Stránka 1 z 2

Preventivka

Napsal: 23 pro 2013 21:18
od Blare
Dobry den, na notas mi zacina nieco liezt... pozreli by ste sa na to?
Dakujem a prajem krasne sviatky :)


Logfile of random's system information tool 1.09 (written by random/random)
Run by Turbo at 2013-12-23 21:06:43
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 42 GB (16%) free of 260 GB
Total RAM: 3063 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:06:47, on 23. 12. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
C:\Program Files\Lenovo\VeriFace\PManage.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Genius\ioCentre\gTaskBar.exe
C:\windows\system32\taskhost.exe
C:\Program Files\Lenovo\YouCam\YCMMirage.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Genius\ioCentre\gMouseTask.exe
C:\Genius\ioCentre\gKbdTask.exe
C:\Genius\ioCentre\gIoCentreFunMgm.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
C:\Users\Turbo\Downloads\RSIT.exe
C:\Program Files\trend micro\Turbo.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [OnekeyStudio] C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files\Lenovo\YouCam\YouCam.exe" /s
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Turbo\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\RunOnce: [WLStart] "C:\Program Files\Windows Live\Installer\wlstart.exe" /nosearch /nohomepage (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WLStart] "C:\Program Files\Windows Live\Installer\wlstart.exe" /nosearch /nohomepage (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

--
End of file - 8680 bytes

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3825014317-2607772001-1910489964-1003Core1ceebb13a91d691.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3825014317-2607772001-1910489964-1003UA1ceebb13ad1ecd7.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.facebook.com/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@cambridgesoft.com/Chem3D,version=12.0]
"Description"=CambridgeSoft Chem3D Plugin 12.0
"Path"=C:\Program Files\CambridgeSoft\ChemOffice2010\Chem3D\npChem3DPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@cambridgesoft.com/ChemDraw,version=12.0]
"Description"=CambridgeSoft ChemDraw Plugin 12.0
"Path"=C:\Program Files\CambridgeSoft\ChemOffice2010\ChemDraw\npcdp32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
nsILegitCheckPlugin.xpt
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npLegitCheckPlugin.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-11-28 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-11-28 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [2009-11-16 487992]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-11-24 501640]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2009-12-19 665504]
"VeriFaceManager"=C:\Program Files\Lenovo\VeriFace\PManage.exe [2010-02-06 3122528]
"EnergyUtility"=C:\Program Files\Lenovo\Energy Management\utility.exe [2009-12-17 4114368]
"Energy Management"=C:\Program Files\Lenovo\Energy Management\Energy Management.exe [2009-12-17 6223808]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2009-09-03 61440]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"YouCam Mirage"=C:\Program Files\Lenovo\YouCam\YCMMirage.exe [2011-01-11 136488]
"YouCam Tray"=C:\Program Files\Lenovo\YouCam\YouCam.exe [2011-01-11 228448]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2013-09-12 5110672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"Google Update"=C:\Users\Turbo\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe [2013-04-19 1090912]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2013-11-11 208384]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=28
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.clmp3enc"=C:\PROGRA~1\Lenovo\Power2Go\CLMP3Enc.ACM
"msacm.siren"=sirenacm.dll
"vidc.XVID"=xvidvfw.dll
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"vidc.VP60"=C:\windows\system32\vp6vfw.dll
"vidc.VP61"=C:\windows\system32\vp6vfw.dll
"vidc.tscc"=tsccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2013-12-23 21:00:04 ----D---- C:\ProgramData\SecTaskMan
2013-12-11 14:58:52 ----A---- C:\windows\system32\ie4uinit.exe
2013-12-11 14:58:51 ----A---- C:\windows\system32\jsproxy.dll
2013-12-11 14:58:50 ----A---- C:\windows\system32\ieui.dll
2013-12-11 14:58:50 ----A---- C:\windows\system32\ieetwcollectorres.dll
2013-12-11 14:58:50 ----A---- C:\windows\system32\ieapfltr.dll
2013-12-11 14:58:49 ----A---- C:\windows\system32\jscript9diag.dll
2013-12-11 14:58:49 ----A---- C:\windows\system32\ieUnatt.exe
2013-12-11 14:58:49 ----A---- C:\windows\system32\iesetup.dll
2013-12-11 14:58:49 ----A---- C:\windows\system32\iernonce.dll
2013-12-11 14:58:49 ----A---- C:\windows\system32\ieetwproxystub.dll
2013-12-11 14:58:48 ----A---- C:\windows\system32\ieetwcollector.exe
2013-12-11 14:58:47 ----A---- C:\windows\system32\wininet.dll
2013-12-11 14:58:46 ----A---- C:\windows\system32\urlmon.dll
2013-12-11 14:58:46 ----A---- C:\windows\system32\iertutil.dll
2013-12-11 14:58:44 ----A---- C:\windows\system32\ieframe.dll
2013-12-11 14:58:43 ----A---- C:\windows\system32\mshtml.dll
2013-12-11 14:58:42 ----A---- C:\windows\system32\jscript9.dll
2013-12-11 14:46:51 ----A---- C:\windows\system32\wmp.dll
2013-12-11 14:46:50 ----A---- C:\windows\system32\wmploc.DLL
2013-12-11 14:45:45 ----A---- C:\windows\system32\imagehlp.dll
2013-12-11 14:45:16 ----A---- C:\windows\system32\tzres.dll
2013-12-11 14:44:42 ----A---- C:\windows\system32\msieftp.dll
2013-12-11 14:44:39 ----A---- C:\windows\system32\wscript.exe
2013-12-11 14:44:39 ----A---- C:\windows\system32\scrrun.dll
2013-12-11 14:44:39 ----A---- C:\windows\system32\cscript.exe
2013-12-11 14:44:36 ----A---- C:\windows\system32\WMPhoto.dll
2013-12-11 14:44:29 ----A---- C:\windows\system32\win32k.sys
2013-12-11 14:44:26 ----A---- C:\windows\system32\drivers\portcls.sys
2013-12-11 14:44:26 ----A---- C:\windows\system32\drivers\drmk.sys
2013-12-04 02:23:26 ----A---- C:\windows\system32\nvhdap32.dll
2013-12-04 02:23:26 ----A---- C:\windows\system32\nvhdagenco32.dll
2013-12-04 02:23:26 ----A---- C:\windows\system32\drivers\nvhda32v.sys
2013-11-28 22:54:46 ----D---- C:\ProgramData\Oracle
2013-11-28 22:54:42 ----D---- C:\Program Files\Common Files\Java
2013-11-28 22:54:38 ----A---- C:\windows\system32\javaws.exe
2013-11-28 22:54:31 ----A---- C:\windows\system32\WindowsAccessBridge.dll
2013-11-28 21:27:10 ----D---- C:\Program Files\Mozilla Firefox
2013-11-27 08:22:10 ----D---- C:\windows\Migration

