Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

prosím o kontrolu logu

#1 Příspěvek od ferko123 »

čaute, mám podozrenie na vírusy. Nejde mi safe mod. Opravil som MBR a spustil SFC a stále nejde. RSIT:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:42:49, on 27. 12. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%SystemRoot%\system32\wlms\wlms.exe,-1 (WLMS) - Unknown owner - C:\Windows\system32\wlms\wlms.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

a MBR:

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002

device: opened successfully
user: error reading MBR
error: Read Popisovač nie je platný.
kernel: error reading MBR

GMER:


MER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-27 12:39:45
Windows 6.1.7600
Running: 3486ynry.exe


---- Files - GMER 1.0.15 ----

File C:\Windows\System32\wbem\Performance\WmiApRpl_new.h 357 bytes

---- EOF - GMER 1.0.15 ----
Naposledy upravil(a) ferko123 dne 16 lis 2012 19:58, celkem upraveno 1 x.

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: prosím o kontrolu logu

#2 Příspěvek od chodnik74 »

Dobrý den :welcome:

:arrow: ZDE je oprava nouzového režimu...

Pohledáme po havěti

:arrow: Malwarebytes' Anti-Malware Obrázek
  • Stáhneme,nainstalujeme a spustíme(pokud si nevíte rady jak,klikněte ZDE)
  • Vybereme Úplná kontrola a klikneme na tlačítko ProhledatObrázek
  • Program provede kontrolu počítače a na konci se vám objeví hláska,že bylo skenování dokončeno,tak potvrdíme tlačítkem OK
  • Objeví se vám log,který mi sem vložte
  • NIC NEMAZAT!!Program mívá občas falešné detekce,takže mazat budeme až po konzultaci :twisted:
:arrow: A nakonec bych poprosil o log z RSIT je podrobnější než HJT :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

Re: prosím o kontrolu logu

#3 Příspěvek od ferko123 »

safemod vždy padne pri zadávaní hesla. Reštartuje sa PC. Bez chybovej hlášky.




