Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

samovolné spouštění programů?

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
aravir
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 12 dub 2010 15:38

samovolné spouštění programů?

#1 Příspěvek od aravir »

Kamarádovi se prý samy spouští různé programy (třeba 3x po sobě). Koukáme na to a teď se to neprojevilo. Předpokládal jsem nějaký vir, neměl vůbec antivirus, tak jsme nainstalovali MS Security Essentials a nic nenašel a počítač se momentálně chová normálně. Přesto bych poprosil o kontrolu logu.
Díky moc

Logfile of random's system information tool 1.09 (written by random/random)
Run by Elizabeth at 2012-05-20 11:30:18
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 34 GB (34%) free of 100 GB
Total RAM: 1023 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:30:52, on 20.5.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\ICQ7.4\ICQ.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\CNAB4RPK.EXE
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Elizabeth\Plocha\RSIT.exe
C:\Program Files\trend micro\Elizabeth.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/ig?hl=cs&source=webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe /s
O4 - HKCU\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.4\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 7448219375
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 6075 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
C:\WINDOWS\tasks\MpIdleTask.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Elizabeth\Data aplikací\Mozilla\Firefox\Profiles\i6919h21.default

prefs.js - "browser.startup.homepage" - "about:home"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.4.7&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Elizabeth\Data aplikací\Mozilla\Firefox\Profiles\i6919h21.default\searchplugins\
icqplugin-1.xml
icqplugin-10.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-03-02 4296864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-11-30 74752]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-05-12 49152]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-04-04 843712]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 931200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"KiesHelper"=C:\Program Files\Samsung\Kies\KiesHelper.exe [2011-01-30 888120]
"KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2011-01-30 3372856]
"ICQ"=C:\Program Files\ICQ7.4\ICQ.exe [2011-03-24 119608]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-02-29 17148552]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\CNAB4RPK.EXE"="C:\WINDOWS\system32\CNAB4RPK.EXE:*:Enabled:Canon LBP2900 RPC Server Process"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll

======List of files/folders created in the last 1 month======

2012-05-20 11:30:19 ----D---- C:\Program Files\trend micro
2012-05-20 11:30:18 ----D---- C:\rsit
2012-05-20 11:23:31 ----D---- C:\Program Files\CCleaner
2012-05-19 23:45:14 ----D---- C:\Documents and Settings\Elizabeth\Data aplikací\Malwarebytes
2012-05-19 23:45:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-05-19 23:20:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2492386$
2012-05-19 22:31:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-05-19 22:31:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-05-19 22:29:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$
2012-05-19 22:23:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2695962$
2012-05-19 22:19:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2675157$
2012-05-19 22:19:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2653956$
2012-05-19 22:15:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2621440$
2012-05-19 22:15:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2012-05-19 22:13:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2467659$
2012-05-19 22:12:53 ----D---- C:\WINDOWS\ie8updates
2012-05-19 22:12:11 ----D---- C:\WINDOWS\WBEM
2012-05-19 22:11:07 ----HDC---- C:\WINDOWS\ie8
2012-05-19 22:06:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-05-19 22:06:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-05-19 22:06:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-05-19 22:06:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2012-05-19 22:06:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-05-19 22:06:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2012-05-19 22:03:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2633952$
2012-05-19 22:03:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2012-05-19 22:03:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2012-05-19 22:03:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2618451$
2012-05-19 22:03:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2624667$
2012-05-19 22:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2012-05-19 22:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2012-05-19 22:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2012-05-19 22:02:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2012-05-19 22:01:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2012-05-19 22:01:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2012-05-19 22:01:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2012-05-19 22:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2012-05-19 22:00:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2544521$
2012-05-19 22:00:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2012-05-19 22:00:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2012-05-19 21:59:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2012-05-19 21:59:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2012-05-19 21:59:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2012-05-19 21:59:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2012-05-19 21:59:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-05-19 21:59:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2012-05-19 21:58:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2012-05-19 21:58:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2012-05-19 21:58:36 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2012-05-19 21:58:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2012-05-19 21:58:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2012-05-19 21:58:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2012-05-19 21:57:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2012-05-19 21:57:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2012-05-19 21:57:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2012-05-19 21:56:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2012-05-19 21:56:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2012-05-19 21:56:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2012-05-19 21:56:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2012-05-19 21:56:26 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2012-05-19 21:56:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2012-05-19 21:56:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2012-05-19 21:55:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2012-05-19 21:55:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2012-05-19 21:55:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2012-05-19 21:55:34 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2012-05-19 21:54:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2012-05-19 21:54:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2012-05-19 21:54:39 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2012-05-19 21:54:31 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2012-05-19 21:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2012-05-19 21:52:43 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2012-05-19 21:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2012-05-19 21:51:48 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2012-05-19 21:51:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2012-05-19 21:48:36 ----N---- C:\WINDOWS\system32\iacenc.dll
2012-05-19 21:14:06 ----D---- C:\WINDOWS\Prefetch
2012-05-19 21:12:28 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2012-05-19 21:12:21 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2012-05-19 21:12:13 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2012-05-19 21:12:02 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2012-05-19 21:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2012-05-19 21:11:47 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2012-05-19 21:11:40 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2012-05-19 21:11:32 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2012-05-19 21:11:25 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-05-19 21:11:17 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2012-05-19 21:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2012-05-19 21:11:02 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2012-05-19 21:10:54 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2012-05-19 21:10:45 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2012-05-19 21:10:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2012-05-19 21:10:29 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2012-05-19 21:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2012-05-19 21:10:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2012-05-19 21:10:07 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2012-05-19 21:10:00 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2012-05-19 21:09:52 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2012-05-19 21:09:45 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2012-05-19 21:09:37 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-05-19 21:09:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2012-05-19 21:09:21 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2012-05-19 21:09:13 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2012-05-19 21:09:06 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2012-05-19 21:08:59 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2012-05-19 21:08:51 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-05-19 21:08:44 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2012-05-19 21:08:37 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2012-05-19 21:08:29 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2012-05-19 21:08:20 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2012-05-19 21:08:11 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2012-05-19 21:08:03 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2012-05-19 21:07:55 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-05-19 21:07:48 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-05-19 21:07:41 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2012-05-19 21:07:33 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2012-05-19 21:07:25 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2012-05-19 21:07:19 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-05-19 21:07:11 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2012-05-19 21:07:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2012-05-19 21:06:50 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2012-05-19 21:06:41 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2012-05-19 21:06:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2012-05-19 21:06:26 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2012-05-19 21:06:19 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2012-05-19 21:06:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2012-05-19 21:06:02 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2012-05-19 21:05:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2012-05-19 21:05:46 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2012-05-19 21:05:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2012-05-19 21:05:31 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2012-05-19 21:05:23 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2012-05-19 21:05:15 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2012-05-19 21:05:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2012-05-19 21:01:49 ----D---- C:\WINDOWS\system32\cs-cz
