Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivna kontrola

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zpráva
Autor
IVIarkI2I
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 38
Registrován: 20 črc 2008 15:56

Preventivna kontrola

#1 Příspěvek od IVIarkI2I »

Poprosim o preventivnu kontrolu.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:03:26, on 18. 4. 2012
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
S:\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\ProgramData\Firefly Studios\Stronghold Kingdoms\1.21.1.66\StrongholdKingdoms.exe
C:\Users\DELL\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [ACSW14EN] "C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe" /pid ACSW14EN
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Connectify] C:\Program Files (x86)\Connectify\Connectify.exe
O4 - HKCU\..\Run: [Steam] "S:\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Google Update] "C:\Users\DELL\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Connectify - Unknown owner - C:\Program Files (x86)\Connectify\ConnectifyService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit (mi-raysat_3dsmax2012_64) - Unknown owner - S:\Program Files\Autodesk 3ds Max 2012\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Mobile Broadband Service (WMCoreService) - Ericsson AB - C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11735 bytes

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivna kontrola

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Jakozto vzorny navstevnik byste mel daaaavno vedet ze uz pouzivame RSIT a davat log z nej...I toto ocekavame od lidi s vn - ze znaji pravidla a chovani na nasem foru

:arrow: Takze prosim o RSIT
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

IVIarkI2I
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 38
Registrován: 20 črc 2008 15:56

Re: Preventivna kontrola

#3 Příspěvek od IVIarkI2I »

ospravedlňujem sa niaky ten rok som tu nebol :D

Logfile of random's system information tool 1.09 (written by random/random)
Run by DELL at 2012-04-18 18:55:57
Microsoft Windows 7 Home Premium
System drive C: has 140 GB (68%) free of 205 GB
Total RAM: 6038 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:56:00, on 18. 4. 2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
S:\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\ProgramData\Firefly Studios\Stronghold Kingdoms\1.21.1.66\StrongholdKingdoms.exe
C:\Program Files\trend micro\DELL.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [ACSW14EN] "C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe" /pid ACSW14EN
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Connectify] C:\Program Files (x86)\Connectify\Connectify.exe
O4 - HKCU\..\Run: [Steam] "S:\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Google Update] "C:\Users\DELL\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2602030269-2964672339-2095405884-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-2602030269-2964672339-2095405884-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Connectify - Unknown owner - C:\Program Files (x86)\Connectify\ConnectifyService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit (mi-raysat_3dsmax2012_64) - Unknown owner - S:\Program Files\Autodesk 3ds Max 2012\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Mobile Broadband Service (WMCoreService) - Ericsson AB - C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12418 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d7488339-6f9c-4c13-a068-480c34492ddf -SystemEventPortName:HostProcess-4b1f23d9-4edb-44e1-a733-40e911f7b39b -IoCancelEventPortName:HostProcess-963c956b-132d-49a9-b297-f985d017ae4a -NonStateChangingEventPortName:HostProcess-8df05bf8-50f8-427b-a744-83a1af5c0e73 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a8cae16e-f5c7-4eaf-a9d8-38a3b38fe13f
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\WLANExt.exe 4842224
\??\C:\Windows\system32\conhost.exe "-314413103684007947-13959770329986994191527625604240077135-1611717988859431843
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
"C:\Program Files (x86)\Connectify\ConnectifyService.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"ConnectifyD.exe"
\??\C:\Windows\system32\conhost.exe "-1328574409-492230693-1367866503-2080153450799782876-1480203562-7980407501801398534
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"S:\Program Files\Autodesk 3ds Max 2012\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe" servicemode
WLIDSvcM.exe 2512
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Dell\QuickSet\quickset.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX3
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
"C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"S:\Steam\Steam.exe" -silent
"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe" /pid ACSW14EN
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe" -Embedding
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1832.b978d50.998866507 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll" E7CF176E110C211B -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" 1832 "\\.\pipe\gecko-crash-server-pipe.1832" plugin
"C:\Windows\system32\wuauclt.exe"
"C:\ProgramData\Firefly Studios\Stronghold Kingdoms\1.21.1.66\StrongholdKingdoms.exe" "-InstallerVersion" "117" "en"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 540 544 552 65536 548
"C:\Users\DELL\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2602030269-2964672339-2095405884-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2602030269-2964672339-2095405884-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\DELL\AppData\Roaming\Mozilla\Firefox\Profiles\hrp7bhu7.default

prefs.js - "browser.startup.homepage" - "chrome://speeddial/content/speeddial.xul"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.233 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.233 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_233.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 6721936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-03-02 4296864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickSet"=C:\Program Files\Dell\QuickSet\QuickSet.exe [2011-01-25 4479648]
"IntelTBRunOnce"=wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-03-30 167960]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-03-30 391704]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-03-30 418840]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2011-02-18 6611048]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2011-01-18 2188904]
"IntelPAN"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2011-07-27 1935120]
"FreeFallProtection"=C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [2010-12-17 686704]
"NVHotkey"=C:\Windows\system32\nvHotkey.dll [2011-11-04 540992]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 4035152]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-02-29 17148552]
"Connectify"=C:\Program Files (x86)\Connectify\Connectify.exe [2012-02-25 3941192]
"Steam"=S:\Steam\Steam.exe [2012-04-05 1242448]
"Google Update"=C:\Users\DELL\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-05 116648]
"msnmsgr"=C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [2010-09-23 4240760]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"ACSW14EN"=C:\Program Files (x86)\ACD Systems\ACDSee\14.0\ACDSeeInTouch2.exe [2011-09-20 1231472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-03-26 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 6721936]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.ACDV"=ACDV.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

IVIarkI2I
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 38
Registrován: 20 črc 2008 15:56

Re: Preventivna kontrola

#4 Příspěvek od IVIarkI2I »

