Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

DNSchanger - prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Jituuus.ka
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 05 dub 2012 18:52

Re: DNSchanger - prosím o kontrolu logu

#31 Příspěvek od Jituuus.ka »

Tak všechny počítače už jsou v pořádku, žádný není napaden DNSChanger. Mockrát děkuji za pomoc. :)

Ale mám další problém a myslím, že to souvisí. Druhý počítač je sice připojen k domácí Wi-fi, ale nemá přístup na internet. Předtím pokaždé, když jsem zkoušela Aviru a ten jejich program na odstranění DNSChangeru, tak když ho zablokovala, taky přestal internet fungovat... Můžete mi prosím nějak pomoci?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: DNSchanger - prosím o kontrolu logu

#32 Příspěvek od vyosek »

Na PC 1 a 3

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: MBAM muzete odinstalovat nebo nechat na obcasny sken - v pripade nalezu velmi doporucuji dat sem log na posouzeni, at si neodstrelite neco legitimniho

:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden


Na PC 2

:arrow: MBAM muzete odinstalovat nebo nechat na obcasny sken - v pripade nalezu velmi doporucuji dat sem log na posouzeni, at si neodstrelite neco legitimniho


PC 3 - internet
Zkuste restart routeru a pak jej nastavit dle pokynu - pokud je pripojeny k wifi(routeru) a ten nema pristup tak je chyba v nem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jituuus.ka
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 05 dub 2012 18:52

Re: DNSchanger - prosím o kontrolu logu

#33 Příspěvek od Jituuus.ka »

Tak momentálně vše funguje skvěle :) Internet jde všude, nic nehlásí nákazu DNSChangerem a já jenom doufám, že jsem to teď nezakřikla. :D

Mockrát děkuji za pomoc. :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: DNSchanger - prosím o kontrolu logu

#34 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek


A na rozloucenou vam zahraje nase kapela :guitar: :150: :151: :152: :153: :154: :196:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jituuus.ka
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 05 dub 2012 18:52

Re: DNSchanger - prosím o kontrolu logu

#35 Příspěvek od Jituuus.ka »

Opět zdravím!

Nejsem si jistá, jestli dostanu odpověď na starém tématu, ale doufám, že ano. =)

Mám opět problém s DNSchangerem, ale počítač se zdá být čistý. Žádný antivirový program nic nenašel, ani Malwarebytes. Přikládám výpis log z RSIT a doufám, že to pujde spravit. =)


