Stránka 1 z 1

Samovoľné písanie

Napsal: 21 pro 2013 11:36
od Davidkooo
Dobrý deň, poprosil by som o pomoc som zúfalý prešiel som pc všelijakými antivýrami , anti-malware a podobne ale stále mi nejde nijako odstrániť ten vírus mam pocit že sa zapína hneď pri štarte v pc. V podstate ide o to že ked som na pc tak mi začne vypisovat hocikedy tento znak & a zasahuje mi to do písania a chodu pc a nedá sa s tým nič robiť začne mi to vypisovať & & & & & a neprestáva to. Bol by som veľmi vďačný za nejakú radu. Vopred ďakujem.

Re: Samovoľné písanie

Napsal: 21 pro 2013 13:39
od Davidkooo
Tak tu je ten blog diky moc.

Re: Samovoľné písanie

Napsal: 21 pro 2013 19:11
od Davidkooo
Tak tu mam ten log.


ComboFix 13-12-20.01 - PC . 12. 2013 18:55:39.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1051.18.3327.2124 [GMT 1:00]
Running from: c:\users\PC\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\FF\components\config.ini
c:\program files\Dealio Toolbar\FF\chrome.manifest
c:\program files\Dealio Toolbar\FF\chrome\chrome.jar
c:\program files\Dealio Toolbar\FF\install.rdf
c:\program files\Dealio Toolbar\IE\7.3\config.ini
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\facebook.gif
c:\program files\Dealio Toolbar\Res\googleplus.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\Lang\res1031.ini
c:\program files\Dealio Toolbar\Res\Lang\res1033.ini
c:\program files\Dealio Toolbar\Res\Lang\res1034.ini
c:\program files\Dealio Toolbar\Res\Lang\res1036.ini
c:\program files\Dealio Toolbar\Res\Lang\res1040.ini
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\radio-close.gif
c:\program files\Dealio Toolbar\Res\radio-minimize.gif
c:\program files\Dealio Toolbar\Res\radiobeta.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_baidu.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\search_yandex.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\twitter.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\program files\Search Settings
c:\users\PC\AppData\Roaming\Local
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\1.ddi
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\2.ddi
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\3.ddi
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\Inception_Trailer_592.divx.ddr
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\SherlockHolmes_trailer_592.divx.ddr
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Inception_Trailer_592.divx.ddp
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\SherlockHolmes_trailer_592.divx.ddp
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\TheBlindSide_trailer_592.divx.ddp
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\ylfnfkvakpyf.avi.ddp
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\TheBlindSide_trailer_592.divx.ddr
c:\users\PC\AppData\Roaming\Local\Temp\DDM\Settings\ylfnfkvakpyf.avi.ddr
c:\windows\IsUn0405.exe
c:\windows\msxml4-KB954430-enu.LOG
c:\windows\msxml4-KB973688-enu.LOG
.
.
((((((((((((((((((((((((( Files Created from 2013-11-21 to 2013-12-21 )))))))))))))))))))))))))))))))
.
.
2013-12-21 18:04 . 2013-12-21 18:04 -------- d-----w- c:\users\PC\AppData\Local\temp
2013-12-21 18:04 . 2013-12-21 18:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-21 11:55 . 2013-12-21 11:55 40392 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3AA16AE7-9541-4B0F-A622-E7F6BBE1623D}\MpKsl827eda28.sys
2013-12-20 19:53 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3AA16AE7-9541-4B0F-A622-E7F6BBE1623D}\mpengine.dll
2013-12-09 17:37 . 2013-12-09 17:37 -------- d-----w- c:\program files\iPod
2013-12-09 17:37 . 2013-12-09 17:38 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-12-09 17:37 . 2013-12-09 17:38 -------- d-----w- c:\program files\iTunes
2013-12-09 11:26 . 2013-11-08 01:15 7772552 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-06 13:43 . 2013-11-01 14:09 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6904FA66-2BC3-4FD3-A967-8B3B83151724}\gapaengine.dll
2013-12-04 09:26 . 2013-12-04 09:26 -------- d-----w- c:\windows\system32\Wat
2013-12-04 08:50 . 2013-12-04 08:50 -------- d-----w- c:\program files\MSXML 4.0
2013-12-02 21:37 . 2013-12-02 21:38 -------- d-----w- c:\users\PC\AppData\Roaming\DVDVideoSoft
2013-12-02 21:37 . 2013-12-02 21:38 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2013-12-02 11:14 . 2013-12-02 11:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-12-02 11:14 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-01 16:27 . 2013-12-01 16:27 -------- d-----w- c:\users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:27 . 2013-12-01 16:27 -------- d-----w- c:\programdata\Malwarebytes
2013-12-01 16:24 . 2013-12-01 16:24 -------- d-----w- c:\programdata\Oracle
2013-12-01 16:23 . 2013-10-08 06:50 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-12-01 14:51 . 2013-12-01 14:51 -------- d-----w- c:\users\PC\AppData\Roaming\SUPERAntiSpyware.com
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-21 10:16 . 2012-03-30 10:07 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-21 10:16 . 2011-07-02 03:51 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-11-19 10:21 . 2010-03-08 21:17 230048 ------w- c:\windows\system32\MpSigStub.exe
2013-11-01 14:09 . 2013-11-07 11:14 719224 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-10-14 06:39 . 2013-11-01 13:44 7796464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2A07493C-1473-4B6B-AA64-3B348E963160}\mpengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-06-27 14:11 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
"ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2013-04-05 59720]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2008-09-02 8105984]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-11-10 98304]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2008-08-18 98304]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2012-07-16 01:06 138096 ----atw- c:\users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-09-24 12:38 136176 ----atw- c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS5\Bridge.exe" -stealth
"Facebook Update"="c:\users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"ICQ"="c:\program files\ICQ7M\ICQ.exe" silent loginmode=4
"com.apple.dav.bookmarks.daemon"=c:\program files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
"iCloudServices"=c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe"
"HPUsageTrackingLEDM"="c:\program files\HP\HP UT LEDM\bin\hppusg.exe" "c:\program files\HP\HP UT LEDM\"
"Guard.Mail.ru.gui"="c:\program files\Guard-ICQ\GuardICQ.exe" /gui
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"ATKMEDIA"=c:\program files\ASUS\ATK Media\DMedia.exe
"AmIcoSinglun"=c:\program files\AmIcoSingLun\AmIcoSinglun.exe
"ApnTBMon"="c:\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" -hide -runkey
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2009-08-21 27136]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys [x]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 mvusbews;USB EWS Device;c:\windows\system32\Drivers\mvusbews.sys [2011-04-16 17408]
R3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2013-12-04 1343400]
R4 APNMCP;Ask Update Service;c:\program files\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-10-15 166352]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2013-07-05 807800]
R4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-21 162408]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswKbd;aswKbd; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-29 218688]
S1 MpKsl827eda28;MpKsl827eda28;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3AA16AE7-9541-4B0F-A622-E7F6BBE1623D}\MpKsl827eda28.sys [2013-12-21 40392]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-11 172032]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files\Guard-ICQ\GuardICQ.exe [2013-02-02 1564368]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [2009-10-15 136192]
S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2011-05-18 99896]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NLSSRV32.EXE [2012-10-09 69640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2012-09-19 1699168]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-08-12 295376]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [2012-09-19 10088]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL827EDA28
*NewlyCreated* - PCHUNTER32AF
*Deregistered* - PCHunter32af
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 10:16]
.
2012-12-31 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4167722851-2380944550-1776531285-1000Core.job
- c:\users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-19 01:06]
.
2012-12-31 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4167722851-2380944550-1776531285-1000UA.job
- c:\users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-19 01:06]
.
2013-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-14 12:56]
.
2013-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-14 12:56]
.
2013-12-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4167722851-2380944550-1776531285-1000Core.job
- c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 12:38]
.
2013-12-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4167722851-2380944550-1776531285-1000UA.job
- c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 12:38]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Prevziať cez IDM
IE: Prevziať cez IDM všetky prepojenia
IE: Prevziať obsah FLV cez IDM
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\76uq7fni.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - http://www.google.sk
FF - prefs.js: keyword.enabled - false
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Adobe Photoshop 7.0.1 CE - c:\windows\ISUN0405.EXE
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-4167722851-2380944550-1776531285-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8f,d1,34,18,6e,4d,9b,c2,10,ca,e2,89,3e,41,3e,10,20,63,3b,06,7a,
ed,46,29,7c,e0,0c,75,ce,c3,4d,e0,f6,27,9b,a6,ff,ee,7b,db,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-4167722851-2380944550-1776531285-1000_Classes\CLSID\{974e76c4-c792-41a0-b7f7-c7d5b1608e0f}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000122
"Therad"=dword:00000011
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-12-21 19:06:40
ComboFix-quarantined-files.txt 2013-12-21 18:06
.
Pre-Run: 189 833 445 376 bytes free
Post-Run: 189 736 742 912 bytes free
.
- - End Of File - - 14415ABBDCB515D54CDF0565CFD4AD1A
A36C5E4F47E84449FF07ED3517B43A31

Re: Samovoľné písanie

Napsal: 22 pro 2013 13:49
od Davidkooo
Tak ten problem s pisanim sa objavil pri prezerani webu myslim možno nejaky ten gif z facebooku ale nie som si isty ten vyrus mam v pc už dlhšiu dobu. A od kedy som prešiel pc combofixom tak sa ten problem nenaskytol všetko ide ako ma (zatial). Bod obnovy som ešte neskušal. Ešte by som sa chcel spytat na niečo ked že som lajik-amater do antivirusových programoch a momentalne mam iba malwarebytes anti-malware program ktoremu došla skušobna doba tak by som sa chcel spytať, aký dobrý antivirak si mam stiahnut najlepšie by bolo free lebo nemam vela finačnych prostriedkov popripade niečo doplatim len nech mam ochranu pc. Mal som avast free len že ten ma vôbec neochranil. Mimochodom ked odinštalujem ten malwarebytes mam v karantene nejake tie vyrusi čo sa s nimi po vymazani malwarebytes stane? Velmi pekne dakujem za odpoved a ochotu.


