Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Opakované útoky při zapnutí počítače

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Opakované útoky při zapnutí počítače

#1 Příspěvek od Aerox1 »

Dobrý den,
poslední 2 týdny se potýkám s problémem údajných útoků na můj počítač. A to vždy po zapnutí.
Jedná se podle antiviru ESET Smart Security 5 o zneužití skrytého kanálu v ICMP paketu a to vždy z IP adresy : 87.248.122.122 . V souvislosti s tím mi přestávají fungovat i webové služby jako např. Android Market či mám problémy s přihlášením na Facebook ( nepřihlásím se z důvodu že se stránka opravuje ) .
Chci se zeptat zda by měl někdo nejaké řešení, nápad, či radu.
Děkuji

Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Re: Opakované útoky při zapnutí počítače

#2 Příspěvek od Aerox1 »

Přikládám log z RSIT :
________________________________________________________________________________

Logfile of random's system information tool 1.09 (written by random/random)
Run by Honza at 2011-12-27 20:26:20
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 285 GB (60%) free of 477 GB
Total RAM: 4073 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:26:24, on 27.12.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Windows\AsScrPro.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\GIGABYTE\vivoTV\ScheduleAgent.exe
C:\Windows\system\Cm106eye.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe
C:\ExpressGateUtil\VAWinAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\GIGABYTE\U7300 Utilities\CONRCtl.exe
C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Honza.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [FLxHCIm] "C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [CPMonitor] "C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe"
O4 - HKLM\..\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [VAWinAgent] C:\ExpressGateUtil\VAWinAgent.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TiVme Agent] C:\Program Files (x86)\GIGABYTE\vivoTV\ScheduleAgent.exe srec
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Remote Control.lnk = C:\Program Files (x86)\GIGABYTE\U7300 Utilities\CONRCtl.exe
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VideAceWindowsService - Unknown owner - C:\ExpressGateUtil\VAWinService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10466 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe" -switch-3be2f036c43042cdb03588591c9325c3
C:\Windows\System32\spoolsv.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
taskeng.exe {A881126E-A712-4558-9553-F4E424209288}
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
taskeng.exe {069C862C-2ECF-4B51-B043-E5CAD03E3356}
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\Intel\TurboBoost\TurboBoost.exe"
C:\ExpressGateUtil\VAWinService.exe
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Windows\AsScrPro.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Windows\System32\rundll32.exe" C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm106.dll,CMICtrlWnd
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\Program Files (x86)\GIGABYTE\vivoTV\ScheduleAgent.exe" srec
"C:\Windows\system\Cm106eye.exe"
"C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe"
"C:\ExpressGateUtil\VAWinAgent.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
"C:\Program Files (x86)\GIGABYTE\U7300 Utilities\CONRCtl.exe"
C:\Windows\system32\wbem\wmiprvse.exe
ATKOSD.exe
KBFiltr.exe
WDC.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-1d085f84-4e22-4f5a-9051-12b8ebfe32a8 -SystemEventPortName:HostProcess-68a78ff2-f54b-47d3-8a0c-c6b03f7a8f22 -IoCancelEventPortName:HostProcess-99bbf76e-5c88-462e-bc43-2c7493dcc030 -NonStateChangingEventPortName:HostProcess-2430bd73-5407-4cad-8cc4-2d58694baf61 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:45eacfa6-a4d6-4697-b978-28c5ec43aaba
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Windows\system32\mspaint.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/OriginalAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warmest_socket/ --enable-print-preview --channel=5128.05B0A180.873469622 /prefetch:3
C:\Windows\system32\rundll32.exe "C:\Users\Honza\AppData\Local\Google\Chrome\APPLIC~1\160912~1.63\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Honza\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll" --lang=cs --channel=5128.073BE540.1540747767 --flash-broker=584 /prefetch:4
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheListSize/CacheListSize_13/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/OriginalAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warmest_socket/ --extension-process --enable-print-preview --channel=5128.06C09D80.1446642067 /prefetch:3
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheListSize/CacheListSize_13/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/OriginalAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warmest_socket/ --enable-print-preview --channel=5128.06BD7000.919533984 /prefetch:3
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheListSize/CacheListSize_13/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/OriginalAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warmest_socket/ --enable-print-preview --channel=5128.06BD7900.2891493 /prefetch:3
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheListSize/CacheListSize_13/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/OriginalAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/WarmSocketImpact/warmest_socket/ --enable-print-preview --channel=5128.04F73000.436385215 /prefetch:3
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service --lang=cs
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtest=CacheListSize/CacheListSize_13/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/OriginalAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/WarmSocketImpact/warmest_socket/ --enable-print-preview --channel=5128.048CBA80.939367253 /prefetch:3
"C:\Users\Honza\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtest=CacheListSize/CacheListSize_13/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/OriginalAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndDynamic/SpdyImpact/npn_with_spdy/WarmSocketImpact/warmest_socket/ --enable-print-preview --channel=5128.02C8DC00.654731019 /prefetch:3
"C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000
uiWatchDog.exe 4228
\??\C:\Windows\system32\conhost.exe "-131484337839803988-556185060-16655744201219523317-938062037-1399979518-1009734794
coreFrameworkHost.exe 4228 1
\??\C:\Windows\system32\conhost.exe "-1885987041-484617271-895632880147975645493216551749146365-610276416-70544817
AMSP_LogServer.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Honza\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-06 60576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-08-23 1515688]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2011-12-25 59272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-08-23 1515688]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-03-04 2712360]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [2011-03-04 97064]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-01-06 615584]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-01-06 379040]
"IntelTBRunOnce"=wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs []
"THXCfg64"=C:\Windows\system32\THXCfg64.dll [2009-10-15 17920]
"VizorHtmlDialog.exe"=C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe DEF EULA C:\Program Files\Trend Micro\Titanium\UI\Installer.cmpt\resources\preinstall_01_welcome_trial.html DEF DEF DEF []
"Trend Micro Client Framework"=C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [2010-10-12 192520]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 4035152]
"Cm106Sound"=C:\Windows\syswow64\RunDll32.exe [2009-07-14 44544]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-09-12 17351304]
"TiVme Agent"=C:\Program Files (x86)\GIGABYTE\vivoTV\ScheduleAgent.exe [2011-04-18 131584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2011-12-21 3058304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-12-23 11725928]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"FLxHCIm"=C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe [2011-02-24 40448]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17 5732992]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-10-07 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2010-09-23 1601536]
"CPMonitor"=C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe [2010-12-26 84464]
"THX TruStudio NB Settings"=C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [2011-01-28 907776]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"VAWinAgent"=C:\ExpressGateUtil\VAWinAgent.exe [2011-01-13 191304]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-09-30 252296]
""= []
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2011-08-23 887976]