======List of files/folders modified in the last 1 month======

2013-12-23 21:06:44 ----D---- C:\Program Files\trend micro
2013-12-23 21:04:18 ----RD---- C:\Program Files
2013-12-23 21:04:18 ----D---- C:\ProgramData
2013-12-23 21:03:56 ----A---- C:\windows\system32\FlashPlayerApp.exe
2013-12-23 21:03:53 ----D---- C:\windows\temp
2013-12-23 21:02:22 ----D---- C:\windows\Prefetch
2013-12-23 20:59:27 ----D---- C:\windows\system32\config
2013-12-23 20:46:44 ----D---- C:\ProgramData\VeriFace
2013-12-23 20:46:34 ----A---- C:\windows\system32\log.txt
2013-12-23 20:46:32 ----D---- C:\Windows
2013-12-23 20:46:31 ----D---- C:\ProgramData\NVIDIA
2013-12-23 16:16:19 ----D---- C:\windows\SoftwareDistribution
2013-12-20 17:53:08 ----D---- C:\Program Files\Warcraft III
2013-12-18 08:50:25 ----D---- C:\Users\Turbo\AppData\Roaming\vlc
2013-12-14 22:39:05 ----D---- C:\Filmy
2013-12-14 20:54:07 ----D---- C:\Users\Turbo\AppData\Roaming\Skype
2013-12-12 20:47:31 ----D---- C:\windows\System32
2013-12-12 20:47:31 ----D---- C:\windows\inf
2013-12-12 20:47:31 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-12-12 07:01:07 ----D---- C:\windows\system32\catroot2
2013-12-11 19:53:56 ----D---- C:\windows\rescache
2013-12-11 17:41:56 ----D---- C:\windows\debug
2013-12-11 15:18:18 ----D---- C:\windows\winsxs
2013-12-11 15:15:44 ----D---- C:\windows\system32\sk-SK
2013-12-11 15:15:44 ----D---- C:\Program Files\Windows Media Player
2013-12-11 15:15:44 ----D---- C:\Program Files\Internet Explorer
2013-12-11 15:15:43 ----D---- C:\windows\system32\DriverStore
2013-12-11 15:15:42 ----D---- C:\windows\system32\drivers
2013-12-11 14:59:02 ----D---- C:\windows\system32\catroot
2013-12-11 14:58:41 ----SHD---- C:\windows\Installer
2013-12-11 14:58:41 ----D---- C:\ProgramData\Microsoft Help
2013-12-11 14:54:43 ----D---- C:\windows\system32\MRT
2013-12-11 14:47:09 ----A---- C:\windows\system32\MRT.exe
2013-12-08 18:16:42 ----D---- C:\ProgramData\YTD Video Downloader
2013-12-04 22:58:10 ----D---- C:\Program Files\CCleaner
2013-12-03 10:50:20 ----SHD---- C:\System Volume Information
2013-11-29 06:22:34 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-11-28 22:54:42 ----D---- C:\Program Files\Common Files
2013-11-28 22:54:23 ----A---- C:\windows\system32\javaw.exe
2013-11-28 22:54:22 ----A---- C:\windows\system32\java.exe
2013-11-28 22:54:20 ----D---- C:\Program Files\Java
2013-11-28 21:37:19 ----AD---- C:\ProgramData\Temp
2013-11-27 22:24:23 ----D---- C:\windows\Microsoft.NET
2013-11-27 21:42:47 ----D---- C:\windows\system32\Tasks
2013-11-27 21:42:46 ----D---- C:\windows\Tasks
2013-11-27 08:25:02 ----RSD---- C:\windows\assembly
2013-11-27 08:22:33 ----D---- C:\windows\system32\en-US
2013-11-27 08:22:10 ----SD---- C:\ProgramData\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 49240]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-12-17 433176]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\windows\System32\drivers\sfhlp02.sys [2004-10-28 6656]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-10-07 436792]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 188808]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 134248]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 37416]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2013-09-17 174400]
R2 lirsgt;lirsgt; C:\windows\system32\DRIVERS\lirsgt.sys [2010-06-16 18048]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 BCM43XX;Broadcom 802.11 - ovládač sieťového adaptéru; C:\windows\system32\DRIVERS\bcmwl6.sys [2009-11-05 2494968]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-11 27632]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT32.sys [2009-11-24 507392]
R3 ETD;ELAN PS/2 Port Input Device; C:\windows\system32\DRIVERS\ETD.sys [2009-11-26 119296]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\windows\System32\Drivers\gHidPnp.Sys [2009-06-27 20480]
R3 gMouUsb;USB Mouse Device Drv; C:\windows\system32\DRIVERS\gMouUsb.sys [2009-06-25 11520]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda32v.sys [2013-12-04 161056]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 usbsmi;Lenovo EasyCamera; C:\windows\system32\DRIVERS\SMIksdrv.sys [2009-10-26 171776]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
R3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792]
S0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\windows\System32\drivers\sfdrv01.sys [2004-11-25 46080]
S0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\windows\System32\drivers\sfsync02.sys [2004-11-29 19648]
S2 atksgt;atksgt; C:\windows\system32\DRIVERS\atksgt.sys [2010-06-16 271360]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 AVerPola;AVerMedia USB Polaris Series Capture Service; C:\windows\system32\DRIVERS\AVerPola.sys [2009-08-05 314752]
S3 AVPolCIR;AVerMedia USB Polaris Series Custom IR Service; C:\windows\system32\DRIVERS\AVPolCIR.sys [2009-08-05 32896]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 Bridge0;Bridge0; C:\windows\system32\drivers\WDBridge.sys [2009-07-28 63240]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2010-07-04 45736]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2010-07-04 86056]
S3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\DRIVERS\btwavdt.sys [2010-07-04 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2010-07-04 29472]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2010-07-04 18472]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-22 39272]
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfd.sys [2012-10-17 19072]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-12-11 182304]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-08-29 28160]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WimFltr;WimFltr; C:\windows\system32\DRIVERS\wimfltr.sys [2008-08-06 128104]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2010-06-13 628000]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2013-09-12 1337752]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-23 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-12-09 268824]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2012-05-15 645440]
R2 ReadyComm.DirectRouter;ReadyComm.DirectRouter; C:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-06-21 162408]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-23 257416]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-22 1493352]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
S3 IGRS;IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-28 119408]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2009-09-26 149336]
S3 PS_MDP;ReadyComm Presentation Space Helper Service; C:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-06-17 1343400]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: Preventivka

Napsal: 23 pro 2013 22:37
od Márty84
Zdravim :)
Blare píše:na notas mi zacina nieco liezt...
:???: Nejaky konkretnejsi popis by nebyl?


:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Preventivka

Napsal: 24 pro 2013 15:23
od Blare
Dobry den - nasiel som a odstranil najdenych 2 trojanov (stavalo sa - casom spustilo, ze mal som poprehadzovane tlacidla na misi a akoby stlacenu klavesu na klavesnici, ESET nic nenasiel, dokonca len trojana spustil). Pekne Vianoce :)


Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verzia databázy: v2013.12.24.03

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16476
Turbo :: TURBO-PC [administrátor]

24. 12. 2013 12:51:53
mbam-log-2013-12-24 (12-51-53).txt

Typ kontroly: Úplná kontrola (C:\|D:\|)
Možnosti kontroly zapnuté: Pamäť | Po spustení | Registre | Systémové súbory | Heuristika/Extra | Heuristika/Shuriken | PUP | PUM
Možnosti kontroly vypnuté: P2P
Objektov kontrolovaných: 583017
Uplynutý čas: 2 hod, 27 min, 9 sek

Detegované služby pamäte: 0
(Škodlivé položky neboli zistené)

Detegované moduly pamäte: 0
(Škodlivé položky neboli zistené)

Detegované registračné kľúče: 2
HKCU\SOFTWARE\JP595IR86O (Trojan.FakeAlert) -> Pridanie do karantény a zmazanie úspešné.
HKCU\SOFTWARE\Z30KYPG3WS (Trojan.FakeAlert) -> Pridanie do karantény a zmazanie úspešné.

Detegované registračné hodnoty: 0
(Škodlivé položky neboli zistené)

Detegované položky registračných dát: 0
(Škodlivé položky neboli zistené)

Detegované priečinky: 0
(Škodlivé položky neboli zistené)

Detegované súbory: 0
(Škodlivé položky neboli zistené)

(koniec)

Re: Preventivka

Napsal: 24 pro 2013 15:32
od Márty84
:arrow: Restartujte pc a zopakujte test, at vime, jestli se to nevraci. Pokud nic nenajde, MBAM odinstalujte a pokracujte RgueKillerem


:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe , ulozte ho na plochu, kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Zprava a objevi se log. Ten mi sem vlozte

Re: Preventivka

Napsal: 24 pro 2013 18:35
od Blare
RogueKiller V8.7.13 [Dec 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operačný systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spustené v : Normálny režim
Užívateľ : Turbo [Práva Správcu]
Režim : Kontrola -- Dátum : 12/24/2013 18:34:04
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy : 0 ¤¤¤

¤¤¤ Záznamy Registrov : 3 ¤¤¤
[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> NÁJDENÉ
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NÁJDENÉ
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NÁJDENÉ

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spustenie položky : 0 ¤¤¤

¤¤¤ webové prehliadače : 0 ¤¤¤

¤¤¤ Zvláštne súbory / Adresáre: ¤¤¤

¤¤¤ Ovládač : [NENAHRATÉ 0xc0000033] ¤¤¤

¤¤¤ Vonkajšie Hives: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Súbor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


ÿþ1

¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) HITACHI HTS545032B9A300 +++++
--- User ---
[MBR] 56f3236952afce7fcea2de9e899056e5
[BSP] 7c8be3ce707ab59ccc21ab5a7ec4f196 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 411648 | Size: 260243 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 533389312 | Size: 29692 Mo
3 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 594198528 | Size: 15109 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončené : << RKreport[0]_S_12242013_183404.txt >>

Re: Preventivka

Napsal: 25 pro 2013 00:16
od Márty84
:arrow: Znovu spustte RogueKiller jako spravce (pokud jste ho jeste nezavrel/a, rovnou kliknete na napis Smazat)
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Smazat.
Pak kliknete na napis Zprava a objevi se log. Ten mi sem vlozte.
Pak kliknete na napis Oprava Host a Zprava.
Objevi se dalsi log. I ten mi sem vlozte.

