Logfile of random's system information tool 1.09 (written by random/random)
Run by Monster at 2012-08-11 19:52:22
Microsoft Windows XP Professional Service Pack 2
System drive C: has 64 GB (85%) free of 76 GB
Total RAM: 1023 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:52:28, on 11. 8. 2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Monster\Desktop\RSIT.exe
C:\Program Files\trend micro\Monster.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HKLM] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [HKCU] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Run: [RAMSaverPro] C:\Program Files\Godlike Developers\RAM Saver Professional\ramsaverpro.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\install\server.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 4944 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-57989841-682003330-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-57989841-682003330-1003UA.job
C:\WINDOWS\tasks\Your File Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Monster\Application Data\Mozilla\Firefox\Profiles\9kzh6alv.default
prefs.js - "browser.startup.homepage" - "http://search.babylon.com/?affID=112555 ... 064f025764"
prefs.js - "keyword.URL" - "http://search.babylon.com/?affID=112555 ... f025764&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.270 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.5.1]
"Description"=
"Path"=C:\WINDOWS\system32\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
babylon.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\Monster\Application Data\Mozilla\Firefox\Profiles\9kzh6alv.default\extensions\
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-07-05 453544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-07-05 157616]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-08-01 13529088]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-08-01 86016]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
"HKLM"=C:\WINDOWS\system32\install\server.exe [2012-08-10 287744]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Policies"=C:\WINDOWS\system32\install\server.exe [2012-08-10 287744]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-07-12 136176]
"Steam"=C:\Program Files\Steam\Steam.exe [2012-08-04 1353080]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2012-07-31 896400]
"HKCU"=C:\WINDOWS\system32\install\server.exe [2012-08-10 287744]
"RAMSaverPro"=C:\Program Files\Godlike Developers\RAM Saver Professional\ramsaverpro.exe []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-07-13 17418928]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Policies"=C:\WINDOWS\system32\install\server.exe [2012-08-10 287744]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\TeamViewer\Version7\TeamViewer.exe"="C:\Program Files\TeamViewer\Version7\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Counter-Strike 1.6\csko.exe"="C:\Counter-Strike 1.6\csko.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Steam\steamapps\monster12328\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\monster12328\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\WINDOWS\system32\javaw.exe"="C:\WINDOWS\system32\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-08-11 19:52:22 ----D---- C:\rsit
2012-08-11 19:52:22 ----D---- C:\Program Files\trend micro
2012-08-11 15:51:53 ----D---- C:\Program Files\Common Files\Skype
2012-08-11 15:51:52 ----RD---- C:\Program Files\Skype
2012-08-10 17:59:29 ----D---- C:\WINDOWS\system32\install
2012-08-10 15:38:19 ----D---- C:\Documents and Settings\All Users\Application Data\IObit
2012-08-10 15:38:05 ----D---- C:\Documents and Settings\Monster\Application Data\IObit
2012-08-10 15:37:51 ----D---- C:\Program Files\IObit
2012-08-09 21:29:57 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2012-08-07 16:13:04 ----D---- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2012-08-07 11:56:44 ----D---- C:\Program Files\EssNetTools
2012-08-07 03:00:18 ----D---- C:\Program Files\HackerPro
2012-08-05 12:14:13 ----D---- C:\Program Files\Valve
2012-08-03 00:15:43 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2012-08-03 00:00:50 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2012-08-03 00:00:50 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2012-08-03 00:00:50 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2012-08-03 00:00:50 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2012-08-03 00:00:49 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2012-08-03 00:00:49 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2012-08-03 00:00:49 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2012-08-03 00:00:48 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2012-08-03 00:00:48 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2012-08-03 00:00:47 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2012-08-03 00:00:47 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2012-08-03 