[HKEY_CURRENT_USER\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"TiVme Agent"=C:\Program Files (x86)\GIGABYTE\vivoTVScheduleAgent.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Remote Control.lnk - C:\Program Files (x86)\GIGABYTE\U7300 Utilities\CONRCtl.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"mixer5"=wdmaud.drv
"midi5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-12-27 20:26:20 ----D---- C:\rsit
2011-12-27 18:09:10 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-12-27 18:09:10 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-12-27 18:09:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-12-27 18:09:10 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-12-27 18:09:10 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-12-27 18:09:10 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-12-27 18:09:09 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-12-27 18:09:09 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-12-27 18:09:09 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-12-27 18:09:09 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-12-27 18:09:09 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-12-27 18:09:09 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-12-27 18:09:08 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-12-27 18:09:08 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-12-27 18:09:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-12-27 18:09:08 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-12-27 18:09:08 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-12-27 18:09:08 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-12-27 18:09:07 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-12-27 18:09:07 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-12-27 18:09:07 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-12-27 18:09:07 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-12-27 18:09:07 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-12-27 18:09:07 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-12-27 18:09:07 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-12-27 18:09:07 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-12-27 18:09:07 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-12-27 18:09:07 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-12-27 18:09:06 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-12-27 18:09:06 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-12-27 18:09:06 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-12-27 18:09:06 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-12-27 18:09:06 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-12-27 18:09:06 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-12-27 18:09:05 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-12-27 18:09:05 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-12-27 18:09:05 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-12-27 18:09:05 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-12-27 18:09:05 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-12-27 18:09:05 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-12-27 18:09:05 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-12-27 18:09:05 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-12-27 18:09:05 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-12-27 18:09:05 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-12-27 18:09:05 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-12-27 18:09:05 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-12-27 18:09:04 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-12-27 18:09:04 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-12-27 18:09:04 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-12-27 18:09:04 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-12-27 18:09:04 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-12-27 18:09:04 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-12-27 18:09:04 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-12-27 18:09:04 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-12-27 18:09:03 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-12-27 18:09:03 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-12-27 18:09:03 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-12-27 18:09:03 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-12-27 18:09:03 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-12-27 18:09:03 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-12-27 18:09:03 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-12-27 18:09:03 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-12-27 18:09:02 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-12-27 18:09:02 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-12-27 18:09:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-12-27 18:09:02 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-12-27 18:09:02 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-12-27 18:09:02 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-12-27 18:09:01 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-12-27 18:09:01 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-12-27 18:09:01 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-12-27 18:09:01 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-12-27 18:09:01 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-12-27 18:09:01 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-12-27 18:09:01 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-12-27 18:09:01 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-12-27 18:09:01 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-12-27 18:09:01 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-12-27 18:09:00 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-12-27 18:09:00 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-12-27 13:45:05 ----RA---- C:\Windows\SYSWOW64\SuperFrameSplitter.dll
2011-12-27 13:45:04 ----RA---- C:\Windows\SYSWOW64\RTL283XACCESS.dll
2011-12-27 13:45:04 ----RA---- C:\Windows\SYSWOW64\RTKFMSOURCE.dll
2011-12-27 13:45:04 ----RA---- C:\Windows\SYSWOW64\RTKFM.dll
2011-12-27 13:45:04 ----RA---- C:\Windows\SYSWOW64\RTKDABSOURCE.dll
2011-12-27 13:45:04 ----RA---- C:\Windows\SYSWOW64\RTKDABMWare.dll
2011-12-27 13:45:02 ----RA---- C:\Windows\SYSWOW64\RTKDAB.dll
2011-12-27 13:44:58 ----A---- C:\Windows\system32\drivers\RTL2832UUSB.sys
2011-12-27 13:44:58 ----A---- C:\Windows\system32\drivers\RTL2832UBDA.sys
2011-12-27 13:44:57 ----D---- C:\Windows\RTL
2011-12-27 13:41:30 ----RA---- C:\Windows\Vmix106.dll
2011-12-27 13:41:17 ----RA---- C:\Windows\SYSWOW64\CM106.dll
2011-12-27 13:41:16 ----RA---- C:\Windows\SYSWOW64\cmpa106.dll
2011-12-27 13:41:15 ----RA---- C:\Windows\system32\Cmeau106.exe
2011-12-27 13:41:01 ----A---- C:\Windows\system32\drivers\CM10664.sys
2011-12-27 13:40:57 ----RA---- C:\Windows\system32\CmiInstallResAll64.dll
2011-12-27 13:40:53 ----RA---- C:\Windows\difxapi.dll
2011-12-27 13:40:25 ----D---- C:\ProgramData\Adobe
2011-12-27 13:40:15 ----D---- C:\Program Files (x86)\Adobe
2011-12-26 19:37:10 ----D---- C:\Program Files\WinRAR
2011-12-26 17:20:22 ----D---- C:\Users\Honza\AppData\Roaming\Skype
2011-12-26 17:20:17 ----RD---- C:\Program Files (x86)\Skype
2011-12-26 17:20:11 ----D---- C:\ProgramData\Skype
2011-12-26 16:32:17 ----A---- C:\Windows\SYSWOW64\CmdLineExt.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\wextract.exe
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\msls31.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\icardie.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2011-12-26 11:28:53 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2011-12-26 11:28:52 ----A---- C:\Windows\SYSWOW64\mshta.exe
2011-12-26 11:28:52 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-12-26 11:28:52 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2011-12-26 11:28:52 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2011-12-26 11:28:52 ----A---- C:\Windows\SYSWOW64\admparse.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\wininet.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\wextract.exe
2011-12-26 11:28:52 ----A---- C:\Windows\system32\webcheck.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\vbscript.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\urlmon.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\url.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-12-26 11:28:52 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-12-26 11:28:52 ----A---- C:\Windows\system32\pngfilt.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\occache.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\msrating.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\msls31.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\mshtmler.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\mshtml.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\mshta.exe
2011-12-26 11:28:52 ----A---- C:\Windows\system32\msfeedssync.exe
2011-12-26 11:28:52 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\msfeeds.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\licmgr10.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\jscript9.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\jscript.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\inseng.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\imgutil.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\iexpress.exe
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ieUnatt.exe
