Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Prosím o kontrolu logu

#1 Příspěvek od romcolahvac »

Dobrý podvečer, prosím o zkontrolování logu, počítač se mi začal maličko zahlcovat, například beh videa - přesněji řečeno TV se cuká. Moc děkuji za radu :-)

Logfile of random's system information tool 1.09 (written by random/random)
Run by ROMAN at 2011-07-23 19:11:10
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 22 GB (11%) free of 191 GB
Total RAM: 2046 MB (18% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:11:16, on 23.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\Plugins\Helper\AlSrvN.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Fox Magic\ScreenVirtuoso Pro 2.00\dxlock.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\iTraffic Monitor\iTrafficMon.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\ASUS\TurboV EVO\TurboVHELP.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\Program Files (x86)\Mozilla Firefox 3\firefox.exe
C:\Program Files (x86)\Mozilla Firefox 3\plugin-container.exe
C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe
C:\Program Files\trend micro\ROMAN.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14597
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QipLI - {6B5863A0-C43F-4C0A-982B-CC0E9125783F} - C:\Users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\Program Files (x86)\Common Files\justDo\Jd2002.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {D5D47440-0750-463D-BAEF-A47D02414806} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~2\FlashGet\fgiebar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [TurboV EVO] "C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [iTraffic Monitor] C:\Program Files (x86)\iTraffic Monitor\iTrafficMon.exe
O4 - HKLM\..\Run: [Standby] "c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -START
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKCU\..\Run: [NVIDIA driver monitor] c:\windows\nvsvc32.exe
O4 - HKCU\..\Run: [PhoneDaemon] C:\Users\ROMAN\Desktop\iPhone PC Suite\PhoneDaemon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AlSrvN] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\Plugins\Helper\AlSrvN.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [dxlock] C:\Program Files (x86)\Fox Magic\ScreenVirtuoso Pro 2.00\dxlock.exe
O4 - HKCU\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Image Retriever.lnk = C:\Program Files (x86)\ScanSoft\PaperPort\xdcla.exe
O8 - Extra context menu item: &Stáhnout všechno FlashGetem - C:\Program Files (x86)\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL/FlashCatcher.htm
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL
O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://software.kuaiche.com
O16 - DPF: {0427F569-3D57-4F10-B9FB-8D71A6A7BE24} (FormelEditor Control) - file:///C:/Users/ROMAN/AppData/Local/Temp/KJPL60/frmeditor.ocx
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.5.7.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/Juni ... Client.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Cerberus FTP Server - Cerberus, LLC - C:\Program Files (x86)\Cerberus LLC\Cerberus FTP Server\CerberusGUI.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\ASUS.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EWA net DB Core - Transaction Software, D 81829 Munich - C:\Program Files (x86)\EWA net\database\TransBase EWA\tbmux32.exe
O23 - Service: EWA net DB EPC - Transaction Software, D 81829 Munich - C:\Program Files (x86)\EWA net\database\TransBase EPC\tbmux32.exe
O23 - Service: EWA net DB WIS - Transaction Software, D 81829 Munich - C:\Program Files (x86)\EWA net\database\TransBase WIS\tbmux32.exe
O23 - Service: EWA net Server - Alexandria Software Consulting - C:\Program Files (x86)\EWA net\server\bin\tomcat.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TVEnhance Background Capture Service (TBCS) (TVECapSvc) - Unknown owner - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe
O23 - Service: TVEnhance Task Scheduler (TTS)) (TVESched) - Unknown owner - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 17601 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x308
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\Plugins\Helper\AlSrvN.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\Fox Magic\ScreenVirtuoso Pro 2.00\dxlock.exe"
"C:\Program Files\WinFast\WFDTV\WFWIZ.exe"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
"C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe" -hide
"C:\Program Files (x86)\iTraffic Monitor\iTrafficMon.exe"
"C:\Program Files\WinFast\WFDTV\DTVSchdl.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
taskeng.exe {974D04A6-4F63-4DBB-B335-C7F516634C72}
"C:\Program Files (x86)\ASUS\TurboV EVO\TurboVHELP.exe"
"C:\Program Files\ASUS\Six Engine\SixEngine.exe" -b
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Cerberus LLC\Cerberus FTP Server\CerberusGUI.exe" -Service
"C:\ASUS.SYS\config\DVMExportService.exe"
"C:\Program Files (x86)\EWA net\database\TransBase EWA\tbmux32.exe"
"C:\Program Files (x86)\EWA net\database\TransBase EPC\tbmux32.exe"
"C:\Program Files (x86)\EWA net\database\TransBase WIS\tbmux32.exe"
"C:\Program Files (x86)\EWA net\server\bin\tomcat.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
"C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe"
"C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe"
"C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe" -Embedding
"C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sFORDECATDB
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe"
"C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe"
"C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe"
WLIDSvcM.exe 4004
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\EWA net\database\TransBase EWA\tbkern32.exe" -dedi 32677 -inactivity 0
"C:\Program Files (x86)\EWA net\database\TransBase EPC\tbkern32.exe" -dedi 47084 -inactivity 0 -crypt
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Mozilla Firefox 3\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox 3\plugin-container.exe" --channel=4256.fe75020.104814739 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.6.0 -greomni "C:\Program Files (x86)\Mozilla Firefox 3\omni.jar" 4256 "\\.\pipe\gecko-crash-server-pipe.4256" plugin
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -RESTART
"D:\XXX\5.7.11\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-876401281-3636213226-3406816674-1001Core1cc04adfeaaf61.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-876401281-3636213226-3406816674-1001UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "file://///WL-500GPV2/part0/intra/index.html"
prefs.js - "extensions.enabledItems" - "LogMeInClient@logmein.com:1.0.0.608, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.URL" - "http://search.conduit.com/ResultsExt.as ... 2786678&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

C:\Program Files (x86)\Mozilla Firefox 3\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox 3\components\
binary.manifest
browsercomps.dll
FlashGet3.xpi
IICAClient.xpt

C:\Program Files (x86)\Mozilla Firefox 3\plugins\
cgpcfg.dll
CgpCore.dll
confmgr.dll
ctxmui.dll
ICAClObj.class
icafile.dll
icalogon.dll
logging.dll
np-mswmp.dll
npdeployJava1.dll
npicaN.dll
nppdf32.dll
npwachk.dll
sslsdk_b.dll
TcpPServ.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox 3\searchplugins\
Cetrumcz_igeared.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default\extensions\
engine@conduit.com
LogMeInClient@logmein.com
maps@ovi.com
toolbar@ask.com
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}

C:\Users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default\searchplugins\
askcom.xml
conduit.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin.xml
qipsearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll [2010-06-09 45568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-06-09 138240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E}]
SnapFlash Class - C:\Program Files (x86)\Common Files\justDo\Jd2002.dll [2002-12-03 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D5D47440-0750-463D-BAEF-A47D02414806}
{E0E899AB-F487-11D5-8D29-0050BA6940E3} - FlashGet Bar - C:\PROGRA~2\FlashGet\fgiebar.dll [2005-06-07 86016]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2010-01-27 57928]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA driver monitor"=c:\windows\nvsvc32.exe []
"PhoneDaemon"=C:\Users\ROMAN\Desktop\iPhone PC Suite\PhoneDaemon.exe []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"AlSrvN"=C:\Program Files (x86)\Alcohol Soft\Alcohol 120\Plugins\Helper\AlSrvN.exe [2010-02-06 53760]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"dxlock"=C:\Program Files (x86)\Fox Magic\ScreenVirtuoso Pro 2.00\dxlock.exe [2005-07-26 90112]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2010-08-11 2920448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\602PC SUITE PDF Saver]
C:\Program Files (x86)\Common Files\soft602\pdfSaver.exe [2005-08-31 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2010-08-20 33120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-12-14 47904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [2009-01-30 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FineReader7NewsReaderPro]
C:\Program Files (x86)\ABBYY FineReader 7.0 Professional Edition\ABBYYNewsReader.exe [2005-01-23 290816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashGet]
C:\Program Files (x86)\FlashGet Network\FlashGet universal\flashget.exe /min []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\ROMAN\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-25 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-01-25 421160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-02-22 1226024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfSaver3]
c:\Program Files\PDF\pdfSaver\pdfSaver3.exe [2004-05-19 385024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe [2008-09-24 172032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
C:\Users\ROMAN\AppData\Roaming\QipGuard\QipGuard.exe [2010-06-09 187904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVEService]
C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe [2008-10-23 180224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFast Schedule]
C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2010-08-11 2920448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFastDTV]
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2011-06-08 101888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^ROMAN^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~2\MICROS~2\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-07-24 2245120]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2007-03-20 36864]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-07-04 3493720]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-08-03 98304]
"ATICustomerCare"=C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [2010-03-04 311296]
"pdfSaver3"= []
"TurboV EVO"=C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe [2009-09-10 7322624]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"LWS"=C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [2010-05-07 165208]
"iTraffic Monitor"=C:\Program Files (x86)\iTraffic Monitor\iTrafficMon.exe [2009-04-22 942080]
"TaskTray"= []
"Standby"=c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe [2010-06-26 105632]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
""= []
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2011-05-17 395144]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2011-06-08 101888]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2009-02-06 170496]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Image Retriever.lnk - C:\Program Files (x86)\ScanSoft\PaperPort\xdcla.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"
"C:\FIREFOX STAHOVANI\facebook-pic000934519.exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcod64.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-07-23 19:04:49 ----D---- C:\Program Files\trend micro
2011-07-23 19:04:47 ----D---- C:\rsit
2011-07-21 17:50:05 ----A---- C:\Windows\SYSWOW64\unicows.dll
2011-07-13 10:40:16 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 10:40:15 ----A---- C:\Windows\system32\wow64win.dll
2011-07-13 10:40:15 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 10:40:14 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 10:40:12 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-13 10:40:12 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-13 10:40:12 ----A---- C:\Windows\system32\wow64.dll
2011-07-13 10:40:11 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-13 10:40:11 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-13 10:40:10 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-13 10:40:10 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-13 10:40:10 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-13 10:40:06 ----A---- C:\Windows\SYSWOW64\user.exe
2011-07-13 10:36:04 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 10:35:54 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-13 10:35:51 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 10:35:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 10:35:49 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 10:35:49 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 10:35:44 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 10:34:34 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-07-13 10:34:33 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-07-13 10:34:29 ----A---- C:\Windows\system32\win32k.sys
2011-07-12 10:45:09 ----D---- C:\Program Files (x86)\Ask.com
2011-07-07 10:32:34 ----D---- C:\Program Files (x86)\CamStudio
2011-07-07 10:28:12 ----A---- C:\Windows\SYSWOW64\fmcodec.DLL
2011-07-07 10:28:11 ----D---- C:\Program Files (x86)\Fox Magic
2011-07-06 10:12:42 ----D---- C:\Windows\system32\SPReview
2011-07-06 10:10:00 ----D---- C:\Windows\system32\EventProviders
2011-07-06 10:03:18 ----D---- C:\Windows\pss
2011-07-04 16:15:18 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-07-04 16:15:18 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-07-04 16:15:18 ----A---- C:\Windows\SYSWOW64\java.exe
2011-07-03 17:02:01 ----A---- C:\Windows\system32\vpc.exe
2011-07-03 17:02:01 ----A---- C:\Windows\system32\netfxperf.dll
2011-07-03 17:02:01 ----A---- C:\Windows\system32\dfshim.dll
2011-07-03 17:01:54 ----A---- C:\Windows\system32\VPCWizard.exe
2011-07-03 17:01:54 ----A---- C:\Windows\system32\VPCSettings.exe
2011-07-03 17:01:54 ----A---- C:\Windows\system32\VMCPropertyHandler.dll
2011-07-03 17:01:53 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-07-03 17:01:52 ----A---- C:\Windows\system32\VMWindow.exe
2011-07-03 17:01:52 ----A---- C:\Windows\system32\vmsal.exe
2011-07-03 17:01:50 ----A---- C:\Windows\system32\drivers\vpcvmm.sys
2011-07-03 17:01:49 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2011-07-03 17:01:48 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-07-03 17:01:48 ----A---- C:\Windows\system32\mstscax.dll
2011-07-03 17:01:47 ----A---- C:\Windows\system32\d3d10warp.dll
2011-07-03 17:01:41 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-07-03 17:01:35 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-07-03 17:01:33 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-07-03 17:01:33 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-07-03 17:01:33 ----A---- C:\Windows\system32\tssrvlic.dll
2011-07-03 17:01:33 ----A---- C:\Windows\system32\sysmain.dll
2011-07-03 17:01:33 ----A---- C:\Windows\system32\RDVGHelper.exe
2011-07-03 17:01:32 ----A---- C:\Windows\system32\rdpcorets.dll
2011-07-03 17:01:31 ----A---- C:\Windows\system32\shell32.dll
2011-07-03 17:01:30 ----A---- C:\Windows\SYSWOW64\pmcsnap.dll
2011-07-03 17:01:29 ----A---- C:\Windows\system32\MSVidCtl.dll
2011-07-03 17:01:27 ----A---- C:\Windows\SYSWOW64\vmsal.exe
2011-07-03 17:01:26 ----A---- C:\Windows\system32\wmp.dll
2011-07-03 17:01:23 ----A---- C:\Windows\system32\ntdll.dll
2011-07-03 17:01:23 ----A---- C:\Windows\system32\mscoree.dll
2011-07-03 17:01:22 ----A---- C:\Windows\system32\mmcndmgr.dll
2011-07-03 17:01:19 ----A---- C:\Windows\system32\secproc_isv.dll
2011-07-03 17:01:19 ----A---- C:\Windows\system32\mf.dll
2011-07-03 17:01:17 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2011-07-03 17:01:17 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-07-03 17:01:16 ----A---- C:\Windows\system32\secproc.dll
2011-07-03 17:01:16 ----A---- C:\Windows\system32\RMActivate.exe
2011-07-03 17:01:15 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-07-03 17:01:15 ----A---- C:\Windows\system32\xpsservices.dll
2011-07-03 17:01:13 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2011-07-03 17:01:11 ----A---- C:\Windows\SYSWOW64\secproc.dll
2011-07-03 17:01:11 ----A---- C:\Windows\system32\rpcrt4.dll
2011-07-03 17:01:10 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2011-07-03 17:01:10 ----A---- C:\Windows\SYSWOW64\PushPrinterConnections.exe
2011-07-03 17:01:10 ----A---- C:\Windows\SYSWOW64\ppcsnap.dll
2011-07-03 17:01:09 ----A---- C:\Windows\system32\schedsvc.dll
2011-07-03 17:01:09 ----A---- C:\Windows\system32\ole32.dll
2011-07-03 17:01:08 ----A---- C:\Windows\system32\spwizui.dll
2011-07-03 17:01:07 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-07-03 17:01:06 ----A---- C:\Windows\system32\taskschd.dll
2011-07-03 17:01:06 ----A---- C:\Windows\system32\RacEngn.dll
2011-07-03 17:01:06 ----A---- C:\Windows\system32\diagperf.dll
2011-07-03 17:01:05 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-07-03 17:01:05 ----A---- C:\Windows\system32\wevtsvc.dll
2011-07-03 17:01:05 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-07-03 17:01:04 ----A---- C:\Windows\system32\vssapi.dll
2011-07-03 17:01:03 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2011-07-03 17:01:03 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2011-07-03 17:01:03 ----A---- C:\Windows\system32\msxml3.dll
2011-07-03 17:01:03 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2011-07-03 17:01:01 ----A---- C:\Windows\system32\UIRibbon.dll
2011-07-03 17:01:01 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2011-07-03 17:00:58 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-07-03 17:00:56 ----A---- C:\Windows\system32\WsmSvc.dll
2011-07-03 17:00:55 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-07-03 17:00:55 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-07-03 17:00:55 ----A---- C:\Windows\system32\WMVCORE.DLL
2011-07-03 17:00:55 ----A---- C:\Windows\system32\rdpudd.dll
2011-07-03 17:00:55 ----A---- C:\Windows\system32\rdpdd.dll
2011-07-03 17:00:55 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-07-03 17:00:55 ----A---- C:\Windows\system32\PresentationHost.exe
2011-07-03 17:00:54 ----A---- C:\Windows\system32\spreview.exe
2011-07-03 17:00:54 ----A---- C:\Windows\system32\spinstall.exe
2011-07-03 17:00:54 ----A---- C:\Windows\system32\MPSSVC.dll
2011-07-03 17:00:53 ----A---- C:\Windows\system32\WinSAT.exe
2011-07-03 17:00:53 ----A---- C:\Windows\system32\drivers\vpchbus.sys
2011-07-03 17:00:53 ----A---- C:\Windows\system32\drivers\vpcusb.sys
2011-07-03 17:00:53 ----A---- C:\Windows\system32\CertEnroll.dll
2011-07-03 17:00:52 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-07-03 17:00:51 ----A---- C:\Windows\system32\msxml6.dll
2011-07-03 17:00:51 ----A---- C:\Windows\system32\d3d9.dll
2011-07-03 17:00:50 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2011-07-03 17:00:50 ----A---- C:\Windows\system32\SearchFolder.dll
2011-07-03 17:00:50 ----A---- C:\Windows\system32\IKEEXT.DLL
2011-07-03 17:00:49 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2011-07-03 17:00:49 ----A---- C:\Windows\system32\gpsvc.dll
2011-07-03 17:00:49 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2011-07-03 17:00:48 ----A---- C:\Windows\system32\VSSVC.exe
2011-07-03 17:00:48 ----A---- C:\Windows\system32\dwmcore.dll
2011-07-03 17:00:47 ----A---- C:\Windows\system32\drivers\http.sys
2011-07-03 17:00:47 ----A---- C:\Windows\system32\dbgeng.dll
2011-07-03 17:00:46 ----A---- C:\Windows\SYSWOW64\rdvgumd32.dll
2011-07-03 17:00:46 ----A---- C:\Windows\system32\drivers\ndis.sys
2011-07-03 17:00:45 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-07-03 17:00:45 ----A---- C:\Windows\system32\crypt32.dll
2011-07-03 17:00:44 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-07-03 17:00:44 ----A---- C:\Windows\system32\actxprxy.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\TSWorkspace.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\schannel.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\qmgr.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\lsasrv.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\gpprefcl.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\audiosrv.dll
2011-07-03 17:00:42 ----A---- C:\Windows\system32\termsrv.dll
2011-07-03 17:00:41 ----A---- C:\Windows\system32\sqmapi.dll
2011-07-03 17:00:41 ----A---- C:\Windows\system32\mstsc.exe
2011-07-03 17:00:40 ----A---- C:\Windows\system32\netlogon.dll
2011-07-03 17:00:40 ----A---- C:\Windows\system32\imapi2fs.dll
2011-07-03 17:00:40 ----A---- C:\Windows\system32\drivers\vpcnfltr.sys
2011-07-03 17:00:39 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2011-07-03 17:00:39 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2011-07-03 17:00:39 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2011-07-03 17:00:39 ----A---- C:\Windows\system32\winhttp.dll
2011-07-03 17:00:39 ----A---- C:\Windows\system32\QAGENTRT.DLL
2011-07-03 17:00:39 ----A---- C:\Windows\system32\msv1_0.dll
2011-07-03 17:00:39 ----A---- C:\Windows\system32\d3d11.dll
2011-07-03 17:00:38 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-07-03 17:00:38 ----A---- C:\Windows\system32\setupapi.dll
2011-07-03 17:00:38 ----A---- C:\Windows\system32\rpcss.dll
2011-07-03 17:00:38 ----A---- C:\Windows\system32\propsys.dll
2011-07-03 17:00:37 ----A---- C:\Windows\system32\werconcpl.dll
2011-07-03 17:00:37 ----A---- C:\Windows\system32\wbengine.exe
2011-07-03 17:00:37 ----A---- C:\Windows\system32\PushPrinterConnections.exe
2011-07-03 17:00:37 ----A---- C:\Windows\system32\authui.dll
2011-07-03 17:00:36 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2011-07-03 17:00:36 ----A---- C:\Windows\system32\taskeng.exe
2011-07-03 17:00:36 ----A---- C:\Windows\system32\odbc32.dll
2011-07-03 17:00:35 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-07-03 17:00:35 ----A---- C:\Windows\system32\WSDApi.dll
2011-07-03 17:00:35 ----A---- C:\Windows\system32\user32.dll
2011-07-03 17:00:34 ----A---- C:\Windows\system32\drivers\netio.sys
2011-07-03 17:00:34 ----A---- C:\Windows\system32\dhcpcore.dll
2011-07-03 17:00:34 ----A---- C:\Windows\system32\certmgr.dll
2011-07-03 17:00:33 ----A---- C:\Windows\SYSWOW64\wer.dll
2011-07-03 17:00:33 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\webio.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\umrdp.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\scavengeui.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\LSCSHostPolicy.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\drivers\tdx.sys
2011-07-03 17:00:33 ----A---- C:\Windows\system32\drivers\netbt.sys
2011-07-03 17:00:32 ----A---- C:\Windows\SYSWOW64\certcli.dll
2011-07-03 17:00:32 ----A---- C:\Windows\system32\tsmf.dll
2011-07-03 17:00:32 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2011-07-03 17:00:32 ----A---- C:\Windows\system32\localspl.dll
2011-07-03 17:00:31 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-07-03 17:00:31 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2011-07-03 17:00:31 ----A---- C:\Windows\system32\shlwapi.dll
2011-07-03 17:00:31 ----A---- C:\Windows\system32\ncsi.dll
2011-07-03 17:00:31 ----A---- C:\Windows\system32\msdrm.dll
2011-07-03 17:00:30 ----A---- C:\Windows\system32\netshell.dll
2011-07-03 17:00:30 ----A---- C:\Windows\system32\msdtctm.dll
2011-07-03 17:00:30 ----A---- C:\Windows\system32\framedynos.dll
2011-07-03 17:00:29 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2011-07-03 17:00:29 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-07-03 17:00:29 ----A---- C:\Windows\system32\ws2_32.dll
2011-07-03 17:00:29 ----A---- C:\Windows\system32\winlogon.exe
2011-07-03 17:00:29 ----A---- C:\Windows\system32\rdpshell.exe
2011-07-03 17:00:29 ----A---- C:\Windows\system32\netcfgx.dll
2011-07-03 17:00:29 ----A---- C:\Windows\system32\drivers\cng.sys
2011-07-03 17:00:29 ----A---- C:\Windows\system32\appmgr.dll
2011-07-03 17:00:28 ----A---- C:\Windows\system32\usp10.dll
2011-07-03 17:00:28 ----A---- C:\Windows\system32\quartz.dll
2011-07-03 17:00:28 ----A---- C:\Windows\system32\nlasvc.dll
2011-07-03 17:00:28 ----A---- C:\Windows\system32\lsm.exe
2011-07-03 17:00:28 ----A---- C:\Windows\system32\comdlg32.dll
2011-07-03 17:00:27 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-07-03 17:00:27 ----A---- C:\Windows\system32\wmpps.dll
2011-07-03 17:00:27 ----A---- C:\Windows\system32\dxgi.dll
2011-07-03 17:00:27 ----A---- C:\Windows\system32\drivers\csc.sys
2011-07-03 17:00:27 ----A---- C:\Windows\system32\apphelp.dll
2011-07-03 17:00:26 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2011-07-03 17:00:26 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2011-07-03 17:00:25 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-07-03 17:00:25 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2011-07-03 17:00:25 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2011-07-03 17:00:25 ----A---- C:\Windows\system32\wpdshext.dll
2011-07-03 17:00:25 ----A---- C:\Windows\system32\Query.dll
2011-07-03 17:00:25 ----A---- C:\Windows\system32\mswsock.dll
2011-07-03 17:00:25 ----A---- C:\Windows\system32\azroles.dll
2011-07-03 17:00:24 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2011-07-03 17:00:24 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2011-07-03 17:00:24 ----A---- C:\Windows\system32\Vault.dll
2011-07-03 17:00:24 ----A---- C:\Windows\system32\QAGENT.DLL
2011-07-03 17:00:24 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-07-03 17:00:24 ----A---- C:\Windows\system32\BFE.DLL
2011-07-03 17:00:23 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2011-07-03 17:00:23 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2011-07-03 17:00:23 ----A---- C:\Windows\system32\win32spl.dll
2011-07-03 17:00:23 ----A---- C:\Windows\system32\samsrv.dll
2011-07-03 17:00:23 ----A---- C:\Windows\system32\lpksetup.exe
2011-07-03 17:00:23 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2011-07-03 17:00:23 ----A---- C:\Windows\system32\cmd.exe
2011-07-03 17:00:22 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2011-07-03 17:00:22 ----A---- C:\Windows\system32\cscsvc.dll
2011-07-03 17:00:21 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2011-07-03 17:00:21 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2011-07-03 17:00:21 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2011-07-03 17:00:21 ----A---- C:\Windows\system32\WebClnt.dll
2011-07-03 17:00:21 ----A---- C:\Windows\system32\rdpclip.exe
2011-07-03 17:00:20 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-07-03 17:00:20 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-07-03 17:00:20 ----A---- C:\Windows\SYSWOW64\Query.dll
2011-07-03 17:00:20 ----A---- C:\Windows\system32\WindowsCodecs.dll
2011-07-03 17:00:20 ----A---- C:\Windows\system32\sxs.dll
2011-07-03 17:00:20 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2011-07-03 17:00:19 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2011-07-03 17:00:19 ----A---- C:\Windows\SYSWOW64\gpprefcl.dll
2011-07-03 17:00:19 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2011-07-03 17:00:19 ----A---- C:\Windows\system32\Wldap32.dll
2011-07-03 17:00:19 ----A---- C:\Windows\system32\taskcomp.dll
2011-07-03 17:00:19 ----A---- C:\Windows\system32\mfds.dll
2011-07-03 17:00:19 ----A---- C:\Windows\system32\mcbuilder.exe
2011-07-03 17:00:19 ----A---- C:\Windows\system32\cscobj.dll
2011-07-03 17:00:17 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-07-03 17:00:17 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-07-03 17:00:17 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2011-07-03 17:00:17 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2011-07-03 17:00:17 ----A---- C:\Windows\system32\wuaueng.dll
2011-07-03 17:00:17 ----A---- C:\Windows\system32\pnidui.dll
2011-07-03 17:00:17 ----A---- C:\Windows\system32\ipsmsnap.dll
2011-07-03 17:00:17 ----A---- C:\Windows\system32\hgprint.dll
2011-07-03 17:00:16 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-07-03 17:00:16 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2011-07-03 17:00:16 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2011-07-03 17:00:16 ----A---- C:\Windows\system32\webservices.dll
2011-07-03 17:00:16 ----A---- C:\Windows\system32\SessEnv.dll
2011-07-03 17:00:16 ----A---- C:\Windows\system32\rdpendp.dll
2011-07-03 17:00:15 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2011-07-03 17:00:15 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2011-07-03 17:00:15 ----A---- C:\Windows\SYSWOW64\authui.dll
2011-07-03 17:00:15 ----A---- C:\Windows\system32\winsta.dll
2011-07-03 17:00:15 ----A---- C:\Windows\system32\sqlsrv32.dll
2011-07-03 17:00:15 ----A---- C:\Windows\system32\spoolsv.exe
2011-07-03 17:00:15 ----A---- C:\Windows\system32\fveapi.dll
2011-07-03 17:00:15 ----A---- C:\Windows\system32\dot3api.dll
2011-07-03 17:00:14 ----A---- C:\Windows\SYSWOW64\usp10.dll
2011-07-03 17:00:14 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2011-07-03 17:00:14 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2011-07-03 17:00:14 ----A---- C:\Windows\system32\gdi32.dll
2011-07-03 17:00:14 ----A---- C:\Windows\system32\drivers\volsnap.sys
2011-07-03 17:00:14 ----A---- C:\Windows\system32\drivers\msrpc.sys
2011-07-03 17:00:13 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2011-07-03 17:00:13 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2011-07-03 17:00:13 ----A---- C:\Windows\system32\WMNetMgr.dll
2011-07-03 17:00:13 ----A---- C:\Windows\system32\schtasks.exe
2011-07-03 17:00:13 ----A---- C:\Windows\system32\prncache.dll
2011-07-03 17:00:13 ----A---- C:\Windows\system32\mcmde.dll
2011-07-03 17:00:12 ----A---- C:\Windows\SYSWOW64\userenv.dll
2011-07-03 17:00:12 ----A---- C:\Windows\system32\wuapi.dll
2011-07-03 17:00:12 ----A---- C:\Windows\system32\wlanpref.dll
2011-07-03 17:00:12 ----A---- C:\Windows\system32\vpnike.dll
2011-07-03 17:00:12 ----A---- C:\Windows\system32\userenv.dll
2011-07-03 17:00:11 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2011-07-03 17:00:11 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-07-03 17:00:11 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\wintrust.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\tspubwmi.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\photowiz.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\evr.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\drivers\rdbss.sys
2011-07-03 17:00:11 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2011-07-03 17:00:10 ----A---- C:\Windows\system32\framedyn.dll
2011-07-03 17:00:09 ----A---- C:\Windows\system32\wmpmde.dll
2011-07-03 17:00:09 ----A---- C:\Windows\system32\sppobjs.dll
2011-07-03 17:00:09 ----A---- C:\Windows\system32\IPSECSVC.DLL
2011-07-03 17:00:09 ----A---- C:\Windows\system32\FXSSVC.exe
2011-07-03 17:00:09 ----A---- C:\Windows\system32\AudioSes.dll
2011-07-03 17:00:09 ----A---- C:\Windows\system32\aepdu.dll
2011-07-03 17:00:08 ----A---- C:\Windows\SYSWOW64\cmd.exe
2011-07-03 17:00:08 ----A---- C:\Windows\system32\WMPEncEn.dll
2011-07-03 17:00:08 ----A---- C:\Windows\system32\wmpeffects.dll