Re: Preventivka

Napsal: 25 pro 2013 11:37
od Blare
RogueKiller V8.7.13 [Dec 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operačný systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spustené v : Normálny režim
Užívateľ : Turbo [Práva Správcu]
Režim : Odebrať -- Dátum : 12/25/2013 11:36:25
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy : 0 ¤¤¤

¤¤¤ Záznamy Registrov : 3 ¤¤¤
[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> VYMAZANÉ
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRADENÉ (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRADENÉ (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spustenie položky : 0 ¤¤¤

¤¤¤ webové prehliadače : 0 ¤¤¤

¤¤¤ Zvláštne súbory / Adresáre: ¤¤¤

¤¤¤ Ovládač : [NENAHRATÉ 0xc0000033] ¤¤¤

¤¤¤ Vonkajšie Hives: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Súbor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


ÿþ1

¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) HITACHI HTS545032B9A300 +++++
--- User ---
[MBR] 56f3236952afce7fcea2de9e899056e5
[BSP] 7c8be3ce707ab59ccc21ab5a7ec4f196 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 411648 | Size: 260243 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 533389312 | Size: 29692 Mo
3 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 594198528 | Size: 15109 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončené : << RKreport[0]_D_12252013_113625.txt >>
RKreport[0]_S_12242013_183700.txt;RKreport[0]_S_12252013_113617.txt



RogueKiller V8.7.13 [Dec 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operačný systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spustené v : Normálny režim
Užívateľ : Turbo [Práva Správcu]
Režim : Oprava HOSTS -- Dátum : 12/25/2013 11:37:00
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy : 0 ¤¤¤

¤¤¤ Záznamy Registrov : 0 ¤¤¤

¤¤¤ Ovládač : [NENAHRATÉ 0xc0000033] ¤¤¤

¤¤¤ Vonkajšie Hives: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Súbor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


ÿþ1

¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost


Dokončené : << RKreport[0]_H_12252013_113700.txt >>
RKreport[0]_D_12252013_113625.txt;RKreport[0]_S_12242013_183700.txt;RKreport[0]_S_12252013_113617.txt

Re: Preventivka

Napsal: 25 pro 2013 12:10
od Márty84
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a program zacne pracovat.
Az skonci, vyplivne na vas log (pokud ne, najdete ho zde C:\AdwCleaner\AdwCleaner[R?].txt ), ten mi sem zkopirujte.

Re: Preventivka

Napsal: 25 pro 2013 20:23
od Blare
# AdwCleaner v3.016 - Report created 25/12/2013 at 20:21:56
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Turbo - TURBO-PC
# Running from : C:\Users\Turbo\Downloads\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default\ICQToolbarData

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}
Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Found : HKLM\SOFTWARE\Classes\AppID\{5E50AE1D-BC76-418B-94C4-EFEAC0CEF80C}
Key Found : HKLM\SOFTWARE\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}
Key Found : HKLM\SOFTWARE\Classes\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E}
Key Found : HKLM\SOFTWARE\Classes\AppID\NCTAudioCompress3.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\NCTAudioFile3.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\NCTAudioFormatSettings3.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{03F14321-8FED-4CBC-B01A-4B57FC199062}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2C6F7E96-73BC-47A5-9F51-B67F0BAFE24D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4C58EB04-7B72-4D3D-A36E-66167A99BC31}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4EE0B011-604C-47F3-8F2B-39F79640B85E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CD5175E2-7CC1-418C-B66C-0AB95DAD4103}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2790392
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Key Found : HKLM\Software\Trymedia Systems
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v25.0.1 (en-US)

[ File : C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [15680 octets] - [22/08/2013 20:19:20]
AdwCleaner[R1].txt - [3098 octets] - [25/12/2013 20:21:56]
AdwCleaner[S0].txt - [16056 octets] - [22/08/2013 20:20:32]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [3219 octets] ##########

Re: Preventivka

Napsal: 25 pro 2013 20:28
od Márty84
:arrow: Znovu ukoncete vsechny programy a spustte AdwCleaner jako spravce.
Tentokrat kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne dalsi log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zase zkopirujte.

Re: Preventivka

Napsal: 25 pro 2013 21:06
od Blare
# AdwCleaner v3.016 - Report created 25/12/2013 at 21:04:36
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Turbo - TURBO-PC
# Running from : C:\Users\Turbo\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default\ICQToolbarData

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCompress3.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioFile3.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioFormatSettings3.DLL
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2790392
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5E50AE1D-BC76-418B-94C4-EFEAC0CEF80C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F14321-8FED-4CBC-B01A-4B57FC199062}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2C6F7E96-73BC-47A5-9F51-B67F0BAFE24D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4C58EB04-7B72-4D3D-A36E-66167A99BC31}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4EE0B011-604C-47F3-8F2B-39F79640B85E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD5175E2-7CC1-418C-B66C-0AB95DAD4103}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}
Key Deleted : HKLM\Software\Trymedia Systems
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v25.0.1 (en-US)

[ File : C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [15680 octets] - [22/08/2013 20:19:20]
AdwCleaner[R1].txt - [3299 octets] - [25/12/2013 20:21:56]
AdwCleaner[S0].txt - [16056 octets] - [22/08/2013 20:20:32]
AdwCleaner[S1].txt - [3280 octets] - [25/12/2013 21:04:36]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3340 octets] ##########

Re: Preventivka

Napsal: 25 pro 2013 21:18
od Márty84
Dejte novy log z RSIT

Re: Preventivka

Napsal: 25 pro 2013 22:16
od Blare
Logfile of random's system information tool 1.09 (written by random/random)
Run by Turbo at 2013-12-25 22:16:14
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 42 GB (16%) free of 260 GB
Total RAM: 3063 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:16:19, on 25. 12. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
C:\Program Files\Lenovo\VeriFace\PManage.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Genius\ioCentre\gTaskBar.exe
C:\Program Files\Lenovo\YouCam\YCMMirage.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Genius\ioCentre\gMouseTask.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Genius\ioCentre\gKbdTask.exe
C:\Genius\ioCentre\gIoCentreFunMgm.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
C:\Users\Turbo\Downloads\RSIT.exe
C:\windows\system32\DllHost.exe
C:\Program Files\trend micro\Turbo.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [OnekeyStudio] C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files\Lenovo\YouCam\YouCam.exe" /s
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Turbo\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\RunOnce: [WLStart] "C:\Program Files\Windows Live\Installer\wlstart.exe" /nosearch /nohomepage (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WLStart] "C:\Program Files\Windows Live\Installer\wlstart.exe" /nosearch /nohomepage (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