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ieui.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\iesysprep.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\iesetup.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\iertutil.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\iernonce.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\iepeers.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ieframe.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\iedkcs32.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ieapfltr.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ieapfltr.dat
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ieakui.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ieaksie.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ieakeng.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\ie4uinit.exe
2011-12-26 11:28:52 ----A---- C:\Windows\system32\icardie.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\dxtrans.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\dxtmsft.dll
2011-12-26 11:28:52 ----A---- C:\Windows\system32\admparse.dll
2011-12-26 11:08:56 ----A---- C:\Windows\system32\MRT.exe
2011-12-25 19:58:38 ----A---- C:\Windows\SYSWOW64\npdeployJava1.dll
2011-12-25 19:58:38 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-12-25 19:58:38 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-12-25 19:58:38 ----A---- C:\Windows\SYSWOW64\java.exe
2011-12-25 19:58:38 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-12-25 19:56:47 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-12-25 19:56:47 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-12-25 19:56:47 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-12-25 19:56:47 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-12-25 19:56:47 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-12-25 19:56:47 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-12-25 19:56:47 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2011-12-25 19:56:36 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-12-25 19:56:36 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-12-25 19:56:28 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2011-12-25 19:56:28 ----A---- C:\Windows\SYSWOW64\esent.dll
2011-12-25 19:56:28 ----A---- C:\Windows\system32\fsutil.exe
2011-12-25 19:56:28 ----A---- C:\Windows\system32\esent.dll
2011-12-25 19:56:28 ----A---- C:\Windows\system32\drivers\storport.sys
2011-12-25 19:56:28 ----A---- C:\Windows\system32\drivers\nvraid.sys
2011-12-25 19:56:28 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-12-25 19:56:28 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2011-12-25 19:56:28 ----A---- C:\Windows\system32\drivers\amdxata.sys
2011-12-25 19:56:27 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2011-12-25 19:56:27 ----A---- C:\Windows\system32\drivers\nvstor.sys
2011-12-25 19:56:27 ----A---- C:\Windows\system32\drivers\amdsata.sys
2011-12-25 18:20:58 ----D---- C:\Program Files (x86)\SpeedFan
2011-12-25 02:09:00 ----D---- C:\Program Files (x86)\RelevantKnowledge
2011-12-25 02:08:45 ----D---- C:\Program Files (x86)\windows-7-themes.com
2011-12-24 19:27:48 ----D---- C:\Users\Honza\AppData\Roaming\KWorld Multimedia
2011-12-24 19:19:46 ----D---- C:\Program Files (x86)\CyberLink
2011-12-24 19:17:10 ----D---- C:\Program Files (x86)\GIGABYTE
2011-12-22 16:02:54 ----D---- C:\Users\Honza\AppData\Roaming\WinRAR
2011-12-22 16:02:47 ----D---- C:\Program Files (x86)\WinRAR
2011-12-21 17:13:18 ----D---- C:\Users\Honza\AppData\Roaming\.minecraft
2011-12-21 17:13:15 ----D---- C:\ProgramData\Sun
2011-12-21 17:12:59 ----D---- C:\Program Files (x86)\Java
2011-12-21 16:42:41 ----D---- C:\ProgramData\AutoKMS
2011-12-21 16:37:33 ----D---- C:\Windows\PCHEALTH
2011-12-21 16:37:33 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-12-21 16:37:33 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2011-12-21 16:37:33 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-12-21 16:36:45 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-12-21 16:36:28 ----D---- C:\Program Files\Microsoft Office
2011-12-21 16:36:16 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2011-12-21 16:36:10 ----D---- C:\ProgramData\Microsoft Help
2011-12-21 16:36:10 ----D---- C:\Program Files (x86)\Microsoft Office
2011-12-21 16:31:04 ----D---- C:\Users\Honza\AppData\Roaming\vlc
2011-12-21 16:30:50 ----D---- C:\Program Files (x86)\VideoLAN
2011-12-21 16:27:08 ----D---- C:\Program Files (x86)\Rockstar Games
2011-12-21 16:19:45 ----A---- C:\Windows\system32\acovcnt.exe
2011-12-21 16:18:21 ----D---- C:\Windows\SYSWOW64\Wat
2011-12-21 16:18:21 ----D---- C:\Windows\system32\Wat
2011-12-21 14:25:14 ----A---- C:\Windows\system32\FntCache.dll
2011-12-21 14:25:13 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-12-21 14:25:13 ----A---- C:\Windows\system32\DWrite.dll
2011-12-21 14:25:13 ----A---- C:\Windows\system32\d2d1.dll
2011-12-21 14:25:12 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-12-21 11:26:19 ----D---- C:\Users\Honza\AppData\Roaming\ESET
2011-12-21 11:25:34 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-12-21 11:25:34 ----A---- C:\Windows\system32\xmllite.dll
2011-12-21 11:25:33 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-12-21 11:25:33 ----A---- C:\Windows\system32\kerberos.dll
2011-12-21 11:25:31 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-12-21 11:25:31 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-12-21 11:25:31 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-12-21 11:25:31 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-12-21 11:25:31 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-12-21 11:25:31 ----A---- C:\Windows\system32\odbctrac.dll
2011-12-21 11:25:31 ----A---- C:\Windows\system32\odbccu32.dll
2011-12-21 11:25:31 ----A---- C:\Windows\system32\odbccr32.dll
2011-12-21 11:25:31 ----A---- C:\Windows\system32\odbccp32.dll
2011-12-21 11:25:17 ----D---- C:\ProgramData\ESET
2011-12-21 11:25:17 ----D---- C:\Program Files\ESET
2011-12-21 11:25:17 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-12-21 11:25:17 ----A---- C:\Windows\system32\poqexec.exe
2011-12-21 11:25:15 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-12-21 11:25:15 ----A---- C:\Windows\explorer.exe
2011-12-21 11:25:11 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-12-21 11:25:11 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-12-21 11:25:11 ----A---- C:\Windows\system32\sbe.dll
2011-12-21 11:25:11 ----A---- C:\Windows\system32\CPFilters.dll
2011-12-21 11:24:55 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-12-21 11:24:55 ----A---- C:\Windows\system32\tquery.dll
2011-12-21 11:24:55 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-12-21 11:24:55 ----A---- C:\Windows\system32\mssrch.dll
2011-12-21 11:24:54 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-12-21 11:24:54 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-12-21 11:24:54 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-12-21 11:24:54 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-12-21 11:24:54 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-12-21 11:24:54 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-12-21 11:24:54 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-12-21 11:24:54 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-12-21 11:24:54 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-12-21 11:24:54 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-12-21 11:24:54 ----A---- C:\Windows\system32\mssvp.dll
2011-12-21 11:24:54 ----A---- C:\Windows\system32\mssphtb.dll
2011-12-21 11:24:54 ----A---- C:\Windows\system32\mssph.dll
2011-12-21 11:24:54 ----A---- C:\Windows\system32\msscntrs.dll
2011-12-21 11:24:36 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-12-21 11:24:36 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-12-21 11:24:36 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-12-21 11:24:29 ----A---- C:\Windows\system32\drivers\afd.sys
2011-12-21 11:19:06 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-21 11:19:05 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-12-21 11:19:05 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-12-21 11:18:55 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-12-21 11:18:40 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-12-21 11:18:40 ----A---- C:\Windows\system32\XpsPrint.dll
2011-12-21 11:18:37 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-12-21 11:18:37 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-12-21 11:18:37 ----A---- C:\Windows\system32\mfc42u.dll
2011-12-21 11:18:37 ----A---- C:\Windows\system32\mfc42.dll
2011-12-21 11:17:24 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2011-12-21 11:17:24 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-12-21 11:17:24 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-12-21 11:17:24 ----A---- C:\Windows\system32\fontsub.dll
2011-12-21 11:17:24 ----A---- C:\Windows\system32\atmlib.dll
2011-12-21 11:17:24 ----A---- C:\Windows\system32\atmfd.dll
2011-12-21 11:17:19 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-12-21 11:17:19 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-12-21 11:17:19 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-12-21 11:17:19 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-12-21 11:17:19 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-12-21 11:17:19 ----A---- C:\Windows\system32\dnsapi.dll
2011-12-21 11:17:13 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-12-21 11:17:13 ----A---- C:\Windows\system32\d3d10_1.dll
2011-12-21 11:17:12 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2011-12-21 11:17:12 ----A---- C:\Windows\system32\psisdecd.dll