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#2 Příspěvek od romcolahvac »

pokračování:

2011-07-03 17:00:08 ----A---- C:\Windows\system32\SyncCenter.dll
2011-07-03 17:00:08 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-07-03 17:00:07 ----A---- C:\Windows\system32\tscfgwmi.dll
2011-07-03 17:00:07 ----A---- C:\Windows\system32\srvsvc.dll
2011-07-03 17:00:07 ----A---- C:\Windows\system32\shsvcs.dll
2011-07-03 17:00:07 ----A---- C:\Windows\system32\rdpinit.exe
2011-07-03 17:00:07 ----A---- C:\Windows\system32\aeinv.dll
2011-07-03 17:00:06 ----A---- C:\Windows\system32\fde.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\propsys.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\mfds.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\WinSATAPI.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\vmicsvc.exe
2011-07-03 17:00:05 ----A---- C:\Windows\system32\stobject.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\localsec.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\imapi2.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\credui.dll
2011-07-03 17:00:04 ----A---- C:\Windows\SYSWOW64\user32.dll
2011-07-03 17:00:04 ----A---- C:\Windows\SYSWOW64\rdpendp.dll
2011-07-03 17:00:04 ----A---- C:\Windows\system32\netdiagfx.dll
2011-07-03 17:00:04 ----A---- C:\Windows\system32\iphlpsvc.dll
2011-07-03 17:00:04 ----A---- C:\Windows\system32\drivers\vmbus.sys
2011-07-03 17:00:04 ----A---- C:\Windows\system32\drivers\udfs.sys
2011-07-03 17:00:04 ----A---- C:\Windows\system32\cdd.dll
2011-07-03 17:00:04 ----A---- C:\Windows\system32\bcryptprimitives.dll
2011-07-03 17:00:03 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2011-07-03 17:00:03 ----A---- C:\Windows\SYSWOW64\azroles.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\tcpipcfg.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\spp.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\QSHVHOST.DLL
2011-07-03 17:00:03 ----A---- C:\Windows\system32\netid.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\inetpp.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2011-07-03 17:00:03 ----A---- C:\Windows\system32\davclnt.dll
2011-07-03 17:00:02 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2011-07-03 17:00:02 ----A---- C:\Windows\system32\profsvc.dll
2011-07-03 17:00:02 ----A---- C:\Windows\system32\cscui.dll
2011-07-03 17:00:02 ----A---- C:\Windows\system32\biocpl.dll
2011-07-03 17:00:01 ----A---- C:\Windows\SYSWOW64\themeui.dll
2011-07-03 17:00:01 ----A---- C:\Windows\system32\scansetting.dll
2011-07-03 17:00:01 ----A---- C:\Windows\system32\printui.dll
2011-07-03 17:00:01 ----A---- C:\Windows\system32\mspbda.dll
2011-07-03 17:00:01 ----A---- C:\Windows\system32\msinfo32.exe
2011-07-03 17:00:01 ----A---- C:\Windows\system32\gameux.dll
2011-07-03 17:00:00 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-07-03 17:00:00 ----A---- C:\Windows\SYSWOW64\spp.dll
2011-07-03 17:00:00 ----A---- C:\Windows\SYSWOW64\credui.dll
2011-07-03 17:00:00 ----A---- C:\Windows\system32\pla.dll
2011-07-03 17:00:00 ----A---- C:\Windows\system32\PhotoScreensaver.scr
2011-07-03 17:00:00 ----A---- C:\Windows\splwow64.exe
2011-07-03 16:59:59 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2011-07-03 16:59:59 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll
2011-07-03 16:59:59 ----A---- C:\Windows\system32\wusa.exe
2011-07-03 16:59:59 ----A---- C:\Windows\system32\vds.exe
2011-07-03 16:59:59 ----A---- C:\Windows\system32\msdri.dll
2011-07-03 16:59:59 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2011-07-03 16:59:59 ----A---- C:\Windows\system32\aitagent.exe
2011-07-03 16:59:58 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2011-07-03 16:59:58 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-07-03 16:59:58 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-07-03 16:59:58 ----A---- C:\Windows\SYSWOW64\basecsp.dll
2011-07-03 16:59:58 ----A---- C:\Windows\system32\wiaservc.dll
2011-07-03 16:59:58 ----A---- C:\Windows\system32\rpchttp.dll
2011-07-03 16:59:58 ----A---- C:\Windows\system32\mscms.dll
2011-07-03 16:59:58 ----A---- C:\Windows\system32\drivers\pci.sys
2011-07-03 16:59:58 ----A---- C:\Windows\system32\cryptsvc.dll
2011-07-03 16:59:58 ----A---- C:\Windows\system32\AdmTmpl.dll
2011-07-03 16:59:57 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2011-07-03 16:59:57 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2011-07-03 16:59:57 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2011-07-03 16:59:57 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-07-03 16:59:57 ----A---- C:\Windows\system32\wisptis.exe
2011-07-03 16:59:57 ----A---- C:\Windows\system32\msi.dll
2011-07-03 16:59:57 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2011-07-03 16:59:57 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2011-07-03 16:59:56 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-07-03 16:59:56 ----A---- C:\Windows\SYSWOW64\evr.dll
2011-07-03 16:59:56 ----A---- C:\Windows\system32\ocsetup.exe
2011-07-03 16:59:56 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2011-07-03 16:59:55 ----A---- C:\Windows\SYSWOW64\WinSATAPI.dll
2011-07-03 16:59:55 ----A---- C:\Windows\system32\sppwinob.dll
2011-07-03 16:59:54 ----A---- C:\Windows\system32\ocsetapi.dll
2011-07-03 16:59:53 ----A---- C:\Windows\SYSWOW64\sqlsrv32.dll
2011-07-03 16:59:53 ----A---- C:\Windows\SYSWOW64\calc.exe
2011-07-03 16:59:53 ----A---- C:\Windows\system32\wpdbusenum.dll
2011-07-03 16:59:53 ----A---- C:\Windows\system32\rdpcore.dll
2011-07-03 16:59:53 ----A---- C:\Windows\system32\eapp3hst.dll
2011-07-03 16:59:53 ----A---- C:\Windows\system32\DXP.dll
2011-07-03 16:59:53 ----A---- C:\Windows\system32\drivers\volmgr.sys
2011-07-03 16:59:53 ----A---- C:\Windows\system32\drivers\msdsm.sys
2011-07-03 16:59:53 ----A---- C:\Windows\system32\ci.dll
2011-07-03 16:59:52 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2011-07-03 16:59:52 ----A---- C:\Windows\system32\wcncsvc.dll
2011-07-03 16:59:52 ----A---- C:\Windows\system32\upnp.dll
2011-07-03 16:59:52 ----A---- C:\Windows\system32\Robocopy.exe
2011-07-03 16:59:52 ----A---- C:\Windows\system32\ntshrui.dll
2011-07-03 16:59:52 ----A---- C:\Windows\system32\mprapi.dll
2011-07-03 16:59:52 ----A---- C:\Windows\system32\eapphost.dll
2011-07-03 16:59:51 ----A---- C:\Windows\SYSWOW64\ws2_32.dll
2011-07-03 16:59:51 ----A---- C:\Windows\SYSWOW64\sxs.dll
2011-07-03 16:59:51 ----A---- C:\Windows\SYSWOW64\stobject.dll
2011-07-03 16:59:51 ----A---- C:\Windows\SYSWOW64\netshell.dll
2011-07-03 16:59:51 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2011-07-03 16:59:51 ----A---- C:\Windows\system32\thumbcache.dll
2011-07-03 16:59:51 ----A---- C:\Windows\system32\t2embed.dll
2011-07-03 16:59:51 ----A---- C:\Windows\system32\hal.dll
2011-07-03 16:59:51 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2011-07-03 16:59:51 ----A---- C:\Windows\system32\drivers\HpSAMD.sys
2011-07-03 16:59:50 ----A---- C:\Windows\system32\scecli.dll
2011-07-03 16:59:50 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2011-07-03 16:59:50 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2011-07-03 16:59:50 ----A---- C:\Windows\system32\DxpTaskSync.dll
2011-07-03 16:59:50 ----A---- C:\Windows\system32\drivers\fvevol.sys
2011-07-03 16:59:49 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2011-07-03 16:59:49 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2011-07-03 16:59:49 ----A---- C:\Windows\system32\sspicli.dll
2011-07-03 16:59:49 ----A---- C:\Windows\system32\puiobj.dll
2011-07-03 16:59:49 ----A---- C:\Windows\system32\nlaapi.dll
2011-07-03 16:59:49 ----A---- C:\Windows\system32\msasn1.dll
2011-07-03 16:59:49 ----A---- C:\Windows\system32\iasrad.dll
2011-07-03 16:59:49 ----A---- C:\Windows\system32\dwmredir.dll
2011-07-03 16:59:49 ----A---- C:\Windows\system32\drivers\ipfltdrv.sys
2011-07-03 16:59:49 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2011-07-03 16:59:48 ----A---- C:\Windows\SYSWOW64\prncache.dll
2011-07-03 16:59:48 ----A---- C:\Windows\system32\themeui.dll
2011-07-03 16:59:48 ----A---- C:\Windows\system32\scrptadm.dll
2011-07-03 16:59:48 ----A---- C:\Windows\system32\onex.dll
2011-07-03 16:59:47 ----A---- C:\Windows\SYSWOW64\WSDApi.dll
2011-07-03 16:59:47 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2011-07-03 16:59:47 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2011-07-03 16:59:47 ----A---- C:\Windows\SYSWOW64\printui.dll
2011-07-03 16:59:47 ----A---- C:\Windows\SYSWOW64\net1.exe
2011-07-03 16:59:47 ----A---- C:\Windows\SYSWOW64\msi.dll
2011-07-03 16:59:47 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2011-07-03 16:59:47 ----A---- C:\Windows\system32\aaclient.dll
2011-07-03 16:59:45 ----A---- C:\Windows\SYSWOW64\scansetting.dll
2011-07-03 16:59:45 ----A---- C:\Windows\system32\wdc.dll
2011-07-03 16:59:44 ----A---- C:\Windows\system32\wlangpui.dll
2011-07-03 16:59:44 ----A---- C:\Windows\system32\scesrv.dll
2011-07-03 16:59:44 ----A---- C:\Windows\system32\rasmans.dll
2011-07-03 16:59:43 ----A---- C:\Windows\system32\msftedit.dll
2011-07-03 16:59:41 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-07-03 16:59:41 ----A---- C:\Windows\system32\sdengin2.dll
2011-07-03 16:59:40 ----A---- C:\Windows\system32\wiadefui.dll
2011-07-03 16:59:40 ----A---- C:\Windows\system32\VAN.dll
2011-07-03 16:59:39 ----A---- C:\Windows\SYSWOW64\MMDevAPI.dll
2011-07-03 16:59:39 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-07-03 16:59:39 ----A---- C:\Windows\system32\netcenter.dll
2011-07-03 16:59:39 ----A---- C:\Windows\system32\dskquoui.dll
2011-07-03 16:59:38 ----A---- C:\Windows\system32\drivers\partmgr.sys
2011-07-03 16:59:37 ----A---- C:\Windows\system32\samcli.dll
2011-07-03 16:59:37 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2011-07-03 16:59:36 ----A---- C:\Windows\system32\wscapi.dll
2011-07-03 16:59:36 ----A---- C:\Windows\system32\SndVol.exe
2011-07-03 16:59:36 ----A---- C:\Windows\system32\iasacct.dll
2011-07-03 16:59:35 ----A---- C:\Windows\SYSWOW64\WMVCORE.DLL
2011-07-03 16:59:35 ----A---- C:\Windows\SYSWOW64\wlangpui.dll
2011-07-03 16:59:35 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2011-07-03 16:59:35 ----A---- C:\Windows\system32\regapi.dll
2011-07-03 16:59:35 ----A---- C:\Windows\system32\drivers\termdd.sys
2011-07-03 16:59:34 ----A---- C:\Windows\system32\wucltux.dll
2011-07-03 16:59:33 ----A---- C:\Windows\SYSWOW64\QSHVHOST.DLL
2011-07-03 16:59:33 ----A---- C:\Windows\SYSWOW64\pnidui.dll
2011-07-03 16:59:33 ----A---- C:\Windows\system32\TabSvc.dll
2011-07-03 16:59:33 ----A---- C:\Windows\system32\srchadmin.dll
2011-07-03 16:59:33 ----A---- C:\Windows\system32\QUTIL.DLL
2011-07-03 16:59:33 ----A---- C:\Windows\system32\consent.exe
2011-07-03 16:59:32 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2011-07-03 16:59:32 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2011-07-03 16:59:31 ----A---- C:\Windows\SYSWOW64\webservices.dll
2011-07-03 16:59:31 ----A---- C:\Windows\SYSWOW64\scrptadm.dll
2011-07-03 16:59:31 ----A---- C:\Windows\SYSWOW64\fde.dll
2011-07-03 16:59:30 ----A---- C:\Windows\system32\WUDFSvc.dll
2011-07-03 16:59:30 ----A---- C:\Windows\system32\setupcl.exe
2011-07-03 16:59:30 ----A---- C:\Windows\system32\drivers\msahci.sys
2011-07-03 16:59:29 ----A---- C:\Windows\SYSWOW64\SyncCenter.dll
2011-07-03 16:59:29 ----A---- C:\Windows\SYSWOW64\netdiagfx.dll
2011-07-03 16:59:29 ----A---- C:\Windows\system32\wksprt.exe
2011-07-03 16:59:29 ----A---- C:\Windows\system32\taskhost.exe
2011-07-03 16:59:29 ----A---- C:\Windows\system32\rastls.dll
2011-07-03 16:59:27 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2011-07-03 16:59:27 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-07-03 16:59:27 ----A---- C:\Windows\system32\drivers\acpi.sys
2011-07-03 16:59:26 ----A---- C:\Windows\system32\tapisrv.dll
2011-07-03 16:59:25 ----A---- C:\Windows\SYSWOW64\WinSCard.dll
2011-07-03 16:59:25 ----A---- C:\Windows\SYSWOW64\pla.dll
2011-07-03 16:59:25 ----A---- C:\Windows\SYSWOW64\msasn1.dll
2011-07-03 16:59:25 ----A---- C:\Windows\SYSWOW64\cscobj.dll
2011-07-03 16:59:25 ----A---- C:\Windows\system32\netiohlp.dll
2011-07-03 16:59:25 ----A---- C:\Windows\system32\msconfig.exe
2011-07-03 16:59:25 ----A---- C:\Windows\system32\mimefilt.dll
2011-07-03 16:59:25 ----A---- C:\Windows\system32\ListSvc.dll
2011-07-03 16:59:25 ----A---- C:\Windows\system32\hgcpl.dll
2011-07-03 16:59:25 ----A---- C:\Windows\system32\drivers\raspptp.sys
2011-07-03 16:59:23 ----A---- C:\Windows\SYSWOW64\winsta.dll
2011-07-03 16:59:23 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2011-07-03 16:59:23 ----A---- C:\Windows\SYSWOW64\MSMPEG2ENC.DLL
2011-07-03 16:59:23 ----A---- C:\Windows\system32\lsmproxy.dll
2011-07-03 16:59:23 ----A---- C:\Windows\system32\fdeploy.dll
2011-07-03 16:59:23 ----A---- C:\Windows\system32\drivers\sbp2port.sys
2011-07-03 16:59:23 ----A---- C:\Windows\system32\drivers\ks.sys
2011-07-03 16:59:23 ----A---- C:\Windows\system32\clusapi.dll
2011-07-03 16:59:23 ----A---- C:\Windows\system32\basecsp.dll
2011-07-03 16:59:23 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2011-07-03 16:59:22 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2011-07-03 16:59:22 ----A---- C:\Windows\system32\mtxclu.dll
2011-07-03 16:59:21 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2011-07-03 16:59:21 ----A---- C:\Windows\SYSWOW64\imapi2.dll
2011-07-03 16:59:21 ----A---- C:\Windows\SYSWOW64\DXPTaskRingtone.dll
2011-07-03 16:59:21 ----A---- C:\Windows\system32\riched20.dll
2011-07-03 16:59:21 ----A---- C:\Windows\system32\dnscmmc.dll
2011-07-03 16:59:20 ----A---- C:\Windows\SYSWOW64\gameux.dll
2011-07-03 16:59:19 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-07-03 16:59:18 ----A---- C:\Windows\system32\RpcRtRemote.dll
2011-07-03 16:59:18 ----A---- C:\Windows\system32\powercpl.dll
2011-07-03 16:59:18 ----A---- C:\Windows\system32\logoncli.dll
2011-07-03 16:59:17 ----A---- C:\Windows\SYSWOW64\WMPEncEn.dll
2011-07-03 16:59:17 ----A---- C:\Windows\SYSWOW64\onex.dll
2011-07-03 16:59:17 ----A---- C:\Windows\system32\sharemediacpl.dll
2011-07-03 16:59:16 ----A---- C:\Windows\SYSWOW64\winmm.dll
2011-07-03 16:59:16 ----A---- C:\Windows\SYSWOW64\shsvcs.dll
2011-07-03 16:59:16 ----A---- C:\Windows\system32\nci.dll
2011-07-03 16:59:15 ----A---- C:\Windows\SYSWOW64\netiohlp.dll
2011-07-03 16:59:15 ----A---- C:\Windows\SYSWOW64\hbaapi.dll
2011-07-03 16:59:15 ----A---- C:\Windows\SYSWOW64\autofmt.exe
2011-07-03 16:59:15 ----A---- C:\Windows\system32\themecpl.dll
2011-07-03 16:59:15 ----A---- C:\Windows\system32\SensorsCpl.dll
2011-07-03 16:59:15 ----A---- C:\Windows\system32\netjoin.dll
2011-07-03 16:59:15 ----A---- C:\Windows\system32\Narrator.exe
2011-07-03 16:59:15 ----A---- C:\Windows\system32\Faultrep.dll
2011-07-03 16:59:15 ----A---- C:\Windows\system32\eudcedit.exe
2011-07-03 16:59:14 ----A---- C:\Windows\SYSWOW64\samcli.dll
2011-07-03 16:59:14 ----A---- C:\Windows\SYSWOW64\IPHLPAPI.DLL
2011-07-03 16:59:14 ----A---- C:\Windows\SYSWOW64\autochk.exe
2011-07-03 16:59:14 ----A---- C:\Windows\system32\wkssvc.dll
2011-07-03 16:59:14 ----A---- C:\Windows\system32\vpnikeapi.dll
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\thumbcache.dll
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\regapi.dll
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\proquota.exe
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\msutb.dll
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\msinfo32.exe
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\mimefilt.dll
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\ipsmsnap.dll
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\autoconv.exe
2011-07-03 16:59:13 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2011-07-03 16:59:13 ----A---- C:\Windows\system32\sppcomapi.dll
2011-07-03 16:59:13 ----A---- C:\Windows\system32\comctl32.dll
2011-07-03 16:59:13 ----A---- C:\Windows\system32\cabview.dll
2011-07-03 16:59:13 ----A---- C:\Windows\system32\autochk.exe
2011-07-03 16:59:13 ----A---- C:\Windows\system32\autofmt.exe
2011-07-03 16:59:12 ----A---- C:\Windows\SYSWOW64\srchadmin.dll
2011-07-03 16:59:12 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-07-03 16:59:12 ----A---- C:\Windows\system32\shsetup.dll
2011-07-03 16:59:12 ----A---- C:\Windows\system32\nshipsec.dll
2011-07-03 16:59:12 ----A---- C:\Windows\system32\fms.dll
2011-07-03 16:59:12 ----A---- C:\Windows\system32\autoconv.exe
2011-07-03 16:59:12 ----A---- C:\Windows\system32\audiodg.exe
2011-07-03 16:59:11 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-07-03 16:59:11 ----A---- C:\Windows\SYSWOW64\tcpipcfg.dll
2011-07-03 16:59:11 ----A---- C:\Windows\SYSWOW64\powercpl.dll
2011-07-03 16:59:11 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2011-07-03 16:59:11 ----A---- C:\Windows\SYSWOW64\framedyn.dll
2011-07-03 16:59:11 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2011-07-03 16:59:11 ----A---- C:\Windows\system32\wwanconn.dll
2011-07-03 16:59:11 ----A---- C:\Windows\system32\wpd_ci.dll
2011-07-03 16:59:11 ----A---- C:\Windows\system32\sdclt.exe
2011-07-03 16:59:11 ----A---- C:\Windows\system32\prntvpt.dll
2011-07-03 16:59:11 ----A---- C:\Windows\system32\drivers\wanarp.sys
2011-07-03 16:59:11 ----A---- C:\Windows\system32\bcdsrv.dll
2011-07-03 16:59:10 ----A---- C:\Windows\system32\wlanui.dll
2011-07-03 16:59:10 ----A---- C:\Windows\system32\drivers\scsiport.sys
2011-07-03 16:59:09 ----A---- C:\Windows\SYSWOW64\QAGENT.DLL
2011-07-03 16:59:09 ----A---- C:\Windows\SYSWOW64\netid.dll
2011-07-03 16:59:09 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2011-07-03 16:59:09 ----A---- C:\Windows\SYSWOW64\AuxiliaryDisplayCpl.dll
2011-07-03 16:59:09 ----A---- C:\Windows\system32\rdpsign.exe
2011-07-03 16:59:09 ----A---- C:\Windows\system32\mscorier.dll
2011-07-03 16:59:09 ----A---- C:\Windows\system32\fontext.dll
2011-07-03 16:59:09 ----A---- C:\Windows\system32\drivers\winusb.sys
2011-07-03 16:59:09 ----A---- C:\Windows\system32\drivers\volmgrx.sys
2011-07-03 16:59:09 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2011-07-03 16:59:09 ----A---- C:\Windows\system32\dps.dll
2011-07-03 16:59:08 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2011-07-03 16:59:08 ----A---- C:\Windows\system32\qedit.dll
2011-07-03 16:59:08 ----A---- C:\Windows\system32\mprddm.dll
2011-07-03 16:59:08 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2011-07-03 16:59:08 ----A---- C:\Windows\system32\drivers\hidclass.sys
2011-07-03 16:59:08 ----A---- C:\Windows\system32\Display.dll
2011-07-03 16:59:08 ----A---- C:\Windows\system32\credssp.dll
2011-07-03 16:59:08 ----A---- C:\Windows\system32\batmeter.dll
2011-07-03 16:59:08 ----A---- C:\Windows\system32\AxInstSv.dll
2011-07-03 16:59:07 ----A---- C:\Windows\SYSWOW64\wdc.dll
2011-07-03 16:59:07 ----A---- C:\Windows\SYSWOW64\Vault.dll
2011-07-03 16:59:07 ----A---- C:\Windows\SYSWOW64\untfs.dll
2011-07-03 16:59:07 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2011-07-03 16:59:07 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2011-07-03 16:59:07 ----A---- C:\Windows\SYSWOW64\rastls.dll
2011-07-03 16:59:07 ----A---- C:\Windows\SYSWOW64\nci.dll
2011-07-03 16:59:07 ----A---- C:\Windows\system32\wmpsrcwp.dll
2011-07-03 16:59:07 ----A---- C:\Windows\system32\mblctr.exe
2011-07-03 16:59:06 ----A---- C:\Windows\SYSWOW64\WMNetMgr.dll
2011-07-03 16:59:06 ----A---- C:\Windows\SYSWOW64\wlanpref.dll
2011-07-03 16:59:06 ----A---- C:\Windows\SYSWOW64\RpcRtRemote.dll
2011-07-03 16:59:06 ----A---- C:\Windows\system32\usercpl.dll
2011-07-03 16:59:06 ----A---- C:\Windows\system32\rtutils.dll
2011-07-03 16:59:06 ----A---- C:\Windows\system32\DiagCpl.dll
2011-07-03 16:59:05 ----A---- C:\Windows\SYSWOW64\Robocopy.exe
2011-07-03 16:59:05 ----A---- C:\Windows\system32\provsvc.dll
2011-07-03 16:59:05 ----A---- C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2011-07-03 16:59:05 ----A---- C:\Windows\system32\bootres.dll
2011-07-03 16:59:04 ----A---- C:\Windows\system32\wpccpl.dll
2011-07-03 16:59:04 ----A---- C:\Windows\system32\sppsvc.exe