13:31:30.0805 6084 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
13:31:31.0227 6084 ============================================================
13:31:31.0227 6084 Current date / time: 2013/12/22 13:31:31.0227
13:31:31.0227 6084 SystemInfo:
13:31:31.0227 6084
13:31:31.0227 6084 OS Version: 6.1.7600 ServicePack: 0.0
13:31:31.0227 6084 Product type: Workstation
13:31:31.0227 6084 ComputerName: PC-PC
13:31:31.0227 6084 UserName: PC
13:31:31.0227 6084 Windows directory: C:\Windows
13:31:31.0227 6084 System windows directory: C:\Windows
13:31:31.0227 6084 Processor architecture: Intel x86
13:31:31.0227 6084 Number of processors: 2
13:31:31.0227 6084 Page size: 0x1000
13:31:31.0227 6084 Boot type: Normal boot
13:31:31.0227 6084 ============================================================
13:31:33.0022 6084 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:31:33.0117 6084 ============================================================
13:31:33.0117 6084 \Device\Harddisk0\DR0:
13:31:33.0118 6084 MBR partitions:
13:31:33.0118 6084 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1C2DB000
13:31:33.0118 6084 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1C30D800, BlocksNum 0x32000
13:31:33.0118 6084 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x1C33F800, BlocksNum 0x1E046000
13:31:33.0118 6084 ============================================================
13:31:33.0144 6084 C: <-> \Device\Harddisk0\DR0\Partition3
13:31:33.0579 6084 D: <-> \Device\Harddisk0\DR0\Partition1
13:31:33.0580 6084 ============================================================
13:31:33.0580 6084 Initialize success
13:31:33.0580 6084 ============================================================
13:32:05.0354 5924 ============================================================
13:32:05.0354 5924 Scan started
13:32:05.0354 5924 Mode: Manual; SigCheck; TDLFS;
13:32:05.0354 5924 ============================================================
13:32:05.0723 5924 ================ Scan system memory ========================
13:32:05.0723 5924 System memory - ok
13:32:05.0723 5924 ================ Scan services =============================
13:32:05.0872 5924 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
13:32:05.0958 5924 1394ohci - ok
13:32:05.0982 5924 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
13:32:06.0000 5924 ACPI - ok
13:32:06.0020 5924 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
13:32:06.0069 5924 AcpiPmi - ok
13:32:06.0208 5924 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
13:32:06.0220 5924 AdobeARMservice - ok
13:32:06.0277 5924 [ 1BA1AB4141A92EB34DA99F1249CA2D4D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:32:06.0289 5924 AdobeFlashPlayerUpdateSvc - ok
13:32:06.0337 5924 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
13:32:06.0359 5924 adp94xx - ok
13:32:06.0384 5924 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
13:32:06.0403 5924 adpahci - ok
13:32:06.0425 5924 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
13:32:06.0439 5924 adpu320 - ok
13:32:06.0470 5924 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:32:06.0511 5924 AeLookupSvc - ok
13:32:06.0534 5924 [ DDC040FDB01EF1712A6B13E52AFB104C ] AFD C:\Windows\system32\drivers\afd.sys
13:32:06.0639 5924 AFD - ok
13:32:06.0671 5924 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
13:32:06.0683 5924 agp440 - ok
13:32:06.0710 5924 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
13:32:06.0722 5924 aic78xx - ok
13:32:06.0760 5924 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
13:32:06.0800 5924 ALG - ok
13:32:06.0816 5924 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
13:32:06.0827 5924 aliide - ok
13:32:06.0849 5924 [ 76B67D30D23F6E7CFF3EFF9B45B5ED94 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
13:32:06.0901 5924 AMD External Events Utility - ok
13:32:06.0915 5924 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\DRIVERS\amdagp.sys
13:32:06.0927 5924 amdagp - ok
13:32:06.0933 5924 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\DRIVERS\amdide.sys
13:32:06.0944 5924 amdide - ok
13:32:06.0962 5924 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
13:32:06.0977 5924 AmdK8 - ok
13:32:07.0008 5924 [ AD8FA28D8ED0D0A689A0559085CE0F18 ] AmdLLD C:\Windows\system32\DRIVERS\AmdLLD.sys
13:32:07.0042 5924 AmdLLD - ok
13:32:07.0055 5924 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
13:32:07.0095 5924 AmdPPM - ok
13:32:07.0111 5924 [ 2101A86C25C154F8314B24EF49D7FBC2 ] amdsata C:\Windows\system32\DRIVERS\amdsata.sys
13:32:07.0123 5924 amdsata - ok
13:32:07.0144 5924 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
13:32:07.0158 5924 amdsbs - ok
13:32:07.0178 5924 [ B81C2B5616F6420A9941EA093A92B150 ] amdxata C:\Windows\system32\DRIVERS\amdxata.sys
13:32:07.0187 5924 amdxata - ok
13:32:07.0224 5924 [ D2BF422C2611632AFB9CE8F7B2A8C306 ] AmUStor C:\Windows\system32\drivers\AmUStor.SYS
13:32:07.0245 5924 AmUStor - ok
13:32:07.0457 5924 [ BEF294FFE5F40BE768BDCBE1837DFABE ] APNMCP C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
13:32:07.0536 5924 APNMCP - ok
13:32:07.0566 5924 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\Windows\system32\drivers\appid.sys
13:32:07.0627 5924 AppID - ok
13:32:07.0653 5924 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
13:32:07.0693 5924 AppIDSvc - ok
13:32:07.0716 5924 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\Windows\System32\appinfo.dll
13:32:07.0759 5924 Appinfo - ok
13:32:07.0843 5924 [ 30E3850F303EAE5C364782EA78579CC9 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:32:07.0853 5924 Apple Mobile Device - ok
13:32:07.0933 5924 [ C90A4F9619280EBE9AC28733C03D2E60 ] Application Updater C:\Program Files\Application Updater\ApplicationUpdater.exe
13:32:07.0984 5924 Application Updater - ok
13:32:08.0021 5924 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
13:32:08.0062 5924 AppMgmt - ok
13:32:08.0094 5924 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
13:32:08.0106 5924 arc - ok
13:32:08.0120 5924 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
13:32:08.0133 5924 arcsas - ok
13:32:08.0163 5924 [ EB1807795CD3EEAA3288B4A30DE254E8 ] ASLDRService C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
13:32:08.0203 5924 ASLDRService - ok
13:32:08.0272 5924 [ 39CDCB109BF200CC8A05B9C7E6272D11 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
13:32:08.0282 5924 aspnet_state - ok
13:32:08.0357 5924 [ 4691B3FE3717F9D9C64A5282C8543D4D ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
13:32:08.0366 5924 aswKbd - ok
13:32:08.0386 5924 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:32:08.0429 5924 AsyncMac - ok
13:32:08.0456 5924 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\DRIVERS\atapi.sys
13:32:08.0466 5924 atapi - ok
13:32:08.0517 5924 [ 76BAB0C824E2D05B940C4DD40A9B08BF ] athr C:\Windows\system32\DRIVERS\athr.sys
13:32:08.0598 5924 athr - ok
13:32:08.0729 5924 [ FA4A8F05D138E2DFA2AC93411CFBDE0C ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
13:32:08.0901 5924 atikmdag - ok
13:32:08.0931 5924 [ B73C832088DD54B55E04FF6F9646AD8C ] AtiPcie C:\Windows\system32\DRIVERS\AtiPcie.sys
13:32:08.0941 5924 AtiPcie - ok
13:32:08.0980 5924 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:32:09.0026 5924 AudioEndpointBuilder - ok
13:32:09.0046 5924 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:32:09.0081 5924 Audiosrv - ok
13:32:09.0102 5924 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\Windows\System32\AxInstSV.dll
13:32:09.0158 5924 AxInstSV - ok
13:32:09.0195 5924 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
13:32:09.0229 5924 b06bdrv - ok
13:32:09.0264 5924 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
13:32:09.0283 5924 b57nd60x - ok
13:32:09.0323 5924 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
13:32:09.0362 5924 BDESVC - ok
13:32:09.0380 5924 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
13:32:09.0418 5924 Beep - ok
13:32:09.0452 5924 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\Windows\System32\bfe.dll
13:32:09.0488 5924 BFE - ok
13:32:09.0534 5924 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\Windows\system32\qmgr.dll
13:32:09.0603 5924 BITS - ok
13:32:09.0638 5924 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
13:32:09.0664 5924 blbdrive - ok
13:32:09.0735 5924 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
13:32:09.0753 5924 Bonjour Service - ok
13:32:09.0791 5924 [ FCAFAEF6798D7B51FF029F99A9898961 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:32:09.0829 5924 bowser - ok
13:32:09.0850 5924 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:32:09.0882 5924 BrFiltLo - ok
13:32:09.0895 5924 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:32:09.0922 5924 BrFiltUp - ok
13:32:09.0964 5924 [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
13:32:09.0996 5924 BridgeMP - ok
13:32:10.0024 5924 [ 598E1280E7FF3744F4B8329366CC5635 ] Browser C:\Windows\System32\browser.dll
13:32:10.0055 5924 Browser - ok
13:32:10.0082 5924 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
13:32:10.0135 5924 Brserid - ok
13:32:10.0154 5924 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
13:32:10.0173 5924 BrSerWdm - ok
13:32:10.0179 5924 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
13:32:10.0214 5924 BrUsbMdm - ok
13:32:10.0235 5924 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
13:32:10.0260 5924 BrUsbSer - ok
13:32:10.0273 5924 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
13:32:10.0307 5924 BTHMODEM - ok
13:32:10.0336 5924 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
13:32:10.0371 5924 bthserv - ok
13:32:10.0468 5924 catchme - ok
13:32:10.0490 5924 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:32:10.0531 5924 cdfs - ok
13:32:10.0564 5924 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:32:10.0596 5924 cdrom - ok
13:32:10.0617 5924 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\Windows\System32\certprop.dll
13:32:10.0649 5924 CertPropSvc - ok
13:32:10.0664 5924 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
13:32:10.0681 5924 circlass - ok
13:32:10.0702 5924 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
13:32:10.0718 5924 CLFS - ok
13:32:10.0740 5924 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:32:10.0751 5924 clr_optimization_v2.0.50727_32 - ok
13:32:10.0817 5924 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:32:10.0828 5924 clr_optimization_v4.0.30319_32 - ok
13:32:10.0856 5924 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:32:10.0872 5924 CmBatt - ok
13:32:10.0885 5924 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
13:32:10.0896 5924 cmdide - ok
13:32:10.0921 5924 [ 1B675691ED940766149C93E8F4488D68 ] CNG C:\Windows\system32\Drivers\cng.sys
13:32:10.0944 5924 CNG - ok
13:32:10.0962 5924 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:32:10.0972 5924 Compbatt - ok
13:32:10.0991 5924 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
13:32:11.0008 5924 CompositeBus - ok
13:32:11.0014 5924 COMSysApp - ok
13:32:11.0032 5924 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
13:32:11.0044 5924 crcdisk - ok
13:32:11.0076 5924 [ 9C231178CE4FB385F4B54B0A9080B8A4 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:32:11.0110 5924 CryptSvc - ok
13:32:11.0156 5924 [ 27C9490BDD0AE48911AB8CF1932591ED ] CSC C:\Windows\system32\drivers\csc.sys
13:32:11.0199 5924 CSC - ok
13:32:11.0232 5924 [ 56FB5F222EA30D3D3FC459879772CB73 ] CscService C:\Windows\System32\cscsvc.dll
13:32:11.0260 5924 CscService - ok
13:32:11.0293 5924 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\Windows\system32\rpcss.dll
13:32:11.0336 5924 DcomLaunch - ok
13:32:11.0375 5924 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
13:32:11.0420 5924 defragsvc - ok
13:32:11.0438 5924 [ 8E09E52EE2E3CEB199EF3DD99CF9E3FB ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:32:11.0471 5924 DfsC - ok
13:32:11.0513 5924 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\Windows\system32\dhcpcore.dll
13:32:11.0561 5924 Dhcp - ok
13:32:11.0576 5924 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
13:32:11.0618 5924 discache - ok
13:32:11.0651 5924 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
13:32:11.0662 5924 Disk - ok
13:32:11.0680 5924 [ D0722E963D3C6145446874241401B209 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:32:11.0712 5924 Dnscache - ok
13:32:11.0730 5924 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\Windows\System32\dot3svc.dll
13:32:11.0765 5924 dot3svc - ok
13:32:11.0782 5924 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\Windows\system32\dps.dll
13:32:11.0830 5924 DPS - ok
13:32:11.0856 5924 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:32:11.0873 5924 drmkaud - ok
13:32:11.0922 5924 [ 555E54AC2F601A8821CEF58961653991 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
13:32:11.0936 5924 dtsoftbus01 - ok
13:32:11.0983 5924 [ 39806CFEDDCC55E686A49BCCD2972F23 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:32:12.0033 5924 DXGKrnl - ok
13:32:12.0059 5924 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
13:32:12.0098 5924 EapHost - ok
13:32:12.0191 5924 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
13:32:12.0329 5924 ebdrv - ok
13:32:12.0352 5924 [ F42309C4191C506B71DB5D1126D26318 ] EFS C:\Windows\System32\lsass.exe
13:32:12.0369 5924 EFS - ok
13:32:12.0432 5924 [ 3A74A6E33685662B125A3269B1F2114F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:32:12.0484 5924 ehRecvr - ok
13:32:12.0501 5924 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
13:32:12.0532 5924 ehSched - ok
13:32:12.0604 5924 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
13:32:12.0625 5924 elxstor - ok
13:32:12.0647 5924 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
13:32:12.0674 5924 ErrDev - ok
13:32:12.0730 5924 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
13:32:12.0780 5924 EventSystem - ok
13:32:12.0816 5924 ew_hwusbdev - ok
13:32:12.0842 5924 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
13:32:12.0877 5924 exfat - ok
13:32:12.0898 5924 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:32:12.0942 5924 fastfat - ok
13:32:13.0002 5924 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\Windows\system32\fxssvc.exe
13:32:13.0048 5924 Fax - ok
13:32:13.0073 5924 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:32:13.0097 5924 fdc - ok
13:32:13.0110 5924 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
13:32:13.0150 5924 fdPHost - ok
13:32:13.0187 5924 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
13:32:13.0230 5924 FDResPub - ok
13:32:13.0249 5924 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:32:13.0260 5924 FileInfo - ok
13:32:13.0283 5924 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:32:13.0314 5924 Filetrace - ok
13:32:13.0333 5924 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:32:13.0354 5924 flpydisk - ok
13:32:13.0380 5924 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:32:13.0395 5924 FltMgr - ok
13:32:13.0444 5924 [ B6512A85815FDC3D560C3705F5BDB93D ] FontCache C:\Windows\system32\FntCache.dll
13:32:13.0491 5924 FontCache - ok
13:32:13.0538 5924 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:32:13.0548 5924 FontCache3.0.0.0 - ok
13:32:13.0570 5924 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
13:32:13.0582 5924 FsDepends - ok
13:32:13.0602 5924 [ A574B4360E438977038AAE4BF60D79A2 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:32:13.0614 5924 Fs_Rec - ok
13:32:13.0639 5924 [ 5592F5DBA26282D24D2B080EB438A4D7 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
13:32:13.0656 5924 fvevol - ok
13:32:13.0677 5924 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
13:32:13.0688 5924 gagp30kx - ok
13:32:13.0718 5924 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:32:13.0725 5924 GEARAspiWDM - ok
13:32:13.0771 5924 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\Windows\System32\gpsvc.dll
13:32:13.0808 5924 gpsvc - ok
13:32:13.0916 5924 [ E859CA020ED61899F3C74A8D0032D05C ] Guard.Mail.ru C:\Program Files\Guard-ICQ\GuardICQ.exe
13:32:13.0967 5924 Guard.Mail.ru - ok
13:32:14.0017 5924 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
13:32:14.0028 5924 gupdate - ok
13:32:14.0035 5924 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
13:32:14.0046 5924 gupdatem - ok
13:32:14.0082 5924 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
13:32:14.0094 5924 hamachi - ok
13:32:14.0122 5924 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
13:32:14.0155 5924 hcw85cir - ok
13:32:14.0187 5924 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:32:14.0226 5924 HdAudAddService - ok
13:32:14.0251 5924 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:32:14.0284 5924 HDAudBus - ok
13:32:14.0301 5924 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
13:32:14.0327 5924 HidBatt - ok
13:32:14.0348 5924 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
13:32:14.0380 5924 HidBth - ok
13:32:14.0404 5924 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
13:32:14.0422 5924 HidIr - ok
13:32:14.0447 5924 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll
13:32:14.0480 5924 hidserv - ok
13:32:14.0495 5924 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:32:14.0526 5924 HidUsb - ok
13:32:14.0557 5924 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:32:14.0590 5924 hkmsvc - ok
13:32:14.0613 5924 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:32:14.0652 5924 HomeGroupListener - ok
13:32:14.0689 5924 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:32:14.0714 5924 HomeGroupProvider - ok
13:32:14.0801 5924 [ F90DD89E8A482AC976DD4E1029802E49 ] HP LaserJet Service C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
13:32:14.0852 5924 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - warning
13:32:14.0852 5924 HP LaserJet Service - detected UnsignedFile.Multi.Generic (1)
13:32:14.0889 5924 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
13:32:14.0902 5924 HpSAMD - ok
13:32:14.0934 5924 [ 68C0BCE605769DA12996F653AF4CC1F5 ] HPSIService C:\Windows\system32\HPSIsvc.exe
13:32:14.0990 5924 HPSIService - ok
13:32:15.0014 5924 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:32:15.0064 5924 HTTP - ok
13:32:15.0093 5924 Huawei - ok
13:32:15.0124 5924 huawei_cdcacm - ok
13:32:15.0134 5924 huawei_enumerator - ok
13:32:15.0165 5924 hwdatacard - ok
13:32:15.0190 5924 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
13:32:15.0200 5924 hwpolicy - ok
13:32:15.0227 5924 hwusbdev - ok
13:32:15.0255 5924 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:32:15.0282 5924 i8042prt - ok
13:32:15.0310 5924 [ 934AF4D7C5F457B9F0743F4299B77B67 ] iaStorV C:\Windows\system32\DRIVERS\iaStorV.sys
13:32:15.0329 5924 iaStorV - ok
13:32:15.0404 5924 [ 9AC1E19D77BA038F24E2FAB5D95F70D3 ] ICQ Service C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
13:32:15.0419 5924 ICQ Service - ok
13:32:15.0480 5924 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:32:15.0521 5924 idsvc - ok
13:32:15.0540 5924 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
13:32:15.0551 5924 iirsp - ok
13:32:15.0614 5924 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\Windows\System32\ikeext.dll
13:32:15.0678 5924 IKEEXT - ok
13:32:15.0708 5924 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\DRIVERS\intelide.sys
13:32:15.0720 5924 intelide - ok
13:32:15.0739 5924 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:32:15.0765 5924 intelppm - ok
13:32:15.0792 5924 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:32:15.0828 5924 IPBusEnum - ok
13:32:15.0838 5924 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:32:15.0871 5924 IpFilterDriver - ok
13:32:15.0907 5924 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:32:15.0947 5924 iphlpsvc - ok
13:32:15.0969 5924 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
13:32:16.0002 5924 IPMIDRV - ok
13:32:16.0029 5924 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
13:32:16.0063 5924 IPNAT - ok
13:32:16.0116 5924 [ 066F2BBE2EEC9A42B065B552BF356B4E ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
13:32:16.0138 5924 iPod Service - ok
13:32:16.0156 5924 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:32:16.0180 5924 IRENUM - ok
13:32:16.0197 5924 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
13:32:16.0216 5924 isapnp - ok
13:32:16.0236 5924 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:32:16.0251 5924 iScsiPrt - ok
13:32:16.0273 5924 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:32:16.0283 5924 kbdclass - ok
13:32:16.0309 5924 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:32:16.0334 5924 kbdhid - ok
13:32:16.0358 5924 [ F42309C4191C506B71DB5D1126D26318 ] KeyIso C:\Windows\system32\lsass.exe
13:32:16.0375 5924 KeyIso - ok
13:32:16.0392 5924 [ E36A061EC11B373826905B21BE10948F ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:32:16.0403 5924 KSecDD - ok
13:32:16.0439 5924 [ 365C6154BBBC5377173F1CA7BFB6CC59 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
13:32:16.0452 5924 KSecPkg - ok
13:32:16.0485 5924 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
13:32:16.0525 5924 KtmRm - ok
13:32:16.0571 5924 [ BCA92CB047A4326925ECEF759DBAA233 ] LanmanServer C:\Windows\System32\srvsvc.dll
13:32:16.0606 5924 LanmanServer - ok
13:32:16.0638 5924 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:32:16.0673 5924 LanmanWorkstation - ok
13:32:16.0720 5924 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:32:16.0760 5924 lltdio - ok
13:32:16.0790 5924 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:32:16.0827 5924 lltdsvc - ok
13:32:16.0849 5924 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
13:32:16.0897 5924 lmhosts - ok
13:32:16.0925 5924 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
13:32:16.0938 5924 LSI_FC - ok
13:32:16.0983 5924 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
13:32:16.0996 5924 LSI_SAS - ok
13:32:17.0018 5924 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:32:17.0031 5924 LSI_SAS2 - ok
13:32:17.0052 5924 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:32:17.0066 5924 LSI_SCSI - ok
13:32:17.0086 5924 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
13:32:17.0133 5924 luafv - ok
13:32:17.0171 5924 [ A3E700D78EEC390F1208098CDCA5C6B6 ] MarvinBus C:\Windows\system32\DRIVERS\MarvinBus.sys
13:32:17.0245 5924 MarvinBus ( UnsignedFile.Multi.Generic ) - warning
13:32:17.0245 5924 MarvinBus - detected UnsignedFile.Multi.Generic (1)
13:32:17.0299 5924 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
13:32:17.0316 5924 MBAMProtector - ok
13:32:17.0391 5924 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
13:32:17.0409 5924 MBAMScheduler - ok
13:32:17.0457 5924 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
13:32:17.0481 5924 MBAMService - ok
13:32:17.0523 5924 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:32:17.0541 5924 Mcx2Svc - ok
13:32:17.0570 5924 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
13:32:17.0581 5924 megasas - ok
13:32:17.0607 5924 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
13:32:17.0625 5924 MegaSR - ok
13:32:17.0662 5924 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
13:32:17.0698 5924 MMCSS - ok
13:32:17.0724 5924 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
13:32:17.0767 5924 Modem - ok
13:32:17.0789 5924 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:32:17.0819 5924 monitor - ok
13:32:17.0841 5924 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:32:17.0851 5924 mouclass - ok
13:32:17.0872 5924 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:32:17.0887 5924 mouhid - ok
13:32:17.0901 5924 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
13:32:17.0914 5924 mountmgr - ok
13:32:18.0006 5924 [ 3B9398E0146855B1DC0E3D9769C80F01 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:32:18.0021 5924 MozillaMaintenance - ok
13:32:18.0089 5924 [ 24406D75B40F0F6B3C1AC7031D734565 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
13:32:18.0106 5924 MpFilter - ok
13:32:18.0148 5924 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\Windows\system32\DRIVERS\mpio.sys
13:32:18.0161 5924 mpio - ok
13:32:18.0287 5924 [ 06D4F934E09C359B0EFBFB3146F1D910 ] MpKslbb830c4d c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{65104186-7AF0-47DE-AD4E-97EA2A438D15}\MpKslbb830c4d.sys
13:32:18.0297 5924 MpKslbb830c4d - ok
13:32:18.0316 5924 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:32:18.0359 5924 mpsdrv - ok
13:32:18.0393 5924 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\Windows\system32\mpssvc.dll
13:32:18.0436 5924 MpsSvc - ok
13:32:18.0470 5924 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:32:18.0489 5924 MRxDAV - ok
13:32:18.0519 5924 [ F4A054BE78AF7F410129C4B64B07DC9B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:32:18.0562 5924 mrxsmb - ok
13:32:18.0584 5924 [ DEFFA295BD1895C6ED8E3078412AC60B ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:32:18.0624 5924 mrxsmb10 - ok
13:32:18.0681 5924 [ 24D76ABE5DCAD22F19D105F76FDF0CE1 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:32:18.0743 5924 mrxsmb20 - ok
13:32:18.0767 5924 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
13:32:18.0777 5924 msahci - ok
13:32:18.0814 5924 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
13:32:18.0828 5924 msdsm - ok
13:32:18.0867 5924 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
13:32:18.0898 5924 MSDTC - ok
13:32:18.0933 5924 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:32:18.0963 5924 Msfs - ok
13:32:18.0989 5924 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
13:32:19.0033 5924 mshidkmdf - ok
13:32:19.0054 5924 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
13:32:19.0064 5924 msisadrv - ok
13:32:19.0100 5924 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:32:19.0135 5924 MSiSCSI - ok
13:32:19.0145 5924 msiserver - ok
13:32:19.0171 5924 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:32:19.0219 5924 MSKSSRV - ok
13:32:19.0312 5924 [ 0A7F86657755ADA92C57E597BF5151F7 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
13:32:19.0322 5924 MsMpSvc - ok
13:32:19.0345 5924 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:32:19.0386 5924 MSPCLOCK - ok
13:32:19.0444 5924 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:32:19.0495 5924 MSPQM - ok
13:32:19.0531 5924 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:32:19.0545 5924 MsRPC - ok
13:32:19.0576 5924 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:32:19.0589 5924 mssmbios - ok
13:32:19.0683 5924 MSSQL$SONY_MEDIAMGR - ok
13:32:19.0745 5924 [ CB7524C21727404BD3140DCA32DEB7DE ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe
13:32:19.0764 5924 MSSQLServerADHelper ( UnsignedFile.Multi.Generic ) - warning
13:32:19.0764 5924 MSSQLServerADHelper - detected UnsignedFile.Multi.Generic (1)
13:32:19.0810 5924 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:32:19.0843 5924 MSTEE - ok
13:32:19.0870 5924 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
13:32:19.0894 5924 MTConfig - ok
13:32:19.0923 5924 [ BB16693616427EAC1A436E106EA8D318 ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys
13:32:19.0931 5924 MTsensor - ok
13:32:19.0956 5924 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
13:32:19.0967 5924 Mup - ok
13:32:20.0012 5924 [ DA52265242677E1C03B2560A03172612 ] mvusbews C:\Windows\system32\Drivers\mvusbews.sys
13:32:20.0043 5924 mvusbews - ok
13:32:20.0085 5924 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\Windows\system32\qagentRT.dll
13:32:20.0133 5924 napagent - ok
13:32:20.0177 5924 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:32:20.0213 5924 NativeWifiP - ok
13:32:20.0266 5924 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:32:20.0303 5924 NDIS - ok
13:32:20.0325 5924 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
13:32:20.0364 5924 NdisCap - ok
13:32:20.0383 5924 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:32:20.0415 5924 NdisTapi - ok
13:32:20.0434 5924 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:32:20.0467 5924 Ndisuio - ok
13:32:20.0492 5924 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:32:20.0526 5924 NdisWan - ok
13:32:20.0543 5924 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:32:20.0575 5924 NDProxy - ok
13:32:20.0655 5924 [ B90E093E7A7250906F1054418B5339C0 ] Nero BackItUp Scheduler 4.0 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
13:32:20.0706 5924 Nero BackItUp Scheduler 4.0 - ok
13:32:20.0723 5924 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:32:20.0754 5924 NetBIOS - ok
13:32:20.0776 5924 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
13:32:20.0810 5924 NetBT - ok
13:32:20.0825 5924 [ F42309C4191C506B71DB5D1126D26318 ] Netlogon C:\Windows\system32\lsass.exe
13:32:20.0841 5924 Netlogon - ok
13:32:20.0878 5924 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
13:32:20.0914 5924 Netman - ok
13:32:20.0939 5924 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
13:32:20.0980 5924 netprofm - ok
13:32:21.0063 5924 [ 27EE4B406E2F26F6117A9A420BD4CB65 ] netr28u C:\Windows\system32\DRIVERS\netr28u.sys
13:32:21.0093 5924 netr28u - ok
13:32:21.0127 5924 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:32:21.0139 5924 NetTcpPortSharing - ok
13:32:21.0169 5924 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
13:32:21.0182 5924 nfrd960 - ok
13:32:21.0247 5924 [ C58DB40E4C95BE8EE727BE872BE6383F ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
13:32:21.0260 5924 NisDrv - ok
13:32:21.0290 5924 [ 249D12488F9EE43B0D812C87335E0EF2 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
13:32:21.0307 5924 NisSrv - ok
13:32:21.0343 5924 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\Windows\System32\nlasvc.dll
13:32:21.0398 5924 NlaSvc - ok
13:32:21.0467 5924 [ 59194C84ACC776FD4B9A037030331E96 ] nlsX86cc C:\Windows\system32\NLSSRV32.EXE
13:32:21.0479 5924 nlsX86cc - ok
13:32:21.0507 5924 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:32:21.0541 5924 Npfs - ok
13:32:21.0570 5924 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
13:32:21.0602 5924 nsi - ok
13:32:21.0629 5924 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:32:21.0659 5924 nsiproxy - ok
13:32:21.0714 5924 [ 3795DCD21F740EE799FB7223234215AF ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:32:21.0771 5924 Ntfs - ok
13:32:21.0795 5924 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
13:32:21.0842 5924 Null - ok
13:32:21.0868 5924 [ 3F3D04B1D08D43C16EA7963954EC768D ] nvraid C:\Windows\system32\DRIVERS\nvraid.sys
13:32:21.0881 5924 nvraid - ok
13:32:21.0902 5924 [ C99F251A5DE63C6F129CF71933ACED0F ] nvstor C:\Windows\system32\DRIVERS\nvstor.sys
13:32:21.0916 5924 nvstor - ok
13:32:21.0938 5924 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
13:32:21.0951 5924 nv_agp - ok
13:32:21.0976 5924 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
13:32:22.0007 5924 ohci1394 - ok
13:32:22.0057 5924 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:32:22.0068 5924 ose - ok
13:32:22.0115 5924 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
13:32:22.0154 5924 p2pimsvc - ok
13:32:22.0198 5924 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
13:32:22.0221 5924 p2psvc - ok
13:32:22.0284 5924 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
13:32:22.0338 5924 Parport - ok
13:32:22.0412 5924 [ FF4218952B51DE44FE910953A3E686B9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:32:22.0423 5924 partmgr - ok
13:32:22.0456 5924 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
13:32:22.0471 5924 Parvdm - ok
13:32:22.0498 5924 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
13:32:22.0519 5924 PcaSvc - ok
13:32:22.0533 5924 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\Windows\system32\DRIVERS\pci.sys
13:32:22.0546 5924 pci - ok
13:32:22.0573 5924 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\DRIVERS\pciide.sys
13:32:22.0585 5924 pciide - ok
13:32:22.0611 5924 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
13:32:22.0626 5924 pcmcia - ok
13:32:22.0655 5924 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
13:32:22.0666 5924 pcw - ok
13:32:22.0696 5924 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:32:22.0753 5924 PEAUTH - ok
13:32:22.0809 5924 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
13:32:22.0885 5924 PeerDistSvc - ok
13:32:22.0981 5924 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\Windows\system32\pla.dll
13:32:23.0065 5924 pla - ok
13:32:23.0128 5924 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:32:23.0169 5924 PlugPlay - ok
13:32:23.0219 5924 [ 3A2BDD76E7D2A5F40A7174793D1BA794 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
13:32:23.0230 5924 PnkBstrA - ok
13:32:23.0259 5924 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
13:32:23.0287 5924 PNRPAutoReg - ok
13:32:23.0314 5924 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
13:32:23.0333 5924 PNRPsvc - ok
13:32:23.0409 5924 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:32:23.0461 5924 PolicyAgent - ok
13:32:23.0500 5924 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\Windows\system32\umpo.dll
13:32:23.0535 5924 Power - ok
13:32:23.0565 5924 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:32:23.0597 5924 PptpMiniport - ok
13:32:23.0622 5924 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
13:32:23.0650 5924 Processor - ok
13:32:23.0694 5924 [ 630CF26F0227498B7D5A92B12548960F ] ProfSvc C:\Windows\system32\profsvc.dll
13:32:23.0728 5924 ProfSvc - ok
13:32:23.0753 5924 [ F42309C4191C506B71DB5D1126D26318 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:32:23.0769 5924 ProtectedStorage - ok
13:32:23.0793 5924 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
13:32:23.0834 5924 Psched - ok
13:32:23.0889 5924 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
13:32:23.0959 5924 ql2300 - ok
13:32:23.0998 5924 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
13:32:24.0013 5924 ql40xx - ok
13:32:24.0055 5924 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
13:32:24.0092 5924 QWAVE - ok
13:32:24.0114 5924 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:32:24.0134 5924 QWAVEdrv - ok
13:32:24.0160 5924 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:32:24.0199 5924 RasAcd - ok
13:32:24.0217 5924 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
13:32:24.0262 5924 RasAgileVpn - ok
13:32:24.0299 5924 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
13:32:24.0334 5924 RasAuto - ok
13:32:24.0354 5924 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:32:24.0396 5924 Rasl2tp - ok
13:32:24.0429 5924 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\Windows\System32\rasmans.dll
13:32:24.0466 5924 RasMan - ok
13:32:24.0489 5924 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:32:24.0532 5924 RasPppoe - ok
13:32:24.0557 5924 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:32:24.0597 5924 RasSstp - ok
13:32:24.0620 5924 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:32:24.0656 5924 rdbss - ok
13:32:24.0692 5924 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
13:32:24.0710 5924 rdpbus - ok
13:32:24.0727 5924 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:32:24.0757 5924 RDPCDD - ok
13:32:24.0806 5924 [ C5FF95883FFEF704D50C40D21CFB3AB5 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
13:32:24.0836 5924 RDPDR - ok
13:32:24.0859 5924 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:32:24.0888 5924 RDPENCDD - ok
13:32:24.0922 5924 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
13:32:24.0960 5924 RDPREFMP - ok
13:32:24.0987 5924 [ 801371BA9782282892D00AADB08EE367 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:32:25.0024 5924 RDPWD - ok
13:32:25.0060 5924 [ 4EA225BF1CF05E158853F30A99CA29A7 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
13:32:25.0075 5924 rdyboost - ok
13:32:25.0124 5924 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
13:32:25.0170 5924 RemoteAccess - ok
13:32:25.0206 5924 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:32:25.0240 5924 RemoteRegistry - ok
13:32:25.0270 5924 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
13:32:25.0314 5924 RpcEptMapper - ok
13:32:25.0341 5924 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
13:32:25.0359 5924 RpcLocator - ok
13:32:25.0390 5924 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\Windows\system32\rpcss.dll
13:32:25.0434 5924 RpcSs - ok
13:32:25.0474 5924 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:32:25.0516 5924 rspndr - ok
13:32:25.0556 5924 [ 7DFD48E24479B68B258D8770121155A0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
13:32:25.0590 5924 RTL8167 - ok
13:32:25.0626 5924 [ 5423D8437051E89DD34749F242C98648 ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys
13:32:25.0653 5924 s3cap - ok
13:32:25.0679 5924 [ F42309C4191C506B71DB5D1126D26318 ] SamSs C:\Windows\system32\lsass.exe
13:32:25.0695 5924 SamSs - ok
13:32:25.0728 5924 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
13:32:25.0741 5924 sbp2port - ok
13:32:25.0780 5924 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:32:25.0831 5924 SCardSvr - ok
13:32:25.0864 5924 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
13:32:25.0905 5924 scfilter - ok
13:32:25.0943 5924 [ 3E8B0C453E25613A1F59762A5C42AA75 ] Schedule C:\Windows\system32\schedsvc.dll
13:32:26.0014 5924 Schedule - ok
13:32:26.0046 5924 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:32:26.0077 5924 SCPolicySvc - ok
13:32:26.0103 5924 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:32:26.0140 5924 SDRSVC - ok
13:32:26.0174 5924 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:32:26.0218 5924 secdrv - ok
13:32:26.0240 5924 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
13:32:26.0275 5924 seclogon - ok
13:32:26.0302 5924 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll
13:32:26.0344 5924 SENS - ok
13:32:26.0362 5924 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
13:32:26.0404 5924 SensrSvc - ok
13:32:26.0429 5924 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
13:32:26.0445 5924 Serenum - ok
13:32:26.0475 5924 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
13:32:26.0493 5924 Serial - ok
13:32:26.0505 5924 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
13:32:26.0537 5924 sermouse - ok
13:32:26.0596 5924 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\Windows\system32\sessenv.dll
13:32:26.0641 5924 SessionEnv - ok
13:32:26.0661 5924 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
13:32:26.0695 5924 sffdisk - ok
13:32:26.0723 5924 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys
13:32:26.0749 5924 sffp_mmc - ok
13:32:26.0775 5924 [ 4F1E5B0FE7C8050668DBFADE8999AEFB ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
13:32:26.0793 5924 sffp_sd - ok
13:32:26.0806 5924 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
13:32:26.0831 5924 sfloppy - ok
13:32:26.0873 5924 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:32:26.0912 5924 SharedAccess - ok
13:32:26.0952 5924 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:32:26.0991 5924 ShellHWDetection - ok
13:32:27.0021 5924 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\DRIVERS\sisagp.sys
13:32:27.0034 5924 sisagp - ok
13:32:27.0058 5924 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:32:27.0070 5924 SiSRaid2 - ok
13:32:27.0090 5924 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
13:32:27.0102 5924 SiSRaid4 - ok
13:32:27.0190 5924 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
13:32:27.0203 5924 SkypeUpdate - ok
13:32:27.0232 5924 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:32:27.0272 5924 Smb - ok
13:32:27.0328 5924 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:32:27.0347 5924 SNMPTRAP - ok
13:32:27.0432 5924 [ 060F51141B20B8156804446A04AB8B2A ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
13:32:27.0522 5924 SNP2UVC - ok
13:32:27.0566 5924 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
13:32:27.0576 5924 spldr - ok
13:32:27.0620 5924 [ 49B6DD6AB3715B7A67965F17194E98A9 ] Spooler C:\Windows\System32\spoolsv.exe
13:32:27.0655 5924 Spooler - ok
13:32:27.0751 5924 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\Windows\system32\sppsvc.exe
13:32:27.0862 5924 sppsvc - ok
13:32:27.0910 5924 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\Windows\system32\sppuinotify.dll
13:32:27.0945 5924 sppuinotify - ok
13:32:27.0983 5924 [ 614DEEA4BDCEC3FD5A07BDC705723AD7 ] sptd C:\Windows\System32\Drivers\sptd.sys
13:32:27.0983 5924 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: 614DEEA4BDCEC3FD5A07BDC705723AD7
13:32:27.0993 5924 sptd ( LockedFile.Multi.Generic ) - warning
13:32:27.0993 5924 sptd - detected LockedFile.Multi.Generic (1)
13:32:28.0005 5924 SQLAgent$SONY_MEDIAMGR - ok
13:32:28.0041 5924 [ 2BA4EBC7DFBA845A1EDBE1F75913BE33 ] srv C:\Windows\system32\DRIVERS\srv.sys
13:32:28.0078 5924 srv - ok
13:32:28.0100 5924 [ DCE7E10FEAABD4CAE95948B3DE5340BB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:32:28.0151 5924 srv2 - ok
13:32:28.0166 5924 [ B5665BAA2120B8A54E22E9CD07C05106 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:32:28.0199 5924 srvnet - ok
13:32:28.0237 5924 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:32:28.0271 5924 SSDPSRV - ok
13:32:28.0312 5924 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:32:28.0355 5924 SstpSvc - ok
13:32:28.0391 5924 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
13:32:28.0403 5924 stexstor - ok
13:32:28.0452 5924 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\Windows\System32\wiaservc.dll
13:32:28.0482 5924 StiSvc - ok
13:32:28.0519 5924 [ 957E346CA948668F2496A6CCF6FF82CC ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
13:32:28.0531 5924 storflt - ok
13:32:28.0555 5924 [ 0BF669F0A910BEDA4A32258D363AF2A5 ] StorSvc C:\Windows\system32\storsvc.dll
13:32:28.0586 5924 StorSvc - ok
13:32:28.0614 5924 [ D5751969DC3E4B88BF482AC8EC9FE019 ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys
13:32:28.0625 5924 storvsc - ok
13:32:28.0660 5924 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:32:28.0669 5924 swenum - ok
13:32:28.0746 5924 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
13:32:28.0771 5924 SwitchBoard ( UnsignedFile.Multi.Generic ) - warning
13:32:28.0771 5924 SwitchBoard - detected UnsignedFile.Multi.Generic (1)
13:32:28.0819 5924 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
13:32:28.0858 5924 swprv - ok
13:32:28.0909 5924 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\Windows\system32\sysmain.dll
13:32:28.0974 5924 SysMain - ok
13:32:29.0005 5924 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:32:29.0033 5924 TabletInputService - ok
13:32:29.0064 5924 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\Windows\System32\tapisrv.dll
13:32:29.0099 5924 TapiSrv - ok
13:32:29.0131 5924 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
13:32:29.0172 5924 TBS - ok
13:32:29.0240 5924 [ 63170B9EE1D0EF0032F0408605671D1A ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:32:29.0297 5924 Tcpip - ok
13:32:29.0350 5924 [ 63170B9EE1D0EF0032F0408605671D1A ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
13:32:29.0382 5924 TCPIP6 - ok
13:32:29.0421 5924 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:32:29.0466 5924 tcpipreg - ok
13:32:29.0503 5924 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:32:29.0533 5924 TDPIPE - ok
13:32:29.0547 5924 [ 7551E91EA999EE9A8E9C331D5A9C31F3 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:32:29.0578 5924 TDTCP - ok
13:32:29.0604 5924 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:32:29.0638 5924 tdx - ok
13:32:29.0656 5924 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:32:29.0668 5924 TermDD - ok
13:32:29.0721 5924 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\Windows\System32\termsrv.dll
13:32:29.0765 5924 TermService - ok
13:32:29.0793 5924 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
13:32:29.0814 5924 Themes - ok
13:32:29.0834 5924 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
13:32:29.0866 5924 THREADORDER - ok
13:32:29.0891 5924 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
13:32:29.0938 5924 TrkWks - ok
13:32:29.0998 5924 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:32:30.0017 5924 TrustedInstaller - ok
13:32:30.0057 5924 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:32:30.0091 5924 tssecsrv - ok
13:32:30.0193 5924 [ 947A68C3928FF7B185E1732E24C0201C ] TuneUp.UtilitiesSvc C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
13:32:30.0252 5924 TuneUp.UtilitiesSvc - ok
13:32:30.0289 5924 [ 94C4CD2D19B8C4137A46261F229FEC24 ] TuneUpUtilitiesDrv C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys
13:32:30.0298 5924 TuneUpUtilitiesDrv - ok
13:32:30.0343 5924 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:32:30.0376 5924 tunnel - ok
13:32:30.0397 5924 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
13:32:30.0410 5924 uagp35 - ok
13:32:30.0435 5924 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:32:30.0472 5924 udfs - ok
13:32:30.0536 5924 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:32:30.0568 5924 UI0Detect - ok
13:32:30.0599 5924 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
13:32:30.0611 5924 uliagpkx - ok
13:32:30.0635 5924 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:32:30.0658 5924 umbus - ok
13:32:30.0686 5924 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
13:32:30.0718 5924 UmPass - ok
13:32:30.0759 5924 [ 8ECACA5454844F66386F7BE4AE0D7CD1 ] UmRdpService C:\Windows\System32\umrdp.dll
13:32:30.0779 5924 UmRdpService - ok
13:32:30.0827 5924 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
13:32:30.0864 5924 upnphost - ok
13:32:30.0915 5924 [ 6E421CCC57059B0186C6259CA3B6DFC9 ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys
13:32:30.0975 5924 USBAAPL - ok
13:32:31.0006 5924 [ 8455C4ED038EFD09E99327F9D2D48FFA ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:32:31.0032 5924 usbccgp - ok
13:32:31.0057 5924 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
13:32:31.0086 5924 usbcir - ok
13:32:31.0112 5924 [ 1C333BFD60F2FED2C7AD5DAF533CB742 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:32:31.0131 5924 usbehci - ok
13:32:31.0168 5924 [ EE6EF93CCFA94FAE8C6AB298273D8AE2 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:32:31.0187 5924 usbhub - ok
13:32:31.0216 5924 [ A6FB7957EA7AFB1165991E54CE934B74 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
13:32:31.0231 5924 usbohci - ok
13:32:31.0260 5924 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:32:31.0295 5924 usbprint - ok
13:32:31.0337 5924 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:32:31.0353 5924 usbscan - ok
13:32:31.0394 5924 [ D8889D56E0D27E57ED4591837FE71D27 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:32:31.0410 5924 USBSTOR - ok
13:32:31.0453 5924 [ 78780C3EBCE17405B1CCD07A3A8A7D72 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:32:31.0484 5924 usbuhci - ok
13:32:31.0536 5924 [ F642A7E4BF78CFA359CCA0A3557C28D7 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:32:31.0555 5924 usbvideo - ok
13:32:31.0620 5924 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
13:32:31.0665 5924 UxSms - ok
13:32:31.0722 5924 [ 1E9C5F658C0BACEFD1232011FF8B90A0 ] UxTuneUp C:\Windows\System32\uxtuneup.dll
13:32:31.0733 5924 UxTuneUp - ok
13:32:31.0753 5924 [ F42309C4191C506B71DB5D1126D26318 ] VaultSvc C:\Windows\system32\lsass.exe
13:32:31.0768 5924 VaultSvc - ok
13:32:31.0816 5924 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
13:32:31.0827 5924 vdrvroot - ok
13:32:31.0883 5924 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\Windows\System32\vds.exe
13:32:31.0937 5924 vds - ok
13:32:31.0958 5924 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:32:31.0976 5924 vga - ok
13:32:32.0006 5924 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
13:32:32.0037 5924 VgaSave - ok
13:32:32.0074 5924 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
13:32:32.0089 5924 vhdmp - ok
13:32:32.0119 5924 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\DRIVERS\viaagp.sys
13:32:32.0132 5924 viaagp - ok
13:32:32.0148 5924 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
13:32:32.0174 5924 ViaC7 - ok
13:32:32.0196 5924 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\DRIVERS\viaide.sys
13:32:32.0207 5924 viaide - ok
13:32:32.0240 5924 [ 379B349F65F453D2A6E75EA6B7448E49 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
13:32:32.0255 5924 vmbus - ok
13:32:32.0281 5924 [ EC2BBAB4B84D0738C6C83D2234DC36FE ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
13:32:32.0295 5924 VMBusHID - ok
13:32:32.0327 5924 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
13:32:32.0337 5924 volmgr - ok
13:32:32.0356 5924 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:32:32.0374 5924 volmgrx - ok
13:32:32.0393 5924 [ 58DF9D2481A56EDDE167E51B334D44FD ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
13:32:32.0408 5924 volsnap - ok
13:32:32.0440 5924 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
13:32:32.0454 5924 vsmraid - ok
13:32:32.0606 5924 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\Windows\system32\vssvc.exe
13:32:32.0712 5924 VSS - ok
13:32:32.0748 5924 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
13:32:32.0772 5924 vwifibus - ok
13:32:32.0799 5924 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
13:32:32.0818 5924 vwififlt - ok
13:32:32.0850 5924 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
13:32:32.0867 5924 vwifimp - ok
13:32:32.0919 5924 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
13:32:32.0958 5924 W32Time - ok
13:32:32.0992 5924 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
13:32:33.0007 5924 WacomPen - ok
13:32:33.0038 5924 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
13:32:33.0070 5924 WANARP - ok
13:32:33.0084 5924 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:32:33.0113 5924 Wanarpv6 - ok
13:32:33.0231 5924 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
13:32:33.0288 5924 WatAdminSvc - ok
13:32:33.0344 5924 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\Windows\system32\wbengine.exe
13:32:33.0414 5924 wbengine - ok
13:32:33.0433 5924 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
13:32:33.0455 5924 WbioSrvc - ok
13:32:33.0478 5924 [ D0F88AA11EE1A62BCC6D6A8A7783CA11 ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:32:33.0515 5924 wcncsvc - ok
13:32:33.0532 5924 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:32:33.0570 5924 WcsPlugInService - ok
13:32:33.0611 5924 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
13:32:33.0623 5924 Wd - ok
13:32:33.0663 5924 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:32:33.0684 5924 Wdf01000 - ok
13:32:33.0724 5924 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:32:33.0744 5924 WdiServiceHost - ok
13:32:33.0759 5924 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:32:33.0777 5924 WdiSystemHost - ok
13:32:33.0810 5924 [ D87C7D2C517F82A5AB7A73E203063D9E ] WebClient C:\Windows\System32\webclnt.dll
13:32:33.0834 5924 WebClient - ok
13:32:33.0852 5924 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:32:33.0888 5924 Wecsvc - ok
13:32:33.0911 5924 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:32:33.0943 5924 wercplsupport - ok
13:32:33.0967 5924 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
13:32:34.0001 5924 WerSvc - ok
13:32:34.0037 5924 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
13:32:34.0067 5924 WfpLwf - ok
13:32:34.0092 5924 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
13:32:34.0103 5924 WIMMount - ok
13:32:34.0177 5924 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
13:32:34.0219 5924 WinDefend - ok
13:32:34.0247 5924 WinHttpAutoProxySvc - ok
13:32:34.0308 5924 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:32:34.0340 5924 Winmgmt - ok
13:32:34.0402 5924 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\Windows\system32\WsmSvc.dll
13:32:34.0478 5924 WinRM - ok
13:32:34.0546 5924 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
13:32:34.0563 5924 WinUsb - ok
13:32:34.0620 5924 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:32:34.0662 5924 Wlansvc - ok
13:32:34.0695 5924 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
13:32:34.0722 5924 WmiAcpi - ok
13:32:34.0772 5924 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:32:34.0790 5924 wmiApSrv - ok
13:32:34.0874 5924 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:32:34.0927 5924 WMPNetworkSvc - ok
13:32:35.0017 5924 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:32:35.0047 5924 WPCSvc - ok
13:32:35.0087 5924 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:32:35.0097 5924 WPDBusEnum - ok
13:32:35.0127 5924 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:32:35.0167 5924 ws2ifsl - ok
13:32:35.0207 5924 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\system32\wscsvc.dll
13:32:35.0227 5924 wscsvc - ok
13:32:35.0237 5924 WSearch - ok
13:32:35.0337 5924 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
13:32:35.0427 5924 wuauserv - ok
13:32:35.0467 5924 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
13:32:35.0507 5924 WudfPf - ok
13:32:35.0537 5924 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:32:35.0577 5924 WUDFRd - ok
13:32:35.0597 5924 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:32:35.0637 5924 wudfsvc - ok
13:32:35.0657 5924 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
13:32:35.0687 5924 WwanSvc - ok
13:32:35.0767 5924 ================ Scan global ===============================
13:32:35.0807 5924 [ 9A595DF601070DA78C40481120DD2C06 ] C:\Windows\system32\basesrv.dll
13:32:35.0847 5924 [ 8531AAF69394EFB93BC653916C46D245 ] C:\Windows\system32\winsrv.dll
13:32:35.0857 5924 [ 8531AAF69394EFB93BC653916C46D245 ] C:\Windows\system32\winsrv.dll
13:32:35.0887 5924 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
13:32:35.0927 5924 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
13:32:35.0927 5924 [Global] - ok
13:32:35.0927 5924 ================ Scan MBR ==================================
13:32:35.0957 5924 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:32:36.0757 5924 \Device\Harddisk0\DR0 - ok
13:32:36.0757 5924 ================ Scan VBR ==================================
13:32:36.0797 5924 [ 4C86F0FFF786B44FDEF19B827FE7FE79 ] \Device\Harddisk0\DR0\Partition1
13:32:36.0797 5924 \Device\Harddisk0\DR0\Partition1 - ok
13:32:36.0807 5924 [ 4289058E5DC4710CFEC5471E83E572E2 ] \Device\Harddisk0\DR0\Partition2
13:32:36.0807 5924 \Device\Harddisk0\DR0\Partition2 - ok
13:32:36.0827 5924 [ BE8CA48FD8DD6084A1F6BC05A904CE7E ] \Device\Harddisk0\DR0\Partition3
13:32:36.0827 5924 \Device\Harddisk0\DR0\Partition3 - ok
13:32:36.0827 5924 ============================================================
13:32:36.0827 5924 Scan finished
13:32:36.0827 5924 ============================================================
13:32:36.0847 3700 Detected object count: 5
13:32:36.0847 3700 Actual detected object count: 5
13:33:15.0121 3700 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - skipped by user
13:33:15.0121 3700 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:33:15.0121 3700 MarvinBus ( UnsignedFile.Multi.Generic ) - skipped by user
13:33:15.0121 3700 MarvinBus ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:33:15.0121 3700 MSSQLServerADHelper ( UnsignedFile.Multi.Generic ) - skipped by user
13:33:15.0121 3700 MSSQLServerADHelper ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:33:15.0121 3700 sptd ( LockedFile.Multi.Generic ) - skipped by user
13:33:15.0121 3700 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
13:33:15.0121 3700 SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user
13:33:15.0121 3700 SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:33:35.0492 3904 Deinitialize success

Re: Samovoľné písanie

Napsal: 23 pro 2013 01:00
od Davidkooo
Jasne po sviatkach sa ozvem či to všetko ide ako ma =), zatial diky za všetko prijemne sviatky.

Hadžem sem log z MBAM


Malwarebytes Anti-Malware (Skúšobná verzia) 1.75.0.1300
http://www.malwarebytes.org

Verzia databázy: v2013.12.01.03

Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
PC :: PC-PC [administrátor]

Ochrana: Zapnuté

1. 12. 2013 17:48:08
mbam-log-2013-12-01 (17-48-08).txt

Typ kontroly: Úplná kontrola (C:\|D:\|I:\|)
Možnosti kontroly zapnuté: Pamäť | Po spustení | Registre | Systémové súbory | Heuristika/Extra | Heuristika/Shuriken | PUP | PUM
Možnosti kontroly vypnuté: P2P
Objektov kontrolovaných: 429848
Uplynutý čas: 2 hod, 18 min, 21 sek

Detegované služby pamäte: 0
(Škodlivé položky neboli zistené)

Detegované moduly pamäte: 0
(Škodlivé položky neboli zistené)

Detegované registračné kľúče: 1
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CHROME.EXE (Security.Hijack) -> Pridanie do karantény a zmazanie úspešné.

Detegované registračné hodnoty: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe|Debugger (Security.Hijack) -> Dáta: "C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe" -> Pridanie do karantény a zmazanie úspešné.

Detegované položky registračných dát: 0
(Škodlivé položky neboli zistené)

Detegované priečinky: 2
C:\Users\PC\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Pridanie do karantény a zmazanie úspešné.
C:\Users\PC\AppData\Roaming\OpenCandy\1CC0EED9C8FE488F8171BA4223A703D2 (PUP.Optional.OpenCandy) -> Pridanie do karantény a zmazanie úspešné.

Detegované súbory: 1
C:\Windows\Installer\13543b6.msi (PUP.Optional.Spigot.A) -> Pridanie do karantény a zmazanie úspešné.

(koniec)

Re: Samovoľné písanie

Napsal: 31 pro 2013 10:20
od Davidkooo
A& mam to na&spet za&s& mi to piše& ti&e znaky.

Ahoj zas mi to začalo vypisovat ako môžeš vidiet vyšie, samovolne mi to pri pisani vypisuje znaky. Neviem aka haved to môže byt ...

Re: Samovoľné písanie

Napsal: 31 pro 2013 15:26
od Davidkooo
Ved prave že to neviem presne ... môžem to dat aj z hruba& ?

Re: Samovoľné písanie

Napsal: 31 pro 2013 19:08
od Davidkooo
Každy jeden bod obnovi je iba z prosinca, je to možné ?

Re: Samovoľné písanie

Napsal: 18 led 2014 12:27
od Davidkooo
Ahoj tu je ten log,

Logfile of random's system information tool 1.09 (written by random/random)
Run by PC at 2014-01-18 12:16:25
Microsoft Windows 7 Professional
System drive C: has 172 GB (70%) free of 246 GB
Total RAM: 3327 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:16:54, on 18. 1. 2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\PC\Desktop\RSIT.exe
C:\Program Files\trend micro\PC.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - (no file)
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Unibet - {1B3C7793-B163-40C0-B949-B1D5C9BEB7FA} - C:\Microgaming\Poker\unibetpokerMPP\MPPoker.exe (HKCU)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Guard.Mail.ru - Unknown owner - C:\Program Files\Guard-ICQ\GuardICQ.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: ICQ Service - Unknown owner - C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe

--
End of file - 7585 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4167722851-2380944550-1776531285-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4167722851-2380944550-1776531285-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4167722851-2380944550-1776531285-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4167722851-2380944550-1776531285-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\76uq7fni.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "www.google.sk"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.01, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.enabled" - false

"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
"{6904342A-8307-11DF-A508-4AE2DFD72085}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
"quickprint@hp.com"=C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=Doplnok iTunes Detector
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0]
"Description"=DivX OVS Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFFICE.DLL
nppdf32.dll
npwachk.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
fcmdSrchddr.xml
yahoo.xml

C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\76uq7fni.default\extensions\
toolbar@ask.com
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}

C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\76uq7fni.default\searchplugins\
conduit.xml
daemon-search.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
winamp-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2011-03-11 1373512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video>

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-18 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14 4531320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-18 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2011-03-11 1373512]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2012-03-20 1056320]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"=C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [2008-09-02 8105984]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-11-10 98304]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"HControlUser"=C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [2008-08-18 98304]
"Avira Systray"=C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [2013-12-16 174648]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2013-12-09 684600]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 354304]
"ApplePhotoStreams"=C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [2013-04-05 59720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-16 138096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.DIVX"=DivX.dll
"VIDC.CFHD"=cfhd.dll
"vidc.yv12"=yv12vfw.dll
"vidc.i420"=i420vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-01-18 12:16:25 ----D---- C:\rsit
2014-01-18 12:16:25 ----D---- C:\Program Files\trend micro
2014-01-17 10:38:25 ----A---- C:\Windows\system32\javaws.exe
2014-01-17 10:38:18 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2014-01-17 10:38:18 ----A---- C:\Windows\system32\javaw.exe
2014-01-17 10:38:18 ----A---- C:\Windows\system32\java.exe
2013-12-23 11:02:42 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2013-12-23 01:42:56 ----D---- C:\Users\PC\AppData\Roaming\Avira
2013-12-23 01:36:21 ----A---- C:\Windows\system32\drivers\ssmdrv.sys
2013-12-23 01:36:09 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2013-12-23 01:36:09 ----A---- C:\Windows\system32\drivers\avipbb.sys
2013-12-23 01:36:09 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2013-12-23 01:29:42 ----D---- C:\ProgramData\Avira
2013-12-23 01:29:42 ----D---- C:\Program Files\Avira
2013-12-23 01:29:35 ----D---- C:\ProgramData\Package Cache
2013-12-22 13:31:30 ----A---- C:\TDSSKiller.2.8.16.0_22.12.2013_13.31.30_log.txt
2013-12-21 19:06:48 ----SHD---- C:\$RECYCLE.BIN
2013-12-21 19:06:43 ----D---- C:\Windows\temp
2013-12-21 19:06:41 ----A---- C:\ComboFix.txt
2013-12-21 18:53:36 ----A---- C:\Windows\zip.exe
2013-12-21 18:53:36 ----A---- C:\Windows\SWSC.exe
2013-12-21 18:53:36 ----A---- C:\Windows\SWREG.exe
2013-12-21 18:53:36 ----A---- C:\Windows\sed.exe
2013-12-21 18:53:36 ----A---- C:\Windows\PEV.exe
2013-12-21 18:53:36 ----A---- C:\Windows\NIRCMD.exe
2013-12-21 18:53:36 ----A---- C:\Windows\MBR.exe
2013-12-21 18:53:36 ----A---- C:\Windows\grep.exe
2013-12-21 18:53:08 ----D---- C:\Qoobox
2013-12-21 18:52:52 ----D---- C:\Windows\erdnt
2013-12-21 11:50:29 ----D---- C:\Program Files\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2014-01-18 12:16:38 ----D---- C:\Windows\Prefetch
2014-01-18 12:16:25 ----D---- C:\Program Files
2014-01-18 11:45:31 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-01-18 11:43:36 ----D---- C:\Windows\System32
2014-01-18 11:43:35 ----D---- C:\Windows\inf
2014-01-18 11:43:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-01-17 10:42:19 ----D---- C:\ProgramData\Oracle
2014-01-17 10:38:30 ----SHD---- C:\Windows\Installer
2014-01-17 10:38:18 ----D---- C:\Program Files\Java
2014-01-17 10:37:26 ----SHD---- C:\System Volume Information
2014-01-02 01:30:05 ----D---- C:\Program Files\Steam
2013-12-31 19:17:36 ----D---- C:\Windows\system32\config
2013-12-31 00:51:38 ----D---- C:\Users\PC\AppData\Roaming\vlc
2013-12-27 12:48:56 ----D---- C:\Program Files\Common Files\Steam
2013-12-24 11:59:06 ----D---- C:\Users\PC\AppData\Roaming\Microgaming
2013-12-23 11:02:42 ----D---- C:\Windows\system32\drivers
2013-12-23 01:36:39 ----D---- C:\Windows\system32\catroot
2013-12-23 01:29:42 ----D---- C:\ProgramData
2013-12-22 13:09:47 ----D---- C:\Windows\system32\catroot2
2013-12-21 19:19:21 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-12-21 19:06:43 ----AD---- C:\Windows
2013-12-21 19:04:38 ----A---- C:\Windows\system.ini
2013-12-21 19:04:27 ----D---- C:\Windows\system32\drivers\etc
2013-12-21 19:00:25 ----D---- C:\Windows\AppPatch
2013-12-21 19:00:24 ----D---- C:\Program Files\Common Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 14392]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-06-18 211560]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-04-17 431672]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2013-03-07 21576]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2013-12-09 135648]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2013-12-09 37352]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-29 218688]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2013-12-09 28520]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2013-12-09 90400]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-11-11 5092864]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2008-12-24 14392]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2008-08-11 1752704]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [2012-09-19 10088]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS [2009-08-21 27136]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 catchme;catchme; \??\C:\Users\PC\AppData\Local\Temp\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys []
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys []
S3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2011-04-16 17408]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista; C:\Windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2012-12-13 45056]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S4 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-11-11 172032]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2013-12-09 440376]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2013-12-09 440376]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 ASLDRService;ASLDR Service; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [2008-08-13 100920]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [2013-12-16 103480]
R2 Guard.Mail.ru;Guard.Mail.ru; C:\Program Files\Guard-ICQ\GuardICQ.exe [2013-02-02 1564368]
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [2009-10-15 136192]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2011-05-18 99896]
R2 ICQ Service;ICQ Service; C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE [2012-03-20 247872]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-08-12 22208]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-20 935208]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\system32\NLSSRV32.EXE [2012-10-09 69640]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2013-07-07 75136]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2012-09-19 1699168]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-08-12 295376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-18 257928]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 553288]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-21 119408]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2013-12-11 569768]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-12-04 1343400]
S4 AntiVirWebService;Avira Web Protection; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [2013-12-09 1011768]
S4 APNMCP;Ask Update Service; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-10-15 166352]
S4 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2013-07-05 807800]
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-14 136176]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-14 136176]
S4 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
S4 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-06-21 162408]
S4 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]

-----------------EOF-----------------