2011-12-21 11:17:12 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-12-21 11:17:12 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-12-21 11:17:12 ----A---- C:\Windows\system32\drivers\srv.sys
2011-12-21 11:09:32 ----A---- C:\Windows\system32\winload.exe
2011-12-21 11:09:31 ----A---- C:\Windows\system32\winresume.exe
2011-12-21 11:09:31 ----A---- C:\Windows\system32\kdusb.dll
2011-12-21 11:09:31 ----A---- C:\Windows\system32\kdcom.dll
2011-12-21 11:09:31 ----A---- C:\Windows\system32\kd1394.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-12-21 11:03:37 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-12-21 11:03:37 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-12-21 11:03:37 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-12-21 11:03:37 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-12-21 11:03:37 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-12-21 11:03:37 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-12-21 11:03:37 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-12-21 11:03:37 ----A---- C:\Windows\system32\wow64win.dll
2011-12-21 11:03:37 ----A---- C:\Windows\system32\wow64cpu.dll
2011-12-21 11:03:37 ----A---- C:\Windows\system32\wow64.dll
2011-12-21 11:03:37 ----A---- C:\Windows\system32\winsrv.dll
2011-12-21 11:03:37 ----A---- C:\Windows\system32\ntvdm64.dll
2011-12-21 11:03:37 ----A---- C:\Windows\system32\KernelBase.dll
2011-12-21 11:03:37 ----A---- C:\Windows\system32\kernel32.dll
2011-12-21 11:03:37 ----A---- C:\Windows\system32\conhost.exe
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-12-21 11:03:36 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-12-21 11:03:36 ----A---- C:\Windows\SYSWOW64\user.exe
2011-12-21 11:03:22 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-12-21 11:03:22 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-12-21 11:03:22 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-12-21 11:03:22 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-12-21 11:03:22 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-12-21 11:03:16 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2011-12-21 11:03:16 ----A---- C:\Windows\system32\prevhost.exe
2011-12-21 11:03:14 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-12-21 11:03:11 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-12-21 11:03:11 ----A---- C:\Windows\system32\inetcomm.dll
2011-12-21 11:03:06 ----A---- C:\Windows\system32\win32k.sys
2011-12-21 11:03:02 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-12-21 11:02:58 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-12-21 11:02:58 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2011-12-21 11:02:58 ----A---- C:\Windows\system32\oleaut32.dll
2011-12-21 11:02:58 ----A---- C:\Windows\system32\oleacc.dll
2011-12-21 11:02:54 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-12-21 11:02:54 ----A---- C:\Windows\system32\EncDec.dll
2011-12-21 11:02:45 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-12-21 11:02:45 ----A---- C:\Windows\system32\tzres.dll
2011-12-21 11:01:41 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-12-21 11:01:40 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-12-21 11:01:39 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-12-21 10:53:59 ----D---- C:\Users\Honza\AppData\Roaming\Macromedia
2011-12-21 10:53:59 ----D---- C:\Users\Honza\AppData\Roaming\Adobe
2011-12-21 10:42:27 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-12-21 10:42:23 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-12-21 10:42:08 ----D---- C:\Users\Honza\AppData\Roaming\DAEMON Tools Lite
2011-12-21 10:42:05 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-12-21 10:35:50 ----D---- C:\Program Files (x86)\Ask.com
2011-12-21 10:35:50 ----D---- C:\Firefox
2011-12-21 10:35:38 ----D---- C:\Program Files (x86)\PANDORA.TV
2011-12-21 10:35:31 ----D---- C:\Program Files (x86)\The KMPlayer
2011-12-21 10:17:27 ----D---- C:\Program Files\Trend Micro
2011-12-21 10:16:42 ----A---- C:\Windows\Asus_GSeries_Screensaver Uninstaller.exe
2011-12-21 10:16:20 ----D---- C:\Windows\SYSWOW64\Macromed
2011-12-21 10:16:07 ----A---- C:\Windows\AsScrPro.exe
2011-12-21 10:15:30 ----HD---- C:\ExpressGate
2011-12-21 10:15:16 ----HD---- C:\ExpressGateUtil
2011-12-21 10:12:27 ----N---- C:\Windows\Updreg.EXE
2011-12-21 10:12:26 ----N---- C:\Windows\THXCfg_SP_APOIM.ini
2011-12-21 10:12:26 ----N---- C:\Windows\THXCfg_HP_APOIM.ini
2011-12-21 10:12:26 ----N---- C:\Windows\THXCfg_APOIM.ini
2011-12-21 10:12:26 ----N---- C:\Windows\system32\THXCfgUninstall64.ini
2011-12-21 10:12:26 ----N---- C:\Windows\system32\THXCfg64.ini
2011-12-21 10:12:26 ----N---- C:\Windows\system32\THXCfg64.exe
2011-12-21 10:12:26 ----N---- C:\Windows\system32\THXCfg64.dll
2011-12-21 10:12:21 ----A---- C:\Windows\SYSWOW64\CmdRtr.DLL
2011-12-21 10:12:21 ----A---- C:\Windows\SYSWOW64\APOMngr.DLL
2011-12-21 10:12:21 ----A---- C:\Windows\system32\CmdRtr64.DLL
2011-12-21 10:12:21 ----A---- C:\Windows\system32\APOMgr64.DLL
2011-12-21 10:12:18 ----RA---- C:\Windows\SYSWOW64\tmp842D.tmp
2011-12-21 10:12:18 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2011-12-21 10:12:18 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2011-12-21 10:12:18 ----A---- C:\Windows\system32\wrap_oal.dll
2011-12-21 10:12:18 ----A---- C:\Windows\system32\OpenAL32.dll
2011-12-21 10:12:10 ----N---- C:\Windows\SYSWOW64\Sens_oal.dll
2011-12-21 10:12:10 ----N---- C:\Windows\system32\Sens_oal.dll
2011-12-21 10:11:50 ----D---- C:\Program Files (x86)\Creative
2011-12-21 10:10:26 ----D---- C:\ProgramData\Sonic
2011-12-21 10:10:24 ----D---- C:\ProgramData\Uninstall
2011-12-21 10:09:58 ----N---- C:\Windows\system32\drivers\PxHlpa64.sys
2011-12-21 10:09:58 ----N---- C:\Windows\system32\drivers\cdralw2k.sys
2011-12-21 10:09:58 ----N---- C:\Windows\system32\drivers\cdr4_xp.sys
2011-12-21 10:09:55 ----D---- C:\ProgramData\Macrovision
2011-12-21 10:09:54 ----D---- C:\Program Files (x86)\Roxio
2011-12-21 10:09:41 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-12-21 10:09:41 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-12-21 10:09:40 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-12-21 10:09:40 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-12-21 10:09:40 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-12-21 10:09:40 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-12-21 10:09:40 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-12-21 10:09:40 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-12-21 10:09:40 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-12-21 10:09:40 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-12-21 10:09:40 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-12-21 10:09:40 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-12-21 10:09:40 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-12-21 10:09:40 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-12-21 10:09:39 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-12-21 10:09:39 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-12-21 10:09:39 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-12-21 10:09:39 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-12-21 10:09:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-12-21 10:09:39 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-12-21 10:09:39 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-12-21 10:09:39 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-12-21 10:09:39 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-12-21 10:09:39 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-12-21 10:09:38 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-12-21 10:09:38 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-12-21 10:09:38 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-12-21 10:09:38 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-12-21 10:09:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-12-21 10:09:38 ----A---- C:\Windows\system32\xinput1_3.dll
2011-12-21 10:09:38 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-12-21 10:09:38 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-12-21 10:09:38 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-12-21 10:09:38 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-12-21 10:09:37 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-12-21 10:09:37 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-12-21 10:09:37 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-12-21 10:09:37 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-12-21 10:09:37 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-12-21 10:09:37 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-12-21 10:09:37 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-12-21 10:09:37 ----A---- C:\Windows\system32\d3dx10.dll
2011-12-21 10:09:36 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-12-21 10:09:36 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-12-21 10:09:36 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-12-21 10:09:36 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-12-21 10:09:36 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-12-21 10:09:36 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-12-21 10:09:36 ----A---- C:\Windows\system32\xinput1_2.dll