2011-07-03 16:59:03 ----A---- C:\Windows\SYSWOW64\taskmgr.exe
2011-07-03 16:59:03 ----A---- C:\Windows\SYSWOW64\mtxclu.dll
2011-07-03 16:59:03 ----A---- C:\Windows\SYSWOW64\DxpTaskSync.dll
2011-07-03 16:59:03 ----A---- C:\Windows\SYSWOW64\Display.dll
2011-07-03 16:59:03 ----A---- C:\Windows\system32\SndVolSSO.dll
2011-07-03 16:59:03 ----A---- C:\Windows\system32\rasppp.dll
2011-07-03 16:59:03 ----A---- C:\Windows\system32\drivers\winhv.sys
2011-07-03 16:59:03 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2011-07-03 16:59:03 ----A---- C:\Windows\system32\dot3cfg.dll
2011-07-03 16:59:02 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-07-03 16:59:02 ----A---- C:\Windows\SYSWOW64\userinit.exe
2011-07-03 16:59:02 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2011-07-03 16:59:02 ----A---- C:\Windows\system32\shdocvw.dll
2011-07-03 16:59:02 ----A---- C:\Windows\system32\hbaapi.dll
2011-07-03 16:59:02 ----A---- C:\Windows\system32\dxdiagn.dll
2011-07-03 16:59:01 ----A---- C:\Windows\SYSWOW64\termmgr.dll
2011-07-03 16:59:01 ----A---- C:\Windows\SYSWOW64\eudcedit.exe
2011-07-03 16:59:01 ----A---- C:\Windows\system32\taskmgr.exe
2011-07-03 16:59:01 ----A---- C:\Windows\system32\proquota.exe
2011-07-03 16:59:01 ----A---- C:\Windows\system32\prnfldr.dll
2011-07-03 16:59:01 ----A---- C:\Windows\system32\pdh.dll
2011-07-03 16:59:01 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2011-07-03 16:59:01 ----A---- C:\Windows\system32\drivers\hwpolicy.sys
2011-07-03 16:59:00 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2011-07-03 16:59:00 ----A---- C:\Windows\system32\drivers\ataport.sys
2011-07-03 16:58:59 ----A---- C:\Windows\SYSWOW64\wiadefui.dll
2011-07-03 16:58:59 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
2011-07-03 16:58:59 ----A---- C:\Windows\SYSWOW64\shsetup.dll
2011-07-03 16:58:59 ----A---- C:\Windows\SYSWOW64\rasppp.dll
2011-07-03 16:58:59 ----A---- C:\Windows\SYSWOW64\logoncli.dll
2011-07-03 16:58:59 ----A---- C:\Windows\SYSWOW64\FirewallControlPanel.dll
2011-07-03 16:58:59 ----A---- C:\Windows\SYSWOW64\cabview.dll
2011-07-03 16:58:59 ----A---- C:\Windows\system32\vpchbuspipe.dll
2011-07-03 16:58:59 ----A---- C:\Windows\system32\userinit.exe
2011-07-03 16:58:59 ----A---- C:\Windows\system32\untfs.dll
2011-07-03 16:58:59 ----A---- C:\Windows\system32\rdpcorekmts.dll
2011-07-03 16:58:59 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2011-07-03 16:58:59 ----A---- C:\Windows\system32\accessibilitycpl.dll
2011-07-03 16:58:58 ----A---- C:\Windows\SYSWOW64\themecpl.dll
2011-07-03 16:58:58 ----A---- C:\Windows\SYSWOW64\SensorsCpl.dll
2011-07-03 16:58:57 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2011-07-03 16:58:57 ----A---- C:\Windows\SYSWOW64\dnscmmc.dll
2011-07-03 16:58:57 ----A---- C:\Windows\system32\zipfldr.dll
2011-07-03 16:58:57 ----A---- C:\Windows\system32\slui.exe
2011-07-03 16:58:57 ----A---- C:\Windows\system32\msieftp.dll
2011-07-03 16:58:57 ----A---- C:\Windows\system32\drivers\storvsc.sys
2011-07-03 16:58:57 ----A---- C:\Windows\system32\defaultlocationcpl.dll
2011-07-03 16:58:56 ----A---- C:\Windows\SYSWOW64\PhotoScreensaver.scr
2011-07-03 16:58:56 ----A---- C:\Windows\SYSWOW64\hgcpl.dll
2011-07-03 16:58:55 ----A---- C:\Windows\SYSWOW64\tapisrv.dll
2011-07-03 16:58:55 ----A---- C:\Windows\SYSWOW64\scecli.dll
2011-07-03 16:58:55 ----A---- C:\Windows\SYSWOW64\mscories.dll
2011-07-03 16:58:55 ----A---- C:\Windows\SYSWOW64\mscms.dll
2011-07-03 16:58:55 ----A---- C:\Windows\SYSWOW64\fontext.dll
2011-07-03 16:58:55 ----A---- C:\Windows\system32\sud.dll
2011-07-03 16:58:55 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2011-07-03 16:58:54 ----A---- C:\Windows\SYSWOW64\mprddm.dll
2011-07-03 16:58:54 ----A---- C:\Windows\SYSWOW64\localsec.dll
2011-07-03 16:58:54 ----A---- C:\Windows\SYSWOW64\iasacct.dll
2011-07-03 16:58:54 ----A---- C:\Windows\system32\networkmap.dll
2011-07-03 16:58:54 ----A---- C:\Windows\system32\dot3svc.dll
2011-07-03 16:58:54 ----A---- C:\Windows\system32\DeviceCenter.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\wlanui.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\VAN.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\usercpl.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\SndVolSSO.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\qedit.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\prntvpt.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\PerfCenterCPL.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\netcenter.dll
2011-07-03 16:58:53 ----A---- C:\Windows\SYSWOW64\batmeter.dll
2011-07-03 16:58:53 ----A---- C:\Windows\system32\twext.dll
2011-07-03 16:58:53 ----A---- C:\Windows\system32\taskbarcpl.dll
2011-07-03 16:58:53 ----A---- C:\Windows\system32\srcore.dll
2011-07-03 16:58:53 ----A---- C:\Windows\system32\rdpwsx.dll
2011-07-03 16:58:53 ----A---- C:\Windows\system32\qdvd.dll
2011-07-03 16:58:53 ----A---- C:\Windows\system32\OnLineIDCpl.dll
2011-07-03 16:58:53 ----A---- C:\Windows\system32\cryptui.dll
2011-07-03 16:58:53 ----A---- C:\Windows\system32\ActionCenter.dll
2011-07-03 16:58:52 ----A---- C:\Windows\SYSWOW64\w32tm.exe
2011-07-03 16:58:52 ----A---- C:\Windows\SYSWOW64\SndVol.exe
2011-07-03 16:58:52 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2011-07-03 16:58:52 ----A---- C:\Windows\system32\uxlib.dll
2011-07-03 16:58:52 ----A---- C:\Windows\system32\recovery.dll
2011-07-03 16:58:52 ----A---- C:\Windows\system32\OobeFldr.dll
2011-07-03 16:58:52 ----A---- C:\Windows\system32\bcdedit.exe
2011-07-03 16:58:52 ----A---- C:\Windows\system32\azroleui.dll
2011-07-03 16:58:51 ----A---- C:\Windows\SYSWOW64\zipfldr.dll
2011-07-03 16:58:51 ----A---- C:\Windows\SYSWOW64\spwizeng.dll
2011-07-03 16:58:51 ----A---- C:\Windows\SYSWOW64\azroleui.dll
2011-07-03 16:58:51 ----A---- C:\Windows\SYSWOW64\accessibilitycpl.dll
2011-07-03 16:58:51 ----A---- C:\Windows\system32\tzutil.exe
2011-07-03 16:58:51 ----A---- C:\Windows\system32\sisbkup.dll
2011-07-03 16:58:51 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2011-07-03 16:58:51 ----A---- C:\Windows\system32\isoburn.exe
2011-07-03 16:58:51 ----A---- C:\Windows\system32\efscore.dll
2011-07-03 16:58:51 ----A---- C:\Windows\system32\dsuiext.dll
2011-07-03 16:58:51 ----A---- C:\Windows\system32\cca.dll
2011-07-03 16:58:51 ----A---- C:\Windows\system32\asycfilt.dll
2011-07-03 16:58:50 ----A---- C:\Windows\SYSWOW64\MSAC3ENC.DLL
2011-07-03 16:58:50 ----A---- C:\Windows\SYSWOW64\fdeploy.dll
2011-07-03 16:58:50 ----A---- C:\Windows\system32\systemcpl.dll
2011-07-03 16:58:50 ----A---- C:\Windows\system32\syncui.dll
2011-07-03 16:58:50 ----A---- C:\Windows\system32\sdcpl.dll
2011-07-03 16:58:50 ----A---- C:\Windows\system32\recdisc.exe
2011-07-03 16:58:50 ----A---- C:\Windows\system32\netplwiz.dll
2011-07-03 16:58:50 ----A---- C:\Windows\system32\httpapi.dll
2011-07-03 16:58:50 ----A---- C:\Windows\system32\autoplay.dll
2011-07-03 16:58:49 ----A---- C:\Windows\SYSWOW64\networkmap.dll
2011-07-03 16:58:49 ----A---- C:\Windows\SYSWOW64\netjoin.dll
2011-07-03 16:58:49 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2011-07-03 16:58:49 ----A---- C:\Windows\SYSWOW64\adsldp.dll
2011-07-03 16:58:49 ----A---- C:\Windows\system32\sysclass.dll
2011-07-03 16:58:49 ----A---- C:\Windows\system32\sspisrv.dll
2011-07-03 16:58:49 ----A---- C:\Windows\system32\shwebsvc.dll
2011-07-03 16:58:49 ----A---- C:\Windows\system32\sdrsvc.dll
2011-07-03 16:58:49 ----A---- C:\Windows\system32\ncryptui.dll
2011-07-03 16:58:49 ----A---- C:\Windows\system32\fvecpl.dll
2011-07-03 16:58:49 ----A---- C:\Windows\system32\drivers\rdpdr.sys
2011-07-03 16:58:49 ----A---- C:\Windows\system32\drivers\mpio.sys
2011-07-03 16:58:49 ----A---- C:\Windows\system32\certcli.dll
2011-07-03 16:58:49 ----A---- C:\Windows\system32\appinfo.dll
2011-07-03 16:58:48 ----A---- C:\Windows\SYSWOW64\wusa.exe
2011-07-03 16:58:48 ----A---- C:\Windows\SYSWOW64\MCEWMDRMNDBootstrap.dll
2011-07-03 16:58:48 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2011-07-03 16:58:48 ----A---- C:\Windows\system32\wlanmsm.dll
2011-07-03 16:58:48 ----A---- C:\Windows\system32\msvidc32.dll
2011-07-03 16:58:48 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2011-07-03 16:58:48 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2011-07-03 16:58:47 ----A---- C:\Windows\SYSWOW64\sud.dll
2011-07-03 16:58:47 ----A---- C:\Windows\SYSWOW64\prnfldr.dll
2011-07-03 16:58:47 ----A---- C:\Windows\SYSWOW64\photowiz.dll
2011-07-03 16:58:47 ----A---- C:\Windows\SYSWOW64\OnLineIDCpl.dll
2011-07-03 16:58:47 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2011-07-03 16:58:47 ----A---- C:\Windows\SYSWOW64\MediaMetadataHandler.dll
2011-07-03 16:58:47 ----A---- C:\Windows\SYSWOW64\credssp.dll
2011-07-03 16:58:47 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2011-07-03 16:58:47 ----A---- C:\Windows\system32\vdsutil.dll
2011-07-03 16:58:47 ----A---- C:\Windows\system32\termmgr.dll
2011-07-03 16:58:47 ----A---- C:\Windows\system32\spwizeng.dll
2011-07-03 16:58:47 ----A---- C:\Windows\system32\MFPlay.dll
2011-07-03 16:58:46 ----A---- C:\Windows\SYSWOW64\iprtrmgr.dll
2011-07-03 16:58:46 ----A---- C:\Windows\SYSWOW64\iasrad.dll
2011-07-03 16:58:46 ----A---- C:\Windows\SYSWOW64\defaultlocationcpl.dll
2011-07-03 16:58:46 ----A---- C:\Windows\system32\sethc.exe
2011-07-03 16:58:46 ----A---- C:\Windows\system32\rstrui.exe
2011-07-03 16:58:46 ----A---- C:\Windows\system32\odbccp32.dll
2011-07-03 16:58:46 ----A---- C:\Windows\system32\msscp.dll
2011-07-03 16:58:45 ----A---- C:\Windows\SYSWOW64\sisbkup.dll
2011-07-03 16:58:45 ----A---- C:\Windows\SYSWOW64\shwebsvc.dll
2011-07-03 16:58:45 ----A---- C:\Windows\SYSWOW64\ifsutil.dll
2011-07-03 16:58:45 ----A---- C:\Windows\SYSWOW64\ftp.exe
2011-07-03 16:58:45 ----A---- C:\Windows\SYSWOW64\dot3cfg.dll
2011-07-03 16:58:45 ----A---- C:\Windows\system32\tsgqec.dll
2011-07-03 16:58:45 ----A---- C:\Windows\system32\sqlcese30.dll
2011-07-03 16:58:45 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2011-07-03 16:58:45 ----A---- C:\Windows\system32\ReAgent.dll
2011-07-03 16:58:45 ----A---- C:\Windows\system32\ntlanman.dll
2011-07-03 16:58:45 ----A---- C:\Windows\system32\drivers\ndproxy.sys
2011-07-03 16:58:44 ----A---- C:\Windows\SYSWOW64\efscore.dll
2011-07-03 16:58:44 ----A---- C:\Windows\system32\wwanprotdim.dll
2011-07-03 16:58:44 ----A---- C:\Windows\system32\UserAccountControlSettings.dll
2011-07-03 16:58:44 ----A---- C:\Windows\system32\secur32.dll
2011-07-03 16:58:44 ----A---- C:\Windows\system32\rdpd3d.dll
2011-07-03 16:58:44 ----A---- C:\Windows\system32\iprtrmgr.dll
2011-07-03 16:58:43 ----A---- C:\Windows\SYSWOW64\syncui.dll
2011-07-03 16:58:43 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-07-03 16:58:43 ----A---- C:\Windows\SYSWOW64\DeviceCenter.dll
2011-07-03 16:58:43 ----A---- C:\Windows\SYSWOW64\autoplay.dll
2011-07-03 16:58:43 ----A---- C:\Windows\SYSWOW64\ActionCenterCPL.dll
2011-07-03 16:58:43 ----A---- C:\Windows\system32\wmdrmsdk.dll
2011-07-03 16:58:43 ----A---- C:\Windows\system32\ssText3d.scr
2011-07-03 16:58:43 ----A---- C:\Windows\system32\srvcli.dll
2011-07-03 16:58:43 ----A---- C:\Windows\system32\slwga.dll
2011-07-03 16:58:43 ----A---- C:\Windows\system32\odbctrac.dll
2011-07-03 16:58:43 ----A---- C:\Windows\system32\iyuv_32.dll
2011-07-03 16:58:43 ----A---- C:\Windows\system32\iTVData.dll
2011-07-03 16:58:43 ----A---- C:\Windows\system32\drmmgrtn.dll
2011-07-03 16:58:43 ----A---- C:\Windows\system32\drivers\vmstorfl.sys
2011-07-03 16:58:42 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2011-07-03 16:58:42 ----A---- C:\Windows\SYSWOW64\ntlanman.dll
2011-07-03 16:58:42 ----A---- C:\Windows\SYSWOW64\dskquoui.dll
2011-07-03 16:58:42 ----A---- C:\Windows\system32\msiexec.exe
2011-07-03 16:58:41 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2011-07-03 16:58:41 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2011-07-03 16:58:41 ----A---- C:\Windows\SYSWOW64\sethc.exe
2011-07-03 16:58:41 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2011-07-03 16:58:41 ----A---- C:\Windows\SYSWOW64\riched20.dll
2011-07-03 16:58:41 ----A---- C:\Windows\SYSWOW64\OobeFldr.dll
2011-07-03 16:58:41 ----A---- C:\Windows\SYSWOW64\ntprint.dll
2011-07-03 16:58:41 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2011-07-03 16:58:41 ----A---- C:\Windows\system32\wavemsp.dll
2011-07-03 16:58:41 ----A---- C:\Windows\system32\srrstr.dll
2011-07-03 16:58:41 ----A---- C:\Windows\system32\ntprint.dll
2011-07-03 16:58:41 ----A---- C:\Windows\system32\nslookup.exe
2011-07-03 16:58:41 ----A---- C:\Windows\system32\NAPHLPR.DLL
2011-07-03 16:58:41 ----A---- C:\Windows\system32\DevicePairingFolder.dll
2011-07-03 16:58:41 ----A---- C:\Windows\system32\bcdboot.exe
2011-07-03 16:58:41 ----A---- C:\Windows\system32\acppage.dll
2011-07-03 16:58:40 ----A---- C:\Windows\SYSWOW64\NAPHLPR.DLL
2011-07-03 16:58:40 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2011-07-03 16:58:40 ----A---- C:\Windows\system32\sppnp.dll
2011-07-03 16:58:39 ----A---- C:\Windows\SYSWOW64\wmpsrcwp.dll
2011-07-03 16:58:39 ----A---- C:\Windows\SYSWOW64\netplwiz.dll
2011-07-03 16:58:39 ----A---- C:\Windows\SYSWOW64\migisol.dll
2011-07-03 16:58:39 ----A---- C:\Windows\SYSWOW64\fms.dll
2011-07-03 16:58:39 ----A---- C:\Windows\SYSWOW64\activeds.dll
2011-07-03 16:58:39 ----A---- C:\Windows\system32\TSpkg.dll
2011-07-03 16:58:39 ----A---- C:\Windows\system32\networkexplorer.dll
2011-07-03 16:58:39 ----A---- C:\Windows\system32\fsquirt.exe
2011-07-03 16:58:39 ----A---- C:\Windows\system32\certprop.dll
2011-07-03 16:58:39 ----A---- C:\Windows\system32\cabinet.dll
2011-07-03 16:58:38 ----A---- C:\Windows\SYSWOW64\nshipsec.dll
2011-07-03 16:58:38 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2011-07-03 16:58:38 ----A---- C:\Windows\SYSWOW64\httpapi.dll
2011-07-03 16:58:38 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2011-07-03 16:58:38 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2011-07-03 16:58:38 ----A---- C:\Windows\system32\wkscli.dll
2011-07-03 16:58:38 ----A---- C:\Windows\system32\remotepg.dll
2011-07-03 16:58:38 ----A---- C:\Windows\system32\PresentationSettings.exe
2011-07-03 16:58:38 ----A---- C:\Windows\system32\cdosys.dll
2011-07-03 16:58:37 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2011-07-03 16:58:37 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll
2011-07-03 16:58:37 ----A---- C:\Windows\SYSWOW64\wavemsp.dll
2011-07-03 16:58:37 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2011-07-03 16:58:37 ----A---- C:\Windows\SYSWOW64\provsvc.dll
2011-07-03 16:58:37 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2011-07-03 16:58:37 ----A---- C:\Windows\SYSWOW64\isoburn.exe
2011-07-03 16:58:37 ----A---- C:\Windows\SYSWOW64\dot3ui.dll
2011-07-03 16:58:37 ----A---- C:\Windows\system32\wsnmp32.dll
2011-07-03 16:58:37 ----A---- C:\Windows\system32\wmpdxm.dll
2011-07-03 16:58:37 ----A---- C:\Windows\system32\WinSCard.dll
2011-07-03 16:58:37 ----A---- C:\Windows\system32\net1.exe
2011-07-03 16:58:37 ----A---- C:\Windows\system32\ftp.exe
2011-07-03 16:58:37 ----A---- C:\Windows\system32\dfrgui.exe
2011-07-03 16:58:36 ----A---- C:\Windows\SYSWOW64\tzutil.exe
2011-07-03 16:58:36 ----A---- C:\Windows\SYSWOW64\ocsetup.exe
2011-07-03 16:58:36 ----A---- C:\Windows\SYSWOW64\dsuiext.dll
2011-07-03 16:58:36 ----A---- C:\Windows\SYSWOW64\dfrgui.exe
2011-07-03 16:58:36 ----A---- C:\Windows\system32\wvc.dll
2011-07-03 16:58:36 ----A---- C:\Windows\system32\wuwebv.dll
2011-07-03 16:58:36 ----A---- C:\Windows\system32\wsqmcons.exe
2011-07-03 16:58:36 ----A---- C:\Windows\system32\wmdrmdev.dll
2011-07-03 16:58:36 ----A---- C:\Windows\system32\WerFaultSecure.exe
2011-07-03 16:58:36 ----A---- C:\Windows\system32\blackbox.dll
2011-07-03 16:58:35 ----A---- C:\Windows\SYSWOW64\wvc.dll
2011-07-03 16:58:35 ----A---- C:\Windows\SYSWOW64\wtsapi32.dll
2011-07-03 16:58:35 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2011-07-03 16:58:35 ----A---- C:\Windows\SYSWOW64\twext.dll
2011-07-03 16:58:35 ----A---- C:\Windows\SYSWOW64\mstask.dll
2011-07-03 16:58:35 ----A---- C:\Windows\SYSWOW64\AdmTmpl.dll
2011-07-03 16:58:35 ----A---- C:\Windows\system32\msyuv.dll
2011-07-03 16:58:35 ----A---- C:\Windows\system32\mfps.dll
2011-07-03 16:58:34 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-07-03 16:58:33 ----A---- C:\Windows\twain_32.dll
2011-07-03 16:58:33 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2011-07-03 16:58:33 ----A---- C:\Windows\SYSWOW64\setupugc.exe
2011-07-03 16:58:33 ----A---- C:\Windows\SYSWOW64\qcap.dll
2011-07-03 16:58:33 ----A---- C:\Windows\SYSWOW64\qasf.dll
2011-07-03 16:58:33 ----A---- C:\Windows\system32\WUDFPlatform.dll
2011-07-03 16:58:33 ----A---- C:\Windows\system32\unimdmat.dll
2011-07-03 16:58:33 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2011-07-03 16:58:33 ----A---- C:\Windows\system32\OpcServices.dll
2011-07-03 16:58:33 ----A---- C:\Windows\system32\msrle32.dll
2011-07-03 16:58:33 ----A---- C:\Windows\system32\mapistub.dll
2011-07-03 16:58:33 ----A---- C:\Windows\system32\mapi32.dll
2011-07-03 16:58:33 ----A---- C:\Windows\system32\iscsium.dll
2011-07-03 16:58:33 ----A---- C:\Windows\system32\Bubbles.scr
2011-07-03 16:58:32 ----A---- C:\Windows\SYSWOW64\uxlib.dll
2011-07-03 16:58:32 ----A---- C:\Windows\system32\diskraid.exe
2011-07-03 16:58:31 ----A---- C:\Windows\SYSWOW64\ssText3d.scr
2011-07-03 16:58:31 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-07-03 16:58:31 ----A---- C:\Windows\SYSWOW64\msvfw32.dll
2011-07-03 16:58:31 ----A---- C:\Windows\system32\tsbyuv.dll
2011-07-03 16:58:31 ----A---- C:\Windows\system32\seclogon.dll
2011-07-03 16:58:31 ----A---- C:\Windows\system32\Ribbons.scr
2011-07-03 16:58:31 ----A---- C:\Windows\system32\Mystify.scr
2011-07-03 16:58:31 ----A---- C:\Windows\system32\ifsutil.dll
2011-07-03 16:58:30 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2011-07-03 16:58:30 ----A---- C:\Windows\SYSWOW64\nslookup.exe
2011-07-03 16:58:30 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2011-07-03 16:58:30 ----A---- C:\Windows\SYSWOW64\audiodev.dll
2011-07-03 16:58:30 ----A---- C:\Windows\system32\muifontsetup.dll
2011-07-03 16:58:30 ----A---- C:\Windows\system32\drivers\umbus.sys
2011-07-03 16:58:30 ----A---- C:\Windows\system32\d3d10level9.dll
2011-07-03 16:58:29 ----A---- C:\Windows\SYSWOW64\WPDShServiceObj.dll
2011-07-03 16:58:29 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2011-07-03 16:58:29 ----A---- C:\Windows\SYSWOW64\msscp.dll
2011-07-03 16:58:29 ----A---- C:\Windows\SYSWOW64\diskraid.exe
2011-07-03 16:58:29 ----A---- C:\Windows\SYSWOW64\DevicePairingFolder.dll
2011-07-03 16:58:29 ----A---- C:\Windows\SYSWOW64\clusapi.dll
2011-07-03 16:58:29 ----A---- C:\Windows\system32\wmpshell.dll
2011-07-03 16:58:29 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2011-07-03 16:58:29 ----A---- C:\Windows\system32\rdpencom.dll
2011-07-03 16:58:29 ----A---- C:\Windows\system32\perfmon.exe
2011-07-03 16:58:29 ----A---- C:\Windows\system32\netutils.dll
2011-07-03 16:58:29 ----A---- C:\Windows\system32\AzSqlExt.dll
2011-07-03 16:58:28 ----A---- C:\Windows\SYSWOW64\wimserv.exe
2011-07-03 16:58:28 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2011-07-03 16:58:28 ----A---- C:\Windows\SYSWOW64\rdpencom.dll
2011-07-03 16:58:28 ----A---- C:\Windows\SYSWOW64\perfmon.exe
2011-07-03 16:58:28 ----A---- C:\Windows\SYSWOW64\acppage.dll
2011-07-03 16:58:28 ----A---- C:\Windows\system32\umb.dll
2011-07-03 16:58:28 ----A---- C:\Windows\system32\tlscsp.dll
2011-07-03 16:58:28 ----A---- C:\Windows\system32\runonce.exe
2011-07-03 16:58:28 ----A---- C:\Windows\system32\qasf.dll
2011-07-03 16:58:28 ----A---- C:\Windows\system32\NAPCRYPT.DLL
2011-07-03 16:58:28 ----A---- C:\Windows\system32\FXSAPI.dll
2011-07-03 16:58:28 ----A---- C:\Windows\system32\dbghelp.dll
2011-07-03 16:58:28 ----A---- C:\Windows\system32\browser.dll
2011-07-03 16:58:28 ----A---- C:\Windows\system32\ActionQueue.dll
2011-07-03 16:58:27 ----A---- C:\Windows\SYSWOW64\remotepg.dll