======List of files/folders created in the last 1 month======

2012-04-18 18:55:57 ----D---- C:\Program Files\trend micro
2012-04-18 18:55:56 ----D---- C:\rsit
2012-04-16 22:42:24 ----D---- C:\Windows\Minidump
2012-04-15 02:41:10 ----D---- C:\Python26
2012-04-15 02:12:51 ----A---- C:\Windows\SYSWOW64\nvRegDev.dll
2012-04-15 02:12:18 ----A---- C:\Windows\SYSWOW64\nvPhotoshopUtil.dll
2012-04-15 02:12:18 ----A---- C:\Windows\SYSWOW64\nvISWOW64.dll
2012-04-14 12:10:07 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2012-04-13 03:02:04 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-04-13 03:02:04 ----A---- C:\Windows\system32\mshtmled.dll
2012-04-13 03:02:03 ----A---- C:\Windows\SYSWOW64\url.dll
2012-04-13 03:02:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-04-13 03:02:03 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-04-13 03:02:03 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-04-13 03:02:03 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-04-13 03:02:03 ----A---- C:\Windows\system32\url.dll
2012-04-13 03:02:03 ----A---- C:\Windows\system32\jscript9.dll
2012-04-13 03:02:03 ----A---- C:\Windows\system32\ieui.dll
2012-04-13 03:02:03 ----A---- C:\Windows\system32\iertutil.dll
2012-04-13 03:02:02 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-04-13 03:02:02 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-04-13 03:02:02 ----A---- C:\Windows\system32\urlmon.dll
2012-04-13 03:02:02 ----A---- C:\Windows\system32\jsproxy.dll
2012-04-13 03:02:02 ----A---- C:\Windows\system32\jscript.dll
2012-04-13 03:02:01 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-04-13 03:02:01 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-04-13 03:02:01 ----A---- C:\Windows\system32\wininet.dll
2012-04-13 03:02:00 ----A---- C:\Windows\system32\mshtml.dll
2012-04-13 03:01:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-04-13 03:01:58 ----A---- C:\Windows\system32\ieframe.dll
2012-04-13 03:01:47 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-04-13 03:01:46 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-04-13 03:01:45 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-04-13 03:01:02 ----A---- C:\Windows\SYSWOW64\wmi.dll
2012-04-13 03:01:02 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2012-04-13 03:01:02 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2012-04-13 03:01:02 ----A---- C:\Windows\system32\wmi.dll
2012-04-13 03:01:02 ----A---- C:\Windows\system32\wintrust.dll
2012-04-13 03:01:02 ----A---- C:\Windows\system32\imagehlp.dll
2012-04-13 03:01:02 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-04-12 22:48:52 ----D---- C:\Users\DELL\AppData\Roaming\Need for Speed World
2012-04-12 22:39:48 ----D---- C:\ProgramData\Electronic Arts
2012-04-07 02:59:48 ----D---- C:\Program Files (x86)\uTorrent
2012-04-07 02:58:57 ----D---- C:\Users\DELL\AppData\Roaming\uTorrent
2012-04-06 22:25:01 ----D---- C:\Windows\SYSWOW64\URTTEMP
2012-04-06 15:52:45 ----D---- C:\Users\DELL\AppData\Roaming\ACD Systems
2012-04-06 15:51:40 ----D---- C:\ProgramData\ACD Systems
2012-04-06 15:51:31 ----D---- C:\Program Files (x86)\ACD Systems
2012-04-06 15:44:10 ----D---- C:\Program Files\Autodesk
2012-04-06 15:44:04 ----D---- C:\Program Files\Common Files\Macrovision Shared
2012-04-06 15:42:51 ----D---- C:\Program Files\Common Files\Autodesk Shared
2012-04-06 15:42:36 ----D---- C:\Program Files (x86)\Autodesk
2012-04-06 15:41:27 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-04-06 15:41:27 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-04-06 15:41:27 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-04-06 15:41:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-04-06 15:41:27 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-04-06 15:41:27 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-04-06 15:41:27 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-04-06 15:41:27 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-04-06 15:41:26 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-04-06 15:41:26 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-04-06 15:41:26 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-04-06 15:41:26 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-04-06 15:41:26 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-04-06 15:41:26 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-04-06 15:41:26 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-04-06 15:41:26 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-04-06 15:41:26 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-04-06 15:41:26 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-04-06 15:41:26 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-04-06 15:41:26 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-04-06 15:41:26 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-04-06 15:41:26 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-04-06 15:41:25 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-04-06 15:41:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-04-06 15:41:25 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-04-06 15:41:25 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-04-06 15:41:23 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-04-06 15:41:23 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-04-06 15:41:22 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-04-06 15:41:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-04-06 15:41:22 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-04-06 15:41:22 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-04-06 15:41:22 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-04-06 15:41:22 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-04-06 15:41:22 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-04-06 15:41:21 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-04-06 15:41:21 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-04-06 15:41:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-04-06 15:41:20 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-04-06 15:41:19 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-04-06 15:41:19 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-04-06 15:39:57 ----D---- C:\Users\DELL\AppData\Roaming\NVIDIA
2012-04-06 15:39:56 ----D---- C:\Users\DELL\AppData\Roaming\MilkShape 3D 1.x.x
2012-04-06 15:39:00 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2012-04-06 15:30:49 ----D---- C:\Users\DELL\AppData\Roaming\Autodesk
2012-04-06 15:30:49 ----D---- C:\ProgramData\Autodesk
2012-04-06 15:27:53 ----D---- C:\Autodesk
2012-04-06 15:18:19 ----D---- C:\Users\DELL\AppData\Roaming\GHISLER
2012-04-06 15:18:19 ----D---- C:\totalcmd
2012-04-06 15:18:19 ----A---- C:\Windows\UC.PIF
2012-04-06 15:18:19 ----A---- C:\Windows\RAR.PIF
2012-04-06 15:18:19 ----A---- C:\Windows\PKZIP.PIF
2012-04-06 15:18:19 ----A---- C:\Windows\PKUNZIP.PIF
2012-04-06 15:18:19 ----A---- C:\Windows\NOCLOSE.PIF
2012-04-06 15:18:19 ----A---- C:\Windows\LHA.PIF
2012-04-06 15:18:19 ----A---- C:\Windows\ARJ.PIF
2012-04-06 15:12:20 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-04-06 15:09:06 ----D---- C:\Program Files\Common Files\Adobe
2012-04-06 15:08:47 ----D---- C:\Users\DELL\AppData\Roaming\Notepad++
2012-04-06 15:08:21 ----D---- C:\Program Files (x86)\Adobe Media Player
2012-04-06 11:57:51 ----D---- C:\Program Files (x86)\Windows Live
2012-04-06 11:57:09 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-04-06 03:46:17 ----SHD---- C:\ProgramData\SecuROM
2012-04-06 03:45:31 ----RHD---- C:\Users\DELL\AppData\Roaming\SecuROM
2012-04-06 03:45:30 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2012-04-06 03:45:23 ----D---- C:\Windows\SYSWOW64\xlive
2012-04-06 03:45:23 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2012-04-06 03:43:49 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-04-06 03:43:48 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-04-06 03:43:48 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-04-06 03:43:46 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-04-06 03:43:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-04-06 03:43:46 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-04-06 03:43:46 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-04-06 03:43:46 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-04-06 03:43:46 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-04-06 03:43:46 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-04-06 03:43:46 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-04-06 03:43:45 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-04-06 03:43:45 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-04-06 03:43:45 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-04-06 03:43:45 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-04-06 03:43:45 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-04-06 03:43:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-04-06 03:43:45 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-04-06 03:43:45 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-04-06 03:43:45 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-04-06 03:43:45 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-04-06 03:43:45 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-04-06 03:43:45 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-04-06 03:43:44 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-04-06 03:43:44 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-04-06 03:43:44 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-04-06 03:43:44 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-04-06 03:43:44 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-04-06 03:43:44 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-04-06 03:43:44 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-04-06 03:43:44 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-04-06 03:43:44 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-04-06 03:43:44 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-04-06 03:43:44 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-04-06 03:43:44 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-04-06 03:43:43 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-04-06 03:43:43 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-04-06 03:43:43 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-04-06 03:43:43 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-04-06 03:43:43 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-04-06 03:43:43 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-04-06 03:43:43 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-04-06 03:43:43 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-04-06 03:43:42 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-04-06 03:43:42 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-04-06 03:43:42 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-04-06 03:43:42 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-04-06 03:43:42 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-04-06 03:43:42 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-04-06 03:43:42 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-04-06 03:43:42 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-04-06 03:43:42 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-04-06 03:43:42 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-04-06 03:43:42 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-04-06 03:43:42 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-04-06 03:43:41 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-04-06 03:43:41 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2012-04-06 03:43:41 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-04-06 03:43:41 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-04-06 03:43:41 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-04-06 03:43:41 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-04-06 03:43:41 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-04-06 03:43:41 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-04-06 03:43:40 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-04-06 03:43:40 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-04-06 03:43:40 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-04-06 03:43:40 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-04-06 03:43:40 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-04-06 03:43:40 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-04-06 03:43:40 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-04-06 03:43:40 ----A---- C:\Windows\system32\d3dx10.dll
2012-04-06 03:43:39 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-04-06 03:43:39 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2012-04-06 03:43:39 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-04-06 03:43:39 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-04-06 03:43:39 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-04-06 03:43:39 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-04-06 03:43:39 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-04-06 03:43:39 ----A---- C:\Windows\system32\xinput1_2.dll
2012-04-06 03:43:39 ----A---- C:\Windows\system32\xinput1_1.dll
2012-04-06 03:43:39 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-04-06 03:43:39 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-04-06 03:43:39 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-04-06 03:43:39 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-04-06 03:43:39 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-04-06 03:43:38 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2012-04-06 03:43:38 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-04-06 03:43:36 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-04-06 03:43:36 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2012-04-06 03:43:36 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2012-04-06 03:43:36 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-04-06 03:43:36 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-04-06 03:43:36 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-04-06 03:43:36 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-04-06 03:43:36 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-04-06 03:43:36 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-04-06 03:43:36 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-04-06 03:43:35 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-04-06 03:43:35 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-04-06 03:43:35 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2012-04-06 03:43:35 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-04-06 03:43:35 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-04-06 03:43:35 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-04-06 03:43:34 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-04-06 03:43:34 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-04-05 22:16:19 ----A---- C:\Windows\OutLog.txt
2012-04-05 21:46:39 ----A---- C:\Windows\BcdLog.txt
2012-04-05 21:44:53 ----A---- C:\Windows\SYSWOW64\setupempdrv03.exe
2012-04-05 21:44:53 ----A---- C:\Windows\SYSWOW64\EuGdiDrv.sys
2012-04-05 21:44:53 ----A---- C:\Windows\SYSWOW64\EuEpmGdi.dll
2012-04-05 21:44:53 ----A---- C:\Windows\SYSWOW64\BootMan.exe
2012-04-05 21:44:53 ----A---- C:\Windows\system32\setupempdrvx64.exe
2012-04-05 21:44:53 ----A---- C:\Windows\system32\EuGdiDrv.sys
2012-04-05 21:44:53 ----A---- C:\Windows\system32\EuEpmGdi.dll
2012-04-05 21:44:53 ----A---- C:\Windows\system32\epmntdrv.sys
2012-04-05 21:44:53 ----A---- C:\Windows\system32\BootMan.exe
2012-04-05 21:44:52 ----A---- C:\Windows\SYSWOW64\epmntdrv.sys
2012-04-05 21:44:37 ----D---- C:\Program Files (x86)\EASEUS
2012-04-05 21:30:08 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2012-04-05 21:30:08 ----A---- C:\Windows\system32\drivers\usbport.sys
2012-04-05 21:30:08 ----A---- C:\Windows\system32\drivers\usbohci.sys
2012-04-05 21:30:08 ----A---- C:\Windows\system32\drivers\usbhub.sys
2012-04-05 21:30:08 ----A---- C:\Windows\system32\drivers\usbehci.sys
2012-04-05 21:30:08 ----A---- C:\Windows\system32\drivers\usbd.sys
2012-04-05 21:30:08 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2012-04-05 21:30:07 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2012-04-05 21:30:07 ----A---- C:\Windows\system32\drivers\bthport.sys
2012-04-05 21:30:01 ----A---- C:\Windows\system32\esent.dll
2012-04-05 21:30:01 ----A---- C:\Windows\system32\drivers\nvstor.sys
2012-04-05 21:30:01 ----A---- C:\Windows\system32\drivers\nvraid.sys
2012-04-05 21:30:01 ----A---- C:\Windows\system32\drivers\ntfs.sys
2012-04-05 21:30:01 ----A---- C:\Windows\system32\drivers\amdsata.sys
2012-04-05 21:30:00 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2012-04-05 21:30:00 ----A---- C:\Windows\SYSWOW64\esent.dll
2012-04-05 21:30:00 ----A---- C:\Windows\system32\fsutil.exe
2012-04-05 21:30:00 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2012-04-05 21:30:00 ----A---- C:\Windows\system32\drivers\storport.sys
2012-04-05 21:30:00 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2012-04-05 21:30:00 ----A---- C:\Windows\system32\drivers\amdxata.sys
2012-04-05 13:56:13 ----D---- C:\Windows\SYSWOW64\Wat
2012-04-05 13:56:13 ----D---- C:\Windows\system32\Wat
2012-04-05 01:49:13 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2012-04-05 01:49:13 ----A---- C:\Windows\system32\wcncsvc.dll
2012-04-05 01:37:21 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2012-04-05 01:37:21 ----A---- C:\Windows\system32\msv1_0.dll
2012-04-05 01:24:02 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2012-04-05 01:24:02 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2012-04-05 01:24:02 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2012-04-05 01:24:02 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2012-04-05 01:24:02 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2012-04-05 01:24:02 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-04-05 01:24:02 ----A---- C:\Windows\system32\PresentationHost.exe
2012-04-05 01:24:02 ----A---- C:\Windows\system32\netfxperf.dll
2012-04-05 01:24:02 ----A---- C:\Windows\system32\mscoree.dll
2012-04-05 01:24:02 ----A---- C:\Windows\system32\dfshim.dll
2012-04-05 01:23:28 ----A---- C:\Windows\system32\browserchoice.exe
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\msrating.dll
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\msls31.dll
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2012-04-05 01:20:48 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\wextract.exe
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\occache.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\mshta.exe
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\inseng.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\icardie.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2012-04-05 01:20:47 ----A---- C:\Windows\SYSWOW64\admparse.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\wextract.exe
2012-04-05 01:20:46 ----A---- C:\Windows\system32\webcheck.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\vbscript.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2012-04-05 01:20:46 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2012-04-05 01:20:46 ----A---- C:\Windows\system32\pngfilt.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\occache.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\msrating.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\msls31.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\mshtmler.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\mshta.exe
2012-04-05 01:20:46 ----A---- C:\Windows\system32\msfeedssync.exe
2012-04-05 01:20:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\msfeeds.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\licmgr10.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\inseng.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\imgutil.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\iexpress.exe
2012-04-05 01:20:46 ----A---- C:\Windows\system32\ieUnatt.exe
2012-04-05 01:20:46 ----A---- C:\Windows\system32\iesysprep.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\iesetup.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\iernonce.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\iepeers.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\iedkcs32.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\ieapfltr.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\ieapfltr.dat
2012-04-05 01:20:46 ----A---- C:\Windows\system32\ieakui.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\ieaksie.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\ieakeng.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\IEAdvpack.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\ie4uinit.exe
2012-04-05 01:20:46 ----A---- C:\Windows\system32\icardie.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\dxtrans.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\dxtmsft.dll
2012-04-05 01:20:46 ----A---- C:\Windows\system32\admparse.dll
2012-04-05 01:09:05 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2012-04-05 01:09:05 ----A---- C:\Windows\system32\drivers\ks.sys
2012-04-05 00:00:30 ----D---- C:\Users\DELL\AppData\Roaming\WinRAR
2012-04-05 00:00:29 ----D---- C:\Program Files\WinRAR
2012-04-04 22:58:21 ----A---- C:\Windows\system32\drivers\cnnctfy2.sys
2012-04-04 22:58:12 ----D---- C:\Program Files (x86)\Connectify
2012-04-04 22:58:11 ----D---- C:\ProgramData\Connectify
2012-04-04 15:20:52 ----D---- C:\Program Files (x86)\Adobe
2012-04-04 15:20:37 ----D---- C:\ProgramData\Adobe
2012-04-04 15:11:16 ----D---- C:\Users\DELL\AppData\Roaming\Firefly Studios
2012-04-04 15:09:46 ----D---- C:\ProgramData\Firefly Studios
2012-04-04 14:35:42 ----D---- C:\Users\DELL\AppData\Roaming\vlc
2012-04-04 14:33:11 ----D---- C:\Program Files\VideoLAN
2012-04-04 14:32:02 ----D---- C:\Users\DELL\AppData\Roaming\ESET
2012-04-04 14:31:16 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-04-04 14:31:16 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-04-04 14:31:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-04-04 14:31:16 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-04-04 14:31:16 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-04-04 14:31:16 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-04-04 14:31:15 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-04-04 14:31:15 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-04-04 14:31:15 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-04-04 14:31:15 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-04-04 14:31:14 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-04-04 14:31:14 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-04-04 14:31:14 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-04-04 14:31:14 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-04-04 14:31:13 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-04-04 14:31:13 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-04-04 14:31:11 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2012-04-04 14:31:11 ----A---- C:\Windows\system32\xinput1_3.dll
2012-04-04 14:30:43 ----D---- C:\Program Files (x86)\Firefly Studios
2012-04-04 14:29:15 ----D---- C:\ProgramData\ESET
2012-04-04 14:29:15 ----D---- C:\Program Files\ESET
2012-04-04 14:25:24 ----A---- C:\Windows\AutoKMS.ini
2012-04-04 14:25:24 ----A---- C:\Windows\AutoKMS.exe
2012-04-04 14:21:35 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2012-04-04 14:21:24 ----D---- C:\Windows\PCHEALTH
2012-04-04 14:21:24 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-04-04 14:21:24 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2012-04-04 14:21:24 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-04-04 14:19:56 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2012-04-04 14:19:29 ----D---- C:\Program Files\Microsoft Office
2012-04-04 14:18:56 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2012-04-04 14:18:30 ----D---- C:\Program Files (x86)\Microsoft Office
2012-04-04 14:18:29 ----D---- C:\ProgramData\Microsoft Help
2012-04-04 14:18:17 ----RHD---- C:\MSOCache
2012-04-04 14:13:47 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2012-04-04 14:13:47 ----A---- C:\Windows\system32\xmllite.dll
2012-04-04 14:13:46 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2012-04-04 14:13:46 ----A---- C:\Windows\system32\kerberos.dll
2012-04-04 14:13:32 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2012-04-04 14:13:32 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2012-04-04 14:13:32 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2012-04-04 14:13:32 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2012-04-04 14:13:32 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2012-04-04 14:13:32 ----A---- C:\Windows\system32\odbctrac.dll
2012-04-04 14:13:32 ----A---- C:\Windows\system32\odbccu32.dll
2012-04-04 14:13:32 ----A---- C:\Windows\system32\odbccr32.dll
2012-04-04 14:13:32 ----A---- C:\Windows\system32\odbccp32.dll
2012-04-04 14:13:31 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2012-04-04 14:13:31 ----A---- C:\Windows\system32\drivers\dfsc.sys
2012-04-04 14:13:31 ----A---- C:\Windows\system32\asycfilt.dll
2012-04-04 14:13:27 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2012-04-04 14:13:27 ----A---- C:\Windows\system32\poqexec.exe
2012-04-04 14:13:25 ----A---- C:\Windows\SYSWOW64\explorer.exe
2012-04-04 14:13:25 ----A---- C:\Windows\explorer.exe
2012-04-04 14:13:22 ----A---- C:\Windows\system32\CPFilters.dll
2012-04-04 14:13:21 ----A---- C:\Windows\SYSWOW64\sbe.dll
2012-04-04 14:13:21 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2012-04-04 14:13:21 ----A---- C:\Windows\system32\sbe.dll
2012-04-04 14:13:20 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2012-04-04 14:13:20 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-04-04 14:13:20 ----A---- C:\Windows\system32\t2embed.dll
2012-04-04 14:13:20 ----A---- C:\Windows\system32\quartz.dll
2012-04-04 14:13:19 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-04-04 14:13:19 ----A---- C:\Windows\system32\qdvd.dll
2012-04-04 14:13:18 ----A---- C:\Windows\system32\shell32.dll
2012-04-04 14:13:17 ----A---- C:\Windows\SYSWOW64\shell32.dll
2012-04-04 14:13:17 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2012-04-04 14:13:17 ----A---- C:\Windows\system32\ntshrui.dll
2012-04-04 14:13:15 ----A---- C:\Windows\system32\ole32.dll
2012-04-04 14:13:14 ----A---- C:\Windows\SYSWOW64\ole32.dll
2012-04-04 14:13:14 ----A---- C:\Windows\system32\schedsvc.dll
2012-04-04 14:13:13 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2012-04-04 14:13:13 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2012-04-04 14:13:13 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2012-04-04 14:13:13 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2012-04-04 14:13:13 ----A---- C:\Windows\system32\wmicmiplugin.dll
2012-04-04 14:13:13 ----A---- C:\Windows\system32\taskschd.dll
2012-04-04 14:13:13 ----A---- C:\Windows\system32\taskeng.exe
2012-04-04 14:13:13 ----A---- C:\Windows\system32\taskcomp.dll
2012-04-04 14:13:13 ----A---- C:\Windows\system32\schtasks.exe
2012-04-04 14:13:12 ----A---- C:\Windows\system32\mssrch.dll
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\tquery.dll
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\mssph.dll
2012-04-04 14:13:11 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2012-04-04 14:13:11 ----A---- C:\Windows\system32\tquery.dll
2012-04-04 14:13:11 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2012-04-04 14:13:11 ----A---- C:\Windows\system32\SearchIndexer.exe
2012-04-04 14:13:11 ----A---- C:\Windows\system32\SearchFilterHost.exe
2012-04-04 14:13:11 ----A---- C:\Windows\system32\mssvp.dll
2012-04-04 14:13:11 ----A---- C:\Windows\system32\mssphtb.dll
2012-04-04 14:13:11 ----A---- C:\Windows\system32\mssph.dll
2012-04-04 14:13:11 ----A---- C:\Windows\system32\msscntrs.dll
2012-04-04 14:13:09 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2012-04-04 14:13:09 ----A---- C:\Windows\system32\StructuredQuery.dll
2012-04-04 14:13:08 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2012-04-04 14:13:08 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2012-04-04 14:13:08 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2012-04-04 14:13:07 ----A---- C:\Windows\SYSWOW64\webio.dll
2012-04-04 14:13:07 ----A---- C:\Windows\SYSWOW64\schannel.dll
2012-04-04 14:13:07 ----A---- C:\Windows\system32\webio.dll
2012-04-04 14:13:07 ----A---- C:\Windows\system32\schannel.dll
2012-04-04 14:13:07 ----A---- C:\Windows\system32\lsasrv.dll
2012-04-04 14:13:07 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-04-04 14:13:07 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-04-04 14:13:07 ----A---- C:\Windows\system32\drivers\cng.sys
2012-04-04 14:13:06 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2012-04-04 14:13:06 ----A---- C:\Windows\SYSWOW64\secur32.dll
2012-04-04 14:13:06 ----A---- C:\Windows\system32\sspisrv.dll
2012-04-04 14:13:06 ----A---- C:\Windows\system32\sspicli.dll
2012-04-04 14:13:06 ----A---- C:\Windows\system32\secur32.dll
2012-04-04 14:13:06 ----A---- C:\Windows\system32\lsass.exe
2012-04-04 14:13:04 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2012-04-04 14:13:04 ----A---- C:\Windows\system32\CertEnroll.dll
2012-04-04 14:12:58 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2012-04-04 14:12:58 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2012-04-04 14:12:58 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2012-04-04 14:12:58 ----A---- C:\Windows\SYSWOW64\secproc.dll
2012-04-04 14:12:58 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2012-04-04 14:12:58 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2012-04-04 14:12:58 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2012-04-04 14:12:58 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2012-04-04 14:12:58 ----A---- C:\Windows\system32\secproc_ssp.dll
2012-04-04 14:12:58 ----A---- C:\Windows\system32\secproc_isv.dll
2012-04-04 14:12:58 ----A---- C:\Windows\system32\secproc.dll
2012-04-04 14:12:58 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2012-04-04 14:12:58 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2012-04-04 14:12:58 ----A---- C:\Windows\system32\RMActivate_isv.exe
2012-04-04 14:12:58 ----A---- C:\Windows\system32\RMActivate.exe
2012-04-04 14:12:57 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2012-04-04 14:12:55 ----A---- C:\Windows\system32\win32k.sys
2012-04-04 14:12:49 ----A---- C:\Windows\system32\msdri.dll
2012-04-04 14:12:44 ----A---- C:\Windows\system32\csrsrv.dll
2012-04-04 14:12:41 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2012-04-04 14:12:41 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2012-04-04 14:12:40 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2012-04-04 14:12:40 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2012-04-04 14:12:40 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2012-04-04 14:12:40 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2012-04-04 14:12:40 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2012-04-04 14:12:40 ----A---- C:\Windows\system32\DWrite.dll
2012-04-04 14:12:40 ----A---- C:\Windows\system32\d3d10warp.dll
2012-04-04 14:12:40 ----A---- C:\Windows\system32\d3d10_1core.dll
2012-04-04 14:12:40 ----A---- C:\Windows\system32\d3d10_1.dll
2012-04-04 14:12:40 ----A---- C:\Windows\system32\d2d1.dll
2012-04-04 14:12:36 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-04-04 14:12:33 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2012-04-04 14:12:33 ----A---- C:\Windows\system32\comctl32.dll
2012-04-04 14:12:30 ----A---- C:\Windows\SYSWOW64\upnp.dll
2012-04-04 14:12:30 ----A---- C:\Windows\system32\upnp.dll
2012-04-04 14:12:30 ----A---- C:\Windows\system32\msxml6.dll
2012-04-04 14:12:30 ----A---- C:\Windows\system32\msxml3.dll
2012-04-04 14:12:29 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2012-04-04 14:12:29 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2012-04-04 14:12:29 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2012-04-04 14:12:29 ----A---- C:\Windows\SYSWOW64\slwga.dll
2012-04-04 14:12:29 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2012-04-04 14:12:29 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2012-04-04 14:12:29 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2012-04-04 14:12:29 ----A---- C:\Windows\system32\wscapi.dll
2012-04-04 14:12:29 ----A---- C:\Windows\system32\winhttp.dll
2012-04-04 14:12:29 ----A---- C:\Windows\system32\WebClnt.dll
2012-04-04 14:12:29 ----A---- C:\Windows\system32\slwga.dll
2012-04-04 14:12:29 ----A---- C:\Windows\system32\davclnt.dll
2012-04-04 14:12:28 ----A---- C:\Windows\system32\wscsvc.dll
2012-04-04 14:12:26 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2012-04-04 14:12:26 ----A---- C:\Windows\system32\XpsPrint.dll
2012-04-04 14:12:25 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2012-04-04 14:12:25 ----A---- C:\Windows\system32\winlogon.exe
2012-04-04 14:12:25 ----A---- C:\Windows\system32\mfc42u.dll
2012-04-04 14:12:25 ----A---- C:\Windows\system32\mfc42.dll
2012-04-04 14:12:24 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2012-04-04 14:12:24 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2012-04-04 14:12:24 ----A---- C:\Windows\system32\rtutils.dll
2012-04-04 14:12:15 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2012-04-04 14:12:15 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-04-04 14:12:15 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-04-04 14:12:15 ----A---- C:\Windows\system32\spoolsv.exe
2012-04-04 14:12:15 ----A---- C:\Windows\system32\fontsub.dll
2012-04-04 14:12:15 ----A---- C:\Windows\system32\atmlib.dll
2012-04-04 14:12:15 ----A---- C:\Windows\system32\atmfd.dll
2012-04-04 14:12:13 ----A---- C:\Windows\SYSWOW64\mf.dll
2012-04-04 14:12:13 ----A---- C:\Windows\system32\WMVDECOD.DLL
2012-04-04 14:12:13 ----A---- C:\Windows\system32\mf.dll
2012-04-04 14:12:13 ----A---- C:\Windows\system32\FntCache.dll
2012-04-04 14:12:12 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2012-04-04 14:12:12 ----A---- C:\Windows\system32\ExplorerFrame.dll
2012-04-04 14:12:12 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2012-04-04 14:12:11 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2012-04-04 14:12:11 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2012-04-04 14:12:11 ----A---- C:\Windows\system32\mfreadwrite.dll
2012-04-04 14:12:11 ----A---- C:\Windows\system32\cdd.dll
2012-04-04 14:12:10 ----A---- C:\Windows\system32\XpsRasterService.dll
2012-04-04 14:12:10 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2012-04-04 14:12:09 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2012-04-04 14:12:09 ----A---- C:\Windows\system32\mfps.dll
2012-04-04 14:12:06 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2012-04-04 14:12:06 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2012-04-04 14:12:05 ----A---- C:\Windows\system32\drivers\fvevol.sys
2012-04-04 14:11:52 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2012-04-04 14:11:52 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2012-04-04 14:11:52 ----A---- C:\Windows\system32\dnsrslvr.dll
2012-04-04 14:11:52 ----A---- C:\Windows\system32\dnscacheugc.exe
2012-04-04 14:11:52 ----A---- C:\Windows\system32\dnsapi.dll
2012-04-04 14:11:51 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2012-04-04 14:11:51 ----A---- C:\Windows\system32\wmpmde.dll
2012-04-04 14:11:50 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2012-04-04 14:11:50 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2012-04-04 14:11:50 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2012-04-04 14:11:50 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2012-04-04 14:11:50 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2012-04-04 14:11:50 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2012-04-04 14:11:50 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2012-04-04 14:11:50 ----A---- C:\Windows\system32\tsbyuv.dll
2012-04-04 14:11:50 ----A---- C:\Windows\system32\msyuv.dll
2012-04-04 14:11:50 ----A---- C:\Windows\system32\msvidc32.dll
2012-04-04 14:11:50 ----A---- C:\Windows\system32\msrle32.dll
2012-04-04 14:11:50 ----A---- C:\Windows\system32\iyuv_32.dll
2012-04-04 14:11:49 ----A---- C:\Windows\system32\drivers\srvnet.sys
2012-04-04 14:11:49 ----A---- C:\Windows\system32\drivers\srv2.sys
2012-04-04 14:11:49 ----A---- C:\Windows\system32\drivers\srv.sys
2012-04-04 14:11:46 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2012-04-04 14:11:46 ----A---- C:\Windows\system32\psisdecd.dll
2012-04-04 14:11:42 ----A---- C:\Windows\system32\drivers\afd.sys
2012-04-04 14:11:30 ----A---- C:\Windows\system32\winresume.exe
2012-04-04 14:11:30 ----A---- C:\Windows\system32\winload.exe
2012-04-04 14:11:30 ----A---- C:\Windows\system32\kdusb.dll
2012-04-04 14:11:30 ----A---- C:\Windows\system32\kdcom.dll
2012-04-04 14:11:30 ----A---- C:\Windows\system32\kd1394.dll
2012-04-04 14:11:29 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2012-04-04 14:11:29 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2012-04-04 14:11:28 ----A---- C:\Windows\SYSWOW64\msasn1.dll
2012-04-04 14:11:28 ----A---- C:\Windows\system32\msasn1.dll
2012-04-04 14:11:27 ----A---- C:\Windows\system32\wow64win.dll
2012-04-04 14:11:27 ----A---- C:\Windows\system32\winsrv.dll
2012-04-04 14:11:27 ----A---- C:\Windows\system32\KernelBase.dll
2012-04-04 14:11:27 ----A---- C:\Windows\system32\kernel32.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-04-04 14:11:26 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-04-04 14:11:26 ----A---- C:\Windows\SYSWOW64\wow32.dll
2012-04-04 14:11:26 ----A---- C:\Windows\SYSWOW64\user.exe
2012-04-04 14:11:26 ----A---- C:\Windows\SYSWOW64\setup16.exe
2012-04-04 14:11:26 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2012-04-04 14:11:26 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2012-04-04 14:11:26 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2012-04-04 14:11:26 ----A---- C:\Windows\SYSWOW64\instnm.exe
2012-04-04 14:11:26 ----A---- C:\Windows\system32\wow64cpu.dll
2012-04-04 14:11:26 ----A---- C:\Windows\system32\wow64.dll
2012-04-04 14:11:26 ----A---- C:\Windows\system32\ntvdm64.dll
2012-04-04 14:11:26 ----A---- C:\Windows\system32\conhost.exe
2012-04-04 14:11:25 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2012-04-04 14:11:25 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2012-04-04 14:11:25 ----A---- C:\Windows\system32\mstscax.dll
2012-04-04 14:11:25 ----A---- C:\Windows\system32\mstsc.exe
2012-04-04 14:11:24 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2012-04-04 14:11:24 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2012-04-04 14:11:24 ----A---- C:\Windows\SYSWOW64\devobj.dll
2012-04-04 14:11:24 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2012-04-04 14:11:24 ----A---- C:\Windows\system32\umpnpmgr.dll
2012-04-04 14:11:17 ----A---- C:\Windows\system32\wmp.dll
2012-04-04 14:11:16 ----A---- C:\Windows\SYSWOW64\wmp.dll
2012-04-04 14:11:15 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2012-04-04 14:11:15 ----A---- C:\Windows\system32\wmploc.DLL
2012-04-04 14:11:13 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2012-04-04 14:11:13 ----A---- C:\Windows\system32\prevhost.exe
2012-04-04 14:11:13 ----A---- C:\Windows\system32\FXSCOVER.exe
2012-04-04 14:11:12 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2012-04-04 14:11:12 ----A---- C:\Windows\system32\inetcomm.dll
2012-04-04 14:11:11 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2012-04-04 14:11:11 ----A---- C:\Windows\system32\msvcrt.dll
2012-04-04 14:11:11 ----A---- C:\Windows\system32\consent.exe
2012-04-04 14:11:09 ----A---- C:\Windows\system32\oleaut32.dll
2012-04-04 14:11:09 ----A---- C:\Windows\system32\oleacc.dll
2012-04-04 14:11:09 ----A---- C:\Windows\system32\drivers\bowser.sys
2012-04-04 14:11:08 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2012-04-04 14:11:08 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2012-04-04 14:11:08 ----A---- C:\Windows\system32\EncDec.dll
2012-04-04 14:11:07 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2012-04-04 14:11:04 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-04-04 14:11:04 ----A---- C:\Windows\system32\tzres.dll
2012-04-04 14:11:01 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2012-04-04 14:11:01 ----A---- C:\Windows\system32\odbc32.dll
2012-04-04 14:11:00 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-04-04 14:11:00 ----A---- C:\Windows\system32\ntdll.dll
2012-04-04 14:10:59 ----A---- C:\Windows\SYSWOW64\sscore.dll
2012-04-04 14:10:59 ----A---- C:\Windows\system32\srvsvc.dll
2012-04-04 14:10:56 ----D---- C:\Users\DELL\AppData\Roaming\Macromedia
2012-04-04 14:10:55 ----D---- C:\Users\DELL\AppData\Roaming\Adobe
2012-04-04 14:10:43 ----D---- C:\Windows\SYSWOW64\Macromed
2012-04-04 14:10:43 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-04-04 14:10:42 ----D---- C:\Windows\system32\Macromed
2012-04-04 14:08:34 ----D---- C:\Users\DELL\AppData\Roaming\Skype
2012-04-04 14:08:28 ----RD---- C:\Program Files (x86)\Skype
2012-04-04 14:08:22 ----D---- C:\ProgramData\Skype
2012-04-04 14:03:56 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-04-04 14:03:56 ----A---- C:\Windows\system32\packager.dll
2012-04-04 14:03:11 ----N---- C:\Windows\system32\MpSigStub.exe
2012-04-04 14:01:33 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-04-04 14:01:33 ----A---- C:\Windows\system32\rdpwsx.dll
2012-04-04 14:01:33 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-04-04 14:01:24 ----A---- C:\Windows\SYSWOW64\cabview.dll
2012-04-04 14:01:24 ----A---- C:\Windows\system32\cabview.dll
2012-04-04 14:00:04 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2012-04-04 14:00:04 ----A---- C:\Windows\system32\rdpcore.dll
2012-04-04 14:00:03 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2012-04-04 14:00:03 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-04-04 13:59:45 ----D---- C:\Users\DELL\AppData\Roaming\Mozilla
2012-04-04 13:59:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-04-03 08:59:46 ----D---- C:\Windows\SYSWOW64\NV
2012-04-03 08:59:46 ----D---- C:\Windows\system32\NV
2012-04-03 08:58:19 ----A---- C:\Windows\system32\drivers\Mbm3whnt.sys
2012-04-03 08:58:19 ----A---- C:\Windows\system32\drivers\Mbm3wh.sys
2012-04-03 08:58:18 ----A---- C:\Windows\system32\drivers\wwussf64.sys
2012-04-03 08:58:18 ----A---- C:\Windows\system32\drivers\wwuss64.sys
2012-04-03 08:58:18 ----A---- C:\Windows\system32\drivers\Mbm3CBus.sys
2012-04-03 08:58:14 ----A---- C:\Windows\system32\drivers\WwanUsbMp64.sys
2012-04-03 08:58:12 ----A---- C:\Windows\system32\drivers\Mbm3DevMt.sys
2012-04-03 08:58:12 ----A---- C:\Windows\system32\drivers\Mbm3cmnt.sys
2012-04-03 08:58:12 ----A---- C:\Windows\system32\drivers\Mbm3cm.sys
2012-04-03 08:58:10 ----A---- C:\Windows\system32\drivers\Mbm3Mdm.sys
2012-04-03 08:58:10 ----A---- C:\Windows\system32\drivers\Mbm3mdfl.sys
2012-04-03 08:58:10 ----A---- C:\Windows\system32\drivers\d554gps64.sys
2012-04-03 08:58:09 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll
2012-04-03 08:58:09 ----A---- C:\Windows\system32\drivers\d554scard.sys
2012-04-03 08:58:08 ----D---- C:\Program Files (x86)\Dell
2012-04-03 08:56:26 ----D---- C:\ProgramData\NVIDIA
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nvvsvc.exe
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nvsvcr.dll
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nvsvc64.dll
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nvshext.dll
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nvmctray.dll
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nvhotkey.dll
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nvcpl.dll
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nv3dappshextr.dll
2012-04-03 08:56:18 ----A---- C:\Windows\system32\nv3dappshext.dll
2012-04-03 08:56:18 ----A---- C:\Windows\system32\easyupdatusapiu64.dll
2012-04-03 08:56:11 ----D---- C:\ProgramData\NVIDIA Corporation
2012-04-03 08:56:09 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvoptimusmft.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvdecodemft.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-04-03 08:55:50 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\OpenCL.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvumdshimx.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvoptimusmft.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvoglv64.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvinitx.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvgenco64.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvdispco64.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvdecodemft.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvcuvid.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvcuda.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvcompiler.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\nvapi64.dll
2012-04-03 08:55:50 ----A---- C:\Windows\system32\drivers\nvpciflt.sys
2012-04-03 08:55:50 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-04-03 08:55:50 ----A---- C:\Windows\system32\drivers\nvkflt.sys
2012-04-03 08:55:43 ----D---- C:\Program Files\NVIDIA Corporation
2012-04-03 08:45:38 ----DC---- C:\Windows\system32\DRVSTORE
2012-04-03 08:45:38 ----A---- C:\Windows\system32\drivers\stdcfltn.sys
2012-04-03 08:45:15 ----D---- C:\Program Files\STMicroelectronics
2012-04-03 08:44:55 ----D---- C:\Program Files (x86)\STMicroelectronics
2012-04-03 08:44:55 ----A---- C:\Windows\system32\drivers\Accelern.sys
2012-04-03 08:44:55 ----A---- C:\Windows\system32\accelernco01.dll
2012-04-03 08:41:38 ----D---- C:\Users\DELL\AppData\Roaming\Intel
2012-04-03 08:41:29 ----D---- C:\ProgramData\Roaming
2012-04-03 08:40:31 ----D---- C:\ProgramData\Intel
2012-04-03 08:40:31 ----D---- C:\Program Files (x86)\Cisco
2012-04-03 08:36:11 ----A---- C:\Windows\system32\drivers\RTWAVES30.dat
2012-04-03 08:36:10 ----D---- C:\Windows\system32\SRSLabs
2012-04-03 08:36:09 ----D---- C:\Windows\SYSWOW64\RTCOM
2012-04-03 08:36:09 ----D---- C:\Program Files\Realtek
2012-04-03 08:35:44 ----A---- C:\Windows\SYSWOW64\MBAPO32.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\WavesGUILib.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\SRSWOW64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\SRSTSX64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\SRSTSH64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\SRSHP64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RtPgEx64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RtkGuiCompLib.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RtkCfg64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RtkAPO64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RtkApi64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RTEEP64A.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RTEEL64A.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RTEEG64A.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RTEED64A.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RTCOM64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RP3DHT64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RP3DAA64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RCORES64.dat
2012-04-03 08:35:44 ----A---- C:\Windows\system32\RCoInst64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MBWrp64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MBppld64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MBPPCn64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MBAPO64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MaxxAudioRealtek2.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\FMAPO64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2012-04-03 08:35:44 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\AERTAR64.dll
2012-04-03 08:35:43 ----A---- C:\Windows\system32\AERTAC64.dll
2012-04-03 08:35:40 ----HD---- C:\Program Files (x86)\Temp
2012-04-03 08:35:40 ----A---- C:\Windows\RtlExUpd.dll
2012-04-03 08:34:59 ----D---- C:\Program Files\Common Files\Intel
2012-04-03 08:34:25 ----A---- C:\Windows\system32\igfxtray.exe
2012-04-03 08:34:25 ----A---- C:\Windows\system32\igfxsrvc.exe
2012-04-03 08:34:25 ----A---- C:\Windows\system32\igfxpers.exe
2012-04-03 08:34:25 ----A---- C:\Windows\system32\igfxext.exe
2012-04-03 08:34:25 ----A---- C:\Windows\system32\hkcmd.exe
2012-04-03 08:34:25 ----A---- C:\Windows\system32\GfxUI.exe
2012-04-03 08:34:25 ----A---- C:\Windows\system32\difx64.exe
2012-04-03 08:34:23 ----A---- C:\Windows\system32\IntcDAuC.dll
2012-04-03 08:34:23 ----A---- C:\Windows\system32\drivers\IntcDAud.sys
2012-04-03 08:34:21 ----A---- C:\Windows\SYSWOW64\iglhsip32.dll
2012-04-03 08:34:21 ----A---- C:\Windows\SYSWOW64\iglhcp32.dll
2012-04-03 08:34:21 ----A---- C:\Windows\system32\iglhsip64.dll
2012-04-03 08:34:21 ----A---- C:\Windows\system32\iglhcp64.dll
2012-04-03 08:34:21 ----A---- C:\Windows\system32\igfxTMM.dll
2012-04-03 08:34:21 ----A---- C:\Windows\system32\igfxsrvc.dll
2012-04-03 08:34:21 ----A---- C:\Windows\system32\igfxCoIn_v2342.dll
2012-04-03 08:34:20 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll
2012-04-03 08:34:20 ----A---- C:\Windows\SYSWOW64\igfxdv32.dll
2012-04-03 08:34:20 ----A---- C:\Windows\SYSWOW64\igfxcmrt32.dll
2012-04-03 08:34:20 ----A---- C:\Windows\SYSWOW64\igdumdx32.dll
2012-04-03 08:34:20 ----A---- C:\Windows\SYSWOW64\igdumd32.dll
2012-04-03 08:34:20 ----A---- C:\Windows\system32\igfxress.dll
2012-04-03 08:34:20 ----A---- C:\Windows\system32\igfxpph.dll
2012-04-03 08:34:20 ----A---- C:\Windows\system32\igfxexps.dll
2012-04-03 08:34:20 ----A---- C:\Windows\system32\igfxdo.dll
2012-04-03 08:34:20 ----A---- C:\Windows\system32\IGFXDEVLib.dll
2012-04-03 08:34:20 ----A---- C:\Windows\system32\igfxdev.dll
2012-04-03 08:34:20 ----A---- C:\Windows\system32\igfxcmrt64.dll
2012-04-03 08:34:20 ----A---- C:\Windows\system32\igdumd64.dll
2012-04-03 08:34:19 ----A---- C:\Windows\SYSWOW64\igd10umd32.dll
2012-04-03 08:34:19 ----A---- C:\Windows\SYSWOW64\ig4icd32.dll
2012-04-03 08:34:19 ----A---- C:\Windows\system32\igd10umd64.dll
2012-04-03 08:34:19 ----A---- C:\Windows\system32\ig4icd64.dll
2012-04-03 08:34:19 ----A---- C:\Windows\system32\IccLibDll_x64.dll
2012-04-03 08:34:19 ----A---- C:\Windows\system32\hccutils.dll
2012-04-03 08:34:19 ----A---- C:\Windows\system32\gfxSrvc.dll
2012-04-03 08:34:19 ----A---- C:\Windows\system32\drivers\igdkmd64.sys
2012-04-03 08:34:01 ----D---- C:\Program Files\Intel
2012-04-03 08:32:51 ----D---- C:\Program Files (x86)\Renesas Electronics
2012-04-03 08:32:15 ----A---- C:\Windows\system32\drivers\IntelMEFWVer.dll
2012-04-03 08:32:13 ----A---- C:\Windows\SYSWOW64\log.txt
2012-04-03 08:32:04 ----A---- C:\Windows\system32\drivers\HECIx64.sys
2012-04-03 08:32:03 ----D---- C:\Users\DELL\AppData\Roaming\InstallShield
2012-04-03 08:31:21 ----D---- C:\ProgramData\Dell
2012-04-03 08:31:19 ----D---- C:\Program Files\Dell
2012-04-03 08:31:02 ----SHD---- C:\Windows\Installer
2012-04-03 08:30:15 ----A---- C:\Windows\system32\RTNUninst64.dll
2012-04-03 08:30:15 ----A---- C:\Windows\system32\RtNicProp64.dll
2012-04-03 08:30:15 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2012-04-03 08:29:54 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-04-03 08:29:54 ----D---- C:\Program Files (x86)\Realtek
2012-04-03 08:28:04 ----D---- C:\Program Files (x86)\Intel
2012-04-03 08:28:04 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2012-04-03 08:27:59 ----D---- C:\Intel
2012-04-03 08:27:36 ----D---- C:\Program Files (x86)\JMicron
2012-04-03 08:27:34 ----D---- C:\Windows\SYSWOW64\SDA
2012-04-03 08:27:32 ----D---- C:\dell
2012-04-03 01:07:49 ----D---- C:\Windows\Panther
2012-04-03 01:07:23 ----RA---- C:\Windows\csup.txt
2012-04-03 01:07:23 ----D---- C:\Windows\system32\oem
2012-04-03 01:06:46 ----D---- C:\Windows\SYSWOW64\drivers\sk-SK
2012-04-03 01:06:46 ----D---- C:\Windows\system32\drivers\sk-SK
2012-04-03 01:06:46 ----D---- C:\Windows\sk-SK
2012-04-02 15:17:29 ----D---- C:\Users\DELL\AppData\Roaming\Identities
2012-04-02 15:17:10 ----SD---- C:\Users\DELL\AppData\Roaming\Microsoft
2012-04-02 15:17:10 ----D---- C:\Users\DELL\AppData\Roaming\Media Center Programs
2012-04-02 15:17:02 ----SHD---- C:\Recovery
2012-04-02 15:16:53 ----D---- C:\Windows\SoftwareDistribution
2012-04-02 15:08:46 ----D---- C:\Windows\Prefetch
2012-04-02 15:08:09 ----ASH---- C:\pagefile.sys
2012-04-02 15:08:07 ----SHD---- C:\System Volume Information
2012-04-02 15:08:07 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 month======