2011-12-21 10:09:36 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-12-21 10:09:36 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-12-21 10:09:36 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-12-21 10:09:36 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-12-21 10:09:36 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-12-21 10:09:35 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-12-21 10:09:35 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-12-21 10:09:35 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-12-21 10:09:35 ----A---- C:\Windows\system32\xinput1_1.dll
2011-12-21 10:09:35 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-12-21 10:09:35 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-12-21 10:09:34 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-12-21 10:09:34 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-12-21 10:09:34 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-12-21 10:09:34 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-12-21 10:09:34 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-12-21 10:09:34 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-12-21 10:09:33 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-12-21 10:09:33 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-12-21 10:09:33 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-12-21 10:09:33 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-12-21 10:09:33 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-12-21 10:09:33 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-12-21 10:09:32 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-12-21 10:09:32 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-12-21 10:09:32 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-12-21 10:09:32 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-12-21 10:09:32 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-12-21 10:09:32 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-12-21 10:07:58 ----D---- C:\Users\Honza\AppData\Roaming\Roxio Log Files
2011-12-21 10:07:47 ----D---- C:\eSupport
2011-12-21 10:05:38 ----D---- C:\Program Files\ASUS
2011-12-21 10:05:38 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-12-21 10:05:38 ----A---- C:\Windows\system32\RemoveFont.ini
2011-12-21 10:05:38 ----A---- C:\Windows\system32\FBAgent.exe
2011-12-21 10:05:38 ----A---- C:\Windows\system32\FastBoot.ini
2011-12-21 10:05:38 ----A---- C:\Windows\system32\Defrag.ini
2011-12-21 10:05:38 ----A---- C:\Windows\system32\BootTime.ini
2011-12-21 10:05:38 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-12-21 10:05:34 ----A---- C:\Windows\SYSWOW64\ACEngSvr.exe
2011-12-21 10:04:58 ----D---- C:\ProgramData\P4G
2011-12-21 10:04:58 ----D---- C:\Program Files\P4G
2011-12-21 10:04:34 ----D---- C:\Program Files\Intel
2011-12-21 10:04:08 ----D---- C:\Program Files (x86)\ASUS
2011-12-21 10:03:57 ----A---- C:\Windows\system32\drivers\kbfiltr.sys
2011-12-21 10:02:28 ----D---- C:\Program Files (x86)\Atheros
2011-12-21 10:02:28 ----A---- C:\Windows\system32\drivers\athrx.sys
2011-12-21 10:02:28 ----A---- C:\Windows\system32\athrx.sys
2011-12-21 10:00:17 ----D---- C:\ProgramData\Atheros
2011-12-21 09:58:39 ----D---- C:\Program Files (x86)\Bluetooth Suite
2011-12-21 09:40:17 ----D---- C:\temp
2011-12-21 09:39:41 ----RA---- C:\Windows\system32\drivers\rtsuvstor.sys
2011-12-21 09:39:41 ----R---- C:\Windows\system32\drivers\diskperf64.sys
2011-12-21 09:39:40 ----A---- C:\Windows\SYSWOW64\RtsUVStoricon.dll
2011-12-21 09:38:30 ----D---- C:\Program Files\Fresco Logic Inc
2011-12-21 09:38:19 ----D---- C:\Program Files\Synaptics
2011-12-21 09:38:16 ----A---- C:\Windows\SYSWOW64\SynTPEnhPS.dll
2011-12-21 09:38:16 ----A---- C:\Windows\SYSWOW64\SynTPCOM.dll
2011-12-21 09:38:16 ----A---- C:\Windows\SYSWOW64\SynCtrl.dll
2011-12-21 09:38:16 ----A---- C:\Windows\SYSWOW64\SynCOM.dll
2011-12-21 09:38:16 ----A---- C:\Windows\system32\SynTPCo9.dll
2011-12-21 09:38:16 ----A---- C:\Windows\system32\SynTPAPI.dll
2011-12-21 09:38:16 ----A---- C:\Windows\system32\SynCtrl.dll
2011-12-21 09:38:16 ----A---- C:\Windows\system32\drivers\SynTP.sys
2011-12-21 09:37:02 ----A---- C:\Windows\system32\RtNicProp64.dll
2011-12-21 09:37:02 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2011-12-21 09:37:01 ----A---- C:\Windows\system32\RTNUninst64.dll
2011-12-21 09:36:14 ----D---- C:\Windows\SYSWOW64\RTCOM
2011-12-21 09:36:14 ----D---- C:\Program Files\Realtek
2011-12-21 09:36:06 ----R---- C:\Windows\system32\drivers\SamSfPa.dat
2011-12-21 09:36:04 ----A---- C:\Windows\system32\drivers\MBfilt64.sys
2011-12-21 09:36:03 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-12-21 09:36:03 ----A---- C:\Windows\system32\SRSWOW64.dll
2011-12-21 09:36:03 ----A---- C:\Windows\system32\SRSTSX64.dll
2011-12-21 09:36:03 ----A---- C:\Windows\system32\SRSTSH64.dll
2011-12-21 09:36:03 ----A---- C:\Windows\system32\SRSHP64.dll
2011-12-21 09:36:03 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2011-12-21 09:36:02 ----A---- C:\Windows\system32\RtkCfg64.dll
2011-12-21 09:36:01 ----A---- C:\Windows\system32\RtPgEx64.dll
2011-12-21 09:36:01 ----A---- C:\Windows\system32\RtkAPO64.dll
2011-12-21 09:36:01 ----A---- C:\Windows\system32\RtkApi64.dll
2011-12-21 09:36:01 ----A---- C:\Windows\system32\RTCOM64.dll
2011-12-21 09:36:00 ----A---- C:\Windows\system32\RTEEP64A.dll
2011-12-21 09:36:00 ----A---- C:\Windows\system32\RTEEL64A.dll
2011-12-21 09:36:00 ----A---- C:\Windows\system32\RTEEG64A.dll
2011-12-21 09:36:00 ----A---- C:\Windows\system32\RTEED64A.dll
2011-12-21 09:36:00 ----A---- C:\Windows\system32\RP3DHT64.dll
2011-12-21 09:36:00 ----A---- C:\Windows\system32\RP3DAA64.dll
2011-12-21 09:36:00 ----A---- C:\Windows\system32\RCoInst64.dll
2011-12-21 09:36:00 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2011-12-21 09:35:57 ----A---- C:\Windows\system32\MBWrp64.dll
2011-12-21 09:35:57 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-12-21 09:35:57 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-12-21 09:35:56 ----A---- C:\Windows\SYSWOW64\MBTHX32.dll
2011-12-21 09:35:56 ----A---- C:\Windows\system32\MBTHX64.dll
2011-12-21 09:35:53 ----A---- C:\Windows\system32\FMAPO64.dll
2011-12-21 09:35:51 ----D---- C:\Program Files (x86)\Realtek
2011-12-21 09:35:51 ----A---- C:\Windows\system32\AERTAR64.dll
2011-12-21 09:35:51 ----A---- C:\Windows\system32\AERTAC64.dll
2011-12-21 09:35:43 ----HD---- C:\Program Files (x86)\Temp
2011-12-21 09:35:41 ----R---- C:\Windows\RtlExUpd.dll
2011-12-21 09:34:31 ----A---- C:\Windows\system32\nvhdap64.dll
2011-12-21 09:34:31 ----A---- C:\Windows\system32\nvhdagenco642040.dll
2011-12-21 09:34:31 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2011-12-21 09:33:49 ----D---- C:\ProgramData\NVIDIA
2011-12-21 09:33:43 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-12-21 09:32:09 ----SHD---- C:\Windows\Installer
2011-12-21 09:31:30 ----D---- C:\ProgramData\NVIDIA Corporation
2011-12-21 09:31:23 ----A---- C:\Windows\system32\nvgenco642040.dll
2011-12-21 09:31:23 ----A---- C:\Windows\system32\nvdispco642090.dll
2011-12-21 09:29:21 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-12-21 09:29:21 ----A---- C:\Windows\system32\OpenCL.dll
2011-12-21 09:29:20 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-12-21 09:29:20 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-12-21 09:29:19 ----A---- C:\Windows\system32\nvoglv64.dll
2011-12-21 09:29:18 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-12-21 09:29:17 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-12-21 09:29:15 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-12-21 09:29:15 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-12-21 09:29:14 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-12-21 09:29:14 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-12-21 09:29:14 ----A---- C:\Windows\system32\nvcuvid.dll
2011-12-21 09:29:14 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-12-21 09:29:13 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-12-21 09:29:13 ----A---- C:\Windows\system32\nvcuda.dll
2011-12-21 09:29:02 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-12-21 09:28:59 ----A---- C:\Windows\system32\nvcompiler.dll
2011-12-21 09:28:58 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-12-21 09:28:58 ----A---- C:\Windows\system32\nvapi64.dll
2011-12-21 09:26:23 ----D---- C:\Program Files\NVIDIA Corporation
2011-12-21 09:25:15 ----A---- C:\Windows\SYSWOW64\drivers\IntelMEFWVer.dll
2011-12-21 09:25:15 ----A---- C:\Windows\system32\drivers\IntelMEFWVer.dll
2011-12-21 09:25:13 ----A---- C:\Windows\SYSWOW64\log.txt
2011-12-21 09:25:06 ----A---- C:\Windows\system32\drivers\HECIx64.sys
2011-12-21 09:25:02 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-12-21 09:24:59 ----D---- C:\Users\Honza\AppData\Roaming\InstallShield
2011-12-21 09:23:01 ----RA---- C:\Windows\SYSWOW64\CSVer.dll
2011-12-21 09:23:01 ----D---- C:\Program Files (x86)\Intel
2011-12-21 09:22:45 ----D---- C:\Intel
2011-12-21 09:19:12 ----D---- C:\Users\Honza\AppData\Roaming\Identities
2011-12-21 09:19:03 ----SD---- C:\Users\Honza\AppData\Roaming\Microsoft
2011-12-21 09:19:03 ----D---- C:\Users\Honza\AppData\Roaming\Media Center Programs
2011-12-21 09:18:58 ----SHD---- C:\Recovery
2011-12-21 09:18:58 ----SHD---- C:\ProgramData\Šablony
2011-12-21 09:18:58 ----SHD---- C:\ProgramData\Plocha
2011-12-21 09:18:58 ----SHD---- C:\ProgramData\Oblíbené položky
2011-12-21 09:18:58 ----SHD---- C:\ProgramData\Nabídka Start
2011-12-21 09:18:58 ----SHD---- C:\ProgramData\Dokumenty
2011-12-21 09:18:58 ----SHD---- C:\ProgramData\Data aplikací
2011-12-21 09:18:55 ----D---- C:\Windows\SoftwareDistribution
2011-12-21 09:12:07 ----D---- C:\Windows\Prefetch
2011-12-21 09:11:36 ----SHD---- C:\System Volume Information
2011-12-21 09:11:36 ----ASH---- C:\pagefile.sys
2011-12-21 09:11:36 ----ASH---- C:\hiberfil.sys
2011-12-21 09:11:08 ----D---- C:\Windows\Panther