2011-07-03 16:58:27 ----A---- C:\Windows\SYSWOW64\raschap.dll
2011-07-03 16:58:27 ----A---- C:\Windows\SYSWOW64\QUTIL.DLL
2011-07-03 16:58:27 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-07-03 16:58:27 ----A---- C:\Windows\SYSWOW64\NAPCRYPT.DLL
2011-07-03 16:58:27 ----A---- C:\Windows\SYSWOW64\input.dll
2011-07-03 16:58:27 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2011-07-03 16:58:27 ----A---- C:\Windows\system32\wpdwcn.dll
2011-07-03 16:58:27 ----A---- C:\Windows\system32\WMADMOD.DLL
2011-07-03 16:58:27 ----A---- C:\Windows\system32\wiavideo.dll
2011-07-03 16:58:27 ----A---- C:\Windows\system32\syssetup.dll
2011-07-03 16:58:27 ----A---- C:\Windows\system32\raschap.dll
2011-07-03 16:58:27 ----A---- C:\Windows\bfsvc.exe
2011-07-03 16:58:26 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2011-07-03 16:58:26 ----A---- C:\Windows\SYSWOW64\vpnikeapi.dll
2011-07-03 16:58:26 ----A---- C:\Windows\SYSWOW64\UserAccountControlSettings.dll
2011-07-03 16:58:26 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2011-07-03 16:58:26 ----A---- C:\Windows\SYSWOW64\ocsetapi.dll
2011-07-03 16:58:26 ----A---- C:\Windows\SYSWOW64\networkexplorer.dll
2011-07-03 16:58:26 ----A---- C:\Windows\system32\vdsbas.dll
2011-07-03 16:58:26 ----A---- C:\Windows\system32\PrintIsolationProxy.dll
2011-07-03 16:58:26 ----A---- C:\Windows\system32\MdSched.exe
2011-07-03 16:58:25 ----A---- C:\Windows\SYSWOW64\wpdwcn.dll
2011-07-03 16:58:25 ----A---- C:\Windows\SYSWOW64\vdsbas.dll
2011-07-03 16:58:25 ----A---- C:\Windows\SYSWOW64\runonce.exe
2011-07-03 16:58:25 ----A---- C:\Windows\SYSWOW64\onexui.dll
2011-07-03 16:58:25 ----A---- C:\Windows\SYSWOW64\iTVData.dll
2011-07-03 16:58:25 ----A---- C:\Windows\SYSWOW64\dxdiagn.dll
2011-07-03 16:58:25 ----A---- C:\Windows\system32\WMVSDECD.DLL
2011-07-03 16:58:25 ----A---- C:\Windows\system32\nltest.exe
2011-07-03 16:58:25 ----A---- C:\Windows\system32\mstask.dll
2011-07-03 16:58:25 ----A---- C:\Windows\system32\Mcx2Svc.dll
2011-07-03 16:58:25 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2011-07-03 16:58:25 ----A---- C:\Windows\system32\drivers\rmcast.sys
2011-07-03 16:58:24 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2011-07-03 16:58:24 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2011-07-03 16:58:24 ----A---- C:\Windows\SYSWOW64\logagent.exe
2011-07-03 16:58:24 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2011-07-03 16:58:24 ----A---- C:\Windows\system32\bitsadmin.exe
2011-07-03 16:58:23 ----A---- C:\Windows\SYSWOW64\wmdrmdev.dll
2011-07-03 16:58:23 ----A---- C:\Windows\SYSWOW64\shacct.dll
2011-07-03 16:58:23 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2011-07-03 16:58:23 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2011-07-03 16:58:23 ----A---- C:\Windows\system32\wmdrmnet.dll
2011-07-03 16:58:23 ----A---- C:\Windows\system32\vss_ps.dll
2011-07-03 16:58:23 ----A---- C:\Windows\system32\tabcal.exe
2011-07-03 16:58:23 ----A---- C:\Windows\system32\shacct.dll
2011-07-03 16:58:23 ----A---- C:\Windows\system32\QSVRMGMT.DLL
2011-07-03 16:58:23 ----A---- C:\Windows\system32\drivers\USBAUDIO.sys
2011-07-03 16:58:23 ----A---- C:\Windows\system32\cscapi.dll
2011-07-03 16:58:22 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2011-07-03 16:58:22 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2011-07-03 16:58:22 ----A---- C:\Windows\SYSWOW64\lsmproxy.dll
2011-07-03 16:58:22 ----A---- C:\Windows\SYSWOW64\bitsadmin.exe
2011-07-03 16:58:22 ----A---- C:\Windows\system32\wudriver.dll
2011-07-03 16:58:22 ----A---- C:\Windows\system32\WPDSp.dll
2011-07-03 16:58:22 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2011-07-03 16:58:22 ----A---- C:\Windows\system32\qcap.dll
2011-07-03 16:58:22 ----A---- C:\Windows\system32\msnetobj.dll
2011-07-03 16:58:22 ----A---- C:\Windows\system32\logman.exe
2011-07-03 16:58:21 ----A---- C:\Windows\SYSWOW64\unimdmat.dll
2011-07-03 16:58:21 ----A---- C:\Windows\SYSWOW64\sqlcese30.dll
2011-07-03 16:58:21 ----A---- C:\Windows\SYSWOW64\rdpd3d.dll
2011-07-03 16:58:21 ----A---- C:\Windows\SYSWOW64\iscsium.dll
2011-07-03 16:58:21 ----A---- C:\Windows\SYSWOW64\Bubbles.scr
2011-07-03 16:58:21 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2011-07-03 16:58:21 ----A---- C:\Windows\system32\secproc_ssp.dll
2011-07-03 16:58:21 ----A---- C:\Windows\system32\PortableDeviceSyncProvider.dll
2011-07-03 16:58:21 ----A---- C:\Windows\system32\CscMig.dll
2011-07-03 16:58:20 ----A---- C:\Windows\SYSWOW64\mprapi.dll
2011-07-03 16:58:20 ----A---- C:\Windows\system32\vmictimeprovider.dll
2011-07-03 16:58:20 ----A---- C:\Windows\system32\qdv.dll
2011-07-03 16:58:14 ----A---- C:\Windows\SYSWOW64\pdh.dll
2011-07-03 16:58:14 ----A---- C:\Windows\SYSWOW64\cscapi.dll
2011-07-03 16:58:13 ----A---- C:\Windows\SYSWOW64\WPDSp.dll
2011-07-03 16:58:13 ----A---- C:\Windows\SYSWOW64\srvcli.dll
2011-07-03 16:58:13 ----A---- C:\Windows\SYSWOW64\PortableDeviceSyncProvider.dll
2011-07-03 16:58:13 ----A---- C:\Windows\SYSWOW64\OpcServices.dll
2011-07-03 16:58:13 ----A---- C:\Windows\SYSWOW64\olethk32.dll
2011-07-03 16:58:13 ----A---- C:\Windows\SYSWOW64\ncryptui.dll
2011-07-03 16:58:13 ----A---- C:\Windows\SYSWOW64\logman.exe
2011-07-03 16:58:13 ----A---- C:\Windows\system32\spbcd.dll
2011-07-03 16:58:13 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2011-07-03 16:58:13 ----A---- C:\Windows\system32\fphc.dll
2011-07-03 16:58:13 ----A---- C:\Windows\system32\drivers\ndisuio.sys
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\Ribbons.scr
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\QSVRMGMT.DLL
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\PortableDeviceStatus.dll
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\Mystify.scr
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\mapistub.dll
2011-07-03 16:58:12 ----A---- C:\Windows\SYSWOW64\mapi32.dll
2011-07-03 16:58:12 ----A---- C:\Windows\system32\takeown.exe
2011-07-03 16:58:12 ----A---- C:\Windows\system32\PnPUnattend.exe
2011-07-03 16:58:12 ----A---- C:\Windows\system32\dot3ui.dll
2011-07-03 16:58:11 ----A---- C:\Windows\SYSWOW64\WMADMOD.DLL
2011-07-03 16:58:11 ----A---- C:\Windows\SYSWOW64\wiavideo.dll
2011-07-03 16:58:11 ----A---- C:\Windows\SYSWOW64\utildll.dll
2011-07-03 16:58:11 ----A---- C:\Windows\SYSWOW64\takeown.exe
2011-07-03 16:58:11 ----A---- C:\Windows\SYSWOW64\fphc.dll
2011-07-03 16:58:11 ----A---- C:\Windows\SYSWOW64\dot3msm.dll
2011-07-03 16:58:11 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2011-07-03 16:58:11 ----A---- C:\Windows\system32\WMPhoto.dll
2011-07-03 16:58:11 ----A---- C:\Windows\system32\EhStorAPI.dll
2011-07-03 16:58:11 ----A---- C:\Windows\system32\amstream.dll
2011-07-03 16:58:10 ----A---- C:\Windows\SYSWOW64\WMVSDECD.DLL
2011-07-03 16:58:10 ----A---- C:\Windows\SYSWOW64\wmdrmnet.dll
2011-07-03 16:58:10 ----A---- C:\Windows\SYSWOW64\sqmapi.dll
2011-07-03 16:58:10 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2011-07-03 16:58:10 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2011-07-03 16:58:10 ----A---- C:\Windows\system32\vfwwdm32.dll
2011-07-03 16:58:10 ----A---- C:\Windows\system32\shimgvw.dll
2011-07-03 16:58:10 ----A---- C:\Windows\system32\QCLIPROV.DLL
2011-07-03 16:58:10 ----A---- C:\Windows\system32\netapi32.dll
2011-07-03 16:58:10 ----A---- C:\Windows\system32\HotStartUserAgent.dll
2011-07-03 16:58:10 ----A---- C:\Windows\system32\djoin.exe
2011-07-03 16:58:09 ----A---- C:\Windows\SYSWOW64\sppinst.dll
2011-07-03 16:58:09 ----A---- C:\Windows\SYSWOW64\qdv.dll
2011-07-03 16:58:09 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2011-07-03 16:58:09 ----A---- C:\Windows\SYSWOW64\EhStorAPI.dll
2011-07-03 16:58:09 ----A---- C:\Windows\system32\WUDFHost.exe
2011-07-03 16:58:09 ----A---- C:\Windows\system32\nrpsrv.dll
2011-07-03 16:58:09 ----A---- C:\Windows\system32\iasrecst.dll
2011-07-03 16:58:09 ----A---- C:\Windows\system32\cmstp.exe
2011-07-03 16:58:09 ----A---- C:\Windows\system32\CertPolEng.dll
2011-07-03 16:58:08 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2011-07-03 16:58:08 ----A---- C:\Windows\system32\WUDFx.dll
2011-07-03 16:58:08 ----A---- C:\Windows\system32\WavDest.dll
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\wsnmp32.dll
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\WMSPDMOD.DLL
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\vfwwdm32.dll
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\QCLIPROV.DLL
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\pdhui.dll
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\MuiUnattend.exe
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\cmstp.exe
2011-07-03 16:58:07 ----A---- C:\Windows\SYSWOW64\cca.dll
2011-07-03 16:58:07 ----A---- C:\Windows\system32\MultiDigiMon.exe
2011-07-03 16:58:07 ----A---- C:\Windows\system32\KMSVC.DLL
2011-07-03 16:58:07 ----A---- C:\Windows\system32\fdProxy.dll
2011-07-03 16:58:07 ----A---- C:\Windows\system32\drivers\usbser.sys
2011-07-03 16:58:07 ----A---- C:\Windows\system32\drivers\pacer.sys
2011-07-03 16:58:06 ----A---- C:\Windows\SYSWOW64\setupcln.dll
2011-07-03 16:58:06 ----A---- C:\Windows\system32\wuauclt.exe
2011-07-03 16:58:06 ----A---- C:\Windows\system32\relog.exe
2011-07-03 16:58:06 ----A---- C:\Windows\system32\mydocs.dll
2011-07-03 16:58:05 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2011-07-03 16:58:05 ----A---- C:\Windows\SYSWOW64\relog.exe
2011-07-03 16:58:05 ----A---- C:\Windows\SYSWOW64\netiougc.exe
2011-07-03 16:58:05 ----A---- C:\Windows\SYSWOW64\msorcl32.dll
2011-07-03 16:58:05 ----A---- C:\Windows\SYSWOW64\iasrecst.dll
2011-07-03 16:58:05 ----A---- C:\Windows\SYSWOW64\AzSqlExt.dll
2011-07-03 16:58:05 ----A---- C:\Windows\system32\sscore.dll
2011-07-03 16:58:05 ----A---- C:\Windows\system32\mobsync.exe
2011-07-03 16:58:05 ----A---- C:\Windows\system32\iscsicli.exe
2011-07-03 16:58:05 ----A---- C:\Windows\system32\diskpart.exe
2011-07-03 16:58:05 ----A---- C:\Windows\system32\BWUnpairElevated.dll
2011-07-03 16:58:04 ----A---- C:\Windows\SYSWOW64\wkscli.dll
2011-07-03 16:58:04 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2011-07-03 16:58:04 ----A---- C:\Windows\SYSWOW64\iscsicli.exe
2011-07-03 16:58:04 ----A---- C:\Windows\system32\itircl.dll
2011-07-03 16:58:04 ----A---- C:\Windows\system32\BdeHdCfg.exe
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\resutils.dll
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\rastapi.dll
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\netbtugc.exe
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\mydocs.dll
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\itircl.dll
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\diskpart.exe
2011-07-03 16:58:03 ----A---- C:\Windows\SYSWOW64\amstream.dll
2011-07-03 16:58:03 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2011-07-03 16:58:03 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2011-07-03 16:58:03 ----A---- C:\Windows\system32\msdmo.dll
2011-07-03 16:58:03 ----A---- C:\Windows\system32\dot3msm.dll
2011-07-03 16:58:03 ----A---- C:\Windows\system32\browcli.dll
2011-07-03 16:58:02 ----A---- C:\Windows\SYSWOW64\wmpps.dll
2011-07-03 16:58:02 ----A---- C:\Windows\SYSWOW64\syssetup.dll
2011-07-03 16:58:02 ----A---- C:\Windows\SYSWOW64\CertPolEng.dll
2011-07-03 16:58:02 ----A---- C:\Windows\system32\wuapp.exe
2011-07-03 16:58:02 ----A---- C:\Windows\system32\qprocess.exe
2011-07-03 16:58:02 ----A---- C:\Windows\system32\mciqtz32.dll
2011-07-03 16:58:02 ----A---- C:\Windows\system32\choice.exe
2011-07-03 16:58:02 ----A---- C:\Windows\system32\FXSTIFF.dll
2011-07-03 16:58:02 ----A---- C:\Windows\system32\findstr.exe
2011-07-03 16:58:02 ----A---- C:\Windows\system32\eappgnui.dll
2011-07-03 16:58:01 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2011-07-03 16:58:01 ----A---- C:\Windows\SYSWOW64\WerFaultSecure.exe
2011-07-03 16:58:01 ----A---- C:\Windows\SYSWOW64\tlscsp.dll
2011-07-03 16:58:01 ----A---- C:\Windows\SYSWOW64\secur32.dll
2011-07-03 16:58:01 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2011-07-03 16:58:01 ----A---- C:\Windows\SYSWOW64\ReAgentc.exe
2011-07-03 16:58:01 ----A---- C:\Windows\SYSWOW64\findstr.exe
2011-07-03 16:58:01 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2011-07-03 16:58:01 ----A---- C:\Windows\system32\sppc.dll
2011-07-03 16:58:01 ----A---- C:\Windows\system32\luainstall.dll
2011-07-03 16:58:01 ----A---- C:\Windows\system32\imagehlp.dll
2011-07-03 16:58:01 ----A---- C:\Windows\system32\drivers\tunnel.sys
2011-07-03 16:57:59 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2011-07-03 16:57:59 ----A---- C:\Windows\SYSWOW64\netutils.dll
2011-07-03 16:57:59 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2011-07-03 16:57:59 ----A---- C:\Windows\SYSWOW64\muifontsetup.dll
2011-07-03 16:57:59 ----A---- C:\Windows\SYSWOW64\mobsync.exe
2011-07-03 16:57:59 ----A---- C:\Windows\SYSWOW64\mciqtz32.dll
2011-07-03 16:57:59 ----A---- C:\Windows\system32\schedcli.dll
2011-07-03 16:57:59 ----A---- C:\Windows\system32\onexui.dll
2011-07-03 16:57:59 ----A---- C:\Windows\system32\manage-bde.exe
2011-07-03 16:57:59 ----A---- C:\Windows\system32\chglogon.exe
2011-07-03 16:57:59 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-07-03 16:57:58 ----A---- C:\Windows\SYSWOW64\sppc.dll
2011-07-03 16:57:58 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2011-07-03 16:57:58 ----A---- C:\Windows\SYSWOW64\cabinet.dll
2011-07-03 16:57:58 ----A---- C:\Windows\system32\wdiasqmmodule.dll
2011-07-03 16:57:58 ----A---- C:\Windows\system32\spopk.dll
2011-07-03 16:57:58 ----A---- C:\Windows\system32\repair-bde.exe
2011-07-03 16:57:58 ----A---- C:\Windows\system32\qappsrv.exe
2011-07-03 16:57:58 ----A---- C:\Windows\system32\inetmib1.dll
2011-07-03 16:57:57 ----A---- C:\Windows\SYSWOW64\unlodctr.exe
2011-07-03 16:57:57 ----A---- C:\Windows\SYSWOW64\spopk.dll
2011-07-03 16:57:57 ----A---- C:\Windows\SYSWOW64\shimgvw.dll
2011-07-03 16:57:57 ----A---- C:\Windows\SYSWOW64\msdmo.dll
2011-07-03 16:57:57 ----A---- C:\Windows\SYSWOW64\luainstall.dll
2011-07-03 16:57:57 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2011-07-03 16:57:57 ----A---- C:\Windows\system32\vmicres.dll
2011-07-03 16:57:57 ----A---- C:\Windows\system32\tscon.exe
2011-07-03 16:57:57 ----A---- C:\Windows\system32\RDPENCDD.dll
2011-07-03 16:57:57 ----A---- C:\Windows\system32\profprov.dll
2011-07-03 16:57:57 ----A---- C:\Windows\system32\odbcconf.dll
2011-07-03 16:57:57 ----A---- C:\Windows\system32\chgport.exe
2011-07-03 16:57:57 ----A---- C:\Windows\system32\fixmapi.exe
2011-07-03 16:57:56 ----A---- C:\Windows\SYSWOW64\rdprefdrvapi.dll
2011-07-03 16:57:56 ----A---- C:\Windows\SYSWOW64\inetmib1.dll
2011-07-03 16:57:56 ----A---- C:\Windows\system32\vmstorfltres.dll
2011-07-03 16:57:56 ----A---- C:\Windows\system32\tskill.exe
2011-07-03 16:57:56 ----A---- C:\Windows\system32\tsdiscon.exe
2011-07-03 16:57:56 ----A---- C:\Windows\system32\rwinsta.exe
2011-07-03 16:57:56 ----A---- C:\Windows\system32\logoff.exe
2011-07-03 16:57:56 ----A---- C:\Windows\system32\chgusr.exe
2011-07-03 16:57:55 ----A---- C:\Windows\SYSWOW64\wups.dll
2011-07-03 16:57:55 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2011-07-03 16:57:55 ----A---- C:\Windows\SYSWOW64\odbcconf.dll
2011-07-03 16:57:55 ----A---- C:\Windows\SYSWOW64\browcli.dll
2011-07-03 16:57:55 ----A---- C:\Windows\system32\vmbusres.dll
2011-07-03 16:57:55 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-07-03 16:57:55 ----A---- C:\Windows\system32\TRAPI.dll
2011-07-03 16:57:55 ----A---- C:\Windows\system32\shadow.exe
2011-07-03 16:57:55 ----A---- C:\Windows\system32\FXSMON.dll
2011-07-03 16:57:55 ----A---- C:\Windows\system32\elsTrans.dll
2011-07-03 16:57:55 ----A---- C:\Windows\system32\drivers\tdi.sys
2011-07-03 16:57:54 ----A---- C:\Windows\SYSWOW64\perfts.dll
2011-07-03 16:57:54 ----A---- C:\Windows\SYSWOW64\imm32.dll
2011-07-03 16:57:54 ----A---- C:\Windows\system32\wshbth.dll
2011-07-03 16:57:54 ----A---- C:\Windows\system32\LogonUI.exe
2011-07-03 16:57:54 ----A---- C:\Windows\system32\dsauth.dll
2011-07-03 16:57:53 ----A---- C:\Windows\SYSWOW64\elsTrans.dll
2011-07-03 16:57:53 ----A---- C:\Windows\system32\reset.exe
2011-07-03 16:57:53 ----A---- C:\Windows\system32\rdprefdrvapi.dll
2011-07-03 16:57:53 ----A---- C:\Windows\system32\query.exe
2011-07-03 16:57:53 ----A---- C:\Windows\system32\napdsnap.dll
2011-07-03 16:57:53 ----A---- C:\Windows\system32\change.exe
2011-07-03 16:57:53 ----A---- C:\Windows\system32\FXSUNATD.exe
2011-07-03 16:57:52 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2011-07-03 16:57:52 ----A---- C:\Windows\SYSWOW64\TRAPI.dll
2011-07-03 16:57:52 ----A---- C:\Windows\SYSWOW64\schedcli.dll
2011-07-03 16:57:52 ----A---- C:\Windows\SYSWOW64\bitsperf.dll
2011-07-03 16:57:52 ----A---- C:\Windows\system32\drivers\usbrpm.sys
2011-07-03 16:57:52 ----A---- C:\Windows\system32\cscdll.dll
2011-07-03 16:57:52 ----A---- C:\Windows\system32\bitsperf.dll
2011-07-03 16:57:51 ----A---- C:\Windows\SYSWOW64\napdsnap.dll
2011-07-03 16:57:51 ----A---- C:\Windows\SYSWOW64\dsauth.dll
2011-07-03 16:57:51 ----A---- C:\Windows\SYSWOW64\cscdll.dll
2011-07-03 16:57:51 ----A---- C:\Windows\system32\wups2.dll
2011-07-03 16:57:51 ----A---- C:\Windows\system32\drivers\acpipmi.sys
2011-07-03 16:57:50 ----A---- C:\Windows\SYSWOW64\sscore.dll
2011-07-03 16:57:50 ----A---- C:\Windows\system32\wups.dll
2011-07-03 16:57:50 ----A---- C:\Windows\system32\wsdchngr.dll
2011-07-03 16:57:50 ----A---- C:\Windows\system32\shgina.dll
2011-07-03 16:57:49 ----A---- C:\Windows\SYSWOW64\wsdchngr.dll
2011-07-03 16:57:49 ----A---- C:\Windows\SYSWOW64\shgina.dll
2011-07-03 16:57:49 ----A---- C:\Windows\SYSWOW64\riched32.dll
2011-07-03 16:57:49 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2011-07-03 16:57:48 ----A---- C:\Windows\system32\drivers\CompositeBus.sys
2011-07-03 16:57:47 ----A---- C:\Windows\system32\wshirda.dll
2011-07-03 16:57:47 ----A---- C:\Windows\system32\drivers\appid.sys
2011-07-03 16:57:45 ----A---- C:\Windows\SYSWOW64\wshirda.dll
2011-07-03 16:57:45 ----A---- C:\Windows\system32\rdpcfgex.dll
2011-07-03 16:57:45 ----A---- C:\Windows\system32\drivers\hidusb.sys
2011-07-03 16:57:44 ----A---- C:\Windows\system32\vmbuspipe.dll
2011-07-03 16:57:44 ----A---- C:\Windows\system32\riched32.dll
2011-07-03 16:57:44 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2011-07-03 16:57:44 ----A---- C:\Windows\system32\browseui.dll
2011-07-03 16:57:43 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2011-07-03 16:57:43 ----A---- C:\Windows\SYSWOW64\browseui.dll
2011-07-03 16:57:43 ----A---- C:\Windows\system32\VmdCoinstall.dll
2011-07-03 16:57:43 ----A---- C:\Windows\system32\VmbusCoinstaller.dll
2011-07-03 16:57:43 ----A---- C:\Windows\system32\spwmp.dll
2011-07-03 16:57:43 ----A---- C:\Windows\system32\IcCoinstall.dll
2011-07-03 16:57:43 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2011-07-03 16:57:43 ----A---- C:\Windows\system32\C_ISCII.DLL
2011-07-03 16:57:42 ----A---- C:\Windows\SYSWOW64\C_ISCII.DLL
2011-07-03 16:57:42 ----A---- C:\Windows\system32\dxmasf.dll
2011-07-03 16:57:42 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2011-07-03 16:57:42 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2011-07-03 16:57:42 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2011-07-03 16:57:42 ----A---- C:\Windows\system32\drivers\cdrom.sys
2011-07-03 16:57:41 ----AH---- C:\Windows\system32\api-ms-win-core-ums-l1-1-0.dll
2011-07-03 16:57:41 ----A---- C:\Windows\SYSWOW64\shunimpl.dll
2011-07-03 16:57:41 ----A---- C:\Windows\SYSWOW64\KBDTUF.DLL
2011-07-03 16:57:41 ----A---- C:\Windows\SYSWOW64\KBDSG.DLL
2011-07-03 16:57:41 ----A---- C:\Windows\SYSWOW64\kbdlk41a.dll
2011-07-03 16:57:41 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2011-07-03 16:57:41 ----A---- C:\Windows\system32\shunimpl.dll
2011-07-03 16:57:41 ----A---- C:\Windows\system32\KBDTUF.DLL
2011-07-03 16:57:41 ----A---- C:\Windows\system32\KBDSF.DLL
2011-07-03 16:57:41 ----A---- C:\Windows\system32\KBDPO.DLL
2011-07-03 16:57:41 ----A---- C:\Windows\system32\drivers\WUDFPf.sys

