RSA 4096 Ransomware Description
Napsal: 14 dub 2016 15:22
Zdravicko ve spolek!
Prosim o radu. Pritelkyni jsem daval do poradku jeji PC. Mela tam hrozne zaneradene Visty a ja ji tam chtel nahodit Win7. Bohuzel jsem nedal odstraneni logicke jednotky a znovu vytvoreni, ale jen naformatovani pred samotnou instalaci. Tim ta svine RSA 4096 Ransomware Description zustala v zavadecim oddilu. Vim, ze tady v jejim pripade uz zasifrovane data bez zaplaceni nezachranim. (pokud se platu, prosim, opravte mne!)
Mam tu proto jen dotaz, jestli byste se mi, prosim, nemrkli na tento log. Jestli nahodou tu svini nemam na svem PC taky:
Diky!
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:07:09, on 14.4.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Windows\System32\TiltWheelMouse.exe
C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\LG Soft India\forteManager\bin\Monitor.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Petr\Downloads\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mylumia.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKLM\..\RunOnce: [InstallShieldSetup] C:\PROGRA~2\INSTAL~1\{E3A5A~1\setup.exe -rebootC:\PROGRA~2\INSTAL~1\{E3A5A~1\reboot.ini
O4 - HKCU\..\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
O4 - HKCU\..\Run: [Bose Updater] "C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: forteManager.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/ ... 0516352997
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A9041C8-6B35-4684-8844-DB2EECC54D6F}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O18 - Protocol: bw+0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw+0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw-0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw-0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw00 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw00s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw10 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw10s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw20 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw20s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw30 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw30s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw40 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw40s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw50 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw50s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw60 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw60s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw70 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw70s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw80 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw80s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw90 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw90s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwa0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwa0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwb0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwb0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwc0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwc0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwd0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwd0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwe0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwe0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwf0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwf0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwg0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwg0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwh0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwh0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwi0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwi0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwj0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwj0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwk0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwk0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwl0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwl0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwm0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwm0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwn0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwn0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwo0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwo0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwp0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwp0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwq0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwq0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwr0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwr0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bws0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bws0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwt0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwt0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwu0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwu0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwv0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwv0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bww0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bww0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwx0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwx0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwy0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwy0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwz0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwz0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: offline-8876480 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\Windows\system32\ASTSRV.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron X64 Service (nlscc) - Unknown owner - C:\Windows\system32\nlsInterface.exe (file missing)
O23 - Service: NPVR Recording Service - Unknown owner - C:\Program Files (x86)\NPVR\NRecord.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 17106 bytes
Prosim o radu. Pritelkyni jsem daval do poradku jeji PC. Mela tam hrozne zaneradene Visty a ja ji tam chtel nahodit Win7. Bohuzel jsem nedal odstraneni logicke jednotky a znovu vytvoreni, ale jen naformatovani pred samotnou instalaci. Tim ta svine RSA 4096 Ransomware Description zustala v zavadecim oddilu. Vim, ze tady v jejim pripade uz zasifrovane data bez zaplaceni nezachranim. (pokud se platu, prosim, opravte mne!)
Mam tu proto jen dotaz, jestli byste se mi, prosim, nemrkli na tento log. Jestli nahodou tu svini nemam na svem PC taky:
Diky!
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:07:09, on 14.4.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Windows\System32\TiltWheelMouse.exe
C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\LG Soft India\forteManager\bin\Monitor.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Petr\Downloads\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mylumia.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKLM\..\RunOnce: [InstallShieldSetup] C:\PROGRA~2\INSTAL~1\{E3A5A~1\setup.exe -rebootC:\PROGRA~2\INSTAL~1\{E3A5A~1\reboot.ini
O4 - HKCU\..\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
O4 - HKCU\..\Run: [Bose Updater] "C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: forteManager.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/ ... 0516352997
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A9041C8-6B35-4684-8844-DB2EECC54D6F}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O18 - Protocol: bw+0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw+0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw-0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw-0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw00 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw00s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw10 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw10s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw20 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw20s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw30 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw30s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw40 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw40s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw50 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw50s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw60 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw60s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw70 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw70s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw80 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw80s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw90 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bw90s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwa0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwa0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwb0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwb0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwc0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwc0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwd0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwd0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwe0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwe0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwf0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwf0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwg0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwg0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwh0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwh0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwi0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwi0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwj0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwj0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwk0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwk0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwl0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwl0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwm0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwm0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwn0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwn0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwo0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwo0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwp0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwp0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwq0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwq0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwr0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwr0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bws0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bws0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwt0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwt0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwu0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwu0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwv0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwv0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bww0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bww0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwx0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwx0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwy0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwy0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwz0 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: bwz0s - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O18 - Protocol: offline-8876480 - {E9EC13B0-DD6B-4004-AEB5-C70C2D2A1174} - (no file)
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\Windows\system32\ASTSRV.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron X64 Service (nlscc) - Unknown owner - C:\Windows\system32\nlsInterface.exe (file missing)
O23 - Service: NPVR Recording Service - Unknown owner - C:\Program Files (x86)\NPVR\NRecord.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 17106 bytes