Stránka 1 z 1

Prosím o preventivní kontrolu logu

Napsal: 05 bře 2014 21:34
od Knoll.Jaroslav
S počítačem, žádné zvláštní problémy nemám. Snad jen s připojením (což ale přisuzuji tomu, že jde o starší PC).
Děkuji

Logfile of random's system information tool 1.09 (written by random/random)
Run by Jaroslav at 2014-03-05 21:35:08
Systém Microsoft Windows XP Professional Service Pack 3
System drive F: has 3 GB (23%) free of 11 GB
Total RAM: 1023 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:35:20, on 5.3.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\Ati2evxx.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\System32\svchost.exe
C:\Program Files\Online Armor\OAcat.exe
F:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Online Armor\oasrv.exe
F:\WINNT\Explorer.EXE
F:\WINNT\system32\spoolsv.exe
C:\Program Files\NETGATE\Amiti Antivirus\AmitiAvSrv.exe
F:\WINNT\system32\inetsrv\inetinfo.exe
F:\Program Files\Java\jre7\bin\jqs.exe
F:\WINNT\system32\tcpsvcs.exe
F:\WINNT\System32\snmp.exe
C:\Program Files\Online Armor\OAui.exe
C:\Program Files\NETGATE\Amiti Antivirus\AmitiAv.exe
C:\Program Files\Online Armor\OAhlp.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\WINNT\system32\wuauclt.exe
C:\Program Files\TeamSpeak 3 Client\ts3client_win32.exe
F:\Program Files\Mozilla Firefox\plugin-container.exe
C:\programy\mIRC\mirc.exe
F:\WINNT\Explorer.EXE
C:\zaznamy\RSIT.exe
F:\Program Files\trend micro\Jaroslav.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.atlas.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Online Armor\OAui.exe"
O4 - HKCU\..\Run: [AmitiAntivirus] C:\Program Files\NETGATE\Amiti Antivirus\AmitiAv.exe
O4 - HKUS\S-1-5-19\..\Run: [internat.exe] internat.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] F:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [internat.exe] internat.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] F:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] F:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] F:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - F:\WINNT\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\WINNT\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - F:\WINNT\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMITI Antivirus Engine (amitiavsrv) - NETGATE Technologies s.r.o. - C:\Program Files\NETGATE\Amiti Antivirus\AmitiAvSrv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINNT\system32\ati2sgag.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - F:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - F:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - F:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - F:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files\Online Armor\OAcat.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - F:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Online Armor\oasrv.exe

--
End of file - 5768 bytes

======Scheduled tasks folder======

F:\WINNT\tasks\Adobe Flash Player Updater.job
F:\WINNT\tasks\GoogleUpdateTaskMachineCore.job
F:\WINNT\tasks\GoogleUpdateTaskMachineUA.job
F:\WINNT\tasks\SmartDefrag.job
F:\WINNT\tasks\Wise Disk Cleaner Schedule Task.job

=========Mozilla firefox=========

ProfilePath - F:\Documents and Settings\Jaroslav\Data aplikací\Mozilla\Firefox\Profiles\pzogbnh9.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "jqs@sun.com:1.0, {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100823, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2, {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.6.5, {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10, {20a82645-c095-46ed-80e3-08825760534b}:0.0.0, {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, wrc@avast.com:9.0.2006.53, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.10"
prefs.js - "keyword.URL" - "http://www.webhledani.cz/results.aspx?i=39&tp=ab&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=F:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.70 Plugin
"Path"=F:\WINNT\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=F:\WINNT\system32\Adobe\Director\np32dsw_1205146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Web Player
"Path"=C:\Program Files\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=F:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=F:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=F:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=F:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=F:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=F:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll


F:\Program Files\Mozilla Firefox\plugins\
npDivxPlayerPlugin.dll
nsIDivxPlayerPlugin.xpt

F:\Documents and Settings\Jaroslav\Data aplikací\Mozilla\Firefox\Profiles\pzogbnh9.default\extensions\
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - F:\Program Files\Java\jre7\bin\ssv.dll [2013-11-24 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - F:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-11-24 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"@OnlineArmor GUI"=C:\Program Files\Online Armor\OAui.exe [2014-02-24 7558464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AmitiAntivirus"=C:\Program Files\NETGATE\Amiti Antivirus\AmitiAv.exe [2013-05-27 1557312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
F:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
F:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
F:\WINNT\system32\Ati2evxx.dll [2006-02-21 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
F:\WINNT\system32\wzcdlg.dll [2008-04-14 383488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - F:\WINNT\system32\wpdshserviceobj.dll [2008-08-08 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= []
"{4F07DA45-8170-4859-9B5F-037EF2970034}"=C:\Program Files\Online Armor\oaevent.dll [2014-02-24 1033968]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NBF]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nbf.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sglfb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tga.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"undockwithoutlogon"=1
"ShutdownWithoutLogon"=1
"NoDispCPL"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoResolveTrack"=1
"NoViewContextMenu"=0
"NoFileAssociate"=0
"NoFind"=0
"NoRun"=0
"NoClose"=0
"StartMenuLogoff"=0
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"F:\WINNT\system32\mqsvc.exe"="F:\WINNT\system32\mqsvc.exe:*:Enabled:Message Queuing"
"F:\Program Files\Skype\Plugin Manager\skypePM.exe"="F:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"F:\Program Files\mIRC\mirc.exe"="F:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"F:\Program Files\Google\Google Earth\plugin\geplugin.exe"="F:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"F:\Program Files\Google\Google Earth\client\googleearth.exe"="F:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"F:\Program Files\Skype\Phone\Skype.exe"="F:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"F:\WINNT\system32\mqsvc.exe"="F:\WINNT\system32\mqsvc.exe:*:Enabled:Message Queuing"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wavemapper"=msacm32.drv
"msacm.lhacm"=lhacm.acm
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"vidc.I420"=msh263.drv
"msacm.iac2"=F:\WINNT\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"aux"=mmdrv.dll
"wave2"=wdmaud.drv
"midi1"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"wdmaud.drv"=wdmaud.drv
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=F:\WINNT\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll

======List of files/folders created in the last 1 month======

2014-03-05 21:15:15 ----D---- F:\rsit
2014-02-22 23:07:24 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\OnlineArmor
2014-02-22 23:07:24 ----D---- F:\Documents and Settings\All Users\Data aplikací\OnlineArmor
2014-02-22 23:07:03 ----A---- F:\WINNT\system32\drivers\OAnet.sys
2014-02-22 23:07:03 ----A---- F:\WINNT\system32\drivers\OAmon.sys
2014-02-22 23:07:03 ----A---- F:\WINNT\system32\drivers\oahlp32.sys
2014-02-22 23:07:03 ----A---- F:\WINNT\system32\drivers\OADriver.sys
2014-02-22 22:52:13 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\Amiti Antivirus
2014-02-22 22:52:11 ----A---- F:\WINNT\system32\drivers\amitiav_guard.sys
2014-02-22 22:52:04 ----D---- F:\Documents and Settings\All Users\Data aplikací\NETGATE
2014-02-14 13:50:46 ----D---- F:\Program Files\Mozilla Firefox
2014-02-14 01:54:36 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me
2014-02-14 01:52:14 ----D---- F:\Program Files\Seznam.cz