======List of files/folders modified in the last 1 month======

2011-12-27 20:26:21 ----D---- C:\Windows\Temp
2011-12-27 20:08:14 ----D---- C:\Windows\System32
2011-12-27 20:08:14 ----D---- C:\Windows\inf
2011-12-27 20:08:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-27 20:02:13 ----D---- C:\Windows\system32\Tasks
2011-12-27 20:01:31 ----D---- C:\Windows\system32\config
2011-12-27 18:58:13 ----D---- C:\Windows\system32\NDF
2011-12-27 18:09:10 ----D---- C:\Windows\SysWOW64
2011-12-27 18:08:49 ----RSD---- C:\Windows\assembly
2011-12-27 18:07:52 ----D---- C:\Windows\Logs
2011-12-27 16:39:41 ----D---- C:\Windows\rescache
2011-12-27 16:35:29 ----D---- C:\Windows\Microsoft.NET
2011-12-27 15:12:11 ----D---- C:\Windows
2011-12-27 13:49:01 ----D---- C:\Windows\winsxs
2011-12-27 13:45:44 ----RSD---- C:\Windows\Fonts
2011-12-27 13:44:59 ----D---- C:\Windows\system32\drivers
2011-12-27 13:44:58 ----D---- C:\Windows\system32\DriverStore
2011-12-27 13:44:58 ----D---- C:\Windows\system32\catroot
2011-12-27 13:41:29 ----D---- C:\Windows\system
2011-12-27 13:40:42 ----D---- C:\Program Files (x86)\Common Files
2011-12-27 13:40:25 ----HD---- C:\ProgramData
2011-12-27 13:40:15 ----RD---- C:\Program Files (x86)
2011-12-27 03:03:23 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-12-27 03:03:23 ----D---- C:\Windows\system32\cs-CZ
2011-12-27 03:01:08 ----D---- C:\Windows\SYSWOW64\en-US
2011-12-27 03:01:08 ----D---- C:\Windows\system32\en-US
2011-12-26 19:37:10 ----RD---- C:\Program Files
2011-12-26 11:30:03 ----D---- C:\Program Files\Internet Explorer
2011-12-26 11:30:03 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-26 11:30:02 ----D---- C:\Windows\SYSWOW64\migration
2011-12-26 11:30:02 ----D---- C:\Windows\system32\migration
2011-12-26 11:30:02 ----D---- C:\Windows\PolicyDefinitions
2011-12-26 11:29:24 ----D---- C:\Windows\system32\catroot2
2011-12-26 10:51:30 ----D---- C:\Windows\system32\wdi
2011-12-25 19:51:02 ----D---- C:\Windows\Tasks
2011-12-25 19:51:01 ----D---- C:\Windows\system32\wfp
2011-12-25 19:50:56 ----D---- C:\Windows\system32\wbem
2011-12-25 19:50:08 ----RSD---- C:\Windows\Media
2011-12-25 19:50:08 ----D---- C:\Windows\SYSWOW64\wbem
2011-12-25 19:50:03 ----D---- C:\Windows\system32\drivers\UMDF
2011-12-25 19:50:03 ----D---- C:\Windows\system32\CodeIntegrity
2011-12-25 19:50:01 ----D---- C:\Windows\AppCompat
2011-12-25 19:49:58 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-12-25 19:49:15 ----D---- C:\Windows\registration
2011-12-25 19:48:01 ----SD---- C:\ProgramData\Microsoft
2011-12-21 16:34:53 ----D---- C:\Windows\debug
2011-12-21 16:18:24 ----D---- C:\Program Files\Common Files\System
2011-12-21 16:18:21 ----D---- C:\Windows\AppPatch
2011-12-21 16:18:20 ----D---- C:\Windows\ehome
2011-12-21 16:18:19 ----D---- C:\Windows\system32\Boot
2011-12-21 10:17:36 ----D---- C:\Windows\SYSWOW64\drivers
2011-12-21 09:36:42 ----D---- C:\Windows\system32\restore
2011-12-21 09:32:24 ----D---- C:\Windows\Help
2011-12-21 09:19:11 ----SHD---- C:\$Recycle.Bin
2011-12-21 09:19:03 ----RD---- C:\Users
2011-12-21 09:18:58 ----D---- C:\Program Files\Windows NT
2011-12-21 09:14:05 ----D---- C:\Windows\system32\sysprep

Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Re: Opakované útoky při zapnutí počítače

#3 Příspěvek od Aerox1 »

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 62496]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-11-05 438808]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-07-26 17024]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-12-21 279616]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 38288]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2011-08-04 187632]
R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys [2010-04-16 13832]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2011-01-06 36000]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-07-08 2228736]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2011-01-06 298144]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2011-01-06 28832]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2011-01-06 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2011-01-06 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2011-01-06 154272]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2011-01-06 279200]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver; C:\Windows\system32\DRIVERS\FLxHCIc.sys [2011-02-24 302592]
R3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver; C:\Windows\system32\DRIVERS\FLxHCIh.sys [2011-02-24 81920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-12-23 2684136]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-09-21 56344]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-03-14 173160]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2010-08-03 290920]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-12-28 412776]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-03-04 1413168]
R3 USBMULCD;USB Multi-Channel Audio Device Interface; C:\Windows\system32\drivers\CM10664.sys [2009-06-11 1306624]
S3 ASUSProcObsrv;ASUS Process Creation/Termination Observer; \??\D:\I386\AsPrOb64.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RTL2832UBDA;REALTEK 2832U BDA Driver; C:\Windows\system32\drivers\RTL2832UBDA.sys [2011-05-03 174368]
S3 RTL2832UUSB;REALTEK 2832U USB Driver; C:\Windows\System32\Drivers\RTL2832UUSB.sys [2011-05-03 38944]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-23 154168]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2011-01-25 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-15 84536]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-06 138400]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-06 53920]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-10-05 325656]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-03-06 993896]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2011-12-21 578264]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-03-06 378472]
R2 TurboBoost;Intel(R) Turbo Boost Technology Monitor; C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-04-16 134928]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-05 2655768]
R2 VideAceWindowsService;VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [2011-01-12 91464]
S2 Amsp;Trend Micro Solution Platform; C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [2010-09-17 267480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-21 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-21 79360]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-21 1255736]

-----------------EOF-----------------

Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Re: Opakované útoky při zapnutí počítače

#4 Příspěvek od Aerox1 »

Posouvám ->

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Opakované útoky při zapnutí počítače

#5 Příspěvek od motji »

Zdravím :)

:arrow: Stáhněte Roguekiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
-ukončete všechny spuštěné programy
-spusťte program, pro visty/win 7 spustte pravým tlačítkem myši - jako správce
-použijte volbu 2 - enter
-pak použijte postupně i volby 3,4,5
-vložte zde logy



:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Re: Opakované útoky při zapnutí počítače

#6 Příspěvek od Aerox1 »

Rogue Killer log 2 :

RogueKiller V6.2.0 [12/12/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: Remove -- Date : 12/28/2011 00:21:02

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 3 ¤¤¤
[SUSP PATH] ASUS Patch 10430001.job : C:\Windows\AsPatch10430001.exe -> DELETED
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤


¤¤¤ MBR Check: ¤¤¤
--- User ---
[MBR] 2f1c48860427a8abd35814188f405555
[BSP] af8ff1200021f6956c86e3d5f07fb3cb : MBR Code unknown
Partition table:
0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 2048 | Size: 104 Mo
1 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 206848 | Size: 500000 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[1].txt >>
RKreport[1].txt


log 3


RogueKiller V6.2.0 [12/12/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: HOSTSFix -- Date : 12/28/2011 00:21:24

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤


¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt


log 4

RogueKiller V6.2.0 [12/12/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: HOSTSFix -- Date : 12/28/2011 00:21:35

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

log5

RogueKiller V6.2.0 [12/12/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: ProxyFix -- Date : 12/28/2011 00:21:39

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Registry Entries: 0 ¤¤¤

Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt


log 6

RogueKiller V6.2.0 [12/12/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: Shortcuts HJfix -- Date : 12/28/2011 00:22:25

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 1 / Fail 0
Quick launch: Success 1 / Fail 0
Programs: Success 5 / Fail 0
Start menu: Success 1 / Fail 0
User folder: Success 68 / Fail 0
My documents: Success 0 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 8 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 74 / Fail 0
Backup: [NOT FOUND]

Drives:
[C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[D:] \Device\CdRom0 -- 0x5 --> Skipped
[E:] \Device\HarddiskVolume3 -- 0x2 --> Restored
[G:] \Device\CdRom1 -- 0x5 --> Skipped

¤¤¤ Infection : ¤¤¤

Finished : << RKreport[5].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt


MBAM sem ve vašem podpisu nenašel, prosím o zaslání odkazu na stažení. Děkuji

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Opakované útoky při zapnutí počítače

#7 Příspěvek od motji »

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Re: Opakované útoky při zapnutí počítače

#8 Příspěvek od Aerox1 »

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.60.0.1800
www.malwarebytes.org

Verze databáze: v2011.12.24.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Honza :: ASUS-G53ROG [administrátor]

Ochrana: Povolena

28.12.2011 12:26:37
mbam-log-2011-12-28 (12-45-29).txt

Typ: Úplná kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 280328
Uplynulý čas: 18 minut, 41 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 1
C:\Program Files (x86)\RelevantKnowledge (Spyware.MarketScore) -> Žádná instrukce nebyla provedena.

Nalezené soubory: 3
C:\Users\Honza\Documents\MW3\Phx_data\Res\EmuCfg.exe (Trojan.Agent) -> Žádná instrukce nebyla provedena.
C:\Users\Honza\Documents\MW3\Phx_data\Res\GCFMgr.exe (Trojan.Agent) -> Žádná instrukce nebyla provedena.
C:\Users\Honza\Documents\MW3\Phx_data\Res\ss.exe (Backdoor.Bot) -> Žádná instrukce nebyla provedena.