2012-05-19 21:01:47 ----D---- C:\WINDOWS\system32\cs
2012-05-19 21:01:47 ----D---- C:\WINDOWS\system32\bits
2012-05-19 21:01:47 ----D---- C:\WINDOWS\l2schemas
2012-05-19 20:55:51 ----D---- C:\WINDOWS\network diagnostic
2012-05-19 20:52:05 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2012-05-19 20:24:12 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2012-05-19 20:24:08 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2012-05-19 20:24:08 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2012-05-19 20:24:08 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2012-05-19 20:24:08 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2012-05-19 20:24:07 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2012-05-19 20:24:07 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2012-05-19 20:24:06 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2012-05-19 20:24:05 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2012-05-19 20:24:05 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2012-05-19 20:24:05 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2012-05-19 20:24:04 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2012-05-19 20:23:59 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2012-05-19 20:23:59 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2012-05-19 20:23:59 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2012-05-19 20:01:01 ----A---- C:\WINDOWS\system32\MRT.exe
2012-05-19 20:00:06 ----HDC---- C:\WINDOWS\$NtUninstallKB982381_0$
2012-05-19 20:00:02 ----D---- C:\Program Files\MSXML 4.0
2012-05-19 19:59:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593_0$
2012-05-19 19:59:44 ----HDC---- C:\WINDOWS\$NtUninstallKB979559_0$
2012-05-19 19:59:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975562_0$
2012-05-19 19:59:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979482_0$
2012-05-19 19:59:23 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2012-05-19 19:59:17 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2012-05-19 19:59:11 ----HDC---- C:\WINDOWS\$NtUninstallKB980218_0$
2012-05-19 19:59:04 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2012-05-19 19:58:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978542_0$
2012-05-19 19:58:46 ----HDC---- C:\WINDOWS\$NtUninstallKB978601_0$
2012-05-19 19:58:39 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2012-05-19 19:58:29 ----HDC---- C:\WINDOWS\$NtUninstallKB979683_0$
2012-05-19 19:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978338_0$
2012-05-19 19:58:11 ----HDC---- C:\WINDOWS\$NtUninstallKB979309_0$
2012-05-19 19:58:05 ----HDC---- C:\WINDOWS\$NtUninstallKB981350$
2012-05-19 19:57:58 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2012-05-19 19:57:50 ----HDC---- C:\WINDOWS\$NtUninstallKB980232_0$
2012-05-19 19:57:42 ----HDC---- C:\WINDOWS\$NtUninstallKB975561_0$
2012-05-19 19:57:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978706_0$
2012-05-19 19:57:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971468_0$
2012-05-19 19:57:20 ----HDC---- C:\WINDOWS\$NtUninstallKB977914_0$
2012-05-19 19:57:09 ----HDC---- C:\WINDOWS\$NtUninstallKB975560_0$
2012-05-19 19:56:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978037_0$
2012-05-19 19:56:51 ----HDC---- C:\WINDOWS\$NtUninstallKB975713_0$
2012-05-19 19:56:43 ----HDC---- C:\WINDOWS\$NtUninstallKB972270_0$
2012-05-19 19:56:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2012-05-19 19:56:27 ----HDC---- C:\WINDOWS\$NtUninstallKB955759_0$
2012-05-19 19:56:20 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2012-05-19 19:56:13 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2012-05-19 19:56:05 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2012-05-19 19:55:57 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2012-05-19 19:55:50 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2012-05-19 19:55:41 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2012-05-19 19:55:34 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2012-05-19 19:55:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2012-05-19 19:55:21 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2012-05-19 19:55:14 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2012-05-19 19:55:08 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2012-05-19 19:55:01 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2012-05-19 19:54:55 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2012-05-19 19:54:48 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2012-05-19 19:54:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2012-05-19 19:54:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2012-05-19 19:54:27 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2012-05-19 19:54:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2012-05-19 19:54:10 ----D---- C:\WINDOWS\ServicePackFiles
2012-05-19 19:54:08 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2012-05-19 19:54:02 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2012-05-19 19:53:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2012-05-19 19:53:36 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2012-05-19 19:53:16 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2012-05-19 19:53:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2012-05-19 19:53:01 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2012-05-19 19:52:53 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2012-05-19 19:52:44 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2012-05-19 19:52:22 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2012-05-19 19:52:10 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2012-05-19 19:50:31 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2012-05-19 19:50:24 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2012-05-19 19:50:17 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2012-05-19 19:50:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2012-05-19 19:50:02 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2012-05-19 19:49:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2012-05-19 19:49:49 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2012-05-19 19:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2012-05-19 19:49:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2012-05-19 19:49:31 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2012-05-19 19:49:24 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2012-05-19 19:49:07 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2012-05-19 19:48:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2012-05-19 19:48:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2012-05-19 19:48:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2012-05-19 19:46:28 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2012-05-19 19:46:13 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2012-05-19 19:38:08 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2012-05-19 19:14:45 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2012-05-19 19:12:41 ----N---- C:\WINDOWS\system32\browserchoice.exe
2012-05-19 19:11:49 ----D---- C:\Program Files\Microsoft Security Client
2012-05-19 19:08:43 ----A---- C:\WINDOWS\system32\wpa.bak
2012-05-19 19:06:39 ----N---- C:\WINDOWS\system32\tzchange.exe
2012-05-19 19:04:24 ----D---- C:\WINDOWS\system32\PreInstall
2012-05-19 19:04:23 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2012-05-19 19:01:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2012-05-19 18:59:41 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-05-19 18:58:07 ----HDC---- C:\WINDOWS\$NtUninstallKB914882$
2012-05-19 18:58:04 ----HD---- C:\WINDOWS\$hf_mig$
2012-05-19 18:55:34 ----D---- C:\Program Files\Adobe
2012-05-19 18:54:26 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2012-05-19 18:51:52 ----A---- C:\WINDOWS\system32\hidserv.dll
2012-05-19 18:51:50 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2012-05-19 18:51:39 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2012-05-19 18:51:27 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys

======List of files/folders modified in the last 1 month======

2012-05-20 11:30:19 ----RD---- C:\Program Files
2012-05-20 11:27:42 ----D---- C:\Documents and Settings\Elizabeth\Data aplikací\Winamp
2012-05-20 11:27:42 ----D---- C:\Documents and Settings\Elizabeth\Data aplikací\Skype
2012-05-20 11:27:33 ----D---- C:\WINDOWS\Temp
2012-05-20 11:27:33 ----D---- C:\WINDOWS\Minidump
2012-05-20 11:27:33 ----D---- C:\WINDOWS\Logs
2012-05-20 11:27:33 ----D---- C:\WINDOWS\Debug
2012-05-20 11:27:33 ----D---- C:\WINDOWS
2012-05-20 11:24:56 ----SD---- C:\WINDOWS\Tasks
2012-05-20 11:15:41 ----D---- C:\WINDOWS\system32\CatRoot2
2012-05-20 11:13:09 ----N---- C:\WINDOWS\SchedLgU.Txt
2012-05-20 11:12:49 ----D---- C:\WINDOWS\system32\drivers
2012-05-20 00:04:09 ----D---- C:\WINDOWS\Microsoft.NET
2012-05-20 00:04:09 ----D---- C:\WINDOWS\assembly
2012-05-19 23:37:35 ----D---- C:\WINDOWS\system32
2012-05-19 23:37:35 ----D---- C:\WINDOWS\AppPatch
2012-05-19 23:36:18 ----SHD---- C:\WINDOWS\Installer
2012-05-19 23:36:18 ----HD---- C:\Config.Msi
2012-05-19 23:35:22 ----D---- C:\WINDOWS\WinSxS
2012-05-19 23:35:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-05-19 23:33:06 ----HD---- C:\WINDOWS\inf
2012-05-19 23:32:59 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-05-19 22:33:54 ----D---- C:\WINDOWS\Help
2012-05-19 22:33:54 ----D---- C:\Program Files\Internet Explorer
2012-05-19 22:12:16 ----D---- C:\WINDOWS\system32\config
2012-05-19 22:12:03 ----D---- C:\WINDOWS\Media
2012-05-19 22:07:07 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-05-19 22:00:51 ----D---- C:\Program Files\Microsoft Office
2012-05-19 21:56:52 ----D---- C:\Program Files\Outlook Express
2012-05-19 21:54:41 ----D---- C:\Program Files\Movie Maker
2012-05-19 21:52:46 ----D---- C:\WINDOWS\system32\CatRoot
2012-05-19 21:13:48 ----D---- C:\WINDOWS\system32\wbem
2012-05-19 21:13:48 ----D---- C:\WINDOWS\system32\Setup
2012-05-19 21:13:48 ----D---- C:\Program Files\Messenger
2012-05-19 21:13:47 ----RSD---- C:\WINDOWS\Fonts
2012-05-19 21:10:58 ----D---- C:\WINDOWS\security
2012-05-19 21:02:24 ----D---- C:\Program Files\Windows Media Player
2012-05-19 21:02:11 ----D---- C:\WINDOWS\ehome
2012-05-19 21:02:10 ----D---- C:\WINDOWS\system32\inetsrv
2012-05-19 21:02:09 ----D---- C:\WINDOWS\ime
2012-05-19 21:01:49 ----D---- C:\WINDOWS\system32\usmt
2012-05-19 21:01:47 ----D---- C:\WINDOWS\PeerNet
2012-05-19 20:58:22 ----D---- C:\WINDOWS\system32\Restore
2012-05-19 20:58:21 ----D---- C:\WINDOWS\system32\npp
2012-05-19 20:58:20 ----D---- C:\WINDOWS\msagent
2012-05-19 20:58:19 ----D---- C:\WINDOWS\srchasst
2012-05-19 20:58:18 ----D---- C:\Program Files\NetMeeting
2012-05-19 20:58:16 ----D---- C:\WINDOWS\system32\Com
2012-05-19 20:58:13 ----D---- C:\Program Files\Windows NT
2012-05-19 20:58:08 ----D---- C:\Program Files\Common Files\System
2012-05-19 20:57:44 ----D---- C:\WINDOWS\system32\oobe
2012-05-19 20:57:42 ----D---- C:\WINDOWS\system
2012-05-19 20:54:25 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-05-19 19:23:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-05-19 19:23:45 ----D---- C:\WINDOWS\SoftwareDistribution
2012-05-19 19:21:31 ----D---- C:\Program Files\Mozilla Firefox
2012-05-19 19:12:07 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-05-19 18:55:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-05-19 18:55:26 ----D---- C:\Program Files\Common Files\Adobe
2012-04-22 13:55:13 ----D---- C:\Documents and Settings\All Users\Data aplikací\tmp

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2012-03-20 171064]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2003-07-02 27904]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 9216]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-03-08 4027840]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys [2011-01-03 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys [2011-01-03 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys [2011-01-03 136680]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 11552]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-19 257696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: samovolné spouštění programů?

#2 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Skype\Toolbars

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

aravir
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 12 dub 2010 15:38

Re: samovolné spouštění programů?

#3 Příspěvek od aravir »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Elizabeth at 2012-05-20 11:49:54
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 35 GB (35%) free of 100 GB
Total RAM: 1023 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:50:06, on 20.5.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\CNAB4RPK.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\ICQ7.4\ICQ.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Elizabeth\Plocha\RSIT.exe
C:\Program Files\trend micro\Elizabeth.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/ig?hl=cs&source=webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe /s
O4 - HKCU\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.4\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 7448219375
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 6060 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
C:\WINDOWS\tasks\MpIdleTask.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Elizabeth\Data aplikací\Mozilla\Firefox\Profiles\i6919h21.default

prefs.js - "browser.startup.homepage" - "about:home"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.4.7&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Elizabeth\Data aplikací\Mozilla\Firefox\Profiles\i6919h21.default\searchplugins\
icqplugin-1.xml
icqplugin-10.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-11-30 74752]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-05-12 49152]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-04-04 843712]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 931200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"KiesHelper"=C:\Program Files\Samsung\Kies\KiesHelper.exe [2011-01-30 888120]
"KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2011-01-30 3372856]
"ICQ"=C:\Program Files\ICQ7.4\ICQ.exe [2011-03-24 119608]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-02-29 17148552]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\CNAB4RPK.EXE"="C:\WINDOWS\system32\CNAB4RPK.EXE:*:Enabled:Canon LBP2900 RPC Server Process"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll

======List of files/folders created in the last 1 month======

2012-05-20 11:44:57 ----D---- C:\_OTM
2012-05-20 11:30:19 ----D---- C:\Program Files\trend micro
2012-05-20 11:30:18 ----D---- C:\rsit
2012-05-20 11:23:31 ----D---- C:\Program Files\CCleaner
2012-05-19 23:45:14 ----D---- C:\Documents and Settings\Elizabeth\Data aplikací\Malwarebytes
2012-05-19 23:45:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-05-19 23:20:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2492386$
2012-05-19 22:31:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-05-19 22:31:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-05-19 22:29:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$
2012-05-19 22:23:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2695962$
2012-05-19 22:19:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2675157$
2012-05-19 22:19:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2653956$
2012-05-19 22:15:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2621440$
2012-05-19 22:15:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2012-05-19 22:13:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2467659$
2012-05-19 22:12:53 ----D---- C:\WINDOWS\ie8updates
2012-05-19 22:12:11 ----D---- C:\WINDOWS\WBEM
2012-05-19 22:11:07 ----HDC---- C:\WINDOWS\ie8
2012-05-19 22:06:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-05-19 22:06:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-05-19 22:06:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-05-19 22:06:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2012-05-19 22:06:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-05-19 22:06:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2012-05-19 22:03:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2633952$
2012-05-19 22:03:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2012-05-19 22:03:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2012-05-19 22:03:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2618451$
2012-05-19 22:03:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2624667$
2012-05-19 22:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2012-05-19 22:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2012-05-19 22:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2012-05-19 22:02:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2012-05-19 22:01:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2012-05-19 22:01:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2012-05-19 22:01:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2012-05-19 22:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2012-05-19 22:00:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2544521$
2012-05-19 22:00:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2012-05-19 22:00:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2012-05-19 21:59:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2012-05-19 21:59:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2012-05-19 21:59:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2012-05-19 21:59:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2012-05-19 21:59:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-05-19 21:59:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2012-05-19 21:58:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2012-05-19 21:58:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2012-05-19 21:58:36 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2012-05-19 21:58:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2012-05-19 21:58:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2012-05-19 21:58:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2012-05-19 21:57:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2012-05-19 21:57:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2012-05-19 21:57:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2012-05-19 21:56:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2012-05-19 21:56:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2012-05-19 21:56:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2012-05-19 21:56:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2012-05-19 21:56:26 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2012-05-19 21:56:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2012-05-19 21:56:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2012-05-19 21:55:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2012-05-19 21:55:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2012-05-19 21:55:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2012-05-19 21:55:34 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2012-05-19 21:54:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2012-05-19 21:54:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2012-05-19 21:54:39 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2012-05-19 21:54:31 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2012-05-19 21:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2012-05-19 21:52:43 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2012-05-19 21:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2012-05-19 21:51:48 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2012-05-19 21:51:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2012-05-19 21:48:36 ----N---- C:\WINDOWS\system32\iacenc.dll
2012-05-19 21:14:06 ----D---- C:\WINDOWS\Prefetch
2012-05-19 21:12:28 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2012-05-19 21:12:21 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2012-05-19 21:12:13 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2012-05-19 21:12:02 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2012-05-19 21:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2012-05-19 21:11:47 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2012-05-19 21:11:40 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2012-05-19 21:11:32 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2012-05-19 21:11:25 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-05-19 21:11:17 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2012-05-19 21:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2012-05-19 21:11:02 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2012-05-19 21:10:54 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2012-05-19 21:10:45 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2012-05-19 21:10:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2012-05-19 21:10:29 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2012-05-19 21:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2012-05-19 21:10:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2012-05-19 21:10:07 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2012-05-19 21:10:00 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2012-05-19 21:09:52 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2012-05-19 21:09:45 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2012-05-19 21:09:37 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-05-19 21:09:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2012-05-19 21:09:21 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2012-05-19 21:09:13 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2012-05-19 21:09:06 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2012-05-19 21:08:59 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2012-05-19 21:08:51 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-05-19 21:08:44 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2012-05-19 21:08:37 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2012-05-19 21:08:29 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2012-05-19 21:08:20 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2012-05-19 21:08:11 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2012-05-19 21:08:03 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2012-05-19 21:07:55 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-05-19 21:07:48 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-05-19 21:07:41 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2012-05-19 21:07:33 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2012-05-19 21:07:25 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2012-05-19 21:07:19 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-05-19 21:07:11 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2012-05-19 21:07:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2012-05-19 21:06:50 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2012-05-19 21:06:41 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2012-05-19 21:06:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2012-05-19 21:06:26 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2012-05-19 21:06:19 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2012-05-19 21:06:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2012-05-19 21:06:02 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2012-05-19 21:05:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2012-05-19 21:05:46 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2012-05-19 21:05:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2012-05-19 21:05:31 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2012-05-19 21:05:23 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2012-05-19 21:05:15 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2012-05-19 21:05:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2012-05-19 21:01:49 ----D---- C:\WINDOWS\system32\cs-cz
2012-05-19 21:01:47 ----D---- C:\WINDOWS\system32\cs
2012-05-19 21:01:47 ----D---- C:\WINDOWS\system32\bits
2012-05-19 21:01:47 ----D---- C:\WINDOWS\l2schemas
2012-05-19 20:55:51 ----D---- C:\WINDOWS\network diagnostic
2012-05-19 20:52:05 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2012-05-19 20:24:12 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2012-05-19 20:24:11 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2012-05-19 20:24:08 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2012-05-19 20:24:08 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2012-05-19 20:24:08 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2012-05-19 20:24:08 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2012-05-19 20:24:07 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2012-05-19 20:24:07 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2012-05-19 20:24:06 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2012-05-19 20:24:05 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2012-05-19 20:24:05 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2012-05-19 20:24:05 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2012-05-19 20:24:04 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2012-05-19 20:23:59 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2012-05-19 20:23:59 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2012-05-19 20:23:59 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2012-05-19 20:21:46 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2012-05-19 20:21:45 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2012-05-19 20:01:01 ----A---- C:\WINDOWS\system32\MRT.exe
2012-05-19 20:00:06 ----HDC---- C:\WINDOWS\$NtUninstallKB982381_0$
2012-05-19 20:00:02 ----D---- C:\Program Files\MSXML 4.0
2012-05-19 19:59:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593_0$
2012-05-19 19:59:44 ----HDC---- C:\WINDOWS\$NtUninstallKB979559_0$
2012-05-19 19:59:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975562_0$
2012-05-19 19:59:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979482_0$
2012-05-19 19:59:23 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2012-05-19 19:59:17 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2012-05-19 19:59:11 ----HDC---- C:\WINDOWS\$NtUninstallKB980218_0$
2012-05-19 19:59:04 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2012-05-19 19:58:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978542_0$
2012-05-19 19:58:46 ----HDC---- C:\WINDOWS\$NtUninstallKB978601_0$
2012-05-19 19:58:39 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2012-05-19 19:58:29 ----HDC---- C:\WINDOWS\$NtUninstallKB979683_0$
2012-05-19 19:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978338_0$
2012-05-19 19:58:11 ----HDC---- C:\WINDOWS\$NtUninstallKB979309_0$
2012-05-19 19:58:05 ----HDC---- C:\WINDOWS\$NtUninstallKB981350$
2012-05-19 19:57:58 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2012-05-19 19:57:50 ----HDC---- C:\WINDOWS\$NtUninstallKB980232_0$
2012-05-19 19:57:42 ----HDC---- C:\WINDOWS\$NtUninstallKB975561_0$
2012-05-19 19:57:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978706_0$
2012-05-19 19:57:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971468_0$
2012-05-19 19:57:20 ----HDC---- C:\WINDOWS\$NtUninstallKB977914_0$
2012-05-19 19:57:09 ----HDC---- C:\WINDOWS\$NtUninstallKB975560_0$
2012-05-19 19:56:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978037_0$
2012-05-19 19:56:51 ----HDC---- C:\WINDOWS\$NtUninstallKB975713_0$
2012-05-19 19:56:43 ----HDC---- C:\WINDOWS\$NtUninstallKB972270_0$
2012-05-19 19:56:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2012-05-19 19:56:27 ----HDC---- C:\WINDOWS\$NtUninstallKB955759_0$
2012-05-19 19:56:20 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2012-05-19 19:56:13 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2012-05-19 19:56:05 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2012-05-19 19:55:57 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2012-05-19 19:55:50 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2012-05-19 19:55:41 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2012-05-19 19:55:34 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2012-05-19 19:55:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2012-05-19 19:55:21 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2012-05-19 19:55:14 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2012-05-19 19:55:08 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2012-05-19 19:55:01 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2012-05-19 19:54:55 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2012-05-19 19:54:48 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2012-05-19 19:54:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2012-05-19 19:54:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2012-05-19 19:54:27 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2012-05-19 19:54:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2012-05-19 19:54:10 ----D---- C:\WINDOWS\ServicePackFiles
2012-05-19 19:54:08 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2012-05-19 19:54:02 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2012-05-19 19:53:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2012-05-19 19:53:36 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2012-05-19 19:53:16 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2012-05-19 19:53:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2012-05-19 19:53:01 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2012-05-19 19:52:53 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2012-05-19 19:52:44 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2012-05-19 19:52:22 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2012-05-19 19:52:10 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2012-05-19 19:50:31 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2012-05-19 19:50:24 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2012-05-19 19:50:17 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2012-05-19 19:50:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2012-05-19 19:50:02 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2012-05-19 19:49:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2012-05-19 19:49:49 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2012-05-19 19:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2012-05-19 19:49:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2012-05-19 19:49:31 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2012-05-19 19:49:24 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2012-05-19 19:49:07 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2012-05-19 19:48:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2012-05-19 19:48:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2012-05-19 19:48:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2012-05-19 19:46:28 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2012-05-19 19:46:13 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2012-05-19 19:38:08 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2012-05-19 19:14:45 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2012-05-19 19:12:41 ----N---- C:\WINDOWS\system32\browserchoice.exe
2012-05-19 19:11:49 ----D---- C:\Program Files\Microsoft Security Client
2012-05-19 19:08:43 ----A---- C:\WINDOWS\system32\wpa.bak
2012-05-19 19:06:39 ----N---- C:\WINDOWS\system32\tzchange.exe
2012-05-19 19:04:24 ----D---- C:\WINDOWS\system32\PreInstall
2012-05-19 19:04:23 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2012-05-19 19:01:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2012-05-19 18:59:41 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-05-19 18:58:07 ----HDC---- C:\WINDOWS\$NtUninstallKB914882$
2012-05-19 18:58:04 ----HD---- C:\WINDOWS\$hf_mig$
2012-05-19 18:55:34 ----D---- C:\Program Files\Adobe
2012-05-19 18:54:26 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2012-05-19 18:51:52 ----A---- C:\WINDOWS\system32\hidserv.dll
2012-05-19 18:51:50 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2012-05-19 18:51:39 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2012-05-19 18:51:27 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys

======List of files/folders modified in the last 1 month======

2012-05-20 11:49:13 ----D---- C:\Documents and Settings\Elizabeth\Data aplikací\Skype
2012-05-20 11:48:11 ----D---- C:\WINDOWS\system32\CatRoot2
2012-05-20 11:48:10 ----D---- C:\WINDOWS\Temp
2012-05-20 11:46:38 ----D---- C:\WINDOWS
2012-05-20 11:45:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-05-20 11:45:13 ----D---- C:\WINDOWS\system32
2012-05-20 11:44:57 ----RD---- C:\Program Files\Skype
2012-05-20 11:30:19 ----RD---- C:\Program Files
2012-05-20 11:27:42 ----D---- C:\Documents and Settings\Elizabeth\Data aplikací\Winamp
2012-05-20 11:27:33 ----D---- C:\WINDOWS\Minidump
2012-05-20 11:27:33 ----D---- C:\WINDOWS\Logs
2012-05-20 11:27:33 ----D---- C:\WINDOWS\Debug
2012-05-20 11:24:56 ----SD---- C:\WINDOWS\Tasks
2012-05-20 11:12:49 ----D---- C:\WINDOWS\system32\drivers
2012-05-20 00:04:09 ----D---- C:\WINDOWS\Microsoft.NET
2012-05-20 00:04:09 ----D---- C:\WINDOWS\assembly
2012-05-19 23:37:35 ----D---- C:\WINDOWS\AppPatch
2012-05-19 23:36:18 ----SHD---- C:\WINDOWS\Installer
2012-05-19 23:36:18 ----HD---- C:\Config.Msi
2012-05-19 23:35:22 ----D---- C:\WINDOWS\WinSxS
2012-05-19 23:35:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-05-19 23:33:06 ----HD---- C:\WINDOWS\inf
2012-05-19 23:32:59 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-05-19 22:33:54 ----D---- C:\WINDOWS\Help
2012-05-19 22:33:54 ----D---- C:\Program Files\Internet Explorer
2012-05-19 22:12:16 ----D---- C:\WINDOWS\system32\config
2012-05-19 22:12:03 ----D---- C:\WINDOWS\Media
2012-05-19 22:07:07 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-05-19 22:00:51 ----D---- C:\Program Files\Microsoft Office
2012-05-19 21:56:52 ----D---- C:\Program Files\Outlook Express
2012-05-19 21:54:41 ----D---- C:\Program Files\Movie Maker
2012-05-19 21:52:46 ----D---- C:\WINDOWS\system32\CatRoot
2012-05-19 21:13:48 ----D---- C:\WINDOWS\system32\wbem
2012-05-19 21:13:48 ----D---- C:\WINDOWS\system32\Setup
2012-05-19 21:13:48 ----D---- C:\Program Files\Messenger
2012-05-19 21:13:47 ----RSD---- C:\WINDOWS\Fonts
2012-05-19 21:10:58 ----D---- C:\WINDOWS\security
2012-05-19 21:02:24 ----D---- C:\Program Files\Windows Media Player
2012-05-19 21:02:11 ----D---- C:\WINDOWS\ehome
2012-05-19 21:02:10 ----D---- C:\WINDOWS\system32\inetsrv
2012-05-19 21:02:09 ----D---- C:\WINDOWS\ime
2012-05-19 21:01:49 ----D---- C:\WINDOWS\system32\usmt
2012-05-19 21:01:47 ----D---- C:\WINDOWS\PeerNet
2012-05-19 20:58:22 ----D---- C:\WINDOWS\system32\Restore
2012-05-19 20:58:21 ----D---- C:\WINDOWS\system32\npp
2012-05-19 20:58:20 ----D---- C:\WINDOWS\msagent
2012-05-19 20:58:19 ----D---- C:\WINDOWS\srchasst
2012-05-19 20:58:18 ----D---- C:\Program Files\NetMeeting
2012-05-19 20:58:16 ----D---- C:\WINDOWS\system32\Com
2012-05-19 20:58:13 ----D---- C:\Program Files\Windows NT
2012-05-19 20:58:08 ----D---- C:\Program Files\Common Files\System
2012-05-19 20:57:44 ----D---- C:\WINDOWS\system32\oobe
2012-05-19 20:57:42 ----D---- C:\WINDOWS\system
2012-05-19 20:54:25 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-05-19 19:23:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-05-19 19:23:45 ----D---- C:\WINDOWS\SoftwareDistribution
2012-05-19 19:21:31 ----D---- C:\Program Files\Mozilla Firefox
2012-05-19 19:12:07 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-05-19 18:55:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-05-19 18:55:26 ----D---- C:\Program Files\Common Files\Adobe
2012-04-22 13:55:13 ----D---- C:\Documents and Settings\All Users\Data aplikací\tmp

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2012-03-20 171064]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2003-07-02 27904]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 9216]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-03-08 4027840]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys [2011-01-03 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys [2011-01-03 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys [2011-01-03 136680]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 11552]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-19 257696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: samovolné spouštění programů?

#4 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\Elizabeth.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo vě čtverečcích zaškrtněte:
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
Klikněte na >FixChecked< a restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

aravir
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 12 dub 2010 15:38

Re: samovolné spouštění programů?

#5 Příspěvek od aravir »

hotovo, mám dát další log z rsit?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: samovolné spouštění programů?

#6 Příspěvek od Rudy »

Pokud nastala změna k lepšímu, nemusíte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

aravir
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 12 dub 2010 15:38

Re: samovolné spouštění programů?

#7 Příspěvek od aravir »

Děkuji za pomoc!

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: samovolné spouštění programů?

#8 Příspěvek od Rudy »

Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět