Virus
Napsal: 28 kvě 2014 22:17
Dobry vecer
mam v pc Malwarebytes Anti-Malware, ktery mi pred 10 min. nasel Trojan BitcoinMiner a jeste jeden vir s nazvem backdoor, tak jsem je dal smazat a jeste jednou jsem to s nim projel a uz nic nenasel. Jenom ze pc vykon je porad spatny a nevim co s tim... poradi nekdo jak to mam resit?
Logfile of random's system information tool 1.08 (written by random/random)
Run by Rudolf at 2014-05-28 23:15:14
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 731 GB (77%) free of 954 GB
Total RAM: 8173 MB (76% free)
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun
"C:\Program Files (x86)\Steam\Steam.exe" -silent
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3f1d641d-daca-4102-8ce0-7a2ea7402607 -SystemEventPortName:HostProcess-e12c0b9a-c81e-4a32-b385-d6aff0d2dcd2 -IoCancelEventPortName:HostProcess-e79676eb-5926-4fd7-a556-fc250f6742bb -NonStateChangingEventPortName:HostProcess-1e2b9f8d-3323-410a-b638-0729ffef2024 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6e9caeb6-3b9f-4cc1-a946-842e074d4752 -DeviceGroupId:WpdFsGroup
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1264.0.1368471783\1735827282" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,15,39 --gpu-vendor-id=0x10de --gpu-device-id=0x1200 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3523 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/PrePeriod_Hivemind_A4_Stable_R5/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_95/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="1264.2.455804154\53344743" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/PrePeriod_Hivemind_A4_Stable_R5/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_95/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="1264.6.959476398\505146645" /prefetch:673131151
"C:\Users\Rudolf\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\trend micro\Rudolf.exe" /silentautolog
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Rudolf\Downloads\RSITx64 (2).exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-03-21 1797064]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-09-30 825184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2014-05-28 1775808]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe RGB Color"=C:\ProgramData\Adobe\color.vbs [2013-12-14 106]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-05-28 23:12:26 ----D---- C:\rsit
2014-05-28 23:12:26 ----D---- C:\Program Files\trend micro
2014-05-28 20:03:43 ----D---- C:\ProgramData\adobe
2014-05-25 23:52:36 ----D---- C:\Program Files (x86)\FinalWire
2014-05-14 17:36:23 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-05-14 17:36:23 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-05-14 17:36:23 ----A---- C:\Windows\system32\mshtmled.dll
2014-05-14 17:36:23 ----A---- C:\Windows\system32\mshtml.dll
2014-05-14 11:13:22 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-05-14 11:13:22 ----A---- C:\Windows\system32\shell32.dll
2014-05-14 11:13:21 ----A---- C:\Windows\system32\aepdu.dll
2014-05-14 11:13:20 ----A---- C:\Windows\system32\aeinv.dll
2014-05-14 11:13:09 ----A---- C:\Windows\system32\lsasrv.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\winlogon.exe
2014-05-14 11:13:08 ----A---- C:\Windows\system32\wdigest.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\TSpkg.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\schannel.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\objsel.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-05-14 11:13:08 ----A---- C:\Windows\system32\msv1_0.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\KernelBase.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\kerberos.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-05-14 11:13:08 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\dimsroam.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\cngprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\capiprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\adprovider.dll
2014-05-14 11:13:07 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-05-14 11:13:07 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-05-14 11:13:07 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-05-14 11:13:07 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\wincredprovider.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\sspisrv.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\sspicli.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\secur32.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\lsass.exe
2014-05-14 11:13:07 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-05-14 11:13:07 ----A---- C:\Windows\system32\credssp.dll
2014-05-12 22:52:47 ----D---- C:\Users\Rudolf\AppData\Roaming\DarkSoulsII
2014-05-12 22:52:47 ----D---- C:\ProgramData\Steam
2014-05-09 19:55:43 ----A---- C:\Windows\system32\drivers\48230029.sys
======List of files/folders modified in the last 1 months======
2014-05-28 23:15:13 ----D---- C:\Windows\Temp
2014-05-28 23:15:12 ----D---- C:\Windows\Prefetch
2014-05-28 23:12:26 ----RD---- C:\Program Files
2014-05-28 22:58:42 ----D---- C:\Windows\system32\config
2014-05-28 22:54:28 ----D---- C:\Windows\inf
2014-05-28 22:54:28 ----D---- C:\Windows
2014-05-28 22:50:39 ----D---- C:\Windows\System32
2014-05-28 22:50:39 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-05-28 22:44:55 ----D---- C:\Program Files (x86)\Steam
2014-05-28 22:44:40 ----D---- C:\ProgramData\NVIDIA
2014-05-28 22:44:37 ----D---- C:\Windows\system32\drivers
2014-05-28 22:43:28 ----D---- C:\Windows\Resources
2014-05-28 21:36:58 ----D---- C:\Users\Rudolf\AppData\Roaming\uTorrent
2014-05-28 20:03:43 ----HD---- C:\ProgramData
2014-05-27 18:49:21 ----SHD---- C:\System Volume Information
2014-05-27 09:28:27 ----D---- C:\Windows\system32\NDF
2014-05-25 23:52:36 ----RD---- C:\Program Files (x86)
2014-05-16 22:26:57 ----D---- C:\Windows\Logs
2014-05-16 16:36:51 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-05-16 16:04:11 ----RSD---- C:\Windows\assembly
2014-05-16 16:03:49 ----SHD---- C:\Windows\Installer
2014-05-15 16:14:11 ----D---- C:\Windows\debug
2014-05-14 21:50:37 ----D---- C:\Windows\rescache
2014-05-14 18:25:55 ----D---- C:\Windows\Microsoft.NET
2014-05-14 17:39:42 ----D---- C:\Windows\winsxs
2014-05-14 17:38:21 ----SD---- C:\Windows\system32\CompatTel
2014-05-14 17:38:21 ----D---- C:\Windows\SysWOW64
2014-05-14 17:38:20 ----D---- C:\Windows\system32\cs-CZ
2014-05-14 17:36:26 ----D---- C:\Windows\system32\catroot
2014-05-14 17:36:05 ----D---- C:\Windows\system32\MRT
2014-05-14 17:35:41 ----A---- C:\Windows\system32\MRT.exe
2014-05-14 11:13:03 ----D---- C:\Windows\system32\catroot2
2014-05-13 10:02:14 ----D---- C:\ProgramData\Origin
2014-05-12 09:19:06 ----D---- C:\Windows\ServiceProfiles
2014-05-05 12:29:09 ----D---- C:\Users\Rudolf\AppData\Roaming\Tera_Awesomium
2014-05-04 09:18:45 ----D---- C:\Users\Rudolf\AppData\Roaming\TS3Client
2014-04-30 18:14:31 ----D---- C:\Windows\SoftwareDistribution
2014-04-30 00:26:26 ----D---- C:\Windows\system32\LogFiles
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-01-27 385512]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-04-03 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-05-28 119512]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-04-03 63192]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-03-03 174184]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-08-21 79976]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-04-03 857912]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-04-03 1809720]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-03-04 922968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-05-28 564928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26 116648]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-06 111616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-03-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
mam v pc Malwarebytes Anti-Malware, ktery mi pred 10 min. nasel Trojan BitcoinMiner a jeste jeden vir s nazvem backdoor, tak jsem je dal smazat a jeste jednou jsem to s nim projel a uz nic nenasel. Jenom ze pc vykon je porad spatny a nevim co s tim... poradi nekdo jak to mam resit?
Logfile of random's system information tool 1.08 (written by random/random)
Run by Rudolf at 2014-05-28 23:15:14
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 731 GB (77%) free of 954 GB
Total RAM: 8173 MB (76% free)
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun
"C:\Program Files (x86)\Steam\Steam.exe" -silent
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3f1d641d-daca-4102-8ce0-7a2ea7402607 -SystemEventPortName:HostProcess-e12c0b9a-c81e-4a32-b385-d6aff0d2dcd2 -IoCancelEventPortName:HostProcess-e79676eb-5926-4fd7-a556-fc250f6742bb -NonStateChangingEventPortName:HostProcess-1e2b9f8d-3323-410a-b638-0729ffef2024 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6e9caeb6-3b9f-4cc1-a946-842e074d4752 -DeviceGroupId:WpdFsGroup
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1264.0.1368471783\1735827282" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,15,39 --gpu-vendor-id=0x10de --gpu-device-id=0x1200 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3523 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/PrePeriod_Hivemind_A4_Stable_R5/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_95/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="1264.2.455804154\53344743" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/PrePeriod_Hivemind_A4_Stable_R5/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_95/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="1264.6.959476398\505146645" /prefetch:673131151
"C:\Users\Rudolf\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\trend micro\Rudolf.exe" /silentautolog
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Rudolf\Downloads\RSITx64 (2).exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-03-21 1797064]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-09-30 825184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2014-05-28 1775808]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe RGB Color"=C:\ProgramData\Adobe\color.vbs [2013-12-14 106]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-05-28 23:12:26 ----D---- C:\rsit
2014-05-28 23:12:26 ----D---- C:\Program Files\trend micro
2014-05-28 20:03:43 ----D---- C:\ProgramData\adobe
2014-05-25 23:52:36 ----D---- C:\Program Files (x86)\FinalWire
2014-05-14 17:36:23 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-05-14 17:36:23 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-05-14 17:36:23 ----A---- C:\Windows\system32\mshtmled.dll
2014-05-14 17:36:23 ----A---- C:\Windows\system32\mshtml.dll
2014-05-14 11:13:22 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-05-14 11:13:22 ----A---- C:\Windows\system32\shell32.dll
2014-05-14 11:13:21 ----A---- C:\Windows\system32\aepdu.dll
2014-05-14 11:13:20 ----A---- C:\Windows\system32\aeinv.dll
2014-05-14 11:13:09 ----A---- C:\Windows\system32\lsasrv.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\winlogon.exe
2014-05-14 11:13:08 ----A---- C:\Windows\system32\wdigest.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\TSpkg.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\schannel.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\objsel.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-05-14 11:13:08 ----A---- C:\Windows\system32\msv1_0.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\KernelBase.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\kerberos.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-05-14 11:13:08 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\dimsroam.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\cngprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\capiprovider.dll
2014-05-14 11:13:08 ----A---- C:\Windows\system32\adprovider.dll
2014-05-14 11:13:07 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-05-14 11:13:07 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-05-14 11:13:07 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-05-14 11:13:07 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\wincredprovider.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\sspisrv.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\sspicli.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\secur32.dll
2014-05-14 11:13:07 ----A---- C:\Windows\system32\lsass.exe
2014-05-14 11:13:07 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-05-14 11:13:07 ----A---- C:\Windows\system32\credssp.dll
2014-05-12 22:52:47 ----D---- C:\Users\Rudolf\AppData\Roaming\DarkSoulsII
2014-05-12 22:52:47 ----D---- C:\ProgramData\Steam
2014-05-09 19:55:43 ----A---- C:\Windows\system32\drivers\48230029.sys
======List of files/folders modified in the last 1 months======
2014-05-28 23:15:13 ----D---- C:\Windows\Temp
2014-05-28 23:15:12 ----D---- C:\Windows\Prefetch
2014-05-28 23:12:26 ----RD---- C:\Program Files
2014-05-28 22:58:42 ----D---- C:\Windows\system32\config
2014-05-28 22:54:28 ----D---- C:\Windows\inf
2014-05-28 22:54:28 ----D---- C:\Windows
2014-05-28 22:50:39 ----D---- C:\Windows\System32
2014-05-28 22:50:39 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-05-28 22:44:55 ----D---- C:\Program Files (x86)\Steam
2014-05-28 22:44:40 ----D---- C:\ProgramData\NVIDIA
2014-05-28 22:44:37 ----D---- C:\Windows\system32\drivers
2014-05-28 22:43:28 ----D---- C:\Windows\Resources
2014-05-28 21:36:58 ----D---- C:\Users\Rudolf\AppData\Roaming\uTorrent
2014-05-28 20:03:43 ----HD---- C:\ProgramData
2014-05-27 18:49:21 ----SHD---- C:\System Volume Information
2014-05-27 09:28:27 ----D---- C:\Windows\system32\NDF
2014-05-25 23:52:36 ----RD---- C:\Program Files (x86)
2014-05-16 22:26:57 ----D---- C:\Windows\Logs
2014-05-16 16:36:51 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-05-16 16:04:11 ----RSD---- C:\Windows\assembly
2014-05-16 16:03:49 ----SHD---- C:\Windows\Installer
2014-05-15 16:14:11 ----D---- C:\Windows\debug
2014-05-14 21:50:37 ----D---- C:\Windows\rescache
2014-05-14 18:25:55 ----D---- C:\Windows\Microsoft.NET
2014-05-14 17:39:42 ----D---- C:\Windows\winsxs
2014-05-14 17:38:21 ----SD---- C:\Windows\system32\CompatTel
2014-05-14 17:38:21 ----D---- C:\Windows\SysWOW64
2014-05-14 17:38:20 ----D---- C:\Windows\system32\cs-CZ
2014-05-14 17:36:26 ----D---- C:\Windows\system32\catroot
2014-05-14 17:36:05 ----D---- C:\Windows\system32\MRT
2014-05-14 17:35:41 ----A---- C:\Windows\system32\MRT.exe
2014-05-14 11:13:03 ----D---- C:\Windows\system32\catroot2
2014-05-13 10:02:14 ----D---- C:\ProgramData\Origin
2014-05-12 09:19:06 ----D---- C:\Windows\ServiceProfiles
2014-05-05 12:29:09 ----D---- C:\Users\Rudolf\AppData\Roaming\Tera_Awesomium
2014-05-04 09:18:45 ----D---- C:\Users\Rudolf\AppData\Roaming\TS3Client
2014-04-30 18:14:31 ----D---- C:\Windows\SoftwareDistribution
2014-04-30 00:26:26 ----D---- C:\Windows\system32\LogFiles
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-01-27 385512]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-04-03 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-05-28 119512]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-04-03 63192]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-03-03 174184]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-08-21 79976]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-04-03 857912]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-04-03 1809720]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-03-04 922968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-05-28 564928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26 116648]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-06 111616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-03-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------