--
End of file - 8617 bytes

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3825014317-2607772001-1910489964-1003Core1ceebb13a91d691.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3825014317-2607772001-1910489964-1003UA1ceebb13ad1ecd7.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.facebook.com/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@cambridgesoft.com/Chem3D,version=12.0]
"Description"=CambridgeSoft Chem3D Plugin 12.0
"Path"=C:\Program Files\CambridgeSoft\ChemOffice2010\Chem3D\npChem3DPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@cambridgesoft.com/ChemDraw,version=12.0]
"Description"=CambridgeSoft ChemDraw Plugin 12.0
"Path"=C:\Program Files\CambridgeSoft\ChemOffice2010\ChemDraw\npcdp32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
nsILegitCheckPlugin.xpt
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npLegitCheckPlugin.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-11-28 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-11-28 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [2009-11-16 487992]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-11-24 501640]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2009-12-19 665504]
"VeriFaceManager"=C:\Program Files\Lenovo\VeriFace\PManage.exe [2010-02-06 3122528]
"EnergyUtility"=C:\Program Files\Lenovo\Energy Management\utility.exe [2009-12-17 4114368]
"Energy Management"=C:\Program Files\Lenovo\Energy Management\Energy Management.exe [2009-12-17 6223808]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2009-09-03 61440]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"YouCam Mirage"=C:\Program Files\Lenovo\YouCam\YCMMirage.exe [2011-01-11 136488]
"YouCam Tray"=C:\Program Files\Lenovo\YouCam\YouCam.exe [2011-01-11 228448]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2013-09-12 5110672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"Google Update"=C:\Users\Turbo\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe [2013-04-19 1090912]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2013-11-11 208384]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=28
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.clmp3enc"=C:\PROGRA~1\Lenovo\Power2Go\CLMP3Enc.ACM
"msacm.siren"=sirenacm.dll
"vidc.XVID"=xvidvfw.dll
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"vidc.VP60"=C:\windows\system32\vp6vfw.dll
"vidc.VP61"=C:\windows\system32\vp6vfw.dll
"vidc.tscc"=tsccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2013-12-24 18:34:01 ----A---- C:\windows\system32\drivers\WUDFRd.sys.bak
2013-12-24 18:34:01 ----A---- C:\windows\system32\drivers\WUDFPf.sys.bak
2013-12-24 18:34:01 ----A---- C:\windows\system32\drivers\wsvd.sys.bak
2013-12-24 18:34:00 ----A---- C:\windows\system32\drivers\ws2ifsl.sys.bak
2013-12-24 18:34:00 ----A---- C:\windows\system32\drivers\wmilib.sys.bak
2013-12-24 18:34:00 ----A---- C:\windows\system32\drivers\wmiacpi.sys.bak
2013-12-24 18:34:00 ----A---- C:\windows\system32\drivers\winusb.sys.bak
2013-12-24 18:34:00 ----A---- C:\windows\system32\drivers\wimmount.sys.bak
2013-12-24 18:34:00 ----A---- C:\windows\system32\drivers\WimFltr.sys.bak
2013-12-24 18:34:00 ----A---- C:\windows\system32\drivers\wfplwf.sys.bak
2013-12-24 18:33:59 ----A---- C:\windows\system32\drivers\WDMirror.sys.bak
2013-12-24 18:33:59 ----A---- C:\windows\system32\drivers\WdfLdr.sys.bak
2013-12-24 18:33:59 ----A---- C:\windows\system32\drivers\Wdf01000.sys.bak
2013-12-24 18:33:59 ----A---- C:\windows\system32\drivers\wdbridge.sys.bak
2013-12-24 18:33:59 ----A---- C:\windows\system32\drivers\wd.sys.bak
2013-12-24 18:33:59 ----A---- C:\windows\system32\drivers\watchdog.sys.bak
2013-12-24 18:33:58 ----A---- C:\windows\system32\drivers\wanarp.sys.bak
2013-12-24 18:33:58 ----A---- C:\windows\system32\drivers\wacompen.sys.bak
2013-12-24 18:33:58 ----A---- C:\windows\system32\drivers\vwifimp.sys.bak
2013-12-24 18:33:58 ----A---- C:\windows\system32\drivers\vwififlt.sys.bak
2013-12-24 18:33:58 ----A---- C:\windows\system32\drivers\vwifibus.sys.bak
2013-12-24 18:33:58 ----A---- C:\windows\system32\drivers\vsmraid.sys.bak
2013-12-24 18:33:58 ----A---- C:\windows\system32\drivers\volsnap.sys.bak
2013-12-24 18:33:57 ----A---- C:\windows\system32\drivers\volmgrx.sys.bak
2013-12-24 18:33:57 ----A---- C:\windows\system32\drivers\volmgr.sys.bak
2013-12-24 18:33:57 ----A---- C:\windows\system32\drivers\videoprt.sys.bak
2013-12-24 18:33:57 ----A---- C:\windows\system32\drivers\viaide.sys.bak
2013-12-24 18:33:57 ----A---- C:\windows\system32\drivers\viac7.sys.bak
2013-12-24 18:33:57 ----A---- C:\windows\system32\drivers\VIAAGP.SYS.bak
2013-12-24 18:33:57 ----A---- C:\windows\system32\drivers\vhdmp.sys.bak
2013-12-24 18:33:56 ----A---- C:\windows\system32\drivers\vgapnp.sys.bak
2013-12-24 18:33:56 ----A---- C:\windows\system32\drivers\vga.sys.bak
2013-12-24 18:33:56 ----A---- C:\windows\system32\drivers\vdrvroot.sys.bak
2013-12-24 18:33:56 ----A---- C:\windows\system32\drivers\usbvideo.sys.bak
2013-12-24 18:33:56 ----A---- C:\windows\system32\drivers\usbuhci.sys.bak
2013-12-24 18:33:55 ----A---- C:\windows\system32\drivers\USBSTOR.SYS.bak
2013-12-24 18:33:55 ----A---- C:\windows\system32\drivers\usbser_lowerfltj.sys.bak
2013-12-24 18:33:55 ----A---- C:\windows\system32\drivers\usbser_lowerflt.sys.bak
2013-12-24 18:33:55 ----A---- C:\windows\system32\drivers\usbser.sys.bak
2013-12-24 18:33:55 ----A---- C:\windows\system32\drivers\usbrpm.sys.bak
2013-12-24 18:33:55 ----A---- C:\windows\system32\drivers\usbprint.sys.bak
2013-12-24 18:33:54 ----A---- C:\windows\system32\drivers\usbport.sys.bak
2013-12-24 18:33:54 ----A---- C:\windows\system32\drivers\usbohci.sys.bak
2013-12-24 18:33:54 ----A---- C:\windows\system32\drivers\usbhub.sys.bak
2013-12-24 18:33:54 ----A---- C:\windows\system32\drivers\usbehci.sys.bak
2013-12-24 18:33:54 ----A---- C:\windows\system32\drivers\usbd.sys.bak
2013-12-24 18:33:54 ----A---- C:\windows\system32\drivers\usbcir.sys.bak
2013-12-24 18:33:53 ----A---- C:\windows\system32\drivers\usbccgp.sys.bak
2013-12-24 18:33:53 ----A---- C:\windows\system32\drivers\USBCAMD2.sys.bak
2013-12-24 18:33:53 ----A---- C:\windows\system32\drivers\USBCAMD.sys.bak
2013-12-24 18:33:53 ----A---- C:\windows\system32\drivers\usb8023.sys.bak
2013-12-24 18:33:53 ----A---- C:\windows\system32\drivers\umpass.sys.bak
2013-12-24 18:33:53 ----A---- C:\windows\system32\drivers\umbus.sys.bak
2013-12-24 18:33:53 ----A---- C:\windows\system32\drivers\ULIAGPKX.SYS.bak
2013-12-24 18:33:52 ----A---- C:\windows\system32\drivers\udfs.sys.bak
2013-12-24 18:33:52 ----A---- C:\windows\system32\drivers\UAGP35.SYS.bak
2013-12-24 18:33:52 ----A---- C:\windows\system32\drivers\tunnel.sys.bak
2013-12-24 18:33:52 ----A---- C:\windows\system32\drivers\TsUsbFlt.sys.bak
2013-12-24 18:33:52 ----A---- C:\windows\system32\drivers\tssecsrv.sys.bak
2013-12-24 18:33:52 ----A---- C:\windows\system32\drivers\termdd.sys.bak
2013-12-24 18:33:51 ----A---- C:\windows\system32\drivers\tdx.sys.bak
2013-12-24 18:33:51 ----A---- C:\windows\system32\drivers\tdtcp.sys.bak
2013-12-24 18:33:51 ----A---- C:\windows\system32\drivers\tdpipe.sys.bak
2013-12-24 18:33:51 ----A---- C:\windows\system32\drivers\tdi.sys.bak
2013-12-24 18:33:51 ----A---- C:\windows\system32\drivers\tcpipreg.sys.bak