00:00:47 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2012-08-03 00:00:47 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2012-08-03 00:00:46 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2012-08-03 00:00:46 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2012-08-03 00:00:46 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2012-08-03 00:00:45 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2012-08-03 00:00:45 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2012-08-03 00:00:44 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2012-08-03 00:00:44 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2012-08-03 00:00:44 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2012-08-03 00:00:43 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2012-08-03 00:00:43 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2012-08-03 00:00:43 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2012-08-03 00:00:43 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2012-08-03 00:00:43 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2012-08-03 00:00:42 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2012-08-03 00:00:40 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2012-08-03 00:00:38 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2012-08-03 00:00:38 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2012-08-03 00:00:35 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2012-08-03 00:00:35 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2012-08-03 00:00:34 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2012-08-03 00:00:34 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2012-08-03 00:00:33 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2012-08-03 00:00:33 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2012-08-03 00:00:33 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2012-08-03 00:00:33 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2012-08-03 00:00:32 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2012-08-03 00:00:32 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2012-08-03 00:00:32 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2012-08-03 00:00:31 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2012-08-03 00:00:31 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2012-08-03 00:00:30 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2012-08-03 00:00:30 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2012-08-03 00:00:30 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2012-08-03 00:00:30 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2012-08-03 00:00:29 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2012-08-03 00:00:29 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2012-08-03 00:00:29 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2012-08-03 00:00:26 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2012-08-03 00:00:21 ----D---- C:\WINDOWS\Logs
2012-08-02 23:58:31 ----D---- C:\Documents and Settings\Monster\Application Data\Leadertech
2012-07-31 17:42:06 ----D---- C:\Program Files\uTorrent
2012-07-31 17:40:11 ----D---- C:\Documents and Settings\Monster\Application Data\uTorrent
2012-07-31 00:13:27 ----A---- C:\WINDOWS\system32\NCTWMAFile2.dll
2012-07-31 00:13:27 ----A---- C:\WINDOWS\system32\NCTAudioVisualization2.dll
2012-07-31 00:13:27 ----A---- C:\WINDOWS\system32\NCTAudioTransform2.dll
2012-07-31 00:13:27 ----A---- C:\WINDOWS\system32\NCTAudioRecord2.dll
2012-07-31 00:13:27 ----A---- C:\WINDOWS\system32\NCTAudioPlayer2.dll
2012-07-31 00:13:27 ----A---- C:\WINDOWS\system32\NCTAudioInformation2.dll
2012-07-31 00:13:26 ----A---- C:\WINDOWS\system32\NCTAudioFile2.dll
2012-07-31 00:13:26 ----A---- C:\WINDOWS\system32\NCTAudioEditor2.dll
2012-07-31 00:13:26 ----A---- C:\WINDOWS\system32\NCTAudioDisplay2.dll
2012-07-31 00:13:25 ----A---- C:\WINDOWS\system32\NCTAudioDesign2.dll
2012-07-31 00:13:25 ----A---- C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
2012-07-31 00:13:21 ----A---- C:\WINDOWS\system32\msvcr71d.dll
2012-07-31 00:13:21 ----A---- C:\WINDOWS\system32\msvcr70.dll
2012-07-31 00:13:20 ----D---- C:\Program Files\Digital Audio Editor
2012-07-30 23:42:15 ----D---- C:\Documents and Settings\Monster\Application Data\vlc
2012-07-30 23:39:45 ----D---- C:\Program Files\VideoLAN
2012-07-29 20:50:57 ----D---- C:\Documents and Settings\Monster\Application Data\.minecraft
2012-07-28 14:34:23 ----D---- C:\WINDOWS\system32\appmgmt
2012-07-27 23:54:46 ----A---- C:\user.js
2012-07-27 23:54:18 ----D---- C:\Documents and Settings\All Users\Application Data\Babylon
2012-07-27 23:54:17 ----D---- C:\Documents and Settings\Monster\Application Data\Babylon
2012-07-27 23:54:11 ----D---- C:\Program Files\YourFileDownloader
2012-07-27 23:54:11 ----D---- C:\Documents and Settings\Monster\Application Data\YourFileDownloader
2012-07-27 19:59:24 ----HD---- C:\WINDOWS\PIF
2012-07-26 23:09:34 ----D---- C:\WINDOWS\Sun
2012-07-26 23:08:51 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2012-07-26 23:08:50 ----D---- C:\Program Files\Common Files\Java
2012-07-26 23:08:23 ----D---- C:\Program Files\Oracle
2012-07-26 23:08:15 ----D---- C:\Documents and Settings\Monster\Application Data\Oracle
2012-07-26 23:08:11 ----A---- C:\WINDOWS\system32\npDeployJava1.dll
2012-07-26 23:08:11 ----A---- C:\WINDOWS\system32\javaws.exe
2012-07-26 23:08:11 ----A---- C:\WINDOWS\system32\deployJava1.dll
2012-07-26 23:07:51 ----A---- C:\WINDOWS\system32\javaw.exe
2012-07-26 23:07:51 ----A---- C:\WINDOWS\system32\java.exe
2012-07-26 23:07:31 ----D---- C:\Program Files\Java
2012-07-26 23:05:30 ----D---- C:\Documents and Settings\Monster\Application Data\Sun
2012-07-19 15:06:57 ----D---- C:\Documents and Settings\Monster\Application Data\BANDISOFT
2012-07-19 15:04:56 ----D---- C:\Program Files\Bandicam
2012-07-19 11:08:24 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2012-07-18 17:28:52 ----A---- C:\WINDOWS\acehtml6.ini
2012-07-18 16:45:59 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-07-18 16:24:16 ----D---- C:\Documents and Settings\Monster\Application Data\Mozilla
2012-07-18 16:23:51 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-07-18 16:23:51 ----D---- C:\Documents and Settings\All Users\Application Data\Mozilla
2012-07-18 16:23:46 ----D---- C:\Program Files\Mozilla Firefox
2012-07-18 16:08:19 ----N---- C:\WINDOWS\system32\spmsg.dll
2012-07-18 16:08:10 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2012-07-17 23:00:44 ----D---- C:\Program Files\Realtek AC97
2012-07-17 21:11:58 ----D---- C:\Program Files\Half-Life Model Viewer
2012-07-17 13:28:50 ----D---- C:\Program Files\studio
2012-07-16 12:53:22 ----D---- C:\Program Files\Notepad++
2012-07-16 12:53:22 ----D---- C:\Documents and Settings\Monster\Application Data\Notepad++
2012-07-16 12:43:01 ----D---- C:\Documents and Settings\Monster\Application Data\FileZilla
2012-07-16 12:41:18 ----D---- C:\Program Files\FileZilla FTP Client
2012-07-16 00:36:55 ----D---- C:\Program Files\Visicom Media
2012-07-15 12:37:12 ----SHD---- C:\USMT.TMP
2012-07-14 21:40:42 ----D---- C:\Documents and Settings\Monster\Application Data\TeamViewer
2012-07-14 21:40:34 ----D---- C:\Program Files\TeamViewer
2012-07-14 16:55:31 ----D---- C:\Program Files\PokerStars
2012-07-13 12:15:30 ----D---- C:\Documents and Settings\Monster\Application Data\WinRAR
2012-07-13 12:15:21 ----D---- C:\Program Files\WinRAR
2012-07-12 20:54:39 ----A---- C:\WINDOWS\UC.PIF
2012-07-12 20:54:39 ----A---- C:\WINDOWS\RAR.PIF
2012-07-12 20:54:39 ----A---- C:\WINDOWS\PKZIP.PIF
2012-07-12 20:54:39 ----A---- C:\WINDOWS\PKUNZIP.PIF
2012-07-12 20:54:39 ----A---- C:\WINDOWS\NOCLOSE.PIF
2012-07-12 20:54:39 ----A---- C:\WINDOWS\LHA.PIF
2012-07-12 20:54:39 ----A---- C:\WINDOWS\ARJ.PIF
2012-07-12 20:54:38 ----D---- C:\totalcmd
2012-07-12 20:54:38 ----D---- C:\Documents and Settings\Monster\Application Data\GHISLER
2012-07-12 20:51:54 ----D---- C:\WINDOWS\nview
2012-07-12 20:51:54 ----A---- C:\WINDOWS\system32\nvudisp.exe
2012-07-12 20:51:41 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-07-12 20:51:29 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2012-07-12 20:50:44 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2012-07-12 20:38:07 ----D---- C:\Documents and Settings\Monster\Application Data\Identities
2012-07-12 20:38:04 ----HD---- C:\Program Files\Uninstall Information
2012-07-12 20:37:57 ----SD---- C:\Documents and Settings\Monster\Application Data\Microsoft
2012-07-12 20:37:57 ----ASH---- C:\Documents and Settings\Monster\Application Data\desktop.ini
2012-07-12 20:37:55 ----ASH---- C:\hiberfil.sys
2012-07-12 20:37:00 ----D---- C:\WINDOWS\SoftwareDistribution
2012-07-12 20:36:58 ----SD---- C:\WINDOWS\system32\Microsoft
2012-07-12 20:36:58 ----D---- C:\WINDOWS\Prefetch
2012-07-12 20:36:57 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-07-12 20:35:35 ----AS---- C:\WINDOWS\bootstat.dat
2012-07-12 20:32:42 ----D---- C:\WINDOWS\system32\xircom
2012-07-12 20:32:42 ----D---- C:\Program Files\xerox
2012-07-12 20:32:42 ----D---- C:\Program Files\microsoft frontpage
2012-07-12 20:32:23 ----RASH---- C:\MSDOS.SYS
2012-07-12 20:32:23 ----RASH---- C:\IO.SYS
2012-07-12 20:32:23 ----A---- C:\WINDOWS\control.ini
2012-07-12 20:32:23 ----A---- C:\CONFIG.SYS
2012-07-12 20:32:23 ----A---- C:\AUTOEXEC.BAT
2012-07-12 20:32:00 ----A---- C:\WINDOWS\system32\mapi32.dll
2012-07-12 20:30:58 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-07-12 20:30:58 ----RD---- C:\WINDOWS\Offline Web Pages
2012-07-12 20:30:45 ----HD---- C:\Program Files\WindowsUpdate
2012-07-12 20:30:23 ----D---- C:\WINDOWS\system32\DirectX
2012-07-12 20:29:58 ----A---- C:\WINDOWS\system32\atrace.dll
2012-07-12 20:29:55 ----A---- C:\WINDOWS\system32\desktop.ini
2012-07-12 20:29:55 ----A---- C:\WINDOWS\desktop.ini