2012-04-18 18:55:57 ----RD---- C:\Program Files
2012-04-18 18:55:52 ----D---- C:\Windows\Temp
2012-04-18 17:47:14 ----D---- C:\Windows\system32\config
2012-04-18 17:39:44 ----D---- C:\Windows\System32
2012-04-18 17:39:44 ----D---- C:\Windows\inf
2012-04-18 17:39:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-18 17:35:44 ----D---- C:\Windows
2012-04-16 01:05:56 ----D---- C:\Windows\winsxs
2012-04-16 01:05:18 ----D---- C:\Windows\system32\catroot2
2012-04-16 01:05:18 ----D---- C:\Windows\system32\catroot
2012-04-16 00:57:43 ----D---- C:\Windows\rescache
2012-04-16 00:52:25 ----D---- C:\Program Files\Windows Sidebar
2012-04-16 00:52:25 ----D---- C:\Program Files\Windows Photo Viewer
2012-04-16 00:52:25 ----D---- C:\Program Files\Windows Mail
2012-04-16 00:52:25 ----D---- C:\Program Files\Windows Journal
2012-04-16 00:52:25 ----D---- C:\Program Files\DVD Maker
2012-04-16 00:52:25 ----D---- C:\Program Files (x86)\Windows Sidebar
2012-04-16 00:52:25 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2012-04-16 00:52:25 ----D---- C:\Program Files (x86)\Windows Mail
2012-04-16 00:52:24 ----D---- C:\Windows\SYSWOW64\migwiz
2012-04-16 00:52:24 ----D---- C:\Windows\SYSWOW64\en-US
2012-04-16 00:52:24 ----D---- C:\Windows\SYSWOW64\drivers\en-US
2012-04-16 00:52:23 ----D---- C:\Windows\en-US
2012-04-16 00:52:22 ----D---- C:\Windows\system32\migwiz
2012-04-16 00:52:22 ----D---- C:\Windows\system32\en-US
2012-04-16 00:52:22 ----D---- C:\Windows\system32\drivers\en-US
2012-04-15 17:41:31 ----D---- C:\Windows\system32\WCN
2012-04-15 17:41:29 ----D---- C:\Windows\Speech
2012-04-15 17:40:18 ----D---- C:\Windows\Logs
2012-04-15 02:36:09 ----D---- C:\Windows\SysWOW64
2012-04-13 18:36:31 ----RSD---- C:\Windows\assembly
2012-04-13 18:36:31 ----D---- C:\Windows\Microsoft.NET
2012-04-13 18:18:01 ----D---- C:\Windows\SYSWOW64\migration
2012-04-13 18:18:01 ----D---- C:\Program Files\Internet Explorer
2012-04-13 18:18:01 ----D---- C:\Program Files (x86)\Internet Explorer
2012-04-13 18:18:00 ----D---- C:\Windows\system32\migration
2012-04-13 18:17:58 ----D---- C:\Windows\system32\drivers
2012-04-13 03:02:50 ----A---- C:\Windows\win.ini
2012-04-12 22:39:48 ----HD---- C:\ProgramData
2012-04-12 02:24:06 ----D---- C:\Windows\system32\wdi
2012-04-08 03:09:05 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-04-07 02:59:48 ----RD---- C:\Program Files (x86)
2012-04-06 22:25:39 ----D---- C:\Windows\Registration
2012-04-06 20:38:07 ----RSD---- C:\Windows\Fonts
2012-04-06 15:51:31 ----D---- C:\Program Files (x86)\Common Files
2012-04-06 15:44:04 ----D---- C:\Program Files\Common Files
2012-04-06 15:21:49 ----D---- C:\Windows\system32\Tasks
2012-04-06 15:18:52 ----D---- C:\Windows\system32\drivers\etc
2012-04-06 11:57:50 ----SD---- C:\ProgramData\Microsoft
2012-04-06 03:36:43 ----D---- C:\Windows\system32\DriverStore
2012-04-05 22:17:26 ----D---- C:\Windows\Tasks
2012-04-05 13:56:35 ----D---- C:\Program Files\Common Files\System
2012-04-05 13:56:34 ----D---- C:\Windows\ehome
2012-04-05 13:56:26 ----D---- C:\Windows\AppPatch
2012-04-05 13:56:24 ----D---- C:\Windows\SYSWOW64\sk-SK
2012-04-05 13:56:24 ----D---- C:\Windows\system32\sk-SK
2012-04-05 13:56:19 ----D---- C:\Windows\PolicyDefinitions
2012-04-05 13:56:10 ----D---- C:\Windows\system32\Boot
2012-04-05 13:56:07 ----D---- C:\Program Files\Windows Media Player
2012-04-05 13:56:07 ----D---- C:\Program Files (x86)\Windows Media Player
2012-04-04 23:00:42 ----D---- C:\Windows\system32\LogFiles
2012-04-04 14:21:55 ----D---- C:\Windows\ShellNew
2012-04-04 14:21:47 ----D---- C:\Program Files (x86)\MSBuild
2012-04-03 08:58:22 ----D---- C:\Windows\system32\drivers\UMDF
2012-04-03 08:56:26 ----RD---- C:\Users
2012-04-03 08:56:17 ----D---- C:\Windows\Help
2012-04-03 08:29:42 ----D---- C:\Windows\system32\restore
2012-04-03 01:07:23 ----D---- C:\Windows\system32\oobe
2012-04-03 01:07:23 ----D---- C:\Windows\Setup
2012-04-03 01:06:47 ----D---- C:\Windows\servicing
2012-04-03 01:06:47 ----D---- C:\Program Files\Windows Defender
2012-04-03 01:06:47 ----D---- C:\Program Files (x86)\Windows Defender
2012-04-03 01:06:46 ----D---- C:\Windows\SYSWOW64\WCN
2012-04-03 01:06:46 ----D---- C:\Windows\SYSWOW64\wbem
2012-04-03 01:06:46 ----D---- C:\Windows\SYSWOW64\drivers
2012-04-03 01:06:46 ----D---- C:\Windows\system32\wbem
2012-04-02 15:22:02 ----D---- C:\Windows\system32\CodeIntegrity
2012-04-02 15:17:23 ----SHD---- C:\$Recycle.Bin
2012-04-02 15:17:02 ----D---- C:\Windows\system32\Recovery
2012-04-02 15:16:56 ----D---- C:\Windows\debug
2012-04-02 15:11:17 ----D---- C:\Windows\system32\sysprep