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#3 Příspěvek od romcolahvac »

pokračování 2 :

2011-07-03 16:57:41 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-07-03 16:57:41 ----A---- C:\Windows\system32\drivers\scfilter.sys
2011-07-03 16:57:40 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\SYSWOW64\KBDTUQ.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\SYSWOW64\KBDGR1.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\SYSWOW64\KBDGKL.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\system32\KBDTUQ.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\system32\KBDSG.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\system32\KBDNEPR.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\system32\kbdlk41a.dll
2011-07-03 16:57:40 ----A---- C:\Windows\system32\KBDINTAM.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\system32\KBDINBEN.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\system32\KBDGR1.DLL
2011-07-03 16:57:40 ----A---- C:\Windows\system32\KBDGKL.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDUS.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDTURME.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDTAJIK.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDMON.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDINTEL.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDINHIN.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDGEO.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDCZ1.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\SYSWOW64\KBDBLR.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\system32\wmploc.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\system32\KBDGEO.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\system32\KBDCZ1.DLL
2011-07-03 16:57:39 ----A---- C:\Windows\system32\drivers\vms3cap.sys
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDUGHR1.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDSF.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDPO.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDNEPR.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDMAORI.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDLT1.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDINTAM.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDINORI.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDINMAR.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDINKAN.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDINBEN.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDBULG.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDUS.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDUGHR1.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDTURME.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDTAJIK.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDMON.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDLT1.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDBULG.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDBLR.DLL
2011-07-03 16:57:38 ----A---- C:\Windows\system32\KBDBASH.DLL
2011-07-03 16:57:37 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-07-03 16:57:37 ----A---- C:\Windows\SYSWOW64\spwizres.dll
2011-07-03 16:57:37 ----A---- C:\Windows\SYSWOW64\pifmgr.dll
2011-07-03 16:57:37 ----A---- C:\Windows\SYSWOW64\nlsbres.dll
2011-07-03 16:57:37 ----A---- C:\Windows\SYSWOW64\dpnaddr.dll
2011-07-03 16:57:37 ----A---- C:\Windows\system32\tzres.dll
2011-07-03 16:57:37 ----A---- C:\Windows\system32\spwizres.dll
2011-07-03 16:57:37 ----A---- C:\Windows\system32\pifmgr.dll
2011-07-03 16:57:37 ----A---- C:\Windows\system32\nlsbres.dll
2011-07-03 16:57:37 ----A---- C:\Windows\system32\KBDMAORI.DLL
2011-07-03 16:57:37 ----A---- C:\Windows\system32\KBDINTEL.DLL
2011-07-03 16:57:37 ----A---- C:\Windows\system32\KBDINORI.DLL
2011-07-03 16:57:37 ----A---- C:\Windows\system32\KBDINMAR.DLL
2011-07-03 16:57:37 ----A---- C:\Windows\system32\KBDINKAN.DLL
2011-07-03 16:57:37 ----A---- C:\Windows\system32\KBDINHIN.DLL
2011-07-03 16:57:37 ----A---- C:\Windows\system32\drivers\VMBusHID.sys
2011-07-03 16:57:37 ----A---- C:\Windows\system32\dpnaddr.dll
2011-07-03 16:57:37 ----A---- C:\Windows\system32\BlbEvents.dll
2011-07-03 16:56:43 ----A---- C:\Windows\SYSWOW64\wdscore.dll
2011-07-03 16:56:43 ----A---- C:\Windows\SYSWOW64\PkgMgr.exe
2011-07-03 16:56:42 ----A---- C:\Windows\SYSWOW64\printmanagement.msc
2011-07-03 16:56:26 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2011-07-03 16:56:26 ----A---- C:\Windows\SYSWOW64\dpx.dll
2011-07-03 16:56:23 ----A---- C:\Windows\SYSWOW64\wbemcomn.dll
2011-07-03 16:52:57 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-07-03 16:52:57 ----A---- C:\Windows\system32\wbemcomn.dll
2011-07-03 16:52:49 ----A---- C:\Windows\system32\SmiEngine.dll
2011-07-03 16:52:43 ----A---- C:\Windows\system32\PkgMgr.exe
2011-07-03 16:52:11 ----A---- C:\Windows\system32\drvstore.dll
2011-07-03 16:52:11 ----A---- C:\Windows\system32\dpx.dll
2011-06-30 09:11:33 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-06-30 09:11:33 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-06-30 09:11:33 ----A---- C:\Windows\system32\tquery.dll
2011-06-30 09:11:33 ----A---- C:\Windows\system32\mssrch.dll
2011-06-30 09:11:32 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-30 09:11:32 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-30 09:11:32 ----A---- C:\Windows\system32\mssvp.dll
2011-06-30 09:11:31 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-06-30 09:11:31 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-06-30 09:11:31 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-06-30 09:11:31 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-06-30 09:11:31 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-06-30 09:11:31 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-30 09:11:31 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-30 09:11:31 ----A---- C:\Windows\system32\mssph.dll
2011-06-30 09:11:30 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-06-30 09:11:30 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-30 09:11:29 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-06-30 09:11:28 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-30 09:11:28 ----A---- C:\Windows\system32\cfgmgr32.dll
2011-06-30 09:11:27 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-06-30 09:11:27 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-06-30 09:11:27 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-06-30 09:11:27 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll

======List of files/folders modified in the last 1 month======

2011-07-23 19:11:17 ----D---- C:\Windows\Temp
2011-07-23 19:10:56 ----D---- C:\Windows\Prefetch
2011-07-23 19:06:11 ----D---- C:\Windows\system32\config
2011-07-23 19:04:49 ----RD---- C:\Program Files
2011-07-23 19:01:17 ----SHD---- C:\System Volume Information
2011-07-23 18:12:24 ----D---- C:\Windows\SYSWOW64\logishrd
2011-07-23 18:12:24 ----D---- C:\Windows\system32\logishrd
2011-07-23 18:12:24 ----D---- C:\ProgramData\LogMeIn
2011-07-21 19:34:53 ----D---- C:\Windows\System32
2011-07-21 19:34:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-21 19:34:52 ----D---- C:\Windows\inf
2011-07-21 18:57:03 ----A---- C:\Windows\SYSWOW64\Dvbpws.dll
2011-07-21 18:52:45 ----D---- C:\Program Files (x86)\Mozilla Firefox 3
2011-07-21 17:52:47 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-07-21 17:50:05 ----D---- C:\Windows\SysWOW64
2011-07-21 17:48:02 ----D---- C:\Windows\system32\catroot2
2011-07-21 17:43:49 ----AD---- C:\Windows
2011-07-21 17:42:59 ----D---- C:\Windows\system32\drivers
2011-07-21 17:42:57 ----D---- C:\Windows\system32\DriverStore
2011-07-21 17:42:57 ----D---- C:\Windows\system32\catroot
2011-07-21 16:44:09 ----D---- C:\Program Files (x86)\LogMeIn
2011-07-21 16:35:50 ----D---- C:\Windows\winsxs
2011-07-21 16:30:41 ----D---- C:\Windows\AppPatch
2011-07-21 16:30:31 ----A---- C:\Windows\system32\LMIRfsClientNP.dll
2011-07-21 16:30:31 ----A---- C:\Windows\system32\LMIport.dll
2011-07-21 16:30:31 ----A---- C:\Windows\system32\LMIinit.dll
2011-07-13 20:48:57 ----A---- C:\Windows\system32\MRT.exe
2011-07-13 20:48:53 ----SHD---- C:\Windows\Installer
2011-07-13 20:48:40 ----D---- C:\ProgramData\Microsoft Help
2011-07-12 10:45:14 ----D---- C:\Windows\system32\Tasks
2011-07-12 10:45:09 ----RD---- C:\Program Files (x86)
2011-07-11 23:48:25 ----D---- C:\Users\ROMAN\AppData\Roaming\GeoGet
2011-07-11 12:08:51 ----D---- C:\Program Files (x86)\GeoGet
2011-07-09 10:20:17 ----D---- C:\Windows\Microsoft.NET
2011-07-09 10:19:23 ----RSD---- C:\Windows\assembly
2011-07-08 12:24:36 ----HD---- C:\ProgramData
2011-07-07 11:57:40 ----D---- C:\Windows\rescache
2011-07-07 10:45:17 ----D---- C:\Users\ROMAN\AppData\Roaming\vlc
2011-07-07 08:10:20 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-07-07 08:10:20 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-07-07 08:10:20 ----D---- C:\Program Files (x86)\Windows Media Player
2011-07-07 08:10:20 ----D---- C:\Program Files (x86)\Windows Mail
2011-07-07 08:10:19 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-07-07 08:10:16 ----D---- C:\Program Files\Windows Sidebar
2011-07-07 08:10:16 ----D---- C:\Program Files\Windows Portable Devices
2011-07-07 08:10:16 ----D---- C:\Program Files\Windows Media Player
2011-07-07 08:10:16 ----D---- C:\Program Files\Windows Mail
2011-07-07 08:10:16 ----D---- C:\Program Files\DVD Maker
2011-07-07 08:10:15 ----D---- C:\Program Files\Windows Photo Viewer
2011-07-07 08:10:15 ----D---- C:\Program Files\Windows Journal
2011-07-07 08:10:10 ----D---- C:\Windows\servicing
2011-07-07 08:10:10 ----D---- C:\Windows\ehome
2011-07-07 08:10:10 ----D---- C:\Program Files\Windows Defender
2011-07-07 08:09:57 ----SHD---- C:\Windows\BitLockerDiscoveryVolumeContents
2011-07-07 08:09:56 ----D---- C:\Windows\SYSWOW64\oobe
2011-07-07 08:09:56 ----D---- C:\Windows\SYSWOW64\migration
2011-07-07 08:09:56 ----D---- C:\Windows\SYSWOW64\ko-KR
2011-07-07 08:09:56 ----D---- C:\Windows\SYSWOW64\it-IT
2011-07-07 08:09:56 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-07 08:09:56 ----D---- C:\Windows\SYSWOW64\el-GR
2011-07-07 08:09:56 ----D---- C:\Windows\SYSWOW64\de-DE
2011-07-07 08:09:56 ----D---- C:\Windows\SYSWOW64\da-DK
2011-07-07 08:09:55 ----D---- C:\Windows\SYSWOW64\sv-SE
2011-07-07 08:09:55 ----D---- C:\Windows\SYSWOW64\Setup
2011-07-07 08:09:55 ----D---- C:\Windows\SYSWOW64\ru-RU
2011-07-07 08:09:55 ----D---- C:\Windows\SYSWOW64\he-IL
2011-07-07 08:09:55 ----D---- C:\Windows\SYSWOW64\fr-FR
2011-07-07 08:09:55 ----D---- C:\Windows\SYSWOW64\fi-FI
2011-07-07 08:09:55 ----D---- C:\Windows\SYSWOW64\cs
2011-07-07 08:09:55 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-07-07 08:09:54 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-07-07 08:09:53 ----D---- C:\Windows\SYSWOW64\zh-TW
2011-07-07 08:09:53 ----D---- C:\Windows\SYSWOW64\zh-CN
2011-07-07 08:09:53 ----D---- C:\Windows\SYSWOW64\pt-PT
2011-07-07 08:09:53 ----D---- C:\Windows\SYSWOW64\pl-PL
2011-07-07 08:09:53 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-07-07 08:09:53 ----D---- C:\Windows\SYSWOW64\hu-HU
2011-07-07 08:09:53 ----D---- C:\Windows\SYSWOW64\es-ES
2011-07-07 08:09:52 ----D---- C:\Windows\SYSWOW64\sppui
2011-07-07 08:09:52 ----D---- C:\Windows\SYSWOW64\ro-RO
2011-07-07 08:09:52 ----D---- C:\Windows\SYSWOW64\ja-JP
2011-07-07 08:09:50 ----D---- C:\Windows\SYSWOW64\wbem
2011-07-07 08:09:50 ----D---- C:\Windows\SYSWOW64\tr-TR
2011-07-07 08:09:50 ----D---- C:\Windows\SYSWOW64\th-TH
2011-07-07 08:09:50 ----D---- C:\Windows\SYSWOW64\nl-NL
2011-07-07 08:09:50 ----D---- C:\Windows\SYSWOW64\nb-NO
2011-07-07 08:09:50 ----D---- C:\Windows\SYSWOW64\ar-SA
2011-07-07 08:09:49 ----D---- C:\Windows\SYSWOW64\migwiz
2011-07-07 08:09:49 ----D---- C:\Windows\SYSWOW64\Dism
2011-07-07 08:09:48 ----D---- C:\Windows\SYSWOW64\pt-BR
2011-07-07 08:09:12 ----D---- C:\Windows\system32\ko-KR
2011-07-07 08:09:12 ----D---- C:\Windows\system32\da-DK
2011-07-07 08:09:12 ----D---- C:\Windows\PolicyDefinitions
2011-07-07 08:09:11 ----D---- C:\Windows\system32\en-US
2011-07-07 08:09:10 ----D---- C:\Windows\system32\it-IT
2011-07-07 08:09:10 ----D---- C:\Windows\system32\el-GR
2011-07-07 08:09:10 ----D---- C:\Windows\system32\de-DE
2011-07-07 08:09:09 ----D---- C:\Windows\system32\oobe
2011-07-07 08:09:09 ----D---- C:\Windows\system32\migration
2011-07-07 08:09:07 ----D---- C:\Windows\system32\ru-RU
2011-07-07 08:09:07 ----D---- C:\Windows\system32\fr-FR
2011-07-07 08:09:07 ----D---- C:\Windows\system32\AdvancedInstallers
2011-07-07 08:09:06 ----D---- C:\Windows\system32\sv-SE
2011-07-07 08:09:06 ----D---- C:\Windows\system32\Setup
2011-07-07 08:09:06 ----D---- C:\Windows\system32\he-IL
2011-07-07 08:09:06 ----D---- C:\Windows\system32\fi-FI
2011-07-07 08:09:05 ----D---- C:\Windows\system32\cs
2011-07-07 08:09:04 ----D---- C:\Windows\system32\cs-CZ
2011-07-07 08:09:01 ----D---- C:\Windows\system32\zh-CN
2011-07-07 08:09:01 ----D---- C:\Windows\system32\pt-PT
2011-07-07 08:09:01 ----D---- C:\Windows\system32\manifeststore
2011-07-07 08:09:01 ----D---- C:\Windows\system32\hu-HU
2011-07-07 08:09:01 ----D---- C:\Windows\system32\es-ES
2011-07-07 08:09:00 ----D---- C:\Windows\system32\zh-TW
2011-07-07 08:09:00 ----D---- C:\Windows\system32\sppui
2011-07-07 08:09:00 ----D---- C:\Windows\system32\pl-PL
2011-07-07 08:09:00 ----D---- C:\Windows\system32\ja-JP
2011-07-07 08:08:59 ----D---- C:\Windows\system32\ro-RO
2011-07-07 08:08:57 ----D---- C:\Windows\system32\th-TH
2011-07-07 08:08:57 ----D---- C:\Windows\system32\drivers\pt-PT
2011-07-07 08:08:57 ----D---- C:\Windows\system32\drivers\pt-BR
2011-07-07 08:08:57 ----D---- C:\Windows\system32\drivers\pl-PL
2011-07-07 08:08:57 ----D---- C:\Windows\system32\drivers\ko-KR
2011-07-07 08:08:57 ----D---- C:\Windows\system32\drivers\it-IT
2011-07-07 08:08:57 ----D---- C:\Windows\system32\drivers\he-IL
2011-07-07 08:08:56 ----D---- C:\Windows\system32\drivers\tr-TR
2011-07-07 08:08:56 ----D---- C:\Windows\system32\drivers\th-TH
2011-07-07 08:08:56 ----D---- C:\Windows\system32\drivers\nl-NL
2011-07-07 08:08:56 ----D---- C:\Windows\system32\drivers\hu-HU
2011-07-07 08:08:56 ----D---- C:\Windows\system32\drivers\fr-FR
2011-07-07 08:08:56 ----D---- C:\Windows\system32\drivers\fi-FI
2011-07-07 08:08:56 ----D---- C:\Windows\system32\drivers\el-GR
2011-07-07 08:08:55 ----D---- C:\Windows\system32\drivers\zh-TW
2011-07-07 08:08:55 ----D---- C:\Windows\system32\drivers\sv-SE
2011-07-07 08:08:55 ----D---- C:\Windows\system32\drivers\es-ES
2011-07-07 08:08:55 ----D---- C:\Windows\system32\drivers\de-DE
2011-07-07 08:08:55 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-07-07 08:08:54 ----D---- C:\Windows\system32\drivers\zh-CN
2011-07-07 08:08:54 ----D---- C:\Windows\system32\drivers\ja-JP
2011-07-07 08:08:54 ----D---- C:\Windows\system32\drivers\ar-SA
2011-07-07 08:08:53 ----D---- C:\Windows\system32\drivers\ru-RU
2011-07-07 08:08:53 ----D---- C:\Windows\system32\drivers\ro-RO
2011-07-07 08:08:53 ----D---- C:\Windows\system32\drivers\nb-NO
2011-07-07 08:08:52 ----D---- C:\Windows\system32\drivers\UMDF
2011-07-07 08:08:52 ----D---- C:\Windows\system32\drivers\en-US
2011-07-07 08:08:52 ----D---- C:\Windows\system32\drivers\da-DK
2011-07-07 08:08:51 ----D---- C:\Windows\system32\wbem
2011-07-07 08:08:51 ----D---- C:\Windows\system32\tr-TR
2011-07-07 08:08:50 ----D---- C:\Windows\system32\nb-NO
2011-07-07 08:08:49 ----D---- C:\Windows\system32\nl-NL
2011-07-07 08:08:48 ----D---- C:\Windows\system32\ar-SA
2011-07-07 08:08:47 ----D---- C:\Windows\system32\pt-BR
2011-07-07 08:08:47 ----D---- C:\Windows\system32\migwiz
2011-07-07 08:08:47 ----D---- C:\Windows\system32\Dism
2011-07-07 08:07:20 ----RSD---- C:\Windows\Fonts
2011-07-07 08:05:52 ----D---- C:\Windows\system32\Boot
2011-07-06 10:26:32 ----A---- C:\Windows\SYSWOW64\msclmd.dll
2011-07-06 10:26:31 ----A---- C:\Windows\system32\msclmd.dll
2011-07-06 08:55:54 ----A---- C:\Windows\SYSWOW64\DTVWizard_LOG.txt
2011-07-05 16:38:10 ----A---- C:\Windows\win.ini
2011-07-05 16:38:10 ----A---- C:\Windows\RBSystem.ini
2011-07-05 16:38:10 ----A---- C:\Windows\ESIDATA.ini
2011-07-05 16:01:27 ----D---- C:\DOWNLOAD
2011-07-05 16:00:56 ----D---- C:\Downloads
2011-07-05 15:47:30 ----D---- C:\Program Files (x86)\office Convert Pdf to Jpg Jpeg Tiff Free
2011-07-05 15:42:13 ----D---- C:\Program Files (x86)\GoFTP
2011-07-05 15:41:38 ----D---- C:\Program Files (x86)\Common Files
2011-07-04 16:15:06 ----D---- C:\Program Files (x86)\Java
2011-07-04 13:43:51 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-07-04 13:43:42 ----A---- C:\Windows\system32\aswBoot.exe
2011-07-03 20:48:54 ----D---- C:\FIREFOX STAHOVANI
2011-07-03 16:37:57 ----D---- C:\ProgramData\LightScribe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 EUBAKUP;EUBAKUP; C:\Windows\sysWow64\drivers\eubakup.sys [2009-12-02 30600]
R0 EUFS;EUFS; C:\Windows\sysWow64\drivers\eufs.sys [2009-12-02 26504]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2009-07-18 109480]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-03-30 503352]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-04-06 13368]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 288088]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 45400]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 31400]
R1 NEOFLTR_650_16339;Juniper Networks TDI Filter Driver (NEOFLTR_650_16339); \??\C:\Windows\system32\Drivers\NEOFLTR_650_16339.SYS [2010-08-03 100472]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 64856]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [2010-01-27 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2010-01-27 72216]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-08-04 7451648]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-08-04 268288]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-07-15 116240]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-16 40648]
R3 EuDisk;EASEUS Disk Enumerator; C:\Windows\system32\DRIVERS\EuDisk.sys [2009-12-02 137608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2010-01-27 11552]
R3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2010-05-07 30304]
R3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2010-07-27 339040]
R3 LVUVC64;Logitech Webcam C160(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2010-07-27 6465632]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 MTSBDA;TechniSat SkyStar HD2; C:\Windows\System32\Drivers\MtsBda.sys [2009-07-13 344592]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-03-21 452200]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-07-10 1222144]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]
S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [2005-09-09 47104]
S2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2005-08-12 4608]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 ATICDSDr;ATICDSDr; \??\C:\Users\ROMAN\AppData\Local\Temp\ATICDSDr.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-08-31 120336]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-08-04 7451648]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 EUDSKACS;EUDSKACS; \??\C:\Windows\sysWow64\drivers\eudskacs.sys [2009-12-02 17800]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 lvpopf64;Logitech POP Suppression Filter; C:\Windows\system32\DRIVERS\lvpopf64.sys [2010-07-27 271712]
S3 LVPr2Mon;LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2010-05-07 30304]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-12-02 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-07-30 26624]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2007-11-06 40464]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 ULCDRHlp;ULCDRHlp; C:\Windows\System32\Drivers\ULCDRHlp.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-07-30 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-02-06 109056]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-08-04 203264]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-08-19 90112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-07-04 42184]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 Cerberus FTP Server;Cerberus FTP Server; C:\Program Files (x86)\Cerberus LLC\Cerberus FTP Server\CerberusGUI.exe [2011-05-17 5376832]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\ASUS.SYS\config\DVMExportService.exe [2009-07-17 319488]
R2 EWA net DB Core;EWA net DB Core; C:\Program Files (x86)\EWA net\database\TransBase EWA\tbmux32.exe [2008-04-04 417792]
R2 EWA net DB EPC;EWA net DB EPC; C:\Program Files (x86)\EWA net\database\TransBase EPC\tbmux32.exe [2007-11-27 417792]
R2 EWA net DB WIS;EWA net DB WIS; C:\Program Files (x86)\EWA net\database\TransBase WIS\tbmux32.exe [2008-04-04 417792]
R2 EWA net Server;EWA net Server; C:\Program Files (x86)\EWA net\server\bin\tomcat.exe [2003-07-31 65536]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-07-21 375176]
R2 LogMeIn;LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [2010-11-08 407424]
R2 LVPrcS64;Process Monitor; C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-05-07 197976]
R2 MSSQL$FORDECATDB;SQL Server (FORDECATDB); C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-02-18 462632]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2008-10-23 241734]
R2 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 153440]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS); C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [2008-10-23 364635]
R2 TVESched;TVEnhance Task Scheduler (TTS)); C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [2008-10-23 172121]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2009-12-17 53408]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 iPod Service;iPod Service; C:\Program Files (x86)\iPod\bin\iPodService.exe [2011-01-25 933664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe -d -f C:\Program Files\WinPcap\rpcapd.ini []
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-09-01 1255736]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

děkuji

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#4 Příspěvek od romcolahvac »

Nevím zda jsem udělal dobře, když jsem musel log rozdělit do vícero částí :-) dnad to bude takhle v pořádku. díky

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu logu

#5 Příspěvek od motji »

Dobrý večer :)

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#6 Příspěvek od romcolahvac »

Dobrý den, prováděl jsem úplný test a to již 2x ale pokaždé se po jedné hodině testování zobrazilo, že program přestal správně fungovat a ukončí se. Prosím o radu co provádět dále, nebo jinak. díky

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#7 Příspěvek od romcolahvac »

Provedl jsem alespon rychlou kontrolu zde je log:

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verze databáze: 7298

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

28.7.2011 10:33:42
mbam-log-2011-07-28 (10-32-56).txt

Typ kontroly: Rychlý test
Testované objekty: 191563
Uplynulý čas: 7 minut, 10 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 1
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 1

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Backdoor.Agent) -> Value: NVIDIA driver monitor -> No action taken.

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\Windows\AutoKMS.exe (RiskWare.Tool.CK) -> No action taken.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu logu

#8 Příspěvek od motji »

V mbamu vše smažte.

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#9 Příspěvek od romcolahvac »

Smazáno a proveden ukon s ComboFix, zde je log:

ComboFix 11-07-28.06 - ROMAN 28.07.2011 22:28:02.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2046.414 [GMT 2:00]
Spuštěný z: d:\xxx\5.7.11\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
ADS - Windows: deleted 24 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qsTAtsrv.dll
c:\users\ROMAN\Desktop\Setup.exe
c:\windows\IsUn0405.exe
c:\windows\SysWow64\Dvbpws.dll
c:\windows\SysWow64\logs
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-28 do 2011-07-28 )))))))))))))))))))))))))))))))
.
.
2011-07-28 20:53 . 2011-07-28 20:53 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp
2011-07-28 20:53 . 2011-07-28 20:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-27 20:15 . 2011-07-27 20:17 -------- d-----w- c:\program files (x86)\HTML Beauty 2
2011-07-27 18:52 . 2011-07-27 18:52 -------- d-----w- c:\users\ROMAN\AppData\Roaming\Malwarebytes
2011-07-27 18:51 . 2011-07-27 18:51 -------- d-----w- c:\programdata\Malwarebytes
2011-07-27 18:51 . 2010-11-29 15:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-27 18:51 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-27 18:51 . 2011-07-27 18:51 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-26 19:30 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E1866C38-AC55-4B9C-A38E-C4BAE720A6CF}\mpengine.dll
2011-07-25 19:20 . 2011-07-25 19:21 -------- d-----w- c:\program files (x86)\Memory Max
2011-07-23 17:04 . 2011-07-25 14:10 -------- d-----w- c:\program files\trend micro
2011-07-23 17:04 . 2011-07-23 17:05 -------- d-----w- C:\rsit
2011-07-21 15:50 . 2005-07-16 00:35 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2011-07-13 08:36 . 2011-06-03 06:56 421888 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-13 08:34 . 2011-04-28 03:55 552960 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-13 08:34 . 2011-04-28 03:54 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-13 08:34 . 2011-06-11 03:07 3137536 ----a-w- c:\windows\system32\win32k.sys
2011-07-12 08:45 . 2011-07-12 08:45 -------- d-----w- c:\program files (x86)\Ask.com
2011-07-07 08:32 . 2011-07-07 10:27 -------- d-----w- c:\program files (x86)\CamStudio
2011-07-07 08:28 . 2005-06-12 16:29 77824 ----a-w- c:\windows\SysWow64\fmcodec.DLL
2011-07-07 08:28 . 2011-07-07 08:28 -------- d-----w- c:\program files (x86)\Fox Magic
2011-07-06 08:12 . 2011-07-06 08:12 -------- d-----w- c:\windows\system32\SPReview
2011-07-06 08:10 . 2011-07-06 08:10 -------- d-----w- c:\windows\system32\EventProviders
2011-07-04 14:16 . 2011-07-04 14:16 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-03 15:01 . 2010-11-20 13:25 2264064 ----a-w- c:\windows\system32\VPCWizard.exe
2011-07-03 15:00 . 2010-11-20 13:25 4583424 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
2011-07-03 14:59 . 2010-11-20 13:27 1096704 ----a-w- c:\program files\Windows Photo Viewer\PhotoAcq.dll
2011-07-03 14:58 . 2010-11-20 13:27 403968 ----a-w- c:\windows\system32\untfs.dll
2011-07-03 14:57 . 2010-11-20 13:27 24064 ----a-w- c:\windows\system32\schedcli.dll
2011-07-03 14:56 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2011-07-03 14:56 . 2010-11-20 12:17 209920 ----a-w- c:\windows\SysWow64\PkgMgr.exe
2011-07-03 14:56 . 2010-11-20 12:18 323072 ----a-w- c:\windows\SysWow64\drvstore.dll
2011-07-03 14:56 . 2010-11-20 12:18 257024 ----a-w- c:\windows\SysWow64\dpx.dll
2011-07-03 14:56 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-07-03 14:56 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-07-03 14:52 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-07-03 14:52 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-07-03 14:52 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-07-03 14:52 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-07-03 14:52 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-07-03 14:52 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-07-03 14:52 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-21 14:30 . 2010-09-15 07:15 33152 ----a-w- c:\windows\system32\LMIport.dll
2011-07-21 14:30 . 2010-09-15 07:15 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-21 14:30 . 2010-09-15 07:15 80768 ----a-w- c:\windows\system32\LMIinit.dll
2011-07-06 08:26 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-07-06 08:26 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-04 11:43 . 2010-08-31 15:01 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:43 . 2010-08-31 15:01 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-04 11:43 . 2011-01-19 11:09 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-04 11:36 . 2011-05-25 18:46 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-04 11:36 . 2010-08-31 15:02 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-04 11:35 . 2010-08-31 15:02 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-04 11:32 . 2010-08-31 15:02 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-04 11:32 . 2010-08-31 15:02 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-04 11:32 . 2010-08-31 15:02 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-06-21 16:51 . 2011-05-23 17:44 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-09 09:16 . 2010-09-01 08:13 5018 --sha-w- c:\programdata\KGyGaAvL.sys
2011-06-03 05:57 . 2011-07-13 08:40 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2010-08-31 13:32 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-04 02:52 . 2010-09-02 10:32 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-05-03 05:29 . 2011-06-16 18:46 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-03 04:30 . 2011-06-16 18:46 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 11:29 1490312 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"AlSrvN"="c:\program files (x86)\Alcohol Soft\Alcohol 120\Plugins\Helper\AlSrvN.exe" [2010-02-06 53760]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"dxlock"="c:\program files (x86)\Fox Magic\ScreenVirtuoso Pro 2.00\dxlock.exe" [2005-07-26 90112]
"WinFast Schedule"="c:\program files\WinFast\WFDTV\WFWIZ.exe" [2010-08-11 2920448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-07-24 2245120]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-03 98304]
"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"TurboV EVO"="c:\program files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" [2009-09-10 7322624]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-07 165208]
"iTraffic Monitor"="c:\program files (x86)\iTraffic Monitor\iTrafficMon.exe" [2009-04-22 942080]
"Standby"="c:\program files (x86)\Common Files\Corel\Standby\Standby.exe" [2010-06-26 105632]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-05-17 395144]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2011-06-08 101888]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-02-06 170496]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2010-11-29 963976]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Image Retriever.lnk - c:\program files (x86)\ScanSoft\PaperPort\xdcla.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [x]
R3 ATICDSDr;ATICDSDr;c:\users\ROMAN\AppData\Local\Temp\ATICDSDr.sys [x]
R3 EUDSKACS;EUDSKACS;c:\windows\sysWow64\drivers\eudskacs.sys [2009-12-02 17800]
R3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 EUBAKUP;EUBAKUP;c:\windows\sysWow64\drivers\eubakup.sys [2009-12-02 30600]
S0 EUFS;EUFS;c:\windows\sysWow64\drivers\eufs.sys [2009-12-02 26504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 NEOFLTR_650_16339;Juniper Networks TDI Filter Driver (NEOFLTR_650_16339);c:\windows\system32\Drivers\NEOFLTR_650_16339.SYS [x]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files (x86)\CyberLink\PlayMovie\000.fcl [2008-05-16 32240]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-08-19 90112]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 Cerberus FTP Server;Cerberus FTP Server;c:\program files (x86)\Cerberus LLC\Cerberus FTP Server\CerberusGUI.exe [2011-05-17 5376832]
S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-07-17 319488]
S2 EWA net DB Core;EWA net DB Core;c:\program files (x86)\EWA net\database\TransBase EWA\tbmux32.exe [2008-04-04 417792]
S2 EWA net DB EPC;EWA net DB EPC;c:\program files (x86)\EWA net\database\TransBase EPC\tbmux32.exe [2007-11-27 417792]
S2 EWA net DB WIS;EWA net DB WIS;c:\program files (x86)\EWA net\database\TransBase WIS\tbmux32.exe [2008-04-04 417792]
S2 EWA net Server;EWA net Server;c:\program files (x86)\EWA net\server\bin\tomcat.exe [2003-07-31 65536]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-07-21 375176]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-01-27 15928]
S2 LVPrcS64;Process Monitor;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-05-07 197976]
S2 MSSQL$FORDECATDB;SQL Server (FORDECATDB);c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S2 NAUpdate;Aktualizace Nero;c:\program files (x86)\Nero\Update\NASvc.exe [2010-02-18 462632]
S2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\program files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [2008-10-22 364635]
S2 TVESched;TVEnhance Task Scheduler (TTS));c:\program files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [2008-10-22 172121]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 EuDisk;EASEUS Disk Enumerator;c:\windows\system32\DRIVERS\EuDisk.sys [x]
S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech Webcam C160(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
S3 MTSBDA;TechniSat SkyStar HD2;c:\windows\system32\Drivers\MtsBda.sys [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S3 WFLR6654;WinFast DTV1800 H (XC3028);c:\windows\system32\drivers\wfeaglxt.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-876401281-3636213226-3406816674-1001Core1cc04adfeaaf61.job
- c:\users\ROMAN\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-25 20:28]
.
2011-07-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-876401281-3636213226-3406816674-1001UA.job
- c:\users\ROMAN\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-25 20:28]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-01-27 57928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://eu.ask.com/?l=dis&o=14597
uDefault_Search_URL = hxxp://search.qip.ru
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: &Stáhnout všechno FlashGetem - c:\program files (x86)\FlashGet\jc_all.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Save Flash with Flash Catcher - c:\program files (x86)\Common Files\justDo\IECatcher.DLL/FlashCatcher.htm
IE: Stáhnout Free Download Managerem - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: ????3?? - c:\users\ROMAN\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\ROMAN\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
Trusted Zone: kuaiche.com\software
TCP: DhcpNameServer = 10.0.0.138 10.0.0.50
DPF: {0427F569-3D57-4F10-B9FB-8D71A6A7BE24} - file:///C:/Users/ROMAN/AppData/Local/Temp/KJPL60/frmeditor.ocx
FF - ProfilePath - c:\users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - file://///WL-500GPV2/part0/intra/index.html
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
Wow6432Node-HKCU-Run-PhoneDaemon - c:\users\ROMAN\Desktop\iPhone PC Suite\PhoneDaemon.exe
Wow6432Node-HKLM-Run-pdfSaver3 - (no file)
Wow6432Node-HKLM-Run-TaskTray - (no file)
Notify-WgaLogon - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
AddRemove-GeoKuk - c:\windows\system32\javaws.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PlayMovie\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-876401281-3636213226-3406816674-1001\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@="c:\\Users\\ROMAN\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-876401281-3636213226-3406816674-1001\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@="c:\\Users\\ROMAN\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_USERS\S-1-5-21-876401281-3636213226-3406816674-1001\Software\SecuROM\License information*]
"datasecu"=hex:60,b4,74,a9,dc,4c,b2,4d,9b,70,a4,9d,90,6f,57,04,9b,3c,65,d6,1c,
63,cd,b6,8e,52,ef,8d,04,06,83,32,2b,9e,de,1c,57,3e,ab,f6,c9,97,a2,c6,b2,4d,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-07-28 23:08:31
ComboFix-quarantined-files.txt 2011-07-28 21:08
.
Před spuštěním: Volných bajtů: 31 851 524 096
Po spuštění: Volných bajtů: 31 681 441 792
.
- - End Of File - - 97E9094F0FF1F7824DA6648F0150E789

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu logu

#10 Příspěvek od motji »

Večer domažu nějaké zbytečnosti. Zlepšilo se to?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#11 Příspěvek od romcolahvac »

Je divné že RAM je zabrana z 70% i když neběží žádná aplikace, která by jasně odebírala hodně RAM. Není tam znatelný nějaký běžící proces navíc? děkuji za info! :-)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu logu