Logfile of random's system information tool 1.09 (written by random/random)
Run by Jitka at 2012-06-11 17:05:39
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 207 GB (80%) free of 260 GB
Total RAM: 1641 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:06:01, on 11.6.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
c:\PROGRA~2\mcafee\SITEAD~1\saui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jitka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120602101405.dll
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [332BigDog] C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe" /s
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll/206 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: BitComet Disk Boost Service (BITCOMET_HELPER_SERVICE) - www.BitComet.com - C:\Program Files (x86)\BitComet\tools\BitCometService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - c:\PROGRA~1\mcafee\msc\mcawfwk.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12936 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\windows\system32\services.exe
winlogon.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\windows\system32\mfevtps.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
C:\windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
System32\TPHDEXLG64.exe
"taskhost.exe"
"C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\CapsLK OSD\64\Capsosd.exe"
"C:\Windows\System32\TpShocks.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
taskeng.exe {D3F927F8-F679-4D8D-AE4A-080907EAE744}
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\USB Camera2\VM332_STI.EXE"
"C:\Program Files\mcafee.com\agent\mcagent.exe" /runkey
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3252.1.628932152\2010753771" --reduce-gpu-sandbox --disable-image-transport-surface /prefetch:12
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/0/Prerender/ContentPrefetchPrerender1/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/WebStoreLinkExperiment/FooterLink/ --extension-process --renderer-print-preview --channel="3252.2.823669375\1508914773" /prefetch:3
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Jitka\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll" --lang=cs --channel="3252.3.96554705\798006800" /prefetch:4
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\windows\system32\rundll32.exe" "c:\PROGRA~2\mcafee\SITEAD~1\saHook.dll", saHooker_Initialize_and_Wait
"C:\windows\system32\rundll32.exe" "c:\PROGRA~2\mcafee\SITEAD~1\x64\saHook.dll", saHooker_Initialize_and_Wait
"C:\windows\system32\rundll32.exe" "c:\PROGRA~2\mcafee\SITEAD~1\saHook.dll", saHooker_Initialize_and_Wait
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/0/Prerender/ContentPrefetchPrerender1/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --channel="3252.5.1241880010\719429961" /prefetch:3
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 5692
"c:\PROGRA~2\mcafee\SITEAD~1\saui.exe" -Embedding
"C:\windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ComodoDNSExperiment/inactive/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Hidden/OmniboxPrerenderHitWeightingTrial/OmniboxPrerenderWeight8.0/OmniboxSearchSuggest/0/Prerender/ContentPrefetchPrerender1/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/WebStoreLinkExperiment/FooterLink/ --renderer-print-preview --channel="3252.7.1988482727\303153992" /prefetch:3
C:\windows\system32\rundll32.exe "C:\PROGRA~2\Google\Chrome\APPLIC~1\190108~1.52\gcswf32.dll",BrokerMain browser=chrome
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.52\gcswf32.dll" --lang=cs --channel="3252.11.732481901\23473970" --flash-broker=7476 /prefetch:4
"C:\Users\Jitka\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Jitka\AppData\Roaming\Mozilla\Firefox\Profiles\ymk9yxjc.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.257 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.4.1]
"Description"=
"Path"=C:\windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@mcafee.com/MSC,version=10]
"Description"=McAfee Total Protection MIME Plugin
"Path"=c:\progra~2\mcafee\msc\npmcsn~1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@mcafee.com/SAFFPlugin]
"Description"=
"Path"=C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.257 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_257.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@mcafee.com/MSC,version=10]
"Description"=McAfee Total Protection MIME Plugin
"Path"=c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120530190039.dll [2012-03-20 94688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
Partner BHO Class - C:\ProgramData\Partner\Partner64.dll [2011-08-23 750064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2012-05-30 253040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll [2012-02-17 348592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll [2011-04-11 767280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-04-04 453504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120602101405.dll [2012-03-20 79744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
Partner BHO Class - C:\ProgramData\Partner\Partner.dll [2011-08-23 433648]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2012-05-30 192112]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [2012-02-17 281600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-04-04 157576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll [2012-02-17 348592]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2012-05-30 253040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [2012-02-17 281600]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2012-05-30 192112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-10-21 2396968]
"{BA1E422A-80A8-4AA0-B67B-CAA3D04C5162}"=C:\Program Files\CapsLK OSD\64\CAPSOSD.EXE [2010-10-25 3699752]
"TpShocks"=C:\Windows\System32\TpShocks.exe [2010-03-15 231328]
"Lenovo EE Boot Optimizer"=C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [2011-08-23 206176]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2011-08-23 9753024]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2011-08-23 5908928]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-08-23 39408]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-06-08 336384]
"332BigDog"=C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [2010-01-19 536576]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2012-03-21 1675160]
"YouCam Mirage"=C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2010-12-24 136488]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [2010-12-24 224352]
"VeriFaceManager"=C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [2011-08-23 329056]
"UpdatePRCShortCut"=C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [2009-05-13 222504]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro36]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro36.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefire]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfevtp]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-06-11 17:05:40 ----D---- C:\Program Files\trend micro
2012-06-11 17:05:39 ----D---- C:\rsit
2012-06-10 21:35:16 ----D---- C:\ProgramData\HitmanPro
2012-06-10 18:33:07 ----D---- C:\Users\Jitka\AppData\Roaming\Google
2012-06-10 18:20:21 ----D---- C:\Users\Jitka\AppData\Roaming\Malwarebytes
2012-06-10 18:19:54 ----D---- C:\ProgramData\Malwarebytes
2012-06-10 18:19:45 ----A---- C:\windows\system32\drivers\mbam.sys
2012-06-10 18:19:43 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-09 11:30:29 ----D---- C:\ProgramData\Ubisoft
2012-06-08 11:17:43 ----D---- C:\ProgramData\Sun
2012-06-08 11:16:51 ----D---- C:\Program Files (x86)\Oracle
2012-06-08 11:16:13 ----A---- C:\windows\SYSWOW64\npDeployJava1.dll
2012-06-08 11:16:13 ----A---- C:\windows\SYSWOW64\javaws.exe
2012-06-08 11:16:13 ----A---- C:\windows\SYSWOW64\deployJava1.dll
2012-06-08 11:15:36 ----A---- C:\windows\SYSWOW64\javaw.exe
2012-06-08 11:15:36 ----A---- C:\windows\SYSWOW64\java.exe
2012-06-08 11:14:44 ----D---- C:\Program Files (x86)\Java
2012-06-06 17:11:55 ----RHD---- C:\MSOCache
2012-06-04 22:29:30 ----D---- C:\ProgramData\VirtualizedApplications
2012-06-04 20:17:26 ----D---- C:\Users\Jitka\AppData\Roaming\SoftGrid Client
2012-06-04 20:15:17 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2012-06-04 20:14:36 ----D---- C:\Program Files\Microsoft Office
2012-06-04 20:14:35 ----D---- C:\Program Files (x86)\Microsoft Application Virtualization Client
2012-06-04 20:13:40 ----D---- C:\Users\Jitka\AppData\Roaming\TP
2012-06-04 10:59:21 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-06-03 09:03:03 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2012-06-03 09:03:03 ----A---- C:\windows\system32\mshtmled.dll
2012-06-03 09:03:02 ----A---- C:\windows\system32\iertutil.dll
2012-06-03 09:03:01 ----A---- C:\windows\SYSWOW64\iertutil.dll
2012-06-03 09:03:01 ----A---- C:\windows\system32\jscript9.dll
2012-06-03 09:03:00 ----A---- C:\windows\SYSWOW64\url.dll
2012-06-03 09:02:59 ----A---- C:\windows\SYSWOW64\ieui.dll
2012-06-03 09:02:59 ----A---- C:\windows\system32\url.dll
2012-06-03 09:02:59 ----A---- C:\windows\system32\ieui.dll
2012-06-03 09:02:58 ----A---- C:\windows\SYSWOW64\jscript9.dll
2012-06-03 09:02:58 ----A---- C:\windows\SYSWOW64\jscript.dll
2012-06-03 09:02:57 ----A---- C:\windows\SYSWOW64\urlmon.dll
2012-06-03 09:02:57 ----A---- C:\windows\system32\urlmon.dll
2012-06-03 09:02:57 ----A---- C:\windows\system32\jscript.dll
2012-06-03 09:02:55 ----A---- C:\windows\system32\jsproxy.dll
2012-06-03 09:02:53 ----A---- C:\windows\SYSWOW64\wininet.dll
2012-06-03 09:02:52 ----A---- C:\windows\system32\wininet.dll
2012-06-03 09:02:51 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2012-06-03 09:02:50 ----A---- C:\windows\SYSWOW64\mshtml.dll
2012-06-03 09:02:48 ----A---- C:\windows\system32\mshtml.dll
2012-06-03 09:02:46 ----A---- C:\windows\SYSWOW64\ieframe.dll
2012-06-03 09:02:44 ----A---- C:\windows\system32\ieframe.dll
2012-06-02 11:30:35 ----D---- C:\Users\Jitka\AppData\Roaming\Mozilla
2012-06-02 11:03:09 ----A---- C:\windows\system32\drivers\bthport.sys
2012-06-02 11:03:08 ----A---- C:\windows\system32\drivers\BTHUSB.SYS
2012-06-02 10:44:18 ----D---- C:\windows\SYSWOW64\Wat
2012-06-02 10:44:17 ----D---- C:\windows\system32\Wat
2012-06-02 10:14:14 ----A---- C:\windows\SYSWOW64\imagehlp.dll
2012-06-02 10:14:14 ----A---- C:\windows\system32\imagehlp.dll
2012-06-02 10:14:14 ----A---- C:\windows\system32\drivers\fs_rec.sys
2012-06-02 10:14:13 ----A---- C:\windows\SYSWOW64\wmi.dll
2012-06-02 10:14:13 ----A---- C:\windows\SYSWOW64\wintrust.dll
2012-06-02 10:14:13 ----A---- C:\windows\system32\wmi.dll
2012-06-02 10:14:13 ----A---- C:\windows\system32\wintrust.dll
2012-06-01 14:31:23 ----A---- C:\windows\system32\odbccr32.dll
2012-06-01 14:31:22 ----A---- C:\windows\system32\odbctrac.dll
2012-06-01 14:31:22 ----A---- C:\windows\system32\odbccu32.dll
2012-06-01 14:31:22 ----A---- C:\windows\system32\odbccp32.dll
2012-06-01 14:31:21 ----A---- C:\windows\SYSWOW64\odbcjt32.dll
2012-06-01 14:31:20 ----A---- C:\windows\SYSWOW64\odbccu32.dll
2012-06-01 14:31:20 ----A---- C:\windows\SYSWOW64\odbccr32.dll
2012-06-01 14:31:19 ----A---- C:\windows\SYSWOW64\odbccp32.dll
2012-06-01 14:31:17 ----A---- C:\windows\SYSWOW64\odbctrac.dll
2012-06-01 14:31:10 ----A---- C:\windows\system32\xmllite.dll
2012-06-01 14:31:09 ----A---- C:\windows\SYSWOW64\xmllite.dll
2012-06-01 14:30:35 ----A---- C:\windows\system32\DWrite.dll
2012-06-01 14:30:34 ----A---- C:\windows\SYSWOW64\DWrite.dll
2012-06-01 14:30:04 ----A---- C:\windows\system32\poqexec.exe
2012-06-01 14:30:03 ----A---- C:\windows\SYSWOW64\poqexec.exe
2012-06-01 14:29:50 ----A---- C:\windows\system32\quartz.dll
2012-06-01 14:29:49 ----A---- C:\windows\SYSWOW64\quartz.dll
2012-06-01 14:29:47 ----A---- C:\windows\SYSWOW64\qdvd.dll
2012-06-01 14:29:47 ----A---- C:\windows\system32\qdvd.dll
2012-06-01 14:29:35 ----A---- C:\windows\system32\shell32.dll
2012-06-01 14:29:33 ----A---- C:\windows\SYSWOW64\shell32.dll
2012-06-01 14:29:32 ----A---- C:\windows\system32\ntshrui.dll
2012-06-01 14:29:31 ----A---- C:\windows\SYSWOW64\ntshrui.dll
2012-06-01 14:28:33 ----A---- C:\windows\system32\tquery.dll
2012-06-01 14:28:32 ----A---- C:\windows\system32\SearchIndexer.exe
2012-06-01 14:28:32 ----A---- C:\windows\system32\mssrch.dll
2012-06-01 14:28:31 ----A---- C:\windows\SYSWOW64\mssrch.dll
2012-06-01 14:28:30 ----A---- C:\windows\system32\SearchProtocolHost.exe
2012-06-01 14:28:29 ----A---- C:\windows\SYSWOW64\tquery.dll
2012-06-01 14:28:28 ----A---- C:\windows\SYSWOW64\SearchIndexer.exe
2012-06-01 14:28:27 ----A---- C:\windows\SYSWOW64\SearchProtocolHost.exe
2012-06-01 14:28:27 ----A---- C:\windows\SYSWOW64\mssph.dll
2012-06-01 14:28:26 ----A---- C:\windows\system32\SearchFilterHost.exe
2012-06-01 14:28:26 ----A---- C:\windows\system32\mssvp.dll
2012-06-01 14:28:26 ----A---- C:\windows\system32\mssph.dll
2012-06-01 14:28:25 ----A---- C:\windows\system32\mssphtb.dll
2012-06-01 14:28:24 ----A---- C:\windows\SYSWOW64\mssvp.dll
2012-06-01 14:28:21 ----A---- C:\windows\SYSWOW64\SearchFilterHost.exe
2012-06-01 14:28:21 ----A---- C:\windows\SYSWOW64\mssphtb.dll
2012-06-01 14:28:21 ----A---- C:\windows\system32\msscntrs.dll
2012-06-01 14:28:20 ----A---- C:\windows\SYSWOW64\msscntrs.dll
2012-06-01 14:28:15 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2012-06-01 14:28:06 ----A---- C:\windows\system32\schannel.dll
2012-06-01 14:28:05 ----A---- C:\windows\SYSWOW64\schannel.dll
2012-06-01 14:28:05 ----A---- C:\windows\system32\lsasrv.dll
2012-06-01 14:28:05 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2012-06-01 14:28:04 ----A---- C:\windows\system32\lsass.exe
2012-06-01 14:28:04 ----A---- C:\windows\system32\drivers\ksecdd.sys
2012-06-01 14:28:04 ----A---- C:\windows\system32\drivers\cng.sys
2012-06-01 14:28:03 ----A---- C:\windows\SYSWOW64\webio.dll
2012-06-01 14:28:03 ----A---- C:\windows\system32\webio.dll
2012-06-01 14:28:02 ----A---- C:\windows\system32\sspicli.dll
2012-06-01 14:28:02 ----A---- C:\windows\system32\secur32.dll
2012-06-01 14:28:01 ----A---- C:\windows\SYSWOW64\secur32.dll
2012-06-01 14:28:01 ----A---- C:\windows\system32\sspisrv.dll
2012-06-01 14:28:00 ----A---- C:\windows\SYSWOW64\sspicli.dll
2012-06-01 14:27:50 ----A---- C:\windows\system32\csrsrv.dll
2012-06-01 14:27:19 ----A---- C:\windows\system32\ntoskrnl.exe
2012-06-01 14:27:18 ----A---- C:\windows\system32\win32k.sys
2012-06-01 14:27:17 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2012-06-01 14:27:16 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2012-06-01 14:27:08 ----A---- C:\windows\system32\XpsPrint.dll
2012-06-01 14:27:07 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2012-06-01 14:23:21 ----A---- C:\windows\system32\psisdecd.dll
2012-06-01 14:23:18 ----A---- C:\windows\SYSWOW64\psisdecd.dll
2012-06-01 14:23:00 ----A---- C:\windows\system32\drivers\afd.sys
2012-06-01 14:22:53 ----A---- C:\windows\system32\drivers\partmgr.sys
2012-06-01 14:22:03 ----A---- C:\windows\system32\KernelBase.dll
2012-06-01 14:22:02 ----A---- C:\windows\system32\kernel32.dll
2012-06-01 14:22:01 ----A---- C:\windows\system32\wow64win.dll
2012-06-01 14:22:00 ----A---- C:\windows\system32\winsrv.dll
2012-06-01 14:21:58 ----A---- C:\windows\system32\conhost.exe
2012-06-01 14:21:57 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2012-06-01 14:21:55 ----A---- C:\windows\SYSWOW64\kernel32.dll
2012-06-01 14:21:55 ----A---- C:\windows\system32\wow64.dll
2012-06-01 14:21:54 ----A---- C:\windows\SYSWOW64\setup16.exe
2012-06-01 14:21:53 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2012-06-01 14:21:53 ----A---- C:\windows\system32\ntvdm64.dll
2012-06-01 14:21:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-06-01 14:21:52 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-06-01 14:21:51 ----A---- C:\windows\system32\wow64cpu.dll
2012-06-01 14:21:50 ----A---- C:\windows\SYSWOW64\instnm.exe
2012-06-01 14:21:49 ----A---- C:\windows\SYSWOW64\wow32.dll
2012-06-01 14:21:48 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2012-06-01 14:21:48 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-06-01 14:21:47 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-06-01 14:21:47 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-06-01 14:21:46 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-06-01 14:21:46 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-06-01 14:21:44 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-06-01 14:21:44 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-06-01 14:21:43 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-06-01 14:21:42 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-06-01 14:21:42 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-06-01 14:21:41 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-06-01 14:21:40 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-06-01 14:21:39 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-06-01 14:21:39 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-06-01 14:21:39 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-06-01 14:21:37 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-06-01 14:21:37 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-06-01 14:21:36 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2012-06-01 14:21:36 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-06-01 14:21:35 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-06-01 14:21:35 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-06-01 14:21:34 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-06-01 14:21:33 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-06-01 14:21:32 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-06-01 14:21:31 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-06-01 14:21:31 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-06-01 14:21:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-06-01 14:21:30 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-06-01 14:21:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2012-06-01 14:21:29 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-06-01 14:21:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-06-01 14:21:27 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-06-01 14:21:27 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-06-01 14:21:26 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-06-01 14:21:26 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-06-01 14:21:25 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-06-01 14:21:25 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-06-01 14:21:23 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-06-01 14:21:23 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-06-01 14:21:22 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-06-01 14:21:22 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-06-01 14:21:21 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-06-01 14:21:20 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-06-01 14:21:20 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-06-01 14:21:19 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-06-01 14:21:18 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2012-06-01 14:21:18 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-06-01 14:21:17 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-06-01 14:21:16 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2012-06-01 14:21:16 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-06-01 14:21:15 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-06-01 14:21:15 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-06-01 14:21:14 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2012-06-01 14:21:12 ----A---- C:\windows\SYSWOW64\user.exe
2012-06-01 14:20:45 ----A---- C:\windows\system32\umpnpmgr.dll
2012-06-01 14:20:41 ----A---- C:\windows\SYSWOW64\drvinst.exe
2012-06-01 14:20:41 ----A---- C:\windows\SYSWOW64\cfgmgr32.dll
2012-06-01 14:20:40 ----A---- C:\windows\SYSWOW64\devobj.dll
2012-06-01 14:20:38 ----A---- C:\windows\SYSWOW64\devrtl.dll
2012-06-01 14:18:25 ----A---- C:\windows\system32\msvcrt.dll
2012-06-01 14:18:24 ----A---- C:\windows\SYSWOW64\msvcrt.dll
2012-06-01 14:17:42 ----A---- C:\windows\system32\drivers\bowser.sys
2012-06-01 14:16:20 ----A---- C:\windows\SYSWOW64\oleacc.dll
2012-06-01 14:16:20 ----A---- C:\windows\system32\oleacc.dll
2012-06-01 14:16:18 ----A---- C:\windows\SYSWOW64\oleaut32.dll
2012-06-01 14:16:18 ----A---- C:\windows\system32\oleaut32.dll
2012-06-01 14:15:29 ----A---- C:\windows\SYSWOW64\EncDec.dll
2012-06-01 14:15:29 ----A---- C:\windows\system32\EncDec.dll
2012-06-01 14:15:11 ----D---- C:\Program Files (x86)\Ubisoft
2012-06-01 14:11:00 ----A---- C:\windows\SYSWOW64\tzres.dll
2012-06-01 14:11:00 ----A---- C:\windows\system32\tzres.dll
2012-06-01 14:08:31 ----A---- C:\windows\system32\drivers\tcpip.sys
2012-06-01 14:07:34 ----A---- C:\windows\SYSWOW64\ntdll.dll
2012-06-01 14:07:34 ----A---- C:\windows\system32\ntdll.dll
2012-06-01 13:59:06 ----A---- C:\windows\SYSWOW64\packager.dll
2012-06-01 13:59:06 ----A---- C:\windows\system32\packager.dll
2012-05-30 23:22:50 ----D---- C:\ProgramData\Mozilla
2012-05-30 23:22:49 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-05-30 23:22:38 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-05-30 22:52:57 ----D---- C:\Program Files (x86)\PANDORA.TV
2012-05-30 22:52:19 ----D---- C:\Program Files (x86)\The KMPlayer
2012-05-30 22:24:45 ----D---- C:\Program Files (x86)\Adobe
2012-05-30 22:23:27 ----D---- C:\ProgramData\Adobe
2012-05-30 21:45:05 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2012-05-30 21:45:04 ----D---- C:\windows\SYSWOW64\Macromed
2012-05-30 21:45:01 ----D---- C:\windows\system32\Macromed
2012-05-30 20:33:39 ----SHD---- C:\System Volume Information
2012-05-30 20:33:39 ----ASH---- C:\pagefile.sys
2012-05-30 20:33:32 ----ASH---- C:\hiberfil.sys
2012-05-30 20:25:54 ----D---- C:\Program Files (x86)\Avidemux 2.5
2012-05-30 20:24:57 ----D---- C:\Users\Jitka\AppData\Roaming\BitComet
2012-05-30 20:24:54 ----D---- C:\Program Files (x86)\BitComet
2012-05-30 20:23:39 ----D---- C:\Program Files\CCleaner
2012-05-30 20:23:12 ----D---- C:\Users\Jitka\AppData\Roaming\WinRAR
2012-05-30 19:07:47 ----A---- C:\windows\SYSWOW64\PnkBstrB.exe
2012-05-30 19:07:43 ----A---- C:\windows\SYSWOW64\PnkBstrA.exe
2012-05-30 19:07:41 ----D---- C:\Users\Jitka\AppData\Roaming\PunkBuster
2012-05-30 19:04:09 ----A---- C:\windows\SYSWOW64\XAudio2_7.dll
2012-05-30 19:04:09 ----A---- C:\windows\SYSWOW64\XAPOFX1_5.dll
2012-05-30 19:04:09 ----A---- C:\windows\system32\XAudio2_7.dll
2012-05-30 19:04:09 ----A---- C:\windows\system32\XAPOFX1_5.dll
2012-05-30 19:04:08 ----A---- C:\windows\SYSWOW64\xactengine3_7.dll
2012-05-30 19:04:08 ----A---- C:\windows\system32\xactengine3_7.dll
2012-05-30 19:04:07 ----A---- C:\windows\SYSWOW64\D3DCompiler_43.dll
2012-05-30 19:04:07 ----A---- C:\windows\system32\D3DCompiler_43.dll
2012-05-30 19:04:05 ----A---- C:\windows\SYSWOW64\d3dcsx_43.dll
2012-05-30 19:04:05 ----A---- C:\windows\system32\d3dcsx_43.dll
2012-05-30 19:04:04 ----A---- C:\windows\SYSWOW64\d3dx11_43.dll
2012-05-30 19:04:04 ----A---- C:\windows\system32\d3dx11_43.dll
2012-05-30 19:04:03 ----A---- C:\windows\SYSWOW64\d3dx10_43.dll
2012-05-30 19:04:03 ----A---- C:\windows\system32\d3dx10_43.dll
2012-05-30 19:04:01 ----A---- C:\windows\SYSWOW64\D3DX9_43.dll
2012-05-30 19:04:01 ----A---- C:\windows\system32\D3DX9_43.dll
2012-05-30 19:03:58 ----A---- C:\windows\SYSWOW64\XAudio2_6.dll
2012-05-30 19:03:58 ----A---- C:\windows\SYSWOW64\XAPOFX1_4.dll
2012-05-30 19:03:58 ----A---- C:\windows\system32\XAudio2_6.dll
2012-05-30 19:03:58 ----A---- C:\windows\system32\XAPOFX1_4.dll
2012-05-30 19:03:56 ----A---- C:\windows\SYSWOW64\xactengine3_6.dll
2012-05-30 19:03:56 ----A---- C:\windows\system32\xactengine3_6.dll
2012-05-30 19:03:55 ----A---- C:\windows\SYSWOW64\X3DAudio1_7.dll
2012-05-30 19:03:55 ----A---- C:\windows\system32\X3DAudio1_7.dll
2012-05-30 19:03:53 ----A---- C:\windows\system32\XAudio2_5.dll
2012-05-30 19:03:51 ----A---- C:\windows\SYSWOW64\xactengine3_5.dll
2012-05-30 19:03:51 ----A---- C:\windows\system32\xactengine3_5.dll
2012-05-30 19:03:50 ----A---- C:\windows\SYSWOW64\D3DCompiler_42.dll
2012-05-30 19:03:50 ----A---- C:\windows\system32\D3DCompiler_42.dll
2012-05-30 19:03:48 ----A---- C:\windows\SYSWOW64\d3dcsx_42.dll
2012-05-30 19:03:48 ----A---- C:\windows\system32\d3dcsx_42.dll
2012-05-30 19:03:46 ----A---- C:\windows\SYSWOW64\d3dx11_42.dll
2012-05-30 19:03:46 ----A---- C:\windows\system32\d3dx11_42.dll
2012-05-30 19:03:44 ----A---- C:\windows\SYSWOW64\D3DX9_42.dll
2012-05-30 19:03:44 ----A---- C:\windows\system32\D3DX9_42.dll
2012-05-30 19:03:41 ----A---- C:\windows\system32\d3dx10_41.dll
2012-05-30 19:03:41 ----A---- C:\windows\system32\D3DCompiler_41.dll
2012-05-30 19:03:35 ----A---- C:\windows\SYSWOW64\D3DX9_41.dll
2012-05-30 19:03:35 ----A---- C:\windows\system32\D3DX9_41.dll
2012-05-30 19:03:31 ----A---- C:\windows\SYSWOW64\XAudio2_4.dll
2012-05-30 19:03:31 ----A---- C:\windows\system32\XAudio2_4.dll
2012-05-30 19:03:31 ----A---- C:\windows\system32\XAPOFX1_3.dll
2012-05-30 19:03:30 ----A---- C:\windows\SYSWOW64\xactengine3_4.dll
2012-05-30 19:03:30 ----A---- C:\windows\system32\xactengine3_4.dll
2012-05-30 19:03:29 ----A---- C:\windows\SYSWOW64\X3DAudio1_6.dll
2012-05-30 19:03:29 ----A---- C:\windows\system32\X3DAudio1_6.dll
2012-05-30 19:03:28 ----A---- C:\windows\SYSWOW64\D3DCompiler_40.dll
2012-05-30 19:03:28 ----A---- C:\windows\system32\D3DCompiler_40.dll
2012-05-30 19:03:27 ----A---- C:\windows\SYSWOW64\d3dx10_40.dll
2012-05-30 19:03:27 ----A---- C:\windows\system32\d3dx10_40.dll
2012-05-30 19:03:26 ----A---- C:\windows\SYSWOW64\D3DX9_40.dll
2012-05-30 19:03:26 ----A---- C:\windows\system32\D3DX9_40.dll
2012-05-30 19:03:24 ----A---- C:\windows\SYSWOW64\XAudio2_3.dll
2012-05-30 19:03:24 ----A---- C:\windows\SYSWOW64\XAPOFX1_2.dll
2012-05-30 19:03:24 ----A---- C:\windows\system32\XAudio2_3.dll
2012-05-30 19:03:24 ----A---- C:\windows\system32\XAPOFX1_2.dll
2012-05-30 19:03:23 ----A---- C:\windows\SYSWOW64\xactengine3_3.dll
2012-05-30 19:03:23 ----A---- C:\windows\system32\xactengine3_3.dll
2012-05-30 19:03:22 ----A---- C:\windows\SYSWOW64\X3DAudio1_5.dll
2012-05-30 19:03:22 ----A---- C:\windows\system32\X3DAudio1_5.dll
2012-05-30 19:03:21 ----A---- C:\windows\SYSWOW64\XAudio2_2.dll
2012-05-30 19:03:21 ----A---- C:\windows\SYSWOW64\XAPOFX1_1.dll
2012-05-30 19:03:21 ----A---- C:\windows\system32\XAudio2_2.dll
2012-05-30 19:03:21 ----A---- C:\windows\system32\XAPOFX1_1.dll
2012-05-30 19:03:19 ----A---- C:\windows\SYSWOW64\xactengine3_2.dll
2012-05-30 19:03:19 ----A---- C:\windows\system32\xactengine3_2.dll
2012-05-30 19:03:17 ----A---- C:\windows\SYSWOW64\d3dx10_39.dll
2012-05-30 19:03:17 ----A---- C:\windows\SYSWOW64\D3DCompiler_39.dll
2012-05-30 19:03:17 ----A---- C:\windows\system32\d3dx10_39.dll
2012-05-30 19:03:17 ----A---- C:\windows\system32\D3DCompiler_39.dll
2012-05-30 19:03:16 ----A---- C:\windows\SYSWOW64\D3DX9_39.dll
2012-05-30 19:03:16 ----A---- C:\windows\system32\D3DX9_39.dll
2012-05-30 19:03:13 ----A---- C:\windows\SYSWOW64\XAudio2_1.dll
2012-05-30 19:03:13 ----A---- C:\windows\SYSWOW64\XAPOFX1_0.dll
2012-05-30 19:03:13 ----A---- C:\windows\system32\XAudio2_1.dll
2012-05-30 19:03:13 ----A---- C:\windows\system32\XAPOFX1_0.dll
2012-05-30 19:03:12 ----A---- C:\windows\SYSWOW64\xactengine3_1.dll
2012-05-30 19:03:12 ----A---- C:\windows\system32\xactengine3_1.dll
2012-05-30 19:03:11 ----A---- C:\windows\SYSWOW64\X3DAudio1_4.dll
2012-05-30 19:03:11 ----A---- C:\windows\system32\X3DAudio1_4.dll
2012-05-30 19:03:10 ----A---- C:\windows\SYSWOW64\d3dx10_38.dll
2012-05-30 19:03:10 ----A---- C:\windows\SYSWOW64\D3DCompiler_38.dll
2012-05-30 19:03:10 ----A---- C:\windows\system32\d3dx10_38.dll
2012-05-30 19:03:10 ----A---- C:\windows\system32\D3DCompiler_38.dll
2012-05-30 19:03:08 ----A---- C:\windows\SYSWOW64\D3DX9_38.dll
2012-05-30 19:03:08 ----A---- C:\windows\system32\D3DX9_38.dll
2012-05-30 19:03:07 ----A---- C:\windows\SYSWOW64\XAudio2_0.dll
2012-05-30 19:03:07 ----A---- C:\windows\system32\XAudio2_0.dll
2012-05-30 19:03:05 ----A---- C:\windows\SYSWOW64\xactengine3_0.dll
2012-05-30 19:03:05 ----A---- C:\windows\system32\xactengine3_0.dll
2012-05-30 19:03:04 ----A---- C:\windows\SYSWOW64\X3DAudio1_3.dll
2012-05-30 19:03:04 ----A---- C:\windows\system32\X3DAudio1_3.dll
2012-05-30 19:03:03 ----A---- C:\windows\SYSWOW64\d3dx10_37.dll
2012-05-30 19:03:03 ----A---- C:\windows\SYSWOW64\D3DCompiler_37.dll
2012-05-30 19:03:03 ----A---- C:\windows\system32\d3dx10_37.dll
2012-05-30 19:03:03 ----A---- C:\windows\system32\D3DCompiler_37.dll
2012-05-30 19:03:01 ----A---- C:\windows\SYSWOW64\D3DX9_37.dll
2012-05-30 19:03:01 ----A---- C:\windows\system32\D3DX9_37.dll
2012-05-30 19:02:59 ----A---- C:\windows\SYSWOW64\xactengine2_10.dll
2012-05-30 19:02:59 ----A---- C:\windows\system32\xactengine2_10.dll
2012-05-30 19:02:55 ----A---- C:\windows\SYSWOW64\d3dx10_36.dll
2012-05-30 19:02:55 ----A---- C:\windows\SYSWOW64\D3DCompiler_36.dll
2012-05-30 19:02:55 ----A---- C:\windows\system32\d3dx10_36.dll
2012-05-30 19:02:55 ----A---- C:\windows\system32\D3DCompiler_36.dll
2012-05-30 19:02:53 ----A---- C:\windows\SYSWOW64\d3dx9_36.dll
2012-05-30 19:02:53 ----A---- C:\windows\system32\d3dx9_36.dll
2012-05-30 19:02:51 ----A---- C:\windows\SYSWOW64\xactengine2_9.dll
2012-05-30 19:02:51 ----A---- C:\windows\system32\xactengine2_9.dll
2012-05-30 19:02:49 ----A---- C:\windows\SYSWOW64\d3dx10_35.dll
2012-05-30 19:02:49 ----A---- C:\windows\SYSWOW64\D3DCompiler_35.dll
2012-05-30 19:02:49 ----A---- C:\windows\system32\d3dx10_35.dll
2012-05-30 19:02:49 ----A---- C:\windows\system32\D3DCompiler_35.dll
2012-05-30 19:02:47 ----A---- C:\windows\system32\d3dx9_35.dll
2012-05-30 19:02:45 ----A---- C:\windows\SYSWOW64\xactengine2_8.dll
2012-05-30 19:02:45 ----A---- C:\windows\SYSWOW64\X3DAudio1_2.dll
2012-05-30 19:02:45 ----A---- C:\windows\system32\xactengine2_8.dll
2012-05-30 19:02:45 ----A---- C:\windows\system32\X3DAudio1_2.dll
2012-05-30 19:02:44 ----A---- C:\windows\SYSWOW64\d3dx10_34.dll
2012-05-30 19:02:44 ----A---- C:\windows\SYSWOW64\D3DCompiler_34.dll
2012-05-30 19:02:44 ----A---- C:\windows\system32\d3dx10_34.dll
2012-05-30 19:02:44 ----A---- C:\windows\system32\D3DCompiler_34.dll
2012-05-30 19:02:42 ----A---- C:\windows\SYSWOW64\d3dx9_34.dll
2012-05-30 19:02:42 ----A---- C:\windows\system32\d3dx9_34.dll
2012-05-30 19:02:41 ----A---- C:\windows\SYSWOW64\xinput1_3.dll
2012-05-30 19:02:41 ----A---- C:\windows\system32\xinput1_3.dll
2012-05-30 19:02:39 ----A---- C:\windows\SYSWOW64\xactengine2_7.dll
2012-05-30 19:02:39 ----A---- C:\windows\system32\xactengine2_7.dll
2012-05-30 19:02:38 ----A---- C:\windows\SYSWOW64\d3dx10_33.dll
2012-05-30 19:02:38 ----A---- C:\windows\SYSWOW64\D3DCompiler_33.dll
2012-05-30 19:02:38 ----A---- C:\windows\system32\d3dx10_33.dll
2012-05-30 19:02:38 ----A---- C:\windows\system32\D3DCompiler_33.dll
2012-05-30 19:02:36 ----A---- C:\windows\SYSWOW64\d3dx9_33.dll
2012-05-30 19:02:36 ----A---- C:\windows\system32\d3dx9_33.dll
2012-05-30 19:02:34 ----A---- C:\windows\SYSWOW64\xactengine2_6.dll
2012-05-30 19:02:34 ----A---- C:\windows\system32\xactengine2_6.dll
2012-05-30 19:02:33 ----A---- C:\windows\SYSWOW64\xactengine2_5.dll
2012-05-30 19:02:33 ----A---- C:\windows\system32\xactengine2_5.dll
2012-05-30 19:02:32 ----A---- C:\windows\SYSWOW64\d3dx10.dll
2012-05-30 19:02:32 ----A---- C:\windows\system32\d3dx10.dll
2012-05-30 19:02:27 ----A---- C:\windows\SYSWOW64\xactengine2_4.dll
2012-05-30 19:02:27 ----A---- C:\windows\SYSWOW64\x3daudio1_1.dll
2012-05-30 19:02:27 ----A---- C:\windows\system32\xactengine2_4.dll
2012-05-30 19:02:27 ----A---- C:\windows\system32\x3daudio1_1.dll
2012-05-30 19:02:24 ----A---- C:\windows\SYSWOW64\d3dx9_31.dll
2012-05-30 19:02:24 ----A---- C:\windows\system32\d3dx9_31.dll
2012-05-30 19:02:22 ----A---- C:\windows\SYSWOW64\xactengine2_3.dll
2012-05-30 19:02:22 ----A---- C:\windows\system32\xactengine2_3.dll
2012-05-30 19:02:21 ----A---- C:\windows\SYSWOW64\xinput1_2.dll
2012-05-30 19:02:21 ----A---- C:\windows\system32\xinput1_2.dll
2012-05-30 19:02:19 ----A---- C:\windows\SYSWOW64\xactengine2_2.dll
2012-05-30 19:02:19 ----A---- C:\windows\system32\xactengine2_2.dll
2012-05-30 19:02:18 ----A---- C:\windows\SYSWOW64\xinput1_1.dll
2012-05-30 19:02:18 ----A---- C:\windows\system32\xinput1_1.dll
2012-05-30 19:02:17 ----A---- C:\windows\SYSWOW64\xactengine2_1.dll
2012-05-30 19:02:17 ----A---- C:\windows\system32\xactengine2_1.dll
2012-05-30 19:02:01 ----A---- C:\windows\SYSWOW64\d3dx9_30.dll
2012-05-30 19:02:01 ----A---- C:\windows\system32\d3dx9_30.dll
2012-05-30 19:01:58 ----A---- C:\windows\SYSWOW64\xactengine2_0.dll
2012-05-30 19:01:58 ----A---- C:\windows\SYSWOW64\x3daudio1_0.dll
2012-05-30 19:01:58 ----A---- C:\windows\system32\xactengine2_0.dll
2012-05-30 19:01:58 ----A---- C:\windows\system32\x3daudio1_0.dll
2012-05-30 19:01:57 ----A---- C:\windows\SYSWOW64\d3dx9_29.dll
2012-05-30 19:01:57 ----A---- C:\windows\system32\d3dx9_29.dll
2012-05-30 19:01:55 ----A---- C:\windows\SYSWOW64\d3dx9_28.dll
2012-05-30 19:01:55 ----A---- C:\windows\system32\d3dx9_28.dll
2012-05-30 19:01:54 ----A---- C:\windows\SYSWOW64\d3dx9_27.dll
2012-05-30 19:01:54 ----A---- C:\windows\system32\d3dx9_27.dll
2012-05-30 19:01:53 ----A---- C:\windows\SYSWOW64\d3dx9_26.dll
2012-05-30 19:01:53 ----A---- C:\windows\system32\d3dx9_26.dll
2012-05-30 19:01:51 ----A---- C:\windows\SYSWOW64\d3dx9_25.dll
2012-05-30 19:01:51 ----A---- C:\windows\system32\d3dx9_25.dll
2012-05-30 19:01:50 ----A---- C:\windows\SYSWOW64\d3dx9_24.dll
2012-05-30 19:01:50 ----A---- C:\windows\system32\d3dx9_24.dll
2012-05-30 19:00:15 ----D---- C:\Users\Jitka\AppData\Roaming\Macromedia
2012-05-30 19:00:14 ----D---- C:\Users\Jitka\AppData\Roaming\Adobe
2012-05-30 18:58:01 ----A---- C:\windows\system32\rdrmemptylst.exe
2012-05-30 18:58:01 ----A---- C:\windows\system32\rdpwsx.dll
2012-05-30 18:58:01 ----A---- C:\windows\system32\rdpcorekmts.dll
2012-05-30 18:57:52 ----A---- C:\windows\SYSWOW64\rdpcore.dll
2012-05-30 18:57:52 ----A---- C:\windows\system32\rdpcore.dll
2012-05-30 18:57:52 ----A---- C:\windows\system32\drivers\tdtcp.sys
2012-05-30 18:57:52 ----A---- C:\windows\system32\drivers\rdpwd.sys
2012-05-30 18:42:10 ----D---- C:\Users\Jitka\AppData\Roaming\ATI
2012-05-30 18:41:10 ----D---- C:\Users\Jitka\AppData\Roaming\Identities
2012-05-30 18:41:01 ----SHD---- C:\$RECYCLE.BIN
2012-05-30 18:40:25 ----SD---- C:\Users\Jitka\AppData\Roaming\Microsoft
2012-05-30 18:40:25 ----D---- C:\Users\Jitka\AppData\Roaming\Media Center Programs
2012-05-30 18:38:23 ----SHD---- C:\Recovery

======List of files/folders modified in the last 1 month======

2012-06-11 17:05:42 ----D---- C:\windows\Temp
2012-06-11 17:05:40 ----RD---- C:\Program Files
2012-06-11 17:01:57 ----D---- C:\windows\system32\config
2012-06-11 16:53:24 ----D---- C:\windows\System32
2012-06-11 16:53:24 ----A---- C:\windows\system32\PerfStringBackup.INI
2012-06-11 16:53:23 ----D---- C:\windows\inf
2012-06-11 16:51:10 ----D---- C:\ProgramData\VeriFace
2012-06-11 15:44:38 ----D---- C:\Windows
2012-06-10 22:01:59 ----RD---- C:\Program Files (x86)
2012-06-10 22:01:32 ----SHD---- C:\windows\Installer
2012-06-10 22:01:30 ----D---- C:\Program Files (x86)\Internet Explorer
2012-06-10 22:01:21 ----D---- C:\windows\system32\Tasks
2012-06-10 21:59:58 ----D---- C:\windows\Panther
2012-06-10 21:59:58 ----D---- C:\windows\Logs
2012-06-10 21:59:57 ----D---- C:\windows\debug
2012-06-10 21:35:48 ----D---- C:\windows\system32\drivers
2012-06-10 21:35:16 ----HD---- C:\ProgramData
2012-06-10 13:07:36 ----RSD---- C:\windows\assembly
2012-06-10 13:07:36 ----D---- C:\windows\Microsoft.NET
2012-06-09 11:29:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-06-09 11:27:48 ----D---- C:\windows\system32\catroot2
2012-06-09 11:11:09 ----D---- C:\windows\system32\drivers\etc
2012-06-08 22:46:35 ----D---- C:\windows\system32\wdi
2012-06-08 11:17:39 ----D---- C:\Program Files (x86)\Common Files
2012-06-08 11:16:13 ----D---- C:\windows\SysWOW64
2012-06-07 10:10:25 ----D---- C:\windows\winsxs
2012-06-07 09:47:42 ----D---- C:\windows\system32\catroot
2012-06-07 09:34:05 ----D---- C:\windows\rescache
2012-06-07 00:44:49 ----D---- C:\Program Files\Windows Sidebar
2012-06-07 00:44:49 ----D---- C:\Program Files\Windows Mail
2012-06-07 00:44:48 ----D---- C:\Program Files\Windows Media Player
2012-06-07 00:44:48 ----D---- C:\Program Files\Windows Journal
2012-06-07 00:44:47 ----D---- C:\Program Files\Windows Photo Viewer
2012-06-07 00:44:47 ----D---- C:\Program Files\Windows Defender
2012-06-07 00:44:47 ----D---- C:\Program Files\Common Files\System
2012-06-07 00:44:47 ----D---- C:\Program Files (x86)\Windows Sidebar
2012-06-07 00:44:46 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2012-06-07 00:44:46 ----D---- C:\Program Files (x86)\Windows Media Player
2012-06-07 00:44:46 ----D---- C:\Program Files (x86)\Windows Mail
2012-06-07 00:44:45 ----D---- C:\windows\servicing
2012-06-07 00:44:45 ----D---- C:\Program Files (x86)\Windows Defender
2012-06-07 00:44:44 ----D---- C:\windows\SYSWOW64\winrm
2012-06-07 00:44:44 ----D---- C:\windows\SYSWOW64\slmgr
2012-06-07 00:44:44 ----D---- C:\windows\SYSWOW64\sk-SK
2012-06-07 00:44:44 ----D---- C:\windows\SYSWOW64\migwiz
2012-06-07 00:44:44 ----D---- C:\windows\SYSWOW64\en
2012-06-07 00:44:44 ----D---- C:\windows\ehome
2012-06-07 00:44:36 ----D---- C:\windows\SYSWOW64\en-US
2012-06-07 00:44:36 ----D---- C:\windows\SYSWOW64\drivers\en-US
2012-06-07 00:44:36 ----D---- C:\windows\SYSWOW64\drivers
2012-06-07 00:44:27 ----D---- C:\windows\SYSWOW64\WCN
2012-06-07 00:44:27 ----D---- C:\windows\SYSWOW64\Printing_Admin_Scripts
2012-06-07 00:44:27 ----D---- C:\windows\SYSWOW64\DriverStore
2012-06-07 00:44:27 ----D---- C:\windows\SYSWOW64\Dism
2012-06-07 00:44:25 ----D---- C:\windows\en-US
2012-06-07 00:44:24 ----D---- C:\windows\system32\winrm
2012-06-07 00:44:24 ----D---- C:\windows\system32\sysprep
2012-06-07 00:44:24 ----D---- C:\windows\system32\slmgr
2012-06-07 00:44:24 ----D---- C:\windows\system32\sk-SK
2012-06-07 00:44:24 ----D---- C:\windows\system32\oobe
2012-06-07 00:44:24 ----D---- C:\windows\system32\migwiz
2012-06-07 00:44:24 ----D---- C:\windows\system32\en
2012-06-07 00:44:24 ----D---- C:\windows\system32\Boot
2012-06-07 00:44:12 ----D---- C:\windows\system32\en-US
2012-06-07 00:43:54 ----D---- C:\windows\system32\drivers\en-US
2012-06-07 00:43:53 ----D---- C:\windows\system32\WCN
2012-06-07 00:43:53 ----D---- C:\windows\system32\DriverStore
2012-06-07 00:43:53 ----D---- C:\windows\system32\Dism
2012-06-07 00:43:46 ----D---- C:\windows\system32\Printing_Admin_Scripts
2012-06-07 00:43:18 ----D---- C:\Program Files\DVD Maker
2012-06-07 00:42:38 ----D---- C:\windows\Speech
2012-06-06 16:43:51 ----D---- C:\windows\Prefetch
2012-06-05 21:56:53 ----D---- C:\windows\system32\NDF
2012-06-04 20:16:39 ----SD---- C:\ProgramData\Microsoft
2012-06-04 20:14:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-06-04 20:14:37 ----D---- C:\Program Files (x86)\Microsoft Office
2012-06-04 11:26:06 ----D---- C:\windows\SYSWOW64\cs-CZ
2012-06-04 11:26:06 ----D---- C:\windows\system32\cs-CZ
2012-06-03 13:22:48 ----D---- C:\windows\SYSWOW64\migration
2012-06-03 13:22:48 ----D---- C:\Program Files\Internet Explorer
2012-06-03 13:22:46 ----D---- C:\windows\system32\migration
2012-06-02 10:44:22 ----RSD---- C:\windows\Fonts
2012-06-02 10:44:01 ----D---- C:\windows\AppPatch
2012-05-31 11:51:10 ----D---- C:\windows\system32\LogFiles
2012-05-31 11:25:18 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-05-30 21:45:07 ----D---- C:\windows\Tasks
2012-05-30 20:14:27 ----D---- C:\Program Files (x86)\Google
2012-05-30 19:41:14 ----D---- C:\ProgramData\McAfee
2012-05-30 18:58:45 ----D---- C:\windows\SoftwareDistribution
2012-05-30 18:49:20 ----D---- C:\windows\system32\restore
2012-05-30 18:40:44 ----D---- C:\Program Files (x86)\McAfee
2012-05-30 18:40:25 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2011-08-23 57952]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2011-08-23 39008]
R0 mfehidk;McAfee Inc. mfehidk; C:\windows\system32\drivers\mfehidk.sys [2012-02-22 647208]
R0 mfewfpk;McAfee Inc. mfewfpk; C:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 Shockprf;Shockprf; C:\windows\System32\DRIVERS\Apsx64.sys [2010-10-11 135776]
R0 TPDIGIMN;TPDIGIMN; C:\windows\System32\DRIVERS\ApsHM64.sys [2009-12-09 23648]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2011-08-23 13408]
R1 mfenlfk;McAfee NDIS Light Filter; C:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2011-08-23 29792]
R3 amdiox64;AMD IO Driver; C:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-06-08 9360896]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-06-08 309760]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 cfwids;McAfee Inc. cfwids; C:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2010-12-24 31088]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT64.sys [2010-12-08 1574016]
R3 mfeapfk;McAfee Inc. mfeapfk; C:\windows\system32\drivers\mfeapfk.sys [2012-02-22 160792]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\windows\system32\drivers\mfeavfk.sys [2012-02-22 229528]
R3 mfefirek;McAfee Inc. mfefirek; C:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2010-12-30 1177440]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2010-11-30 307304]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2010-10-26 406632]
R3 Sftfs;Sftfs; C:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
R3 Sftplay;Sftplay; C:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
R3 Sftredir;Sftredir; C:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
R3 Sftvol;Sftvol; C:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-10-21 1396784]
R3 usbfilter;AMD USB Filter Driver; C:\windows\system32\DRIVERS\usbfilter.sys [2010-11-29 44672]
R3 vm2uvcflt;Vimicro USB Camera Filter 2; C:\windows\System32\Drivers\vm2uvcflt.sys [2010-09-22 15056]
R3 vm332avs;Lenovo Camera2; C:\windows\System32\Drivers\vm332avs.sys [2010-11-19 234960]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2010-04-08 54824]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2010-01-15 98344]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2010-01-15 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2010-01-15 21288]
S3 mfeavfk01;McAfee Inc.; C:\windows\system32\drivers\mfeavfk01.sys []
S3 mferkdet;McAfee Inc. mferkdet; C:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-06-08 204288]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-06-08 365568]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2010-05-10 907040]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McMPFSvc;McAfee Personal Firewall Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 mcmscsvc;McAfee Services; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McNaiAnn;McAfee VirusScan Announcer; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McNASvc;McAfee Network Agent; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McProxy;McAfee Proxy Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McShield;McAfee McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [2012-03-20 199272]
R2 mfefire;McAfee Firewall Core Service; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584]
R2 mfevtp;McAfee Validation Trust Protection Service; C:\windows\system32\mfevtps.exe [2012-03-20 162192]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2011-12-21 578264]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2012-05-30 75136]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
R2 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\windows\System32\TPHDEXLG64.exe [2009-12-09 47712]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-10 257224]
S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service; C:\Program Files (x86)\BitComet\tools\BitCometService.exe [2010-12-28 1296728]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 136176]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-08-23 182768]
S3 McAWFwk;McAfee Activation Service; c:\PROGRA~1\mcafee\msc\mcawfwk.exe [2011-01-28 225216]
S3 McODS;McAfee Scanner; C:\Program Files\mcafee\VirusScan\mcods.exe [2012-04-19 502032]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Partner Service;Partner Service; C:\ProgramData\Partner\Partner.exe [2011-08-23 332272]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-06-02 1255736]
S4 McOobeSv;McAfee OOBE Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: DNSchanger - prosím o kontrolu logu

#36 Příspěvek od vyosek »

Zdravim :)

Jak jste tedy prisla na to ze mate DNS changera :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jituuus.ka
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 05 dub 2012 18:52

Re: DNSchanger - prosím o kontrolu logu

#37 Příspěvek od Jituuus.ka »

Na www.dns-ok.cz mi to píše napadeno a UPC mě na to taky pořád upozorňuje. Byl u mě i jeden odborník a vůbec nevěděl, co to znamná, protože to vypadá, že z počítačem nic neni. Takovýhle problémy prostě přitahuju :D

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: DNSchanger - prosím o kontrolu logu

#38 Příspěvek od vyosek »

MBAM jste delala na vsech PC v siti? Je v routeru nastaveny dobre DN server od udaju UPC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jituuus.ka
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 05 dub 2012 18:52

Re: DNSchanger - prosím o kontrolu logu

#39 Příspěvek od Jituuus.ka »

MBAM jsem udělala, nikde to nic nenašlo. Jeden počítač nic nehlásí, ale dva ano, takže netuším, čím to je. A když se snažím zpřístunit nastavení routeru, někdy se to ani nenačte a hodně časte se zasekne, takže nevím.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: DNSchanger - prosím o kontrolu logu

#40 Příspěvek od vyosek »

Tak na tech dvou co MBAM neco hlasi zrejme bude...dejte mi logy z MBAMu z nich...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jituuus.ka
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 05 dub 2012 18:52

Re: DNSchanger - prosím o kontrolu logu

#41 Příspěvek od Jituuus.ka »

Právě že MBAM nikde nic nehlásí. Nikde není žádná chyba ani vir k opravení, či odstranění. Jen stránka www.dns-ok.cz hlásí nákazu.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: DNSchanger - prosím o kontrolu logu

#42 Příspěvek od vyosek »

Tam bude ale pak chyba na strane UPC :?:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jituuus.ka
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 05 dub 2012 18:52

Re: DNSchanger - prosím o kontrolu logu

#43 Příspěvek od Jituuus.ka »

A nemáte nějaký nápad jak jim to mám vysvětlit? :D

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: DNSchanger - prosím o kontrolu logu

#44 Příspěvek od vyosek »

Jeste jeden pokus, dle kolegy :)
stell píše:daj spustit tento program
http://www.bleepingcomputer.com/downloa ... box/dl/65/

Spustit>.zafajknut.
1:Report IEPROXY
2:Report FFPROXY
3:List comtent OFF HOSTS
4:List IP CONFIGURATION
5:LIST WINSOCK...
6:List Last 10 EvENTS..
7:Only problems
8:Klik GO a log nech ti da do fora.
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Jituuus.ka
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 05 dub 2012 18:52

Re: DNSchanger - prosím o kontrolu logu

#45 Příspěvek od Jituuus.ka »

MiniToolBox by Farbar Version: 09-06-2012
Ran by Jitka (administrator) on 15-06-2012 at 11:44:08
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

========================= Hosts content: =================================



========================= IP Configuration: ================================

Ralink RT3090 802.11n WiFi Adapter = Bezdrátové připojení k síti (Connected)
Realtek PCIe FE Family Controller = Připojení k místní síti (Media disconnected)


# ----------------------------------
# Konfigurace protokolu IPv4
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# Konec konfigurace protokolu IPv4



Konfigurace protokolu IP syst‚mu Windows

N zev hostitele . . . . . . . . . : Tulkun
Prim rnˇ pýˇpona DNS. . . . . . . :
Typ uzlu . . . . . . . . . . . . : hybridnˇ
Povoleno smŘrov nˇ IP . . . . . . : Ne
WINS Proxy povoleno . . . . . . . : Ne

Adapt‚r sˇtŘ Ethernet Pýipojenˇ k mˇstnˇ sˇti:

Stav m‚dia . . . . . . . . . . . : odpojeno
Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Realtek PCIe FE Family Controller
Fyzick  Adresa. . . . . . . . . . : F0-DE-F1-83-19-71
Protokol DHCP povolen . . . . . . : Ano
Automatick  konfigurace povolena : Ano

Adapt‚r bezdr tov‚ sˇtŘ LAN Bezdr tov‚ pýipojenˇ k sˇti:

Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Ralink RT3090 802.11n WiFi Adapter
Fyzick  Adresa. . . . . . . . . . : 38-59-F9-94-56-F5
Protokol DHCP povolen . . . . . . : Ano
Automatick  konfigurace povolena : Ano
Mˇstnˇ IPv6 adresa v r mci propojenˇ . . . : fe80::b102:ed07:cb61:2cc9%11(Preferovan‚)
Adresa IPv4 . . . . . . . . . . . : 192.168.1.195(Preferovan‚)
Maska podsˇtŘ . . . . . . . . . . : 255.255.255.0
Zap…jźeno . . . . . . . . . . . . : 15. źervna 2012 10:35:02
Z p…jźka vyprçˇ . . . . . . . . . : 27. źervence 2012 2:37:35
Věchozˇ br na . . . . . . . . . . : 192.168.1.254
Server DHCP . . . . . . . . . . . : 192.168.1.254
IAID DHCPv6 . . . . . . . . . . : 188242425
DUID klienta DHCPv6. . . . . . . : 00-01-00-01-15-E4-AD-FB-38-59-F9-94-56-F5
Servery DNS . . . . . . . . . . . : 85.255.112.125
192.168.1.254
Rozhranˇ NetBios nad protokolem TCP/IP. . . . . . . . : Povoleno

Adapt‚r pro tunelov‚ pýipojenˇ isatap.{EE13F732-2AB9-4A3B-BDA8-7C32306060E1}:

Stav m‚dia . . . . . . . . . . . : odpojeno
Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Microsoft ISATAP Adapter
Fyzick  Adresa. . . . . . . . . . : 00-00-00-00-00-00-00-E0
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano

Adapt‚r pro tunelov‚ pýipojenˇ Pýipojenˇ k mˇstnˇ sˇti* 11:

Stav m‚dia . . . . . . . . . . . : odpojeno
Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Microsoft 6to4 Adapter
Fyzick  Adresa. . . . . . . . . . : 00-00-00-00-00-00-00-E0
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano

Adapt‚r pro tunelov‚ pýipojenˇ Teredo Tunneling Pseudo-Interface:

Stav m‚dia . . . . . . . . . . . : odpojeno
Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Fyzick  Adresa. . . . . . . . . . : 00-00-00-00-00-00-00-E0
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano
Server: UnKnown
Address: 85.255.112.125

Nazev: google.com
Addresses: 2001:4860:800a::64
74.125.134.102
74.125.134.100
74.125.134.139
74.125.134.101
74.125.134.113
74.125.134.138


Pýˇkaz PING na google.com [74.125.134.139] - 32 bajt… dat:
OdpovŘÔ od 74.125.134.139: bajty=32 źas=974ms TTL=40
OdpovŘÔ od 74.125.134.139: bajty=32 źas=117ms TTL=40

Statistika ping pro 74.125.134.139:
Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),
Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:
Minimum = 117ms, Maximum = 974ms, Pr…mŘr = 545ms
Server: UnKnown
Address: 85.255.112.125

Nazev: yahoo.com
Addresses: 98.139.183.24
72.30.38.140
209.191.122.70


Pýˇkaz PING na yahoo.com [209.191.122.70] - 32 bajt… dat:
OdpovŘÔ od 209.191.122.70: bajty=32 źas=341ms TTL=50
OdpovŘÔ od 209.191.122.70: bajty=32 źas=157ms TTL=50

Statistika ping pro 209.191.122.70:
Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),
Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:
Minimum = 157ms, Maximum = 341ms, Pr…mŘr = 249ms
Server: UnKnown
Address: 85.255.112.125

Nazev: bleepingcomputer.com
Address: 208.43.87.2


Pýˇkaz PING na bleepingcomputer.com [208.43.87.2] - 32 bajt… dat:
Vyprçel źasově limit § dosti.
Vyprçel źasově limit § dosti.

Statistika ping pro 208.43.87.2:
Pakety: Odeslan‚ = 2, Pýijat‚ = 0, Ztracen‚ = 2 (ztr ta 100%),

Pýˇkaz PING na 127.0.0.1 - 32 bajt… dat:
OdpovŘÔ od 127.0.0.1: bajty=32 źas < 1ms TTL=128
OdpovŘÔ od 127.0.0.1: bajty=32 źas < 1ms TTL=128

Statistika ping pro 127.0.0.1:
Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),
Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:
Minimum = 0ms, Maximum = 0ms, Pr…mŘr = 0ms
===========================================================================
Seznam rozhranˇ
14...f0 de f1 83 19 71 ......Realtek PCIe FE Family Controller
11...38 59 f9 94 56 f5 ......Ralink RT3090 802.11n WiFi Adapter
1...........................Software Loopback Interface 1
17...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
15...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
16...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 SmŘrovacˇ tabulka
===========================================================================
Aktivnˇ smŘrov nˇ:
Cˇl v sˇti Sˇśov  maska Br na Rozhranˇ Metrika
0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.195 25
127.0.0.0 255.0.0.0 Propojen‚ 127.0.0.1 306
127.0.0.1 255.255.255.255 Propojen‚ 127.0.0.1 306
127.255.255.255 255.255.255.255 Propojen‚ 127.0.0.1 306
192.168.1.0 255.255.255.0 Propojen‚ 192.168.1.195 281
192.168.1.195 255.255.255.255 Propojen‚ 192.168.1.195 281
192.168.1.255 255.255.255.255 Propojen‚ 192.168.1.195 281
224.0.0.0 240.0.0.0 Propojen‚ 127.0.0.1 306
224.0.0.0 240.0.0.0 Propojen‚ 192.168.1.195 281
255.255.255.255 255.255.255.255 Propojen‚ 127.0.0.1 306
255.255.255.255 255.255.255.255 Propojen‚ 192.168.1.195 281
===========================================================================
Trval‚ trasy:
¦ dn‚

IPv6 SmŘrovacˇ tabulka
===========================================================================
Aktivnˇ smŘrov nˇ:
Rozhranˇ Metrika Cˇl v sˇti Br na
1 306 ::1/128 Propojen‚
11 281 fe80::/64 Propojen‚
11 281 fe80::b102:ed07:cb61:2cc9/128
Propojen‚
1 306 ff00::/8 Propojen‚
11 281 ff00::/8 Propojen‚
===========================================================================
Trval‚ trasy:
¦ dn‚
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (06/15/2012 10:35:51 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/14/2012 11:44:01 PM) (Source: McLogEvent) (User: SYSTEM)SYSTEM
Description: A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe took longer than 90000 ms to complete a request.

The process will be terminated.
Thread id : 5308 (0x14bc)

Thread address : 0x000000007799135A

Thread message :

Build VSCORE.14.4.0.387 / 5400.1158
Object being scanned = \Device\HarddiskVolume2\Program Files (x86)\Lenovo\VeriFace\RICPlayerInterface.dll
by C:\Program Files (x86)\Lenovo\VeriFace\VerifyHost.exe
7011(29045811)(0)
93(29045811)(0)
5(29045811)(0)
4(0)(0)
4(0)(0)
7200(0)(0)
7595(0)(0)
7005(0)(0)

Error: (06/14/2012 02:05:48 PM) (Source: Application Hang) (User: )
Description: Program UbisoftGameLauncher.exe verze 0.0.0.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 1828

Čas spuštění: 01cd4a240b3e3537

Čas ukončení: 130

Cesta k aplikaci: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe

ID hlášení: 3c5b3ee0-b619-11e1-a602-f0def1831971

Error: (06/14/2012 01:12:52 PM) (Source: Application Error) (User: )
Description: Název chybující aplikace: explorer.exe, verze: 6.1.7601.17567, časové razítko: 0x4d6727a7
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x6c3a1488
ID chybujícího procesu: 0x79c
Čas spuštění chybující aplikace: 0xexplorer.exe0
Cesta k chybující aplikaci: explorer.exe1
Cesta k chybujícímu modulu: explorer.exe2
ID zprávy: explorer.exe3

Error: (06/14/2012 10:14:09 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/13/2012 10:15:12 PM) (Source: RapiMgr) (User: )
Description: Zařízení se systémem Windows Mobile se nepodařilo připojit z důvodu chyby communication (0x80072745) (viz data pro kód chyby).

Error: (06/13/2012 02:19:46 PM) (Source: Application Error) (User: )
Description: Název chybující aplikace: UbisoftGameLauncher.exe, verze: 0.0.0.0, časové razítko: 0x4fbb8837
Název chybujícího modulu: UbisoftGameLauncher.exe, verze: 0.0.0.0, časové razítko: 0x4fbb8837
Kód výjimky: 0xc0000005
Posun chyby: 0x002db182
ID chybujícího procesu: 0xd6c
Čas spuštění chybující aplikace: 0xUbisoftGameLauncher.exe0
Cesta k chybující aplikaci: UbisoftGameLauncher.exe1
Cesta k chybujícímu modulu: UbisoftGameLauncher.exe2
ID zprávy: UbisoftGameLauncher.exe3

Error: (06/13/2012 02:17:42 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/13/2012 02:11:57 PM) (Source: Application Error) (User: )
Description: Název chybující aplikace: UbisoftGameLauncher.exe, verze: 0.0.0.0, časové razítko: 0x4fbb8837
Název chybujícího modulu: UbisoftGameLauncher.exe, verze: 0.0.0.0, časové razítko: 0x4fbb8837
Kód výjimky: 0xc0000005
Posun chyby: 0x002db182
ID chybujícího procesu: 0x1cd4
Čas spuštění chybující aplikace: 0xUbisoftGameLauncher.exe0
Cesta k chybující aplikaci: UbisoftGameLauncher.exe1
Cesta k chybujícímu modulu: UbisoftGameLauncher.exe2
ID zprávy: UbisoftGameLauncher.exe3

Error: (06/13/2012 02:10:54 PM) (Source: Application Error) (User: )
Description: Název chybující aplikace: UbisoftGameLauncher.exe, verze: 0.0.0.0, časové razítko: 0x4fbb8837
Název chybujícího modulu: UbisoftGameLauncher.exe, verze: 0.0.0.0, časové razítko: 0x4fbb8837
Kód výjimky: 0xc0000005
Posun chyby: 0x002db182
ID chybujícího procesu: 0x1a18
Čas spuštění chybující aplikace: 0xUbisoftGameLauncher.exe0
Cesta k chybující aplikaci: UbisoftGameLauncher.exe1
Cesta k chybujícímu modulu: UbisoftGameLauncher.exe2
ID zprávy: UbisoftGameLauncher.exe3


System errors:
=============
Error: (06/15/2012 01:26:21 AM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (06/14/2012 11:44:23 PM) (Source: Service Control Manager) (User: )
Description: Služba McAfee McShield byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 5000 milisekund: Restartovat službu.

Error: (06/14/2012 11:43:59 PM) (Source: Service Control Manager) (User: )
Description: Při čekání na odezvu transakce služby Wlansvc bylo dosaženo časového limitu (30000 ms).

Error: (06/13/2012 11:10:59 PM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (06/13/2012 09:49:31 PM) (Source: Service Control Manager) (User: )
Description: Při čekání na odezvu transakce služby AMD External Events Utility bylo dosaženo časového limitu (30000 ms).

Error: (06/13/2012 02:14:23 PM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (06/12/2012 11:42:51 PM) (Source: DCOM) (User: )
Description: {ABC01078-F197-4B0B-ADBC-CFE684B39C82}

Error: (06/12/2012 11:42:45 PM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (06/11/2012 08:16:40 PM) (Source: Service Control Manager) (User: )
Description: Při čekání na odezvu transakce služby ShellHWDetection bylo dosaženo časového limitu (30000 ms).

Error: (06/10/2012 11:14:25 PM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}


Microsoft Office Sessions:
=========================
Error: (06/15/2012 10:35:51 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/14/2012 11:44:01 PM) (Source: McLogEvent)(User: SYSTEM)SYSTEM
Description: C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe900005308 (0x14bc)0x000000007799135A
Build VSCORE.14.4.0.387 / 5400.1158
Object being scanned = \Device\HarddiskVolume2\Program Files (x86)\Lenovo\VeriFace\RICPlayerInterface.dll
by C:\Program Files (x86)\Lenovo\VeriFace\VerifyHost.exe
7011(29045811)(0)
93(29045811)(0)
5(29045811)(0)
4(0)(0)
4(0)(0)
7200(0)(0)
7595(0)(0)
7005(0)(0)

Error: (06/14/2012 02:05:48 PM) (Source: Application Hang)(User: )
Description: UbisoftGameLauncher.exe0.0.0.0182801cd4a240b3e3537130C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe3c5b3ee0-b619-11e1-a602-f0def1831971

Error: (06/14/2012 01:12:52 PM) (Source: Application Error)(User: )
Description: explorer.exe6.1.7601.175674d6727a7unknown0.0.0.000000000c00000056c3a148879c01cd4a1ea2ec660cC:\windows\SysWOW64\explorer.exeunknowne1ac706d-b611-11e1-a602-f0def1831971

Error: (06/14/2012 10:14:09 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/13/2012 10:15:12 PM) (Source: RapiMgr)(User: )
Description: communication (0x80072745)

Error: (06/13/2012 02:19:46 PM) (Source: Application Error)(User: )
Description: UbisoftGameLauncher.exe0.0.0.04fbb8837UbisoftGameLauncher.exe0.0.0.04fbb8837c0000005002db182d6c01cd495ec70c4296C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exeC:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe0f837912-b552-11e1-9263-f0def1831971

Error: (06/13/2012 02:17:42 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/13/2012 02:11:57 PM) (Source: Application Error)(User: )
Description: UbisoftGameLauncher.exe0.0.0.04fbb8837UbisoftGameLauncher.exe0.0.0.04fbb8837c0000005002db1821cd401cd495dba174d9fC:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exeC:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exef8401eda-b550-11e1-a392-f0def1831971

Error: (06/13/2012 02:10:54 PM) (Source: Application Error)(User: )
Description: UbisoftGameLauncher.exe0.0.0.04fbb8837UbisoftGameLauncher.exe0.0.0.04fbb8837c0000005002db1821a1801cd495d94983681C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exeC:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exed2b9dbb1-b550-11e1-a392-f0def1831971


**** End of log ****

Odpovědět