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 62496]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2011-11-04 28992]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer; C:\Windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616]
R1 cnnctfy2;Connectify LightWeight Filter; C:\Windows\system32\DRIVERS\cnnctfy2.sys [2012-04-04 31344]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 38288]
R1 nvkflt;nvkflt; C:\Windows\system32\DRIVERS\nvkflt.sys [2011-11-04 249152]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2011-08-04 187632]
R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
R3 Acceler;Accelerometer Service; C:\Windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter; C:\Windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 d554gps;Dell Wireless HSPA Mini-Card GPS Port; C:\Windows\system32\DRIVERS\d554gps64.sys [2010-01-25 96296]
R3 d554scard;Dell Wireless 5540 HSPA Mini-Card USIM Port; C:\Windows\system32\DRIVERS\d554scard.sys [2010-01-25 60968]
R3 ecnssndis;Selective Suspend Enabler For NDIS device; C:\Windows\System32\Drivers\wwuss64.sys [2010-03-03 26664]
R3 ecnssndisfltr;SSNDIS filter service; C:\Windows\System32\Drivers\wwussf64.sys [2010-03-03 30248]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-03-26 12262336]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-02-18 2748520]
R3 IntcDAud;Intel(R) Zvuk pre obrazovky; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 Mbm3CBus;Dell Wireless HSPA Mini-Card Device (WDM); C:\Windows\system32\DRIVERS\Mbm3CBus.sys [2010-04-27 378952]
R3 Mbm3DevMt;Dell Wireless HSPA Mini-Card Device Management Driver (WDM); C:\Windows\system32\DRIVERS\Mbm3DevMt.sys [2010-04-27 416328]
R3 Mbm3mdfl;Dell Wireless HSPA Mini-Card Modem Filter; C:\Windows\system32\DRIVERS\Mbm3mdfl.sys [2010-04-27 19528]
R3 Mbm3Mdm;Dell Wireless HSPA Mini-Card Modem Driver; C:\Windows\system32\DRIVERS\Mbm3Mdm.sys [2010-04-27 468552]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2011-08-03 8604672]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-02-16 428136]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WwanUsbServ;Ericsson WWAN Wireless Module Device Driver; C:\Windows\system32\DRIVERS\WwanUsbMp64.sys [2010-05-25 271400]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol; C:\Windows\system32\DRIVERS\amppal.sys [2011-08-08 299008]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552448]
S3 epmntdrv;epmntdrv; \??\C:\Windows\syswow64\epmntdrv.sys [2010-07-15 14216]
S3 EuGdiDrv;EuGdiDrv; \??\C:\Windows\syswow64\EuGdiDrv.sys [2010-07-15 8456]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-08-08 1166848]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
R2 Connectify;Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [2012-02-25 69632]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2011-07-27 1517328]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-20 325656]
R2 mi-raysat_3dsmax2012_64;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit; S:\Program Files\Autodesk 3ds Max 2012\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe [2011-02-22 86016]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-11-04 1640768]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-11-04 2253120]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2011-07-27 844560]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-11-03 381248]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R2 WMCoreService;Mobile Broadband Service; C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe [2010-06-09 463912]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-04-05 489256]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 253088]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-04-06 1431888]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-27 340240]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0; C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-04-05 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivna kontrola

#5 Příspěvek od vyosek »

Jeste poprosim o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

IVIarkI2I
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 38
Registrován: 20 črc 2008 15:56

Re: Preventivna kontrola

#6 Příspěvek od IVIarkI2I »

info.txt logfile of random's system information tool 1.09 2012-04-18 18:56:04

======Uninstall list======

µTorrent-->"C:\Program Files (x86)\uTorrent\uTorrent.exe" /UNINSTALL
AccelerometerP11-->"C:\Program Files (x86)\InstallShield Installation Information\{87434D51-51DB-4109-B68F-A829ECDCF380}\setup.exe" -runfromtemp -l0x041b -removeonly
ACDSee 14-->MsiExec.exe /I{6F5A71BD-9EC9-4A59-BFBD-CA63CFB4885D}
Adobe AIR-->C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Community Help-->msiexec /qb /x {0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Community Help-->MsiExec.exe /I{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Flash Player 11 Plugin 64-bit-->C:\Windows\system32\Macromed\Flash\FlashUtil64_11_2_202_233_Plugin.exe -maintain plugin
Adobe Media Player-->msiexec /qb /x {DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Media Player-->MsiExec.exe /I{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Photoshop CS5-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader X (10.1.3)-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-AA1000000001}
Autodesk 3ds Max 2012 64-bit - English-->S:\Program Files\Autodesk 3ds Max 2012\3ds Max 2012\Setup\Setup.exe /P {723C8298-C7B0-0409-A1B6-C3BA6F3FFAB1} /M MAX /LANG en-US
Autodesk Backburner 2012.0.0-->MsiExec.exe /I{3D347E6D-5A03-4342-B5BA-6A771885F379}
Autodesk FBX Plug-in 2012.0 - 3ds Max 2012 64-bit-->C:\Program Files\Autodesk\FBX\FBXPlugins\2012.0\3ds Max 2012 64-bit\Uninstall.exe
Autodesk Material Library 2012-->MsiExec.exe /I{8F0837C2-EE09-4903-88F3-1976FE7FFF4E}
Autodesk Material Library Base Resolution Image Library 2012-->MsiExec.exe /I{65420DC9-306E-4371-905F-F4DC3B418E52}
Autodesk Material Library Medium Resolution Image Library 2012-->MsiExec.exe /I{B5751715-EC10-43D9-8C95-62E1368433EF}
Barbarian Invasion-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}\setup.exe" -l0x9
Broken Crescent version 2.3-->"T:\Medieval II Total War\mods\Broken_Crescent_kingdoms\unins000.exe"
Broken Crescent version 2.3-->"T:\Medieval II Total War\mods\Broken_Crescent_kingdoms\unins001.exe"
Broken Crescent version 2.3-->"T:\Medieval II Total War\mods\Broken_Crescent_kingdoms\unins002.exe"
Composite 2012 64-bit-->MsiExec.exe /I{EA234BC3-39FE-4734-B72F-076086889F6D}
Connectify-->C:\Program Files (x86)\Connectify\Uninstall.exe
D3DX10-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{4FE6ABAF-20F3-4F5F-A966-380FDAE9A31A}" "1051" "0"
Dell Wireless HSPA Mini-Card Drivers-->"C:\Program Files (x86)\InstallShield Installation Information\{9D583F01-A973-4B04-90BD-FB7886779090}\setup.exe" -runfromtemp -l0x001b -removeonly
EASEUS Partition Master 6.5.1 Professional-->"C:\Program Files (x86)\EASEUS\EASEUS Partition Master 6.5.1 Professional Edition\unins000.exe"
Grand Theft Auto IV-->"S:\Steam\steam.exe" steam://uninstall/12210
Intel PROSet Wireless-->Intel PROSet Wireless
Intel PROSet Wireless-->Intel PROSet Wireless
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Intel(R) Processor Graphics-->C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
Intel(R) PROSet/Wireless WiFi Software-->MsiExec.exe /I{25FBDA9A-E868-4B3B-B9FF-D923818511A1}
Intel(R) Turbo Boost Technology Monitor 2.0-->MsiExec.exe /X{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}
JMicron Flash Media Controller Driver-->"C:\Program Files (x86)\JMicron\JMCR_DIR\setup.exe" delpkg
Medieval II Total War : Kingdoms : Britannia-->C:\Program Files (x86)\InstallShield Installation Information\{CEDDEE73-3D36-41C2-AA40-29355D9FBD63}\setup.exe -runfromtemp -l0x0009 -removeonly
Medieval II Total War : Kingdoms : Teutonic-->C:\Program Files (x86)\InstallShield Installation Information\{7AEE1963-7001-4C37-BC20-2FAEB74AA41C}\setup.exe -runfromtemp -l0x0009 -removeonly
Medieval II Total War-->C:\Program Files (x86)\InstallShield Installation Information\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}\setup.exe -runfromtemp -l0x0009 -removeonly
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft .NET Framework 4 Extended-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /x64 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{8E34682C-8118-31F1-BC4C-98CD9675E1C2}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}
Microsoft Games for Windows - LIVE-->MsiExec.exe /X{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0015-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0016-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0018-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0019-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001B-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0405-0000-0000000FF1CE}" "{2304F942-79D2-46F7-A512-269A7F5B7EFC}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0407-0000-0000000FF1CE}" "{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0409-0000-0000000FF1CE}" "{99ACCA38-6DD3-48A8-96AE-A283C9759279}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-040E-0000-0000000FF1CE}" "{71431694-851E-4BC7-92A9-4BB9D196E24F}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-041B-0000-0000000FF1CE}" "{A162C5E6-7778-4D5B-9F0A-38F0122DD859}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-041B-1000-0000000FF1CE}" "{6AD0855C-A3FC-4B71-907A-D4372C6F75DB}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002C-041B-0000-0000000FF1CE}" "{93F2D01D-F7E6-46E5-9A7C-316262461F9F}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0044-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-006E-041B-0000-0000000FF1CE}" "{56405E5D-9583-4644-B183-AFB3E19D80B3}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-00A1-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-00BA-041B-0000-0000000FF1CE}" "{9C5E0700-7189-470B-A02E-7FFE75C8BD43}" "1051" "0"
Microsoft Office 2010 Service Pack 1 (SP1)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{047B0968-E622-4FAA-9B4B-121FA109EDDE}" "1051" "0"
Microsoft Office Access MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0015-041B-0000-0000000FF1CE}
Microsoft Office Excel MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0016-041B-0000-0000000FF1CE}
Microsoft Office Groove MUI (Slovak) 2010-->MsiExec.exe /X{90140000-00BA-041B-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0044-041B-0000-0000000FF1CE}
Microsoft Office Office 64-bit Components 2010-->MsiExec.exe /X{90140000-002A-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Slovak) 2010-->MsiExec.exe /X{90140000-00A1-041B-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Slovak) 2010-->MsiExec.exe /X{90140000-001A-041B-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0018-041B-0000-0000000FF1CE}
Microsoft Office Professional Plus 2010-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUSR /dll OSETUP.DLL
Microsoft Office Professional Plus 2010-->MsiExec.exe /X{91140000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2010-->MsiExec.exe /X{90140000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Hungarian) 2010-->MsiExec.exe /X{90140000-001F-040E-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2010-->MsiExec.exe /X{90140000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2010-->MsiExec.exe /X{90140000-002C-041B-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Slovak) 2010-->MsiExec.exe /X{90140000-0019-041B-0000-0000000FF1CE}
Microsoft Office Shared 64-bit MUI (Slovak) 2010-->MsiExec.exe /X{90140000-002A-041B-1000-0000000FF1CE}
Microsoft Office Shared MUI (Slovak) 2010-->MsiExec.exe /X{90140000-006E-041B-0000-0000000FF1CE}
Microsoft Office Word MUI (Slovak) 2010-->MsiExec.exe /X{90140000-001B-041B-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual J# .NET Redistributable Package 1.1-->MsiExec.exe /X{1A655D51-1423-48A3-B748-8F5A0BE294C8}
Microsoft_VC80_ATL_x86_x64-->MsiExec.exe /I{925D058B-564A-443A-B4B2-7E90C6432E55}
Microsoft_VC80_ATL_x86-->MsiExec.exe /I{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}
Microsoft_VC80_CRT_x86_x64-->MsiExec.exe /I{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86_x64-->MsiExec.exe /I{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86_x64-->MsiExec.exe /I{1E9FC118-651D-4934-97BE-E53CAE5C7D45}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86_x64-->MsiExec.exe /I{8557397C-A42D-486F-97B3-A2CBC2372593}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86_x64-->MsiExec.exe /I{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86_x64-->MsiExec.exe /I{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
MilkShape 3D 1.8.4-->"S:\Program Files\MilkShape 3D 1.8.4\uninstall.exe"
Mozilla Firefox 11.0 (x86 en-US)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
Need For Speed™ World-->"S:\Need For Speed World\unins000.exe"
Notepad++-->S:\Program Files\Notepad++\uninstall.exe
NVIDIA Grafický ovládač 285.77-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA Ovládač 3D Vision 285.77-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA Ovládač zvuku HD 1.2.24.0-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage HDAudio.Driver
NVIDIA Photoshop Plug-ins 64 bit-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{5E386C5B-CDE7-435A-B5C9-EC73A1B0553A}\setup.exe" -l0x9
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
PDF Settings CS5-->MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
Python 2.6-->MsiExec.exe /I{110EB5C4-E995-4CFB-AB80-A5F315BEA9E8}
Quickset64-->MsiExec.exe /I{87CF757E-C1F1-4D22-865C-00C6950B5258}
Realtek Ethernet Controller Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -removeonly
Renesas Electronics USB 3.0 Host Controller Driver-->"C:\Program Files (x86)\InstallShield Installation Information\{5442DAB8-7177-49E1-8B22-09A049EA5996}\setup.exe" -runfromtemp -l0x041b -removeonly
Renesas Electronics USB 3.0 Host Controller Driver-->MsiExec.exe /X{5442DAB8-7177-49E1-8B22-09A049EA5996}
Rome - Total War-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{2E97F7E8-ABDE-4E0D-B0AD-B6B4BAD89E24}\setup.exe" -l0x9 -removeonly
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E720AD01-93D5-3E8E-BB8D-E4EF5AF4E5DD} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FF811680-AECE-3F35-A98C-1B84B6E09168} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {5D45782A-1099-317E-ABCC-FF63D5B21386} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E59B2174-E924-311F-8549-AD714C14664D} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FDD13F1E-9C6B-311E-A0D9-D6E172FC28FF} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {9D621E6E-E010-3C80-A055-135891134750} /parameterfolder Extended
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {E59B2174-E924-311F-8549-AD714C14664D} /parameterfolder Extended
Security Update for Microsoft Office 2010 (KB2553091)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{07CA44F3-F5B3-4D12-8C91-EDC5FE91D45C}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2553096)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{10802A6D-EDBF-4383-BCBD-9D5B32F56D35}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{DCE6D0BF-93E4-46C5-9A7C-F1EFF9707C02}" "1051" "0"
Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{01F2485C-FAEE-47E7-986E-B4F2FFC22D57}" "1051" "0"
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{61461470-8168-4F4B-97B7-617AF354F028}" "1051" "0"
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{337A3FB9-281D-4EC8-9CC1-7F6DDAC2359F}" "1051" "0"
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{337A3FB9-281D-4EC8-9CC1-7F6DDAC2359F}" "1051" "0"
Security Update for Microsoft Visio Viewer 2010 (KB2597170) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{011FE2F6-5427-4EC9-AE80-6B28E69781C1}" "1051" "0"
Skype Click to Call-->MsiExec.exe /I{B6CF2967-C81E-40C0-9815-C05774FEF120}
Skype™ 5.8-->MsiExec.exe /X{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Stronghold Kingdoms-->"C:\Program Files (x86)\Firefly Studios\Stronghold Kingdoms\unins000.exe"
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {29C7BE97-DE59-37A2-A687-2ADD5321948A} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7D799A81-5661-3159-BF92-754161CED6E6} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {4DFA8287-EA36-3469-99FE-F568FEC81653} /parameterfolder Client
Update for Microsoft .NET Framework 4 Extended (KB2468871)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {29C7BE97-DE59-37A2-A687-2ADD5321948A} /parameterfolder Extended
Update for Microsoft .NET Framework 4 Extended (KB2533523)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {7D799A81-5661-3159-BF92-754161CED6E6} /parameterfolder Extended
Update for Microsoft .NET Framework 4 Extended (KB2600217)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {4DFA8287-EA36-3469-99FE-F568FEC81653} /parameterfolder Extended
Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{3D1F379C-AA64-4823-90A4-A8DDD4B48C21}" "1051" "0"
Update for Microsoft Office 2010 (KB2494150)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}" "1051" "0"
Update for Microsoft Office 2010 (KB2553065)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{A8686D24-1E89-43A1-973E-05A258D2B3F8}" "1051" "0"
Update for Microsoft Office 2010 (KB2553092)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{7AC49FC8-F8D2-4DD8-9086-09E52385A21F}" "1051" "0"
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{48E1B6C2-7299-4F3F-AA63-42F0ACE55AA4}" "1051" "0"
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{18B3CF2A-73F7-4716-B1AE-86D68726D408}" "1051" "0"
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0405-0000-0000000FF1CE}" "{2AB2E0DF-DF6F-4051-895B-A09FA08AD387}" "1051" "0"
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0407-0000-0000000FF1CE}" "{E6EAF5E1-5E2A-4E4F-847E-97B45179E45B}" "1051" "0"
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001F-0409-0000-0000000FF1CE}" "{17E7B9AB-2DD2-457D-8D8E-CD14ACA973FE}" "1051" "0"
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-006E-041B-0000-0000000FF1CE}" "{45BC4A6A-9337-4276-AF51-6481A747BB32}" "1051" "0"
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{C8694FF0-8203-483B-A07A-2BC40433167D}" "1051" "0"
Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{28FAC187-7C0E-413A-B90A-76F19D0FBF30}" "1051" "0"
Update for Microsoft Office 2010 (KB2566458)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{EFB525A0-E1C0-4E32-9968-FE401BC87363}" "1051" "0"
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{ED31DE9A-3E13-4E2C-9106-E0D8AFFB9FA6}" "1051" "0"
Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{4D98EEEA-A31B-42FA-991A-F989594F4DA5}" "1051" "0"
Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{4D98EEEA-A31B-42FA-991A-F989594F4DA5}" "1051" "0"
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-002A-0000-1000-0000000FF1CE}" "{BEBC2484-290C-46AD-9834-6DAD1FA80273}" "1051" "0"
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-00A1-041B-0000-0000000FF1CE}" "{B4E15135-5272-4194-9724-5FA19F72296D}" "1051" "0"
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{BEBC2484-290C-46AD-9834-6DAD1FA80273}" "1051" "0"
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-041B-0000-0000000FF1CE}" "{755E365E-46A8-40C7-B92D-6CFEA1760099}" "1051" "0"
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{38990592-F6A1-4A26-96C7-0600E36AE794}" "1051" "0"
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-041B-0000-0000000FF1CE}" "{939C62F7-4741-43AF-A29F-5ED0BF0D318A}" "1051" "0"
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{BC6DFBFD-16DD-47E1-A7EF-2C062930FA4F}" "1051" "0"
VLC media player 2.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live Communications Platform-->MsiExec.exe /I{D45240D3-B6B3-4FF9-B243-54ECE3E10066}
Windows Live Essentials-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{6491AB99-A11E-41FD-A5E7-32DE8A097B8E}
Windows Live Essentials-->MsiExec.exe /I{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}
Windows Live ID Sign-in Assistant-->MsiExec.exe /I{1B8ABA62-74F0-47ED-B18C-A43128E591B8}
Windows Live Installer-->MsiExec.exe /I{0B0F231F-CE6A-483D-AA23-77B364F75917}
Windows Live Language Selector-->MsiExec.exe /I{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}
Windows Live Messenger-->MsiExec.exe /X{34C4F5AF-D757-4E6A-ABCA-65AB5A50A1A8}
Windows Live Messenger-->MsiExec.exe /X{80956555-A512-4190-9CAD-B000C36D6B6B}
Windows Live Messenger-->MsiExec.exe /X{EB4DF488-AAEF-406F-A341-CB2AAA315B90}
Windows Live Photo Common-->MsiExec.exe /X{6F37D92B-41AA-44B7-80D2-457ABDE11896}
Windows Live Photo Common-->MsiExec.exe /X{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}
Windows Live Photo Common-->MsiExec.exe /X{D436F577-1695-4D2F-8B44-AC76C99E0002}
Windows Live PIMT Platform-->MsiExec.exe /I{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}
Windows Live SOXE Definitions-->MsiExec.exe /I{200FEC62-3C34-4D60-9CE8-EC372E01C08F}
Windows Live SOXE-->MsiExec.exe /I{682B3E4F-696A-42DE-A41C-4C07EA1678B4}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{02C0A02E-AB30-446C-B4C3-A03310D95F53}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}
Windows Live UX Platform-->MsiExec.exe /I{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}
WinRAR 4.11 (64-bit)-->C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns 3.adobe.com
127.0.0.1 3dns 2.adobe.com
127.0.0.1 adobe dns.adobe.com
127.0.0.1 adobe dns 2.adobe.com
127.0.0.1 adobe dns 3.adobe.com