======List of files/folders modified in the last 1 month======

2014-03-05 21:35:14 ----D---- F:\Program Files\trend micro
2014-03-05 21:15:27 ----AD---- F:\WINNT\Temp
2014-03-05 21:11:55 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\PSpad
2014-03-05 21:11:30 ----AD---- F:\WINNT\system32
2014-03-05 21:11:28 ----AD---- F:\WINNT
2014-03-05 21:04:02 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\mIRC
2014-03-05 20:11:20 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\TS3Client
2014-03-05 18:30:13 ----D---- F:\WINNT\system32\inetsrv
2014-03-05 18:26:20 ----D---- F:\WINNT\system32\NtmsData
2014-03-05 18:26:03 ----AD---- F:\WINNT\security
2014-03-05 00:32:37 ----N---- F:\WINNT\SchedLgU.Txt
2014-03-04 22:01:20 ----D---- F:\WINNT\system32\CatRoot2
2014-03-04 22:01:20 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\vlc
2014-03-04 21:55:15 ----D---- F:\WINNT\Prefetch
2014-02-25 19:09:25 ----RAD---- F:\Program Files
2014-02-25 19:06:38 ----D---- F:\WINNT\Minidump
2014-02-25 19:05:27 ----SD---- F:\WINNT\Tasks
2014-02-22 23:33:17 ----AD---- F:\WINNT\system32\drivers
2014-02-22 23:16:35 ----D---- F:\Documents and Settings\All Users\Data aplikací\Agnitum
2014-02-22 23:16:34 ----AD---- F:\WINNT\system32\config
2014-02-22 18:02:29 ----D---- F:\WINNT\system32\LogFiles
2014-02-22 18:02:25 ----AD---- F:\WINNT\Debug
2014-02-22 17:14:23 ----SHD---- F:\WINNT\Installer
2014-02-22 17:14:23 ----SD---- F:\Documents and Settings\Jaroslav\Data aplikací\Microsoft
2014-02-22 17:07:57 ----HD---- F:\Program Files\InstallShield Installation Information
2014-02-22 17:06:21 ----D---- F:\Program Files\Foxit Software
2014-02-22 17:04:56 ----D---- F:\Documents and Settings\All Users\Data aplikací\DivX
2014-02-22 17:04:13 ----D---- F:\Program Files\Common Files\DivX Shared
2014-02-22 16:28:45 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\IObit
2014-02-22 13:13:00 ----RSD---- F:\WINNT\assembly
2014-02-22 13:13:00 ----D---- F:\WINNT\Microsoft.NET
2014-02-22 01:41:00 ----HD---- F:\WINNT\inf
2014-02-22 01:40:54 ----RASHDC---- F:\WINNT\system32\dllcache
2014-02-22 01:31:42 ----D---- F:\WINNT\WinSxS
2014-02-22 01:31:34 ----AC---- F:\WINNT\system32\PerfStringBackup.INI
2014-02-22 01:24:41 ----D---- F:\WINNT\system32\MRT
2014-02-22 01:21:16 ----AC---- F:\WINNT\system32\MRT.exe
2014-02-22 01:11:21 ----D---- F:\Program Files\Internet Explorer
2014-02-22 01:10:55 ----D---- F:\WINNT\ie8updates
2014-02-20 23:53:10 ----AC---- F:\WINNT\system32\FlashPlayerApp.exe
2014-02-16 10:24:56 ----D---- F:\Program Files\Mozilla Maintenance Service
2014-02-12 22:19:12 ----AD---- F:\Program Files\Common Files
2014-02-06 20:29:22 ----D---- F:\Documents and Settings\Jaroslav\Data aplikací\DivX
2014-02-06 04:38:36 ----A---- F:\WINNT\system32\wininet.dll
2014-02-06 00:08:34 ----N---- F:\WINNT\system32\occache.dll
2014-02-06 00:08:34 ----N---- F:\WINNT\system32\mstime.dll
2014-02-06 00:08:34 ----N---- F:\WINNT\system32\mshtmled.dll
2014-02-06 00:08:34 ----N---- F:\WINNT\system32\licmgr10.dll
2014-02-06 00:08:34 ----N---- F:\WINNT\system32\jsproxy.dll
2014-02-06 00:08:34 ----A---- F:\WINNT\system32\urlmon.dll
2014-02-06 00:08:34 ----A---- F:\WINNT\system32\url.dll
2014-02-06 00:08:34 ----A---- F:\WINNT\system32\mshtml.dll
2014-02-06 00:08:34 ----A---- F:\WINNT\system32\msfeedsbs.dll
2014-02-06 00:08:34 ----A---- F:\WINNT\system32\msfeeds.dll
2014-02-06 00:08:33 ----N---- F:\WINNT\system32\iepeers.dll
2014-02-06 00:08:33 ----N---- F:\WINNT\system32\iedkcs32.dll
2014-02-06 00:08:33 ----N---- F:\WINNT\system32\corpol.dll
2014-02-06 00:08:33 ----A---- F:\WINNT\system32\iertutil.dll
2014-02-06 00:08:33 ----A---- F:\WINNT\system32\ieframe.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; F:\WINNT\system32\DRIVERS\agp440.sys [2008-04-14 42368]
R0 PxHelp20;PxHelp20; F:\WINNT\System32\Drivers\PxHelp20.sys [2009-11-14 43528]
R1 intelppm;Řadič procesoru Intel; F:\WINNT\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 OADevice;OADriver; \??\F:\WINNT\system32\drivers\OADriver.sys []
R1 oahlpXX;Online Armor helper driver; \??\F:\WINNT\system32\drivers\oahlp32.sys []
R1 OAmon;OAmon; \??\F:\WINNT\system32\drivers\OAmon.sys []
R1 OAnet;OAnet; \??\F:\WINNT\system32\drivers\OAnet.sys []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; F:\WINNT\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; F:\WINNT\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 PfModNT;PfModNT; \??\F:\WINNT\system32\PfModNT.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); F:\WINNT\system32\drivers\ALCXWDM.SYS [2003-06-19 752764]
R3 AmitiAvGuard;Amiti Antivirus Real-Time Shield Driver; F:\WINNT\System32\Drivers\amitiav_guard.sys [2013-05-23 16576]
R3 ati2mtag;ati2mtag; F:\WINNT\system32\DRIVERS\ati2mtag.sys [2006-02-21 1505792]
R3 HidUsb;Ovladač třídy standardu HID; F:\WINNT\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; F:\WINNT\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MQAC;Řízení přístupu služby MSMQ; \??\F:\WINNT\System32\drivers\mqac.sys []
R3 RMCAST;Reliable Multicast Protocol driver; \??\F:\WINNT\system32\drivers\RMCast.sys []
R3 ROOTMODEM;Microsoft Legacy Modem Driver; F:\WINNT\System32\Drivers\RootMdm.sys [2001-10-25 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; F:\WINNT\System32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 sbpci;SB PCI Family Audio Driver (WDM); F:\WINNT\system32\drivers\sbpci.sys [2002-10-22 668160]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; F:\WINNT\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; F:\WINNT\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; F:\WINNT\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 SpyEmrg;Amiti Antivirus Driver; F:\WINNT\System32\Drivers\spyemrg.sys []
S1 tga;tga; F:\WINNT\system32\drivers\tga.sys []
S3 EagleNT;EagleNT; \??\F:\WINNT\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\F:\WINNT\system32\drivers\EagleXNt.sys []
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; F:\WINNT\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 pwdrvio;pwdrvio; \??\F:\WINNT\system32\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\F:\WINNT\system32\pwdspio.sys []
S3 WINIO;WINIO; \??\D:\DRIVER\Audio\winio.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; F:\WINNT\system32\DRIVERS\WudfPf.sys [2008-08-08 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; F:\WINNT\system32\DRIVERS\wudfrd.sys [2008-08-08 82944]
S4 aic116x;aic116x; F:\WINNT\system32\drivers\aic116x.sys []
S4 ami0nt;ami0nt; F:\WINNT\system32\drivers\ami0nt.sys []
S4 BusLogic;BusLogic; F:\WINNT\system32\drivers\BusLogic.sys []
S4 cpqarry2;cpqarry2; F:\WINNT\system32\drivers\cpqarry2.sys []
S4 cpqfcalm;cpqfcalm; F:\WINNT\system32\drivers\cpqfcalm.sys []
S4 cpqfws2e;cpqfws2e; F:\WINNT\system32\drivers\cpqfws2e.sys []
S4 deckzpsx;deckzpsx; F:\WINNT\system32\drivers\deckzpsx.sys []
S4 EFS;EFS; F:\WINNT\system32\drivers\EFS.sys []
S4 Fd16_700;Fd16_700; F:\WINNT\system32\drivers\Fd16_700.sys []
S4 fireport;fireport; F:\WINNT\system32\drivers\fireport.sys []
S4 flashpnt;flashpnt; F:\WINNT\system32\drivers\flashpnt.sys []
S4 ipsraidn;ipsraidn; F:\WINNT\system32\drivers\ipsraidn.sys []
S4 lp6nds35;lp6nds35; F:\WINNT\system32\drivers\lp6nds35.sys []
S4 Ncrc710;Ncrc710; F:\WINNT\system32\drivers\Ncrc710.sys []
S4 Parallel;Parallel; F:\WINNT\system32\drivers\Parallel.sys []
S4 ql2100;ql2100; F:\WINNT\system32\drivers\ql2100.sys []
S4 ultra66;ultra66; F:\WINNT\system32\drivers\ultra66.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; F:\WINNT\system32\svchost.exe [2008-04-14 14336]
R2 amitiavsrv;AMITI Antivirus Engine; C:\Program Files\NETGATE\Amiti Antivirus\AmitiAvSrv.exe [2013-05-27 726848]
R2 Ati HotKey Poller;Ati HotKey Poller; F:\WINNT\system32\Ati2evxx.exe [2006-02-21 405504]
R2 IISADMIN;Správa služby IIS; F:\WINNT\system32\inetsrv\inetinfo.exe [2008-04-14 15872]
R2 Iprip;Naslouchání RIP; F:\WINNT\System32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; F:\Program Files\Java\jre7\bin\jqs.exe [2013-11-24 182696]
R2 MSFTPSVC;Publikování FTP; F:\WINNT\system32\inetsrv\inetinfo.exe [2008-04-14 15872]
R2 OAcat;Online Armor Helper Service; C:\Program Files\Online Armor\OAcat.exe [2014-02-24 584864]
R2 SimpTcp;Jednoduché služby TCP/IP; F:\WINNT\system32\tcpsvcs.exe [2001-10-25 19456]
R2 SMTPSVC;SMTP (Simple Mail Transport Protocol); F:\WINNT\System32\inetsrv\inetinfo.exe [2008-04-14 15872]
R2 SNMP;SNMP; F:\WINNT\System32\snmp.exe [2008-04-14 32768]
R2 SvcOnlineArmor;Online Armor; C:\Program Files\Online Armor\oasrv.exe [2014-02-24 4457688]
R2 W3SVC;Publikování na webu; F:\WINNT\system32\inetsrv\inetinfo.exe [2008-04-14 15872]
S2 ATI Smart;ATI Smart; F:\WINNT\system32\ati2sgag.exe [2009-09-29 593920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; F:\WINNT\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); F:\Program Files\Google\Update\GoogleUpdate.exe [2010-06-16 136176]
S2 MSMQ;Message Queuing; F:\WINNT\System32\mqsvc.exe [2008-04-14 4608]
S2 SkypeUpdate;Skype Updater; F:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; F:\WINNT\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-20 257928]
S3 aspnet_state;ASP.NET State Service; F:\WINNT\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; F:\WINNT\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); F:\Program Files\Google\Update\GoogleUpdate.exe [2010-06-16 136176]
S3 IDriverT;InstallDriver Table Manager; F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; F:\WINNT\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; F:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-02-14 118896]
S3 SNMPTRAP;Zachytávání pro službu SNMP; F:\WINNT\System32\snmptrap.exe [2008-04-14 8704]
S3 UtilMan;Správce nástrojů; F:\WINNT\System32\UtilMan.exe [2008-04-14 50176]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; F:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; F:\WINNT\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; F:\WINNT\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; F:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; F:\WINNT\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Prosím o preventivní kontrolu logu

Napsal: 06 bře 2014 07:33
od JaRon
prescanuj PC s MBAM + pridaj log z TDSSKiller

Re: Prosím o preventivní kontrolu logu

Napsal: 06 bře 2014 23:03
od Knoll.Jaroslav
Tady jsou logy

Nejdříve z MBAM

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.03.06.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Jaroslav :: JAROSLAV-KNOLL [administrátor]

6.3.2014 20:30:45
MBAM-log-2014-03-06 (22-51-10).txt

Typ: Kompletní kontrola (C:\|E:\|F:\|H:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 253822
Uplynulý čas: 2 hodin, 18 minut, 33 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 2
F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me\cache (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 4
F:\Documents and Settings\Jaroslav\Dokumenty\Downloads\GotClip_Setup.exe (PUP.Optional.Remarkit) -> Nebyla provedena žádná instrukce.
F:\Documents and Settings\Jaroslav\Local Settings\Data aplikací\genienext\nengine.dll (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.
F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Nebyla provedena žádná instrukce.

(konec)

A teď z TDDS killeru

23:05:22.0328 0584 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
23:05:25.0187 0584 ============================================================
23:05:25.0187 0584 Current date / time: 2014/03/06 23:05:25.0187
23:05:25.0187 0584 SystemInfo:
23:05:25.0187 0584
23:05:25.0187 0584 OS Version: 5.1.2600 ServicePack: 3.0
23:05:25.0187 0584 Product type: Workstation
23:05:25.0187 0584 ComputerName: JAROSLAV-KNOLL
23:05:25.0187 0584 UserName: Jaroslav
23:05:25.0187 0584 Windows directory: F:\WINNT
23:05:25.0187 0584 System windows directory: F:\WINNT
23:05:25.0187 0584 Processor architecture: Intel x86
23:05:25.0187 0584 Number of processors: 1
23:05:25.0187 0584 Page size: 0x1000
23:05:25.0187 0584 Boot type: Normal boot
23:05:25.0187 0584 ============================================================
23:05:29.0937 0584 Drive \Device\Harddisk0\DR0 - Size: 0x25458C000 (9.32 Gb), SectorSize: 0x200, Cylinders: 0x50C, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000054
23:05:29.0953 0584 Drive \Device\Harddisk1\DR1 - Size: 0x9516AE000 (37.27 Gb), SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
23:05:29.0968 0584 Drive \Device\Harddisk2\DR5 - Size: 0x1EC000000 (7.69 Gb), SectorSize: 0x200, Cylinders: 0x3EB, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
23:05:29.0968 0584 ============================================================
23:05:29.0968 0584 \Device\Harddisk0\DR0:
23:05:29.0968 0584 MBR partitions:
23:05:29.0968 0584 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x129D971
23:05:29.0968 0584 \Device\Harddisk1\DR1:
23:05:29.0968 0584 MBR partitions:
23:05:29.0968 0584 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x160025D
23:05:29.0984 0584 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x16002DB, BlocksNum 0x3488EE6
23:05:29.0984 0584 \Device\Harddisk2\DR5:
23:05:30.0000 0584 MBR partitions:
23:05:30.0000 0584 \Device\Harddisk2\DR5\Partition1: MBR, Type 0xB, StartLBA 0x20, BlocksNum 0xF5FFE0
23:05:30.0000 0584 ============================================================
23:05:30.0015 0584 F: <-> \Device\Harddisk1\DR1\Partition1
23:05:30.0031 0584 H: <-> \Device\Harddisk0\DR0\Partition1
23:05:30.0062 0584 C: <-> \Device\Harddisk1\DR1\Partition2
23:05:30.0062 0584 ============================================================
23:05:30.0062 0584 Initialize success
23:05:30.0062 0584 ============================================================
23:05:36.0515 4076 ============================================================
23:05:36.0515 4076 Scan started
23:05:36.0515 4076 Mode: Manual;
23:05:36.0515 4076 ============================================================
23:05:37.0421 4076 ================ Scan system memory ========================
23:05:37.0421 4076 System memory - ok
23:05:37.0437 4076 ================ Scan services =============================
23:05:37.0562 4076 [ D76E9F5A991458A9F7E28395479B3150 ] 6to4 F:\WINNT\System32\6to4svc.dll
23:05:37.0562 4076 6to4 - ok
23:05:37.0593 4076 Abiosdsk - ok
23:05:37.0609 4076 abp480n5 - ok
23:05:37.0640 4076 [ 4FE34F1F3126B61FCC6B2043AA8112C9 ] ACPI F:\WINNT\system32\DRIVERS\ACPI.sys
23:05:37.0656 4076 ACPI - ok
23:05:37.0687 4076 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC F:\WINNT\system32\drivers\ACPIEC.sys
23:05:37.0687 4076 ACPIEC - ok
23:05:37.0781 4076 [ F7AB315A4D400CA876381D1E188A2E20 ] AdobeFlashPlayerUpdateSvc F:\WINNT\system32\Macromed\Flash\FlashPlayerUpdateService.exe
23:05:37.0781 4076 AdobeFlashPlayerUpdateSvc - ok
23:05:37.0796 4076 adpu160m - ok
23:05:37.0843 4076 [ 8BED39E3C35D6A489438B8141717A557 ] aec F:\WINNT\system32\drivers\aec.sys
23:05:37.0843 4076 aec - ok
23:05:37.0890 4076 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD F:\WINNT\System32\drivers\afd.sys
23:05:37.0890 4076 AFD - ok
23:05:37.0921 4076 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 F:\WINNT\system32\DRIVERS\agp440.sys
23:05:37.0937 4076 agp440 - ok
23:05:37.0937 4076 Aha154x - ok
23:05:37.0953 4076 aic116x - ok
23:05:37.0968 4076 aic78u2 - ok
23:05:37.0984 4076 aic78xx - ok
23:05:38.0046 4076 [ 02D94D2D336D3DE8C5E8FE04A62D552D ] ALCXWDM F:\WINNT\system32\drivers\ALCXWDM.SYS
23:05:38.0078 4076 ALCXWDM - ok
23:05:38.0109 4076 [ E0A6FA244B8624D78FE5FF6F56A33BAE ] Alerter F:\WINNT\system32\alrsvc.dll
23:05:38.0109 4076 Alerter - ok
23:05:38.0140 4076 [ 88842DE939A827577BF24243699AC80A ] ALG F:\WINNT\System32\alg.exe
23:05:38.0140 4076 ALG - ok
23:05:38.0156 4076 AliIde - ok
23:05:38.0171 4076 ami0nt - ok
23:05:38.0203 4076 [ A23277E90EB553CE3A97D86C77FF3CAA ] AmitiAvGuard F:\WINNT\system32\Drivers\amitiav_guard.sys
23:05:38.0203 4076 AmitiAvGuard - ok
23:05:38.0312 4076 [ 07741A7956ED70847C1D21AEDFFA7EBA ] amitiavsrv C:\Program Files\NETGATE\Amiti Antivirus\AmitiAvSrv.exe
23:05:38.0328 4076 amitiavsrv - ok
23:05:38.0343 4076 amsint - ok
23:05:38.0390 4076 [ 6B8E7A90E576D4FE308F97C69060A171 ] AppMgmt F:\WINNT\System32\appmgmts.dll
23:05:38.0390 4076 AppMgmt - ok
23:05:38.0406 4076 asc - ok
23:05:38.0421 4076 asc3350p - ok
23:05:38.0437 4076 asc3550 - ok
23:05:38.0578 4076 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state F:\WINNT\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
23:05:38.0578 4076 aspnet_state - ok
23:05:38.0609 4076 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac F:\WINNT\system32\DRIVERS\asyncmac.sys
23:05:38.0609 4076 AsyncMac - ok
23:05:38.0656 4076 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi F:\WINNT\system32\DRIVERS\atapi.sys
23:05:38.0656 4076 atapi - ok
23:05:38.0671 4076 Atdisk - ok
23:05:38.0718 4076 [ BBA22521D24625C7A7B8D57FB20A812E ] Ati HotKey Poller F:\WINNT\system32\Ati2evxx.exe
23:05:38.0734 4076 Ati HotKey Poller - ok
23:05:38.0796 4076 [ EF94E95E9D5366A88275FBB15E9D6E74 ] ATI Smart F:\WINNT\system32\ati2sgag.exe
23:05:38.0828 4076 ATI Smart - ok
23:05:38.0921 4076 [ 07AC9A98EA70B5A6655A5797174BD282 ] ati2mtag F:\WINNT\system32\DRIVERS\ati2mtag.sys
23:05:38.0984 4076 ati2mtag - ok
23:05:39.0031 4076 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc F:\WINNT\system32\DRIVERS\atmarpc.sys
23:05:39.0031 4076 Atmarpc - ok
23:05:39.0078 4076 [ DE31B88962A8645DBA5A37B993E7B0F1 ] AudioSrv F:\WINNT\System32\audiosrv.dll
23:05:39.0078 4076 AudioSrv - ok
23:05:39.0125 4076 [ D9F724AA26C010A217C97606B160ED68 ] audstub F:\WINNT\system32\DRIVERS\audstub.sys
23:05:39.0125 4076 audstub - ok
23:05:39.0156 4076 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep F:\WINNT\system32\drivers\Beep.sys
23:05:39.0171 4076 Beep - ok
23:05:39.0218 4076 [ 19395D092FD85DDC2D9C7729CF5A2AC8 ] BITS F:\WINNT\system32\qmgr.dll
23:05:39.0250 4076 BITS - ok
23:05:39.0281 4076 [ 89E739BBA5F636297EA5B5F811189E06 ] Browser F:\WINNT\System32\browser.dll
23:05:39.0296 4076 Browser - ok
23:05:39.0296 4076 BusLogic - ok
23:05:39.0343 4076 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k F:\WINNT\system32\drivers\cbidf2k.sys
23:05:39.0343 4076 cbidf2k - ok
23:05:39.0375 4076 cd20xrnt - ok
23:05:39.0390 4076 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio F:\WINNT\system32\drivers\Cdaudio.sys
23:05:39.0390 4076 Cdaudio - ok
23:05:39.0421 4076 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs F:\WINNT\system32\drivers\Cdfs.sys
23:05:39.0437 4076 Cdfs - ok
23:05:39.0453 4076 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom F:\WINNT\system32\DRIVERS\cdrom.sys
23:05:39.0453 4076 Cdrom - ok
23:05:39.0468 4076 Changer - ok
23:05:39.0484 4076 [ E390DC1D7C461D7D56EC53402F329928 ] cisvc F:\WINNT\system32\cisvc.exe
23:05:39.0500 4076 cisvc - ok
23:05:39.0531 4076 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA ] ClipSrv F:\WINNT\system32\clipsrv.exe
23:05:39.0531 4076 ClipSrv - ok
23:05:39.0578 4076 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 F:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
23:05:39.0593 4076 clr_optimization_v2.0.50727_32 - ok
23:05:39.0625 4076 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 F:\WINNT\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
23:05:39.0625 4076 clr_optimization_v4.0.30319_32 - ok
23:05:39.0640 4076 CmdIde - ok
23:05:39.0656 4076 COMSysApp - ok
23:05:39.0687 4076 Cpqarray - ok
23:05:39.0703 4076 cpqarry2 - ok
23:05:39.0703 4076 cpqfcalm - ok
23:05:39.0734 4076 cpqfws2e - ok
23:05:39.0765 4076 [ F3AB0933CBD166D271992F411C27CCAF ] CryptSvc F:\WINNT\System32\cryptsvc.dll
23:05:39.0765 4076 CryptSvc - ok
23:05:39.0781 4076 dac2w2k - ok
23:05:39.0796 4076 dac960nt - ok
23:05:39.0859 4076 [ BE27674D1CBC3214AEC84B4336A38BBF ] DcomLaunch F:\WINNT\system32\rpcss.dll
23:05:39.0890 4076 DcomLaunch - ok
23:05:39.0906 4076 deckzpsx - ok
23:05:39.0937 4076 [ 8C9A53E285AC5E6704844D0459EC85BE ] Dhcp F:\WINNT\System32\dhcpcsvc.dll
23:05:39.0937 4076 Dhcp - ok
23:05:39.0968 4076 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk F:\WINNT\system32\DRIVERS\disk.sys
23:05:39.0984 4076 Disk - ok
23:05:40.0000 4076 dmadmin - ok
23:05:40.0031 4076 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C ] dmboot F:\WINNT\system32\drivers\dmboot.sys
23:05:40.0062 4076 dmboot - ok
23:05:40.0078 4076 [ FFF1720AF51171F32F1EAD5CF71F2810 ] dmio F:\WINNT\system32\DRIVERS\dmio.sys
23:05:40.0093 4076 dmio - ok
23:05:40.0093 4076 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload F:\WINNT\system32\drivers\dmload.sys
23:05:40.0109 4076 dmload - ok
23:05:40.0156 4076 [ 2BFEFE9E865655A76982F050450B9591 ] dmserver F:\WINNT\System32\dmserver.dll
23:05:40.0171 4076 dmserver - ok
23:05:40.0203 4076 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic F:\WINNT\system32\drivers\DMusic.sys
23:05:40.0203 4076 DMusic - ok
23:05:40.0250 4076 [ DFAA406BF19F4EE806A6F8D4342137F7 ] Dnscache F:\WINNT\System32\dnsrslvr.dll
23:05:40.0250 4076 Dnscache - ok
23:05:40.0296 4076 [ 4A3E2BD20157A0946751229E92EB8621 ] Dot3svc F:\WINNT\System32\dot3svc.dll
23:05:40.0296 4076 Dot3svc - ok
23:05:40.0312 4076 dpti2o - ok
23:05:40.0343 4076 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud F:\WINNT\system32\drivers\drmkaud.sys
23:05:40.0343 4076 drmkaud - ok
23:05:40.0359 4076 EagleNT - ok
23:05:40.0359 4076 EagleXNt - ok
23:05:40.0421 4076 [ 0887D9C2BE8D940778CAD1E3B85F2A41 ] EapHost F:\WINNT\System32\eapsvc.dll
23:05:40.0421 4076 EapHost - ok
23:05:40.0437 4076 EFS - ok
23:05:40.0453 4076 [ A2A4912798F2BE706ABADD3D30800D16 ] ERSvc F:\WINNT\System32\ersvc.dll
23:05:40.0468 4076 ERSvc - ok
23:05:40.0500 4076 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] Eventlog F:\WINNT\system32\services.exe
23:05:40.0515 4076 Eventlog - ok
23:05:40.0562 4076 [ A371F11EF07653591C8DE26AFB13CE7F ] EventSystem F:\WINNT\system32\es.dll
23:05:40.0578 4076 EventSystem - ok
23:05:40.0625 4076 [ 38D332A6D56AF32635675F132548343E ] Fastfat F:\WINNT\system32\drivers\Fastfat.sys
23:05:40.0625 4076 Fastfat - ok
23:05:40.0687 4076 [ EE9A2B9EA968A792A053C9D1A86BF870 ] FastUserSwitchingCompatibility F:\WINNT\System32\shsvcs.dll
23:05:40.0687 4076 FastUserSwitchingCompatibility - ok
23:05:40.0703 4076 Fd16_700 - ok
23:05:40.0734 4076 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc F:\WINNT\system32\DRIVERS\fdc.sys
23:05:40.0734 4076 Fdc - ok
23:05:40.0765 4076 [ AC366695A0796560AA37215AD5762AAF ] Fips F:\WINNT\system32\drivers\Fips.sys
23:05:40.0781 4076 Fips - ok
23:05:40.0796 4076 fireport - ok
23:05:40.0796 4076 flashpnt - ok
23:05:40.0828 4076 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk F:\WINNT\system32\DRIVERS\flpydisk.sys
23:05:40.0828 4076 Flpydisk - ok
23:05:40.0875 4076 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr F:\WINNT\system32\drivers\fltmgr.sys
23:05:40.0875 4076 FltMgr - ok
23:05:40.0937 4076 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 F:\WINNT\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
23:05:40.0937 4076 FontCache3.0.0.0 - ok
23:05:40.0984 4076 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec F:\WINNT\system32\drivers\Fs_Rec.sys
23:05:40.0984 4076 Fs_Rec - ok
23:05:41.0015 4076 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk F:\WINNT\system32\DRIVERS\ftdisk.sys
23:05:41.0015 4076 Ftdisk - ok
23:05:41.0062 4076 [ 065639773D8B03F33577F6CDAEA21063 ] gameenum F:\WINNT\system32\DRIVERS\gameenum.sys
23:05:41.0062 4076 gameenum - ok
23:05:41.0125 4076 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc F:\WINNT\system32\DRIVERS\msgpc.sys
23:05:41.0125 4076 Gpc - ok
23:05:41.0203 4076 [ F02A533F517EB38333CB12A9E8963773 ] gupdate F:\Program Files\Google\Update\GoogleUpdate.exe
23:05:41.0203 4076 gupdate - ok
23:05:41.0218 4076 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem F:\Program Files\Google\Update\GoogleUpdate.exe
23:05:41.0265 4076 gupdatem - ok
23:05:41.0343 4076 [ FCFE31FB75F8A6295B6B0AF87A626282 ] helpsvc F:\WINNT\PCHealth\HelpCtr\Binaries\pchsvc.dll
23:05:41.0343 4076 helpsvc - ok
23:05:41.0359 4076 HidServ - ok
23:05:41.0437 4076 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb F:\WINNT\system32\DRIVERS\hidusb.sys
23:05:41.0453 4076 HidUsb - ok
23:05:41.0484 4076 [ 7A6B320928F86BC851530D63C82965D9 ] hkmsvc F:\WINNT\System32\kmsvc.dll
23:05:41.0484 4076 hkmsvc - ok
23:05:41.0500 4076 hpn - ok
23:05:41.0593 4076 [ F6AACF5BCE2893E0C1754AFEB672E5C9 ] HTTP F:\WINNT\system32\Drivers\HTTP.sys
23:05:41.0609 4076 HTTP - ok
23:05:41.0656 4076 [ 58FE2F2DA3BC5573F4A35B3760D3125F ] HTTPFilter F:\WINNT\System32\w3ssl.dll
23:05:41.0703 4076 HTTPFilter - ok
23:05:41.0718 4076 i2omgmt - ok
23:05:41.0734 4076 i2omp - ok
23:05:41.0765 4076 [ C528E27945367191E7BAE364930B6932 ] i8042prt F:\WINNT\system32\DRIVERS\i8042prt.sys
23:05:41.0781 4076 i8042prt - ok
23:05:41.0921 4076 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
23:05:41.0921 4076 IDriverT - ok
23:05:42.0031 4076 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc F:\WINNT\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
23:05:42.0062 4076 idsvc - ok
23:05:42.0140 4076 [ 07AD42303519A955560B5A19FE20B68F ] IISADMIN F:\WINNT\system32\inetsrv\inetinfo.exe
23:05:42.0140 4076 IISADMIN - ok
23:05:42.0171 4076 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi F:\WINNT\system32\DRIVERS\imapi.sys
23:05:42.0171 4076 Imapi - ok
23:05:42.0218 4076 [ F7B93AAFAD33B2320954C17E26C8D361 ] ImapiService F:\WINNT\system32\imapi.exe
23:05:42.0234 4076 ImapiService - ok
23:05:42.0265 4076 ini910u - ok
23:05:42.0281 4076 [ 57D928E548B38502ABBA7A77A6EB7312 ] IntelIde F:\WINNT\system32\DRIVERS\intelide.sys
23:05:42.0296 4076 IntelIde - ok
23:05:42.0328 4076 [ 27B290D632AF2CF3CF40BFDDB7370985 ] intelppm F:\WINNT\system32\DRIVERS\intelppm.sys
23:05:42.0328 4076 intelppm - ok
23:05:42.0359 4076 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw F:\WINNT\system32\drivers\ip6fw.sys
23:05:42.0359 4076 Ip6Fw - ok
23:05:42.0406 4076 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver F:\WINNT\system32\DRIVERS\ipfltdrv.sys
23:05:42.0406 4076 IpFilterDriver - ok
23:05:42.0421 4076 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp F:\WINNT\system32\DRIVERS\ipinip.sys
23:05:42.0437 4076 IpInIp - ok
23:05:42.0453 4076 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat F:\WINNT\system32\DRIVERS\ipnat.sys
23:05:42.0453 4076 IpNat - ok
23:05:42.0500 4076 [ 77BC45F0DC276D8CA1FE3F7E6A9E4735 ] Iprip F:\WINNT\System32\iprip.dll
23:05:42.0500 4076 Iprip - ok
23:05:42.0531 4076 [ 23C74D75E36E7158768DD63D92789A91 ] IPSEC F:\WINNT\system32\DRIVERS\ipsec.sys
23:05:42.0531 4076 IPSEC - ok
23:05:42.0546 4076 ipsraidn - ok
23:05:42.0578 4076 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM F:\WINNT\system32\DRIVERS\irenum.sys
23:05:42.0593 4076 IRENUM - ok
23:05:42.0640 4076 [ CC9F8A2D60AED1A51A3AC34C59B987AE ] isapnp F:\WINNT\system32\DRIVERS\isapnp.sys
23:05:42.0640 4076 isapnp - ok
23:05:42.0734 4076 [ 80A79264302910C7C24BA7E44267EFEF ] JavaQuickStarterService F:\Program Files\Java\jre7\bin\jqs.exe
23:05:42.0734 4076 JavaQuickStarterService - ok
23:05:42.0781 4076 [ 1B6162FE7F66B1A71A4B70F941C4AA9B ] Kbdclass F:\WINNT\system32\DRIVERS\kbdclass.sys
23:05:42.0781 4076 Kbdclass - ok
23:05:42.0828 4076 [ 692BCF44383D056AED41B045A323D378 ] kmixer F:\WINNT\system32\drivers\kmixer.sys
23:05:42.0843 4076 kmixer - ok
23:05:42.0875 4076 [ 1705745D900DABF2D89F90EBADDC7517 ] KSecDD F:\WINNT\system32\drivers\KSecDD.sys
23:05:42.0875 4076 KSecDD - ok
23:05:42.0906 4076 [ 21920AC69594AB021237054FA728FE46 ] lanmanserver F:\WINNT\System32\srvsvc.dll
23:05:42.0921 4076 lanmanserver - ok
23:05:42.0968 4076 [ 936C1D110232D23B621CB0196E4F80F0 ] lanmanworkstation F:\WINNT\System32\wkssvc.dll
23:05:42.0984 4076 lanmanworkstation - ok
23:05:43.0000 4076 lbrtfdc - ok
23:05:43.0062 4076 [ 0AB159F536E3E8F7F07113702A07CCA5 ] LmHosts F:\WINNT\System32\lmhsvc.dll
23:05:43.0062 4076 LmHosts - ok
23:05:43.0078 4076 lp6nds35 - ok
23:05:43.0109 4076 [ 0DB7527DB188C7D967A37BB51BBF3963 ] MBAMSwissArmy F:\WINNT\system32\drivers\mbamswissarmy.sys
23:05:43.0109 4076 MBAMSwissArmy - ok
23:05:43.0156 4076 [ 221CD1C815B8A6B79389C3F5D1018DE8 ] Messenger F:\WINNT\System32\msgsvc.dll
23:05:43.0171 4076 Messenger - ok
23:05:43.0218 4076 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd F:\WINNT\system32\drivers\mnmdd.sys
23:05:43.0218 4076 mnmdd - ok
23:05:43.0265 4076 [ 9A57D046F88F4B69751B11FD40088A61 ] mnmsrvc F:\WINNT\System32\mnmsrvc.exe
23:05:43.0265 4076 mnmsrvc - ok
23:05:43.0312 4076 [ 44032B0C6D9954D3FD26438330B99EE7 ] Modem F:\WINNT\system32\drivers\Modem.sys
23:05:43.0312 4076 Modem - ok
23:05:43.0328 4076 [ 4CB582831DBDE63CE43B45D771218374 ] Mouclass F:\WINNT\system32\DRIVERS\mouclass.sys
23:05:43.0343 4076 Mouclass - ok
23:05:43.0375 4076 [ BB269EBA740737AB749B214D568B6812 ] mouhid F:\WINNT\system32\DRIVERS\mouhid.sys
23:05:43.0375 4076 mouhid - ok
23:05:43.0421 4076 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr F:\WINNT\system32\drivers\MountMgr.sys
23:05:43.0421 4076 MountMgr - ok
23:05:43.0453 4076 [ 338037EFA0E8E8699B2667D57B751574 ] MozillaMaintenance F:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
23:05:43.0468 4076 MozillaMaintenance - ok
23:05:43.0500 4076 [ 70C14F5CCA5CF73F8A645C73A01D8726 ] MQAC F:\WINNT\System32\drivers\mqac.sys
23:05:43.0515 4076 MQAC - ok
23:05:43.0531 4076 mraid35x - ok
23:05:43.0578 4076 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV F:\WINNT\system32\DRIVERS\mrxdav.sys
23:05:43.0578 4076 MRxDAV - ok
23:05:43.0640 4076 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb F:\WINNT\system32\DRIVERS\mrxsmb.sys
23:05:43.0671 4076 MRxSmb - ok
23:05:43.0718 4076 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D ] MSDTC F:\WINNT\System32\msdtc.exe
23:05:43.0718 4076 MSDTC - ok
23:05:43.0781 4076 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs F:\WINNT\system32\drivers\Msfs.sys
23:05:43.0781 4076 Msfs - ok
23:05:43.0812 4076 [ 07AD42303519A955560B5A19FE20B68F ] MSFTPSVC F:\WINNT\system32\inetsrv\inetinfo.exe
23:05:43.0812 4076 MSFTPSVC - ok
23:05:43.0828 4076 MSIServer - ok
23:05:43.0859 4076 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV F:\WINNT\system32\drivers\MSKSSRV.sys
23:05:43.0859 4076 MSKSSRV - ok
23:05:43.0890 4076 [ EFD41125C99B4C18744EBF290397F311 ] MSMQ F:\WINNT\System32\mqsvc.exe
23:05:43.0890 4076 MSMQ - ok
23:05:43.0921 4076 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK F:\WINNT\system32\drivers\MSPCLOCK.sys
23:05:43.0921 4076 MSPCLOCK - ok
23:05:43.0968 4076 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM F:\WINNT\system32\drivers\MSPQM.sys
23:05:43.0968 4076 MSPQM - ok
23:05:43.0984 4076 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios F:\WINNT\system32\DRIVERS\mssmbios.sys
23:05:43.0984 4076 mssmbios - ok
23:05:44.0031 4076 [ CA3E22598F411199ADC2DFEE76CD0AE0 ] ms_mpu401 F:\WINNT\system32\drivers\msmpu401.sys
23:05:44.0031 4076 ms_mpu401 - ok
23:05:44.0078 4076 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup F:\WINNT\system32\drivers\Mup.sys
23:05:44.0078 4076 Mup - ok
23:05:44.0125 4076 [ 6EA362E9DB03D44F6B996F4D8BE237E9 ] napagent F:\WINNT\System32\qagentrt.dll
23:05:44.0140 4076 napagent - ok
23:05:44.0156 4076 Ncrc710 - ok
23:05:44.0203 4076 [ 1DF7F42665C94B825322FAE71721130D ] NDIS F:\WINNT\system32\drivers\NDIS.sys
23:05:44.0203 4076 NDIS - ok
23:05:44.0281 4076 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi F:\WINNT\system32\DRIVERS\ndistapi.sys
23:05:44.0296 4076 NdisTapi - ok
23:05:44.0343 4076 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio F:\WINNT\system32\DRIVERS\ndisuio.sys
23:05:44.0343 4076 Ndisuio - ok
23:05:44.0390 4076 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan F:\WINNT\system32\DRIVERS\ndiswan.sys
23:05:44.0406 4076 NdisWan - ok
23:05:44.0453 4076 [ 2F597BB467E05B1FE3830EABD821B8E0 ] NDProxy F:\WINNT\system32\drivers\NDProxy.sys
23:05:44.0453 4076 NDProxy - ok
23:05:44.0500 4076 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS F:\WINNT\system32\DRIVERS\netbios.sys
23:05:44.0500 4076 NetBIOS - ok
23:05:44.0562 4076 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT F:\WINNT\system32\DRIVERS\netbt.sys
23:05:44.0562 4076 NetBT - ok
23:05:44.0609 4076 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDE F:\WINNT\system32\netdde.exe
23:05:44.0625 4076 NetDDE - ok
23:05:44.0656 4076 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDEdsdm F:\WINNT\system32\netdde.exe
23:05:44.0671 4076 NetDDEdsdm - ok
23:05:44.0718 4076 [ ED0A176354487CEED65B80A7148AB739 ] Netlogon F:\WINNT\system32\lsass.exe
23:05:44.0734 4076 Netlogon - ok
23:05:44.0750 4076 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40 ] Netman F:\WINNT\System32\netman.dll
23:05:44.0781 4076 Netman - ok
23:05:44.0828 4076 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing F:\WINNT\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
23:05:44.0843 4076 NetTcpPortSharing - ok
23:05:44.0890 4076 [ 39EE7C3BFBC64BA87CC8CF67386E814C ] Nla F:\WINNT\System32\mswsock.dll
23:05:44.0906 4076 Nla - ok
23:05:44.0968 4076 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs F:\WINNT\system32\drivers\Npfs.sys
23:05:44.0968 4076 Npfs - ok
23:05:45.0046 4076 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs F:\WINNT\system32\drivers\Ntfs.sys
23:05:45.0078 4076 Ntfs - ok
23:05:45.0125 4076 [ ED0A176354487CEED65B80A7148AB739 ] NtLmSsp F:\WINNT\system32\lsass.exe
23:05:45.0140 4076 NtLmSsp - ok
23:05:45.0234 4076 [ 023DD70573D644F3D9C8B1258A7BFD08 ] NtmsSvc F:\WINNT\system32\ntmssvc.dll
23:05:45.0265 4076 NtmsSvc - ok
23:05:45.0296 4076 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null F:\WINNT\system32\drivers\Null.sys
23:05:45.0296 4076 Null - ok
23:05:45.0312 4076 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt F:\WINNT\system32\DRIVERS\nwlnkflt.sys
23:05:45.0328 4076 NwlnkFlt - ok
23:05:45.0343 4076 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd F:\WINNT\system32\DRIVERS\nwlnkfwd.sys
23:05:45.0343 4076 NwlnkFwd - ok
23:05:45.0468 4076 [ C1342DDE1D9D33B670DC91F146AFEBAA ] OAcat C:\Program Files\Online Armor\OAcat.exe
23:05:45.0500 4076 OAcat - ok
23:05:45.0546 4076 [ EE9DCAC3D1E7B9CD0737463B11DDA2B7 ] OADevice F:\WINNT\system32\drivers\OADriver.sys
23:05:45.0546 4076 OADevice - ok
23:05:45.0578 4076 [ AC43969DA69E97B5A8E4B63A599F309F ] oahlpXX F:\WINNT\system32\drivers\oahlp32.sys
23:05:45.0578 4076 oahlpXX - ok
23:05:45.0593 4076 [ 3A317DA68E8CDE920C0572307EDDC4BF ] OAmon F:\WINNT\system32\drivers\OAmon.sys
23:05:45.0609 4076 OAmon - ok
23:05:45.0625 4076 [ B9913B154FE9F28914221E9A6348E950 ] OAnet F:\WINNT\system32\drivers\OAnet.sys
23:05:45.0625 4076 OAnet - ok
23:05:45.0656 4076 Parallel - ok
23:05:45.0703 4076 [ 46F8DB73B4A53E543F8E371DC7C75BAE ] Parport F:\WINNT\system32\drivers\Parport.sys
23:05:45.0703 4076 Parport - ok
23:05:45.0750 4076 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr F:\WINNT\system32\drivers\PartMgr.sys
23:05:45.0750 4076 PartMgr - ok
23:05:45.0781 4076 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm F:\WINNT\system32\drivers\ParVdm.sys
23:05:45.0781 4076 ParVdm - ok
23:05:45.0828 4076 [ 6CE351D149CB4BEFC702951E471E1730 ] PCI F:\WINNT\system32\DRIVERS\pci.sys
23:05:45.0828 4076 PCI - ok
23:05:45.0859 4076 PCIDump - ok
23:05:45.0890 4076 [ 2DA4EC85E0EA7A45C6B2A05820492D5A ] PCIIde F:\WINNT\system32\drivers\PCIIde.sys
23:05:45.0906 4076 PCIIde - ok
23:05:45.0937 4076 [ 4FC31E6C19A5CE5198B1ABFF94CAE758 ] Pcmcia F:\WINNT\system32\drivers\Pcmcia.sys
23:05:45.0937 4076 Pcmcia - ok
23:05:45.0968 4076 PDCOMP - ok
23:05:45.0984 4076 PDFRAME - ok
23:05:46.0015 4076 PDRELI - ok
23:05:46.0031 4076 PDRFRAME - ok
23:05:46.0062 4076 perc2 - ok
23:05:46.0093 4076 perc2hib - ok
23:05:46.0203 4076 [ B293F05AD9120B0232C28945C1E98CD0 ] PfModNT F:\WINNT\system32\PfModNT.sys
23:05:46.0218 4076 PfModNT - ok
23:05:46.0250 4076 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] PlugPlay F:\WINNT\system32\services.exe
23:05:46.0281 4076 PlugPlay - ok
23:05:46.0296 4076 [ ED0A176354487CEED65B80A7148AB739 ] PolicyAgent F:\WINNT\system32\lsass.exe
23:05:46.0312 4076 PolicyAgent - ok
23:05:46.0375 4076 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport F:\WINNT\system32\DRIVERS\raspptp.sys
23:05:46.0375 4076 PptpMiniport - ok
23:05:46.0390 4076 [ ED0A176354487CEED65B80A7148AB739 ] ProtectedStorage F:\WINNT\system32\lsass.exe
23:05:46.0421 4076 ProtectedStorage - ok
23:05:46.0453 4076 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink F:\WINNT\system32\DRIVERS\ptilink.sys
23:05:46.0453 4076 Ptilink - ok
23:05:46.0500 4076 [ 99CF0190F1F346CB0A0BBD1873683425 ] pwdrvio F:\WINNT\system32\pwdrvio.sys
23:05:46.0515 4076 pwdrvio - ok
23:05:46.0546 4076 [ 57FEBCC5F8C577FAAD55B0FF2D617826 ] pwdspio F:\WINNT\system32\pwdspio.sys
23:05:46.0562 4076 pwdspio - ok
23:05:46.0609 4076 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 F:\WINNT\system32\Drivers\PxHelp20.sys
23:05:46.0609 4076 PxHelp20 - ok
23:05:46.0625 4076 ql1080 - ok
23:05:46.0656 4076 Ql10wnt - ok
23:05:46.0687 4076 ql12160 - ok
23:05:46.0703 4076 ql1240 - ok
23:05:46.0734 4076 ql1280 - ok
23:05:46.0750 4076 ql2100 - ok
23:05:46.0796 4076 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd F:\WINNT\system32\DRIVERS\rasacd.sys
23:05:46.0796 4076 RasAcd - ok
23:05:46.0843 4076 [ 2B5E44EA009F2F374B980E1E9A70635D ] RasAuto F:\WINNT\System32\rasauto.dll
23:05:46.0859 4076 RasAuto - ok
23:05:46.0875 4076 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp F:\WINNT\system32\DRIVERS\rasl2tp.sys
23:05:46.0890 4076 Rasl2tp - ok
23:05:46.0906 4076 [ D57554C664B64604BD1EE13EA2C07E77 ] RasMan F:\WINNT\System32\rasmans.dll
23:05:46.0921 4076 RasMan - ok
23:05:46.0937 4076 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe F:\WINNT\system32\DRIVERS\raspppoe.sys
23:05:46.0953 4076 RasPppoe - ok
23:05:46.0984 4076 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti F:\WINNT\system32\DRIVERS\raspti.sys
23:05:46.0984 4076 Raspti - ok
23:05:47.0015 4076 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss F:\WINNT\system32\DRIVERS\rdbss.sys
23:05:47.0031 4076 Rdbss - ok
23:05:47.0046 4076 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD F:\WINNT\system32\DRIVERS\RDPCDD.sys
23:05:47.0046 4076 RDPCDD - ok
23:05:47.0109 4076 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr F:\WINNT\system32\DRIVERS\rdpdr.sys
23:05:47.0125 4076 rdpdr - ok
23:05:47.0187 4076 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD F:\WINNT\system32\drivers\RDPWD.sys
23:05:47.0187 4076 RDPWD - ok
23:05:47.0234 4076 [ C0D9D9711CB74EE9BC66353D8CBDAB0E ] RDSessMgr F:\WINNT\system32\sessmgr.exe
23:05:47.0250 4076 RDSessMgr - ok
23:05:47.0281 4076 [ 611BFD220305BE3A85AE876EA47D4AA5 ] redbook F:\WINNT\system32\DRIVERS\redbook.sys
23:05:47.0281 4076 redbook - ok
23:05:47.0312 4076 [ 127C26B5371651043450E52542099ABA ] RemoteAccess F:\WINNT\System32\mprdim.dll
23:05:47.0328 4076 RemoteAccess - ok
23:05:47.0375 4076 [ 8F31505484A190D5B22274708799F4EC ] RemoteRegistry F:\WINNT\system32\regsvc.dll
23:05:47.0390 4076 RemoteRegistry - ok
23:05:47.0437 4076 [ 96F7A9A7BF0C9C0440A967440065D33C ] RMCAST F:\WINNT\system32\drivers\RMCast.sys
23:05:47.0437 4076 RMCAST - ok
23:05:47.0468 4076 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7 ] ROOTMODEM F:\WINNT\system32\Drivers\RootMdm.sys
23:05:47.0484 4076 ROOTMODEM - ok
23:05:47.0515 4076 [ 718B3BDC0BC3C2F7D065A53D26202AF9 ] RpcLocator F:\WINNT\system32\locator.exe
23:05:47.0531 4076 RpcLocator - ok
23:05:47.0562 4076 [ BE27674D1CBC3214AEC84B4336A38BBF ] RpcSs F:\WINNT\system32\rpcss.dll
23:05:47.0578 4076 RpcSs - ok
23:05:47.0609 4076 [ 09AB2E71E58B078038E3BFDBA7FFC984 ] RSVP F:\WINNT\system32\rsvp.exe
23:05:47.0625 4076 RSVP - ok
23:05:47.0671 4076 [ D507C1400284176573224903819FFDA3 ] rtl8139 F:\WINNT\system32\DRIVERS\RTL8139.SYS
23:05:47.0671 4076 rtl8139 - ok
23:05:47.0687 4076 [ ED0A176354487CEED65B80A7148AB739 ] SamSs F:\WINNT\system32\lsass.exe
23:05:47.0703 4076 SamSs - ok
23:05:47.0750 4076 [ B84BC802CCC0F2FAC78F8B8E22DAE60C ] sbpci F:\WINNT\system32\drivers\sbpci.sys
23:05:47.0781 4076 sbpci - ok
23:05:47.0843 4076 [ 410046E401EB11E1E6749E9DEEA41D4A ] SCardSvr F:\WINNT\System32\SCardSvr.exe
23:05:47.0859 4076 SCardSvr - ok
23:05:47.0921 4076 [ 3FF232A7731621B8902D81D42418C93C ] Schedule F:\WINNT\system32\schedsvc.dll
23:05:47.0953 4076 Schedule - ok
23:05:48.0015 4076 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv F:\WINNT\system32\DRIVERS\secdrv.sys
23:05:48.0015 4076 Secdrv - ok
23:05:48.0296 4076 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6 ] seclogon F:\WINNT\System32\seclogon.dll
23:05:48.0312 4076 seclogon - ok
23:05:48.0359 4076 [ A530B75C10C23C9AB28FDB6CE719E21F ] SENS F:\WINNT\system32\sens.dll
23:05:48.0359 4076 SENS - ok
23:05:48.0390 4076 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum F:\WINNT\system32\DRIVERS\serenum.sys
23:05:48.0390 4076 serenum - ok
23:05:48.0421 4076 [ B842729337C9B921615C40D3C1A1AF96 ] Serial F:\WINNT\system32\DRIVERS\serial.sys
23:05:48.0437 4076 Serial - ok
23:05:48.0515 4076 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy F:\WINNT\system32\drivers\Sfloppy.sys
23:05:48.0515 4076 Sfloppy - ok
23:05:48.0562 4076 [ 19C016C79DB4D1A840B9D5A20D7ECA54 ] SharedAccess F:\WINNT\System32\ipnathlp.dll
23:05:48.0578 4076 SharedAccess - ok
23:05:48.0609 4076 [ EE9A2B9EA968A792A053C9D1A86BF870 ] ShellHWDetection F:\WINNT\System32\shsvcs.dll
23:05:48.0625 4076 ShellHWDetection - ok
23:05:48.0640 4076 Simbad - ok
23:05:48.0671 4076 [ 0BEFA983F8B9511EADD6960DD13E9FBF ] SimpTcp F:\WINNT\system32\tcpsvcs.exe
23:05:48.0687 4076 SimpTcp - ok
23:05:48.0734 4076 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate F:\Program Files\Skype\Updater\Updater.exe
23:05:48.0734 4076 SkypeUpdate - ok
23:05:48.0781 4076 [ 07AD42303519A955560B5A19FE20B68F ] SMTPSVC F:\WINNT\System32\inetsrv\inetinfo.exe
23:05:48.0781 4076 SMTPSVC - ok
23:05:48.0828 4076 [ 442D891CF7CB138F185FB2A1161C8AF9 ] SNMP F:\WINNT\System32\snmp.exe
23:05:48.0828 4076 SNMP - ok
23:05:48.0875 4076 [ 4296E52A9D3CA6DCD1CF57E8BCA45AB7 ] SNMPTRAP F:\WINNT\System32\snmptrap.exe
23:05:48.0890 4076 SNMPTRAP - ok
23:05:48.0906 4076 Sparrow - ok
23:05:48.0937 4076 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter F:\WINNT\system32\drivers\splitter.sys
23:05:48.0937 4076 splitter - ok
23:05:48.0984 4076 [ 60784F891563FB1B767F70117FC2428F ] Spooler F:\WINNT\system32\spoolsv.exe
23:05:49.0000 4076 Spooler - ok
23:05:49.0000 4076 SpyEmrg - ok
23:05:49.0046 4076 [ 94610C8653635E4459316A0050D55CE7 ] Sr F:\WINNT\system32\DRIVERS\sr.sys
23:05:49.0062 4076 Sr - ok
23:05:49.0109 4076 [ 35B91147124F64AC8081A2EDB9EA4DEE ] srservice F:\WINNT\system32\srsvc.dll
23:05:49.0125 4076 srservice - ok
23:05:49.0187 4076 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv F:\WINNT\system32\DRIVERS\srv.sys
23:05:49.0203 4076 Srv - ok
23:05:49.0250 4076 [ BECD5271DC4E3B7C3D035F790FCBC1E5 ] SSDPSRV F:\WINNT\System32\ssdpsrv.dll
23:05:49.0265 4076 SSDPSRV - ok
23:05:49.0312 4076 [ C1CDD9275F6A115BB0AE1D55D8D27BA6 ] stisvc F:\WINNT\system32\wiaservc.dll
23:05:49.0343 4076 stisvc - ok
23:05:49.0562 4076 [ DFF023B4100EB120D2DC62F3AC393A05 ] SvcOnlineArmor C:\Program Files\Online Armor\oasrv.exe
23:05:49.0734 4076 SvcOnlineArmor - ok
23:05:49.0781 4076 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum F:\WINNT\system32\DRIVERS\swenum.sys
23:05:49.0781 4076 swenum - ok
23:05:49.0828 4076 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi F:\WINNT\system32\drivers\swmidi.sys
23:05:49.0828 4076 swmidi - ok
23:05:49.0843 4076 SwPrv - ok
23:05:49.0875 4076 symc810 - ok
23:05:49.0890 4076 symc8xx - ok
23:05:49.0906 4076 sym_hi - ok
23:05:49.0921 4076 sym_u3 - ok
23:05:49.0953 4076 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio F:\WINNT\system32\drivers\sysaudio.sys
23:05:49.0953 4076 sysaudio - ok
23:05:50.0000 4076 [ CE06F01B88ACE199A1BF460CAC29C110 ] SysmonLog F:\WINNT\system32\smlogsvc.exe
23:05:50.0000 4076 SysmonLog - ok
23:05:50.0046 4076 [ C2546CD7A398476F9DF5614B2AE160E8 ] TapiSrv F:\WINNT\System32\tapisrv.dll
23:05:50.0062 4076 TapiSrv - ok
23:05:50.0125 4076 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip F:\WINNT\system32\DRIVERS\tcpip.sys
23:05:50.0140 4076 Tcpip - ok
23:05:50.0187 4076 [ 4E53BBCC4BE37D7A4BD6EF1098C89FF7 ] Tcpip6 F:\WINNT\system32\DRIVERS\tcpip6.sys
23:05:50.0203 4076 Tcpip6 - ok
23:05:50.0234 4076 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE F:\WINNT\system32\drivers\TDPIPE.sys
23:05:50.0234 4076 TDPIPE - ok
23:05:50.0281 4076 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP F:\WINNT\system32\drivers\TDTCP.sys
23:05:50.0281 4076 TDTCP - ok
23:05:50.0312 4076 [ 88155247177638048422893737429D9E ] TermDD F:\WINNT\system32\DRIVERS\termdd.sys
23:05:50.0312 4076 TermDD - ok
23:05:50.0343 4076 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E ] TermService F:\WINNT\System32\termsrv.dll
23:05:50.0359 4076 TermService - ok
23:05:50.0375 4076 tga - ok
23:05:50.0406 4076 [ EE9A2B9EA968A792A053C9D1A86BF870 ] Themes F:\WINNT\System32\shsvcs.dll
23:05:50.0421 4076 Themes - ok
23:05:50.0468 4076 [ CD0CC7B167D78043A41C98D4921EFB54 ] TlntSvr F:\WINNT\system32\tlntsvr.exe
23:05:50.0468 4076 TlntSvr - ok
23:05:50.0484 4076 TosIde - ok
23:05:50.0515 4076 [ 38853304CCB938D30E0C4CDE8D2C2A8A ] TrkWks F:\WINNT\system32\trkwks.dll
23:05:50.0531 4076 TrkWks - ok
23:05:50.0578 4076 [ 8F861EDA21C05857EB8197300A92501C ] tunmp F:\WINNT\system32\DRIVERS\tunmp.sys
23:05:50.0578 4076 tunmp - ok
23:05:50.0609 4076 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs F:\WINNT\system32\drivers\Udfs.sys
23:05:50.0609 4076 Udfs - ok
23:05:50.0640 4076 ultra - ok
23:05:50.0640 4076 ultra66 - ok
23:05:50.0703 4076 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update F:\WINNT\system32\DRIVERS\update.sys
23:05:50.0718 4076 Update - ok
23:05:50.0750 4076 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E ] upnphost F:\WINNT\System32\upnphost.dll
23:05:50.0781 4076 upnphost - ok
23:05:50.0796 4076 [ 20A0F6A11959E92908717D09E87D670D ] UPS F:\WINNT\System32\ups.exe
23:05:50.0812 4076 UPS - ok
23:05:50.0859 4076 [ 4BAC8DF07F1D8434FC640E677A62204E ] usbehci F:\WINNT\system32\DRIVERS\usbehci.sys
23:05:50.0859 4076 usbehci - ok
23:05:50.0890 4076 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub F:\WINNT\system32\DRIVERS\usbhub.sys
23:05:50.0906 4076 usbhub - ok
23:05:50.0937 4076 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR F:\WINNT\system32\DRIVERS\USBSTOR.SYS
23:05:50.0953 4076 USBSTOR - ok
23:05:50.0984 4076 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci F:\WINNT\system32\DRIVERS\usbuhci.sys
23:05:50.0984 4076 usbuhci - ok
23:05:51.0031 4076 [ FDC4EFFEDFE9B533D2923922761A9D9E ] UtilMan F:\WINNT\System32\UtilMan.exe
23:05:51.0031 4076 UtilMan - ok
23:05:51.0078 4076 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave F:\WINNT\System32\drivers\vga.sys
23:05:51.0078 4076 VgaSave - ok
23:05:51.0109 4076 ViaIde - ok
23:05:51.0140 4076 [ 28A4B296B47782173C346E376CB374D1 ] VolSnap F:\WINNT\system32\drivers\VolSnap.sys
23:05:51.0156 4076 VolSnap - ok
23:05:51.0187 4076 [ D6BA1A63D9E00933F1CD2A885573AFB2 ] VSS F:\WINNT\System32\vssvc.exe
23:05:51.0203 4076 VSS - ok
23:05:51.0250 4076 [ FA4E1CDBA256787F2149F4AAD07BC91F ] W32Time F:\WINNT\system32\w32time.dll
23:05:51.0281 4076 W32Time - ok
23:05:51.0296 4076 [ 07AD42303519A955560B5A19FE20B68F ] W3SVC F:\WINNT\system32\inetsrv\inetinfo.exe
23:05:51.0296 4076 W3SVC - ok
23:05:51.0328 4076 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp F:\WINNT\system32\DRIVERS\wanarp.sys
23:05:51.0343 4076 Wanarp - ok
23:05:51.0359 4076 WDICA - ok
23:05:51.0406 4076 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud F:\WINNT\system32\drivers\wdmaud.sys
23:05:51.0406 4076 wdmaud - ok
23:05:51.0421 4076 [ 47AE51048A82DFA1CD6B51D369F7E169 ] WebClient F:\WINNT\System32\webclnt.dll
23:05:51.0437 4076 WebClient - ok
23:05:51.0468 4076 WINIO - ok
23:05:51.0531 4076 [ E488332126E3B1182D2B8A0C35408EC6 ] winmgmt F:\WINNT\system32\wbem\WMIsvc.dll
23:05:51.0531 4076 winmgmt - ok
23:05:51.0593 4076 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN F:\WINNT\system32\mspmsnsv.dll
23:05:51.0609 4076 WmdmPmSN - ok
23:05:51.0656 4076 [ 0171CFF34BBA8C5977F18C48D8AEF8C6 ] Wmi F:\WINNT\System32\advapi32.dll
23:05:51.0687 4076 Wmi - ok
23:05:51.0750 4076 [ 23F6F03272F7E5679F1F050AED5ACEE6 ] WmiApSrv F:\WINNT\system32\wbem\wmiapsrv.exe
23:05:51.0750 4076 WmiApSrv - ok
23:05:51.0828 4076 [ 3739866D20ABD42F26A7B85F9E2560AF ] WMPNetworkSvc F:\Program Files\Windows Media Player\WMPNetwk.exe
23:05:51.0859 4076 WMPNetworkSvc - ok
23:05:51.0953 4076 [ 15673BD0B86150CB8E27766059C72A9B ] WPFFontCache_v0400 F:\WINNT\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
23:05:51.0984 4076 WPFFontCache_v0400 - ok
23:05:52.0031 4076 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL F:\WINNT\System32\drivers\ws2ifsl.sys
23:05:52.0031 4076 WS2IFSL - ok
23:05:52.0062 4076 [ 4C86D5FAF78194995AF9CC1075F65DD3 ] wscsvc F:\WINNT\system32\wscsvc.dll
23:05:52.0078 4076 wscsvc - ok
23:05:52.0125 4076 [ C1364564800EE9784192145324A23308 ] wuauserv F:\WINNT\system32\wuauserv.dll
23:05:52.0140 4076 wuauserv - ok
23:05:52.0171 4076 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf F:\WINNT\system32\DRIVERS\WudfPf.sys
23:05:52.0171 4076 WudfPf - ok
23:05:52.0203 4076 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd F:\WINNT\system32\DRIVERS\wudfrd.sys
23:05:52.0203 4076 WudfRd - ok
23:05:52.0218 4076 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc F:\WINNT\System32\WUDFSvc.dll
23:05:52.0234 4076 WudfSvc - ok
23:05:52.0296 4076 [ A27D4BA7264C0BF52F32D10405BEA1D4 ] WZCSVC F:\WINNT\System32\wzcsvc.dll
23:05:52.0328 4076 WZCSVC - ok
23:05:52.0375 4076 [ EAA4BB9EDB3FB10CF8979FE65E63658F ] xmlprov F:\WINNT\System32\xmlprov.dll
23:05:52.0390 4076 xmlprov - ok
23:05:52.0406 4076 ================ Scan global ===============================
23:05:52.0437 4076 [ F36278E42C8C5DF03CE17DAC8231C91C ] F:\WINNT\system32\basesrv.dll
23:05:52.0468 4076 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] F:\WINNT\system32\winsrv.dll
23:05:52.0515 4076 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] F:\WINNT\system32\winsrv.dll
23:05:52.0546 4076 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] F:\WINNT\system32\services.exe
23:05:52.0546 4076 [Global] - ok
23:05:52.0562 4076 ================ Scan MBR ==================================
23:05:52.0578 4076 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
23:05:52.0843 4076 \Device\Harddisk0\DR0 - ok
23:05:52.0859 4076 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk1\DR1
23:05:53.0015 4076 \Device\Harddisk1\DR1 - ok
23:05:53.0062 4076 [ 65E858A8A0293BE11A920B0BC99D695E ] \Device\Harddisk2\DR5
23:05:54.0109 4076 \Device\Harddisk2\DR5 - ok
23:05:54.0109 4076 ================ Scan VBR ==================================
23:05:54.0125 4076 [ A5B7132CF171C56C31C7B25EB43CF42B ] \Device\Harddisk0\DR0\Partition1
23:05:54.0125 4076 \Device\Harddisk0\DR0\Partition1 - ok
23:05:54.0140 4076 [ 8570756169F2BCF44F2C37C4A53C7FF4 ] \Device\Harddisk1\DR1\Partition1
23:05:54.0140 4076 \Device\Harddisk1\DR1\Partition1 - ok
23:05:54.0171 4076 [ 567F84C8B6AF4F915595A4F8D8159AFA ] \Device\Harddisk1\DR1\Partition2
23:05:54.0171 4076 \Device\Harddisk1\DR1\Partition2 - ok
23:05:54.0187 4076 [ 09C6F77B5D4D42E9FA19BA2C19681E82 ] \Device\Harddisk2\DR5\Partition1
23:05:54.0203 4076 \Device\Harddisk2\DR5\Partition1 - ok
23:05:54.0203 4076 ============================================================
23:05:54.0203 4076 Scan finished
23:05:54.0203 4076 ============================================================
23:05:54.0265 2172 Detected object count: 0
23:05:54.0265 2172 Actual detected object count: 0

Re: Prosím o preventivní kontrolu logu

Napsal: 07 bře 2014 07:10
od JaRon
najdene polozky nechaj zmazat v MBAM

Re: Prosím o preventivní kontrolu logu

Napsal: 07 bře 2014 21:54
od Knoll.Jaroslav
Položky smazány

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.03.06.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Jaroslav :: JAROSLAV-KNOLL [administrátor]

7.3.2014 17:12:30
mbam-log-2014-03-07 (17-12-30).txt

Typ: Kompletní kontrola (C:\|E:\|F:\|H:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 254024
Uplynulý čas: 4 hodin, 9 minut, 5 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 2
F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me\cache (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.

Nalezené soubory: 4
F:\Documents and Settings\Jaroslav\Dokumenty\Downloads\GotClip_Setup.exe (PUP.Optional.Remarkit) -> Přesun do karantény a smazání se zdařilo.
F:\Documents and Settings\Jaroslav\Local Settings\Data aplikací\genienext\nengine.dll (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
F:\Documents and Settings\Jaroslav\Data aplikací\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.

(konec)

Re: Prosím o preventivní kontrolu logu

Napsal: 09 bře 2014 13:45
od JaRon
ak nie su ziadne problemy, tak hotovo