2013-12-24 18:33:51 ----A---- C:\windows\system32\drivers\tcpip.sys.bak
2013-12-24 18:33:50 ----A---- C:\windows\system32\drivers\tape.sys.bak
2013-12-24 18:33:50 ----A---- C:\windows\system32\drivers\swenum.sys.bak
2013-12-24 18:33:50 ----A---- C:\windows\system32\drivers\stream.sys.bak
2013-12-24 18:33:50 ----A---- C:\windows\system32\drivers\storport.sys.bak
2013-12-24 18:33:50 ----A---- C:\windows\system32\drivers\stexstor.sys.bak
2013-12-24 18:33:50 ----A---- C:\windows\system32\drivers\srvnet.sys.bak
2013-12-24 18:33:49 ----A---- C:\windows\system32\drivers\srv2.sys.bak
2013-12-24 18:33:49 ----A---- C:\windows\system32\drivers\srv.sys.bak
2013-12-24 18:33:49 ----A---- C:\windows\system32\drivers\sptd.sys.bak
2013-12-24 18:33:49 ----A---- C:\windows\system32\drivers\spsys.sys.bak
2013-12-24 18:33:49 ----A---- C:\windows\system32\drivers\spldr.sys.bak
2013-12-24 18:33:48 ----A---- C:\windows\system32\drivers\SMIksdrv.sys.bak
2013-12-24 18:33:48 ----A---- C:\windows\system32\drivers\SMIexp.sys.bak
2013-12-24 18:33:48 ----A---- C:\windows\system32\drivers\smclib.sys.bak
2013-12-24 18:33:48 ----A---- C:\windows\system32\drivers\smb.sys.bak
2013-12-24 18:33:47 ----A---- C:\windows\system32\drivers\sisraid4.sys.bak
2013-12-24 18:33:47 ----A---- C:\windows\system32\drivers\sisraid2.sys.bak
2013-12-24 18:33:47 ----A---- C:\windows\system32\drivers\SISAGP.SYS.bak
2013-12-24 18:33:47 ----A---- C:\windows\system32\drivers\sfsync02.sys.bak
2013-12-24 18:33:47 ----A---- C:\windows\system32\drivers\sfloppy.sys.bak
2013-12-24 18:33:47 ----A---- C:\windows\system32\drivers\sfhlp02.sys.bak
2013-12-24 18:33:47 ----A---- C:\windows\system32\drivers\sffp_sd.sys.bak
2013-12-24 18:33:46 ----A---- C:\windows\system32\drivers\sffp_mmc.sys.bak
2013-12-24 18:33:46 ----A---- C:\windows\system32\drivers\sffdisk.sys.bak
2013-12-24 18:33:46 ----A---- C:\windows\system32\drivers\sfdrv01.sys.bak
2013-12-24 18:33:46 ----A---- C:\windows\system32\drivers\sermouse.sys.bak
2013-12-24 18:33:46 ----A---- C:\windows\system32\drivers\serial.sys.bak
2013-12-24 18:33:46 ----A---- C:\windows\system32\drivers\serenum.sys.bak
2013-12-24 18:33:46 ----A---- C:\windows\system32\drivers\secdrv.sys.bak
2013-12-24 18:33:45 ----A---- C:\windows\system32\drivers\scsiport.sys.bak
2013-12-24 18:33:45 ----A---- C:\windows\system32\drivers\scfilter.sys.bak
2013-12-24 18:33:45 ----A---- C:\windows\system32\drivers\sbp2port.sys.bak
2013-12-24 18:33:45 ----A---- C:\windows\system32\drivers\RtsUStor.sys.bak
2013-12-24 18:33:45 ----A---- C:\windows\system32\drivers\Rt86win7.sys.bak
2013-12-24 18:33:45 ----A---- C:\windows\system32\drivers\rspndr.sys.bak
2013-12-24 18:33:45 ----A---- C:\windows\system32\drivers\rootmdm.sys.bak
2013-12-24 18:33:44 ----A---- C:\windows\system32\drivers\RNDISMP.sys.bak
2013-12-24 18:33:44 ----A---- C:\windows\system32\drivers\rmcast.sys.bak
2013-12-24 18:33:44 ----A---- C:\windows\system32\drivers\rfcomm.sys.bak
2013-12-24 18:33:44 ----A---- C:\windows\system32\drivers\rdyboost.sys.bak
2013-12-24 18:33:44 ----A---- C:\windows\system32\drivers\rdpwd.sys.bak
2013-12-24 18:33:44 ----A---- C:\windows\system32\drivers\rdpvideominiport.sys.bak
2013-12-24 18:33:43 ----A---- C:\windows\system32\drivers\RDPREFMP.sys.bak
2013-12-24 18:33:43 ----A---- C:\windows\system32\drivers\RDPENCDD.sys.bak
2013-12-24 18:33:43 ----A---- C:\windows\system32\drivers\RDPCDD.sys.bak
2013-12-24 18:33:43 ----A---- C:\windows\system32\drivers\rdpbus.sys.bak
2013-12-24 18:33:43 ----A---- C:\windows\system32\drivers\rdbss.sys.bak
2013-12-24 18:33:43 ----A---- C:\windows\system32\drivers\rassstp.sys.bak
2013-12-24 18:33:43 ----A---- C:\windows\system32\drivers\raspptp.sys.bak
2013-12-24 18:33:42 ----A---- C:\windows\system32\drivers\raspppoe.sys.bak
2013-12-24 18:33:42 ----A---- C:\windows\system32\drivers\rasl2tp.sys.bak
2013-12-24 18:33:42 ----A---- C:\windows\system32\drivers\rasacd.sys.bak
2013-12-24 18:33:42 ----A---- C:\windows\system32\drivers\qwavedrv.sys.bak
2013-12-24 18:33:42 ----A---- C:\windows\system32\drivers\ql40xx.sys.bak
2013-12-24 18:33:42 ----A---- C:\windows\system32\drivers\ql2300.sys.bak
2013-12-24 18:33:41 ----A---- C:\windows\system32\drivers\processr.sys.bak
2013-12-24 18:33:41 ----A---- C:\windows\system32\drivers\portcls.sys.bak
2013-12-24 18:33:41 ----A---- C:\windows\system32\drivers\PEAuth.sys.bak
2013-12-24 18:33:41 ----A---- C:\windows\system32\drivers\pcw.sys.bak
2013-12-24 18:33:41 ----A---- C:\windows\system32\drivers\pcmcia.sys.bak
2013-12-24 18:33:41 ----A---- C:\windows\system32\drivers\pciidex.sys.bak
2013-12-24 18:33:40 ----A---- C:\windows\system32\drivers\pciide.sys.bak
2013-12-24 18:33:40 ----A---- C:\windows\system32\drivers\pci.sys.bak
2013-12-24 18:33:40 ----A---- C:\windows\system32\drivers\pccsmcfd.sys.bak
2013-12-24 18:33:40 ----A---- C:\windows\system32\drivers\parvdm.sys.bak
2013-12-24 18:33:40 ----A---- C:\windows\system32\drivers\partmgr.sys.bak
2013-12-24 18:33:40 ----A---- C:\windows\system32\drivers\parport.sys.bak
2013-12-24 18:33:40 ----A---- C:\windows\system32\drivers\pacer.sys.bak
2013-12-24 18:33:39 ----A---- C:\windows\system32\drivers\ohci1394.sys.bak
2013-12-24 18:33:39 ----A---- C:\windows\system32\drivers\nwifi.sys.bak
2013-12-24 18:33:39 ----A---- C:\windows\system32\drivers\nvstor.sys.bak
2013-12-24 18:33:39 ----A---- C:\windows\system32\drivers\NV_AGP.SYS.bak
2013-12-24 18:33:37 ----A---- C:\windows\system32\drivers\nvraid.sys.bak
2013-12-24 18:33:35 ----A---- C:\windows\system32\drivers\nvlddmkm.sys.bak
2013-12-24 18:33:35 ----A---- C:\windows\system32\drivers\nvhda32v.sys.bak
2013-12-24 18:33:35 ----A---- C:\windows\system32\drivers\null.sys.bak
2013-12-24 18:33:35 ----A---- C:\windows\system32\drivers\ntfs.sys.bak
2013-12-24 18:33:35 ----A---- C:\windows\system32\drivers\nsiproxy.sys.bak
2013-12-24 18:33:34 ----A---- C:\windows\system32\drivers\npfs.sys.bak
2013-12-24 18:33:34 ----A---- C:\windows\system32\drivers\nfrd960.sys.bak
2013-12-24 18:33:33 ----A---- C:\windows\system32\drivers\netw5v32.sys.bak
2013-12-24 18:33:33 ----A---- C:\windows\system32\drivers\netio.sys.bak
2013-12-24 18:33:33 ----A---- C:\windows\system32\drivers\netbt.sys.bak
2013-12-24 18:33:33 ----A---- C:\windows\system32\drivers\netbios.sys.bak
2013-12-24 18:33:33 ----A---- C:\windows\system32\drivers\ndproxy.sys.bak
2013-12-24 18:33:32 ----A---- C:\windows\system32\drivers\ndiswan.sys.bak
2013-12-24 18:33:32 ----A---- C:\windows\system32\drivers\ndisuio.sys.bak
2013-12-24 18:33:32 ----A---- C:\windows\system32\drivers\ndistapi.sys.bak
2013-12-24 18:33:32 ----A---- C:\windows\system32\drivers\ndiscap.sys.bak
2013-12-24 18:33:32 ----A---- C:\windows\system32\drivers\ndis.sys.bak
2013-12-24 18:33:32 ----A---- C:\windows\system32\drivers\mup.sys.bak
2013-12-24 18:33:31 ----A---- C:\windows\system32\drivers\MTConfig.sys.bak
2013-12-24 18:33:31 ----A---- C:\windows\system32\drivers\mstee.sys.bak
2013-12-24 18:33:31 ----A---- C:\windows\system32\drivers\mssmbios.sys.bak
2013-12-24 18:33:31 ----A---- C:\windows\system32\drivers\msrpc.sys.bak
2013-12-24 18:33:31 ----A---- C:\windows\system32\drivers\mspqm.sys.bak
2013-12-24 18:33:31 ----A---- C:\windows\system32\drivers\mspclock.sys.bak
2013-12-24 18:33:31 ----A---- C:\windows\system32\drivers\mskssrv.sys.bak
2013-12-24 18:33:30 ----A---- C:\windows\system32\drivers\msiscsi.sys.bak
2013-12-24 18:33:30 ----A---- C:\windows\system32\drivers\msisadrv.sys.bak
2013-12-24 18:33:30 ----A---- C:\windows\system32\drivers\mshidkmdf.sys.bak
2013-12-24 18:33:30 ----A---- C:\windows\system32\drivers\msfs.sys.bak
2013-12-24 18:33:30 ----A---- C:\windows\system32\drivers\msdsm.sys.bak
2013-12-24 18:33:30 ----A---- C:\windows\system32\drivers\msahci.sys.bak
2013-12-24 18:33:30 ----A---- C:\windows\system32\drivers\mrxsmb20.sys.bak
2013-12-24 18:33:29 ----A---- C:\windows\system32\drivers\mrxsmb10.sys.bak
2013-12-24 18:33:29 ----A---- C:\windows\system32\drivers\mrxsmb.sys.bak
2013-12-24 18:33:29 ----A---- C:\windows\system32\drivers\mrxdav.sys.bak
2013-12-24 18:33:29 ----A---- C:\windows\system32\drivers\mpsdrv.sys.bak
2013-12-24 18:33:29 ----A---- C:\windows\system32\drivers\mpio.sys.bak
2013-12-24 18:33:29 ----A---- C:\windows\system32\drivers\mountmgr.sys.bak
2013-12-24 18:33:29 ----A---- C:\windows\system32\drivers\mouhid.sys.bak
2013-12-24 18:33:29 ----A---- C:\windows\system32\drivers\mouclass.sys.bak
2013-12-24 18:33:28 ----A---- C:\windows\system32\drivers\monitor.sys.bak
2013-12-24 18:33:28 ----A---- C:\windows\system32\drivers\modem.sys.bak
2013-12-24 18:33:28 ----A---- C:\windows\system32\drivers\MegaSR.sys.bak
2013-12-24 18:33:28 ----A---- C:\windows\system32\drivers\megasas.sys.bak
2013-12-24 18:33:28 ----A---- C:\windows\system32\drivers\mcd.sys.bak
2013-12-24 18:33:28 ----A---- C:\windows\system32\drivers\luafv.sys.bak
2013-12-24 18:33:28 ----A---- C:\windows\system32\drivers\lsi_scsi.sys.bak
2013-12-24 18:33:27 ----A---- C:\windows\system32\drivers\lsi_sas2.sys.bak
2013-12-24 18:33:27 ----A---- C:\windows\system32\drivers\lsi_sas.sys.bak
2013-12-24 18:33:27 ----A---- C:\windows\system32\drivers\lsi_fc.sys.bak
2013-12-24 18:33:27 ----A---- C:\windows\system32\drivers\lltdio.sys.bak
2013-12-24 18:33:27 ----A---- C:\windows\system32\drivers\lirsgt.sys.bak
2013-12-24 18:33:27 ----A---- C:\windows\system32\drivers\ksecpkg.sys.bak
2013-12-24 18:33:26 ----A---- C:\windows\system32\drivers\ksecdd.sys.bak
2013-12-24 18:33:26 ----A---- C:\windows\system32\drivers\ks.sys.bak
2013-12-24 18:33:26 ----A---- C:\windows\system32\drivers\kbdhid.sys.bak
2013-12-24 18:33:26 ----A---- C:\windows\system32\drivers\kbdclass.sys.bak
2013-12-24 18:33:26 ----A---- C:\windows\system32\drivers\k57nd60x.sys.bak
2013-12-24 18:33:26 ----A---- C:\windows\system32\drivers\isapnp.sys.bak
2013-12-24 18:33:26 ----A---- C:\windows\system32\drivers\irenum.sys.bak
2013-12-24 18:33:26 ----A---- C:\windows\system32\drivers\irda.sys.bak
2013-12-24 18:33:25 ----A---- C:\windows\system32\drivers\ipnat.sys.bak
2013-12-24 18:33:25 ----A---- C:\windows\system32\drivers\IPMIDrv.sys.bak
2013-12-24 18:33:25 ----A---- C:\windows\system32\drivers\ipfltdrv.sys.bak
2013-12-24 18:33:25 ----A---- C:\windows\system32\drivers\intelppm.sys.bak
2013-12-24 18:33:25 ----A---- C:\windows\system32\drivers\intelide.sys.bak
2013-12-24 18:33:24 ----A---- C:\windows\system32\drivers\iirsp.sys.bak
2013-12-24 18:33:24 ----A---- C:\windows\system32\drivers\igdkmd32.sys.bak
2013-12-24 18:33:24 ----A---- C:\windows\system32\drivers\iaStorV.sys.bak
2013-12-24 18:33:23 ----A---- C:\windows\system32\drivers\iaStor.sys.bak
2013-12-24 18:33:23 ----A---- C:\windows\system32\drivers\i8042prt.sys.bak
2013-12-24 18:33:23 ----A---- C:\windows\system32\drivers\hwpolicy.sys.bak
2013-12-24 18:33:23 ----A---- C:\windows\system32\drivers\http.sys.bak
2013-12-24 18:33:22 ----A---- C:\windows\system32\drivers\HpSAMD.sys.bak
2013-12-24 18:33:22 ----A---- C:\windows\system32\drivers\hidusb.sys.bak
2013-12-24 18:33:22 ----A---- C:\windows\system32\drivers\hidparse.sys.bak
2013-12-24 18:33:22 ----A---- C:\windows\system32\drivers\hidir.sys.bak
2013-12-24 18:33:22 ----A---- C:\windows\system32\drivers\hidclass.sys.bak
2013-12-24 18:33:22 ----A---- C:\windows\system32\drivers\hidbth.sys.bak
2013-12-24 18:33:22 ----A---- C:\windows\system32\drivers\hidbatt.sys.bak
2013-12-24 18:33:21 ----A---- C:\windows\system32\drivers\HECI.sys.bak
2013-12-24 18:33:21 ----A---- C:\windows\system32\drivers\HdAudio.sys.bak
2013-12-24 18:33:21 ----A---- C:\windows\system32\drivers\hdaudbus.sys.bak
2013-12-24 18:33:21 ----A---- C:\windows\system32\drivers\hcw85cir.sys.bak
2013-12-24 18:33:21 ----A---- C:\windows\system32\drivers\hamachi.sys.bak
2013-12-24 18:33:21 ----A---- C:\windows\system32\drivers\gMouUsb.sys.bak
2013-12-24 18:33:20 ----A---- C:\windows\system32\drivers\gHidPnp.sys.bak
2013-12-24 18:33:20 ----A---- C:\windows\system32\drivers\GAGP30KX.SYS.bak
2013-12-24 18:33:20 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS.bak
2013-12-24 18:33:20 ----A---- C:\windows\system32\drivers\fvevol.sys.bak
2013-12-24 18:33:20 ----A---- C:\windows\system32\drivers\fssfltr.sys.bak
2013-12-24 18:33:20 ----A---- C:\windows\system32\drivers\fs_rec.sys.bak
2013-12-24 18:33:19 ----A---- C:\windows\system32\drivers\fsdepends.sys.bak
2013-12-24 18:33:19 ----A---- C:\windows\system32\drivers\fltMgr.sys.bak
2013-12-24 18:33:19 ----A---- C:\windows\system32\drivers\flpydisk.sys.bak
2013-12-24 18:33:19 ----A---- C:\windows\system32\drivers\filetrace.sys.bak
2013-12-24 18:33:19 ----A---- C:\windows\system32\drivers\fileinfo.sys.bak
2013-12-24 18:33:19 ----A---- C:\windows\system32\drivers\fdc.sys.bak
2013-12-24 18:33:19 ----A---- C:\windows\system32\drivers\fastfat.sys.bak
2013-12-24 18:33:18 ----A---- C:\windows\system32\drivers\exfat.sys.bak
2013-12-24 18:33:18 ----A---- C:\windows\system32\drivers\evbdx.sys.bak
2013-12-24 18:33:18 ----A---- C:\windows\system32\drivers\ETD.sys.bak
2013-12-24 18:33:18 ----A---- C:\windows\system32\drivers\errdev.sys.bak
2013-12-24 18:33:17 ----A---- C:\windows\system32\drivers\epfwwfp.sys.bak
2013-12-24 18:33:17 ----A---- C:\windows\system32\drivers\EpfwLWF.sys.bak
2013-12-24 18:33:17 ----A---- C:\windows\system32\drivers\epfw.sys.bak
2013-12-24 18:33:17 ----A---- C:\windows\system32\drivers\elxstor.sys.bak
2013-12-24 18:33:17 ----A---- C:\windows\system32\drivers\ehdrv.sys.bak
2013-12-24 18:33:17 ----A---- C:\windows\system32\drivers\eamonm.sys.bak
2013-12-24 18:33:16 ----A---- C:\windows\system32\drivers\dxgmms1.sys.bak
2013-12-24 18:33:16 ----A---- C:\windows\system32\drivers\dxgkrnl.sys.bak
2013-12-24 18:33:16 ----A---- C:\windows\system32\drivers\dxg.sys.bak
2013-12-24 18:33:16 ----A---- C:\windows\system32\drivers\dxapi.sys.bak
2013-12-24 18:33:16 ----A---- C:\windows\system32\drivers\dumpfve.sys.bak
2013-12-24 18:33:16 ----A---- C:\windows\system32\drivers\Dumpata.sys.bak
2013-12-24 18:33:15 ----A---- C:\windows\system32\drivers\drmkaud.sys.bak
2013-12-24 18:33:15 ----A---- C:\windows\system32\drivers\drmk.sys.bak
2013-12-24 18:33:15 ----A---- C:\windows\system32\drivers\djsvs.sys.bak
2013-12-24 18:33:15 ----A---- C:\windows\system32\drivers\Diskdump.sys.bak
2013-12-24 18:33:15 ----A---- C:\windows\system32\drivers\disk.sys.bak
2013-12-24 18:33:15 ----A---- C:\windows\system32\drivers\discache.sys.bak
2013-12-24 18:33:15 ----A---- C:\windows\system32\drivers\dfsc.sys.bak
2013-12-24 18:33:14 ----A---- C:\windows\system32\drivers\crcdisk.sys.bak
2013-12-24 18:33:14 ----A---- C:\windows\system32\drivers\crashdmp.sys.bak
2013-12-24 18:33:14 ----A---- C:\windows\system32\drivers\CompositeBus.sys.bak
2013-12-24 18:33:14 ----A---- C:\windows\system32\drivers\compbatt.sys.bak
2013-12-24 18:33:14 ----A---- C:\windows\system32\drivers\cng.sys.bak
2013-12-24 18:33:14 ----A---- C:\windows\system32\drivers\cmdide.sys.bak
2013-12-24 18:33:14 ----A---- C:\windows\system32\drivers\CmBatt.sys.bak
2013-12-24 18:33:13 ----A---- C:\windows\system32\drivers\CHDRT32.sys.bak
2013-12-24 18:33:13 ----A---- C:\windows\system32\drivers\clwvd.sys.bak
2013-12-24 18:33:13 ----A---- C:\windows\system32\drivers\Classpnp.sys.bak
2013-12-24 18:33:13 ----A---- C:\windows\system32\drivers\circlass.sys.bak
2013-12-24 18:33:13 ----A---- C:\windows\system32\drivers\cdrom.sys.bak
2013-12-24 18:33:12 ----A---- C:\windows\system32\drivers\cdfs.sys.bak
2013-12-24 18:33:12 ----A---- C:\windows\system32\drivers\ccdcmbo.sys.bak
2013-12-24 18:33:12 ----A---- C:\windows\system32\drivers\ccdcmb.sys.bak
2013-12-24 18:33:12 ----A---- C:\windows\system32\drivers\bxvbdx.sys.bak
2013-12-24 18:33:12 ----A---- C:\windows\system32\drivers\btwrchid.sys.bak
2013-12-24 18:33:11 ----A---- C:\windows\system32\drivers\btwl2cap.sys.bak
2013-12-24 18:33:11 ----A---- C:\windows\system32\drivers\btwavdt.sys.bak
2013-12-24 18:33:11 ----A---- C:\windows\system32\drivers\btwaudio.sys.bak
2013-12-24 18:33:11 ----A---- C:\windows\system32\drivers\btusbflt.sys.bak
2013-12-24 18:33:11 ----A---- C:\windows\system32\drivers\BTHUSB.SYS.bak
2013-12-24 18:33:11 ----A---- C:\windows\system32\drivers\bthport.sys.bak
2013-12-24 18:33:10 ----A---- C:\windows\system32\drivers\bthpan.sys.bak
2013-12-24 18:33:10 ----A---- C:\windows\system32\drivers\bthmodem.sys.bak
2013-12-24 18:33:10 ----A---- C:\windows\system32\drivers\bthenum.sys.bak
2013-12-24 18:33:10 ----A---- C:\windows\system32\drivers\BrUsbSer.sys.bak
2013-12-24 18:33:10 ----A---- C:\windows\system32\drivers\BrUsbMdm.sys.bak
2013-12-24 18:33:10 ----A---- C:\windows\system32\drivers\BrSerWdm.sys.bak
2013-12-24 18:33:10 ----A---- C:\windows\system32\drivers\BrSerId.sys.bak
2013-12-24 18:33:09 ----A---- C:\windows\system32\drivers\bridge.sys.bak
2013-12-24 18:33:09 ----A---- C:\windows\system32\drivers\BrFiltUp.sys.bak
2013-12-24 18:33:09 ----A---- C:\windows\system32\drivers\BrFiltLo.sys.bak
2013-12-24 18:33:09 ----A---- C:\windows\system32\drivers\bowser.sys.bak
2013-12-24 18:33:09 ----A---- C:\windows\system32\drivers\blbdrive.sys.bak
2013-12-24 18:33:09 ----A---- C:\windows\system32\drivers\beep.sys.bak
2013-12-24 18:33:09 ----A---- C:\windows\system32\drivers\BdaSup.sys.bak
2013-12-24 18:33:08 ----A---- C:\windows\system32\drivers\BCMWL6.SYS.bak
2013-12-24 18:33:08 ----A---- C:\windows\system32\drivers\battc.sys.bak
2013-12-24 18:33:08 ----A---- C:\windows\system32\drivers\b57nd60x.sys.bak
2013-12-24 18:33:07 ----A---- C:\windows\system32\drivers\AVPolCIR.sys.bak
2013-12-24 18:33:07 ----A---- C:\windows\system32\drivers\AVerPola.sys.bak
2013-12-24 18:33:07 ----A---- C:\windows\system32\drivers\atksgt.sys.bak
2013-12-24 18:33:07 ----A---- C:\windows\system32\drivers\ataport.sys.bak
2013-12-24 18:33:06 ----A---- C:\windows\system32\drivers\atapi.sys.bak
2013-12-24 18:33:06 ----A---- C:\windows\system32\drivers\asyncmac.sys.bak
2013-12-24 18:33:06 ----A---- C:\windows\system32\drivers\arcsas.sys.bak
2013-12-24 18:33:06 ----A---- C:\windows\system32\drivers\arc.sys.bak
2013-12-24 18:33:06 ----A---- C:\windows\system32\drivers\appid.sys.bak
2013-12-24 18:33:06 ----A---- C:\windows\system32\drivers\amdxata.sys.bak
2013-12-24 18:33:06 ----A---- C:\windows\system32\drivers\amdsbs.sys.bak
2013-12-24 18:33:06 ----A---- C:\windows\system32\drivers\amdsata.sys.bak
2013-12-24 18:33:05 ----A---- C:\windows\system32\drivers\amdppm.sys.bak
2013-12-24 18:33:05 ----A---- C:\windows\system32\drivers\amdk8.sys.bak
2013-12-24 18:33:05 ----A---- C:\windows\system32\drivers\amdide.sys.bak
2013-12-24 18:33:05 ----A---- C:\windows\system32\drivers\AMDAGP.SYS.bak
2013-12-24 18:33:05 ----A---- C:\windows\system32\drivers\aliide.sys.bak
2013-12-24 18:33:05 ----A---- C:\windows\system32\drivers\AGP440.sys.bak
2013-12-24 18:33:05 ----A---- C:\windows\system32\drivers\agilevpn.sys.bak
2013-12-24 18:33:04 ----A---- C:\windows\system32\drivers\afd.sys.bak
2013-12-24 18:33:04 ----A---- C:\windows\system32\drivers\adpu320.sys.bak
2013-12-24 18:33:04 ----A---- C:\windows\system32\drivers\adpahci.sys.bak
2013-12-24 18:33:03 ----A---- C:\windows\system32\drivers\adp94xx.sys.bak
2013-12-24 18:33:03 ----A---- C:\windows\system32\drivers\AcpiVpc.sys.bak
2013-12-24 18:33:03 ----A---- C:\windows\system32\drivers\acpipmi.sys.bak
2013-12-24 18:33:03 ----A---- C:\windows\system32\drivers\acpi.sys.bak
2013-12-24 18:33:03 ----A---- C:\windows\system32\drivers\1394ohci.sys.bak
2013-12-24 18:33:01 ----A---- C:\windows\system32\drivers\1394bus.sys.bak
2013-12-24 09:45:35 ----D---- C:\Users\Turbo\AppData\Roaming\Malwarebytes
2013-12-24 09:45:27 ----D---- C:\ProgramData\Malwarebytes
2013-12-23 21:00:04 ----D---- C:\ProgramData\SecTaskMan
2013-12-11 14:58:52 ----A---- C:\windows\system32\ie4uinit.exe
2013-12-11 14:58:51 ----A---- C:\windows\system32\jsproxy.dll
2013-12-11 14:58:50 ----A---- C:\windows\system32\ieui.dll
2013-12-11 14:58:50 ----A---- C:\windows\system32\ieetwcollectorres.dll
2013-12-11 14:58:50 ----A---- C:\windows\system32\ieapfltr.dll
2013-12-11 14:58:49 ----A---- C:\windows\system32\jscript9diag.dll
2013-12-11 14:58:49 ----A---- C:\windows\system32\ieUnatt.exe
2013-12-11 14:58:49 ----A---- C:\windows\system32\iesetup.dll
2013-12-11 14:58:49 ----A---- C:\windows\system32\iernonce.dll
2013-12-11 14:58:49 ----A---- C:\windows\system32\ieetwproxystub.dll
2013-12-11 14:58:48 ----A---- C:\windows\system32\ieetwcollector.exe
2013-12-11 14:58:47 ----A---- C:\windows\system32\wininet.dll
2013-12-11 14:58:46 ----A---- C:\windows\system32\urlmon.dll
2013-12-11 14:58:46 ----A---- C:\windows\system32\iertutil.dll
2013-12-11 14:58:44 ----A---- C:\windows\system32\ieframe.dll
2013-12-11 14:58:43 ----A---- C:\windows\system32\mshtml.dll
2013-12-11 14:58:42 ----A---- C:\windows\system32\jscript9.dll
2013-12-11 14:46:51 ----A---- C:\windows\system32\wmp.dll
2013-12-11 14:46:50 ----A---- C:\windows\system32\wmploc.DLL
2013-12-11 14:45:45 ----A---- C:\windows\system32\imagehlp.dll
2013-12-11 14:45:16 ----A---- C:\windows\system32\tzres.dll
2013-12-11 14:44:42 ----A---- C:\windows\system32\msieftp.dll
2013-12-11 14:44:39 ----A---- C:\windows\system32\wscript.exe
2013-12-11 14:44:39 ----A---- C:\windows\system32\scrrun.dll
2013-12-11 14:44:39 ----A---- C:\windows\system32\cscript.exe
2013-12-11 14:44:36 ----A---- C:\windows\system32\WMPhoto.dll
2013-12-11 14:44:29 ----A---- C:\windows\system32\win32k.sys
2013-12-11 14:44:26 ----A---- C:\windows\system32\drivers\portcls.sys
2013-12-11 14:44:26 ----A---- C:\windows\system32\drivers\drmk.sys
2013-12-04 02:23:26 ----A---- C:\windows\system32\nvhdap32.dll
2013-12-04 02:23:26 ----A---- C:\windows\system32\nvhdagenco32.dll
2013-12-04 02:23:26 ----A---- C:\windows\system32\drivers\nvhda32v.sys
2013-11-28 22:54:46 ----D---- C:\ProgramData\Oracle
2013-11-28 22:54:42 ----D---- C:\Program Files\Common Files\Java
2013-11-28 22:54:38 ----A---- C:\windows\system32\javaws.exe
2013-11-28 22:54:31 ----A---- C:\windows\system32\WindowsAccessBridge.dll
2013-11-28 21:27:10 ----D---- C:\Program Files\Mozilla Firefox
2013-11-27 08:22:10 ----D---- C:\windows\Migration