(konec)

Podotýkám že soubory ve složce MW3 jsou soubory hry Call of Duty Modern Warfare 3. Proto by neměly být nijak nebezpečné.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Opakované útoky při zapnutí počítače

#9 Příspěvek od motji »

Ty soubory otestujte na www.virustotal.com
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Re: Opakované útoky při zapnutí počítače

#10 Příspěvek od Aerox1 »

Ani jeden z vložených souborů nebyl shledán podezřelým ( vyskočila na mně ale že tento soubor byl již v minulosti testován a že je vše v pořádku, po volbě reanalyse ovšem žádnou hrozbu nehlásí )

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Opakované útoky při zapnutí počítače

#11 Příspěvek od motji »

V tom případě je nemažte.
Ted to s pc vypadá jak?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Re: Opakované útoky při zapnutí počítače

#12 Příspěvek od Aerox1 »

Úplně to samé
do přílohy jsem dal screenshot mého problému. Mně jde hlavně o to jestli se proti tomu mohu nějak bránit já? Firewall naštěstí funguje jak má.
http://imageshack.us/photo/my-images/17/efenum.jpg/
[IMG=http://img17.imageshack.us/img17/9073/efenum.jpg][/IMG]

Uploaded with ImageShack.us

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Opakované útoky při zapnutí počítače

#13 Příspěvek od motji »

Nemám ESET, ale mám pocit že jsem tohle už někde řešila :?: Pro jistotu ještě pc prověříme na viry a já se zatím kouknu, kde jsem to viděla :)

:arrow: Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe


- ComboFix je třeba spustit pod účtem s právy administrátora

- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary

- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano

- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna :!:

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Aerox1
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 27 pro 2011 20:05

Re: Opakované útoky při zapnutí počítače

#14 Příspěvek od Aerox1 »

ComboFix 11-12-29.05 - Honza 30.12.2011 1:19.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4073.2722 [GMT 1:00]
Spuštěný z: c:\users\Honza\Desktop\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\AsDebug.log
c:\windows\AsPatch10430001.exe
c:\windows\SysWow64\tmp82A6.tmp
c:\windows\SysWow64\tmp842D.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-28 do 2011-12-30 )))))))))))))))))))))))))))))))
.
.
2011-12-30 00:22 . 2011-12-30 00:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-30 00:13 . 2011-12-30 00:13 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0233443E-57B4-4A13-8CA8-F9FE306325FE}\offreg.dll
2011-12-28 11:25 . 2011-12-28 11:25 -------- d-----w- c:\programdata\Malwarebytes
2011-12-28 11:25 . 2011-12-28 11:25 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-28 11:25 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-27 19:26 . 2011-12-27 19:26 -------- d-----w- C:\rsit
2011-12-27 12:45 . 2011-05-03 09:06 90213 ----a-r- c:\windows\SysWow64\SuperFrameSplitter.dll
2011-12-27 12:45 . 2011-05-03 09:06 69632 ----a-r- c:\windows\SysWow64\RTKDABMWare.dll
2011-12-27 12:45 . 2011-05-03 09:06 352335 ----a-r- c:\windows\SysWow64\RTKFM.dll
2011-12-27 12:45 . 2011-05-03 09:06 139369 ----a-r- c:\windows\SysWow64\RTKDABSOURCE.dll
2011-12-27 12:45 . 2011-05-03 09:06 135277 ----a-r- c:\windows\SysWow64\RTKFMSOURCE.dll
2011-12-27 12:45 . 2011-05-03 09:06 114688 ----a-r- c:\windows\SysWow64\RTL283XACCESS.dll
2011-12-27 12:45 . 2011-05-03 09:06 4698216 ----a-r- c:\windows\SysWow64\RTKDAB.dll
2011-12-27 12:44 . 2011-05-03 09:06 38944 ----a-w- c:\windows\system32\drivers\RTL2832UUSB.sys
2011-12-27 12:44 . 2011-05-03 09:06 174368 ----a-w- c:\windows\system32\drivers\RTL2832UBDA.sys
2011-12-27 12:44 . 2011-12-27 12:45 -------- d-----w- c:\windows\RTL
2011-12-27 12:41 . 2009-06-11 13:09 143360 ----a-r- c:\windows\Vmix106.dll
2011-12-27 12:41 . 2009-06-11 13:09 491520 ----a-r- c:\windows\system\cmau106.dll
2011-12-27 12:41 . 2009-06-11 13:09 221184 ----a-r- c:\windows\system\cm106eye.exe
2011-12-27 12:41 . 2009-06-11 13:09 389120 ----a-r- c:\windows\system32\CM106.cpl
2011-12-27 12:41 . 2009-06-11 13:09 8126464 ----a-r- c:\windows\SysWow64\CM106.dll
2011-12-27 12:41 . 2009-06-11 13:09 200704 ----a-r- c:\windows\SysWow64\cmpa106.dll
2011-12-27 12:41 . 2009-06-11 13:05 779776 ----a-r- c:\windows\system32\Cmeau106.exe
2011-12-27 12:41 . 2009-06-11 13:10 315392 ----a-w- c:\windows\system\fltr106.dll
2011-12-27 12:41 . 2009-06-11 13:10 1306624 ----a-w- c:\windows\system32\drivers\CM10664.sys
2011-12-27 12:40 . 2009-06-11 13:06 354304 ----a-r- c:\windows\system32\CmiInstallResAll64.dll
2011-12-27 12:40 . 2009-06-11 13:06 524768 ----a-r- c:\windows\difxapi.dll
2011-12-27 12:40 . 2011-12-27 12:40 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-12-27 12:40 . 2011-12-27 12:40 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-12-27 12:39 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0233443E-57B4-4A13-8CA8-F9FE306325FE}\mpengine.dll
2011-12-26 16:20 . 2011-12-26 16:20 -------- d-----r- c:\program files (x86)\Skype
2011-12-26 16:20 . 2011-12-26 16:20 -------- d-----w- c:\programdata\Skype
2011-12-26 15:32 . 2011-12-26 15:32 98304 ----a-w- c:\windows\SysWow64\CmdLineExt.dll
2011-12-25 18:58 . 2011-12-25 18:58 637848 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2011-12-25 18:58 . 2011-12-25 18:58 567184 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-12-25 17:20 . 2011-12-25 18:49 -------- d-----w- c:\program files (x86)\SpeedFan
2011-12-25 01:08 . 2011-12-25 01:08 -------- d-----w- c:\program files (x86)\windows-7-themes.com
2011-12-24 18:19 . 2011-12-24 18:23 -------- d-----w- c:\program files (x86)\CyberLink
2011-12-24 18:17 . 2011-12-27 12:49 -------- d-----w- c:\program files (x86)\GIGABYTE
2011-12-21 22:13 . 2011-12-26 10:07 158056 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10139.bin
2011-12-21 16:13 . 2011-12-21 16:13 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-12-21 16:12 . 2011-12-21 16:12 -------- d-----w- c:\program files (x86)\Java
2011-12-21 15:42 . 2011-12-25 18:49 -------- d-----w- c:\programdata\AutoKMS
2011-12-21 15:37 . 2011-12-25 18:49 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-12-21 15:37 . 2011-12-21 15:37 -------- d-----w- c:\windows\PCHEALTH
2011-12-21 15:37 . 2011-12-21 15:37 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework
2011-12-21 15:37 . 2011-12-21 15:37 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-12-21 15:36 . 2011-12-25 18:49 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-12-21 15:36 . 2011-12-21 15:36 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2011-12-21 15:36 . 2011-12-25 18:49 -------- d-----w- c:\programdata\Microsoft Help
2011-12-21 15:30 . 2011-12-21 15:30 -------- d-----w- c:\program files (x86)\VideoLAN
2011-12-21 15:27 . 2011-12-21 15:27 -------- d-----w- c:\program files (x86)\Rockstar Games
2011-12-21 15:19 . 2011-12-30 00:10 45056 ----a-w- c:\windows\system32\acovcnt.exe
2011-12-21 15:18 . 2011-12-21 15:18 -------- d-----w- c:\windows\SysWow64\Wat
2011-12-21 15:18 . 2011-12-21 15:18 -------- d-----w- c:\windows\system32\Wat
2011-12-21 13:25 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-21 13:25 . 2011-02-19 12:04 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-21 13:25 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-21 13:25 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-21 13:25 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-21 10:24 . 2011-05-04 05:25 2315776 ----a-w- c:\windows\system32\tquery.dll
2011-12-21 10:19 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-21 10:19 . 2011-02-24 06:15 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-12-21 10:19 . 2011-02-24 05:38 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-12-21 10:18 . 2011-09-29 16:29 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-12-21 10:18 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
2011-12-21 10:18 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2011-12-21 10:18 . 2011-03-11 06:34 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2011-12-21 10:18 . 2011-03-11 06:34 1395712 ----a-w- c:\windows\system32\mfc42.dll
2011-12-21 10:18 . 2011-03-11 05:33 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
2011-12-21 10:18 . 2011-03-11 05:33 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
2011-12-21 10:09 . 2011-02-05 17:06 605552 ----a-w- c:\windows\system32\winload.exe
2011-12-21 10:09 . 2011-02-05 17:06 566208 ----a-w- c:\windows\system32\winresume.efi
2011-12-21 10:09 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2011-12-21 10:09 . 2011-02-05 17:10 20352 ----a-w- c:\windows\system32\kdusb.dll
2011-12-21 10:09 . 2011-02-05 17:10 19328 ----a-w- c:\windows\system32\kd1394.dll
2011-12-21 10:09 . 2011-02-05 17:10 17792 ----a-w- c:\windows\system32\kdcom.dll
2011-12-21 10:09 . 2011-02-05 17:06 518672 ----a-w- c:\windows\system32\winresume.exe
2011-12-21 10:02 . 2011-08-27 05:37 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-12-21 10:02 . 2011-08-27 05:37 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-12-21 10:02 . 2011-08-27 04:26 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-12-21 10:02 . 2011-08-27 04:26 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2011-12-21 10:02 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-21 10:02 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-21 10:02 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-21 10:02 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-21 10:01 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-12-21 10:01 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-21 10:01 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-12-21 09:42 . 2011-12-21 09:42 279616 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-12-21 09:42 . 2011-12-21 09:46 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-12-21 09:42 . 2011-12-21 09:42 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-12-21 09:35 . 2011-12-27 18:05 -------- d-----w- c:\program files (x86)\Ask.com
2011-12-21 09:35 . 2011-12-21 09:35 -------- d-----w- C:\Firefox
2011-12-21 09:35 . 2011-12-21 09:35 -------- d-----w- c:\program files (x86)\PANDORA.TV
2011-12-21 09:35 . 2011-12-21 09:35 -------- d-----w- c:\program files (x86)\The KMPlayer
2011-12-21 09:17 . 2011-12-27 19:26 -------- d-----w- c:\program files\Trend Micro
2011-12-21 09:16 . 2011-12-21 09:16 80512 ----a-w- c:\windows\Asus_GSeries_Screensaver Uninstaller.exe
2011-12-21 09:16 . 2011-12-21 09:16 -------- d-----w- c:\windows\SysWow64\Macromed
2011-12-21 09:16 . 2011-12-21 09:16 3058304 ----a-w- c:\windows\AsScrPro.exe
2011-12-21 09:15 . 2011-12-21 09:15 -------- d-----w- C:\ExpressGate
2011-12-21 09:10 . 2011-12-21 09:11 -------- d-----w- c:\programdata\Sonic
2011-12-21 09:10 . 2011-12-21 09:10 -------- d-----w- c:\programdata\Uninstall
2011-12-21 09:07 . 2011-12-21 09:07 -------- d-----w- C:\eSupport
2011-12-21 09:05 . 2011-12-21 09:05 -------- d-----w- c:\program files\ASUS
2011-12-21 09:05 . 2011-01-25 13:11 379520 ----a-w- c:\windows\system32\FBAgent.exe
2011-12-21 09:05 . 2006-10-09 18:07 183296 ----a-w- c:\windows\SysWow64\ACEngSvr.exe
2011-12-21 09:04 . 2010-08-03 14:30 196224 ----a-w- c:\program files\Windows Sidebar\Shared Gadgets\P4GUpdate.Gadget\P4GUpdate.dll
2011-12-21 09:04 . 2011-12-25 18:49 -------- d-----w- c:\programdata\P4G
2011-12-21 09:04 . 2011-12-21 09:06 -------- d-----w- c:\program files\P4G
2011-12-21 09:04 . 2011-12-21 09:04 -------- d-----w- c:\program files\Intel
2011-12-21 09:04 . 2011-12-21 09:06 -------- d-----w- c:\program files (x86)\ASUS
2011-12-21 09:03 . 2009-07-20 09:29 15416 ----a-w- c:\windows\system32\drivers\kbfiltr.sys
2011-12-21 09:02 . 2011-12-21 09:02 -------- d-----w- c:\program files (x86)\Atheros
2011-12-21 09:02 . 2010-07-08 01:03 2228736 ----a-w- c:\windows\system32\drivers\athrx.sys
2011-12-21 09:02 . 2010-07-08 01:03 2228736 ----a-w- c:\windows\system32\athrx.sys
2011-12-21 09:00 . 2011-12-25 01:22 -------- d-----w- c:\programdata\Atheros
2011-12-21 08:58 . 2011-12-21 08:58 -------- d-----w- c:\program files (x86)\Common Files\Atheros
2011-12-21 08:58 . 2011-12-25 18:49 -------- d-----w- c:\program files (x86)\Bluetooth Suite
2011-12-21 08:40 . 2011-12-21 09:00 -------- d-----w- C:\temp
2011-12-21 08:39 . 2010-08-03 10:43 290920 ----a-r- c:\windows\system32\drivers\rtsuvstor.sys
2011-12-21 08:39 . 2010-07-13 13:21 15464 ------r- c:\windows\system32\drivers\diskperf64.sys
2011-12-21 08:39 . 2009-11-25 06:21 7367200 ----a-w- c:\windows\SysWow64\RtsUVStoricon.dll
2011-12-21 08:38 . 2011-12-21 08:38 -------- d-----w- c:\program files\Fresco Logic Inc
2011-12-21 08:38 . 2011-12-21 08:38 -------- d-----w- c:\program files\Synaptics
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 13:29 . 2010-11-21 03:27 270720 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-08-23 20:20 1515688 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-08-23 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-09-12 17351304]
"TiVme Agent"="c:\program files (x86)\GIGABYTE\vivoTV\ScheduleAgent.exe" [2011-04-18 131584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"FLxHCIm"="c:\program files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe" [2011-02-24 40448]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536]
"CPMonitor"="c:\program files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe" [2010-12-26 84464]
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2011-01-28 907776]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VAWinAgent"="c:\expressgateutil\VAWinAgent.exe" [2011-01-13 191304]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-09-30 252296]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-08-23 887976]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Remote Control.lnk - c:\program files (x86)\GIGABYTE\U7300 Utilities\CONRCtl.exe [2011-12-27 94208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
3;2 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 ASUSProcObsrv;ASUS Process Creation/Termination Observer;d:\i386\AsPrOb64.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-21 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-12-21 79360]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys [x]
R3 RTL2832UBDA;REALTEK 2832U BDA Driver;c:\windows\system32\drivers\RTL2832UBDA.sys [x]
R3 RTL2832UUSB;REALTEK 2832U USB Driver;c:\windows\system32\Drivers\RTL2832UUSB.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-07-26 17024]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-06 138400]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-01-06 53920]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [2011-12-28 578264]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-03-06 378472]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-04-16 134928]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-05 2655768]
S2 VideAceWindowsService;VideAceWindowsService;c:\expressgateutil\VAWinService.exe [2011-01-12 91464]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [x]
S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\DRIVERS\FLxHCIh.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-01-06 615584]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-01-06 379040]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"THXCfg64"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"Trend Micro Client Framework"="c:\program files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [2010-10-12 192520]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 4035152]
"Cm106Sound"="c:\windows\Syswow64\cm106.dll" [2009-06-11 8126464]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.100.254
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SynAsusAcpi - c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe
HKLM-Run-VizorHtmlDialog.exe - c:\program files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-12-30 01:24:06
ComboFix-quarantined-files.txt 2011-12-30 00:24
.
Před spuštěním: Volných bajtů: 297 769 111 552
Po spuštění: Volných bajtů: 297 561 968 640
.
- - End Of File - - 765DCD75616E1FAB6B37B3A5963005EF

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Opakované útoky při zapnutí počítače

#15 Příspěvek od motji »

Jak to vypadá s počítačem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět