Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
Taller
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 04 čer 2012 11:08
Bydliště: Brandýs nad Labem Stará Boleslav

Prosím o kontrolu logu

#1 Příspěvek od Taller »

Ahoj a hezké odpoledne prosím o kontrolu logu Avast včera hlásil Win32:Malware-gen,Win64:Sirefef-A,Win32:Sirefef-AO (Rtk) dnes zatím nic ale ve Windows přestalo pracovat veškeré zabezpečení.
Logfile of random's system information tool 1.09 (written by random/random)
Run by zip at 2012-06-04 11:56:18
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 74 GB (62%) free of 119 GB
Total RAM: 2038 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:56:36, on 4.6.2012
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\O2\O2CZ\EMMSN.exe
C:\Program Files\O2\Nori\Nori.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\zip\Desktop\VIRY\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\trend micro\zip.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll
O1 - Hosts: ::1 localhost
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {F156768E-81EF-470C-9057-481BA8380DBA} - (no file)
O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Braid OLR] C:\PROGRA~1\Avanquest Software Publishing Ltd\OLR\Braid\BVRPOlr.exe /Braid
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: Download All by FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout pomocí FlashGet - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Stáhnout vše pomocí FlashGet - D:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\flashget.exe (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{C39AC866-A09F-437B-ADC8-2104FE03A79C}: NameServer = 160.218.167.5 160.218.161.60
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe

--
End of file - 8508 bytes

======Scheduled tasks folder======

C:\Windows\tasks\AWC Startup.job
C:\Windows\tasks\User_Feed_Synchronization-{678C1324-F912-4607-A2A8-A13047F27168}.job

=========Mozilla firefox=========

ProfilePath - C:\Users\zip\AppData\Roaming\Mozilla\Firefox\Profiles\b5z2micc.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{20a82645-c095-46ed-80e3-08825760534b}:1.2.1, avg@igeared:6.010.006.004, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://www.webhledani.cz/results.aspx?i=39&tp=ab&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1]
"Description"=Yahoo! activeX Plug-in Bridge
"Path"=C:\Program Files\Yahoo!\Common\npyaxmpb.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll

C:\Program Files\Mozilla Firefox\searchplugins\
avg-secure-search.xml
avg_igeared.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\zip\AppData\Roaming\Mozilla\Firefox\Profiles\b5z2micc.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
ToggleEN Toolbar - C:\Program Files\ToggleEN\tbTog0.dll [2010-02-06 2166296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-03-07 1003704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-07-18 2018368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-05 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{038cb5c7-48ea-4af9-94e0-a1646542e62b} - ToggleEN Toolbar - C:\Program Files\ToggleEN\tbTog0.dll [2010-02-06 2166296]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-07-18 2018368]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-03-07 1003704]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936]
"P2Go_Menu"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-14 210216]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2007-10-18 7737344]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-22 133656]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-10-31 4702208]
"Skytel"=C:\Windows\Skytel.exe [2007-10-11 1826816]
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1029416]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader\Reader_sl.exe [2008-06-12 34672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-03-07 4241512]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2012-03-07 3117344]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe [2009-07-18 155896]
"Braid OLR"=C:\PROGRA~1\Avanquest Software Publishing Ltd\OLR\Braid\BVRPOlr.exe [2009-12-17 79104]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

C:\Users\zip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3codecp"=l3codecp.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.voxacm160"=vct3216.acm
"msacm.scg726"=scg726.acm
"msacm.alf2cd"=alf2cd.acm
"msacm.ac3acm"=AC3ACM.acm
"vidc.dvsd"=mcdvd_32.dll
"vidc.xvid"=xvidvfw.dll
"vidc.DIVX"=DivX.dll
"vidc.mpg4"=mpg4c32.dll
"vidc.mp42"=mpg4c32.dll
"vidc.mp43"=mpg4c32.dll

======List of files/folders created in the last 1 month======

2012-06-04 11:56:19 ----D---- C:\Program Files\trend micro
2012-06-04 11:56:18 ----D---- C:\rsit
2012-06-03 18:18:33 ----D---- C:\Users\zip\AppData\Roaming\ESET
2012-06-03 13:34:14 ----D---- C:\ProgramData\ESET
2012-06-03 12:02:18 ----D---- C:\Program Files\ESET
2012-06-03 06:59:38 ----A---- C:\Windows\system32\drivers\aswSP.sys
2012-06-03 06:59:38 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2012-06-03 06:59:32 ----A---- C:\Windows\system32\drivers\aswFW.sys
2012-06-03 06:57:46 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2012-06-03 06:57:46 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2012-06-03 06:57:46 ----A---- C:\Windows\system32\drivers\aswNdis2.sys
2012-06-03 06:57:45 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2012-06-03 06:57:45 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2012-06-03 06:57:45 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2012-06-03 06:56:36 ----A---- C:\Windows\system32\drivers\aswNdis.sys
2012-06-03 06:56:35 ----A---- C:\Windows\avastSS.scr
2012-06-03 06:56:34 ----A---- C:\Windows\system32\aswBoot.exe
2012-06-03 06:55:40 ----D---- C:\ProgramData\AVAST Software
2012-06-03 06:55:40 ----D---- C:\Program Files\AVAST Software
2012-06-03 06:53:52 ----D---- C:\Program Files\AVAST
2012-05-31 09:14:50 ----D---- C:\Users\zip\AppData\Roaming\Telefónica Móviles
2012-05-31 09:13:47 ----A---- C:\Windows\system32\drivers\ewusbnet.sys
2012-05-31 09:13:47 ----A---- C:\Windows\system32\drivers\ewusbmdm.sys
2012-05-31 09:13:47 ----A---- C:\Windows\system32\drivers\ewusbdev.sys
2012-05-31 09:13:47 ----A---- C:\Windows\system32\drivers\ewdcsc.sys
2012-05-31 09:13:33 ----D---- C:\Program Files\O2

======List of files/folders modified in the last 1 month======

2012-06-04 11:56:19 ----RD---- C:\Program Files
2012-06-04 11:51:54 ----D---- C:\Windows\Temp
2012-06-04 11:45:18 ----D---- C:\Windows\ModemLogs
2012-06-04 11:40:03 ----SHD---- C:\System Volume Information
2012-06-04 11:36:12 ----HD---- C:\ProgramData
2012-06-04 11:35:57 ----D---- C:\Windows\System32
2012-06-04 11:35:57 ----D---- C:\Windows\inf
2012-06-04 11:35:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-06-04 11:34:39 ----SHD---- C:\Windows\Installer
2012-06-04 11:34:39 ----D---- C:\Windows\winsxs
2012-06-03 18:17:26 ----D---- C:\Windows
2012-06-03 18:16:56 ----A---- C:\Windows\system32\acovcnt.exe
2012-06-03 18:15:56 ----D---- C:\Windows\system32\Msdtc
2012-06-03 18:15:54 ----D---- C:\Windows\system32\wbem
2012-06-03 18:14:59 ----D---- C:\Windows\system32\config
2012-06-03 18:14:48 ----D---- C:\Windows\Tasks
2012-06-03 18:14:48 ----D---- C:\Windows\system32\spool
2012-06-03 18:14:48 ----D---- C:\Windows\system32\drivers\etc
2012-06-03 18:14:48 ----D---- C:\Windows\system32\drivers
2012-06-03 18:14:48 ----D---- C:\Windows\system32\CodeIntegrity
2012-06-03 18:14:48 ----D---- C:\Windows\system32\catroot2
2012-06-03 18:14:44 ----D---- C:\Users\zip\AppData\Roaming\Facebook
2012-06-03 18:14:41 ----HD---- C:\Program Files\InstallShield Installation Information
2012-06-03 18:14:41 ----D---- C:\ProgramData\P4G
2012-06-03 18:14:41 ----D---- C:\Program Files\ToggleEN
2012-06-03 18:14:41 ----D---- C:\Program Files\Google
2012-06-03 18:14:40 ----D---- C:\Program Files\Avanquest Software Publishing Ltd
2012-06-03 18:14:37 ----D---- C:\Windows\registration
2012-06-03 13:43:36 ----D---- C:\Windows\system32\catroot
2012-06-03 08:25:30 ----D---- C:\Program Files\Common Files
2012-06-03 08:25:27 ----D---- C:\Program Files\AVG Secure Search
2012-05-31 09:12:46 ----D---- C:\Windows\Prefetch
2012-05-31 08:58:33 ----D---- C:\Program Files\Microsoft Office
2012-05-23 19:01:44 ----SD---- C:\Windows\Downloaded Program Files
2012-05-23 17:44:00 ----D---- C:\Windows\Debug
2012-05-16 21:52:25 ----D---- C:\Program Files\Microsoft Silverlight
2012-05-16 19:21:19 ----D---- C:\ProgramData\Microsoft Help
2012-05-16 19:16:52 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2007-08-11 29752]
R0 aswNdis;avast! Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\aswNdis.sys [2012-03-07 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2012-03-07 196440]
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2012-03-14 50624]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-09-29 308248]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2012-03-07 112984]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-03-07 24408]
R1 AswRdr;aswRdr; C:\Windows\system32\drivers\AswRdr.sys [2012-03-07 35672]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-03-07 612184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-03-07 337880]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-03-07 53848]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2012-03-14 120152]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-03-07 20696]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-03-07 57688]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-11-12 281760]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2012-03-14 148504]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-11-12 25888]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-09 45568]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-06 908800]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 23424]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 102912]
R3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 101120]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-11-01 2011224]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2007-07-13 50688]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-22 982272]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-06 196400]
S3 Axtmvflt;Axesstel USB Filter Service; C:\Windows\system32\DRIVERS\Axtmvflt.sys [2007-03-22 3456]
S3 Axtmvmdm;Axesstel USB Modem; C:\Windows\system32\DRIVERS\Axtmvmdm.sys [2007-03-26 40064]
S3 Axtmvprt;Axesstel Diagnostic Port; C:\Windows\System32\Drivers\Axtmvprt.sys [2007-03-26 38784]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-21 19456]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2012-03-14 169080]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2009-03-02 47360]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-21 49664]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2007-05-18 73728]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-03-07 44768]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2012-03-07 134920]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2012-03-07 913144]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-12-01 33752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-28 129976]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Sirefef neboli ZeroAccess je pekna mrcha, dokaze s PC nadelat pekne vylomeniny, ale zalezi na konkretnim typu a modifikaci...Nekdy se skoro neda lecit

:arrow: Je tam Avast, avg a ESET, na konci pouklizime, musi byt jen jeden

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
Taller
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 04 čer 2012 11:08
Bydliště: Brandýs nad Labem Stará Boleslav

Re: Prosím o kontrolu logu

#3 Příspěvek od Taller »

RogueKiller V7.5.2 [05/30/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v: Normální režim
Uživatel: zip [Práva správce]
Mód: Kontrola -- Datum: 06/04/2012 13:36:35

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 6 ¤¤¤
[SUSP PATH] HKCU\[...]\RunOnce : Braid BVRPOLR ("C:\Program Files\InstallShield Installation Information\{CCA4BD8B-47B5-46CC-818E-2A716B031FE1}\Republishing.exe" -runfromtemp -f2C:\Users\zip\AppData\Local\Temp\Setup.log) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-294344716-497121030-3722303623-1000[...]\RunOnce : Braid BVRPOLR ("C:\Program Files\InstallShield Installation Information\{CCA4BD8B-47B5-46CC-818E-2A716B031FE1}\Republishing.exe" -runfromtemp -f2C:\Users\zip\AppData\Local\Temp\Setup.log) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{C39AC866-A09F-437B-ADC8-2104FE03A79C} : NameServer (160.218.167.5 160.218.161.60) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost
::1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST9250827AS +++++
--- User ---
[MBR] 1bc5fddc172aa00a0a656ce3b214fb6d
[BSP] 68a9a69bc00139773c4fa2984750dba9 : Windows Vista/7 MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 63 | Size: 10001 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 20482875 | Size: 119232 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 264670875 | Size: 109238 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: ADATA USB Flash Drive USB Device +++++
--- User ---
[MBR] 1b59dd49226c4413831dcb2793cb81cc
[BSP] a83a24340e59ea8cbbf2d8eaa19e98b0 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 63 | Size: 7717 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[1].txt >>
RKreport[1].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#4 Příspěvek od vyosek »

:arrow: Spustte znovu RogueKiller
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost Prohledat a pote Smazat a nasledne Zprava - otevre se log, ten sem vlozte
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
Taller
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 04 čer 2012 11:08
Bydliště: Brandýs nad Labem Stará Boleslav

Re: Prosím o kontrolu logu

#5 Příspěvek od Taller »

RogueKiller V7.5.2 [05/30/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v: Normální režim
Uživatel: zip [Práva správce]
Mód: Odebrat -- Datum: 06/04/2012 13:49:58

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 5 ¤¤¤
[SUSP PATH] HKCU\[...]\RunOnce : Braid BVRPOLR ("C:\Program Files\InstallShield Installation Information\{CCA4BD8B-47B5-46CC-818E-2A716B031FE1}\Republishing.exe" -runfromtemp -f2C:\Users\zip\AppData\Local\Temp\Setup.log) -> DELETED
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{C39AC866-A09F-437B-ADC8-2104FE03A79C} : NameServer (160.218.167.5 160.218.161.60) -> NOT REMOVED, USE DNSFIX
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost
::1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST9250827AS +++++
--- User ---
[MBR] 1bc5fddc172aa00a0a656ce3b214fb6d
[BSP] 68a9a69bc00139773c4fa2984750dba9 : Windows Vista/7 MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 63 | Size: 10001 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 20482875 | Size: 119232 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 264670875 | Size: 109238 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: ADATA USB Flash Drive USB Device +++++
--- User ---
[MBR] 1b59dd49226c4413831dcb2793cb81cc
[BSP] a83a24340e59ea8cbbf2d8eaa19e98b0 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 63 | Size: 7717 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

13:51:16.0550 5820 TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:16
13:51:17.0043 5820 ============================================================
13:51:17.0043 5820 Current date / time: 2012/06/04 13:51:17.0043
13:51:17.0043 5820 SystemInfo:
13:51:17.0043 5820
13:51:17.0043 5820 OS Version: 6.0.6001 ServicePack: 1.0
13:51:17.0043 5820 Product type: Workstation
13:51:17.0044 5820 ComputerName: ZIP-PC
13:51:17.0044 5820 UserName: zip
13:51:17.0044 5820 Windows directory: C:\Windows
13:51:17.0044 5820 System windows directory: C:\Windows
13:51:17.0044 5820 Processor architecture: Intel x86
13:51:17.0044 5820 Number of processors: 2
13:51:17.0044 5820 Page size: 0x1000
13:51:17.0044 5820 Boot type: Normal boot
13:51:17.0044 5820 ============================================================
13:51:17.0717 5820 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:51:17.0725 5820 Drive \Device\Harddisk1\DR1 - Size: 0x1E2600000 (7.54 Gb), SectorSize: 0x200, Cylinders: 0x3D7, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:51:17.0737 5820 ============================================================
13:51:17.0738 5820 \Device\Harddisk0\DR0:
13:51:17.0740 5820 MBR partitions:
13:51:17.0740 5820 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1388B3B, BlocksNum 0xE8E0360
13:51:17.0761 5820 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xFC68EDA, BlocksNum 0xD55B6A7
13:51:17.0761 5820 \Device\Harddisk1\DR1:
13:51:17.0762 5820 MBR partitions:
13:51:17.0762 5820 \Device\Harddisk1\DR1\Partition0: MBR, Type 0xB, StartLBA 0x3F, BlocksNum 0xF12FC1
13:51:17.0762 5820 ============================================================
13:51:17.0804 5820 C: <-> \Device\Harddisk0\DR0\Partition0
13:51:17.0853 5820 D: <-> \Device\Harddisk0\DR0\Partition1
13:51:17.0853 5820 ============================================================
13:51:17.0853 5820 Initialize success
13:51:17.0854 5820 ============================================================
13:52:26.0945 5856 ============================================================
13:52:26.0945 5856 Scan started
13:52:26.0945 5856 Mode: Manual; SigCheck; TDLFS;
13:52:26.0945 5856 ============================================================
13:52:27.0314 5856 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
13:52:27.0544 5856 ACPI - ok
13:52:27.0590 5856 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
13:52:27.0643 5856 adp94xx - ok
13:52:27.0696 5856 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
13:52:27.0731 5856 adpahci - ok
13:52:27.0743 5856 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
13:52:27.0784 5856 adpu160m - ok
13:52:27.0799 5856 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
13:52:27.0836 5856 adpu320 - ok
13:52:27.0925 5856 ADSMService (609a6f49b6af0f25837f8a0edddb0745) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
13:52:27.0973 5856 ADSMService ( UnsignedFile.Multi.Generic ) - warning
13:52:27.0973 5856 ADSMService - detected UnsignedFile.Multi.Generic (1)
13:52:28.0005 5856 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
13:52:28.0077 5856 AeLookupSvc - ok
13:52:28.0145 5856 AFD (48eb99503533c27ac6135648e5474457) C:\Windows\system32\drivers\afd.sys
13:52:28.0213 5856 AFD - ok
13:52:28.0267 5856 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
13:52:28.0297 5856 agp440 - ok
13:52:28.0328 5856 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
13:52:28.0362 5856 aic78xx - ok
13:52:28.0397 5856 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
13:52:28.0479 5856 ALG - ok
13:52:28.0511 5856 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
13:52:28.0538 5856 aliide - ok
13:52:28.0568 5856 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
13:52:28.0601 5856 amdagp - ok
13:52:28.0611 5856 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
13:52:28.0635 5856 amdide - ok
13:52:28.0645 5856 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
13:52:28.0729 5856 AmdK7 - ok
13:52:28.0739 5856 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
13:52:28.0820 5856 AmdK8 - ok
13:52:28.0883 5856 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
13:52:28.0945 5856 Appinfo - ok
13:52:28.0990 5856 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
13:52:29.0016 5856 arc - ok
13:52:29.0057 5856 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
13:52:29.0091 5856 arcsas - ok
13:52:29.0132 5856 AsDsm (4385e371c25c94c804e9d3152bd9e1f7) C:\Windows\system32\drivers\AsDsm.sys
13:52:29.0199 5856 AsDsm - ok
13:52:29.0269 5856 ASLDRService (5a055a4777cbbc8845dd598cb2eebf69) C:\Program Files\ATK Hotkey\ASLDRSrv.exe
13:52:29.0318 5856 ASLDRService ( UnsignedFile.Multi.Generic ) - warning
13:52:29.0318 5856 ASLDRService - detected UnsignedFile.Multi.Generic (1)
13:52:29.0360 5856 ASMMAP (7b4d08d2017ac06689d422e06c43f0aa) C:\Program Files\ATKGFNEX\ASMMAP.sys
13:52:29.0378 5856 ASMMAP - ok
13:52:29.0433 5856 aswFsBlk (0ae43c6c411254049279c2ee55630f95) C:\Windows\system32\drivers\aswFsBlk.sys
13:52:29.0457 5856 aswFsBlk - ok
13:52:29.0521 5856 aswFW (80beddcbb4a1417cec0c78a61cac0f66) C:\Windows\system32\drivers\aswFW.sys
13:52:29.0548 5856 aswFW - ok
13:52:29.0587 5856 aswKbd (81e695913fefd4e23360a69c0f151797) C:\Windows\system32\drivers\aswKbd.sys
13:52:29.0608 5856 aswKbd - ok
13:52:29.0633 5856 aswMonFlt (6693141560b1615d8dccf0d8eb00087e) C:\Windows\system32\drivers\aswMonFlt.sys
13:52:29.0653 5856 aswMonFlt - ok
13:52:29.0681 5856 aswNdis (7b948e3657bea62e437bc46ca6ef6012) C:\Windows\system32\DRIVERS\aswNdis.sys
13:52:29.0699 5856 aswNdis - ok
13:52:29.0733 5856 aswNdis2 (72c8f79d72b4ff6e1627276ddf4b01c9) C:\Windows\system32\drivers\aswNdis2.sys
13:52:29.0771 5856 aswNdis2 - ok
13:52:29.0798 5856 AswRdr (da12626fd9a67f4e917e2f2fbe1e1764) C:\Windows\system32\drivers\AswRdr.sys
13:52:29.0820 5856 AswRdr - ok
13:52:29.0879 5856 aswSnx (dcb199b967375753b5019ec15f008f53) C:\Windows\system32\drivers\aswSnx.sys
13:52:29.0940 5856 aswSnx - ok
13:52:29.0999 5856 aswSP (b32873e5a1443c0a1e322266e203bf10) C:\Windows\system32\drivers\aswSP.sys
13:52:30.0059 5856 aswSP - ok
13:52:30.0098 5856 aswTdi (6ff544175a9180c5d88534d3d9c9a9f7) C:\Windows\system32\drivers\aswTdi.sys
13:52:30.0120 5856 aswTdi - ok
13:52:30.0157 5856 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
13:52:30.0227 5856 AsyncMac - ok
13:52:30.0251 5856 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys
13:52:30.0274 5856 atapi - ok
13:52:30.0366 5856 athr (4df523f49694b2884f8e5d870bf3e253) C:\Windows\system32\DRIVERS\athr.sys
13:52:30.0493 5856 athr - ok
13:52:30.0581 5856 ATKGFNEXSrv (7c157574a181b19b9dcf5f339e25337e) C:\Program Files\ATKGFNEX\GFNEXSrv.exe
13:52:30.0629 5856 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - warning
13:52:30.0629 5856 ATKGFNEXSrv - detected UnsignedFile.Multi.Generic (1)
13:52:30.0697 5856 atksgt (f0d933b42cd0594048e4d5200ae9e417) C:\Windows\system32\DRIVERS\atksgt.sys
13:52:30.0729 5856 atksgt - ok
13:52:30.0797 5856 AudioEndpointBuilder (42076e29aafa0830a2c5d4e310f58dd1) C:\Windows\System32\Audiosrv.dll
13:52:30.0891 5856 AudioEndpointBuilder - ok
13:52:30.0903 5856 Audiosrv (42076e29aafa0830a2c5d4e310f58dd1) C:\Windows\System32\Audiosrv.dll
13:52:30.0968 5856 Audiosrv - ok
13:52:31.0063 5856 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
13:52:31.0085 5856 avast! Antivirus - ok
13:52:31.0120 5856 avast! Firewall (7d465549dfb0eca6601e9609c72cd20a) C:\Program Files\AVAST Software\Avast\afwServ.exe
13:52:31.0143 5856 avast! Firewall - ok
13:52:31.0179 5856 Axtmvflt (59629edd214c35a01e2527ac3b8a7fb3) C:\Windows\system32\DRIVERS\Axtmvflt.sys
13:52:31.0207 5856 Axtmvflt ( UnsignedFile.Multi.Generic ) - warning
13:52:31.0207 5856 Axtmvflt - detected UnsignedFile.Multi.Generic (1)
13:52:31.0238 5856 Axtmvmdm (37e23b1756eca768656097f72c0b458d) C:\Windows\system32\DRIVERS\Axtmvmdm.sys
13:52:31.0270 5856 Axtmvmdm ( UnsignedFile.Multi.Generic ) - warning
13:52:31.0270 5856 Axtmvmdm - detected UnsignedFile.Multi.Generic (1)
13:52:31.0280 5856 Axtmvprt (2c7170be24eacc0b432eb1832fee0ddc) C:\Windows\system32\Drivers\Axtmvprt.sys
13:52:31.0310 5856 Axtmvprt ( UnsignedFile.Multi.Generic ) - warning
13:52:31.0310 5856 Axtmvprt - detected UnsignedFile.Multi.Generic (1)
13:52:31.0362 5856 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
13:52:31.0439 5856 Beep - ok
13:52:31.0546 5856 BITS (02ed7b4dbc2a3232a389106da7515c3d) C:\Windows\System32\qmgr.dll
13:52:31.0843 5856 BITS - ok
13:52:31.0876 5856 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
13:52:31.0949 5856 blbdrive - ok
13:52:31.0979 5856 bowser (8153396d5551276227fa146900f734e6) C:\Windows\system32\DRIVERS\bowser.sys
13:52:32.0043 5856 bowser - ok
13:52:32.0087 5856 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
13:52:32.0162 5856 BrFiltLo - ok
13:52:32.0169 5856 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
13:52:32.0250 5856 BrFiltUp - ok
13:52:32.0287 5856 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
13:52:32.0376 5856 Browser - ok
13:52:32.0428 5856 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
13:52:32.0531 5856 Brserid - ok
13:52:32.0540 5856 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
13:52:32.0693 5856 BrSerWdm - ok
13:52:32.0721 5856 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
13:52:32.0868 5856 BrUsbMdm - ok
13:52:32.0896 5856 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
13:52:33.0032 5856 BrUsbSer - ok
13:52:33.0057 5856 BthEnum (da7b195275bda7f8fcf79b40e0f45dde) C:\Windows\system32\DRIVERS\BthEnum.sys
13:52:33.0124 5856 BthEnum - ok
13:52:33.0153 5856 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
13:52:33.0279 5856 BTHMODEM - ok
13:52:33.0320 5856 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
13:52:33.0382 5856 BthPan - ok
13:52:33.0433 5856 BTHPORT (73d53f8e90550ba81e2cf44a0873b410) C:\Windows\system32\Drivers\BTHport.sys
13:52:33.0478 5856 BTHPORT - ok
13:52:33.0529 5856 BthServ (58ee7f5e68310bc8d4e7cebd8358c12e) C:\Windows\System32\bthserv.dll
13:52:33.0630 5856 BthServ - ok
13:52:33.0669 5856 BTHUSB (32045a4bb143bbc5bab1298c4e9e309a) C:\Windows\system32\Drivers\BTHUSB.sys
13:52:33.0711 5856 BTHUSB - ok
13:52:33.0743 5856 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
13:52:33.0801 5856 cdfs - ok
13:52:33.0859 5856 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
13:52:33.0939 5856 cdrom - ok
13:52:33.0966 5856 CertPropSvc (87c2d0377b23e2d8a41093c2f5fb1a5b) C:\Windows\System32\certprop.dll
13:52:34.0054 5856 CertPropSvc - ok
13:52:34.0087 5856 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
13:52:34.0160 5856 circlass - ok
13:52:34.0207 5856 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
13:52:34.0259 5856 CLFS - ok
13:52:34.0315 5856 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:52:34.0397 5856 clr_optimization_v2.0.50727_32 - ok
13:52:34.0482 5856 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:52:34.0549 5856 clr_optimization_v4.0.30319_32 - ok
13:52:34.0595 5856 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
13:52:34.0673 5856 CmBatt - ok
13:52:34.0699 5856 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
13:52:34.0723 5856 cmdide - ok
13:52:34.0744 5856 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
13:52:34.0770 5856 Compbatt - ok
13:52:34.0777 5856 COMSysApp - ok
13:52:34.0792 5856 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
13:52:34.0826 5856 crcdisk - ok
13:52:34.0835 5856 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
13:52:34.0906 5856 Crusoe - ok
13:52:34.0967 5856 CryptSvc (6de363f9f99334514c46aec02d3e3678) C:\Windows\system32\cryptsvc.dll
13:52:35.0083 5856 CryptSvc - ok
13:52:35.0178 5856 DcomLaunch (301ae00e12408650baddc04dbc832830) C:\Windows\system32\rpcss.dll
13:52:35.0433 5856 DcomLaunch - ok
13:52:35.0481 5856 DfsC (a3e9fa213f443ac77c7746119d13feec) C:\Windows\system32\Drivers\dfsc.sys
13:52:35.0537 5856 DfsC - ok
13:52:35.0687 5856 DFSR (fa3463f25f9cc9c3bcf1e7912feff099) C:\Windows\system32\DFSR.exe
13:52:35.0864 5856 DFSR - ok
13:52:35.0996 5856 Dhcp (43a988a9c10333476cb5fb667cbd629d) C:\Windows\System32\dhcpcsvc.dll
13:52:36.0118 5856 Dhcp - ok
13:52:36.0186 5856 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
13:52:36.0212 5856 disk - ok
13:52:36.0252 5856 Dnscache (4805d9a6d281c7a7defd9094dec6af7d) C:\Windows\System32\dnsrslvr.dll
13:52:36.0360 5856 Dnscache - ok
13:52:36.0404 5856 dot3svc (5af620a08c614e24206b79e8153cf1a8) C:\Windows\System32\dot3svc.dll
13:52:36.0524 5856 dot3svc - ok
13:52:36.0572 5856 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
13:52:36.0692 5856 DPS - ok
13:52:36.0735 5856 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
13:52:36.0803 5856 drmkaud - ok
13:52:36.0864 5856 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
13:52:36.0959 5856 DXGKrnl - ok
13:52:37.0010 5856 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
13:52:37.0098 5856 E1G60 - ok
13:52:37.0156 5856 eamonm (8a45015e85a4dce0086b9973f0fd9a20) C:\Windows\system32\DRIVERS\eamonm.sys
13:52:37.0193 5856 eamonm - ok
13:52:37.0229 5856 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
13:52:37.0342 5856 EapHost - ok
13:52:37.0379 5856 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
13:52:37.0409 5856 Ecache - ok
13:52:37.0459 5856 ehdrv (5412ed24fffca64e2f0168399b86c952) C:\Windows\system32\DRIVERS\ehdrv.sys
13:52:37.0485 5856 ehdrv - ok
13:52:37.0551 5856 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
13:52:37.0603 5856 ehRecvr - ok
13:52:37.0628 5856 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
13:52:37.0695 5856 ehSched - ok
13:52:37.0721 5856 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
13:52:37.0770 5856 ehstart - ok
13:52:38.0004 5856 ekrn (ad4faade819e0da9933bea7c01d2c763) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
13:52:38.0076 5856 ekrn - ok
13:52:38.0233 5856 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
13:52:38.0271 5856 elxstor - ok
13:52:38.0337 5856 EMDMgmt (70b1a86df0c8ead17d2bc332edae2c7c) C:\Windows\system32\emdmgmt.dll
13:52:38.0452 5856 EMDMgmt - ok
13:52:38.0509 5856 epfw (774babcb1144513dc86992003740b774) C:\Windows\system32\DRIVERS\epfw.sys
13:52:38.0534 5856 epfw - ok
13:52:38.0557 5856 epfwwfp (2b4e5f01a4e786b422f4d617b51fa7d9) C:\Windows\system32\DRIVERS\epfwwfp.sys
13:52:38.0580 5856 epfwwfp - ok
13:52:38.0619 5856 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
13:52:38.0676 5856 ErrDev - ok
13:52:38.0735 5856 EventSystem (3cb3343d720168b575133a0a20dc2465) C:\Windows\system32\es.dll
13:52:38.0842 5856 EventSystem - ok
13:52:38.0893 5856 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
13:52:38.0973 5856 exfat - ok
13:52:39.0000 5856 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
13:52:39.0075 5856 fastfat - ok
13:52:39.0105 5856 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
13:52:39.0162 5856 fdc - ok
13:52:39.0198 5856 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
13:52:39.0321 5856 fdPHost - ok
13:52:39.0349 5856 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
13:52:39.0513 5856 FDResPub - ok
13:52:39.0543 5856 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
13:52:39.0570 5856 FileInfo - ok
13:52:39.0595 5856 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
13:52:39.0668 5856 Filetrace - ok
13:52:39.0678 5856 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
13:52:39.0752 5856 flpydisk - ok
13:52:39.0785 5856 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
13:52:39.0817 5856 FltMgr - ok
13:52:39.0897 5856 FontCache3.0.0.0 (c9be08664611ddaf98e2331e9288b00b) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:52:39.0918 5856 FontCache3.0.0.0 - ok
13:52:39.0953 5856 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
13:52:40.0014 5856 Fs_Rec - ok
13:52:40.0054 5856 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
13:52:40.0083 5856 gagp30kx - ok
13:52:40.0155 5856 getPlus(R) Helper (7bec703f31e1d441db16886c9aa4cba9) C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
13:52:40.0172 5856 getPlus(R) Helper - ok
13:52:40.0238 5856 ghaio (31b40f40e09513addc460f6a297ad474) C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
13:52:40.0256 5856 ghaio - ok
13:52:40.0315 5856 gpsvc (d9f1113d9401185245573350712f92fc) C:\Windows\System32\gpsvc.dll
13:52:40.0465 5856 gpsvc - ok
13:52:40.0526 5856 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
13:52:40.0637 5856 HdAudAddService - ok
13:52:40.0660 5856 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
13:52:40.0719 5856 HDAudBus - ok
13:52:40.0739 5856 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
13:52:40.0833 5856 HidBth - ok
13:52:40.0842 5856 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
13:52:40.0953 5856 HidIr - ok
13:52:40.0996 5856 hidserv (8fa640195279ace21bea91396a0054fc) C:\Windows\system32\hidserv.dll
13:52:41.0166 5856 hidserv - ok
13:52:41.0202 5856 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys
13:52:41.0279 5856 HidUsb - ok
13:52:41.0312 5856 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
13:52:41.0473 5856 hkmsvc - ok
13:52:41.0499 5856 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
13:52:41.0528 5856 HpCISSs - ok
13:52:41.0580 5856 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys
13:52:41.0654 5856 HTTP - ok
13:52:41.0695 5856 Huawei (c1258adcbe6e51a3c06c234d2bdb81b5) C:\Windows\system32\DRIVERS\ewdcsc.sys
13:52:41.0728 5856 Huawei - ok
13:52:41.0771 5856 hwdatacard (0515065a3c7e8869dd01253e987c5bd1) C:\Windows\system32\DRIVERS\ewusbmdm.sys
13:52:41.0804 5856 hwdatacard - ok
13:52:41.0843 5856 hwusbdev (a259d3619aa23d4562581067f85e2006) C:\Windows\system32\DRIVERS\ewusbdev.sys
13:52:41.0898 5856 hwusbdev - ok
13:52:41.0940 5856 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
13:52:41.0967 5856 i2omp - ok
13:52:42.0016 5856 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
13:52:42.0080 5856 i8042prt - ok
13:52:42.0132 5856 iaStor (e5a0034847537eaee3c00349d5c34c5f) C:\Windows\system32\DRIVERS\iaStor.sys
13:52:42.0164 5856 iaStor - ok
13:52:42.0205 5856 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
13:52:42.0241 5856 iaStorV - ok
13:52:42.0354 5856 IDriverT (daf66902f08796f9c694901660e5a64a) C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
13:52:42.0378 5856 IDriverT ( UnsignedFile.Multi.Generic ) - warning
13:52:42.0378 5856 IDriverT - detected UnsignedFile.Multi.Generic (1)
13:52:42.0494 5856 idsvc (7b630acaed64fef0c3e1cf255cb56686) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:52:42.0602 5856 idsvc - ok
13:52:42.0784 5856 igfx (9378d57e2b96c0a185d844770ad49948) C:\Windows\system32\DRIVERS\igdkmd32.sys
13:52:42.0886 5856 igfx - ok
13:52:43.0022 5856 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
13:52:43.0049 5856 iirsp - ok
13:52:43.0118 5856 IKEEXT (a3bc480a2bf8aa8e4dabd2d5dce0afac) C:\Windows\System32\ikeext.dll
13:52:43.0267 5856 IKEEXT - ok
13:52:43.0422 5856 IntcAzAudAddService (4e38a2883df3ba382a59132b3e7d709e) C:\Windows\system32\drivers\RTKVHDA.sys
13:52:43.0526 5856 IntcAzAudAddService - ok
13:52:43.0660 5856 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
13:52:43.0688 5856 intelide - ok
13:52:43.0708 5856 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
13:52:43.0768 5856 intelppm - ok
13:52:43.0798 5856 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
13:52:43.0943 5856 IPBusEnum - ok
13:52:43.0979 5856 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:52:44.0052 5856 IpFilterDriver - ok
13:52:44.0061 5856 IpInIp - ok
13:52:44.0079 5856 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
13:52:44.0140 5856 IPMIDRV - ok
13:52:44.0180 5856 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
13:52:44.0255 5856 IPNAT - ok
13:52:44.0284 5856 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
13:52:44.0342 5856 IRENUM - ok
13:52:44.0366 5856 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
13:52:44.0395 5856 isapnp - ok
13:52:44.0438 5856 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys
13:52:44.0472 5856 iScsiPrt - ok
13:52:44.0498 5856 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
13:52:44.0525 5856 iteatapi - ok
13:52:44.0533 5856 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
13:52:44.0562 5856 iteraid - ok
13:52:44.0592 5856 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
13:52:44.0622 5856 kbdclass - ok
13:52:44.0634 5856 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
13:52:44.0712 5856 kbdhid - ok
13:52:44.0760 5856 kbfiltr (cc2a86d7bbf14977340dca61bbcba771) C:\Windows\system32\DRIVERS\kbfiltr.sys
13:52:44.0793 5856 kbfiltr - ok
13:52:44.0816 5856 KeyIso (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
13:52:44.0952 5856 KeyIso - ok
13:52:45.0021 5856 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys
13:52:45.0072 5856 KSecDD - ok
13:52:45.0124 5856 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
13:52:45.0311 5856 KtmRm - ok
13:52:45.0345 5856 LanmanServer (1925e63c91cf1610ae41bfd539062079) C:\Windows\system32\srvsvc.dll
13:52:45.0574 5856 LanmanServer - ok
13:52:45.0609 5856 LanmanWorkstation (2ae2e1628c5d3f1c0a46a67c9fa1df15) C:\Windows\System32\wkssvc.dll
13:52:45.0856 5856 LanmanWorkstation - ok
13:52:45.0938 5856 LightScribeService (abf90fc5a127f481219b873c1b8dfc1c) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
13:52:45.0967 5856 LightScribeService ( UnsignedFile.Multi.Generic ) - warning
13:52:45.0967 5856 LightScribeService - detected UnsignedFile.Multi.Generic (1)
13:52:45.0993 5856 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\Windows\system32\DRIVERS\lirsgt.sys
13:52:46.0018 5856 lirsgt - ok
13:52:46.0045 5856 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
13:52:46.0116 5856 lltdio - ok
13:52:46.0157 5856 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
13:52:46.0307 5856 lltdsvc - ok
13:52:46.0331 5856 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
13:52:46.0520 5856 lmhosts - ok
13:52:46.0567 5856 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
13:52:46.0596 5856 LSI_FC - ok
13:52:46.0612 5856 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
13:52:46.0648 5856 LSI_SAS - ok
13:52:46.0676 5856 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
13:52:46.0707 5856 LSI_SCSI - ok
13:52:46.0729 5856 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
13:52:46.0812 5856 luafv - ok
13:52:46.0845 5856 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
13:52:46.0980 5856 Mcx2Svc - ok
13:52:47.0021 5856 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
13:52:47.0050 5856 megasas - ok
13:52:47.0094 5856 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
13:52:47.0137 5856 MegaSR - ok
13:52:47.0170 5856 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
13:52:47.0321 5856 MMCSS - ok
13:52:47.0342 5856 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
13:52:47.0422 5856 Modem - ok
13:52:47.0441 5856 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
13:52:47.0502 5856 monitor - ok
13:52:47.0527 5856 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
13:52:47.0556 5856 mouclass - ok
13:52:47.0574 5856 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
13:52:47.0635 5856 mouhid - ok
13:52:47.0675 5856 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
13:52:47.0705 5856 MountMgr - ok
13:52:47.0778 5856 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:52:47.0809 5856 MozillaMaintenance - ok
13:52:47.0862 5856 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
13:52:47.0894 5856 mpio - ok
13:52:47.0911 5856 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
13:52:47.0984 5856 mpsdrv - ok
13:52:48.0018 5856 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
13:52:48.0048 5856 Mraid35x - ok
13:52:48.0082 5856 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys
13:52:48.0142 5856 MRxDAV - ok
13:52:48.0177 5856 mrxsmb (5734a0f2be7e495f7d3ed6efd4b9f5a1) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:52:48.0217 5856 mrxsmb - ok
13:52:48.0243 5856 mrxsmb10 (6b5fa5adfacac9dbbe0991f4566d7d55) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:52:48.0297 5856 mrxsmb10 - ok
13:52:48.0319 5856 mrxsmb20 (5c80d8159181c7abf1b14ba703b01e0b) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:52:48.0383 5856 mrxsmb20 - ok
13:52:48.0437 5856 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
13:52:48.0466 5856 msahci - ok
13:52:48.0490 5856 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
13:52:48.0521 5856 msdsm - ok
13:52:48.0555 5856 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
13:52:48.0717 5856 MSDTC - ok
13:52:48.0752 5856 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
13:52:48.0828 5856 Msfs - ok
13:52:48.0865 5856 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
13:52:48.0895 5856 msisadrv - ok
13:52:48.0934 5856 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
13:52:49.0079 5856 MSiSCSI - ok
13:52:49.0086 5856 msiserver - ok
13:52:49.0129 5856 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
13:52:49.0213 5856 MSKSSRV - ok
13:52:49.0220 5856 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
13:52:49.0280 5856 MSPCLOCK - ok
13:52:49.0287 5856 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
13:52:49.0363 5856 MSPQM - ok
13:52:49.0395 5856 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys
13:52:49.0429 5856 MsRPC - ok
13:52:49.0480 5856 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
13:52:49.0510 5856 mssmbios - ok
13:52:49.0523 5856 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
13:52:49.0583 5856 MSTEE - ok
13:52:49.0606 5856 MTsensor (97affa9d95ffe20eee6229bc6be166cf) C:\Windows\system32\DRIVERS\ATKACPI.sys
13:52:49.0631 5856 MTsensor - ok
13:52:49.0652 5856 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys
13:52:49.0683 5856 Mup - ok
13:52:49.0741 5856 napagent (c43b25863fbd65b6d2a142af3ae320ca) C:\Windows\system32\qagentRT.dll
13:52:49.0937 5856 napagent - ok
13:52:49.0981 5856 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys
13:52:50.0019 5856 NativeWifiP - ok
13:52:50.0084 5856 NDIS (c8560010a542b5dca94c62468dc20784) C:\Windows\system32\drivers\ndis.sys
13:52:50.0144 5856 NDIS - ok
13:52:50.0164 5856 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
13:52:50.0216 5856 NdisTapi - ok
13:52:50.0231 5856 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
13:52:50.0292 5856 Ndisuio - ok
13:52:50.0325 5856 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys
13:52:50.0402 5856 NdisWan - ok
13:52:50.0427 5856 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
13:52:50.0497 5856 NDProxy - ok
13:52:50.0530 5856 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
13:52:50.0611 5856 NetBIOS - ok
13:52:50.0646 5856 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys
13:52:50.0721 5856 netbt - ok
13:52:50.0747 5856 Netlogon (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
13:52:50.0857 5856 Netlogon - ok
13:52:50.0906 5856 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
13:52:51.0093 5856 Netman - ok
13:52:51.0135 5856 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
13:52:51.0329 5856 netprofm - ok
13:52:51.0413 5856 NetTcpPortSharing (0ad5876ef4e9eb77c8f93eb5b2fff386) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:52:51.0451 5856 NetTcpPortSharing - ok
13:52:51.0481 5856 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
13:52:51.0512 5856 nfrd960 - ok
13:52:51.0546 5856 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
13:52:51.0737 5856 NlaSvc - ok
13:52:51.0768 5856 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys
13:52:51.0830 5856 Npfs - ok
13:52:51.0864 5856 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
13:52:52.0055 5856 nsi - ok
13:52:52.0074 5856 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
13:52:52.0148 5856 nsiproxy - ok
13:52:52.0244 5856 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys
13:52:52.0333 5856 Ntfs - ok
13:52:52.0358 5856 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
13:52:52.0471 5856 ntrigdigi - ok
13:52:52.0489 5856 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
13:52:52.0568 5856 Null - ok
13:52:52.0610 5856 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
13:52:52.0644 5856 nvraid - ok
13:52:52.0655 5856 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
13:52:52.0696 5856 nvstor - ok
13:52:52.0713 5856 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
13:52:52.0748 5856 nv_agp - ok
13:52:52.0754 5856 NwlnkFlt - ok
13:52:52.0765 5856 NwlnkFwd - ok
13:52:52.0928 5856 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
13:52:52.0989 5856 odserv - ok
13:52:53.0054 5856 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
13:52:53.0116 5856 ohci1394 - ok
13:52:53.0162 5856 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:52:53.0191 5856 ose - ok
13:52:53.0267 5856 p2pimsvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
13:52:53.0452 5856 p2pimsvc - ok
13:52:53.0466 5856 p2psvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
13:52:53.0631 5856 p2psvc - ok
13:52:53.0680 5856 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
13:52:53.0779 5856 Parport - ok
13:52:53.0806 5856 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys
13:52:53.0837 5856 partmgr - ok
13:52:53.0847 5856 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
13:52:53.0946 5856 Parvdm - ok
13:52:53.0975 5856 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
13:52:54.0146 5856 PcaSvc - ok
13:52:54.0178 5856 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys
13:52:54.0213 5856 pci - ok
13:52:54.0231 5856 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
13:52:54.0261 5856 pciide - ok
13:52:54.0323 5856 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys
13:52:54.0358 5856 pcmcia - ok
13:52:54.0410 5856 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys
13:52:54.0444 5856 pcouffin - ok
13:52:54.0548 5856 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
13:52:54.0713 5856 PEAUTH - ok
13:52:54.0852 5856 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
13:52:55.0143 5856 pla - ok
13:52:55.0267 5856 PlugPlay (78f975cb6d18265be6f492edb2d7bc7b) C:\Windows\system32\umpnpmgr.dll
13:52:55.0597 5856 PlugPlay - ok
13:52:55.0676 5856 PNRPAutoReg (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
13:52:55.0849 5856 PNRPAutoReg - ok
13:52:55.0864 5856 PNRPsvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
13:52:56.0040 5856 PNRPsvc - ok
13:52:56.0093 5856 PolicyAgent (47b8f37aa18b74d8c2e1bc1a7a2c8f8a) C:\Windows\System32\ipsecsvc.dll
13:52:56.0230 5856 PolicyAgent - ok
13:52:56.0300 5856 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
13:52:56.0382 5856 PptpMiniport - ok
13:52:56.0403 5856 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
13:52:56.0466 5856 Processor - ok
13:52:56.0513 5856 ProfSvc (b627e4fc8585e8843c5905d4d3587a90) C:\Windows\system32\profsvc.dll
13:52:56.0725 5856 ProfSvc - ok
13:52:56.0766 5856 ProtectedStorage (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
13:52:56.0876 5856 ProtectedStorage - ok
13:52:56.0902 5856 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys
13:52:56.0939 5856 PSched - ok
13:52:57.0029 5856 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
13:52:57.0103 5856 ql2300 - ok
13:52:57.0118 5856 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
13:52:57.0150 5856 ql40xx - ok
13:52:57.0194 5856 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
13:52:57.0372 5856 QWAVE - ok
13:52:57.0402 5856 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
13:52:57.0456 5856 QWAVEdrv - ok
13:52:57.0482 5856 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
13:52:57.0545 5856 RasAcd - ok
13:52:57.0576 5856 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
13:52:57.0784 5856 RasAuto - ok
13:52:57.0807 5856 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:52:57.0886 5856 Rasl2tp - ok
13:52:57.0937 5856 RasMan (6e7c284fc5c4ec07ad164d93810385a6) C:\Windows\System32\rasmans.dll
13:52:58.0154 5856 RasMan - ok
13:52:58.0197 5856 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys
13:52:58.0275 5856 RasPppoe - ok
13:52:58.0306 5856 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys
13:52:58.0382 5856 RasSstp - ok
13:52:58.0417 5856 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys
13:52:58.0505 5856 rdbss - ok
13:52:58.0545 5856 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:52:58.0629 5856 RDPCDD - ok
13:52:58.0676 5856 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
13:52:58.0757 5856 rdpdr - ok
13:52:58.0778 5856 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
13:52:58.0840 5856 RDPENCDD - ok
13:52:58.0864 5856 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys
13:52:58.0930 5856 RDPWD - ok
13:52:58.0963 5856 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
13:52:59.0111 5856 RemoteAccess - ok
13:52:59.0148 5856 RemoteRegistry (cc4e32400f3c7253400cf8f3f3a0b676) C:\Windows\system32\regsvc.dll
13:52:59.0358 5856 RemoteRegistry - ok
13:52:59.0405 5856 RFCOMM (34cc78c06587718c2ad6d3aa83b1f072) C:\Windows\system32\DRIVERS\rfcomm.sys
13:52:59.0470 5856 RFCOMM - ok
13:52:59.0501 5856 rimmptsk (c35ca13d3627ebd9dd12a23ce781bc3d) C:\Windows\system32\DRIVERS\rimmptsk.sys
13:52:59.0537 5856 rimmptsk - ok
13:52:59.0555 5856 rimsptsk (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys
13:52:59.0607 5856 rimsptsk - ok
13:52:59.0638 5856 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
13:52:59.0760 5856 RpcLocator - ok
13:52:59.0824 5856 RpcSs (301ae00e12408650baddc04dbc832830) C:\Windows\system32\rpcss.dll
13:53:00.0089 5856 RpcSs - ok
13:53:00.0135 5856 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
13:53:00.0207 5856 rspndr - ok
13:53:00.0239 5856 RTL8023xp (5c5612756b380bcedbf566a780ff9afe) C:\Windows\system32\DRIVERS\Rtnicxp.sys
13:53:00.0306 5856 RTL8023xp - ok
13:53:00.0380 5856 SamSs (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
13:53:00.0494 5856 SamSs - ok
13:53:00.0829 5856 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
13:53:00.0862 5856 sbp2port - ok
13:53:00.0935 5856 SCardSvr (11387e32642269c7e62e8b52c060b3c6) C:\Windows\System32\SCardSvr.dll
13:53:01.0138 5856 SCardSvr - ok
13:53:01.0202 5856 Schedule (7b587b8a6d4a99f79d2902d0385f29bd) C:\Windows\system32\schedsvc.dll
13:53:01.0451 5856 Schedule - ok
13:53:01.0492 5856 SCPolicySvc (87c2d0377b23e2d8a41093c2f5fb1a5b) C:\Windows\System32\certprop.dll
13:53:01.0558 5856 SCPolicySvc - ok
13:53:01.0597 5856 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
13:53:01.0681 5856 sdbus - ok
13:53:01.0713 5856 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
13:53:01.0913 5856 SDRSVC - ok
13:53:01.0941 5856 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
13:53:02.0060 5856 secdrv - ok
13:53:02.0088 5856 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
13:53:02.0307 5856 seclogon - ok
13:53:02.0352 5856 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll
13:53:02.0578 5856 SENS - ok
13:53:02.0616 5856 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
13:53:02.0715 5856 Serenum - ok
13:53:02.0734 5856 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
13:53:02.0857 5856 Serial - ok
13:53:02.0866 5856 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
13:53:02.0929 5856 sermouse - ok
13:53:02.0983 5856 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
13:53:03.0222 5856 SessionEnv - ok
13:53:03.0253 5856 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
13:53:03.0327 5856 sffdisk - ok
13:53:03.0336 5856 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
13:53:03.0399 5856 sffp_mmc - ok
13:53:03.0432 5856 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
13:53:03.0515 5856 sffp_sd - ok
13:53:03.0524 5856 sfloppy (c33bfbd6e9e41fcd9ffef9729e9faed6) C:\Windows\system32\DRIVERS\sfloppy.sys
13:53:03.0587 5856 sfloppy - ok
13:53:03.0628 5856 ShellHWDetection (1e3fdb80e40a3ce645f229dfbdfb7694) C:\Windows\System32\shsvcs.dll
13:53:03.0836 5856 ShellHWDetection - ok
13:53:03.0881 5856 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
13:53:03.0927 5856 sisagp - ok
13:53:03.0939 5856 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
13:53:03.0972 5856 SiSRaid2 - ok
13:53:03.0985 5856 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
13:53:04.0020 5856 SiSRaid4 - ok
13:53:04.0196 5856 slsvc (0ba91e1358ad25236863039bb2609a2e) C:\Windows\system32\SLsvc.exe
13:53:04.0590 5856 slsvc - ok
13:53:04.0710 5856 SLUINotify (7c6dc44ca0bfa6291629ab764200d1d4) C:\Windows\system32\SLUINotify.dll
13:53:05.0003 5856 SLUINotify - ok
13:53:05.0071 5856 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys
13:53:05.0136 5856 Smb - ok
13:53:05.0221 5856 smserial (d9bfd2298f5cf116d8eaae3b02dcee2e) C:\Windows\system32\DRIVERS\smserial.sys
13:53:05.0286 5856 smserial - ok
13:53:05.0324 5856 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
13:53:05.0504 5856 SNMPTRAP - ok
13:53:05.0518 5856 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
13:53:05.0551 5856 spldr - ok
13:53:05.0628 5856 spmgr (739db668dbd812285ecc553e64a5e212) C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
13:53:05.0652 5856 spmgr - ok
13:53:05.0693 5856 Spooler (3665f79026a3f91fbca63f2c65a09b19) C:\Windows\System32\spoolsv.exe
13:53:05.0887 5856 Spooler - ok
13:53:05.0935 5856 srv (2252aef839b1093d16761189f45af885) C:\Windows\system32\DRIVERS\srv.sys
13:53:05.0983 5856 srv - ok
13:53:06.0028 5856 srv2 (b7ff59408034119476b00a81bb53d5d1) C:\Windows\system32\DRIVERS\srv2.sys
13:53:06.0091 5856 srv2 - ok
13:53:06.0125 5856 srvnet (2accc9b12af02030f531e6cca6f8b76e) C:\Windows\system32\DRIVERS\srvnet.sys
13:53:06.0167 5856 srvnet - ok
13:53:06.0200 5856 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
13:53:06.0448 5856 SSDPSRV - ok
13:53:06.0500 5856 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
13:53:06.0714 5856 SstpSvc - ok
13:53:06.0780 5856 stisvc (7dd08a597bc56051f320da0baf69e389) C:\Windows\System32\wiaservc.dll
13:53:07.0062 5856 stisvc - ok
13:53:07.0091 5856 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
13:53:07.0125 5856 swenum - ok
13:53:07.0175 5856 swprv (b36c7cdb86f7f7a8e884479219766950) C:\Windows\System32\swprv.dll
13:53:07.0442 5856 swprv - ok
13:53:07.0458 5856 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
13:53:07.0493 5856 Symc8xx - ok
13:53:07.0517 5856 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
13:53:07.0558 5856 Sym_hi - ok
13:53:07.0570 5856 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
13:53:07.0605 5856 Sym_u3 - ok
13:53:07.0672 5856 SynTP (55f6e55cc2430ca8713387106fa79817) C:\Windows\system32\DRIVERS\SynTP.sys
13:53:07.0707 5856 SynTP - ok
13:53:07.0768 5856 SysMain (8710a92d0024b03b5fb9540df1f71f1d) C:\Windows\system32\sysmain.dll
13:53:08.0056 5856 SysMain - ok
13:53:08.0080 5856 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
13:53:08.0296 5856 TabletInputService - ok
13:53:08.0323 5856 TapiSrv (680916bb09ee0f3a6aca7c274b0d633f) C:\Windows\System32\tapisrv.dll
13:53:08.0602 5856 TapiSrv - ok
13:53:08.0633 5856 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
13:53:08.0861 5856 TBS - ok
13:53:08.0939 5856 Tcpip (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\drivers\tcpip.sys
13:53:09.0009 5856 Tcpip - ok
13:53:09.0031 5856 Tcpip6 (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\DRIVERS\tcpip.sys
13:53:09.0101 5856 Tcpip6 - ok
13:53:09.0130 5856 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys
13:53:09.0196 5856 tcpipreg - ok
13:53:09.0215 5856 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
13:53:09.0295 5856 TDPIPE - ok
13:53:09.0305 5856 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
13:53:09.0379 5856 TDTCP - ok
13:53:09.0402 5856 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys
13:53:09.0480 5856 tdx - ok
13:53:09.0520 5856 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys
13:53:09.0555 5856 TermDD - ok
13:53:09.0608 5856 TermService (d605031e225aaccbceb5b76a4f1603a6) C:\Windows\System32\termsrv.dll
13:53:09.0889 5856 TermService - ok
13:53:09.0936 5856 Themes (1e3fdb80e40a3ce645f229dfbdfb7694) C:\Windows\system32\shsvcs.dll
13:53:10.0111 5856 Themes - ok
13:53:10.0174 5856 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
13:53:10.0315 5856 THREADORDER - ok
13:53:10.0379 5856 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
13:53:10.0649 5856 TrkWks - ok
13:53:10.0703 5856 TrustedInstaller (16613a1bad034d4ecf957af18b7c2ff5) C:\Windows\servicing\TrustedInstaller.exe
13:53:10.0772 5856 TrustedInstaller - ok
13:53:10.0795 5856 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:53:10.0879 5856 tssecsrv - ok
13:53:10.0924 5856 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
13:53:10.0989 5856 tunmp - ok
13:53:11.0018 5856 tunnel (6042505ff6fa9ac1ef7684d0e03b6940) C:\Windows\system32\DRIVERS\tunnel.sys
13:53:11.0060 5856 tunnel - ok
13:53:11.0078 5856 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
13:53:11.0112 5856 uagp35 - ok
13:53:11.0139 5856 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys
13:53:11.0230 5856 udfs - ok
13:53:11.0281 5856 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
13:53:11.0508 5856 UI0Detect - ok
13:53:11.0542 5856 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
13:53:11.0577 5856 uliagpkx - ok
13:53:11.0607 5856 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
13:53:11.0649 5856 uliahci - ok
13:53:11.0664 5856 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
13:53:11.0700 5856 UlSata - ok
13:53:11.0733 5856 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
13:53:11.0768 5856 ulsata2 - ok
13:53:11.0797 5856 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
13:53:11.0861 5856 umbus - ok
13:53:11.0927 5856 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
13:53:12.0220 5856 upnphost - ok
13:53:12.0267 5856 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
13:53:12.0324 5856 usbccgp - ok
13:53:12.0347 5856 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
13:53:12.0450 5856 usbcir - ok
13:53:12.0491 5856 usbehci (cebe90821810e76320155beba722fcf9) C:\Windows\system32\DRIVERS\usbehci.sys
13:53:12.0571 5856 usbehci - ok
13:53:12.0618 5856 usbhub (cc6b28e4ce39951357963119ce47b143) C:\Windows\system32\DRIVERS\usbhub.sys
13:53:12.0701 5856 usbhub - ok
13:53:12.0730 5856 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
13:53:12.0836 5856 usbohci - ok
13:53:12.0875 5856 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
13:53:12.0942 5856 usbprint - ok
13:53:12.0988 5856 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
13:53:13.0064 5856 usbscan - ok
13:53:13.0110 5856 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:53:13.0178 5856 USBSTOR - ok
13:53:13.0220 5856 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
13:53:13.0275 5856 usbuhci - ok
13:53:13.0308 5856 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
13:53:13.0389 5856 usbvideo - ok
13:53:13.0428 5856 UxSms (032a0acc3909ae7215d524e29d536797) C:\Windows\System32\uxsms.dll
13:53:13.0696 5856 UxSms - ok
13:53:13.0749 5856 vds (b13bc395b9d6116628f5af47e0802ac4) C:\Windows\System32\vds.exe
13:53:14.0037 5856 vds - ok
13:53:14.0087 5856 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
13:53:14.0167 5856 vga - ok
13:53:14.0194 5856 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
13:53:14.0275 5856 VgaSave - ok
13:53:14.0301 5856 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
13:53:14.0336 5856 viaagp - ok
13:53:14.0358 5856 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
13:53:14.0426 5856 ViaC7 - ok
13:53:14.0436 5856 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
13:53:14.0471 5856 viaide - ok
13:53:14.0497 5856 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
13:53:14.0533 5856 volmgr - ok
13:53:14.0568 5856 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys
13:53:14.0612 5856 volmgrx - ok
13:53:14.0657 5856 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys
13:53:14.0699 5856 volsnap - ok
13:53:14.0736 5856 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
13:53:14.0775 5856 vsmraid - ok
13:53:14.0869 5856 VSS (d5fb73d19c46ade183f968e13f186b23) C:\Windows\system32\vssvc.exe
13:53:15.0199 5856 VSS - ok
13:53:15.0236 5856 W32Time (1cf9206966a8458cda9a8b20df8ab7d3) C:\Windows\system32\w32time.dll
13:53:15.0503 5856 W32Time - ok
13:53:15.0564 5856 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
13:53:15.0670 5856 WacomPen - ok
13:53:15.0697 5856 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
13:53:15.0754 5856 Wanarp - ok
13:53:15.0761 5856 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
13:53:15.0818 5856 Wanarpv6 - ok
13:53:15.0881 5856 wcncsvc (f3a5c2e1a6533192b070d06ecf6be796) C:\Windows\System32\wcncsvc.dll
13:53:16.0140 5856 wcncsvc - ok
13:53:16.0172 5856 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
13:53:16.0447 5856 WcsPlugInService - ok
13:53:16.0477 5856 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
13:53:16.0512 5856 Wd - ok
13:53:16.0560 5856 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
13:53:16.0619 5856 Wdf01000 - ok
13:53:16.0662 5856 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
13:53:16.0923 5856 WdiServiceHost - ok
13:53:16.0930 5856 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
13:53:17.0145 5856 WdiSystemHost - ok
13:53:17.0218 5856 WebClient (cf9a5f41789b642db967021de06a2713) C:\Windows\System32\webclnt.dll
13:53:17.0465 5856 WebClient - ok
13:53:17.0500 5856 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
13:53:17.0760 5856 Wecsvc - ok
13:53:17.0793 5856 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
13:53:18.0031 5856 wercplsupport - ok
13:53:18.0062 5856 WerSvc (fd1965aaa112c6818a30ab02742d0461) C:\Windows\System32\WerSvc.dll
13:53:18.0328 5856 WerSvc - ok
13:53:18.0340 5856 WinHttpAutoProxySvc - ok
13:53:18.0423 5856 Winmgmt (00b79a7c984678f24cf052e5beb3a2f5) C:\Windows\system32\wbem\WMIsvc.dll
13:53:18.0616 5856 Winmgmt - ok
13:53:18.0712 5856 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
13:53:19.0066 5856 WinRM - ok
13:53:19.0142 5856 Wlansvc (275f4346e569df56cfb95243bd6f6ff0) C:\Windows\System32\wlansvc.dll
13:53:19.0430 5856 Wlansvc - ok
13:53:19.0490 5856 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
13:53:19.0545 5856 WmiAcpi - ok
13:53:19.0628 5856 wmiApSrv (aba4cf9f856d9a3a25f4ddd7690a6e9d) C:\Windows\system32\wbem\WmiApSrv.exe
13:53:19.0712 5856 wmiApSrv - ok
13:53:19.0837 5856 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
13:53:19.0923 5856 WMPNetworkSvc - ok
13:53:19.0982 5856 WPCSvc (5d94cd167751294962ba238d82dd1bb8) C:\Windows\System32\wpcsvc.dll
13:53:20.0226 5856 WPCSvc - ok
13:53:20.0242 5856 WPDBusEnum (396d406292b0cd26e3504ffe82784702) C:\Windows\system32\wpdbusenum.dll
13:53:20.0490 5856 WPDBusEnum - ok
13:53:20.0555 5856 WpdUsb (0cec23084b51b8288099eb710224e955) C:\Windows\system32\DRIVERS\wpdusb.sys
13:53:20.0626 5856 WpdUsb - ok
13:53:20.0782 5856 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:53:20.0867 5856 WPFFontCache_v0400 - ok
13:53:20.0899 5856 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
13:53:20.0978 5856 ws2ifsl - ok
13:53:20.0987 5856 WSearch - ok
13:53:21.0136 5856 wuauserv (6298277b73c77fa99106b271a7525163) C:\Windows\system32\wuaueng.dll
13:53:21.0487 5856 wuauserv - ok
13:53:21.0632 5856 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:53:21.0712 5856 WUDFRd - ok
13:53:21.0750 5856 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
13:53:22.0025 5856 wudfsvc - ok
13:53:22.0088 5856 yukonwlh (7d1f3b131d503ef43ee594b5a2b9b427) C:\Windows\system32\DRIVERS\yk60x86.sys
13:53:22.0197 5856 yukonwlh - ok
13:53:22.0235 5856 MBR (0x1B8) (64b1e91c5c6c2157642651010728f90f) \Device\Harddisk0\DR0
13:53:22.0931 5856 \Device\Harddisk0\DR0 - ok
13:53:22.0939 5856 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk1\DR1
13:53:23.0086 5856 \Device\Harddisk1\DR1 - ok
13:53:23.0117 5856 Boot (0x1200) (123ecb40ed7b69c51798a050b37e1fea) \Device\Harddisk0\DR0\Partition0
13:53:23.0120 5856 \Device\Harddisk0\DR0\Partition0 - ok
13:53:23.0143 5856 Boot (0x1200) (aeb9cf77a222b33e80cb45121da3e7b6) \Device\Harddisk0\DR0\Partition1
13:53:23.0145 5856 \Device\Harddisk0\DR0\Partition1 - ok
13:53:23.0153 5856 Boot (0x1200) (df25fb5d0d9cd16112c6d9b67fc3e0cc) \Device\Harddisk1\DR1\Partition0
13:53:23.0155 5856 \Device\Harddisk1\DR1\Partition0 - ok
13:53:23.0157 5856 ============================================================
13:53:23.0157 5856 Scan finished
13:53:23.0157 5856 ============================================================
13:53:23.0217 5724 Detected object count: 8
13:53:23.0217 5724 Actual detected object count: 8
13:54:50.0647 5724 ADSMService ( UnsignedFile.Multi.Generic ) - skipped by user
13:54:50.0647 5724 ADSMService ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:54:50.0651 5724 ASLDRService ( UnsignedFile.Multi.Generic ) - skipped by user
13:54:50.0651 5724 ASLDRService ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:54:50.0654 5724 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - skipped by user
13:54:50.0654 5724 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:54:50.0658 5724 Axtmvflt ( UnsignedFile.Multi.Generic ) - skipped by user
13:54:50.0658 5724 Axtmvflt ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:54:50.0661 5724 Axtmvmdm ( UnsignedFile.Multi.Generic ) - skipped by user
13:54:50.0661 5724 Axtmvmdm ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:54:50.0665 5724 Axtmvprt ( UnsignedFile.Multi.Generic ) - skipped by user
13:54:50.0665 5724 Axtmvprt ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:54:50.0668 5724 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
13:54:50.0668 5724 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:54:50.0672 5724 LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
13:54:50.0672 5724 LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#6 Příspěvek od vyosek »

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
Taller
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 04 čer 2012 11:08
Bydliště: Brandýs nad Labem Stará Boleslav

Re: Prosím o kontrolu logu

#7 Příspěvek od Taller »

Byl to opravdu dlouhý proces.................................................
ComboFix 12-06-03.05 - zip 04.06.2012 14:48:42.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.1132 [GMT 2:00]
Spuštěný z: c:\users\zip\Desktop\VIRY\ComboFix.exe
AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: ESET Smart Security 5.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: ESET Smart Security 5.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\etc\hosts.ics
.
Nakažená kopie c:\windows\system32\services.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-05-04 do 2012-06-04 )))))))))))))))))))))))))))))))
.
.
2012-06-04 13:24 . 2012-06-04 13:29 -------- d-----w- c:\users\zip\AppData\Local\temp
2012-06-04 13:24 . 2012-06-04 13:24 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-04 09:56 . 2012-06-04 09:56 -------- d-----w- c:\program files\trend micro
2012-06-04 09:56 . 2012-06-04 09:56 -------- d-----w- C:\rsit
2012-06-03 16:18 . 2012-06-03 16:18 -------- d-----w- c:\users\zip\AppData\Local\ESET
2012-06-03 11:40 . 2012-06-03 16:14 -------- d-----w- c:\users\zip\{2c65a960-656f-4490-92ff-22f5e742d8a8}
2012-06-03 10:02 . 2012-06-04 09:28 -------- d-----w- c:\program files\ESET
2012-06-03 04:59 . 2012-03-06 23:03 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-06-03 04:59 . 2012-03-06 23:01 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-06-03 04:59 . 2012-03-06 23:04 112984 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-06-03 04:57 . 2012-03-06 23:03 196440 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-06-03 04:57 . 2012-03-06 23:02 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-06-03 04:57 . 2012-03-06 23:01 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-06-03 04:57 . 2012-03-06 23:03 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-06-03 04:57 . 2012-03-06 23:02 24408 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-06-03 04:57 . 2012-03-06 23:01 57688 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-06-03 04:56 . 2012-03-06 22:44 12112 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-06-03 04:56 . 2012-03-06 23:15 41184 ----a-w- c:\windows\avastSS.scr
2012-06-03 04:56 . 2012-03-06 23:15 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-06-03 04:55 . 2012-06-03 04:55 -------- d-----w- c:\programdata\AVAST Software
2012-06-03 04:55 . 2012-06-03 04:55 -------- d-----w- c:\program files\AVAST Software
2012-06-03 04:53 . 2012-06-03 04:53 -------- d-----w- c:\program files\AVAST
2012-06-02 19:08 . 2012-05-08 16:40 6737808 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0C059006-4933-4BC3-A2C9-C995065119F3}\mpengine.dll
2012-05-31 07:14 . 2012-05-31 07:14 -------- d-----w- c:\users\zip\AppData\Roaming\Telefónica Móviles
2012-05-31 07:13 . 2009-12-15 12:05 23424 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2012-05-31 07:13 . 2009-12-15 12:05 112640 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2012-05-31 07:13 . 2009-12-15 12:05 102912 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2012-05-31 07:13 . 2009-12-15 12:05 101120 ----a-w- c:\windows\system32\drivers\ewusbdev.sys
2012-05-31 07:13 . 2012-06-03 16:14 -------- d-----w- c:\users\zip\{1b00ed9a-b7e2-43ce-87b3-4c6e67c836bf}
2012-05-31 07:13 . 2012-05-31 07:13 -------- d-----w- c:\program files\O2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-04 13:28 . 2008-10-22 07:12 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-03-14 06:40 . 2012-03-14 06:40 148504 ----a-w- c:\windows\system32\drivers\epfw.sys
2012-03-14 06:40 . 2012-03-14 06:40 50624 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2012-03-14 06:40 . 2012-03-14 06:40 169080 ----a-w- c:\windows\system32\drivers\eamonm.sys
2012-03-14 06:40 . 2012-03-14 06:40 120152 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2012-04-28 17:07 . 2011-05-06 19:36 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTog0.dll" [2010-02-06 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2010-02-06 14:57 2166296 ----a-w- c:\program files\ToggleEN\tbTog0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTog0.dll" [2010-02-06 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTog0.dll" [2010-02-06 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" [2009-07-18 155896]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-10-18 7737344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 4702208]
"Skytel"="Skytel.exe" [2007-10-11 1826816]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 3117344]
.
c:\users\zip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-15 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-06-04 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2009-02-25 11:11]
.
2012-03-24 c:\windows\Tasks\User_Feed_Synchronization-{678C1324-F912-4607-A2A8-A13047F27168}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: Download All by FlashGet - d:\program files\FlashGet\jc_all.htm
IE: Download using FlashGet - d:\program files\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Stáhnout pomocí FlashGet - d:\program files\FlashGet\jc_link.htm
IE: Stáhnout vše pomocí FlashGet - d:\program files\FlashGet\jc_all.htm
TCP: Interfaces\{C39AC866-A09F-437B-ADC8-2104FE03A79C}: NameServer = 160.218.167.5 160.218.161.60
FF - ProfilePath - c:\users\zip\AppData\Roaming\Mozilla\Firefox\Profiles\b5z2micc.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=39&tp=ab&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-04 15:28
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
C:\ADSM_PData_0150
.
sken byl úspešně dokončen
skryté soubory: 1
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2320)
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\AVAST Software\Avast\afwServ.exe
c:\program files\ESET\ESET Smart Security\ekrn.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\ATK Hotkey\Hcontrol.exe
c:\program files\ATK Hotkey\MsgTranAgt.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\windows\System32\ACEngSvr.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Celkový čas: 2012-06-04 15:33:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-06-04 13:33
.
Před spuštěním: Volných bajtů: 77 998 481 408
Po spuštění: Volných bajtů: 77 751 693 312
.
- - End Of File - - 770334E2D3F85838E4BCF9F602844F2B

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#8 Příspěvek od vyosek »

:arrow: Na ten ESET mate zakoupenou licenci nebo tam nechame free reseni v podobe Avastu :???:

:arrow: Delka skenu a mazani pres CF zalezi na tom jak je stroj nakazen a kolika soubory se musi pri skenu probrat
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
Taller
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 04 čer 2012 11:08
Bydliště: Brandýs nad Labem Stará Boleslav

Re: Prosím o kontrolu logu

#9 Příspěvek od Taller »

ESET byl odinstalován ale stále zůstává v počítači ??? a prosím nechame tam free reseni v podobe Avastu pokud nemáte jinou lepší variantu v českém jazyce ???

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#10 Příspěvek od vyosek »

:arrow: Avast patri asi ke spicce mezi neplacenymi antiviry s ceskym prostedim

:arrow: Odinstalujte Advanced SystemCare 5 a nasledne i vse od IOBit - jsou to cinske smejdy a spise jen skodi nez jsou uzitkem. Hledaji nesmyslne a neexistujici problemy, databazi haveti ukradli jine renomovane spolecnosti

:arrow: v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti) projedte PC temito utilitami, at se zbavime zbytku antiviru co tam mate :arrow: Znovu nainstalujte Avast Free http://www.avast.com/cs-cz/free-antivirus-download

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    
    Firefox::
    FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=39&tp=ab&q=
    FF - ProfilePath - c:\users\zip\AppData\Roaming\Mozilla\Firefox\Profiles\b5z2micc.default\
    FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
    
    DDS::
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    
    DirLook::
    c:\users\zip\{2c65a960-656f-4490-92ff-22f5e742d8a8}
    c:\users\zip\{1b00ed9a-b7e2-43ce-87b3-4c6e67c836bf}
    
    File::
    c:\program files\ToggleEN\tbTog0.dll
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{038cb5c7-48ea-4af9-94e0-a1646542e62b}"=-
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{038cb5c7-48ea-4af9-94e0-a1646542e62b}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"=-
    [-HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    "WMPNSCFG"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "SunJavaUpdateSched"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000000
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
Taller
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 04 čer 2012 11:08
Bydliště: Brandýs nad Labem Stará Boleslav

Re: Prosím o kontrolu logu

#11 Příspěvek od Taller »

Dobrý večer vše se zdařilo krom AVG http://download.avg.com/filedir/util/su ... 1_1184.exe nešlo stáhnout.Free avast mám taky nainstalovaný.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#12 Příspěvek od vyosek »

Fajn, aplikujte ten skript pro ComboFix pokud jste tam jeste neucinil a log mi sem dejte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
Taller
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 04 čer 2012 11:08
Bydliště: Brandýs nad Labem Stará Boleslav

Re: Prosím o kontrolu logu

#13 Příspěvek od Taller »

Tak se omlouvám ale padá připojení nejde prohlížeč dlouhá doba než PC provede úkon atd.vše začalo po nainstalování antiviru.Píšu z druhého počítače až bude vše v pořádku vložím vám ten script díky za trpělivost...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#14 Příspěvek od vyosek »

Pripadne skript aplikujte v nouzovem rezimu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
Taller
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 04 čer 2012 11:08
Bydliště: Brandýs nad Labem Stará Boleslav

Re: Prosím o kontrolu logu

#15 Příspěvek od Taller »

ComboFix 12-06-03.05 - zip 05.06.2012 21:38:02.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2038.1267 [GMT 2:00]
Spuštěný z: c:\users\zip\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-05-05 do 2012-06-05 )))))))))))))))))))))))))))))))
.
.
2012-06-05 20:02 . 2012-06-05 20:03 -------- d-----w- c:\users\zip\AppData\Local\temp
2012-06-05 20:02 . 2012-06-05 20:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-04 14:41 . 2012-06-04 14:41 -------- d-----w- c:\windows\system32\ca-ES
2012-06-04 14:41 . 2012-06-04 14:41 -------- d-----w- c:\windows\system32\eu-ES
2012-06-04 14:41 . 2012-06-04 14:41 -------- d-----w- c:\windows\system32\vi-VN
2012-06-04 13:58 . 2012-06-04 13:58 -------- d-----w- c:\windows\system32\EventProviders
2012-06-04 09:56 . 2012-06-04 09:56 -------- d-----w- c:\program files\trend micro
2012-06-04 09:56 . 2012-06-04 09:56 -------- d-----w- C:\rsit
2012-06-03 16:18 . 2012-06-03 16:18 -------- d-----w- c:\users\zip\AppData\Local\ESET
2012-06-03 11:40 . 2012-06-03 16:14 -------- d-----w- c:\users\zip\{2c65a960-656f-4490-92ff-22f5e742d8a8}
2012-06-03 04:56 . 2012-03-06 23:15 41184 ----a-w- c:\windows\avastSS.scr
2012-06-03 04:55 . 2012-06-05 18:27 -------- d-----w- c:\programdata\AVAST Software
2012-06-03 04:55 . 2012-06-05 18:27 -------- d-----w- c:\program files\AVAST Software
2012-06-03 04:53 . 2012-06-03 04:53 -------- d-----w- c:\program files\AVAST
2012-06-02 19:08 . 2012-05-08 16:40 6737808 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0C059006-4933-4BC3-A2C9-C995065119F3}\mpengine.dll
2012-05-31 07:14 . 2012-05-31 07:14 -------- d-----w- c:\users\zip\AppData\Roaming\Telefónica Móviles
2012-05-31 07:13 . 2009-12-15 12:05 23424 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2012-05-31 07:13 . 2009-12-15 12:05 112640 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2012-05-31 07:13 . 2009-12-15 12:05 102912 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2012-05-31 07:13 . 2009-12-15 12:05 101120 ----a-w- c:\windows\system32\drivers\ewusbdev.sys
2012-05-31 07:13 . 2012-06-03 16:14 -------- d-----w- c:\users\zip\{1b00ed9a-b7e2-43ce-87b3-4c6e67c836bf}
2012-05-31 07:13 . 2012-06-05 19:20 -------- d-----w- c:\program files\O2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-05 19:24 . 2008-10-22 07:12 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-04-21 01:18 . 2012-06-05 15:17 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTog0.dll" [2010-02-06 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2010-02-06 14:57 2166296 ----a-w- c:\program files\ToggleEN\tbTog0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTog0.dll" [2010-02-06 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTog0.dll" [2010-02-06 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" [2009-07-18 155896]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-10-18 7737344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 4702208]
"Skytel"="Skytel.exe" [2007-10-11 1826816]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\users\zip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-15 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-03-24 c:\windows\Tasks\User_Feed_Synchronization-{678C1324-F912-4607-A2A8-A13047F27168}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: Download All by FlashGet - d:\program files\FlashGet\jc_all.htm
IE: Download using FlashGet - d:\program files\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Stáhnout pomocí FlashGet - d:\program files\FlashGet\jc_link.htm
IE: Stáhnout vše pomocí FlashGet - d:\program files\FlashGet\jc_all.htm
TCP: Interfaces\{C39AC866-A09F-437B-ADC8-2104FE03A79C}: NameServer = 160.218.167.5 160.218.161.60
FF - ProfilePath - c:\users\zip\AppData\Roaming\Mozilla\Firefox\Profiles\smgelg12.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-05 22:03
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2012-06-05 22:06:40
ComboFix-quarantined-files.txt 2012-06-05 20:06
.
Před spuštěním: Volných bajtů: 91 333 058 560
Po spuštění: Volných bajtů: 91 395 686 400
.
- - End Of File - - 9BD05E2F6FF3EA61CBCEF9DCE443AE19

Odpovědět