======System event log======

Computer Name: DELL-PC
Event Code: 10002
Message: Modul WLAN Extensibility Module sa zastavil.

Cesta k modulu: C:\Windows\System32\IWMSSvc.dll

Record Number: 944
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20120403064133.110392-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: DELL-PC
Event Code: 4001
Message: Služba automatickej konfigurácie siete WLAN sa úspešne zastavila.

Record Number: 924
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20120403064116.253641-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: DELL-PC
Event Code: 1
Message: Realtek PCIe GBE Family Controller is disconnected from network.
Record Number: 833
Source Name: RTL8167
Time Written: 20120403063653.775623-000
Event Type: Warning
User:

Computer Name: DELL-PC
Event Code: 1
Message: Realtek PCIe GBE Family Controller is disconnected from network.
Record Number: 744
Source Name: RTL8167
Time Written: 20120403063048.328990-000
Event Type: Warning
User:

Computer Name: DELL-PC
Event Code: 1
Message: Realtek PCIe GBE Family Controller is disconnected from network.
Record Number: 741
Source Name: RTL8167
Time Written: 20120403063042.478980-000
Event Type: Warning
User:

=====Application event log=====

Computer Name: DELL-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 115
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20120402131641.236494-000
Event Type: Error
User: NT AUTHORITY\SYSTEM

Computer Name: DELL-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 113
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20120402131641.158494-000
Event Type: Error
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247E29-32
Event Code: 257
Message: Službe Cryptographic Services sa nepodarilo inicializovať databázu katalógu. Chyba ESENT: -546.
Record Number: 7
Source Name: Microsoft-Windows-CAPI2
Time Written: 20120402130853.011290-000
Event Type: Error
User:

Computer Name: 37L4247E29-32
Event Code: 412
Message: Catalog Database (312) Catalog Database: Unable to read the header of logfile C:\Windows\system32\CatRoot2\edb.log. Error -546.
Record Number: 6
Source Name: ESENT
Time Written: 20120402130852.000000-000
Event Type: Error
User:

Computer Name: 37L4247E29-32
Event Code: 412
Message: Catalog Database (312) Catalog Database: Unable to read the header of logfile C:\Windows\system32\CatRoot2\edb.log. Error -546.
Record Number: 5
Source Name: ESENT
Time Written: 20120402130852.000000-000
Event Type: Error
User:

=====Security event log=====

Computer Name: 37L4247E29-32
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7

Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120402130830.406850-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 5

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x1ec
Process Name: C:\Windows\System32\services.exe

Network Information:
Workstation Name:
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120402130830.406850-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4902
Message: The Per-user audit policy table was created.

Number of Elements: 0
Policy ID: 0x30abb
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120402130823.917239-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0

Logon Type: 0

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x4
Process Name:

Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120402130822.388436-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4608
Message: Windows is starting up.

This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120402130822.279236-000
Event Type: Audit Success
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Autodesk\Backburner\;C:\Program Files\Common Files\Autodesk Shared\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=8
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=2a07
"CM2012DIR"=C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\
"ILBDIR"=C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\
"ILMDIR"=C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\
"ADSK_3DSMAX_x64_2012"=S:\Program Files\Autodesk 3ds Max 2012\3ds Max 2012\

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivna kontrola

#7 Příspěvek od vyosek »

:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "AdobeAAMUpdater-1.0"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Skype"=-
    "Steam"=-
    "Google Update"=-
    "msnmsgr"=-
    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "Adobe ARM"=-
    "SwitchBoard"=-
    "AdobeCS5ServiceManager"=-
    "ACSW14EN"=-
    
    :files
    C:\Windows\tasks\Adobe Flash Player Updater.job
    C:\Windows\tasks\AutoKMS.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2602030269-2964672339-2095405884-1000Core.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2602030269-2964672339-2095405884-1000UA.job
    C:\Windows\AutoKMS.exe
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo.xml
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazondotcom.xml
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

IVIarkI2I
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 38
Registrován: 20 črc 2008 15:56

Re: Preventivna kontrola

#8 Příspěvek od IVIarkI2I »

All processes killed
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Skype deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Steam deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS5ServiceManager deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\ACSW14EN deleted successfully.
========== FILES ==========
C:\Windows\tasks\Adobe Flash Player Updater.job moved successfully.
C:\Windows\tasks\AutoKMS.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2602030269-2964672339-2095405884-1000Core.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2602030269-2964672339-2095405884-1000UA.job moved successfully.
C:\Windows\AutoKMS.exe moved successfully.
C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo.xml moved successfully.
C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazondotcom.xml moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: DELL
->Temp folder emptied: 265650141 bytes
->Temporary Internet Files folder emptied: 5772024 bytes
->FireFox cache emptied: 292534144 bytes
->Google Chrome cache emptied: 6273239 bytes
->Flash cache emptied: 6279 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2744170035 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46356791 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 3 205,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: DELL
->Flash cache emptied: 0 bytes

User: Public

User: UpdatusUser

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.19.0 log created on 04182012_193908

Files moved on Reboot...
C:\Users\DELL\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Nod mi vypisuje hlásenia o Casche poisoningu z neznamej iP

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivna kontrola

#9 Příspěvek od vyosek »

Muzete sem prosim dat screen toho hlaseni, predam kolegum z ESETu, ale asi vim co tam bude...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

IVIarkI2I
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 38
Registrován: 20 črc 2008 15:56

Re: Preventivna kontrola

#10 Příspěvek od IVIarkI2I »

Obrázek

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivna kontrola

#11 Příspěvek od vyosek »

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

IVIarkI2I
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 38
Registrován: 20 črc 2008 15:56

Re: Preventivna kontrola

#12 Příspěvek od IVIarkI2I »

ComboFix 12-04-18.02 - DELL . 04. 2012 22:20:00.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.6038.2130 [GMT 2:00]
Running from: c:\users\DELL\Downloads\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
.
.
((((((((((((((((((((((((( Files Created from 2012-03-18 to 2012-04-18 )))))))))))))))))))))))))))))))
.
.
2012-04-18 20:46 . 2012-04-18 20:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-18 20:26 . 2012-04-18 20:26 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A77F8428-01DD-4840-BA8F-E76027879C55}\offreg.dll
2012-04-18 17:39 . 2012-04-18 17:39 -------- d-----w- C:\_OTM
2012-04-18 16:55 . 2012-04-18 16:56 -------- d-----w- c:\program files\trend micro
2012-04-18 16:55 . 2012-04-18 16:56 -------- d-----w- C:\rsit
2012-04-17 15:05 . 2012-03-20 01:51 8669240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A77F8428-01DD-4840-BA8F-E76027879C55}\mpengine.dll
2012-04-15 00:41 . 2012-04-15 00:41 -------- d-----w- C:\Python26
2012-04-15 00:12 . 2012-04-15 00:12 151552 ----a-w- c:\windows\SysWow64\nvRegDev.dll
2012-04-15 00:12 . 2012-04-15 00:12 61440 ----a-w- c:\windows\SysWow64\nvPhotoshopUtil.dll
2012-04-15 00:12 . 2012-04-15 00:12 40960 ----a-w- c:\windows\SysWow64\nvISWOW64.dll
2012-04-14 10:10 . 2012-04-14 10:10 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-13 01:01 . 2012-03-06 06:43 5504880 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-13 01:01 . 2012-03-06 05:59 3958128 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-04-13 01:01 . 2012-03-06 05:59 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-04-13 01:01 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-13 01:01 . 2012-03-01 06:45 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-13 01:01 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-13 01:01 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-13 01:01 . 2012-03-01 05:49 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-13 01:01 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-13 01:01 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-12 20:39 . 2012-04-12 20:39 -------- d-----w- c:\programdata\Electronic Arts
2012-04-08 01:04 . 2012-04-08 01:04 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-04-07 00:59 . 2012-04-07 00:59 -------- d-----w- c:\program files (x86)\uTorrent
2012-04-06 20:25 . 2012-04-06 20:25 -------- d-----w- c:\windows\SysWow64\URTTEMP
2012-04-06 13:51 . 2012-04-06 13:51 -------- d-----w- c:\programdata\ACD Systems
2012-04-06 13:51 . 2012-04-06 13:51 -------- d-----w- c:\program files (x86)\Common Files\ACD Systems
2012-04-06 13:51 . 2012-04-06 13:51 -------- d-----w- c:\program files (x86)\ACD Systems
2012-04-06 13:44 . 2012-04-06 13:44 -------- d-----w- c:\program files\Autodesk
2012-04-06 13:44 . 2012-04-06 13:44 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2012-04-06 13:42 . 2012-04-06 13:43 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2012-04-06 13:42 . 2012-04-06 13:42 -------- d-----w- c:\program files (x86)\Autodesk
2012-04-06 13:30 . 2012-04-06 13:44 -------- d-----w- c:\programdata\Autodesk
2012-04-06 13:27 . 2012-04-06 13:27 -------- d-----w- C:\Autodesk
2012-04-06 13:18 . 2012-04-06 13:18 -------- d-----w- C:\totalcmd
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\UC.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\RAR.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\PKZIP.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\PKUNZIP.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\LHA.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\ARJ.PIF
2012-04-06 13:12 . 2012-04-06 13:21 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2012-04-06 13:09 . 2012-04-06 13:11 -------- d-----w- c:\program files\Common Files\Adobe
2012-04-06 13:08 . 2012-04-06 13:08 -------- d-----w- c:\program files (x86)\Adobe Media Player
2012-04-06 13:06 . 2012-04-06 13:06 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2012-04-06 09:57 . 2012-04-06 09:58 -------- d-----w- c:\program files (x86)\Windows Live
2012-04-06 09:57 . 2012-04-07 13:58 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-04-06 09:55 . 2012-04-06 09:55 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2012-04-06 01:46 . 2012-04-06 01:46 -------- d-sh--w- c:\programdata\SecuROM
2012-04-06 01:45 . 2012-04-06 01:45 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-04-06 01:45 . 2012-04-06 01:45 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2012-04-06 01:45 . 2012-04-06 01:45 -------- d-----w- c:\windows\SysWow64\xlive
2012-04-05 20:17 . 2012-04-06 01:39 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-04-05 19:44 . 2010-10-28 10:23 2807936 ----a-w- c:\windows\system32\BootMan.exe
2012-04-05 19:44 . 2010-10-28 10:23 2217088 ----a-w- c:\windows\SysWow64\BootMan.exe
2012-04-05 19:44 . 2010-07-15 06:44 9096 ----a-w- c:\windows\system32\EuGdiDrv.sys
2012-04-05 19:44 . 2010-07-15 06:44 86408 ----a-w- c:\windows\SysWow64\setupempdrv03.exe
2012-04-05 19:44 . 2010-07-15 06:44 8456 ----a-w- c:\windows\SysWow64\EuGdiDrv.sys
2012-04-05 19:44 . 2010-07-15 06:44 16776 ----a-w- c:\windows\system32\epmntdrv.sys
2012-04-05 19:44 . 2010-07-15 06:44 11264 ----a-w- c:\windows\system32\EuEpmGdi.dll
2012-04-05 19:44 . 2010-07-15 06:44 100232 ----a-w- c:\windows\system32\setupempdrvx64.exe
2012-04-05 19:44 . 2010-07-15 06:44 14848 ----a-w- c:\windows\SysWow64\EuEpmGdi.dll
2012-04-05 19:44 . 2010-07-15 06:44 14216 ----a-w- c:\windows\SysWow64\epmntdrv.sys
2012-04-05 19:44 . 2012-04-05 19:44 -------- d-----w- c:\program files (x86)\EASEUS
2012-04-05 11:56 . 2012-04-05 11:56 -------- d-----w- c:\windows\SysWow64\Wat
2012-04-05 11:56 . 2012-04-05 11:56 -------- d-----w- c:\windows\system32\Wat
2012-04-04 23:49 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2012-04-04 23:49 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2012-04-04 23:37 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2012-04-04 23:37 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2012-04-04 23:24 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2012-04-04 23:24 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2012-04-04 23:24 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2012-04-04 23:24 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2012-04-04 23:24 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2012-04-04 23:24 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2012-04-04 23:24 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-04-04 23:24 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2012-04-04 23:24 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2012-04-04 23:24 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2012-04-04 23:23 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-04-04 23:09 . 2010-03-04 04:40 184832 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2012-04-04 23:09 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2012-04-04 20:58 . 2012-04-04 20:58 31344 ----a-w- c:\windows\system32\drivers\cnnctfy2.sys
2012-04-04 20:58 . 2012-04-04 21:00 -------- d-----w- c:\program files (x86)\Connectify
2012-04-04 20:58 . 2012-04-04 20:59 -------- d-----w- c:\programdata\Connectify
2012-04-04 13:20 . 2012-04-10 17:54 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-04-04 13:09 . 2012-04-04 13:09 -------- d-----w- c:\programdata\Firefly Studios
2012-04-04 12:33 . 2012-04-04 12:33 -------- d-----w- c:\program files\VideoLAN
2012-04-04 12:30 . 2012-04-04 12:30 -------- d-----w- c:\program files (x86)\Firefly Studios
2012-04-04 12:29 . 2012-04-04 12:29 -------- d-----w- c:\program files\ESET
2012-04-04 12:21 . 2012-04-04 12:21 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2012-04-04 12:21 . 2012-04-05 12:05 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-04-04 12:21 . 2012-04-04 12:21 -------- d-----w- c:\windows\PCHEALTH
2012-04-04 12:21 . 2012-04-04 12:21 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework
2012-04-04 12:21 . 2012-04-04 12:21 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2012-04-04 12:19 . 2012-04-04 12:19 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2012-04-04 12:18 . 2012-04-04 12:18 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-04-04 12:18 . 2012-04-13 01:02 -------- d-----w- c:\programdata\Microsoft Help
2012-04-04 12:18 . 2012-04-04 12:18 -------- d-----r- C:\MSOCache
2012-04-04 12:12 . 2010-01-19 09:05 424960 ----a-w- c:\windows\system32\secproc.dll
2012-04-04 12:11 . 2011-03-03 06:17 182272 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-04-04 12:10 . 2010-08-27 06:14 236032 ----a-w- c:\windows\system32\srvsvc.dll
2012-04-04 12:10 . 2010-08-27 05:46 9728 ----a-w- c:\windows\SysWow64\sscore.dll
2012-04-04 12:10 . 2012-04-14 10:10 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-04 12:10 . 2012-04-14 10:10 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-04-04 12:10 . 2012-04-04 12:10 -------- d-----w- c:\windows\SysWow64\Macromed
2012-04-04 12:10 . 2012-04-04 12:10 -------- d-----w- c:\windows\system32\Macromed
2012-04-04 12:08 . 2012-04-04 12:08 -------- d-----r- c:\program files (x86)\Skype
2012-04-04 12:08 . 2012-04-04 12:08 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-04-04 12:08 . 2012-04-04 12:08 -------- d-----w- c:\programdata\Skype
2012-04-04 12:03 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll
2012-04-04 12:03 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-04-04 12:03 . 2012-02-23 07:18 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-04-04 12:01 . 2012-01-25 06:27 76288 ----a-w- c:\windows\system32\rdpwsx.dll
2012-04-04 12:01 . 2012-01-25 06:27 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-04 12:01 . 2012-01-25 06:20 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-04 12:01 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
2012-04-04 12:01 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
2012-04-04 12:00 . 2012-02-15 06:27 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-04-04 12:00 . 2012-02-15 05:44 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-04-04 12:00 . 2012-02-15 04:47 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-04 12:00 . 2012-02-15 04:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-04-03 06:59 . 2012-04-03 07:04 -------- d-----w- c:\windows\SysWow64\NV
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-06 09:57 . 2009-08-18 09:24 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-04-04 23:20 . 2012-04-04 23:20 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2012-04-04 23:20 . 2012-04-04 23:20 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-02-14 10:09 . 2012-02-14 10:09 1070352 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Connectify"="c:\program files (x86)\Connectify\Connectify.exe" [2012-02-24 3941192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 mi-raysat_3dsmax2012_64;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit;s:\program files\Autodesk 3ds Max 2012\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe [2011-02-22 86016]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 253088]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 16776]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 9096]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-04-06 1431888]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-27 340240]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]
S1 cnnctfy2;Connectify LightWeight Filter;c:\windows\system32\DRIVERS\cnnctfy2.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [x]
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-08-08 1166848]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
S2 Connectify;Connectify;c:\program files (x86)\Connectify\ConnectifyService.exe [2012-02-24 69632]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-11-04 2253120]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-11-03 381248]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S2 WMCoreService;Mobile Broadband Service;c:\program files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe servicemode [x]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [x]
S3 d554gps;Dell Wireless HSPA Mini-Card GPS Port;c:\windows\system32\DRIVERS\d554gps64.sys [x]
S3 d554scard;Dell Wireless 5540 HSPA Mini-Card USIM Port;c:\windows\system32\DRIVERS\d554scard.sys [x]
S3 ecnssndis;Selective Suspend Enabler For NDIS device;c:\windows\system32\Drivers\wwuss64.sys [x]
S3 ecnssndisfltr;SSNDIS filter service;c:\windows\system32\Drivers\wwussf64.sys [x]
S3 IntcDAud;Intel(R) Zvuk pre obrazovky;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 Mbm3CBus;Dell Wireless HSPA Mini-Card Device (WDM);c:\windows\system32\DRIVERS\Mbm3CBus.sys [x]
S3 Mbm3DevMt;Dell Wireless HSPA Mini-Card Device Management Driver (WDM);c:\windows\system32\DRIVERS\Mbm3DevMt.sys [x]
S3 Mbm3mdfl;Dell Wireless HSPA Mini-Card Modem Filter;c:\windows\system32\DRIVERS\Mbm3mdfl.sys [x]
S3 Mbm3Mdm;Dell Wireless HSPA Mini-Card Modem Driver;c:\windows\system32\DRIVERS\Mbm3Mdm.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
S3 WwanUsbServ;Ericsson WWAN Wireless Module Device Driver;c:\windows\system32\DRIVERS\WwanUsbMp64.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-01-25 4479648]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-30 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-30 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-30 418840]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-27 1935120]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-11-04 540992]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 4035152]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\DELL\AppData\Roaming\Mozilla\Firefox\Profiles\hrp7bhu7.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.032"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.abr"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.ani"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.apd"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.arw"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.bay"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.bmp"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.bw"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.cr2"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.crw"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.cs1"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.cur"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.dcr"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.dcx"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.dib"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.djv"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.djvu"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.dng"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.emf"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.eps"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.erf"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.fff"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.fpx"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.gif"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.hdr"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.icl"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.icn"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.iff"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.ilbm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.int"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.inta"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.iw4"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.j2c"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.j2k"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jbr"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jfif"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jif"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jp2"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jpc"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jpe"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jpeg"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jpg"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jpk"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.jpx"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.kdc"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.lbm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.mef"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.mos"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.mrw"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.nef"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.nrw"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.orf"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pbm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pbr"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pcd"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pct"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pcx"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pef"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pgm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pic"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pict"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pix"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.png"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.ppm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.psd"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.psp"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pspbrush"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.pspimage"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.raf"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.ras"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.raw"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.rgb"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.rgba"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.rle"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.rsb"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.rw2"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.rwl"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.sgi"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.sr2"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.srf"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.srw"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.tga"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.thm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.tif"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.tiff"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.ttc"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.ttf"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14o\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.v14o"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14p\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.v14p"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14pf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.v14pf"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.wbm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.wbmp"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.wmf"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.xbm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.xif"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.xmp"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.xpm"
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:d4,09,6a,ee,fe,72,2e,7b,37,45,fd,bd,66,33,f4,78,bd,9c,98,e6,b2,be,73,
a2,83,34,e9,c1,35,c2,4c,d7,4d,83,d9,02,a2,9b,be,da,80,10,14,f3,0d,b1,b2,d8,\
"??"=hex:7f,14,e6,b2,b4,ea,46,28,ce,69,a2,cc,fb,da,ac,d7
.
[HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\SecuROM\License information*]
"datasecu"=hex:64,d4,fe,8b,d6,25,e1,e9,e4,55,eb,2f,29,0b,19,63,47,21,d0,fc,48,
be,1a,ed,6d,73,ed,b7,ec,83,44,37,56,55,fe,2b,11,31,df,b8,78,7c,83,87,ac,37,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-04-18 22:49:31
ComboFix-quarantined-files.txt 2012-04-18 20:49
.
Pre-Run: 154 154 717 184 bytes free
Post-Run: 154 015 494 144 bytes free
.
- - End Of File - - 5F4F74B22D487CF44DE28E2FA4A14078

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivna kontrola

#13 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    DirLook::
    c:\programdata\regid.1986-12.com.adobe
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AdobeAAMUpdater-1.0"=-
    
    RegLock::
    [HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts]
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    RegNull::
    [HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    [HKEY_USERS\S-1-5-21-2602030269-2964672339-2095405884-1000\Software\SecuROM\License information*]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

IVIarkI2I
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 38
Registrován: 20 črc 2008 15:56

Re: Preventivna kontrola

#14 Příspěvek od IVIarkI2I »