======List of files/folders modified in the last 1 month======

2013-12-25 22:16:16 ----D---- C:\Program Files\trend micro
2013-12-25 22:16:13 ----D---- C:\windows\Prefetch
2013-12-25 22:08:37 ----D---- C:\windows\temp
2013-12-25 21:05:40 ----D---- C:\ProgramData\VeriFace
2013-12-25 21:05:35 ----D---- C:\windows\system32\config
2013-12-25 21:05:28 ----A---- C:\windows\system32\log.txt
2013-12-25 21:05:27 ----D---- C:\ProgramData\NVIDIA
2013-12-25 21:04:37 ----D---- C:\AdwCleaner
2013-12-25 11:40:52 ----D---- C:\windows\System32
2013-12-25 11:39:37 ----D---- C:\windows\system32\drivers
2013-12-24 18:31:55 ----RD---- C:\Program Files
2013-12-24 15:27:53 ----D---- C:\Windows
2013-12-24 15:27:36 ----D---- C:\windows\JAVA
2013-12-24 09:45:27 ----D---- C:\ProgramData
2013-12-23 21:03:56 ----A---- C:\windows\system32\FlashPlayerApp.exe
2013-12-23 16:16:19 ----D---- C:\windows\SoftwareDistribution
2013-12-20 17:53:08 ----D---- C:\Program Files\Warcraft III
2013-12-18 08:50:25 ----D---- C:\Users\Turbo\AppData\Roaming\vlc
2013-12-14 22:39:05 ----D---- C:\Filmy
2013-12-14 20:54:07 ----D---- C:\Users\Turbo\AppData\Roaming\Skype
2013-12-12 20:47:31 ----D---- C:\windows\inf
2013-12-12 20:47:31 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-12-12 07:01:07 ----D---- C:\windows\system32\catroot2
2013-12-11 19:53:56 ----D---- C:\windows\rescache
2013-12-11 17:41:56 ----D---- C:\windows\debug
2013-12-11 15:18:18 ----D---- C:\windows\winsxs
2013-12-11 15:15:44 ----D---- C:\windows\system32\sk-SK
2013-12-11 15:15:44 ----D---- C:\Program Files\Windows Media Player
2013-12-11 15:15:44 ----D---- C:\Program Files\Internet Explorer
2013-12-11 15:15:43 ----D---- C:\windows\system32\DriverStore
2013-12-11 14:59:02 ----D---- C:\windows\system32\catroot
2013-12-11 14:58:41 ----SHD---- C:\windows\Installer
2013-12-11 14:58:41 ----D---- C:\ProgramData\Microsoft Help
2013-12-11 14:54:43 ----D---- C:\windows\system32\MRT
2013-12-11 14:47:09 ----A---- C:\windows\system32\MRT.exe
2013-12-08 18:16:42 ----D---- C:\ProgramData\YTD Video Downloader
2013-12-04 22:58:10 ----D---- C:\Program Files\CCleaner
2013-12-03 10:50:20 ----SHD---- C:\System Volume Information
2013-11-29 06:22:34 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-11-28 22:54:42 ----D---- C:\Program Files\Common Files
2013-11-28 22:54:23 ----A---- C:\windows\system32\javaw.exe
2013-11-28 22:54:22 ----A---- C:\windows\system32\java.exe
2013-11-28 22:54:20 ----D---- C:\Program Files\Java
2013-11-28 21:37:19 ----AD---- C:\ProgramData\Temp
2013-11-27 22:24:23 ----D---- C:\windows\Microsoft.NET
2013-11-27 21:42:47 ----D---- C:\windows\system32\Tasks
2013-11-27 21:42:46 ----D---- C:\windows\Tasks
2013-11-27 08:25:02 ----RSD---- C:\windows\assembly
2013-11-27 08:22:33 ----D---- C:\windows\system32\en-US
2013-11-27 08:22:10 ----SD---- C:\ProgramData\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 49240]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-12-17 433176]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\windows\System32\drivers\sfhlp02.sys [2004-10-28 6656]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-10-07 436792]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 188808]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 134248]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 37416]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2013-09-17 174400]
R2 lirsgt;lirsgt; C:\windows\system32\DRIVERS\lirsgt.sys [2010-06-16 18048]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 BCM43XX;Broadcom 802.11 - ovládač sieťového adaptéru; C:\windows\system32\DRIVERS\bcmwl6.sys [2009-11-05 2494968]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-11 27632]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT32.sys [2009-11-24 507392]
R3 ETD;ELAN PS/2 Port Input Device; C:\windows\system32\DRIVERS\ETD.sys [2009-11-26 119296]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\windows\System32\Drivers\gHidPnp.Sys [2009-06-27 20480]
R3 gMouUsb;USB Mouse Device Drv; C:\windows\system32\DRIVERS\gMouUsb.sys [2009-06-25 11520]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda32v.sys [2013-12-04 161056]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 usbsmi;Lenovo EasyCamera; C:\windows\system32\DRIVERS\SMIksdrv.sys [2009-10-26 171776]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
R3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792]
S0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\windows\System32\drivers\sfdrv01.sys [2004-11-25 46080]
S0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\windows\System32\drivers\sfsync02.sys [2004-11-29 19648]
S2 atksgt;atksgt; C:\windows\system32\DRIVERS\atksgt.sys [2010-06-16 271360]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 AVerPola;AVerMedia USB Polaris Series Capture Service; C:\windows\system32\DRIVERS\AVerPola.sys [2009-08-05 314752]
S3 AVPolCIR;AVerMedia USB Polaris Series Custom IR Service; C:\windows\system32\DRIVERS\AVPolCIR.sys [2009-08-05 32896]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 Bridge0;Bridge0; C:\windows\system32\drivers\WDBridge.sys [2009-07-28 63240]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2010-07-04 45736]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2010-07-04 86056]
S3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\DRIVERS\btwavdt.sys [2010-07-04 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2010-07-04 29472]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2010-07-04 18472]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-22 39272]
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfd.sys [2012-10-17 19072]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-12-11 182304]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TrueSight;TrueSight; \??\ []
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-08-29 28160]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WimFltr;WimFltr; C:\windows\system32\DRIVERS\wimfltr.sys [2008-08-06 128104]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2010-06-13 628000]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2013-09-12 1337752]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-23 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-12-09 268824]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2012-05-15 645440]
R2 ReadyComm.DirectRouter;ReadyComm.DirectRouter; C:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-06-21 162408]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-23 257416]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-22 1493352]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
S3 IGRS;IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-28 119408]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2009-09-26 149336]
S3 PS_MDP;ReadyComm Presentation Space Helper Service; C:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-06-17 1343400]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: Preventivka

Napsal: 26 pro 2013 09:09
od Márty84
Jeste jeden sken a budem mazat.


:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Preventivka

Napsal: 26 pro 2013 12:31
od Blare
Vzdy mi to vyhodi chybu v polovici scanovania:

Obrázek