2012-07-12 20:29:47 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2012-07-12 20:29:46 ----A---- C:\WINDOWS\system32\acctres.dll
2012-07-12 20:29:45 ----D---- C:\Program Files\Common Files\Services
2012-07-12 20:29:42 ----SD---- C:\WINDOWS\Tasks
2012-07-12 20:29:42 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2012-07-12 20:29:41 ----D---- C:\Program Files\Common Files\MSSoap
2012-07-12 20:29:36 ----D---- C:\WINDOWS\srchasst
2012-07-12 20:29:35 ----D---- C:\WINDOWS\system32\Macromed
2012-07-12 20:29:31 ----A---- C:\WINDOWS\system32\wuweb.dll
2012-07-12 20:29:31 ----A---- C:\WINDOWS\system32\wucltui.dll
2012-07-12 20:29:31 ----A---- C:\WINDOWS\system32\wuauserv.dll
2012-07-12 20:29:31 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2012-07-12 20:29:30 ----A---- C:\WINDOWS\system32\wups.dll
2012-07-12 20:29:30 ----A---- C:\WINDOWS\system32\wuaueng.dll
2012-07-12 20:29:30 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2012-07-12 20:29:30 ----A---- C:\WINDOWS\system32\wuauclt.exe
2012-07-12 20:29:30 ----A---- C:\WINDOWS\system32\wuapi.dll
2012-07-12 20:29:30 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2012-07-12 20:29:30 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2012-07-12 20:29:29 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2012-07-12 20:29:29 ----A---- C:\WINDOWS\system32\qmgr.dll
2012-07-12 20:29:25 ----D---- C:\Program Files\Movie Maker
2012-07-12 20:29:20 ----A---- C:\WINDOWS\system32\safrslv.dll
2012-07-12 20:29:20 ----A---- C:\WINDOWS\system32\safrdm.dll
2012-07-12 20:29:20 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2012-07-12 20:29:20 ----A---- C:\WINDOWS\system32\racpldlg.dll
2012-07-12 20:29:15 ----A---- C:\WINDOWS\system32\fltMc.exe
2012-07-12 20:29:15 ----A---- C:\WINDOWS\system32\fltlib.dll
2012-07-12 20:29:15 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2012-07-12 20:29:14 ----D---- C:\WINDOWS\system32\Restore
2012-07-12 20:29:14 ----A---- C:\WINDOWS\system32\srsvc.dll
2012-07-12 20:29:14 ----A---- C:\WINDOWS\system32\srrstr.dll
2012-07-12 20:29:14 ----A---- C:\WINDOWS\system32\srclient.dll
2012-07-12 20:29:14 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2012-07-12 20:29:13 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2012-07-12 20:29:13 ----A---- C:\WINDOWS\system32\msconf.dll
2012-07-12 20:29:13 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2012-07-12 20:29:13 ----A---- C:\WINDOWS\system32\mnmdd.dll
2012-07-12 20:29:13 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2012-07-12 20:29:13 ----A---- C:\WINDOWS\system32\ils.dll
2012-07-12 20:29:09 ----D---- C:\Program Files\NetMeeting
2012-07-12 20:29:09 ----A---- C:\WINDOWS\system32\msoert2.dll
2012-07-12 20:29:09 ----A---- C:\WINDOWS\system32\msoeacct.dll
2012-07-12 20:29:08 ----A---- C:\WINDOWS\system32\inetres.dll
2012-07-12 20:29:07 ----A---- C:\WINDOWS\system32\inetcomm.dll
2012-07-12 20:29:05 ----D---- C:\Program Files\Outlook Express
2012-07-12 20:29:05 ----A---- C:\WINDOWS\system32\schedsvc.dll
2012-07-12 20:29:05 ----A---- C:\WINDOWS\system32\mstinit.exe
2012-07-12 20:29:05 ----A---- C:\WINDOWS\system32\mstask.dll
2012-07-12 20:29:04 ----A---- C:\WINDOWS\system32\isign32.dll
2012-07-12 20:29:04 ----A---- C:\WINDOWS\system32\inetcfg.dll
2012-07-12 20:29:04 ----A---- C:\WINDOWS\system32\icwphbk.dll
2012-07-12 20:29:04 ----A---- C:\WINDOWS\system32\icwdial.dll
2012-07-12 20:28:57 ----D---- C:\Program Files\Common Files\System
2012-07-12 20:28:55 ----D---- C:\Program Files\Internet Explorer
2012-07-12 20:28:21 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2012-07-12 20:28:13 ----D---- C:\Program Files\ComPlus Applications
2012-07-12 20:28:11 ----A---- C:\WINDOWS\vbaddin.ini
2012-07-12 20:28:11 ----A---- C:\WINDOWS\vb.ini
2012-07-12 20:28:07 ----D---- C:\WINDOWS\Registration
2012-07-12 20:28:01 ----D---- C:\Program Files\Online Services
2012-07-12 20:28:00 ----D---- C:\Program Files\Windows Media Player
2012-07-12 20:27:52 ----D---- C:\Program Files\Messenger
2012-07-12 20:27:49 ----D---- C:\Program Files\MSN Gaming Zone
2012-07-12 20:27:49 ----A---- C:\WINDOWS\system32\write.exe
2012-07-12 20:27:39 ----A---- C:\WINDOWS\system32\sndvol32.exe
2012-07-12 20:27:39 ----A---- C:\WINDOWS\system32\hticons.dll
2012-07-12 20:27:39 ----A---- C:\WINDOWS\system32\avwav.dll
2012-07-12 20:27:39 ----A---- C:\WINDOWS\system32\avtapi.dll
2012-07-12 20:27:39 ----A---- C:\WINDOWS\system32\avmeter.dll
2012-07-12 20:27:38 ----A---- C:\WINDOWS\system32\winchat.exe
2012-07-12 20:27:32 ----A---- C:\WINDOWS\system32\getuname.dll
2012-07-12 20:27:31 ----A---- C:\WINDOWS\system32\winmine.exe
2012-07-12 20:27:31 ----A---- C:\WINDOWS\system32\sol.exe
2012-07-12 20:27:31 ----A---- C:\WINDOWS\system32\charmap.exe
2012-07-12 20:27:31 ----A---- C:\WINDOWS\system32\calc.exe
2012-07-12 20:27:30 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2012-07-12 20:27:30 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2012-07-12 20:27:30 ----A---- C:\WINDOWS\system32\tslabels.ini
2012-07-12 20:27:30 ----A---- C:\WINDOWS\system32\tskill.exe
2012-07-12 20:27:30 ----A---- C:\WINDOWS\system32\reset.exe
2012-07-12 20:27:30 ----A---- C:\WINDOWS\system32\mshearts.exe
2012-07-12 20:27:30 ----A---- C:\WINDOWS\system32\freecell.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\tscon.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\shadow.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\rwinsta.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\regini.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\qwinsta.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\qappsrv.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\msg.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\logoff.exe
2012-07-12 20:27:29 ----A---- C:\WINDOWS\system32\cdmodem.dll
2012-07-12 20:27:28 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2012-07-12 20:27:28 ----A---- C:\WINDOWS\system32\mtxex.dll
2012-07-12 20:27:28 ----A---- C:\WINDOWS\system32\mtxdm.dll
2012-07-12 20:27:28 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2012-07-12 20:27:28 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2012-07-12 20:27:27 ----A---- C:\WINDOWS\system32\stclient.dll
2012-07-12 20:27:27 ----A---- C:\WINDOWS\system32\comsnap.dll
2012-07-12 20:27:27 ----A---- C:\WINDOWS\system32\comrepl.dll
2012-07-12 20:27:27 ----A---- C:\WINDOWS\system32\comaddin.dll
2012-07-12 20:27:22 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2012-07-12 20:27:11 ----D---- C:\Program Files\MSN
2012-07-12 20:27:10 ----A---- C:\WINDOWS\system32\sndrec32.exe
2012-07-12 20:27:10 ----A---- C:\WINDOWS\system32\mplay32.exe
2012-07-12 20:27:10 ----A---- C:\WINDOWS\system32\accwiz.exe
2012-07-12 20:27:09 ----D---- C:\Program Files\Windows NT
2012-07-12 20:27:09 ----A---- C:\WINDOWS\system32\mspaint.exe
2012-07-12 20:27:09 ----A---- C:\WINDOWS\system32\hypertrm.dll
2012-07-12 20:27:09 ----A---- C:\WINDOWS\system32\clipbrd.exe
2012-07-12 20:27:08 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2012-07-12 20:27:08 ----A---- C:\WINDOWS\system32\spider.exe
2012-07-12 20:27:08 ----A---- C:\WINDOWS\system32\mstscax.dll
2012-07-12 20:27:08 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2012-07-12 20:27:08 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2012-07-12 20:27:08 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\termsrv.dll
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\sessmgr.exe
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\remotepg.dll
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\rdshost.exe
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\rdchost.dll
2012-07-12 20:27:07 ----A---- C:\WINDOWS\system32\mstsc.exe
2012-07-12 20:27:06 ----D---- C:\WINDOWS\system32\MsDtc
2012-07-12 20:27:06 ----A---- C:\WINDOWS\system32\rdpclip.exe
2012-07-12 20:27:06 ----A---- C:\WINDOWS\system32\qprocess.exe
2012-07-12 20:27:06 ----A---- C:\WINDOWS\system32\mtxoci.dll
2012-07-12 20:27:06 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2012-07-12 20:27:06 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2012-07-12 20:27:06 ----A---- C:\WINDOWS\system32\icaapi.dll
2012-07-12 20:27:06 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2012-07-12 20:27:05 ----A---- C:\WINDOWS\system32\xolehlp.dll
2012-07-12 20:27:05 ----A---- C:\WINDOWS\system32\msdtctm.dll
2012-07-12 20:27:05 ----A---- C:\WINDOWS\system32\msdtclog.dll
2012-07-12 20:27:05 ----A---- C:\WINDOWS\system32\msdtc.exe
2012-07-12 20:27:04 ----D---- C:\WINDOWS\system32\Com
2012-07-12 20:27:04 ----A---- C:\WINDOWS\system32\colbact.dll
2012-07-12 20:27:04 ----A---- C:\WINDOWS\system32\clbcatex.dll
2012-07-12 20:27:04 ----A---- C:\WINDOWS\system32\catsrvut.dll
2012-07-12 20:27:04 ----A---- C:\WINDOWS\system32\catsrvps.dll
2012-07-12 20:27:04 ----A---- C:\WINDOWS\system32\catsrv.dll
2012-07-12 20:27:03 ----A---- C:\WINDOWS\system32\comuid.dll
2012-07-12 20:27:03 ----A---- C:\WINDOWS\system32\comsvcs.dll
2012-07-12 20:27:03 ----A---- C:\WINDOWS\system32\clbcatq.dll
2012-07-12 20:26:56 ----A---- C:\WINDOWS\system32\servdeps.dll
2012-07-12 20:26:56 ----A---- C:\WINDOWS\system32\mmfutil.dll
2012-07-12 20:26:56 ----A---- C:\WINDOWS\system32\licwmi.dll
2012-07-12 20:26:56 ----A---- C:\WINDOWS\system32\cmprops.dll
2012-07-12 20:26:51 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys
2012-07-12 20:26:50 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2012-07-12 13:26:04 ----A---- C:\WINDOWS\system32\h323log.txt
2012-07-12 13:24:38 ----A---- C:\WINDOWS\system32\Thawbrkr.dll
2012-07-12 13:24:37 ----RA---- C:\WINDOWS\system32\kbdgeo.dll
2012-07-12 13:24:37 ----RA---- C:\WINDOWS\system32\kbdarmw.dll
2012-07-12 13:24:37 ----RA---- C:\WINDOWS\system32\kbdarme.dll
2012-07-12 13:24:36 ----RA---- C:\WINDOWS\system32\kbdintel.dll
2012-07-12 13:24:36 ----RA---- C:\WINDOWS\system32\kbdinpun.dll
2012-07-12 13:24:36 ----RA---- C:\WINDOWS\system32\kbdinmar.dll
2012-07-12 13:24:36 ----RA---- C:\WINDOWS\system32\kbdinkan.dll
2012-07-12 13:24:36 ----RA---- C:\WINDOWS\system32\kbdinhin.dll
2012-07-12 13:24:36 ----RA---- C:\WINDOWS\system32\kbdinguj.dll
2012-07-12 13:24:35 ----RA---- C:\WINDOWS\system32\kbdvntc.dll
2012-07-12 13:24:35 ----RA---- C:\WINDOWS\system32\kbdintam.dll
2012-07-12 13:24:35 ----RA---- C:\WINDOWS\system32\kbdindev.dll
2012-07-12 13:24:35 ----A---- C:\WINDOWS\system32\c_iscii.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbdurdu.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbdsyr2.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbdsyr1.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbdfa.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbddiv2.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbddiv1.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbda3.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbda2.dll
2012-07-12 13:24:31 ----RA---- C:\WINDOWS\system32\kbda1.dll
2012-07-12 13:24:31 ----A---- C:\WINDOWS\system32\kbdusa.dll
2012-07-12 13:24:27 ----RA---- C:\WINDOWS\system32\kbdheb.dll
2012-07-12 13:24:20 ----RA---- C:\WINDOWS\system32\kbdth3.dll
2012-07-12 13:24:20 ----RA---- C:\WINDOWS\system32\kbdth2.dll
2012-07-12 13:24:20 ----RA---- C:\WINDOWS\system32\kbdth1.dll
2012-07-12 13:24:20 ----RA---- C:\WINDOWS\system32\kbdth0.dll
2012-07-12 13:24:20 ----A---- C:\WINDOWS\system32\ftlx041e.dll
2012-07-12 13:22:58 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2012-07-12 13:22:30 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2012-07-12 13:22:15 ----A---- C:\WINDOWS\system32\drivers\gameenum.sys
2012-07-12 13:21:59 ----A---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2012-07-12 13:21:58 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2012-07-12 13:21:54 ----A---- C:\WINDOWS\system32\drivers\RTL8139.sys
2012-07-12 13:21:47 ----A---- C:\WINDOWS\system32\drivers\intelide.sys
2012-07-12 13:21:45 ----A---- C:\WINDOWS\system32\usbui.dll
2012-07-12 13:21:42 ----A---- C:\WINDOWS\system32\drivers\AGP440.SYS
2012-07-12 13:20:30 ----SHD---- C:\WINDOWS\Installer
2012-07-12 13:20:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-07-12 13:20:29 ----D---- C:\Program Files\Common Files\ODBC
2012-07-12 13:20:29 ----A---- C:\WINDOWS\ODBCINST.INI
2012-07-12 13:20:26 ----D---- C:\Program Files\Common Files\SpeechEngines
2012-07-12 13:20:25 ----RD---- C:\Program Files
2012-07-12 13:20:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-07-12 13:20:25 ----D---- C:\Program Files\Common Files
2012-07-12 13:20:16 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2012-07-12 13:20:16 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2012-07-12 13:20:16 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdur.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdru.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2012-07-12 13:20:14 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2012-07-12 13:20:12 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2012-07-12 13:20:12 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2012-07-12 13:20:12 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2012-07-12 13:20:12 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2012-07-12 13:20:12 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2012-07-12 13:20:12 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2012-07-12 13:20:12 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2012-07-12 13:20:11 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2012-07-12 13:20:11 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2012-07-12 13:20:11 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2012-07-12 13:20:11 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2012-07-12 13:20:11 ----RA---- C:\WINDOWS\system32\kbdest.dll
2012-07-12 13:20:09 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2012-07-12 13:20:09 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2012-07-12 13:20:09 ----RA---- C:\WINDOWS\system32\kbdro.dll
2012-07-12 13:20:09 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2012-07-12 13:20:09 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2012-07-12 13:20:09 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2012-07-12 13:20:09 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2012-07-12 13:20:09 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2012-07-12 13:20:08 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2012-07-12 13:20:08 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2012-07-12 13:20:08 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2012-07-12 13:20:08 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2012-07-12 13:20:08 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2012-07-12 13:20:02 ----A---- C:\WINDOWS\system32\spxcoins.dll
2012-07-12 13:20:02 ----A---- C:\WINDOWS\system32\irclass.dll
2012-07-12 13:20:02 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2012-07-12 13:20:02 ----A---- C:\WINDOWS\system32\dgsetup.dll
2012-07-12 13:20:02 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2012-07-12 13:20:00 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2012-07-12 13:20:00 ----A---- C:\WINDOWS\TASKMAN.EXE
2012-07-12 13:19:59 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2012-07-12 13:19:59 ----A---- C:\WINDOWS\system32\batt.dll
2012-07-12 13:19:59 ----A---- C:\WINDOWS\NOTEPAD.EXE
2012-07-12 13:19:58 ----A---- C:\WINDOWS\system32\storprop.dll
2012-07-12 13:19:50 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2012-07-12 13:19:46 ----RA---- C:\WINDOWS\SET8.tmp
2012-07-12 13:19:42 ----RA---- C:\WINDOWS\SET4.tmp
2012-07-12 13:19:41 ----RA---- C:\WINDOWS\SET3.tmp
2012-07-12 13:19:34 ----D---- C:\WINDOWS\system32\CatRoot2
2012-07-12 13:19:34 ----D---- C:\WINDOWS\system32\CatRoot
2012-07-12 13:19:28 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2012-07-12 13:18:07 ----D---- C:\Documents and Settings
2012-07-12 13:18:06 ----SHD---- C:\System Volume Information
2012-07-12 13:18:06 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2012-07-12 12:19:52 ----SHD---- C:\RECYCLER
2012-07-12 12:17:03 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2012-07-12 12:17:02 ----A---- C:\WINDOWS\system32\ChCfg.exe
2012-07-12 12:16:59 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2012-07-12 12:16:57 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2012-07-12 12:16:56 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2012-07-12 12:16:54 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2012-07-12 12:16:53 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2012-07-12 12:16:51 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2012-07-12 12:16:50 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2012-07-12 12:16:49 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2012-07-12 12:16:47 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2012-07-12 12:16:45 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2012-07-12 12:16:35 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2012-07-12 12:16:34 ----A---- C:\WINDOWS\system32\ksuser.dll
2012-07-12 12:16:34 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2012-07-12 12:16:32 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2012-07-12 12:16:21 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2012-07-12 12:16:19 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2012-07-12 12:16:19 ----A---- C:\WINDOWS\soundman.exe
2012-07-12 12:16:18 ----HD---- C:\Program Files\InstallShield Installation Information
2012-07-12 12:16:18 ----A---- C:\WINDOWS\alcupd.exe
2012-07-12 12:16:18 ----A---- C:\WINDOWS\Alcrmv.exe
2012-07-12 12:16:07 ----D---- C:\Program Files\Common Files\InstallShield
2012-07-12 12:09:35 ----D---- C:\Program Files\Common Files\Steam
2012-07-12 12:09:34 ----D---- C:\Program Files\Steam
2012-07-12 12:05:56 ----D---- C:\Documents and Settings\Monster\Application Data\Macromedia
2012-07-12 12:05:56 ----D---- C:\Documents and Settings\Monster\Application Data\Adobe
2012-07-12 11:56:57 ----D---- C:\Documents and Settings\Monster\Application Data\Skype
2012-07-12 11:56:48 ----SH---- C:\boot.ini
2012-07-12 11:56:31 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2012-07-12 11:52:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-07-12 11:52:40 ----RSD---- C:\WINDOWS\Fonts
2012-07-12 11:52:40 ----RD---- C:\WINDOWS\Web
2012-07-12 11:52:40 ----HD---- C:\WINDOWS\inf
2012-07-12 11:52:40 ----D---- C:\WINDOWS\WinSxS
2012-07-12 11:52:40 ----D---- C:\WINDOWS\twain_32
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Temp
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\wins
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\wbem
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\usmt
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\spool
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\ShellExt
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\Setup
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\ras
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\oobe
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\npp
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\mui
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\inetsrv
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\IME
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\icsxml
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\ias
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\export
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\drivers\etc
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\drivers\disdn
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\drivers
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\dhcp
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\config
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\3com_dmi
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\3076
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\2052
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\1054
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\1042
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\1041
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\1037
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\1033
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\1031
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\1028
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32\1025
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system32
2012-07-12 11:52:40 ----D---- C:\WINDOWS\system
2012-07-12 11:52:40 ----D---- C:\WINDOWS\security
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Resources
2012-07-12 11:52:40 ----D---- C:\WINDOWS\repair
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Provisioning
2012-07-12 11:52:40 ----D---- C:\WINDOWS\pchealth
2012-07-12 11:52:40 ----D---- C:\WINDOWS\PeerNet
2012-07-12 11:52:40 ----D---- C:\WINDOWS\NLDRV
2012-07-12 11:52:40 ----D---- C:\WINDOWS\mui
2012-07-12 11:52:40 ----D---- C:\WINDOWS\msapps
2012-07-12 11:52:40 ----D---- C:\WINDOWS\msagent
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Media
2012-07-12 11:52:40 ----D---- C:\WINDOWS\java
2012-07-12 11:52:40 ----D---- C:\WINDOWS\ime
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Help
2012-07-12 11:52:40 ----D---- C:\WINDOWS\ehome
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Driver Cache
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Debug
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Cursors
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Connection Wizard
2012-07-12 11:52:40 ----D---- C:\WINDOWS\Config
2012-07-12 11:52:40 ----D---- C:\WINDOWS\AppPatch
2012-07-12 11:52:40 ----D---- C:\WINDOWS\addins
2012-07-12 11:52:40 ----D---- C:\WINDOWS
2012-07-12 11:52:40 ----ASH---- C:\pagefile.sys
======List of files/folders modified in the last 1 month======
2012-07-12 20:32:22 ----A---- C:\WINDOWS\win.ini
2012-07-12 20:31:46 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2012-07-12 13:20:24 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2004-08-03 42368]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-03 36096]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-03 9600]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-03 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-08-01 6555104]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [2012-07-05 161704]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-08-01 159812]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-09 250056]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-20 129976]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2012-08-01 529232]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Jde mi pomaly počítač. vypis z log.txt
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 1
- Registrován: 11 srp 2012 18:56
Re: Jde mi pomaly počítač. vypis z log.txt
Zdravím, v první řadě doinstaluj Service Pack 3
Tohle fixni v HJT :
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HKLM] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\install\server.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
HJT najdeš zde :
C:\Program Files\trend micro\Monster.exe
Fix znamená že spustíš HJT
jako admin
v okně které se ti otevře klikneš na Do a system scan only
v dalším okně najdeš řádky které jsem ti vypsal,
vedle nich je čtvereček do kterého uděláš zatržítko,
pak klikneš na Fix checked které je vlevo dole,
program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Tohle fixni v HJT :
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HKLM] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Monster\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\install\server.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
HJT najdeš zde :
C:\Program Files\trend micro\Monster.exe
Fix znamená že spustíš HJT

v okně které se ti otevře klikneš na Do a system scan only
v dalším okně najdeš řádky které jsem ti vypsal,
vedle nich je čtvereček do kterého uděláš zatržítko,
pak klikneš na Fix checked které je vlevo dole,
program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Re: Jde mi pomaly počítač. vypis z log.txt
Jak to tu vypadá? 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Jde mi pomaly počítač. vypis z log.txt
Tak já to tu zamknu
Dobrý den,
pro neaktivitu je toto téma uzamknuto.
Pokud ho budete chtít odemknout, kontaktujte mě na email nebo některého z mých kolegů.
Děkujeme za pochopení

Dobrý den,
pro neaktivitu je toto téma uzamknuto.
Pokud ho budete chtít odemknout, kontaktujte mě na email nebo některého z mých kolegů.
Děkujeme za pochopení

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.