Logfile of random's system information tool 1.09 (written by random/random)
Run by Michal at 2011-12-27 17:07:27
Microsoft Windows 7 Enterprise
System drive C: has 630 GB (88%) free of 715 GB
Total RAM: 8154 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:07:33, on 27. 12. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%SystemRoot%\system32\wlms\wlms.exe,-1 (WLMS) - Unknown owner - C:\Windows\system32\wlms\wlms.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7410 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"taskhost.exe"
taskeng.exe {FD0B528C-AC09-4BCA-BC18-C524AA642DEC}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe" -open
C:\Windows\Explorer.EXE
WLIDSvcM.exe 1764
"C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe" -Init
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe" -Init
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-af0ef930-c152-4564-81cf-8c91441bb554 -SystemEventPortName:HostProcess-ca4fa5ce-d32a-4fd0-ac37-6e989de02c65 -IoCancelEventPortName:HostProcess-42c0df43-70e1-4e28-ae47-1b6a22728808 -NonStateChangingEventPortName:HostProcess-48e0d8e1-27fc-4ad3-8954-1a3ec7f38ed4 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:fcd73df8-faa5-43ed-af17-466f900df57b
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Origin\Origin.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll" --lang=sk --channel=2988.0527F000.1482195240 /prefetch:4
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\160912~1.63\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll" --lang=sk --channel=2988.0509F1C0.926567633 --flash-broker=2180 /prefetch:4
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll" --lang=sk --channel=2988.050A8000.1950941074 /prefetch:4
C:\Windows\SysWOW64\PnkBstrB.exe
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/HiddenControlA/Prefetch/ContentPrefetchPrerender1/PrerenderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/ --enable-print-preview --channel=2988.051EBC00.575507646 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/HiddenControlA/Prefetch/ContentPrefetchPrerender1/PrerenderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/ --enable-print-preview --channel=2988.05BCDD80.171827439 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/HiddenControlA/Prefetch/ContentPrefetchPrerender1/PrerenderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/WarmSocketImpact/warm_socket/ --enable-print-preview --channel=2988.0693B600.318480564 /prefetch:3
taskeng.exe {6F7DAED8-EB43-4BE5-B08A-19B7B4440D11}
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"
"C:\Users\Michal\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-402294361-126543748-1492989729-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-402294361-126543748-1492989729-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2011-12-17 347424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-12-17 49440]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2011-12-17 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-12-17 42272]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-11-19 11613288]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-09-22 4035152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS AiChargerPlus Execute]
C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [2010-11-08 465536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-17 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2010-09-07 43608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2011-12-17 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-12-27 17:07:08 ----A---- C:\Windows\SYSWOW64\drivers\mbamswissarmy.sys
2011-12-27 17:06:13 ----D---- C:\Users\Michal\AppData\Roaming\Malwarebytes
2011-12-27 17:06:08 ----D---- C:\ProgramData\Malwarebytes
2011-12-27 17:06:04 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-27 17:06:04 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-12-27 12:42:44 ----D---- C:\rsit
2011-12-27 12:42:44 ----D---- C:\Program Files\trend micro
2011-12-27 12:31:22 ----A---- C:\Windows\ntbtlog.txt
2011-12-26 18:01:11 ----D---- C:\ProgramData\ESET
2011-12-26 18:01:11 ----D---- C:\Program Files\ESET
2011-12-26 13:28:29 ----D---- C:\ProgramData\NVIDIA
2011-12-26 13:27:15 ----A---- C:\Windows\system32\nvvsvc.exe
2011-12-26 13:27:15 ----A---- C:\Windows\system32\nvsvcr.dll
2011-12-26 13:27:15 ----A---- C:\Windows\system32\nvsvc64.dll
2011-12-26 13:27:15 ----A---- C:\Windows\system32\nvshext.dll
2011-12-26 13:27:15 ----A---- C:\Windows\system32\nvmctray.dll
2011-12-26 13:27:15 ----A---- C:\Windows\system32\nvcpl.dll
2011-12-26 13:27:00 ----D---- C:\ProgramData\NVIDIA Corporation
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-12-26 13:26:20 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\OpenCL.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvoglv64.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvgenco64.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvdispco64.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvcuvid.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvcuda.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvcompiler.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\nvapi64.dll
2011-12-26 13:26:20 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-12-26 13:26:05 ----D---- C:\Program Files\NVIDIA Corporation
2011-12-26 13:25:50 ----D---- C:\NVIDIA
2011-12-26 13:10:05 ----A---- C:\Windows\system32\FNTCACHE.DAT
2011-12-24 17:34:08 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2011-12-24 17:18:12 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-12-24 17:18:11 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-12-24 17:18:05 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-12-24 17:18:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-12-24 17:18:05 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-12-24 17:18:05 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-12-24 17:18:04 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-12-24 17:18:04 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-12-24 16:32:52 ----A---- C:\Windows\SYSWOW64\GX900Hook.dll
2011-12-24 16:32:52 ----A---- C:\Windows\SYSWOW64\GDIPLUS.DLL
2011-12-24 12:58:41 ----D---- C:\Program Files (x86)\Phyxion.net
2011-12-24 12:55:35 ----D---- C:\Program Files\CCleaner
2011-12-21 19:10:30 ----D---- C:\Fraps
2011-12-20 20:16:32 ----D---- C:\Windows\system32\appmgmt
2011-12-20 16:34:44 ----D---- C:\ProgramData\Solidshield
2011-12-20 16:24:32 ----D---- C:\ProgramData\EA Core
2011-12-19 12:39:34 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-12-19 12:39:34 ----A---- C:\Windows\system32\CPFilters.dll
2011-12-19 12:39:33 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2011-12-19 12:39:33 ----A---- C:\Windows\system32\psisdecd.dll
2011-12-19 12:39:33 ----A---- C:\Windows\system32\msdri.dll
2011-12-19 12:39:32 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-12-19 12:39:32 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-12-19 12:39:32 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-12-19 12:39:32 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-12-19 12:39:32 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-12-19 12:36:41 ----D---- C:\Windows\SYSWOW64\Wat
2011-12-19 12:36:40 ----D---- C:\Windows\system32\Wat
2011-12-19 11:55:09 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-12-19 11:55:09 ----A---- C:\Windows\system32\shell32.dll
2011-12-19 11:55:01 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-12-18 14:48:08 ----SHD---- C:\ProgramData\SecuROM
2011-12-18 00:52:52 ----D---- C:\Windows\Panther
2011-12-17 19:57:59 ----RHD---- C:\Users\Michal\AppData\Roaming\SecuROM
2011-12-17 19:38:10 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-12-17 19:36:53 ----D---- C:\Windows\SYSWOW64\xlive
2011-12-17 19:36:53 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-12-17 18:55:57 ----D---- C:\Program Files (x86)\Rockstar Games
2011-12-17 18:45:06 ----D---- C:\Program Files (x86)\FinalWire
2011-12-17 18:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-12-17 18:44:17 ----D---- C:\Program Files (x86)\VideoLAN
2011-12-17 18:37:44 ----D---- C:\Windows\SYSWOW64\drivers\sk-SK
2011-12-17 18:37:43 ----D---- C:\Windows\sk-SK
2011-12-17 18:37:42 ----D---- C:\Windows\system32\drivers\sk-SK
2011-12-17 18:32:33 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-12-17 18:31:12 ----D---- C:\ProgramData\Sun
2011-12-17 18:31:01 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-12-17 18:31:01 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-12-17 18:31:01 ----A---- C:\Windows\SYSWOW64\java.exe
2011-12-17 18:31:01 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-12-17 18:30:55 ----D---- C:\Program Files (x86)\Java
2011-12-17 18:22:10 ----D---- C:\Users\Michal\AppData\Roaming\WinRAR
2011-12-17 18:22:06 ----D---- C:\Program Files\WinRAR
2011-12-17 18:19:41 ----D---- C:\ProgramData\Adobe
2011-12-17 18:19:40 ----D---- C:\Program Files (x86)\Adobe
2011-12-17 18:19:19 ----A---- C:\Windows\system32\javaws.exe
2011-12-17 18:19:19 ----A---- C:\Windows\system32\javaw.exe
2011-12-17 18:19:19 ----A---- C:\Windows\system32\java.exe
2011-12-17 18:19:19 ----A---- C:\Windows\system32\deployJava1.dll
2011-12-17 18:19:13 ----D---- C:\Program Files\Java
2011-12-17 18:14:45 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-12-17 18:13:52 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-12-17 18:11:06 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-12-17 18:11:06 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-12-17 18:11:06 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-12-17 18:11:06 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-12-17 18:11:06 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-12-17 18:11:06 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-12-17 18:11:06 ----A---- C:\Windows\system32\PresentationHost.exe
2011-12-17 18:11:06 ----A---- C:\Windows\system32\netfxperf.dll
2011-12-17 18:11:06 ----A---- C:\Windows\system32\mscoree.dll
2011-12-17 18:11:06 ----A---- C:\Windows\system32\dfshim.dll
2011-12-17 18:08:54 ----D---- C:\Users\Michal\AppData\Roaming\Origin
2011-12-17 18:08:47 ----D---- C:\ProgramData\Origin
2011-12-17 18:08:47 ----D---- C:\ProgramData\Electronic Arts
2011-12-17 18:08:47 ----D---- C:\Program Files (x86)\Origin Games
2011-12-17 18:08:36 ----D---- C:\Program Files (x86)\Origin
2011-12-17 18:02:20 ----A---- C:\Windows\system32\rtvcvfw32.dll
2011-12-17 18:02:18 ----D---- C:\Program Files (x86)\MSI Afterburner
2011-12-17 17:56:17 ----D---- C:\Windows\pss
2011-12-17 17:54:47 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-12-17 17:54:44 ----RD---- C:\Program Files (x86)\Skype
2011-12-17 17:54:44 ----D---- C:\ProgramData\Skype
2011-12-17 17:52:40 ----D---- C:\Program Files (x86)\Steam
2011-12-17 17:49:23 ----A---- C:\Windows\system32\drivers\ks.sys
2011-12-17 17:49:10 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-12-17 17:49:10 ----A---- C:\Windows\system32\ntdll.dll
2011-12-17 17:45:28 ----A---- C:\Windows\system32\xmllite.dll
2011-12-17 17:45:27 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-12-17 17:45:27 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-12-17 17:45:27 ----A---- C:\Windows\explorer.exe
2011-12-17 17:40:40 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-12-17 17:40:40 ----A---- C:\Windows\system32\FntCache.dll
2011-12-17 17:40:39 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-12-17 17:40:39 ----A---- C:\Windows\system32\DWrite.dll
2011-12-17 17:40:39 ----A---- C:\Windows\system32\d2d1.dll
2011-12-17 17:39:03 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2011-12-17 17:39:03 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2011-12-17 17:39:03 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2011-12-17 17:39:03 ----A---- C:\Windows\SYSWOW64\secproc.dll
2011-12-17 17:39:03 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2011-12-17 17:39:03 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2011-12-17 17:39:03 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2011-12-17 17:39:03 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2011-12-17 17:39:03 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2011-12-17 17:39:03 ----A---- C:\Windows\system32\secproc_ssp.dll
2011-12-17 17:39:03 ----A---- C:\Windows\system32\secproc_isv.dll
2011-12-17 17:39:03 ----A---- C:\Windows\system32\secproc.dll
2011-12-17 17:39:03 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2011-12-17 17:39:03 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2011-12-17 17:39:03 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-12-17 17:39:03 ----A---- C:\Windows\system32\RMActivate.exe
2011-12-17 17:35:32 ----A---- C:\Windows\system32\msxml6.dll
2011-12-17 17:35:32 ----A---- C:\Windows\system32\msxml3.dll
2011-12-17 17:35:31 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-12-17 17:35:31 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-12-17 17:35:31 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-12-17 17:35:31 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-12-17 17:35:31 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-12-17 17:35:31 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-12-17 17:35:31 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-12-17 17:35:31 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-12-17 17:35:31 ----A---- C:\Windows\system32\wscsvc.dll
2011-12-17 17:35:31 ----A---- C:\Windows\system32\wscapi.dll
2011-12-17 17:35:31 ----A---- C:\Windows\system32\winhttp.dll
2011-12-17 17:35:31 ----A---- C:\Windows\system32\WebClnt.dll
2011-12-17 17:35:31 ----A---- C:\Windows\system32\upnp.dll
2011-12-17 17:35:31 ----A---- C:\Windows\system32\slwga.dll
2011-12-17 17:35:31 ----A---- C:\Windows\system32\davclnt.dll
2011-12-17 17:35:29 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-12-17 17:35:29 ----A---- C:\Windows\system32\d3d10_1.dll
2011-12-17 17:30:35 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2011-12-17 17:30:35 ----A---- C:\Windows\SYSWOW64\secur32.dll
2011-12-17 17:30:35 ----A---- C:\Windows\system32\lsasrv.dll
2011-12-17 17:30:35 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-12-17 17:30:29 ----A---- C:\Windows\system32\winlogon.exe
2011-12-17 17:30:29 ----A---- C:\Windows\system32\srvsvc.dll
2011-12-17 17:30:29 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-12-17 17:30:29 ----A---- C:\Windows\system32\drivers\srv.sys
2011-12-17 17:30:28 ----A---- C:\Windows\SYSWOW64\sscore.dll
2011-12-17 17:30:28 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-12-17 17:14:28 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-12-17 17:14:28 ----A---- C:\Windows\system32\poqexec.exe
2011-12-17 17:11:45 ----D---- C:\Program Files (x86)\AMD
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\wextract.exe
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\msls31.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\mshta.exe
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\icardie.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2011-12-17 17:06:06 ----A---- C:\Windows\SYSWOW64\admparse.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\wininet.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\wextract.exe
2011-12-17 17:06:06 ----A---- C:\Windows\system32\webcheck.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\vbscript.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\urlmon.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\url.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-12-17 17:06:06 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-12-17 17:06:06 ----A---- C:\Windows\system32\pngfilt.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\occache.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\msrating.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\msls31.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\mshtmler.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\mshtml.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\mshta.exe
2011-12-17 17:06:06 ----A---- C:\Windows\system32\msfeedssync.exe
2011-12-17 17:06:06 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\msfeeds.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\licmgr10.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\jscript9.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\jscript.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\inseng.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\imgutil.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\iexpress.exe
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ieUnatt.exe
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ieui.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\iesysprep.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\iesetup.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\iertutil.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\iernonce.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\iepeers.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ieframe.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\iedkcs32.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ieapfltr.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ieapfltr.dat
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ieakui.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ieaksie.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ieakeng.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\ie4uinit.exe
2011-12-17 17:06:06 ----A---- C:\Windows\system32\icardie.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\dxtrans.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\dxtmsft.dll
2011-12-17 17:06:06 ----A---- C:\Windows\system32\admparse.dll
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-12-17 17:04:46 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\XpsPrint.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-12-17 17:04:46 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\mfps.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\mf.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-12-17 17:04:46 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-12-17 17:04:46 ----A---- C:\Windows\system32\d3d10warp.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-12-17 17:04:46 ----A---- C:\Windows\system32\cdd.dll
2011-12-17 16:56:32 ----D---- C:\ProgramData\ASUS OC Profiles
2011-12-17 16:52:49 ----A---- C:\Windows\system32\drivers\AiChargerPlus.sys
2011-12-17 16:52:34 ----A---- C:\Windows\SYSWOW64\drivers\UpdateHelper.dll
2011-12-17 16:51:28 ----D---- C:\ProgramData\ASUS
2011-12-17 16:51:22 ----RA---- C:\Windows\SYSWOW64\drivers\AsIO.sys
2011-12-17 16:51:22 ----RA---- C:\Windows\SYSWOW64\AsIO.dll
2011-12-17 16:51:22 ----D---- C:\Program Files (x86)\ASUS
2011-12-17 16:51:20 ----N---- C:\Windows\SYSWOW64\drivers\AsInsHelp64.sys
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-12-17 16:48:16 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-12-17 16:48:15 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-12-17 16:48:15 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-12-17 16:48:15 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-12-17 16:48:15 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-12-17 16:48:15 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-12-17 16:48:15 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-12-17 16:48:15 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-12-17 16:48:15 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-12-17 16:48:15 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-12-17 16:48:15 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-12-17 16:48:15 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-12-17 16:48:15 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-12-17 16:48:15 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-12-17 16:48:15 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-12-17 16:48:14 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-12-17 16:48:14 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-12-17 16:48:14 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-12-17 16:48:14 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-12-17 16:48:14 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-12-17 16:48:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-12-17 16:48:14 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-12-17 16:48:14 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-12-17 16:48:14 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-12-17 16:48:14 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-12-17 16:48:14 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-12-17 16:48:14 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-12-17 16:48:13 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-12-17 16:48:13 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-12-17 16:48:13 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-12-17 16:48:13 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-12-17 16:48:13 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-12-17 16:48:13 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-12-17 16:48:13 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-12-17 16:48:13 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-12-17 16:48:12 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-12-17 16:48:12 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-12-17 16:48:12 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-12-17 16:48:12 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-12-17 16:48:12 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-12-17 16:48:12 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-12-17 16:48:12 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-12-17 16:48:12 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-12-17 16:48:12 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-12-17 16:48:12 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-12-17 16:48:11 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-12-17 16:48:11 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-12-17 16:48:11 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-12-17 16:48:11 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-12-17 16:48:11 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-12-17 16:48:11 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-12-17 16:48:11 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-12-17 16:48:11 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-12-17 16:48:11 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-12-17 16:48:11 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-12-17 16:48:11 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-12-17 16:48:11 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-12-17 16:48:11 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-12-17 16:48:11 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-12-17 16:48:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-12-17 16:48:10 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-12-17 16:48:09 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-12-17 16:48:09 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-12-17 16:48:09 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-12-17 16:48:09 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-12-17 16:48:08 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-12-17 16:48:08 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-12-17 16:48:08 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-12-17 16:48:08 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-12-17 16:48:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-12-17 16:48:08 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-12-17 16:48:08 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-12-17 16:48:08 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-12-17 16:48:08 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-12-17 16:48:08 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-12-17 16:48:07 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\xinput1_3.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-12-17 16:48:07 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-12-17 16:48:06 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\xinput1_2.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-12-17 16:48:06 ----A---- C:\Windows\system32\d3dx10.dll
2011-12-17 16:48:05 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-12-17 16:48:05 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-12-17 16:48:05 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-12-17 16:48:05 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-12-17 16:48:05 ----A---- C:\Windows\system32\xinput1_1.dll
2011-12-17 16:48:05 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-12-17 16:48:05 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-12-17 16:48:05 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-12-17 16:48:04 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-12-17 16:48:04 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-12-17 16:48:04 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-12-17 16:48:04 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-12-17 16:48:04 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-12-17 16:48:04 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-12-17 16:48:04 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-12-17 16:48:04 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-12-17 16:48:03 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-12-17 16:48:03 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-12-17 16:48:00 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-12-17 16:48:00 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-12-17 16:48:00 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-12-17 16:48:00 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-12-17 16:48:00 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-12-17 16:48:00 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-12-17 16:41:18 ----HD---- C:\Windows\msdownld.tmp
2011-12-17 16:41:06 ----D---- C:\Windows\SYSWOW64\directx
2011-12-17 16:35:06 ----N---- C:\Windows\system32\MpSigStub.exe
2011-12-17 16:21:05 ----D---- C:\Users\Michal\AppData\Roaming\Macromedia
2011-12-17 16:21:05 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-12-17 16:21:03 ----D---- C:\Windows\SYSWOW64\Macromed
2011-12-17 16:21:02 ----D---- C:\Windows\system32\Macromed
2011-12-17 16:18:37 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2011-12-17 16:18:33 ----A---- C:\Windows\system32\RTNUninst64.dll
2011-12-17 16:18:33 ----A---- C:\Windows\system32\RtNicProp64.dll
2011-12-17 16:17:26 ----D---- C:\Program Files (x86)\ASM104xUSB3
2011-12-17 16:14:57 ----A---- C:\Windows\system32\drivers\jraid.sys
2011-12-17 16:14:55 ----D---- C:\Windows\RaidTool
2011-12-17 16:09:46 ----D---- C:\Windows\SYSWOW64\RTCOM
2011-12-17 16:09:46 ----D---- C:\Program Files\Realtek
2011-12-17 16:09:37 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-12-17 16:09:36 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\SRSWOW64.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\SRSTSX64.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\SRSTSH64.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\SRSHP64.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\SFSS_APO.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\SFNHK64.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\SFCOM64.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\SFAPO64.dll
2011-12-17 16:09:36 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2011-12-17 16:09:34 ----A---- C:\Windows\system32\RtkCfg64.dll
2011-12-17 16:09:34 ----A---- C:\Windows\system32\RtkAPO64.dll
2011-12-17 16:09:34 ----A---- C:\Windows\system32\RtkApi64.dll
2011-12-17 16:09:33 ----A---- C:\Windows\system32\RtPgEx64.dll
2011-12-17 16:09:33 ----A---- C:\Windows\system32\RTCOM64.dll
2011-12-17 16:09:32 ----A---- C:\Windows\system32\RTEEP64A.dll
2011-12-17 16:09:32 ----A---- C:\Windows\system32\RTEEL64A.dll
2011-12-17 16:09:32 ----A---- C:\Windows\system32\RTEEG64A.dll
2011-12-17 16:09:32 ----A---- C:\Windows\system32\RTEED64A.dll
2011-12-17 16:09:32 ----A---- C:\Windows\system32\RP3DHT64.dll
2011-12-17 16:09:32 ----A---- C:\Windows\system32\RP3DAA64.dll
2011-12-17 16:09:32 ----A---- C:\Windows\system32\RCoRes64.dat
2011-12-17 16:09:32 ----A---- C:\Windows\system32\RCoInst64.dll
2011-12-17 16:09:32 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2011-12-17 16:09:30 ----A---- C:\Windows\system32\R4EEP64A.dll
2011-12-17 16:09:30 ----A---- C:\Windows\system32\R4EEL64A.dll
2011-12-17 16:09:30 ----A---- C:\Windows\system32\R4EEG64A.dll
2011-12-17 16:09:29 ----A---- C:\Windows\system32\R4EED64A.dll
2011-12-17 16:09:29 ----A---- C:\Windows\system32\R4EEA64A.dll
2011-12-17 16:09:29 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2011-12-17 16:09:29 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2011-12-17 16:09:29 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-12-17 16:09:29 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2011-12-17 16:09:28 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-12-17 16:09:25 ----A---- C:\Windows\system32\FMAPO64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2011-12-17 16:09:24 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2011-12-17 16:09:23 ----D---- C:\Program Files (x86)\Realtek
2011-12-17 16:09:23 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2011-12-17 16:09:23 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2011-12-17 16:09:23 ----A---- C:\Windows\system32\AERTAR64.dll
2011-12-17 16:09:23 ----A---- C:\Windows\system32\AERTAC64.dll
2011-12-17 16:09:22 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-12-17 16:09:18 ----HD---- C:\Program Files (x86)\Temp
2011-12-17 16:09:17 ----R---- C:\Windows\RtlExUpd.dll
2011-12-17 16:08:13 ----A---- C:\Windows\system32\drivers\amd_xata.sys
2011-12-17 16:08:13 ----A---- C:\Windows\system32\drivers\amd_sata.sys
2011-12-17 16:08:04 ----RA---- C:\Windows\system32\drivers\usbfilter.sys
2011-12-17 16:08:04 ----DC---- C:\Windows\system32\DRVSTORE
2011-12-17 16:08:00 ----D---- C:\Program Files\ATI
2011-12-17 16:07:55 ----SHD---- C:\Windows\Installer
2011-12-17 16:06:47 ----A---- C:\Windows\Language_trs.ini
2011-12-17 16:06:41 ----A---- C:\Windows\Ascd_tmp.ini
2011-12-17 16:00:36 ----D---- C:\Windows\SoftwareDistribution
2011-12-17 15:59:22 ----D---- C:\Users\Michal\AppData\Roaming\Identities
2011-12-17 15:59:12 ----SD---- C:\Users\Michal\AppData\Roaming\Microsoft
2011-12-17 15:59:12 ----D---- C:\Users\Michal\AppData\Roaming\Media Center Programs
2011-12-17 15:59:05 ----SHD---- C:\Recovery
2011-12-17 15:54:03 ----D---- C:\Windows\Prefetch
2011-12-17 15:53:38 ----SHD---- C:\System Volume Information
2011-12-17 15:53:38 ----ASH---- C:\pagefile.sys
2011-12-17 15:53:38 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 month======

2011-12-27 17:07:22 ----D---- C:\Windows\Temp
2011-12-27 17:07:08 ----D---- C:\Windows\SYSWOW64\drivers
2011-12-27 17:06:08 ----HD---- C:\ProgramData
2011-12-27 17:06:04 ----RD---- C:\Program Files (x86)
2011-12-27 17:06:04 ----D---- C:\Windows\system32\drivers
2011-12-27 16:07:31 ----D---- C:\Windows\SysWOW64
2011-12-27 13:13:48 ----D---- C:\Windows\system32\config
2011-12-27 12:42:44 ----RD---- C:\Program Files
2011-12-27 12:38:11 ----D---- C:\Windows\System32
2011-12-27 12:38:11 ----D---- C:\Windows\inf
2011-12-27 12:38:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-27 12:31:22 ----D---- C:\Windows
2011-12-27 12:30:45 ----D---- C:\Windows\system32\catroot2
2011-12-26 18:01:34 ----D---- C:\Windows\system32\DriverStore
2011-12-26 18:01:34 ----D---- C:\Windows\system32\catroot
2011-12-26 14:57:54 ----SD---- C:\ProgramData\Microsoft
2011-12-26 13:27:15 ----D---- C:\Windows\Help
2011-12-26 13:10:17 ----D---- C:\Windows\debug
2011-12-26 13:04:09 ----D---- C:\Windows\Logs
2011-12-26 12:33:35 ----D---- C:\Windows\system32\Tasks
2011-12-26 12:28:55 ----D---- C:\Windows\winsxs
2011-12-26 12:28:13 ----RSD---- C:\Windows\assembly
2011-12-26 12:23:08 ----D---- C:\Windows\system32\wdi
2011-12-24 22:56:30 ----D---- C:\Windows\system32\en-US
2011-12-24 17:18:42 ----D---- C:\Program Files (x86)\Common Files
2011-12-24 17:18:10 ----D---- C:\Windows\system32\LogFiles
2011-12-22 12:51:00 ----D---- C:\Windows\Microsoft.NET
2011-12-19 12:39:57 ----D---- C:\Windows\ehome
2011-12-18 14:44:26 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-12-17 20:39:07 ----D---- C:\Windows\LiveKernelReports
2011-12-17 18:38:24 ----D---- C:\Windows\rescache
2011-12-17 18:37:47 ----D---- C:\Program Files\Windows Sidebar
2011-12-17 18:37:47 ----D---- C:\Program Files\Windows Media Player
2011-12-17 18:37:47 ----D---- C:\Program Files\Windows Mail
2011-12-17 18:37:47 ----D---- C:\Program Files\DVD Maker
2011-12-17 18:37:47 ----D---- C:\Program Files\Common Files\System
2011-12-17 18:37:46 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-12-17 18:37:46 ----D---- C:\Windows\SYSWOW64\migwiz
2011-12-17 18:37:46 ----D---- C:\Windows\servicing
2011-12-17 18:37:46 ----D---- C:\Program Files\Windows Photo Viewer
2011-12-17 18:37:46 ----D---- C:\Program Files\Windows Defender
2011-12-17 18:37:46 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-12-17 18:37:46 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-12-17 18:37:46 ----D---- C:\Program Files (x86)\Windows Media Player
2011-12-17 18:37:46 ----D---- C:\Program Files (x86)\Windows Mail
2011-12-17 18:37:46 ----D---- C:\Program Files (x86)\Windows Defender
2011-12-17 18:37:44 ----D---- C:\Windows\SYSWOW64\WCN
2011-12-17 18:37:43 ----D---- C:\Windows\SYSWOW64\wbem
2011-12-17 18:37:43 ----D---- C:\Windows\system32\sysprep
2011-12-17 18:37:43 ----D---- C:\Windows\system32\sk-SK
2011-12-17 18:37:43 ----D---- C:\Windows\system32\oobe
2011-12-17 18:37:43 ----D---- C:\Windows\system32\migwiz
2011-12-17 18:37:43 ----D---- C:\Windows\PolicyDefinitions
2011-12-17 18:37:42 ----D---- C:\Windows\system32\WCN
2011-12-17 18:37:41 ----D---- C:\Windows\system32\wbem
2011-12-17 18:13:52 ----D---- C:\Windows\SYSWOW64\en-US
2011-12-17 17:40:59 ----D---- C:\Windows\AppPatch
2011-12-17 17:06:41 ----D---- C:\Windows\SYSWOW64\migration
2011-12-17 17:06:41 ----D---- C:\Windows\system32\migration
2011-12-17 17:06:36 ----D---- C:\Program Files\Internet Explorer
2011-12-17 17:06:36 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-17 16:59:23 ----D---- C:\Windows\Tasks
2011-12-17 16:21:05 ----D---- C:\Windows\Downloaded Program Files
2011-12-17 16:14:49 ----D---- C:\Windows\system32\restore
2011-12-17 16:07:01 ----D---- C:\Windows\system32\CodeIntegrity
2011-12-17 15:59:20 ----SHD---- C:\$Recycle.Bin
2011-12-17 15:59:12 ----RD---- C:\Users
2011-12-17 15:54:33 ----D---- C:\Windows\system32\drivers\UMDF
2011-12-17 15:54:00 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AiChargerPlus;ASUS Charger Plus Driver; C:\Windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2011-03-04 78976]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2011-03-04 38528]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-11-25 120408]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2010-08-24 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2010-08-03 14464]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2011-08-04 137144]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2011-02-24 126952]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-02-24 389608]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-11-23 2565736]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-03-21 452200]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-12-16 47232]
S2 AODDriver4.1;AODDriver4.1; \??\C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver2.sys []
S3 cpuz135;cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys []
S3 KMWDFILTER;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 30208]
S3 mbr;mbr; \??\C:\Users\Michal\AppData\Local\Temp\mbr.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
R2 asHmComSvc;ASUS HM Com Service; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-09-22 974944]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-12-17 889664]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-12-25 75136]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2011-12-27 280904]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 WLMS;@%SystemRoot%\system32\wlms\wlms.exe,-1; C:\Windows\system32\wlms\wlms.exe [2009-07-14 19456]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-12-17 419624]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-19 1255736]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------
Naposledy upravil(a) ferko123 dne 16 lis 2012 20:00, celkem upraveno 1 x.

ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

Re: prosím o kontrolu logu

#4 Příspěvek od ferko123 »

MBAM čistý

ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

Re: prosím o kontrolu logu

#5 Příspěvek od ferko123 »

safe mod repair mi nefunguje. napíše error. To druhé mi tiež nejde. Nepodporovaný OS.

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: prosím o kontrolu logu

#6 Příspěvek od chodnik74 »

Nepodporovaný OS.

:!: Mohl bych se zeptat, proč máte Windows 7 Enterprise?
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

Re: prosím o kontrolu logu

#7 Příspěvek od ferko123 »

lebo je to najvyšší model W7

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: prosím o kontrolu logu

#8 Příspěvek od chodnik74 »

A to znamená co pro vás?
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

Re: prosím o kontrolu logu

#9 Příspěvek od ferko123 »

automaticky som nahodil to najlepšie. Ale 35 jazykov, bitlocker, xp mode, vzdialený prístup využívam.

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: prosím o kontrolu logu

#10 Příspěvek od chodnik74 »

Čili jste si stáhnul z internetu a nainstaloval? Pokud vás dobře chápu? Vy umíte 35 jazyků? tak to klobouk dolů :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

Re: prosím o kontrolu logu

#11 Příspěvek od ferko123 »

MSDN. Využívam angličtinu, slovenčinu a nemčinu kvôli videám ale to je nepodstatné.

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: prosím o kontrolu logu

#12 Příspěvek od chodnik74 »

Chcete mi říct, že licence je legální? Tahle edice není volně dostupná...
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

Re: prosím o kontrolu logu

#13 Příspěvek od ferko123 »

keby som mal nelegálny windows, nefungujúci safemod neriešim lebo sám som zistil ako strašne blbnú stiahnuté verzie = legál

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: prosím o kontrolu logu

#14 Příspěvek od chodnik74 »

Fajn.. věřím vám.. Konec konců pokud budete mít nelegální windows, budete škodit sám cobe, protože Combofix může nelegální systém zbiřit :)

:arrow: Stáhněte program RogueKiller
  • Spuste program
  • Stiskněte klávesu 2 a enter
  • Objeví se vám log a ten sem vložte
  • Stějně tak opakujte s volbou 3 a 4 a vložte logy

Program nepoužívejte bez doporučení Rádce a pozorně se řiďte následujících pokynu,protože program netoleruje chyby a může dojít k úplnému poškození systému!!
  • :arrow: Stáhneme si Combofix Obrázek
  • Program uložíme nejlépe na Plochu
  • Vypneme všechny rezidentní štíty.Jak antiviru,tak antispywaru a firewallu
  • Vypneme všechny běžící aplikace (ICQ,prohlížeč,programy) a necháme pouze Combofix
  • Spustíme Combofix.exe s administrátorským oprávněním
    U Windows XP se přihlásíme pod účtem správce
    Ve Windows 7 a Vista klikněte pravým tlačítkem myši na Combofix.exe a dejte ,,Spustit jako správce,,)
  • Hned po startu programu na vás vyskočí licenční podmínky,tak potvrdíme tlačítkemANO
  • Pokud vám Combofix nabídne instalaci Konzoly pro zotavení,tak souhlaste a nechte nainstalovat(zde je potřeba aktivní připojení na internet)
  • Pokračujte dle pokynů programu a během skenování na nic neklikejte,na pc nepracujte(ICQ,jiné aplikace,internet..).Nechte počítač v klidu.
  • Celý sken tvá mezi 5-15 min,ale pokud je v PC hodně havěti,tak se čas může lišit.
  • Po skončení skenování(případném restartu počítače) se vám zobrazí log z Combofixu,který mi vložte sem(Kdyby se log nezobrazil,tak jej najdete zde: C:\ComboFix.txt
  • (Pokud si nevíte rady s kterýmkoliv z výše uvedených kroků,tak se ptejte nebo mrkněte na detailnější návod včetně obrázků http://www.bleepingcomputer.com/combofi ... t-combofix )
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

ferko123
3. Stupeň Varování
Příspěvky: 25
Registrován: 27 pro 2011 12:44

Re: prosím o kontrolu logu

#15 Příspěvek od ferko123 »

idem na ten combofix





RogueKiller V6.2.1 [12/28/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Michal [Admin rights]
Mode: Remove -- Date : 12/29/2011 16:55:50

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 2 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 563e9373db8da4e6c7bc324560b7169a
[BSP] 3325c287a5e56a679783946f6df204e1 : Windows Vista/7 MBR Code
Partition table:
0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 2048 | Size: 104 Mo
1 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 206848 | Size: 750048 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive1: +++++
--- User ---
[MBR] 52fb40d382cca0c648f8604fed34616e
[BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows Vista/7 MBR Code
Partition table:
0 - [ACTIVE] FAT32 [VISIBLE] Offset (sectors): 2048 | Size: 7788 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[1].txt >>
RKreport[1].txt


RogueKiller V6.2.1 [12/28/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Michal [Admin rights]
Mode: HOSTSFix -- Date : 12/29/2011 16:56:08

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤


¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt



RogueKiller V6.2.1 [12/28/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Michal [Admin rights]
Mode: ProxyFix -- Date : 12/29/2011 16:56:19

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Registry Entries: 0 ¤¤¤

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
Naposledy upravil(a) ferko123 dne 16 lis 2012 19:58, celkem upraveno 1 x.

Odpovědět