16839_none_b32e82b7c78da1d1\tcpip.sys : 1 286 016 : 06/21/2011 01:39 AM : c2daaeb48f3a47c410b041a0d2382ee1 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16889_none_b2f8731bc7b62d86\tcpip.sys : 1 285 488 : 09/29/2011 05:43 PM : 56c198ac82efa622dd93e9e43575f79c [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16986_none_b2f57423c7b8dea8\tcpip.sys : 1 287 024 : 03/30/2012 05:29 AM : 55e9965552741f3850cb22cbba9671ed [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_b3b219fae0b0af43\tcpip.sys : 1 288 576 : 06/14/2010 05:06 AM : a39ea325c081ad27461f630c8e3e56e0 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_b39a7d5ae0c2aec5\tcpip.sys : 1 298 816 : 04/25/2011 05:44 AM : 8861b9a06ba99c6e1d62d0c86dfab86c [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20992_none_b3703df4e0e237e0\tcpip.sys : 1 301 376 : 06/21/2011 05:30 AM : 93c444d118b184452132357c322124cd [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21060_none_b38e8546e0cbe4a1\tcpip.sys : 1 301 872 : 09/29/2011 06:02 PM : 22f7e7cbca308dee3428b097d4f8a61c [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21178_none_b38bb990e0ccc871\tcpip.sys : 1 303 408 : 03/30/2012 06:08 AM : e47c2844a1605a44178f4281e4d58b3d [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_b5257c3dc4a85a01\tcpip.sys : 1 290 112 : 11/20/2010 01:30 PM : 37e8fa3779668837ca9e2c36d2415949 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_b52f4dc5c4a121e0\tcpip.sys : 1 290 624 : 04/25/2011 01:31 AM : 24326784df8f3d5f5bbb9f878ce33c14 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_b513df73c4b4f466\tcpip.sys : 1 290 624 : 06/21/2011 01:34 AM : 04e4a7d53a7ace02e8c55b17a498f631 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_b4d1ffa1c4e682b5\tcpip.sys : 1 290 608 : 09/29/2011 06:03 PM : 65d10b191c59c5501a1263fc33f6894b [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_b52e5147c4a202d7\tcpip.sys : 1 291 632 : 03/30/2012 06:23 AM : 7fa2e0f8b072bd04b77b421480b6cc22 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_b5ad1a5addc7c444\tcpip.sys : 1 301 376 : 04/25/2011 06:31 AM : 6d4728cff2724ff3a4654971d61d0f1c [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_b583db3edde666b6\tcpip.sys : 1 303 424 : 06/21/2011 06:54 AM : dec4940487050ae13c60c86f40e07e75 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_b5a84e10ddca7566\tcpip.sys : 1 303 920 : 09/29/2011 06:17 PM : 3c1c41e317710f74cec1e7f0d5325993 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_b583df0adde66104\tcpip.sys : 1 306 480 : 03/30/2012 06:04 AM : 88fcdb9923efeca207b3cebd24407126 [Pos Repl]

Program finished at: 08/29/2012 10:20:51 PM
Execution time: 0 hours(s), 2 minute(s), and 55 seconds(s)

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 21:32
od vyosek
Nedavejte prosim logy do code :)

Nyni spustte ComboFix

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 22:36
od puschpull
Hotovo
po restartu vypsal ComboFix tento log:

ComboFix 12-08-29.01 - Petr 29.08.2012 23:10:34.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3327.1912 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
/wow section - STAGE 50
Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\TMonitor\TMonitor.exe
c:\users\Petr\AppData\Local\assembly\tmp
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\briblo.scr
c:\windows\system32\HDREfexProFC32.dll.orig
c:\windows\system32\SilverEfexPro2FC32.dll.orig
c:\windows\system32\tmp6DBF.tmp
c:\windows\system32\tmp6DD0.tmp
c:\windows\system32\Viveza2FC32.dll.orig
c:\windows\system32\win.ini
c:\windows\XSxS
G:\Autorun.inf
c:\windows\system32\drivers\ba8ea32614ef4adc.sys . . . . nemohl být smazán
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_syshost32
-------\Legacy_ba8ea32614ef4adc
-------\Service_ba8ea32614ef4adc
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-28 do 2012-08-29 )))))))))))))))))))))))))))))))
.
.
2012-08-29 21:19 . 2012-08-29 21:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-29 19:53 . 2012-08-29 19:53 -------- d-----w- c:\program files\trend micro
2012-08-29 19:53 . 2012-08-29 19:53 -------- d-----w- C:\rsit
2012-08-29 19:27 . 2012-08-29 19:27 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-28 20:34 . 2012-08-29 21:24 71296 ----a-w- c:\windows\system32\drivers\ba8ea32614ef4adc.sys
2012-08-28 17:02 . 2012-08-28 17:02 73696 ----a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2012-08-25 12:54 . 2012-07-04 21:14 41984 ----a-w- c:\windows\system32\browcli.dll
2012-08-25 12:54 . 2012-07-04 21:14 102912 ----a-w- c:\windows\system32\browser.dll
2012-08-25 12:54 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll
2012-07-31 20:27 . 2012-07-31 20:27 -------- d-----w- c:\users\Petr\AppData\Roaming\XBMC
2012-07-31 20:26 . 2012-07-31 20:26 -------- d-----w- c:\program files\XBMC
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-29 21:24 . 2012-08-29 21:24 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4381DC0B-BA1F-43E8-835C-C66EBE1388AA}\MpKsl572b3758.sys
2012-08-27 23:50 . 2012-08-29 19:29 7022536 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4381DC0B-BA1F-43E8-835C-C66EBE1388AA}\mpengine.dll
2012-08-26 06:20 . 2012-03-29 14:12 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-26 06:20 . 2011-05-18 15:12 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-18 17:47 . 2012-08-25 12:54 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-05 20:06 . 2012-06-09 18:43 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-07-05 20:06 . 2010-04-18 19:40 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-29 00:09 . 2012-08-25 13:46 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:00 . 2012-08-25 13:46 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-06-06 06:49 . 2012-06-06 06:49 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-06 05:05 . 2012-07-11 13:57 1390080 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05 . 2012-07-11 13:57 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03 . 2012-07-11 13:57 805376 ----a-w- c:\windows\system32\cdosys.dll
2012-06-02 22:19 . 2012-06-19 14:41 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 14:41 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 14:41 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 14:41 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-19 14:41 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-19 14:41 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-19 14:41 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-19 14:41 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-19 14:41 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 04:45 . 2012-07-11 13:57 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45 . 2012-07-11 13:57 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40 . 2012-07-11 13:57 369336 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 04:40 . 2012-07-11 13:57 225280 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 04:39 . 2012-07-11 13:57 219136 ----a-w- c:\windows\system32\ncrypt.dll
2012-08-28 17:02 . 2011-03-22 17:03 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Drive Xpert"="c:\program files\ASUS\Drive Xpert\DriveXpert.exe" [2009-02-02 10231808]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-25 98304]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-06-01 1468296]
"StartupDelayer"="c:\program files\r2 Studios\Startup Delayer\Startup Launcher.exe" [2011-07-29 1068032]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
EarthDesk.lnk - c:\program files\XericDesign\EarthDesk\earthdesk.exe [2010-4-16 1654424]
Translate Client.lnk - c:\program files\Translate Client\translateclient.exe [2011-11-28 1703936]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Monitor Apache Servers.lnk - c:\dev\prog\apache2\bin\ApacheMonitor.exe [2008-12-10 41042]
Process Explorer.lnk - c:\program files\Process Explorer\procexp.exe [2012-2-17 4777280]
RealTemp.lnk - c:\program files\RealTemp\RealTemp.exe [2010-7-1 184176]
Translate Client.lnk - c:\program files\Translate Client\translateclient.exe [2011-11-28 1703936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0ENQBO
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 01:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 02:57 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 13:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FPVProTrialInfo]
2011-12-12 04:26 328936 ----a-w- c:\program files\FastPictureViewer\FPVTrialInfo.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-07-30 17:45 133104 ----atw- c:\users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 15:06 1840424 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-06-08 08:31 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
2012-01-20 19:03 719672 ----a-w- c:\program files\Microsoft Office\Office14\MSOSYNC.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2010-10-17 22:42 404200 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
2011-12-25 10:26 79872 ----a-w- c:\users\Petr\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2009-05-18 12:29 3866624 ----a-w- c:\program files\Analog Devices\SoundMAX\SoundMAX.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2009-06-05 16:42 1310720 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 09:07 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 11:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
S1 ArcSec;archlp;c:\windows\system32\drivers\ArcSec.sys [x]
S2 57xx SteelVine Manager;57xx SteelVine;c:\program files\ASUS\Drive Xpert\SteelVine.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Apache2.2;Apache2.2;c:\dev\prog\apache2\bin\httpd.exe [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - CFCATCHME
*NewlyCreated* - MPFILTER
*NewlyCreated* - MPKSL572B3758
*NewlyCreated* - WINRING0_1_2_0
*NewlyCreated* - WS2IFSL
*Deregistered* - CFcatchme
*Deregistered* - PROCEXP152
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-29 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-05-17 15:24]
.
2012-08-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-31 15:25]
.
2012-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-10 13:32]
.
2012-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-10 13:32]
.
2012-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2787196091-3245655353-2099626037-1001Core.job
- c:\users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-30 17:45]
.
2012-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2787196091-3245655353-2099626037-1001UA.job
- c:\users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-30 17:45]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://pravednes.cz/
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: IEB: Browser: Resize Window - c:\program files\IE Booster\window-size.html
IE: IEB: Frame: Open in &New Window - c:\program files\IE Booster\frame-open-in-new-window.html
IE: IEB: Frame: Open in &This Window - c:\program files\IE Booster\frame-open-in-this-window.html
IE: IEB: Image: Copy Path to Clipboard - c:\program files\IE Booster\image-copy-path-to-clipboard.html
IE: IEB: Image: Show Image Data - c:\program files\IE Booster\image-view-image-data.html
IE: IEB: Image: Show Server Response - c:\program files\IE Booster\link-show-server-response.html
IE: IEB: Link: Copy as <A href="URL">caption</A> - c:\program files\IE Booster\link-copy.html
IE: IEB: Link: Open in New Minimized Window - c:\program files\IE Booster\link-open-minimized.html
IE: IEB: Link: Show Server Response - c:\program files\IE Booster\link-show-server-response.html
IE: IEB: Page: Copy Title as <A href="URL">Title</a> - c:\program files\IE Booster\page-copy-title.html
IE: IEB: Page: Show Forms and Applets - c:\program files\IE Booster\page-show-forms.html
IE: IEB: Page: Show Hyperlinks - c:\program files\IE Booster\page-view-hyperlinks.html
IE: IEB: Page: Show Images - c:\program files\IE Booster\page-show-images.html
IE: IEB: Page: Show Source - c:\program files\IE Booster\page-view-source.html
IE: IEB: Page: Show Stylesheets - c:\program files\IE Booster\page-view-stylesheets.html
IE: IEB: Page: Show TABLE, FORM and DIV Borders - c:\program files\IE Booster\page-show-table-structure.htm
IE: IEB: Selection: Copy as plain text - c:\program files\IE Booster\selection-copy-plaintext.html
IE: IEB: Selection: Open in Browser - c:\program files\IE Booster\selection-open-in-browser.html
IE: IEB: Selection: Show Partial Source - c:\program files\IE Booster\selection-show-source.html
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
TCP: DhcpNameServer = 83.69.53.97 192.168.0.1
DPF: {5C519EC4-2BAE-44CE-B7F5-AD0CCD4BEFBD} - hxxp://www.starvedia.com/ActiveX/axmpeg4.cab
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\6ny88emk.puschpull\
FF - prefs.js: browser.search.defaulturl - hxxp://www.gigabase.ru/search?clid=1&q=
FF - prefs.js: browser.startup.homepage - hxxp://pravednes.cz/#!@puschpull
FF - prefs.js: keyword.URL - hxxp://www.gigabase.ru/search?clid=1&q=
FF - user.js: browser.search.defaulturl - hxxp://www.gigabase.ru/search?clid=1&q=
FF - user.js: keyword.URL - hxxp://www.gigabase.ru/search?clid=1&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-Cmaudio8788 - cmicnfgp.cpl
MSConfigStartUp-AdobeCS4ServiceManager - c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
AddRemove-Briblo - c:\windows\system32\Briblo.scr
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL5]
"ImagePath"="\"c:\dev\prog\mysql5\bin\mysqld-nt\" --defaults-file=\"c:\dev\prog\mysql5\my.ini\" MySQL5"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(1388)
c:\windows\system\HsSrv.dll
c:\program files\HappyFoto\HfAsistent\FotoSync.dll
c:\program files\HappyFoto\HfAsistent\xerc2701.dll
c:\program files\HappyFoto\HfAsistent\fotosynr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\atieclxx.exe
c:\windows\system32\AEADISRV.EXE
c:\windows\system32\astsrv.exe
c:\program files\Cobian Backup 10\cbVSCService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\dev\prog\mysql5\bin\mysqld-nt.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nlssrv32.exe
c:\windows\system32\NMSAccessU.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Sandboxie\SbieSvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Raxco\PerfectDisk\PDEngine.exe
c:\windows\system32\taskhost.exe
c:\program files\Raxco\PerfectDisk\PDAgentS1.exe
c:\windows\system32\conhost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\ASUS Xonar Essence STX Audio\Customapp\ASUSAUDIOCENTER.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\sppsvc.exe
c:\windows\system\HsMgr.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2012-08-29 23:34:20 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-29 21:34
.
Před spuštěním: Volných bajtů: 63 831 310 336
Po spuštění: Volných bajtů: 69 570 203 648
.
- - End Of File - - 336712611904B5541FA9DF0C2EAEA75A

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 22:39
od vyosek
:arrow: Stahnete Avenger http://forum.viry.cz/viewtopic.php?f=11&t=19832
  • Pokud pouzivate Win Vista ci W7, kliknete na Avenger pravym a dejte Run As Administrator ci Spustit jako spravce
  • Po spusteni Vas program upozorni, ze vse co delate, delate na vlastni riziko - Dejte OK
  • Po potvrzeni uz na Vas koukne hlavni okno, kam vlozite skript, ktery mate nize
  • Kód: Vybrat vše

    Files to delete:
    c:\windows\system32\drivers\ba8ea32614ef4adc.sys
  • Do ctverecku u Scan for rootkits a Automatically disable any rootkits found dejte fajecku
  • Nyni uz kliknete na Execute a potvrdte Yes v nasledujicim okne - timto potvrdite spusteni skriptu
  • Na otazku Reboot now odpovezte opet OK - timto se PC restartuje
  • Po restartu by se mel otevrit poznamkovy blok s logem a jeho obsah vlozte sem. Pokud se tak nestane, naleznete pozadovany dokument v C:\avenger.txt

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 22:52
od puschpull
Log po restartu:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "c:\windows\system32\drivers\ba8ea32614ef4adc.sys" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 29 srp 2012 23:18
od puschpull
vyosek: zatím moc děkuji.
Už jdu spát, juknu sem zítra.
Pokud je ještě nutné něco udělat, dej, prosím, vědět.
Také mě zajímá co se mi v PC vlastně stalo a jak k tomu mohlo dojít (abych tomu příště zamezil)
:)

Dobrou noc.

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 30 srp 2012 19:57
od vyosek
:arrow: Omlouvam se za zdrzeni, pracovni povinnosti

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Firefox::
    FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\6ny88emk.puschpull\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.gigabase.ru/search?clid=1&q=
    FF - prefs.js: browser.startup.homepage - hxxp://pravednes.cz/#!@puschpull
    FF - prefs.js: keyword.URL - hxxp://www.gigabase.ru/search?clid=1&q=
    FF - user.js: browser.search.defaulturl - hxxp://www.gigabase.ru/search?clid=1&q=
    FF - user.js: keyword.URL - hxxp://www.gigabase.ru/search?clid=1&q=
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe ARM"=-
    "SunJavaUpdateSched"=-
    
    File::
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\RealTemp.lnk
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 30 srp 2012 21:00
od puschpull
Log:


ComboFix 12-08-30.04 - Petr 30.08.2012 21:40:14.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3327.1570 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\RealTemp.lnk"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\cleanup.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\RealTemp.lnk
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-28 do 2012-08-30 )))))))))))))))))))))))))))))))
.
.
2012-08-30 19:51 . 2012-08-30 19:51 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8759E34D-BDBE-4799-B4D6-C4CFFB6DB7B1}\MpKsl2daff9ec.sys
2012-08-30 19:49 . 2012-08-30 19:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-30 17:48 . 2012-08-30 17:48 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8759E34D-BDBE-4799-B4D6-C4CFFB6DB7B1}\offreg.dll
2012-08-30 16:41 . 2012-08-30 16:41 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8759E34D-BDBE-4799-B4D6-C4CFFB6DB7B1}\MpKsl4b4903d0.sys
2012-08-30 14:08 . 2012-08-27 23:50 7022536 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8759E34D-BDBE-4799-B4D6-C4CFFB6DB7B1}\mpengine.dll
2012-08-29 19:53 . 2012-08-29 19:53 -------- d-----w- c:\program files\trend micro
2012-08-29 19:53 . 2012-08-29 19:53 -------- d-----w- C:\rsit
2012-08-29 19:30 . 2012-02-09 12:17 713784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{10FA6431-48DA-46A4-A599-CB86453D5303}\gapaengine.dll
2012-08-29 19:29 . 2012-08-27 23:50 7022536 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-29 19:27 . 2012-08-29 19:27 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-28 17:02 . 2012-08-28 17:02 73696 ----a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2012-08-25 12:54 . 2012-05-05 07:46 400896 ----a-w- c:\windows\system32\srcore.dll
2012-08-25 12:54 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-25 12:54 . 2012-07-04 21:14 41984 ----a-w- c:\windows\system32\browcli.dll
2012-08-25 12:54 . 2012-07-04 21:14 102912 ----a-w- c:\windows\system32\browser.dll
2012-08-25 12:54 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll
2012-07-31 20:27 . 2012-07-31 20:27 -------- d-----w- c:\users\Petr\AppData\Roaming\XBMC
2012-07-31 20:26 . 2012-07-31 20:26 -------- d-----w- c:\program files\XBMC
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-26 06:20 . 2012-03-29 14:12 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-26 06:20 . 2011-05-18 15:12 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-18 17:47 . 2012-08-25 12:54 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-05 20:06 . 2012-06-09 18:43 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-07-05 20:06 . 2010-04-18 19:40 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-29 00:09 . 2012-08-25 13:46 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-06 06:49 . 2012-06-06 06:49 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-06 05:05 . 2012-07-11 13:57 1390080 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05 . 2012-07-11 13:57 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03 . 2012-07-11 13:57 805376 ----a-w- c:\windows\system32\cdosys.dll
2012-06-02 22:19 . 2012-06-19 14:41 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 14:41 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 14:41 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 14:41 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-19 14:41 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-19 14:41 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-19 14:41 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-19 14:41 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-19 14:41 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 04:45 . 2012-07-11 13:57 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45 . 2012-07-11 13:57 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40 . 2012-07-11 13:57 369336 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 04:40 . 2012-07-11 13:57 225280 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 04:39 . 2012-07-11 13:57 219136 ----a-w- c:\windows\system32\ncrypt.dll
2012-08-28 17:02 . 2011-03-22 17:03 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Drive Xpert"="c:\program files\ASUS\Drive Xpert\DriveXpert.exe" [2009-02-02 10231808]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-25 98304]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-06-01 1468296]
"StartupDelayer"="c:\program files\r2 Studios\Startup Delayer\Startup Launcher.exe" [2011-07-29 1068032]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
c:\users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
EarthDesk.lnk - c:\program files\XericDesign\EarthDesk\earthdesk.exe [2010-4-16 1654424]
Translate Client.lnk - c:\program files\Translate Client\translateclient.exe [2011-11-28 1703936]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Monitor Apache Servers.lnk - c:\dev\prog\apache2\bin\ApacheMonitor.exe [2008-12-10 41042]
Process Explorer.lnk - c:\program files\Process Explorer\procexp.exe [2012-2-17 4777280]
Translate Client.lnk - c:\program files\Translate Client\translateclient.exe [2011-11-28 1703936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FPVProTrialInfo]
2011-12-12 04:26 328936 ----a-w- c:\program files\FastPictureViewer\FPVTrialInfo.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
2012-01-20 19:03 719672 ----a-w- c:\program files\Microsoft Office\Office14\MSOSYNC.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2010-10-17 22:42 404200 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
2011-12-25 10:26 79872 ----a-w- c:\users\Petr\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2009-05-18 12:29 3866624 ----a-w- c:\program files\Analog Devices\SoundMAX\SoundMAX.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2009-06-05 16:42 1310720 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R1 ehksazhi;ehksazhi;c:\windows\system32\drivers\ehksazhi.sys [x]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 CFcatchme;CFcatchme;c:\users\Petr\AppData\Local\Temp\CFcatchme.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 PROCEXP151;PROCEXP151;c:\windows\system32\Drivers\PROCEXP151.SYS [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [x]
S1 ArcSec;archlp;c:\windows\system32\drivers\ArcSec.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [x]
S1 MpKsl2daff9ec;MpKsl2daff9ec;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8759E34D-BDBE-4799-B4D6-C4CFFB6DB7B1}\MpKsl2daff9ec.sys [x]
S1 MpKsl4b4903d0;MpKsl4b4903d0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8759E34D-BDBE-4799-B4D6-C4CFFB6DB7B1}\MpKsl4b4903d0.sys [x]
S2 57xx SteelVine Manager;57xx SteelVine;c:\program files\ASUS\Drive Xpert\SteelVine.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Apache2.2;Apache2.2;c:\dev\prog\apache2\bin\httpd.exe [x]
S2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\Cobian Backup 10\cbVSCService.exe [x]
S2 MySQL5;MySQL5;c:\dev\prog\mysql5\bin\mysqld-nt --defaults-file=c:\dev\prog\mysql5\my.ini MySQL5 [x]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [x]
S3 cmudaxp;ASUS Xonar Essence STX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [x]
S3 yukonw7;Ovladač NDIS6.2 Miniport pro řadič Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL2DAFF9EC
*Deregistered* - PROCEXP152
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-30 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-05-17 15:24]
.
2012-08-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-31 15:25]
.
2012-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-10 13:32]
.
2012-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-10 13:32]
.
2012-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2787196091-3245655353-2099626037-1001Core.job
- c:\users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-30 17:45]
.
2012-08-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2787196091-3245655353-2099626037-1001UA.job
- c:\users\Petr\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-30 17:45]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://pravednes.cz/
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: IEB: Browser: Resize Window - c:\program files\IE Booster\window-size.html
IE: IEB: Frame: Open in &New Window - c:\program files\IE Booster\frame-open-in-new-window.html
IE: IEB: Frame: Open in &This Window - c:\program files\IE Booster\frame-open-in-this-window.html
IE: IEB: Image: Copy Path to Clipboard - c:\program files\IE Booster\image-copy-path-to-clipboard.html
IE: IEB: Image: Show Image Data - c:\program files\IE Booster\image-view-image-data.html
IE: IEB: Image: Show Server Response - c:\program files\IE Booster\link-show-server-response.html
IE: IEB: Link: Copy as <A href="URL">caption</A> - c:\program files\IE Booster\link-copy.html
IE: IEB: Link: Open in New Minimized Window - c:\program files\IE Booster\link-open-minimized.html
IE: IEB: Link: Show Server Response - c:\program files\IE Booster\link-show-server-response.html
IE: IEB: Page: Copy Title as <A href="URL">Title</a> - c:\program files\IE Booster\page-copy-title.html
IE: IEB: Page: Show Forms and Applets - c:\program files\IE Booster\page-show-forms.html
IE: IEB: Page: Show Hyperlinks - c:\program files\IE Booster\page-view-hyperlinks.html
IE: IEB: Page: Show Images - c:\program files\IE Booster\page-show-images.html
IE: IEB: Page: Show Source - c:\program files\IE Booster\page-view-source.html
IE: IEB: Page: Show Stylesheets - c:\program files\IE Booster\page-view-stylesheets.html
IE: IEB: Page: Show TABLE, FORM and DIV Borders - c:\program files\IE Booster\page-show-table-structure.htm
IE: IEB: Selection: Copy as plain text - c:\program files\IE Booster\selection-copy-plaintext.html
IE: IEB: Selection: Open in Browser - c:\program files\IE Booster\selection-open-in-browser.html
IE: IEB: Selection: Show Partial Source - c:\program files\IE Booster\selection-show-source.html
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
TCP: DhcpNameServer = 83.69.53.97 192.168.0.1
DPF: {5C519EC4-2BAE-44CE-B7F5-AD0CCD4BEFBD} - hxxp://www.starvedia.com/ActiveX/axmpeg4.cab
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\6ny88emk.puschpull\
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL5]
"ImagePath"="\"c:\dev\prog\mysql5\bin\mysqld-nt\" --defaults-file=\"c:\dev\prog\mysql5\my.ini\" MySQL5"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4832)
c:\program files\HappyFoto\HfAsistent\FotoSync.dll
c:\program files\HappyFoto\HfAsistent\xerc2701.dll
c:\program files\HappyFoto\HfAsistent\fotosynr.dll
c:\windows\System32\ieframe.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\atieclxx.exe
c:\windows\system32\AEADISRV.EXE
c:\windows\system32\astsrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\dev\prog\mysql5\bin\mysqld-nt.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\NMSAccessU.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Sandboxie\SbieSvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\taskhost.exe
c:\program files\Raxco\PerfectDisk\PDEngine.exe
c:\program files\Raxco\PerfectDisk\PDAgentS1.exe
c:\windows\system32\conhost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-08-30 21:59:04 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-30 19:59
ComboFix2.txt 2012-08-29 21:34
.
Před spuštěním: Volných bajtů: 66 815 930 368
Po spuštění: Volných bajtů: 67 032 776 704
.
- - End Of File - - 247B52A7767F669D699FACAFC3E67725

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 30 srp 2012 21:01
od vyosek
Jak se chova nas pacient :???:

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 30 srp 2012 21:02
od puschpull
zatím pořád nevím, co dělám, co se děje, jen se řídím instrukcemi
?


Mám vážně narušen systém ?
Nebude lepší přeinstalovat PC ?

Co se mi se systémem včera vlastně stalo ?

Re: Microsoft Security Essentials: Ochrana v reálném čase

Napsal: 30 srp 2012 21:04
od vyosek
Byl hodne zavirovan, ale uz by mel byt vylecen :wink:

:arrow: MSE bude lepsi preinstalovat, takze aplikujte tohlehttp://go.microsoft.com/?linkid=9748340 a pak tohle http://download.microsoft.com/download/ ... leanUp.exe

:arrow: Nainstalujte znovu MSE a napiste ci je vse OK