#12 Příspěvek od motji »

Zkusím vám povypínat nějaké programy, co se spouští po startu

:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

Reglock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-07-24 2245120]
"JMB36X IDE Setup"=-
"GrooveMonitor"=-
"Adobe Reader Speed Launcher"=-
"Standby"=-
"SwitchBoard"="-
"ApnUpdater"=-
"WinFastDTV"=-
"ArcSoft Connection Service"=-
"Malwarebytes' Anti-Malware (reboot)"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlSrvN"=-
"DAEMON Tools Lite"=-
"dxlock"=-
"WinFast Schedule"=-
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
[-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

Firefox::
FF - ProfilePath - c:\users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 2786678&q=

DDS::
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://eu.ask.com/?l=dis&o=14597
uDefault_Search_URL = hxxp://search.qip.ru
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie

Driver::
SSPORT

File::
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Image Retriever.lnk 

Folder::
c:\program files (x86)\Ask.com

-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#13 Příspěvek od romcolahvac »

Provedeno, zde je log:

ComboFix 11-07-29.03 - ROMAN 30.07.2011 16:02:08.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2046.448 [GMT 2:00]
Spuštěný z: c:\users\ROMAN\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\ROMAN\Desktop\CFScript.txt.txt
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\assets\oobe\b.png
c:\program files (x86)\Ask.com\assets\oobe\bl.png
c:\program files (x86)\Ask.com\assets\oobe\br.png
c:\program files (x86)\Ask.com\assets\oobe\l.png
c:\program files (x86)\Ask.com\assets\oobe\pointer.png
c:\program files (x86)\Ask.com\assets\oobe\r.png
c:\program files (x86)\Ask.com\assets\oobe\t.png
c:\program files (x86)\Ask.com\assets\oobe\tl.png
c:\program files (x86)\Ask.com\assets\oobe\tr.png
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_2858.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\precache.exe
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\Updater\config.xml
c:\program files (x86)\Ask.com\Updater\Updater.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\windows\SysWow64\logs
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SSPORT
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-28 do 2011-07-30 )))))))))))))))))))))))))))))))
.
.
2011-07-27 20:15 . 2011-07-27 20:17 -------- d-----w- c:\program files (x86)\HTML Beauty 2
2011-07-27 18:52 . 2011-07-27 18:52 -------- d-----w- c:\users\ROMAN\AppData\Roaming\Malwarebytes
2011-07-27 18:51 . 2011-07-27 18:51 -------- d-----w- c:\programdata\Malwarebytes
2011-07-27 18:51 . 2010-11-29 15:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-27 18:51 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-27 18:51 . 2011-07-27 18:51 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-25 19:20 . 2011-07-25 19:21 -------- d-----w- c:\program files (x86)\Memory Max
2011-07-23 17:04 . 2011-07-25 14:10 -------- d-----w- c:\program files\trend micro
2011-07-23 17:04 . 2011-07-23 17:05 -------- d-----w- C:\rsit
2011-07-21 15:50 . 2005-07-16 00:35 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2011-07-13 08:36 . 2011-06-03 06:56 421888 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-13 08:34 . 2011-04-28 03:55 552960 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-13 08:34 . 2011-04-28 03:54 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-13 08:34 . 2011-06-11 03:07 3137536 ----a-w- c:\windows\system32\win32k.sys
2011-07-07 08:32 . 2011-07-07 10:27 -------- d-----w- c:\program files (x86)\CamStudio
2011-07-07 08:28 . 2005-06-12 16:29 77824 ----a-w- c:\windows\SysWow64\fmcodec.DLL
2011-07-07 08:28 . 2011-07-07 08:28 -------- d-----w- c:\program files (x86)\Fox Magic
2011-07-06 08:12 . 2011-07-06 08:12 -------- d-----w- c:\windows\system32\SPReview
2011-07-06 08:10 . 2011-07-06 08:10 -------- d-----w- c:\windows\system32\EventProviders
2011-07-04 14:16 . 2011-07-04 14:16 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-03 15:01 . 2010-11-20 13:25 2264064 ----a-w- c:\windows\system32\VPCWizard.exe
2011-07-03 15:00 . 2010-11-20 13:25 4583424 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
2011-07-03 14:59 . 2010-11-20 13:27 1096704 ----a-w- c:\program files\Windows Photo Viewer\PhotoAcq.dll
2011-07-03 14:58 . 2010-11-20 13:27 403968 ----a-w- c:\windows\system32\untfs.dll
2011-07-03 14:57 . 2010-11-20 13:27 24064 ----a-w- c:\windows\system32\schedcli.dll
2011-07-03 14:56 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2011-07-03 14:56 . 2010-11-20 12:17 209920 ----a-w- c:\windows\SysWow64\PkgMgr.exe
2011-07-03 14:56 . 2010-11-20 12:18 323072 ----a-w- c:\windows\SysWow64\drvstore.dll
2011-07-03 14:56 . 2010-11-20 12:18 257024 ----a-w- c:\windows\SysWow64\dpx.dll
2011-07-03 14:56 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-07-03 14:56 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-07-03 14:52 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-07-03 14:52 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-07-03 14:52 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-07-03 14:52 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-07-03 14:52 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-07-03 14:52 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-07-03 14:52 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-21 14:30 . 2010-09-15 07:15 33152 ----a-w- c:\windows\system32\LMIport.dll
2011-07-21 14:30 . 2010-09-15 07:15 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-21 14:30 . 2010-09-15 07:15 80768 ----a-w- c:\windows\system32\LMIinit.dll
2011-07-13 04:53 . 2011-07-29 20:27 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DC18F878-A1C8-4686-8EBB-D6C3E1CB3B4E}\mpengine.dll
2011-07-06 08:26 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-07-06 08:26 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-04 11:43 . 2010-08-31 15:01 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:43 . 2010-08-31 15:01 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-04 11:43 . 2011-01-19 11:09 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-04 11:36 . 2011-05-25 18:46 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-04 11:36 . 2010-08-31 15:02 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-04 11:35 . 2010-08-31 15:02 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-04 11:32 . 2010-08-31 15:02 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-04 11:32 . 2010-08-31 15:02 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-04 11:32 . 2010-08-31 15:02 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-06-21 16:51 . 2011-05-23 17:44 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-09 09:16 . 2010-09-01 08:13 5018 --sha-w- c:\programdata\KGyGaAvL.sys
2011-06-03 05:57 . 2011-07-13 08:40 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2010-08-31 13:32 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 11:42 . 2011-06-30 07:11 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:40 . 2011-06-30 07:11 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:40 . 2011-06-30 07:11 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:39 . 2011-06-30 07:11 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:37 . 2011-06-30 07:11 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-05-04 05:25 . 2011-06-30 07:11 2315776 ----a-w- c:\windows\system32\tquery.dll
2011-05-04 05:22 . 2011-06-30 07:11 2223616 ----a-w- c:\windows\system32\mssrch.dll
2011-05-04 05:22 . 2011-06-30 07:11 778752 ----a-w- c:\windows\system32\mssvp.dll
2011-05-04 05:22 . 2011-06-30 07:11 491520 ----a-w- c:\windows\system32\mssph.dll
2011-05-04 05:22 . 2011-06-30 07:11 288256 ----a-w- c:\windows\system32\mssphtb.dll
2011-05-04 05:22 . 2011-06-30 07:11 75264 ----a-w- c:\windows\system32\msscntrs.dll
2011-05-04 05:19 . 2011-06-30 07:11 591872 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-05-04 05:19 . 2011-06-30 07:11 249856 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-05-04 05:19 . 2011-06-30 07:11 113664 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-05-04 04:34 . 2011-06-30 07:11 1549312 ----a-w- c:\windows\SysWow64\tquery.dll
2011-05-04 04:32 . 2011-06-30 07:11 666624 ----a-w- c:\windows\SysWow64\mssvp.dll
2011-05-04 04:32 . 2011-06-30 07:11 1401344 ----a-w- c:\windows\SysWow64\mssrch.dll
2011-05-04 04:32 . 2011-06-30 07:11 337408 ----a-w- c:\windows\SysWow64\mssph.dll
2011-05-04 04:32 . 2011-06-30 07:11 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll
2011-05-04 04:32 . 2011-06-30 07:11 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll
2011-05-04 04:28 . 2011-06-30 07:11 427520 ----a-w- c:\windows\SysWow64\SearchIndexer.exe
2011-05-04 04:28 . 2011-06-30 07:11 164352 ----a-w- c:\windows\SysWow64\SearchProtocolHost.exe
2011-05-04 04:28 . 2011-06-30 07:11 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe
2011-05-04 02:52 . 2010-09-02 10:32 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-05-03 05:29 . 2011-06-16 18:46 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-03 04:30 . 2011-06-16 18:46 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-28_20.53.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-07-28 18:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-07-30 14:28 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-07-30 14:28 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-28 18:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-28 18:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-30 14:28 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-08-31 12:39 . 2011-07-28 06:21 68018 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2010-08-31 12:39 . 2011-07-30 13:40 68018 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-07-28 06:22 36214 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-07-30 14:32 36214 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-08-31 12:32 . 2011-07-30 14:32 11284 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-876401281-3636213226-3406816674-1001_UserData.bin
+ 2010-08-31 18:28 . 2011-07-30 14:29 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-08-31 18:28 . 2011-07-28 06:19 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-08-31 18:28 . 2011-07-30 13:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-08-31 18:28 . 2011-07-28 06:19 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-28 06:19 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-30 13:38 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-07-28 06:16 . 2011-07-28 06:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-30 14:27 . 2011-07-30 14:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-30 14:27 . 2011-07-30 14:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-28 06:16 . 2011-07-28 06:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 05:01 . 2011-07-30 14:25 538288 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 04:45 . 2011-07-29 19:19 5081336 c:\windows\system32\FNTCACHE.DAT
+ 2010-08-31 17:23 . 2011-07-30 14:25 16470071 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-876401281-3636213226-3406816674-1001-12288.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-07-24 2245120]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-03 98304]
"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"TurboV EVO"="c:\program files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" [2009-09-10 7322624]
"LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-07 165208]
"iTraffic Monitor"="c:\program files (x86)\iTraffic Monitor\iTrafficMon.exe" [2009-04-22 942080]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Image Retriever.lnk - c:\program files (x86)\ScanSoft\PaperPort\xdcla.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [x]
R3 ATICDSDr;ATICDSDr;c:\users\ROMAN\AppData\Local\Temp\ATICDSDr.sys [x]
R3 EUDSKACS;EUDSKACS;c:\windows\sysWow64\drivers\eudskacs.sys [2009-12-02 17800]
R3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 EUBAKUP;EUBAKUP;c:\windows\sysWow64\drivers\eubakup.sys [2009-12-02 30600]
S0 EUFS;EUFS;c:\windows\sysWow64\drivers\eufs.sys [2009-12-02 26504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 NEOFLTR_650_16339;Juniper Networks TDI Filter Driver (NEOFLTR_650_16339);c:\windows\system32\Drivers\NEOFLTR_650_16339.SYS [x]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files (x86)\CyberLink\PlayMovie\000.fcl [2008-05-16 32240]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-08-19 90112]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 Cerberus FTP Server;Cerberus FTP Server;c:\program files (x86)\Cerberus LLC\Cerberus FTP Server\CerberusGUI.exe [2011-05-17 5376832]
S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-07-17 319488]
S2 EWA net DB Core;EWA net DB Core;c:\program files (x86)\EWA net\database\TransBase EWA\tbmux32.exe [2008-04-04 417792]
S2 EWA net DB EPC;EWA net DB EPC;c:\program files (x86)\EWA net\database\TransBase EPC\tbmux32.exe [2007-11-27 417792]
S2 EWA net DB WIS;EWA net DB WIS;c:\program files (x86)\EWA net\database\TransBase WIS\tbmux32.exe [2008-04-04 417792]
S2 EWA net Server;EWA net Server;c:\program files (x86)\EWA net\server\bin\tomcat.exe [2003-07-31 65536]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-07-21 375176]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-01-27 15928]
S2 LVPrcS64;Process Monitor;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-05-07 197976]
S2 MSSQL$FORDECATDB;SQL Server (FORDECATDB);c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S2 NAUpdate;Aktualizace Nero;c:\program files (x86)\Nero\Update\NASvc.exe [2010-02-18 462632]
S2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\program files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [2008-10-22 364635]
S2 TVESched;TVEnhance Task Scheduler (TTS));c:\program files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [2008-10-22 172121]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 EuDisk;EASEUS Disk Enumerator;c:\windows\system32\DRIVERS\EuDisk.sys [x]
S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech Webcam C160(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
S3 MTSBDA;TechniSat SkyStar HD2;c:\windows\system32\Drivers\MtsBda.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S3 WFLR6654;WinFast DTV1800 H (XC3028);c:\windows\system32\drivers\wfeaglxt.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-876401281-3636213226-3406816674-1001Core1cc04adfeaaf61.job
- c:\users\ROMAN\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-25 20:28]
.
2011-07-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-876401281-3636213226-3406816674-1001UA.job
- c:\users\ROMAN\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-25 20:28]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF5103.cfxxe" [X]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-01-27 57928]
.
------- Doplňkový sken -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: &Stáhnout všechno FlashGetem - c:\program files (x86)\FlashGet\jc_all.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Save Flash with Flash Catcher - c:\program files (x86)\Common Files\justDo\IECatcher.DLL/FlashCatcher.htm
IE: Stáhnout Free Download Managerem - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: ????3?? - c:\users\ROMAN\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\ROMAN\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
Trusted Zone: kuaiche.com\software
TCP: DhcpNameServer = 10.0.0.138 10.0.0.50
DPF: {0427F569-3D57-4F10-B9FB-8D71A6A7BE24} - file:///C:/Users/ROMAN/AppData/Local/Temp/KJPL60/frmeditor.ocx
FF - ProfilePath - c:\users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - file://///WL-500GPV2/part0/intra/index.html
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PlayMovie\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-876401281-3636213226-3406816674-1001\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@="c:\\Users\\ROMAN\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-876401281-3636213226-3406816674-1001\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@="c:\\Users\\ROMAN\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_USERS\S-1-5-21-876401281-3636213226-3406816674-1001\Software\SecuROM\License information*]
"datasecu"=hex:60,b4,74,a9,dc,4c,b2,4d,9b,70,a4,9d,90,6f,57,04,9b,3c,65,d6,1c,
63,cd,b6,8e,52,ef,8d,04,06,83,32,2b,9e,de,1c,57,3e,ab,f6,c9,97,a2,c6,b2,4d,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files (x86)\EWA net\database\TransBase EWA\tbkern32.exe
c:\program files (x86)\EWA net\database\TransBase EPC\tbkern32.exe
.
**************************************************************************
.
Celkový čas: 2011-07-30 16:39:06 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-30 14:39
ComboFix2.txt 2011-07-28 21:08
.
Před spuštěním: Volných bajtů: 31 562 997 760
Po spuštění: Volných bajtů: 30 766 075 904
.
- - End Of File - - 1258B214F494A15A8722DAA841BABB5B

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu logu

#14 Příspěvek od motji »

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

romcolahvac
Návštěvník
Návštěvník
Příspěvky: 186
Registrován: 23 pro 2008 00:30

Re: Prosím o kontrolu logu

#15 Příspěvek od romcolahvac »

Dobrý den, všechno jsem provedl PC mi připadá dobrý, dokoupil jsem druhou RAM 2GB , nyní je operační paměť 4GB. zde je log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by ROMAN at 2011-07-31 12:24:35
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 28 GB (14%) free of 191 GB
Total RAM: 4094 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:24:37, on 31.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\iTraffic Monitor\iTrafficMon.exe
C:\Program Files (x86)\ASUS\TurboV EVO\TurboVHELP.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\Program Files (x86)\Mozilla Firefox 3\firefox.exe
C:\Program Files (x86)\Mozilla Firefox 3\plugin-container.exe
C:\Program Files\trend micro\ROMAN.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\Program Files (x86)\Common Files\justDo\Jd2002.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {D5D47440-0750-463D-BAEF-A47D02414806} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~2\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [TurboV EVO] "C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [iTraffic Monitor] C:\Program Files (x86)\iTraffic Monitor\iTrafficMon.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Image Retriever.lnk = C:\Program Files (x86)\ScanSoft\PaperPort\xdcla.exe
O8 - Extra context menu item: &Stáhnout všechno FlashGetem - C:\Program Files (x86)\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL/FlashCatcher.htm
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL
O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files (x86)\QIP\qip.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://software.kuaiche.com
O16 - DPF: {0427F569-3D57-4F10-B9FB-8D71A6A7BE24} (FormelEditor Control) - file:///C:/Users/ROMAN/AppData/Local/Temp/KJPL60/frmeditor.ocx
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.5.7.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/Juni ... Client.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Cerberus FTP Server - Cerberus, LLC - C:\Program Files (x86)\Cerberus LLC\Cerberus FTP Server\CerberusGUI.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\ASUS.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EWA net DB Core - Transaction Software, D 81829 Munich - C:\Program Files (x86)\EWA net\database\TransBase EWA\tbmux32.exe
O23 - Service: EWA net DB EPC - Transaction Software, D 81829 Munich - C:\Program Files (x86)\EWA net\database\TransBase EPC\tbmux32.exe
O23 - Service: EWA net DB WIS - Transaction Software, D 81829 Munich - C:\Program Files (x86)\EWA net\database\TransBase WIS\tbmux32.exe
O23 - Service: EWA net Server - Alexandria Software Consulting - C:\Program Files (x86)\EWA net\server\bin\tomcat.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TVEnhance Background Capture Service (TBCS) (TVECapSvc) - Unknown owner - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe
O23 - Service: TVEnhance Task Scheduler (TTS)) (TVESched) - Unknown owner - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14582 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x310
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
atieclxx
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
"C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe" -hide
"C:\Program Files (x86)\iTraffic Monitor\iTrafficMon.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
taskeng.exe {0CFB0961-1A09-476B-9653-719C12A7BFEB}
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\ASUS\TurboV EVO\TurboVHELP.exe"
"C:\Program Files\ASUS\Six Engine\SixEngine.exe" -b
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Cerberus LLC\Cerberus FTP Server\CerberusGUI.exe" -Service
"C:\ASUS.SYS\config\DVMExportService.exe"
"C:\Program Files (x86)\EWA net\database\TransBase EWA\tbmux32.exe"
"C:\Program Files (x86)\EWA net\database\TransBase EPC\tbmux32.exe"
"C:\Program Files (x86)\EWA net\database\TransBase WIS\tbmux32.exe"
"C:\Program Files (x86)\EWA net\server\bin\tomcat.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
"C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe"
"C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe"
"C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe" -Embedding
"C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sFORDECATDB
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe"
"C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe"
"C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3764
"C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\EWA net\database\TransBase EWA\tbkern32.exe" -dedi 36734 -inactivity 0
"C:\Program Files (x86)\EWA net\database\TransBase EPC\tbkern32.exe" -dedi 28996 -inactivity 0 -crypt
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Mozilla Firefox 3\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox 3\plugin-container.exe" --channel=2208.13cf6c50.1572259482 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.6.0 -greomni "C:\Program Files (x86)\Mozilla Firefox 3\omni.jar" 2208 "\\.\pipe\gecko-crash-server-pipe.2208" plugin
C:\Windows\system32\wbem\wmiprvse.exe
taskhost.exe $(Arg0)
"C:\Windows\system32\SearchFilterHost.exe" 0 528 532 540 65536 536
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\ROMAN\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-876401281-3636213226-3406816674-1001Core1cc04adfeaaf61.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-876401281-3636213226-3406816674-1001UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "file://///WL-500GPV2/part0/intra/index.html"
prefs.js - "extensions.enabledItems" - "LogMeInClient@logmein.com:1.0.0.608, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

C:\Program Files (x86)\Mozilla Firefox 3\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox 3\components\
binary.manifest
browsercomps.dll
FlashGet3.xpi
IICAClient.xpt

C:\Program Files (x86)\Mozilla Firefox 3\plugins\
cgpcfg.dll
CgpCore.dll
confmgr.dll
ctxmui.dll
ICAClObj.class
icafile.dll
icalogon.dll
logging.dll
np-mswmp.dll
npdeployJava1.dll
npicaN.dll
nppdf32.dll
npwachk.dll
sslsdk_b.dll
TcpPServ.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox 3\searchplugins\
Cetrumcz_igeared.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default\extensions\
engine@conduit.com
LogMeInClient@logmein.com
maps@ovi.com
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}

C:\Users\ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\ls90gvhb.default\searchplugins\
askcom.xml
conduit.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin.xml
qipsearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Users\ROMAN\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-06-09 138240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E}]
SnapFlash Class - C:\Program Files (x86)\Common Files\justDo\Jd2002.dll [2002-12-03 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D5D47440-0750-463D-BAEF-A47D02414806}
{E0E899AB-F487-11D5-8D29-0050BA6940E3} - FlashGet Bar - C:\PROGRA~2\FlashGet\fgiebar.dll [2005-06-07 86016]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2010-01-27 57928]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\602PC SUITE PDF Saver]
C:\Program Files (x86)\Common Files\soft602\pdfSaver.exe [2005-08-31 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2010-08-20 33120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-12-14 47904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [2009-01-30 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FineReader7NewsReaderPro]
C:\Program Files (x86)\ABBYY FineReader 7.0 Professional Edition\ABBYYNewsReader.exe [2005-01-23 290816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashGet]
C:\Program Files (x86)\FlashGet Network\FlashGet universal\flashget.exe /min []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\ROMAN\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-25 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-01-25 421160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-02-22 1226024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfSaver3]
c:\Program Files\PDF\pdfSaver\pdfSaver3.exe [2004-05-19 385024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe [2008-09-24 172032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
C:\Users\ROMAN\AppData\Roaming\QipGuard\QipGuard.exe [2010-06-09 187904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVEService]
C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe [2008-10-23 180224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFast Schedule]
C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2010-08-11 2920448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFastDTV]
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2011-06-08 101888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^ROMAN^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~2\MICROS~2\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-07-24 2245120]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-08-03 98304]
"ATICustomerCare"=C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [2010-03-04 311296]
"TurboV EVO"=C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe [2009-09-10 7322624]
"LWS"=C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [2010-05-07 165208]
"iTraffic Monitor"=C:\Program Files (x86)\iTraffic Monitor\iTrafficMon.exe [2009-04-22 942080]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Image Retriever.lnk - C:\Program Files (x86)\ScanSoft\PaperPort\xdcla.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-03-21 249344]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"
"C:\FIREFOX STAHOVANI\facebook-pic000934519.exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcod64.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-07-31 12:21:56 ----D---- C:\rsit
2011-07-31 12:04:00 ----D---- C:\Program Files (x86)\CCleaner
2011-07-30 21:32:10 ----A---- C:\Windows\SYSWOW64\tsccvid.dll
2011-07-30 21:32:08 ----D---- C:\Program Files (x86)\CDVPlayer
2011-07-30 21:32:06 ----N---- C:\Windows\Setup1.exe
2011-07-30 21:32:04 ----A---- C:\Windows\ST6UNST.EXE
2011-07-30 20:38:43 ----D---- C:\Users\ROMAN\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-07-30 20:07:58 ----A---- C:\Windows\SYSWOW64\Dvbpws.dll
2011-07-30 16:30:50 ----D---- C:\Windows\SYSWOW64\logs
2011-07-30 16:28:20 ----D---- C:\$RECYCLE.BIN
2011-07-27 22:15:51 ----D---- C:\Program Files (x86)\HTML Beauty 2
2011-07-27 20:52:02 ----D---- C:\Users\ROMAN\AppData\Roaming\Malwarebytes
2011-07-27 20:51:46 ----D---- C:\ProgramData\Malwarebytes
2011-07-27 20:51:46 ----A---- C:\Windows\SYSWOW64\drivers\mbamswissarmy.sys
2011-07-27 20:51:43 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-07-27 20:51:42 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-07-25 21:20:58 ----D---- C:\Program Files (x86)\Memory Max
2011-07-23 19:04:49 ----D---- C:\Program Files\trend micro
2011-07-21 17:50:05 ----A---- C:\Windows\SYSWOW64\unicows.dll
2011-07-13 10:40:16 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 10:40:15 ----A---- C:\Windows\system32\wow64win.dll
2011-07-13 10:40:15 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 10:40:14 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 10:40:12 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-13 10:40:12 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-13 10:40:12 ----A---- C:\Windows\system32\wow64.dll
2011-07-13 10:40:11 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-13 10:40:11 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-13 10:40:10 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-13 10:40:10 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-13 10:40:10 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-13 10:40:06 ----A---- C:\Windows\SYSWOW64\user.exe
2011-07-13 10:36:04 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 10:35:54 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-13 10:35:51 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 10:35:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 10:35:49 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 10:35:49 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 10:35:48 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 10:35:47 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 10:35:46 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 10:35:44 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 10:35:43 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 10:35:42 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 10:34:34 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-07-13 10:34:33 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-07-13 10:34:29 ----A---- C:\Windows\system32\win32k.sys
2011-07-07 10:32:34 ----D---- C:\Program Files (x86)\CamStudio
2011-07-07 10:28:12 ----A---- C:\Windows\SYSWOW64\fmcodec.DLL
2011-07-07 10:28:11 ----D---- C:\Program Files (x86)\Fox Magic
2011-07-06 10:12:42 ----D---- C:\Windows\system32\SPReview
2011-07-06 10:10:00 ----D---- C:\Windows\system32\EventProviders
2011-07-06 10:03:18 ----D---- C:\Windows\pss
2011-07-04 16:15:18 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-07-04 16:15:18 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-07-04 16:15:18 ----A---- C:\Windows\SYSWOW64\java.exe
2011-07-03 17:02:01 ----A---- C:\Windows\system32\vpc.exe
2011-07-03 17:02:01 ----A---- C:\Windows\system32\netfxperf.dll
2011-07-03 17:02:01 ----A---- C:\Windows\system32\dfshim.dll
2011-07-03 17:01:54 ----A---- C:\Windows\system32\VPCWizard.exe
2011-07-03 17:01:54 ----A---- C:\Windows\system32\VPCSettings.exe
2011-07-03 17:01:54 ----A---- C:\Windows\system32\VMCPropertyHandler.dll
2011-07-03 17:01:53 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-07-03 17:01:52 ----A---- C:\Windows\system32\VMWindow.exe
2011-07-03 17:01:52 ----A---- C:\Windows\system32\vmsal.exe
2011-07-03 17:01:50 ----A---- C:\Windows\system32\drivers\vpcvmm.sys
2011-07-03 17:01:49 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2011-07-03 17:01:48 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-07-03 17:01:48 ----A---- C:\Windows\system32\mstscax.dll
2011-07-03 17:01:47 ----A---- C:\Windows\system32\d3d10warp.dll
2011-07-03 17:01:41 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-07-03 17:01:35 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-07-03 17:01:33 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-07-03 17:01:33 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-07-03 17:01:33 ----A---- C:\Windows\system32\tssrvlic.dll
2011-07-03 17:01:33 ----A---- C:\Windows\system32\sysmain.dll
2011-07-03 17:01:33 ----A---- C:\Windows\system32\RDVGHelper.exe
2011-07-03 17:01:32 ----A---- C:\Windows\system32\rdpcorets.dll
2011-07-03 17:01:31 ----A---- C:\Windows\system32\shell32.dll
2011-07-03 17:01:30 ----A---- C:\Windows\SYSWOW64\pmcsnap.dll
2011-07-03 17:01:29 ----A---- C:\Windows\system32\MSVidCtl.dll
2011-07-03 17:01:27 ----A---- C:\Windows\SYSWOW64\vmsal.exe
2011-07-03 17:01:26 ----A---- C:\Windows\system32\wmp.dll
2011-07-03 17:01:23 ----A---- C:\Windows\system32\ntdll.dll
2011-07-03 17:01:23 ----A---- C:\Windows\system32\mscoree.dll
2011-07-03 17:01:22 ----A---- C:\Windows\system32\mmcndmgr.dll
2011-07-03 17:01:19 ----A---- C:\Windows\system32\secproc_isv.dll
2011-07-03 17:01:19 ----A---- C:\Windows\system32\mf.dll
2011-07-03 17:01:17 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2011-07-03 17:01:17 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-07-03 17:01:16 ----A---- C:\Windows\system32\secproc.dll
2011-07-03 17:01:16 ----A---- C:\Windows\system32\RMActivate.exe
2011-07-03 17:01:15 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-07-03 17:01:15 ----A---- C:\Windows\system32\xpsservices.dll
2011-07-03 17:01:13 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2011-07-03 17:01:11 ----A---- C:\Windows\SYSWOW64\secproc.dll
2011-07-03 17:01:11 ----A---- C:\Windows\system32\rpcrt4.dll
2011-07-03 17:01:10 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2011-07-03 17:01:10 ----A---- C:\Windows\SYSWOW64\PushPrinterConnections.exe
2011-07-03 17:01:10 ----A---- C:\Windows\SYSWOW64\ppcsnap.dll
2011-07-03 17:01:09 ----A---- C:\Windows\system32\schedsvc.dll
2011-07-03 17:01:09 ----A---- C:\Windows\system32\ole32.dll
2011-07-03 17:01:08 ----A---- C:\Windows\system32\spwizui.dll
2011-07-03 17:01:07 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-07-03 17:01:06 ----A---- C:\Windows\system32\taskschd.dll
2011-07-03 17:01:06 ----A---- C:\Windows\system32\RacEngn.dll
2011-07-03 17:01:06 ----A---- C:\Windows\system32\diagperf.dll
2011-07-03 17:01:05 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-07-03 17:01:05 ----A---- C:\Windows\system32\wevtsvc.dll
2011-07-03 17:01:05 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-07-03 17:01:04 ----A---- C:\Windows\system32\vssapi.dll
2011-07-03 17:01:03 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2011-07-03 17:01:03 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2011-07-03 17:01:03 ----A---- C:\Windows\system32\msxml3.dll
2011-07-03 17:01:03 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2011-07-03 17:01:01 ----A---- C:\Windows\system32\UIRibbon.dll
2011-07-03 17:01:01 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2011-07-03 17:00:58 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-07-03 17:00:56 ----A---- C:\Windows\system32\WsmSvc.dll
2011-07-03 17:00:55 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-07-03 17:00:55 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-07-03 17:00:55 ----A---- C:\Windows\system32\WMVCORE.DLL
2011-07-03 17:00:55 ----A---- C:\Windows\system32\rdpudd.dll
2011-07-03 17:00:55 ----A---- C:\Windows\system32\rdpdd.dll
2011-07-03 17:00:55 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-07-03 17:00:55 ----A---- C:\Windows\system32\PresentationHost.exe
2011-07-03 17:00:54 ----A---- C:\Windows\system32\spreview.exe
2011-07-03 17:00:54 ----A---- C:\Windows\system32\spinstall.exe
2011-07-03 17:00:54 ----A---- C:\Windows\system32\MPSSVC.dll
2011-07-03 17:00:53 ----A---- C:\Windows\system32\WinSAT.exe
2011-07-03 17:00:53 ----A---- C:\Windows\system32\drivers\vpchbus.sys
2011-07-03 17:00:53 ----A---- C:\Windows\system32\drivers\vpcusb.sys
2011-07-03 17:00:53 ----A---- C:\Windows\system32\CertEnroll.dll
2011-07-03 17:00:52 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-07-03 17:00:51 ----A---- C:\Windows\system32\msxml6.dll
2011-07-03 17:00:51 ----A---- C:\Windows\system32\d3d9.dll
2011-07-03 17:00:50 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2011-07-03 17:00:50 ----A---- C:\Windows\system32\SearchFolder.dll
2011-07-03 17:00:50 ----A---- C:\Windows\system32\IKEEXT.DLL
2011-07-03 17:00:49 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2011-07-03 17:00:49 ----A---- C:\Windows\system32\gpsvc.dll
2011-07-03 17:00:49 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2011-07-03 17:00:48 ----A---- C:\Windows\system32\VSSVC.exe
2011-07-03 17:00:48 ----A---- C:\Windows\system32\dwmcore.dll
2011-07-03 17:00:47 ----A---- C:\Windows\system32\drivers\http.sys
2011-07-03 17:00:47 ----A---- C:\Windows\system32\dbgeng.dll
2011-07-03 17:00:46 ----A---- C:\Windows\SYSWOW64\rdvgumd32.dll
2011-07-03 17:00:46 ----A---- C:\Windows\system32\drivers\ndis.sys
2011-07-03 17:00:45 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-07-03 17:00:45 ----A---- C:\Windows\system32\crypt32.dll
2011-07-03 17:00:44 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-07-03 17:00:44 ----A---- C:\Windows\system32\actxprxy.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\TSWorkspace.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\schannel.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\qmgr.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\lsasrv.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\gpprefcl.dll
2011-07-03 17:00:43 ----A---- C:\Windows\system32\audiosrv.dll
2011-07-03 17:00:42 ----A---- C:\Windows\system32\termsrv.dll
2011-07-03 17:00:41 ----A---- C:\Windows\system32\sqmapi.dll
2011-07-03 17:00:41 ----A---- C:\Windows\system32\mstsc.exe
2011-07-03 17:00:40 ----A---- C:\Windows\system32\netlogon.dll
2011-07-03 17:00:40 ----A---- C:\Windows\system32\imapi2fs.dll
2011-07-03 17:00:40 ----A---- C:\Windows\system32\drivers\vpcnfltr.sys
2011-07-03 17:00:39 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2011-07-03 17:00:39 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2011-07-03 17:00:39 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2011-07-03 17:00:39 ----A---- C:\Windows\system32\winhttp.dll
2011-07-03 17:00:39 ----A---- C:\Windows\system32\QAGENTRT.DLL
2011-07-03 17:00:39 ----A---- C:\Windows\system32\msv1_0.dll
2011-07-03 17:00:39 ----A---- C:\Windows\system32\d3d11.dll
2011-07-03 17:00:38 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-07-03 17:00:38 ----A---- C:\Windows\system32\setupapi.dll
2011-07-03 17:00:38 ----A---- C:\Windows\system32\rpcss.dll
2011-07-03 17:00:38 ----A---- C:\Windows\system32\propsys.dll
2011-07-03 17:00:37 ----A---- C:\Windows\system32\werconcpl.dll
2011-07-03 17:00:37 ----A---- C:\Windows\system32\wbengine.exe
2011-07-03 17:00:37 ----A---- C:\Windows\system32\PushPrinterConnections.exe
2011-07-03 17:00:37 ----A---- C:\Windows\system32\authui.dll
2011-07-03 17:00:36 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2011-07-03 17:00:36 ----A---- C:\Windows\system32\taskeng.exe
2011-07-03 17:00:36 ----A---- C:\Windows\system32\odbc32.dll
2011-07-03 17:00:35 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-07-03 17:00:35 ----A---- C:\Windows\system32\WSDApi.dll
2011-07-03 17:00:35 ----A---- C:\Windows\system32\user32.dll
2011-07-03 17:00:34 ----A---- C:\Windows\system32\drivers\netio.sys
2011-07-03 17:00:34 ----A---- C:\Windows\system32\dhcpcore.dll
2011-07-03 17:00:34 ----A---- C:\Windows\system32\certmgr.dll
2011-07-03 17:00:33 ----A---- C:\Windows\SYSWOW64\wer.dll
2011-07-03 17:00:33 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\webio.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\umrdp.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\scavengeui.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\LSCSHostPolicy.dll
2011-07-03 17:00:33 ----A---- C:\Windows\system32\drivers\tdx.sys
2011-07-03 17:00:33 ----A---- C:\Windows\system32\drivers\netbt.sys
2011-07-03 17:00:32 ----A---- C:\Windows\SYSWOW64\certcli.dll
2011-07-03 17:00:32 ----A---- C:\Windows\system32\tsmf.dll
2011-07-03 17:00:32 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2011-07-03 17:00:32 ----A---- C:\Windows\system32\localspl.dll
2011-07-03 17:00:31 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-07-03 17:00:31 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2011-07-03 17:00:31 ----A---- C:\Windows\system32\shlwapi.dll
2011-07-03 17:00:31 ----A---- C:\Windows\system32\ncsi.dll
2011-07-03 17:00:31 ----A---- C:\Windows\system32\msdrm.dll
2011-07-03 17:00:30 ----A---- C:\Windows\system32\netshell.dll
2011-07-03 17:00:30 ----A---- C:\Windows\system32\msdtctm.dll
2011-07-03 17:00:30 ----A---- C:\Windows\system32\framedynos.dll
2011-07-03 17:00:29 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2011-07-03 17:00:29 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-07-03 17:00:29 ----A---- C:\Windows\system32\ws2_32.dll
2011-07-03 17:00:29 ----A---- C:\Windows\system32\winlogon.exe
2011-07-03 17:00:29 ----A---- C:\Windows\system32\rdpshell.exe
2011-07-03 17:00:29 ----A---- C:\Windows\system32\netcfgx.dll
2011-07-03 17:00:29 ----A---- C:\Windows\system32\drivers\cng.sys
2011-07-03 17:00:29 ----A---- C:\Windows\system32\appmgr.dll
2011-07-03 17:00:28 ----A---- C:\Windows\system32\usp10.dll
2011-07-03 17:00:28 ----A---- C:\Windows\system32\quartz.dll
2011-07-03 17:00:28 ----A---- C:\Windows\system32\nlasvc.dll
2011-07-03 17:00:28 ----A---- C:\Windows\system32\lsm.exe
2011-07-03 17:00:28 ----A---- C:\Windows\system32\comdlg32.dll
2011-07-03 17:00:27 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-07-03 17:00:27 ----A---- C:\Windows\system32\wmpps.dll
2011-07-03 17:00:27 ----A---- C:\Windows\system32\dxgi.dll
2011-07-03 17:00:27 ----A---- C:\Windows\system32\drivers\csc.sys
2011-07-03 17:00:27 ----A---- C:\Windows\system32\apphelp.dll
2011-07-03 17:00:26 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2011-07-03 17:00:26 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2011-07-03 17:00:25 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-07-03 17:00:25 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2011-07-03 17:00:25 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2011-07-03 17:00:25 ----A---- C:\Windows\system32\wpdshext.dll
2011-07-03 17:00:25 ----A---- C:\Windows\system32\Query.dll
2011-07-03 17:00:25 ----A---- C:\Windows\system32\mswsock.dll
2011-07-03 17:00:25 ----A---- C:\Windows\system32\azroles.dll
2011-07-03 17:00:24 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2011-07-03 17:00:24 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2011-07-03 17:00:24 ----A---- C:\Windows\system32\Vault.dll
2011-07-03 17:00:24 ----A---- C:\Windows\system32\QAGENT.DLL
2011-07-03 17:00:24 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-07-03 17:00:24 ----A---- C:\Windows\system32\BFE.DLL
2011-07-03 17:00:23 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2011-07-03 17:00:23 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2011-07-03 17:00:23 ----A---- C:\Windows\system32\win32spl.dll
2011-07-03 17:00:23 ----A---- C:\Windows\system32\samsrv.dll
2011-07-03 17:00:23 ----A---- C:\Windows\system32\lpksetup.exe
2011-07-03 17:00:23 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2011-07-03 17:00:23 ----A---- C:\Windows\system32\cmd.exe
2011-07-03 17:00:22 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2011-07-03 17:00:22 ----A---- C:\Windows\system32\cscsvc.dll
2011-07-03 17:00:21 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2011-07-03 17:00:21 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2011-07-03 17:00:21 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2011-07-03 17:00:21 ----A---- C:\Windows\system32\WebClnt.dll
2011-07-03 17:00:21 ----A---- C:\Windows\system32\rdpclip.exe
2011-07-03 17:00:20 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-07-03 17:00:20 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-07-03 17:00:20 ----A---- C:\Windows\SYSWOW64\Query.dll
2011-07-03 17:00:20 ----A---- C:\Windows\system32\WindowsCodecs.dll
2011-07-03 17:00:20 ----A---- C:\Windows\system32\sxs.dll
2011-07-03 17:00:20 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2011-07-03 17:00:19 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2011-07-03 17:00:19 ----A---- C:\Windows\SYSWOW64\gpprefcl.dll
2011-07-03 17:00:19 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2011-07-03 17:00:19 ----A---- C:\Windows\system32\Wldap32.dll
2011-07-03 17:00:19 ----A---- C:\Windows\system32\taskcomp.dll
2011-07-03 17:00:19 ----A---- C:\Windows\system32\mfds.dll
2011-07-03 17:00:19 ----A---- C:\Windows\system32\mcbuilder.exe
2011-07-03 17:00:19 ----A---- C:\Windows\system32\cscobj.dll
2011-07-03 17:00:17 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-07-03 17:00:17 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-07-03 17:00:17 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2011-07-03 17:00:17 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2011-07-03 17:00:17 ----A---- C:\Windows\system32\wuaueng.dll
2011-07-03 17:00:17 ----A---- C:\Windows\system32\pnidui.dll
2011-07-03 17:00:17 ----A---- C:\Windows\system32\ipsmsnap.dll
2011-07-03 17:00:17 ----A---- C:\Windows\system32\hgprint.dll
2011-07-03 17:00:16 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-07-03 17:00:16 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2011-07-03 17:00:16 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2011-07-03 17:00:16 ----A---- C:\Windows\system32\webservices.dll
2011-07-03 17:00:16 ----A---- C:\Windows\system32\SessEnv.dll
2011-07-03 17:00:16 ----A---- C:\Windows\system32\rdpendp.dll
2011-07-03 17:00:15 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2011-07-03 17:00:15 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2011-07-03 17:00:15 ----A---- C:\Windows\SYSWOW64\authui.dll
2011-07-03 17:00:15 ----A---- C:\Windows\system32\winsta.dll
2011-07-03 17:00:15 ----A---- C:\Windows\system32\sqlsrv32.dll
2011-07-03 17:00:15 ----A---- C:\Windows\system32\spoolsv.exe
2011-07-03 17:00:15 ----A---- C:\Windows\system32\fveapi.dll
2011-07-03 17:00:15 ----A---- C:\Windows\system32\dot3api.dll
2011-07-03 17:00:14 ----A---- C:\Windows\SYSWOW64\usp10.dll
2011-07-03 17:00:14 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2011-07-03 17:00:14 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2011-07-03 17:00:14 ----A---- C:\Windows\system32\gdi32.dll
2011-07-03 17:00:14 ----A---- C:\Windows\system32\drivers\volsnap.sys
2011-07-03 17:00:14 ----A---- C:\Windows\system32\drivers\msrpc.sys
2011-07-03 17:00:13 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2011-07-03 17:00:13 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2011-07-03 17:00:13 ----A---- C:\Windows\system32\WMNetMgr.dll
2011-07-03 17:00:13 ----A---- C:\Windows\system32\schtasks.exe
2011-07-03 17:00:13 ----A---- C:\Windows\system32\prncache.dll
2011-07-03 17:00:13 ----A---- C:\Windows\system32\mcmde.dll
2011-07-03 17:00:12 ----A---- C:\Windows\SYSWOW64\userenv.dll
2011-07-03 17:00:12 ----A---- C:\Windows\system32\wuapi.dll
2011-07-03 17:00:12 ----A---- C:\Windows\system32\wlanpref.dll
2011-07-03 17:00:12 ----A---- C:\Windows\system32\vpnike.dll
2011-07-03 17:00:12 ----A---- C:\Windows\system32\userenv.dll
2011-07-03 17:00:11 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2011-07-03 17:00:11 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-07-03 17:00:11 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\wintrust.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\tspubwmi.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\photowiz.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\evr.dll
2011-07-03 17:00:11 ----A---- C:\Windows\system32\drivers\rdbss.sys
2011-07-03 17:00:11 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2011-07-03 17:00:10 ----A---- C:\Windows\system32\framedyn.dll
2011-07-03 17:00:09 ----A---- C:\Windows\system32\wmpmde.dll
2011-07-03 17:00:09 ----A---- C:\Windows\system32\sppobjs.dll
2011-07-03 17:00:09 ----A---- C:\Windows\system32\IPSECSVC.DLL
2011-07-03 17:00:09 ----A---- C:\Windows\system32\FXSSVC.exe
2011-07-03 17:00:09 ----A---- C:\Windows\system32\AudioSes.dll
2011-07-03 17:00:09 ----A---- C:\Windows\system32\aepdu.dll
2011-07-03 17:00:08 ----A---- C:\Windows\SYSWOW64\cmd.exe
2011-07-03 17:00:08 ----A---- C:\Windows\system32\WMPEncEn.dll
2011-07-03 17:00:08 ----A---- C:\Windows\system32\wmpeffects.dll
2011-07-03 17:00:08 ----A---- C:\Windows\system32\SyncCenter.dll
2011-07-03 17:00:08 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-07-03 17:00:07 ----A---- C:\Windows\system32\tscfgwmi.dll
2011-07-03 17:00:07 ----A---- C:\Windows\system32\srvsvc.dll
2011-07-03 17:00:07 ----A---- C:\Windows\system32\shsvcs.dll
2011-07-03 17:00:07 ----A---- C:\Windows\system32\rdpinit.exe
2011-07-03 17:00:07 ----A---- C:\Windows\system32\aeinv.dll
2011-07-03 17:00:06 ----A---- C:\Windows\system32\fde.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\propsys.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\mfds.dll
2011-07-03 17:00:05 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\WinSATAPI.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\vmicsvc.exe
2011-07-03 17:00:05 ----A---- C:\Windows\system32\stobject.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\localsec.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\imapi2.dll
2011-07-03 17:00:05 ----A---- C:\Windows\system32\credui.dll
2011-07-03 17:00:04 ----A---- C:\Windows\SYSWOW64\user32.dll
2011-07-03 17:00:04 ----A---- C:\Windows\SYSWOW64\rdpendp.dll
2011-07-03 17:00:04 ----A---- C:\Windows\system32\netdiagfx.dll
2011-07-03 17:00:04 ----A---- C:\Windows\system32\iphlpsvc.dll
2011-07-03 17:00:04 ----A---- C:\Windows\system32\drivers\vmbus.sys
2011-07-03 17:00:04 ----A---- C:\Windows\system32\drivers\udfs.sys
2011-07-03 17:00:04 ----A---- C:\Windows\system32\cdd.dll
2011-07-03 17:00:04 ----A---- C:\Windows\system32\bcryptprimitives.dll
2011-07-03 17:00:03 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2011-07-03 17:00:03 ----A---- C:\Windows\SYSWOW64\azroles.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\tcpipcfg.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\spp.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\QSHVHOST.DLL
2011-07-03 17:00:03 ----A---- C:\Windows\system32\netid.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\inetpp.dll
2011-07-03 17:00:03 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2011-07-03 17:00:03 ----A---- C:\Windows\system32\davclnt.dll
2011-07-03 17:00:02 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2011-07-03 17:00:02 ----A---- C:\Windows\system32\profsvc.dll
2011-07-03 17:00:02 ----A---- C:\Windows\system32\cscui.dll
2011-07-03 17:00:02 ----A---- C:\Windows\system32\biocpl.dll
2011-07-03 17:00:01 ----A---- C:\Windows\SYSWOW64\themeui.dll
2011-07-03 17:00:01 ----A---- C:\Windows\system32\scansetting.dll

Odpovědět