• Ogłoszenie:

Otwieranie programu za pomoca

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Otwieranie programu za pomoca

Postprzez jacekk04 18 Cze 2011, 00:54

reklama
Problem polega na tym ze gdy chce otworzyc jakis program to wyskakuje okna „Otwieranie za pomocą”
Wiekszosc istotnych programow nie chce się otworzyc np. antywirus w tym wypadku avast, przegladarka w tym wypadku firefox
Zaczelo się to od tego ze Windows wykryl kolo 30 wirusow w tym jakies trojany, po czym zrobiłem przywracanie systemu i teraz nie chca się otwierac programy, nie mogę ingerowac w głośność ani nie mogę zmienic godziny, wogole nie reaguje na klikniecia, gmer nie chce się otworzyc zrobilem tez logi z Silent Runners i HijackThis. Nie mogę w panelu sterowania wybrac opcji „dodaj lub usun programy”. Nie ma mowy o formacie dysku C bo nie mam na plytce windy a w dodatku nie ma mnie w kraju.
O to jakie obrazki sie pojawiaja

Image
Image
Image
Image
Image
Oto logi
http://wklej.org/id/548341/
http://wklej.org/id/548342/


Kod: Zaznacz wszystko
"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINNT\system32\ctfmon.exe" [MS]
"DAEMON Tools Lite" = ""C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun" ["DT Soft Ltd"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"IgfxTray" = "C:\WINNT\system32\igfxtray.exe" ["Intel Corporation"]
"HotKeysCmds" = "C:\WINNT\system32\hkcmd.exe" ["Intel Corporation"]
"Persistence" = "C:\WINNT\system32\igfxpers.exe" ["Intel Corporation"]
"RTHDCPL" = "RTHDCPL.EXE" ["Realtek Semiconductor Corp."]
"SkyTel" = "SkyTel.EXE" ["Realtek Semiconductor Corp."]
"Alcmtr" = "ALCMTR.EXE" ["Realtek Semiconductor Corp."]
"SmcService" = "C:\PROGRA~1\Sygate\SPF\smc.exe -startgui" ["Sygate Technologies, Inc."]
"UnlockerAssistant" = ""C:\Program Files\Unlocker\UnlockerAssistant.exe"" [null data]
"Adobe Reader Speed Launcher" = ""C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"" ["Adobe Systems Incorporated"]
"Adobe ARM" = ""C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"" ["Adobe Systems Incorporated"]
"GrooveMonitor" = ""C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"" [MS]
"WinampAgent" = ""C:\Program Files\Winamp\winampa.exe"" [null data]
"avast5" = ""C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui" ["AVAST Software"]
"NeroFilterCheck" = "C:\WINNT\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"SunJavaUpdateSched" = ""C:\Program Files\Common Files\Java\Java Update\jusched.exe"" ["Sun Microsystems, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\(Default) = "AcroIEHelperStub"
  -> {HKLM...CLSID} = "Adobe PDF Link Helper"
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll" ["Adobe Systems Incorporated"]
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "Groove GFS Browser Helper"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "Java(tm) Plug-In 2 SSV Helper"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre6\bin\jp2ssv.dll" ["Sun Microsystems, Inc."]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\(Default) = "JQSIEStartDetectorImpl"
  -> {HKLM...CLSID} = "JQSIEStartDetectorImpl Class"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll" ["Sun Microsystems, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyœwietlania"
  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyœwietlania"
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                   \InProcServer32\(Default) = "C:\WINNT\system32\hticons.dll" ["Hilgraeve, Inc."]
"{3028902F-6374-48b2-8DC6-9725E775B926}" = "IE Microsoft AutoComplete"
  -> {HKLM...CLSID} = "IE Microsoft AutoComplete"
                   \InProcServer32\(Default) = "C:\WINNT\system32\browseui.dll" [MS]
"{EFA24E62-B078-11d0-89E4-00C04FC9E26E}" = "History Band"
  -> {HKLM...CLSID} = "History Band"
                   \InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"
  -> {HKLM...CLSID} = "UnlockerShellExtension"
                   \InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}" = "Groove GFS Browser Helper"
  -> {HKLM...CLSID} = "Groove GFS Browser Helper"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}" = "Groove GFS Explorer Bar"
  -> {HKLM...CLSID} = "Groove Folder Synchronization"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{A449600E-1DC6-4232-B948-9BD794D62056}" = "Groove GFS Stub Icon Handler"
  -> {HKLM...CLSID} = "Groove GFS Stub Icon Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
  -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{6C467336-8281-4E60-8204-430CED96822D}" = "Groove GFS Context Menu Handler"
  -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{387E725D-DC16-4D76-B310-2C93ED4752A0}" = "Groove XML Icon Handler"
  -> {HKLM...CLSID} = "Groove XML Icon Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{16F3DD56-1AF5-4347-846D-7C10C4192619}" = "Groove Explorer Icon Overlay 3 (GFS Folder)"
  -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}" = "Groove Explorer Icon Overlay 2 (GFS Stub)"
  -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}" = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
  -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{99FD978C-D287-4F50-827F-B2C658EDA8E7}" = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
  -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{920E6DB1-9907-4370-B3A0-BAFC03D81399}" = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
  -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
  -> {HKLM...CLSID} = "Outlook File Icon Extension"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\OLKFSTUB.DLL" [MS]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
  -> {HKLM...CLSID} = "Microsoft Office Outlook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\MLSHEXT.DLL" [MS]
"{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}" = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"
  -> {HKLM...CLSID} = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\ONFILTER.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]
"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"
  -> {HKLM...CLSID} = "Microsoft Office Metadata Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"
  -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
  -> {HKLM...CLSID} = "avast"
                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
  -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
  -> {HKLM...CLSID} = "WPDShServiceObj Class"
                   \InProcServer32\(Default) = "C:\WINNT\system32\WPDShServiceObj.dll" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> igfxcui\DLLName = "igfxdev.dll" ["Intel Corporation"]

HKLM\Software\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"
  -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"
                   \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
  -> {HKLM...CLSID} = "PDF Shell Extension"
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
  -> {HKLM...CLSID} = "avast"
                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
  -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
  -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
  -> {HKLM...CLSID} = "avast"
                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
  -> {HKLM...CLSID} = "UnlockerShellExtension"
                   \InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
  -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]

HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
00avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
  -> {HKLM...CLSID} = "avast"
                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
  -> {HKLM...CLSID} = "UnlockerShellExtension"
                   \InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
  -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]


Default executables:
--------------------

HKCU\Software\Classes\.exe\(Default) = "exefile"
<<!>> HKCU\Software\Classes\.exe\shell\open\command\(Default) = ""C:\Documents and Settings\Jacek\Ustawienia lokalne\Dane aplikacji\acq.exe" -a "%1" %*" [file not found]
<<!>> HKCU\Software\Classes\exefile\shell\open\command\(Default) = ""C:\Documents and Settings\Jacek\Ustawienia lokalne\Dane aplikacji\acq.exe" -a "%1" %*" [file not found]


Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINNT\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Jacek\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINNT\system32\logon.scr" [MS]


Startup items in "Jacek" & "All Users" startup folders:
-------------------------------------------------------

C:\Documents and Settings\Jacek\Menu Start\Programy\Autostart
"Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007" -> shortcut to: "C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE /tsr" [MS]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 13
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Explorer Bars

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

HKLM\Software\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = "Groove Folder Synchronization"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL" [MS]

HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Poszukaj"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL" [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{2670000A-7350-4F3C-8081-5663EE0C6C49}\
"ButtonText" = "Wyœlij do programu OneNote"
"MenuText" = "Wyœlij &do programu OneNote"
"CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"
  -> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll" [MS]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "Research"

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Agere Modem Call Progress Audio, AgereModemAudio, "C:\WINNT\system32\agrsmsvc.exe" ["Agere Systems"]
avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"" ["AVAST Software"]
Java Quick Starter, JavaQuickStarterService, ""C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"" ["Sun Microsystems, Inc."]
Karta wydajnoœci WMI, WmiApSrv, "C:\WINNT\system32\wbem\wmiapsrv.exe" [MS]
Sygate Personal Firewall, SmcService, "C:\Program Files\Sygate\SPF\smc.exe" ["Sygate Technologies, Inc."]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS]


----------
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
  DLL launch points, use the -supp parameter or answer "No" at the
  first message box and "Yes" at the second message box.
---------- (total run time: 46 seconds, including 2 seconds for message boxes)



Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 21:56:42, on 2011-06-16
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\agrsmsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\system32\wbem\wmiapsrv.exe
C:\Program Files\Winamp\winamp.exe
C:\WINNT\system32\mspaint.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
E:\PROGRAMY\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vshare.toolbarhome.com/?hp=df
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = £¹cza
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyœlij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyœlij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINNT\system32\WPDShServiceObj.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINNT\system32\agrsmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Awatar użytkownika
jacekk04
~user
 
Posty: 861
Dołączenie: 05 Paź 2005, 20:02
Miejscowość: Radzyń Podlaski
Pochwały: 5



Otwieranie programu za pomoca

Postprzez wojtas 18 Cze 2011, 19:19

Uruchom OTL i w sekcji własne opcje skanowania / skrypt wklej:

:OTL
IE - HKU\S-1-5-21-527237240-2025429265-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://vshare.toolbarhome.com/?hp=df
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..keyword.URL: "http://vshare.toolbarhome.com/search.aspx?srch=ku&q="
[2011-02-12 20:45:47 | 000,000,000 | ---D | M] (vShare) -- C:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\Firefox\Profiles\tbxrqr7a.default\extensions\vshare@toolbar
O35 - HKU\S-1-5-21-527237240-2025429265-682003330-1003..exefile [open] -- "C:\Documents and Settings\Jacek\Ustawienia lokalne\Dane aplikacji\acq.exe" -a "%1" %*
O37 - HKU\S-1-5-21-527237240-2025429265-682003330-1003\...exe [@ = exefile] -- "C:\Documents and Settings\Jacek\Ustawienia lokalne\Dane aplikacji\acq.exe" -a "%1" %*
[2011-06-16 07:24:23 | 000,000,000 | -HSD | C] -- C:\!KillBox
[2011-06-16 06:55:32 | 000,013,218 | -HS- | M] () -- C:\Documents and Settings\Jacek\Ustawienia lokalne\Dane aplikacji\g5m6ob75g5s1l11u55n4i
[2011-06-16 06:55:32 | 000,013,218 | -HS- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\g5m6ob75g5s1l11u55n4i

:Commands
[emptytemp]
[emptyflash]



Kliknij wykonaj skrypt. I potwierdź reset komputera .

Następnie uruchamiasz OTL z opcją skanuj. Pokazujesz nowy log OTL.txt oraz raport z czyszczenia (zawartość notatnika, która otworzy się po restarcie). + Gmer

daj log z Ad Remover ( opcja Skan )
wykonaj skan: Kaspersky TDSSKiller, jeśli coś znajdzie dajesz Skip.

czyli raport z OTL , nowy OTL , Gmer , Ad Remover i TDSSKiller :)
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Otwieranie programu za pomoca

Postprzez jacekk04 20 Cze 2011, 20:33

http://wklej.org/id/549867/
http://wklej.org/id/549871/
Kod: Zaznacz wszystko
======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 =======

Updated by TeamXscript on 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
website: http://www.teamxscript.org

C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 03:46:59 on 20/06/2011, Normal boot

Microsoft Windows XP Professional Dodatek Service Pack 2 (X86)
Jacek@JACEK-C8FCDEB47 ( )

============== SEARCH ==============


File found: C:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\FireFox\Profiles\tbxrqr7a.default\searchplugins\web-search.xml
Folder found: C:\Documents and Settings\Jacek\Dane aplikacji\DesktopIcon

-- File opened: C:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\FireFox\Profiles\tbxrqr7a.default\Prefs.js --
Line found: user_pref("extensions.enabledAddons", "vshare@toolbar:1.0.0,{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}:5...
Line found: user_pref("extensions.enabledItems", "{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}:5.0.14,vshare@toolbar:1...
Line found: user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"jqs@sun.com\":{...
Line found: user_pref("extensions.vshare@toolbar.update.enabled", false);
Line found: user_pref("vshare.install.date", "1297468800000");
Line found: user_pref("vshare.install.dumpFileCount", 0);
Line found: user_pref("vshare.install.dumpFileDisabled", false);
Line found: user_pref("vshare.install.finished", "1.0.0");
Line found: user_pref("vshare.install.guid", "{870f303f-afde-4937-b587-265f021878c6}");
Line found: user_pref("vshare.install.isHidden", true);
Line found: user_pref("vshare.install.istoolbarhp", true);
Line found: user_pref("vshare.install.istoolbarsearch", true);
Line found: user_pref("vshare.install.laststatreq", "1308182400000");
Line found: user_pref("vshare.install.newtab", true);
Line found: user_pref("vshare.install.overlayVersion", 1);
Line found: user_pref("vshare.install.userHPSettings", "hxxp://www.wykop.pl/");
Line found: user_pref("vshare.install.userSPSettings", "Google");
-- File closed --




============== ADDITIONNAL SCAN ==============

**** Mozilla Firefox Version [4.0.1 (pl)] ****

Searchplugins\allegro-pl.xml (hxxp://www.allegro.pl/search.php?string={searchTerms}&amp;sourceid=Mozilla-search)
Searchplugins\fbc-pl.xml (hxxp://fbc.pionier.net.pl/owoc/results)
Searchplugins\merlin-pl.xml (hxxp://www.merlin.com.pl/frontend/search?sourceid=Mozilla-search&amp;fraza={searchTerms}&amp;skad=crhhxmkohb)
Searchplugins\pwn-pl.xml (hxxp://encyklopedia.pwn.pl/szukaj.php?co={searchTerms})
Searchplugins\wikipedia-pl.xml (hxxp://pl.wikipedia.org/wiki/Specjalna:Szukaj)
Searchplugins\wp-pl.xml (hxxp://szukaj.wp.pl/szukaj.html?z=T&amp;r=T&amp;szukaj={searchTerms})
Components\browsercomps.dll (Mozilla Foundation)
Extensions\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA} (Java Console)

-- C:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\FireFox\Profiles\tbxrqr7a.default --
Searchplugins\web-search.xml (?)
Prefs.js - browser.download.lastDir, D:
Prefs.js - browser.search.defaultenginename,
Prefs.js - browser.search.selectedEngine, Google
Prefs.js - browser.startup.homepage, hxxp://www.wykop.pl/
Prefs.js - browser.startup.homepage_override.buildID, 20110413222027
Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1

========================================

**** Internet Explorer Version [6.0.2900.2180] ****

HKCU_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

========================================

C:\Program Files\Ad-Remover\Quarantine: 0 File(s)
C:\Program Files\Ad-Remover\Backup: 1 File(s)

C:\Ad-Report-SCAN[1].txt - 20/06/2011 03:47:09 (4006 Byte(s))

End at: 03:47:38, 20/06/2011

============== E.O.F ==============


Kod: Zaznacz wszystko
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2011-06-20 03:46:26
Windows 5.1.2600 Dodatek Service Pack 2


---- System - GMER 1.0.13 ----

SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS                      ZwEnumerateKey
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS                      ZwEnumerateValueKey

Code            \SystemRoot\System32\Drivers\aswSP.SYS                       ZwCreateProcessEx
Code            \SystemRoot\System32\Drivers\aswSP.SYS                       ObInsertObject
Code            \SystemRoot\System32\Drivers\aswSP.SYS                       ObMakeTemporaryObject

---- Devices - GMER 1.0.13 ----

Device          \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE                         [A3E663F2] aswSP.SYS
Device          \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE                          [A3E66432] aswSP.SYS
Device          \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE                          [A3E6650E] aswSP.SYS
Device          \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION                [A3E6654E] aswSP.SYS
Device          \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP                        [A3E664A0] aswSP.SYS

AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE                         [F731CF70] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE              [F731CF70] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE                          [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_READ                           [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE                          [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION              [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION                [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA                       [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA                         [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS                  [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION       [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION         [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL              [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL            [F731D160] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL                 [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL        [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN                       [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL                   [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP                        [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT                [F731CF70] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY                 [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY                   [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_POWER                          [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL                 [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE                  [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA                    [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA                      [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE                         [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE              [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE                          [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_READ                           [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE                          [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION              [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION                [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA                       [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA                         [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS                  [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION       [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION         [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL              [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL            [A3D04092] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL                 [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL        [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN                       [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL                   [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP                        [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT                [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY                 [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY                   [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_POWER                          [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL                 [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE                  [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA                    [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA                      [A3D02A08] aswMon2.SYS

Device          \FileSystem\Fastfat \Fat IRP_MJ_CREATE                       [A3E6658E] aswSP.SYS
Device          \FileSystem\Fastfat \Fat IRP_MJ_CLOSE                        [A3E665CE] aswSP.SYS
Device          \FileSystem\Fastfat \Fat IRP_MJ_WRITE                        [A3E666AA] aswSP.SYS
Device          \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION              [A3E666EA] aswSP.SYS
Device          \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP                      [A3E6663C] aswSP.SYS

AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CREATE                       [F731CF70] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE            [F731CF70] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CLOSE                        [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_READ                         [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_WRITE                        [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION            [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION              [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA                     [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_EA                       [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS                [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION     [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION       [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL            [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL          [F731D160] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL               [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL      [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN                     [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL                 [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP                      [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT              [F731CF70] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY               [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY                 [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_POWER                        [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL               [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE                [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA                  [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA                    [F7310F08] fltMgr.sys
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CREATE                       [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE            [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CLOSE                        [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_READ                         [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_WRITE                        [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION            [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION              [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA                     [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_EA                       [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS                [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION     [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION       [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL            [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL          [A3D04092] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL               [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL      [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN                     [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL                 [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP                      [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT              [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY               [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY                 [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_POWER                        [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL               [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE                [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA                  [A3D02A08] aswMon2.SYS
AttachedDevice  \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA                    [A3D02A08] aswMon2.SYS

Device          \Driver\Tcpip \Device\Ip IRP_MJ_CREATE                       [A5398220] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE                        [A5398480] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL               [A53985A0] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL      [A53985D0] wpsdrvnt.sys

AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_CREATE                       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE            [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE                        [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_READ                         [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_WRITE                        [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION            [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA                     [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA                       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS                [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION     [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL            [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL          [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL               [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL      [A4F6C8E0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN                     [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL                 [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP                      [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY               [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY                 [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_POWER                        [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL               [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE                [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA                  [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA                    [A4F6CDB0] aswTdi.SYS

Device          \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE                      [A5398220] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE                       [A5398480] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL              [A53985A0] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL     [A53985D0] wpsdrvnt.sys

AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE                      [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE           [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE                       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_READ                        [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE                       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION           [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION             [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA                    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA                      [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS               [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION      [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL           [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL         [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL     [A4F6C8E0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN                    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL                [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP                     [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT             [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY                [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_POWER                       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE               [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA                 [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA                   [A4F6CDB0] aswTdi.SYS

Device          \Driver\Tcpip \Device\Udp IRP_MJ_CREATE                      [A5398220] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE                       [A5398480] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL              [A53985A0] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL     [A53985D0] wpsdrvnt.sys

AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_CREATE                      [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE           [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE                       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_READ                        [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_WRITE                       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION           [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION             [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA                    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA                      [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS               [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION      [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL           [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL         [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL     [A4F6C8E0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN                    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL                [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP                     [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT             [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY                [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_POWER                       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE               [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA                 [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA                   [A4F6CDB0] aswTdi.SYS

Device          \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE                    [A5398220] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE                     [A5398480] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL            [A53985A0] wpsdrvnt.sys
Device          \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL   [A53985D0] wpsdrvnt.sys

AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE                    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE         [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE                     [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_READ                      [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE                     [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION         [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION           [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA                  [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA                    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS             [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION  [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION    [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL         [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL       [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL            [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL   [A4F6C8E0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN                  [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP                   [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT           [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY            [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY              [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_POWER                     [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL            [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE             [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA               [A4F6CDB0] aswTdi.SYS
AttachedDevice  \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA                 [A4F6CDB0] aswTdi.SYS

---- EOF - GMER 1.0.13 ----




Kod: Zaznacz wszystko
2011/06/20 21:48:41.0031 3444   TDSS rootkit removing tool 2.5.5.0 Jun 16 2011 15:25:15
2011/06/20 21:48:41.0046 3444   ================================================================================
2011/06/20 21:48:41.0046 3444   SystemInfo:
2011/06/20 21:48:41.0046 3444   
2011/06/20 21:48:41.0046 3444   OS Version: 5.1.2600 ServicePack: 2.0
2011/06/20 21:48:41.0046 3444   Product type: Workstation
2011/06/20 21:48:41.0046 3444   ComputerName: JACEK-C8FCDEB47
2011/06/20 21:48:41.0062 3444   UserName: Jacek
2011/06/20 21:48:41.0062 3444   Windows directory: C:\WINNT
2011/06/20 21:48:41.0062 3444   System windows directory: C:\WINNT
2011/06/20 21:48:41.0062 3444   Processor architecture: Intel x86
2011/06/20 21:48:41.0062 3444   Number of processors: 2
2011/06/20 21:48:41.0062 3444   Page size: 0x1000
2011/06/20 21:48:41.0062 3444   Boot type: Normal boot
2011/06/20 21:48:41.0062 3444   ================================================================================
2011/06/20 21:48:41.0812 3444   Initialize success
2011/06/20 21:48:53.0250 3512   ================================================================================
2011/06/20 21:48:53.0250 3512   Scan started
2011/06/20 21:48:53.0250 3512   Mode: Manual;
2011/06/20 21:48:53.0250 3512   ================================================================================
2011/06/20 21:48:53.0609 3512   Aavmker4        (3f6884eff406238d39aaa892218f1df7) C:\WINNT\system32\drivers\Aavmker4.sys
2011/06/20 21:48:53.0703 3512   ACPI            (a966410ecf83b81f3b0b8e07a71957d4) C:\WINNT\system32\DRIVERS\ACPI.sys
2011/06/20 21:48:53.0750 3512   ACPIEC          (66a42b7db194e24b973bbcce840a0f3f) C:\WINNT\system32\DRIVERS\ACPIEC.sys
2011/06/20 21:48:53.0828 3512   aec             (1ee7b434ba961ef845de136224c30fec) C:\WINNT\system32\drivers\aec.sys
2011/06/20 21:48:53.0875 3512   AFD             (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINNT\System32\drivers\afd.sys
2011/06/20 21:48:54.0046 3512   AgereSoftModem  (ce91b158fa490cf4c4d487a4130f4660) C:\WINNT\system32\DRIVERS\AGRSM.sys
2011/06/20 21:48:54.0312 3512   aswFsBlk        (7f08d9c504b015d81a8abd75c80028c5) C:\WINNT\system32\drivers\aswFsBlk.sys
2011/06/20 21:48:54.0390 3512   aswMon2         (c2181ef6b54752273a0759a968c59279) C:\WINNT\system32\drivers\aswMon2.sys
2011/06/20 21:48:54.0421 3512   aswRdr          (ac48bdd4cd5d44af33087c06d6e9511c) C:\WINNT\system32\drivers\aswRdr.sys
2011/06/20 21:48:54.0484 3512   aswSnx          (b64134316fcd1f20e0f10ef3e65bd522) C:\WINNT\system32\drivers\aswSnx.sys
2011/06/20 21:48:54.0562 3512   aswSP           (d6788e3211afa9951ed7a4d617f68a4f) C:\WINNT\system32\drivers\aswSP.sys
2011/06/20 21:48:54.0609 3512   aswTdi          (4d100c45517809439c7b6dd98997fa00) C:\WINNT\system32\drivers\aswTdi.sys
2011/06/20 21:48:54.0656 3512   AsyncMac        (02000abf34af4c218c35d257024807d6) C:\WINNT\system32\DRIVERS\asyncmac.sys
2011/06/20 21:48:54.0703 3512   atapi           (cdfe4411a69c224bd1d11b2da92dac51) C:\WINNT\system32\DRIVERS\atapi.sys
2011/06/20 21:48:54.0796 3512   Atmarpc         (ec88da854ab7d7752ec8be11a741bb7f) C:\WINNT\system32\DRIVERS\atmarpc.sys
2011/06/20 21:48:54.0828 3512   audstub         (d9f724aa26c010a217c97606b160ed68) C:\WINNT\system32\DRIVERS\audstub.sys
2011/06/20 21:48:54.0875 3512   Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINNT\system32\drivers\Beep.sys
2011/06/20 21:48:54.0921 3512   cbidf2k         (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINNT\system32\drivers\cbidf2k.sys
2011/06/20 21:48:54.0968 3512   Cdaudio         (c1b486a7658353d33a10cc15211a873b) C:\WINNT\system32\drivers\Cdaudio.sys
2011/06/20 21:48:55.0015 3512   Cdfs            (cd7d5152df32b47f4e36f710b35aae02) C:\WINNT\system32\drivers\Cdfs.sys
2011/06/20 21:48:55.0062 3512   Cdrom           (af9c19b3100fe010496b1a27181fbf72) C:\WINNT\system32\DRIVERS\cdrom.sys
2011/06/20 21:48:55.0125 3512   CmBatt          (4266be808f85826aedf3c64c1e240203) C:\WINNT\system32\DRIVERS\CmBatt.sys
2011/06/20 21:48:55.0203 3512   Compbatt        (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINNT\system32\DRIVERS\compbatt.sys
2011/06/20 21:48:55.0343 3512   Disk            (00ca44e4534865f8a3b64f7c0984bff0) C:\WINNT\system32\DRIVERS\disk.sys
2011/06/20 21:48:55.0421 3512   dmboot          (3b809ffad55dcebdb156d5ca1bd3da65) C:\WINNT\system32\drivers\dmboot.sys
2011/06/20 21:48:55.0515 3512   dmio            (27725b6501201c3080ba73048bce389a) C:\WINNT\system32\drivers\dmio.sys
2011/06/20 21:48:55.0578 3512   dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINNT\system32\drivers\dmload.sys
2011/06/20 21:48:55.0625 3512   DMusic          (a6f881284ac1150e37d9ae47ff601267) C:\WINNT\system32\drivers\DMusic.sys
2011/06/20 21:48:55.0734 3512   drmkaud         (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINNT\system32\drivers\drmkaud.sys
2011/06/20 21:48:55.0812 3512   Fastfat         (3117f595e9615e04f05a54fc15a03b20) C:\WINNT\system32\drivers\Fastfat.sys
2011/06/20 21:48:55.0875 3512   Fdc             (ced2e8396a8838e59d8fd529c680e02c) C:\WINNT\system32\drivers\Fdc.sys
2011/06/20 21:48:55.0906 3512   Fips            (c5fb298257c0a6514ea17835e774ea0a) C:\WINNT\system32\drivers\Fips.sys
2011/06/20 21:48:55.0984 3512   Flpydisk        (0dd1de43115b93f4d85e889d7a86f548) C:\WINNT\system32\drivers\Flpydisk.sys
2011/06/20 21:48:56.0046 3512   FltMgr          (157754f0df355a9e0a6f54721914f9c6) C:\WINNT\system32\DRIVERS\fltMgr.sys
2011/06/20 21:48:56.0078 3512   Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINNT\system32\drivers\Fs_Rec.sys
2011/06/20 21:48:56.0109 3512   Ftdisk          (ed6d921d8ab423138fb35beee6d6a6cb) C:\WINNT\system32\DRIVERS\ftdisk.sys
2011/06/20 21:48:56.0156 3512   gmer            (35b24c17f8aea65cabc4a4e63e88ac45) C:\WINNT\system32\DRIVERS\gmer.sys
2011/06/20 21:48:56.0218 3512   Gpc             (c0f1d4a21de5a415df8170616703debf) C:\WINNT\system32\DRIVERS\msgpc.sys
2011/06/20 21:48:56.0328 3512   HDAudBus        (3fcc124b6e08ee0e9351f717dd136939) C:\WINNT\system32\DRIVERS\HDAudBus.sys
2011/06/20 21:48:56.0500 3512   hidusb          (1de6783b918f540149aa69943bdfeba8) C:\WINNT\system32\DRIVERS\hidusb.sys
2011/06/20 21:48:56.0578 3512   HTTP            (3247a2db333d1521680e6864a8295a47) C:\WINNT\system32\Drivers\HTTP.sys
2011/06/20 21:48:56.0671 3512   i8042prt        (2656fdfe0a7916c3a16f374454c55dd9) C:\WINNT\system32\DRIVERS\i8042prt.sys
2011/06/20 21:48:56.0953 3512   ialm            (bffa387180121df1e4646c4ced3e16ca) C:\WINNT\system32\DRIVERS\igxpmp32.sys
2011/06/20 21:48:57.0250 3512   iaStor          (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\WINNT\system32\DRIVERS\iaStor.sys
2011/06/20 21:48:57.0296 3512   Imapi           (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINNT\system32\DRIVERS\imapi.sys
2011/06/20 21:48:57.0578 3512   IntcAzAudAddService (fc3a99650afe0b39fe1d214304a7d0d3) C:\WINNT\system32\drivers\RtkHDAud.sys
2011/06/20 21:48:57.0718 3512   intelppm        (78a353438791c6d04c64013a5abec6bd) C:\WINNT\system32\DRIVERS\intelppm.sys
2011/06/20 21:48:57.0765 3512   Ip6Fw           (4448006b6bc60e6c027932cfc38d6855) C:\WINNT\system32\DRIVERS\Ip6Fw.sys
2011/06/20 21:48:57.0796 3512   IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINNT\system32\DRIVERS\ipfltdrv.sys
2011/06/20 21:48:57.0828 3512   IpInIp          (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINNT\system32\DRIVERS\ipinip.sys
2011/06/20 21:48:57.0859 3512   IpNat           (5191673215c91ff13ceaa83ef8e9653f) C:\WINNT\system32\DRIVERS\ipnat.sys
2011/06/20 21:48:57.0890 3512   IPSec           (64537aa5c003a6afeee1df819062d0d1) C:\WINNT\system32\DRIVERS\ipsec.sys
2011/06/20 21:48:58.0015 3512   IRENUM          (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINNT\system32\DRIVERS\irenum.sys
2011/06/20 21:48:58.0046 3512   isapnp          (01a9e68528f4f34e5702123d27c67bd4) C:\WINNT\system32\DRIVERS\isapnp.sys
2011/06/20 21:48:58.0109 3512   Kbdclass        (cc13db862f929ae33f64c3bedc01cd31) C:\WINNT\system32\DRIVERS\kbdclass.sys
2011/06/20 21:48:58.0156 3512   kmixer          (d93cad07c5683db066b0b2d2d3790ead) C:\WINNT\system32\drivers\kmixer.sys
2011/06/20 21:48:58.0250 3512   KSecDD          (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINNT\system32\drivers\KSecDD.sys
2011/06/20 21:48:58.0375 3512   mnmdd           (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINNT\system32\drivers\mnmdd.sys
2011/06/20 21:48:58.0406 3512   Modem           (15f33d12d604d0198ce5561f102cd9c5) C:\WINNT\system32\drivers\Modem.sys
2011/06/20 21:48:58.0453 3512   Mouclass        (69c12b99ae8b6b99ec314e9b99833728) C:\WINNT\system32\DRIVERS\mouclass.sys
2011/06/20 21:48:58.0546 3512   mouhid          (ecec1e6cd558ab80f944f31326e9d3b5) C:\WINNT\system32\DRIVERS\mouhid.sys
2011/06/20 21:48:58.0593 3512   MountMgr        (65653f3b4477f3c63e68a9659f85ee2e) C:\WINNT\system32\drivers\MountMgr.sys
2011/06/20 21:48:58.0656 3512   MRxDAV          (46edcc8f2db2f322c24f48785cb46366) C:\WINNT\system32\DRIVERS\mrxdav.sys
2011/06/20 21:48:58.0718 3512   MRxSmb          (7b195060ff456fa65954c72c5c1640ff) C:\WINNT\system32\DRIVERS\mrxsmb.sys
2011/06/20 21:48:58.0796 3512   Msfs            (561b3a4333ca2dbdba28b5b956822519) C:\WINNT\system32\drivers\Msfs.sys
2011/06/20 21:48:58.0843 3512   MSKSSRV         (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINNT\system32\drivers\MSKSSRV.sys
2011/06/20 21:48:58.0875 3512   MSPCLOCK        (13e75fef9dfeb08eeded9d0246e1f448) C:\WINNT\system32\drivers\MSPCLOCK.sys
2011/06/20 21:48:58.0906 3512   MSPQM           (1988a33ff19242576c3d0ef9ce785da7) C:\WINNT\system32\drivers\MSPQM.sys
2011/06/20 21:48:58.0937 3512   mssmbios        (469541f8bfd2b32659d5d463a6714bce) C:\WINNT\system32\DRIVERS\mssmbios.sys
2011/06/20 21:48:58.0968 3512   Mup             (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINNT\system32\drivers\Mup.sys
2011/06/20 21:48:59.0093 3512   NDIS            (558635d3af1c7546d26067d5d9b6959e) C:\WINNT\system32\drivers\NDIS.sys
2011/06/20 21:48:59.0156 3512   NdisTapi        (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINNT\system32\DRIVERS\ndistapi.sys
2011/06/20 21:48:59.0171 3512   Ndisuio         (34d6cd56409da9a7ed573e1c90a308bf) C:\WINNT\system32\DRIVERS\ndisuio.sys
2011/06/20 21:48:59.0218 3512   NdisWan         (0b90e255a9490166ab368cd55a529893) C:\WINNT\system32\DRIVERS\ndiswan.sys
2011/06/20 21:48:59.0250 3512   NDProxy         (59fc3fb44d2669bc144fd87826bb571f) C:\WINNT\system32\drivers\NDProxy.sys
2011/06/20 21:48:59.0296 3512   NetBIOS         (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINNT\system32\DRIVERS\netbios.sys
2011/06/20 21:48:59.0343 3512   NetBT           (0c80e410cd2f47134407ee7dd19cc86b) C:\WINNT\system32\DRIVERS\netbt.sys
2011/06/20 21:48:59.0390 3512   Npfs            (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINNT\system32\drivers\Npfs.sys
2011/06/20 21:48:59.0453 3512   Ntfs            (b78be402c3f63dd55521f73876951cdd) C:\WINNT\system32\drivers\Ntfs.sys
2011/06/20 21:48:59.0515 3512   Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINNT\system32\drivers\Null.sys
2011/06/20 21:48:59.0546 3512   NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINNT\system32\DRIVERS\nwlnkflt.sys
2011/06/20 21:48:59.0578 3512   NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINNT\system32\DRIVERS\nwlnkfwd.sys
2011/06/20 21:48:59.0640 3512   Parport         (2ff48d8fdc815a8492fb2bd81e6999c2) C:\WINNT\system32\drivers\Parport.sys
2011/06/20 21:48:59.0671 3512   PartMgr         (3334430c29dc338092f79c38ef7b4cd0) C:\WINNT\system32\drivers\PartMgr.sys
2011/06/20 21:48:59.0687 3512   ParVdm          (453ec2c2a20a1382f564541918520eeb) C:\WINNT\system32\drivers\ParVdm.sys
2011/06/20 21:48:59.0734 3512   PCI             (5fd05c92ec56f696eaa50b68cef1b84a) C:\WINNT\system32\DRIVERS\pci.sys
2011/06/20 21:48:59.0843 3512   PCIIde          (548cf2d6369eae441a4c6baa75bc4f0a) C:\WINNT\system32\DRIVERS\pciide.sys
2011/06/20 21:48:59.0890 3512   Pcmcia          (2849812217ecec059cb45f80eb6e52d4) C:\WINNT\system32\drivers\Pcmcia.sys
2011/06/20 21:49:00.0156 3512   PptpMiniport    (1c5cc65aac0783c344f16353e60b72ac) C:\WINNT\system32\DRIVERS\raspptp.sys
2011/06/20 21:49:00.0187 3512   PSched          (48671f327553dcf1d27f6197f622a668) C:\WINNT\system32\DRIVERS\psched.sys
2011/06/20 21:49:00.0234 3512   Ptilink         (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINNT\system32\DRIVERS\ptilink.sys
2011/06/20 21:49:00.0296 3512   PxHelp20        (d86b4a68565e444d76457f14172c875a) C:\WINNT\system32\Drivers\PxHelp20.sys
2011/06/20 21:49:00.0500 3512   RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINNT\system32\DRIVERS\rasacd.sys
2011/06/20 21:49:00.0578 3512   Rasl2tp         (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINNT\system32\DRIVERS\rasl2tp.sys
2011/06/20 21:49:00.0656 3512   RasPppoe        (7306eeed8895454cbed4669be9f79faa) C:\WINNT\system32\DRIVERS\raspppoe.sys
2011/06/20 21:49:00.0703 3512   Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINNT\system32\DRIVERS\raspti.sys
2011/06/20 21:49:00.0750 3512   Rdbss           (d0fef8156d2d2fec557c100956d76887) C:\WINNT\system32\DRIVERS\rdbss.sys
2011/06/20 21:49:00.0796 3512   RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINNT\system32\DRIVERS\RDPCDD.sys
2011/06/20 21:49:00.0875 3512   rdpdr           (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINNT\system32\DRIVERS\rdpdr.sys
2011/06/20 21:49:00.0937 3512   RDPWD           (047bea21274c8a4a233674a76c958c2c) C:\WINNT\system32\drivers\RDPWD.sys
2011/06/20 21:49:01.0031 3512   redbook         (bddcece9acdad26841c987d10376f6f7) C:\WINNT\system32\DRIVERS\redbook.sys
2011/06/20 21:49:01.0109 3512   rtl8139         (d507c1400284176573224903819ffda3) C:\WINNT\system32\DRIVERS\RTL8139.SYS
2011/06/20 21:49:01.0171 3512   RTL8187B        (fe999b16e967c84790be6dc1b4e78f2d) C:\WINNT\system32\DRIVERS\RTL8187B.sys
2011/06/20 21:49:01.0281 3512   Secdrv          (d26e26ea516450af9d072635c60387f4) C:\WINNT\system32\DRIVERS\secdrv.sys
2011/06/20 21:49:01.0328 3512   Serial          (859bc6f8c3d58cfda9181e9926c7ddb9) C:\WINNT\system32\drivers\Serial.sys
2011/06/20 21:49:01.0359 3512   Sfloppy         (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINNT\system32\drivers\Sfloppy.sys
2011/06/20 21:49:01.0468 3512   splitter        (8e186b8f23295d1e42c573b82b80d548) C:\WINNT\system32\drivers\splitter.sys
2011/06/20 21:49:01.0531 3512   sr              (6145ca23bccda679a772ec0af42d6eb5) C:\WINNT\system32\DRIVERS\sr.sys
2011/06/20 21:49:01.0625 3512   Srv             (54e79b08d0abc9c551d0fe69cc2f87ec) C:\WINNT\system32\DRIVERS\srv.sys
2011/06/20 21:49:01.0656 3512   swenum          (03c1bae4766e2450219d20b993d6e046) C:\WINNT\system32\DRIVERS\swenum.sys
2011/06/20 21:49:01.0703 3512   swmidi          (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINNT\system32\drivers\swmidi.sys
2011/06/20 21:49:01.0828 3512   sysaudio        (650ad082d46bac0e64c9c0e0928492fd) C:\WINNT\system32\drivers\sysaudio.sys
2011/06/20 21:49:01.0859 3512   Tcpip           (5562cc0a47b2aef06d3417b733f3c195) C:\WINNT\system32\DRIVERS\tcpip.sys
2011/06/20 21:49:01.0937 3512   TDPIPE          (38d437cf2d98965f239b0abcd66dcb0f) C:\WINNT\system32\drivers\TDPIPE.sys
2011/06/20 21:49:01.0968 3512   TDTCP           (ed0580af02502d00ad8c4c066b156be9) C:\WINNT\system32\drivers\TDTCP.sys
2011/06/20 21:49:02.0000 3512   Teefer          (99336d4da97b4eeaafab46a4f8e512e6) C:\WINNT\system32\Drivers\Teefer.sys
2011/06/20 21:49:02.0062 3512   TermDD          (a540a99c281d933f3d69d55e48727f47) C:\WINNT\system32\DRIVERS\termdd.sys
2011/06/20 21:49:02.0234 3512   Udfs            (12f70256f140cd7d52c58c7048fde657) C:\WINNT\system32\drivers\Udfs.sys
2011/06/20 21:49:02.0312 3512   UnlockerDriver5 (4847639d852763ee39415c929470f672) C:\Program Files\Unlocker\UnlockerDriver5.sys
2011/06/20 21:49:02.0375 3512   Update          (a4815a4884898f355a3513e60843a4fd) C:\WINNT\system32\DRIVERS\update.sys
2011/06/20 21:49:02.0453 3512   usbehci         (15e993ba2f6946b2bfbbfcd30398621e) C:\WINNT\system32\DRIVERS\usbehci.sys
2011/06/20 21:49:02.0500 3512   usbhub          (c72f40947f92cea56a8fb532edf025f1) C:\WINNT\system32\DRIVERS\usbhub.sys
2011/06/20 21:49:02.0546 3512   usbscan         (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINNT\system32\DRIVERS\usbscan.sys
2011/06/20 21:49:02.0609 3512   USBSTOR         (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINNT\system32\DRIVERS\USBSTOR.SYS
2011/06/20 21:49:02.0671 3512   usbuhci         (f8fd1400092e23c8f2f31406ef06167b) C:\WINNT\system32\DRIVERS\usbuhci.sys
2011/06/20 21:49:02.0718 3512   VgaSave         (8a60edd72b4ea5aea8202daf0e427925) C:\WINNT\System32\drivers\vga.sys
2011/06/20 21:49:02.0765 3512   VolSnap         (ecd173739b8ec10a814cc18653df5a36) C:\WINNT\system32\drivers\VolSnap.sys
2011/06/20 21:49:02.0843 3512   Wanarp          (984ef0b9788abf89974cfed4bfbaacbc) C:\WINNT\system32\DRIVERS\wanarp.sys
2011/06/20 21:49:02.0937 3512   wdmaud          (2797f33ebf50466020c430ee4f037933) C:\WINNT\system32\drivers\wdmaud.sys
2011/06/20 21:49:03.0015 3512   wg3n            (a67340b874df9eaf5b226e5f3473b9da) C:\WINNT\SYSTEM32\Drivers\wg3n.sys
2011/06/20 21:49:03.0078 3512   wg4n            (851216e2816b7b7e74b5f7ef1d4acfb7) C:\WINNT\SYSTEM32\Drivers\wg4n.sys
2011/06/20 21:49:03.0109 3512   wg5n            (aedd1fe0df660411d15da3c57cfc2402) C:\WINNT\SYSTEM32\Drivers\wg5n.sys
2011/06/20 21:49:03.0140 3512   wg6n            (dd0d719a58df79086462bd5fc972a908) C:\WINNT\SYSTEM32\Drivers\wg6n.sys
2011/06/20 21:49:03.0234 3512   wpsdrvnt        (93c145dceb13156322423efd62d4549a) C:\WINNT\system32\drivers\wpsdrvnt.sys
2011/06/20 21:49:03.0296 3512   WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINNT\system32\DRIVERS\WudfPf.sys
2011/06/20 21:49:03.0343 3512   WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINNT\system32\DRIVERS\wudfrd.sys
2011/06/20 21:49:03.0406 3512   MBR (0x1B8)     (32052574bf9f325ae309abc7bfd04460) \Device\Harddisk0\DR0
2011/06/20 21:49:03.0625 3512   MBR (0x1B8)     (66d0b28c8b44e531d0c19f436252abaa) \Device\Harddisk1\DR4
2011/06/20 21:49:03.0640 3512   ================================================================================
2011/06/20 21:49:03.0640 3512   Scan finished
2011/06/20 21:49:03.0640 3512   ================================================================================
2011/06/20 21:49:03.0671 3468   Detected object count: 0
2011/06/20 21:49:03.0671 3468   Actual detected object count: 0
2011/06/20 21:49:11.0812 1176   Deinitialize success
Awatar użytkownika
jacekk04
~user
 
Posty: 861
Dołączenie: 05 Paź 2005, 20:02
Miejscowość: Radzyń Podlaski
Pochwały: 5



Otwieranie programu za pomoca

Postprzez wojtas 21 Cze 2011, 11:48

skasuj ten folder:

C:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\FireFox\Profiles\tbxrqr7a.default\searchplugins\web-search.xml



*Uruchom OTL z opcji sprzątanie.
* wykonaj optymalizację Windowsa ( instrukcja dla Windowsa XP, lecz w innych systemach jest podobnie )
* zrób pełny skan Malwarebytes Anti-Malware (zaktualizuj, usuń co znajdzie )
* Skasuj stan przywracania systemu


Zaktualizuj zabezpieczenia:
>>> Adobe Reader (bez Free McAfee® Security Scan Plus)
>>> Internet Explorer 8
>>> Service Pack 3
>>> Java™ 6
>>> Avast 6 (odinstaluj starszą wersję i zainstaluj nową)


napisz jak sytuacja z komputerem :)
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Otwieranie programu za pomoca

Postprzez jacekk04 24 Cze 2011, 17:11

dzieki wojtas teraz jest juz wszystko w porzadku co prawda nie moglem zainstalowac service packa 3 (z braku miejsca na dysku) i IE 8 ale reszta zostala zrobiona pomyslnie, sory za zwloke ale nie ale nie zawsze mam dostep do neta, takze jeszcze raz dzieki
Awatar użytkownika
jacekk04
~user
 
Posty: 861
Dołączenie: 05 Paź 2005, 20:02
Miejscowość: Radzyń Podlaski
Pochwały: 5




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 6 gości