ComboFix 12-04-18.02 - DELL . 04. 2012 12:13:35.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.6038.4292 [GMT 2:00]
Running from: c:\users\DELL\Desktop\ComboFix.exe
Command switches used :: c:\users\DELL\Desktop\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\drivers\etc\hosts1
.
.
((((((((((((((((((((((((( Files Created from 2012-03-19 to 2012-04-19 )))))))))))))))))))))))))))))))
.
.
2012-04-19 10:23 . 2012-04-19 10:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-18 17:39 . 2012-04-18 17:39 -------- d-----w- C:\_OTM
2012-04-18 16:55 . 2012-04-18 16:56 -------- d-----w- c:\program files\trend micro
2012-04-18 16:55 . 2012-04-18 16:56 -------- d-----w- C:\rsit
2012-04-17 15:05 . 2012-03-20 01:51 8669240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A77F8428-01DD-4840-BA8F-E76027879C55}\mpengine.dll
2012-04-15 00:41 . 2012-04-15 00:41 -------- d-----w- C:\Python26
2012-04-15 00:12 . 2012-04-15 00:12 151552 ----a-w- c:\windows\SysWow64\nvRegDev.dll
2012-04-15 00:12 . 2012-04-15 00:12 61440 ----a-w- c:\windows\SysWow64\nvPhotoshopUtil.dll
2012-04-15 00:12 . 2012-04-15 00:12 40960 ----a-w- c:\windows\SysWow64\nvISWOW64.dll
2012-04-14 10:10 . 2012-04-14 10:10 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-13 01:01 . 2012-03-06 06:43 5504880 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-13 01:01 . 2012-03-06 05:59 3958128 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-04-13 01:01 . 2012-03-06 05:59 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-04-13 01:01 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-13 01:01 . 2012-03-01 06:45 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-13 01:01 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-13 01:01 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-13 01:01 . 2012-03-01 05:49 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-13 01:01 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-13 01:01 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-12 20:39 . 2012-04-12 20:39 -------- d-----w- c:\programdata\Electronic Arts
2012-04-08 01:04 . 2012-04-08 01:04 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-04-07 00:59 . 2012-04-07 00:59 -------- d-----w- c:\program files (x86)\uTorrent
2012-04-06 20:25 . 2012-04-06 20:25 -------- d-----w- c:\windows\SysWow64\URTTEMP
2012-04-06 13:51 . 2012-04-06 13:51 -------- d-----w- c:\programdata\ACD Systems
2012-04-06 13:51 . 2012-04-06 13:51 -------- d-----w- c:\program files (x86)\Common Files\ACD Systems
2012-04-06 13:51 . 2012-04-06 13:51 -------- d-----w- c:\program files (x86)\ACD Systems
2012-04-06 13:44 . 2012-04-06 13:44 -------- d-----w- c:\program files\Autodesk
2012-04-06 13:44 . 2012-04-06 13:44 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2012-04-06 13:42 . 2012-04-06 13:43 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2012-04-06 13:42 . 2012-04-06 13:42 -------- d-----w- c:\program files (x86)\Autodesk
2012-04-06 13:30 . 2012-04-06 13:44 -------- d-----w- c:\programdata\Autodesk
2012-04-06 13:27 . 2012-04-06 13:27 -------- d-----w- C:\Autodesk
2012-04-06 13:18 . 2012-04-06 13:18 -------- d-----w- C:\totalcmd
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\UC.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\RAR.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\LHA.PIF
2012-04-06 13:18 . 2012-03-09 05:57 545 ----a-w- c:\windows\ARJ.PIF
2012-04-06 13:12 . 2012-04-06 13:21 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2012-04-06 13:09 . 2012-04-06 13:11 -------- d-----w- c:\program files\Common Files\Adobe
2012-04-06 13:08 . 2012-04-06 13:08 -------- d-----w- c:\program files (x86)\Adobe Media Player
2012-04-06 13:06 . 2012-04-06 13:06 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2012-04-06 09:57 . 2012-04-06 09:58 -------- d-----w- c:\program files (x86)\Windows Live
2012-04-06 09:57 . 2012-04-07 13:58 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-04-06 09:55 . 2012-04-06 09:55 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2012-04-06 01:46 . 2012-04-06 01:46 -------- d-sh--w- c:\programdata\SecuROM
2012-04-06 01:45 . 2012-04-06 01:45 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-04-06 01:45 . 2012-04-06 01:45 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2012-04-06 01:45 . 2012-04-06 01:45 -------- d-----w- c:\windows\SysWow64\xlive
2012-04-05 20:17 . 2012-04-06 01:39 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-04-05 19:44 . 2010-10-28 10:23 2807936 ----a-w- c:\windows\system32\BootMan.exe
2012-04-05 19:44 . 2010-10-28 10:23 2217088 ----a-w- c:\windows\SysWow64\BootMan.exe
2012-04-05 19:44 . 2010-07-15 06:44 9096 ----a-w- c:\windows\system32\EuGdiDrv.sys
2012-04-05 19:44 . 2010-07-15 06:44 86408 ----a-w- c:\windows\SysWow64\setupempdrv03.exe
2012-04-05 19:44 . 2010-07-15 06:44 8456 ----a-w- c:\windows\SysWow64\EuGdiDrv.sys
2012-04-05 19:44 . 2010-07-15 06:44 16776 ----a-w- c:\windows\system32\epmntdrv.sys
2012-04-05 19:44 . 2010-07-15 06:44 11264 ----a-w- c:\windows\system32\EuEpmGdi.dll
2012-04-05 19:44 . 2010-07-15 06:44 100232 ----a-w- c:\windows\system32\setupempdrvx64.exe
2012-04-05 19:44 . 2010-07-15 06:44 14848 ----a-w- c:\windows\SysWow64\EuEpmGdi.dll
2012-04-05 19:44 . 2010-07-15 06:44 14216 ----a-w- c:\windows\SysWow64\epmntdrv.sys
2012-04-05 19:44 . 2012-04-05 19:44 -------- d-----w- c:\program files (x86)\EASEUS
2012-04-05 11:56 . 2012-04-05 11:56 -------- d-----w- c:\windows\SysWow64\Wat
2012-04-05 11:56 . 2012-04-05 11:56 -------- d-----w- c:\windows\system32\Wat
2012-04-04 23:49 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2012-04-04 23:49 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2012-04-04 23:37 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2012-04-04 23:37 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2012-04-04 23:24 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2012-04-04 23:24 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2012-04-04 23:24 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2012-04-04 23:24 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2012-04-04 23:24 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2012-04-04 23:24 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2012-04-04 23:24 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-04-04 23:24 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2012-04-04 23:24 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2012-04-04 23:24 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2012-04-04 23:23 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-04-04 23:09 . 2010-03-04 04:40 184832 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2012-04-04 23:09 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2012-04-04 20:58 . 2012-04-04 20:58 31344 ----a-w- c:\windows\system32\drivers\cnnctfy2.sys
2012-04-04 20:58 . 2012-04-04 21:00 -------- d-----w- c:\program files (x86)\Connectify
2012-04-04 20:58 . 2012-04-04 20:59 -------- d-----w- c:\programdata\Connectify
2012-04-04 13:20 . 2012-04-10 17:54 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-04-04 13:09 . 2012-04-04 13:09 -------- d-----w- c:\programdata\Firefly Studios
2012-04-04 12:33 . 2012-04-04 12:33 -------- d-----w- c:\program files\VideoLAN
2012-04-04 12:30 . 2012-04-04 12:30 -------- d-----w- c:\program files (x86)\Firefly Studios
2012-04-04 12:29 . 2012-04-04 12:29 -------- d-----w- c:\program files\ESET
2012-04-04 12:21 . 2012-04-04 12:21 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2012-04-04 12:21 . 2012-04-05 12:05 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-04-04 12:21 . 2012-04-04 12:21 -------- d-----w- c:\windows\PCHEALTH
2012-04-04 12:21 . 2012-04-04 12:21 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework
2012-04-04 12:21 . 2012-04-04 12:21 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2012-04-04 12:19 . 2012-04-04 12:19 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2012-04-04 12:18 . 2012-04-04 12:18 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-04-04 12:18 . 2012-04-13 01:02 -------- d-----w- c:\programdata\Microsoft Help
2012-04-04 12:18 . 2012-04-04 12:18 -------- d-----r- C:\MSOCache
2012-04-04 12:12 . 2010-01-19 09:05 424960 ----a-w- c:\windows\system32\secproc.dll
2012-04-04 12:11 . 2011-03-03 06:17 182272 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-04-04 12:10 . 2010-08-27 06:14 236032 ----a-w- c:\windows\system32\srvsvc.dll
2012-04-04 12:10 . 2010-08-27 05:46 9728 ----a-w- c:\windows\SysWow64\sscore.dll
2012-04-04 12:10 . 2012-04-14 10:10 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-04 12:10 . 2012-04-14 10:10 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-04-04 12:10 . 2012-04-04 12:10 -------- d-----w- c:\windows\SysWow64\Macromed
2012-04-04 12:10 . 2012-04-04 12:10 -------- d-----w- c:\windows\system32\Macromed
2012-04-04 12:08 . 2012-04-04 12:08 -------- d-----r- c:\program files (x86)\Skype
2012-04-04 12:08 . 2012-04-04 12:08 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-04-04 12:08 . 2012-04-04 12:08 -------- d-----w- c:\programdata\Skype
2012-04-04 12:03 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll
2012-04-04 12:03 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-04-04 12:03 . 2012-02-23 07:18 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-04-04 12:01 . 2012-01-25 06:27 76288 ----a-w- c:\windows\system32\rdpwsx.dll
2012-04-04 12:01 . 2012-01-25 06:27 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-04 12:01 . 2012-01-25 06:20 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-04 12:01 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
2012-04-04 12:01 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
2012-04-04 12:00 . 2012-02-15 06:27 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-04-04 12:00 . 2012-02-15 05:44 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-04-04 12:00 . 2012-02-15 04:47 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-04 12:00 . 2012-02-15 04:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-04-03 06:59 . 2012-04-03 07:04 -------- d-----w- c:\windows\SysWow64\NV
2012-04-03 06:59 . 2012-04-03 07:04 -------- d-----w- c:\windows\system32\NV
2012-04-03 06:56 . 2012-04-19 10:24 -------- d-----w- c:\programdata\NVIDIA
2012-04-03 06:55 . 2011-11-04 03:19 8797504 ----a-w- c:\windows\system32\nvwgf2umx.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-06 09:57 . 2009-08-18 09:24 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-04-04 23:20 . 2012-04-04 23:20 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2012-04-04 23:20 . 2012-04-04 23:20 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-02-14 10:09 . 2012-02-14 10:09 1070352 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\regid.1986-12.com.adobe ----
.
2012-04-06 13:21 . 2012-04-06 13:21 1734 ----a-w- c:\programdata\regid.1986-12.com.adobe\regid.1986-12.com.adobe_MasterCollection-CS5-Win-GM-MUL.swidtag
2012-04-06 13:12 . 2012-04-06 13:19 1710 ----a-w- c:\programdata\regid.1986-12.com.adobe\regid.1986-12.com.adobe_Photoshop-CS5-Win-GM.swidtag
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-18_20.46.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-03 06:30 . 2012-04-19 05:23 32274 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-19 05:23 26840 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-04-03 06:05 . 2012-04-19 05:23 7050 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2602030269-2964672339-2095405884-1000_UserData.bin
- 2012-04-18 17:40 . 2012-04-18 17:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-19 10:24 . 2012-04-19 10:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-19 10:24 . 2012-04-19 10:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-04-18 17:40 . 2012-04-18 17:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-04 14:21 . 2012-04-19 10:05 257000 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 05:01 . 2012-04-18 17:40 469252 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-19 10:24 469252 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 02:34 . 2012-04-18 20:25 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-04-19 10:17 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2012-04-05 19:50 . 2012-04-19 10:24 12521016 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2602030269-2964672339-2095405884-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Connectify"="c:\program files (x86)\Connectify\Connectify.exe" [2012-02-24 3941192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Connectify;Connectify;c:\program files (x86)\Connectify\ConnectifyService.exe [2012-02-24 69632]
R2 mi-raysat_3dsmax2012_64;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit;s:\program files\Autodesk 3ds Max 2012\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe [2011-02-22 86016]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 253088]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 16776]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 9096]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-04-06 1431888]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-27 340240]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]
S1 cnnctfy2;Connectify LightWeight Filter;c:\windows\system32\DRIVERS\cnnctfy2.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [x]
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-08-08 1166848]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-11-04 2253120]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-11-03 381248]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S2 WMCoreService;Mobile Broadband Service;c:\program files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe servicemode [x]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [x]
S3 d554gps;Dell Wireless HSPA Mini-Card GPS Port;c:\windows\system32\DRIVERS\d554gps64.sys [x]
S3 d554scard;Dell Wireless 5540 HSPA Mini-Card USIM Port;c:\windows\system32\DRIVERS\d554scard.sys [x]
S3 ecnssndis;Selective Suspend Enabler For NDIS device;c:\windows\system32\Drivers\wwuss64.sys [x]
S3 ecnssndisfltr;SSNDIS filter service;c:\windows\system32\Drivers\wwussf64.sys [x]
S3 IntcDAud;Intel(R) Zvuk pre obrazovky;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 Mbm3CBus;Dell Wireless HSPA Mini-Card Device (WDM);c:\windows\system32\DRIVERS\Mbm3CBus.sys [x]
S3 Mbm3DevMt;Dell Wireless HSPA Mini-Card Device Management Driver (WDM);c:\windows\system32\DRIVERS\Mbm3DevMt.sys [x]
S3 Mbm3mdfl;Dell Wireless HSPA Mini-Card Modem Filter;c:\windows\system32\DRIVERS\Mbm3mdfl.sys [x]
S3 Mbm3Mdm;Dell Wireless HSPA Mini-Card Modem Driver;c:\windows\system32\DRIVERS\Mbm3Mdm.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
S3 WwanUsbServ;Ericsson WWAN Wireless Module Device Driver;c:\windows\system32\DRIVERS\WwanUsbMp64.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-30 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-30 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-30 418840]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-27 1935120]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-11-04 540992]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 4035152]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\DELL\AppData\Roaming\Mozilla\Firefox\Profiles\hrp7bhu7.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Connectify\ConnectifyD.exe
.
**************************************************************************
.
Completion time: 2012-04-19 12:45:04 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-19 10:44
ComboFix2.txt 2012-04-18 20:49
.
Pre-Run: 153 979 473 920 bytes free
Post-Run: 153 893 285 888 bytes free
.
- - End Of File - - 993535B3225373BBEEA0539F02173FB1

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivna kontrola

#15 Příspěvek od vyosek »

Jak se chova nas pacient :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno