blokace PC Policií ČR
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
blokace PC Policií ČR
Dobrý den, synův PC byl včera večer zablokován s hláškou od Policie ČR a zaplacení pokuty.
Postupovali jsme podle tohoto návodu přes nouzový režim: http://www.viruskasino.com/2012/10/pozo ... any_6.html
- pomocí Roguekliller...a vir byl odblokován.
Přesto prosím o kontrolu logu. Děkuji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Ichigo at 2012-12-29 14:54:48
Microsoft® Windows Vista™ Home Premium
System drive C: has 292 GB (61%) free of 477 GB
Total RAM: 4095 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:54:55, on 29.12.2012
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal
Running processes:
C:\Users\Ichigo\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Hamachi\hamachi.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
C:\Program Files\trend micro\Ichigo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.speedbit.com/?s=C8Ca205
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Philips Device Listener] "C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ichigo\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [SDP] C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: hamachi.lnk = C:\Program Files (x86)\Hamachi\hamachi.exe
O8 - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8537 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe /pipeName=75f3b461-1c2e-4452-8456-705c232b9568 /coreSdkOptions=286 /logConfFile="C:\ProgramData\AVG2012\temp\75d10949-63c7-4563-ab15-4b0f8f303e4c-1a4-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2012\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2012" /tempPath="C:\ProgramData\AVG2012\temp\"
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Users\Ichigo\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe" /auto
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Hamachi\hamachi.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgemca.exe"
"C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe"
taskeng.exe {2BF31A2E-6780-4D04-8FC9-6937C01D77E3}
taskeng.exe {85332374-9B64-46A5-8935-8B320E2EDD48}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler64.exe"
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot) " "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1340.6a4c400.1686121879 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll" - -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" 1340 "\\.\pipe\gecko-crash-server-pipe.1340" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe" --proxy-stub-channel=Flash4980.67FEB7B8.41 --host-broker-channel=Flash4980.67FEB7B8.18467 --host-pid=4980 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe" --channel=4716.0059F680.1042362934 --proxy-stub-channel=Flash4980.67FEB7B8.41 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll" --host-npapi-version=27 --type=renderer
"C:\Windows\system32\SearchFilterHost.exe" 0 648 652 660 65536 656
"C:\Users\Ichigo\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3021093605-2333013262-3278736194-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3021093605-2333013262-3278736194-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do Not Track - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll [2012-08-13 1393272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll [2012-06-24 1968248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-11-24 537576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-11-24 193512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do Not Track - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll [2012-08-13 938104]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll [2012-06-24 1417336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-11-24 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-11-24 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{687578b9-7132-4a7a-80e4-30ee31099e03}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2012-08-10 1581752]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Ichigo\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-11 116648]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2012-12-04 1354736]
"SDP"=C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe [2012-10-03 201808]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-11-09 17877168]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-07-04 641704]
"AVG_TRAY"=C:\Program Files (x86)\AVG\AVG2012\avgtray.exe [2012-07-31 2596984]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
"Philips Device Listener"=C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe [2012-02-08 380416]
C:\Users\Ichigo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
hamachi.lnk - C:\Program Files (x86)\Hamachi\hamachi.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-12-29 14:54:49 ----D---- C:\Program Files\trend micro
2012-12-29 14:54:48 ----D---- C:\rsit
2012-12-29 14:44:02 ----D---- C:\Program Files\CCleaner
2012-12-29 14:41:29 ----ASH---- C:\hiberfil.sys
2012-12-29 00:44:10 ----A---- C:\ProgramData\dsgsdgdsgdsgw.js
2012-12-26 14:57:43 ----D---- C:\Users\Ichigo\AppData\Roaming\.minecraft
2012-12-24 14:24:05 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-12-24 14:24:05 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-12-24 14:24:05 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-12-24 14:24:05 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-12-24 14:24:04 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-12-24 14:24:04 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-12-24 14:24:01 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-12-24 14:24:01 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-12-24 14:24:01 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-12-24 14:24:01 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-12-24 14:24:00 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-12-24 14:24:00 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-12-24 14:24:00 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-12-24 14:24:00 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-12-24 14:23:59 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-12-24 14:23:59 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-12-24 14:23:58 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-12-24 14:23:58 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-12-24 14:23:58 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-12-24 14:23:58 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-12-24 14:23:58 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-12-24 14:23:58 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-12-24 14:23:57 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-12-24 14:23:57 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-12-24 14:23:57 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-12-24 14:23:57 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-12-24 14:23:56 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-12-24 14:23:56 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-12-24 14:23:55 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-12-24 14:23:55 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-12-24 14:23:52 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-12-24 14:23:52 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-12-24 14:23:51 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-12-24 14:23:51 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-12-24 14:23:51 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-12-24 14:23:51 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-12-24 14:23:48 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-12-24 14:23:48 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-12-24 14:23:45 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-12-24 14:23:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-12-24 14:23:45 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-12-24 14:23:45 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-12-24 14:23:42 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-12-24 14:23:42 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-12-24 14:23:41 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-12-24 14:23:41 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-12-24 14:23:41 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-12-24 14:23:41 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-12-24 14:23:41 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-12-24 14:23:41 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-12-24 14:23:40 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-12-24 14:23:40 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-12-24 14:23:38 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-12-24 14:23:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-12-24 14:23:38 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-12-24 14:23:38 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-12-24 14:23:36 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-12-24 14:23:36 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-12-24 14:23:35 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-12-24 14:23:35 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-12-24 14:23:35 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-12-24 14:23:35 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-12-24 14:23:34 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-12-24 14:23:34 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-12-24 14:23:34 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-12-24 14:23:34 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-12-24 14:23:33 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-12-24 14:23:33 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-12-24 14:23:33 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-12-24 14:23:33 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-12-24 14:23:32 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-12-24 14:23:32 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-12-24 14:23:31 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-12-24 14:23:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-12-24 14:23:31 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-12-24 14:23:31 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-12-24 14:23:28 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-12-24 14:23:28 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-12-24 14:23:26 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-12-24 14:23:26 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-12-24 14:23:26 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-12-24 14:23:26 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-12-24 14:23:26 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-12-24 14:23:26 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-12-24 14:23:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-12-24 14:23:25 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-12-24 14:23:23 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-12-24 14:23:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-12-24 14:23:23 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-12-24 14:23:23 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-12-24 14:23:18 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-12-24 14:23:18 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-12-24 14:23:18 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-12-24 14:23:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-12-24 14:23:17 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-12-24 14:23:17 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-12-24 14:23:17 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-12-24 14:23:17 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-12-24 14:23:14 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-12-24 14:23:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-12-24 14:23:14 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-12-24 14:23:14 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-12-24 14:23:09 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-12-24 14:23:09 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-12-24 14:23:09 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-12-24 14:23:09 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-12-24 14:23:06 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-12-24 14:23:06 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-12-24 14:23:06 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-12-24 14:23:06 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-12-24 14:23:02 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-12-24 14:23:02 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-12-24 14:23:02 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-12-24 14:23:02 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-12-24 14:23:00 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-12-24 14:23:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-12-24 14:23:00 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-12-24 14:23:00 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-12-24 14:22:56 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-12-24 14:22:56 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-12-24 14:22:55 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-12-24 14:22:55 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-12-24 14:22:55 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-12-24 14:22:55 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-12-24 14:22:54 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-12-24 14:22:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-12-24 14:22:54 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-12-24 14:22:54 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-12-24 14:22:49 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2012-12-24 14:22:49 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-12-24 14:22:49 ----A---- C:\Windows\system32\xinput1_3.dll
2012-12-24 14:22:49 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-12-24 14:22:48 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-12-24 14:22:48 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-12-24 14:22:46 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-12-24 14:22:46 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-12-24 14:22:46 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-12-24 14:22:46 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-12-24 14:22:43 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2012-12-24 14:22:43 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-12-24 14:22:42 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-12-24 14:22:42 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-12-24 14:22:41 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-12-24 14:22:41 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-12-24 14:22:40 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-12-24 14:22:40 ----A---- C:\Windows\system32\d3dx10.dll
2012-12-24 14:22:37 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-12-24 14:22:37 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-12-24 14:22:36 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-12-24 14:22:36 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-12-24 14:22:36 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-12-24 14:22:36 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-12-24 14:22:34 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-12-24 14:22:34 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-12-24 14:22:33 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-12-24 14:22:33 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-12-24 14:22:33 ----A---- C:\Windows\system32\xinput1_2.dll
2012-12-24 14:22:33 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-12-24 14:22:32 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2012-12-24 14:22:32 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-12-24 14:22:32 ----A---- C:\Windows\system32\xinput1_1.dll
2012-12-24 14:22:32 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-12-24 14:22:31 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2012-12-24 14:22:31 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-12-24 14:22:14 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2012-12-24 14:22:14 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-12-24 14:22:13 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-12-24 14:22:13 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2012-12-24 14:22:13 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-12-24 14:22:13 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-12-24 14:22:11 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-12-24 14:22:11 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-12-24 14:22:09 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-12-24 14:22:09 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-12-24 14:22:07 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-12-24 14:22:07 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-12-24 14:22:05 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-12-24 14:22:05 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-12-24 14:21:59 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2012-12-24 14:21:59 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-12-24 14:21:56 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-12-24 14:21:56 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-12-24 14:15:47 ----D---- C:\Program Files (x86)\Ubisoft
2012-12-10 18:10:07 ----D---- C:\Users\Ichigo\AppData\Roaming\Philips
2012-12-10 18:09:09 ----D---- C:\Users\Ichigo\AppData\Roaming\Philips-Songbird
2012-12-10 18:08:31 ----D---- C:\Program Files\DIFX
2012-12-10 18:07:08 ----D---- C:\ProgramData\{F0489EF2-D393-4114-85BA-A94D71D89543}
2012-12-10 18:07:08 ----A---- C:\Windows\SYSWOW64\GEARAspi.dll
2012-12-10 18:07:08 ----A---- C:\Windows\SYSWOW64\drivers\GEARAspiWDM.sys
2012-12-10 18:06:56 ----D---- C:\Program Files (x86)\Philips
2012-12-10 18:05:42 ----D---- C:\Philips
2012-12-10 18:05:19 ----D---- C:\Users\Ichigo\AppData\Roaming\InstallShield
2012-12-08 11:13:35 ----RD---- C:\Program Files (x86)\Skype
2012-12-07 21:45:57 ----D---- C:\Users\Ichigo\AppData\Roaming\Youtube Downloader HD
======List of files/folders modified in the last 1 month======
2012-12-29 14:54:55 ----D---- C:\Windows\Prefetch
2012-12-29 14:54:49 ----RD---- C:\Program Files
2012-12-29 14:54:36 ----D---- C:\Windows\Temp
2012-12-29 14:53:22 ----D---- C:\Users\Ichigo\AppData\Roaming\Skype
2012-12-29 14:47:56 ----D---- C:\Windows\System32
2012-12-29 14:47:56 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-29 14:47:55 ----D---- C:\Windows\inf
2012-12-29 14:47:47 ----D---- C:\Users\Ichigo\AppData\Roaming\DAEMON Tools Lite
2012-12-29 14:47:46 ----D---- C:\Program Files (x86)\Steam
2012-12-29 14:47:39 ----D---- C:\Windows\system32\drivers\AVG
2012-12-29 14:47:39 ----D---- C:\ProgramData\MFAData
2012-12-29 14:47:08 ----D---- C:\Users\Ichigo\AppData\Roaming\uTorrent
2012-12-29 14:46:53 ----D---- C:\Windows\Panther
2012-12-29 14:46:52 ----D---- C:\Windows\Minidump
2012-12-29 14:46:52 ----D---- C:\Windows\Logs
2012-12-29 14:46:52 ----D---- C:\Windows\Debug
2012-12-29 14:46:52 ----D---- C:\Windows
2012-12-29 14:44:02 ----D---- C:\Windows\system32\Tasks
2012-12-29 14:41:57 ----D---- C:\Users\Ichigo\AppData\Roaming\Hamachi
2012-12-29 00:44:10 ----HD---- C:\ProgramData
2012-12-28 21:42:59 ----SHD---- C:\System Volume Information
2012-12-27 00:05:21 ----D---- C:\Program Files (x86)\Electronic Arts
2012-12-27 00:05:19 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-26 23:56:19 ----D---- C:\Windows\system32\catroot2
2012-12-26 23:06:25 ----SHD---- C:\Windows\Installer
2012-12-24 22:53:58 ----RD---- C:\Program Files (x86)
2012-12-24 22:50:47 ----D---- C:\Program Files (x86)\The KMPlayer
2012-12-24 14:25:07 ----D---- C:\Windows\SysWOW64
2012-12-24 14:22:31 ----RSD---- C:\Windows\assembly
2012-12-17 19:35:14 ----D---- C:\Program Files (x86)\Google
2012-12-17 19:33:08 ----D---- C:\Windows\Tasks
2012-12-12 19:13:20 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-12-12 19:03:27 ----A---- C:\Windows\system32\mrt.exe
2012-12-12 17:55:05 ----D---- C:\Windows\system32\LogFiles
2012-12-11 17:07:31 ----D---- C:\Program Files (x86)\uTorrent
2012-12-10 18:08:54 ----D---- C:\Windows\system32\catroot
2012-12-10 18:07:09 ----D---- C:\Windows\system32\drivers
2012-12-10 18:07:08 ----D---- C:\Windows\SYSWOW64\drivers
2012-12-08 11:13:42 ----D---- C:\ProgramData\Skype
2012-12-08 11:13:35 ----D---- C:\Program Files (x86)\Common Files
2012-12-07 13:34:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-12-06 16:40:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-11-24 564824]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2012-07-26 291680]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2012-08-24 384352]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-24 283200]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdLH6.sys [2012-02-23 92176]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2011-12-23 124496]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2012-08-12 33344]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 273920]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [2012-05-23 585360]
S3 a25qr7x6;a25qr7x6; C:\Windows\system32\drivers\a25qr7x6.sys []
S3 cpudrv64;cpudrv64; \??\C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-06-02 17864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 6144]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys []
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 11008]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 7936]
S3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 97792]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 166656]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 46080]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 108032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2012-08-13 5167736]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-10-23 2848168]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-12-21 541760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-17 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-12 250808]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-17 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-12-06 115168]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Postupovali jsme podle tohoto návodu přes nouzový režim: http://www.viruskasino.com/2012/10/pozo ... any_6.html
- pomocí Roguekliller...a vir byl odblokován.
Přesto prosím o kontrolu logu. Děkuji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Ichigo at 2012-12-29 14:54:48
Microsoft® Windows Vista™ Home Premium
System drive C: has 292 GB (61%) free of 477 GB
Total RAM: 4095 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:54:55, on 29.12.2012
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal
Running processes:
C:\Users\Ichigo\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Hamachi\hamachi.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
C:\Program Files\trend micro\Ichigo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.speedbit.com/?s=C8Ca205
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Philips Device Listener] "C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ichigo\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [SDP] C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: hamachi.lnk = C:\Program Files (x86)\Hamachi\hamachi.exe
O8 - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8537 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe /pipeName=75f3b461-1c2e-4452-8456-705c232b9568 /coreSdkOptions=286 /logConfFile="C:\ProgramData\AVG2012\temp\75d10949-63c7-4563-ab15-4b0f8f303e4c-1a4-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2012\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2012" /tempPath="C:\ProgramData\AVG2012\temp\"
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Users\Ichigo\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe" /auto
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Hamachi\hamachi.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgemca.exe"
"C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe"
taskeng.exe {2BF31A2E-6780-4D04-8FC9-6937C01D77E3}
taskeng.exe {85332374-9B64-46A5-8935-8B320E2EDD48}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler64.exe"
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot) " "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1340.6a4c400.1686121879 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll" - -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" 1340 "\\.\pipe\gecko-crash-server-pipe.1340" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe" --proxy-stub-channel=Flash4980.67FEB7B8.41 --host-broker-channel=Flash4980.67FEB7B8.18467 --host-pid=4980 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe" --channel=4716.0059F680.1042362934 --proxy-stub-channel=Flash4980.67FEB7B8.41 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll" --host-npapi-version=27 --type=renderer
"C:\Windows\system32\SearchFilterHost.exe" 0 648 652 660 65536 656
"C:\Users\Ichigo\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3021093605-2333013262-3278736194-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3021093605-2333013262-3278736194-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do Not Track - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll [2012-08-13 1393272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll [2012-06-24 1968248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-11-24 537576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-11-24 193512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do Not Track - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll [2012-08-13 938104]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll [2012-06-24 1417336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-11-24 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-11-24 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{687578b9-7132-4a7a-80e4-30ee31099e03}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2012-08-10 1581752]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Ichigo\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-11 116648]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2012-12-04 1354736]
"SDP"=C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe [2012-10-03 201808]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-11-09 17877168]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-07-04 641704]
"AVG_TRAY"=C:\Program Files (x86)\AVG\AVG2012\avgtray.exe [2012-07-31 2596984]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
"Philips Device Listener"=C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe [2012-02-08 380416]
C:\Users\Ichigo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
hamachi.lnk - C:\Program Files (x86)\Hamachi\hamachi.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-12-29 14:54:49 ----D---- C:\Program Files\trend micro
2012-12-29 14:54:48 ----D---- C:\rsit
2012-12-29 14:44:02 ----D---- C:\Program Files\CCleaner
2012-12-29 14:41:29 ----ASH---- C:\hiberfil.sys
2012-12-29 00:44:10 ----A---- C:\ProgramData\dsgsdgdsgdsgw.js
2012-12-26 14:57:43 ----D---- C:\Users\Ichigo\AppData\Roaming\.minecraft
2012-12-24 14:24:05 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-12-24 14:24:05 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-12-24 14:24:05 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-12-24 14:24:05 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-12-24 14:24:04 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-12-24 14:24:04 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-12-24 14:24:01 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-12-24 14:24:01 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-12-24 14:24:01 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-12-24 14:24:01 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-12-24 14:24:00 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-12-24 14:24:00 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-12-24 14:24:00 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-12-24 14:24:00 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-12-24 14:23:59 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-12-24 14:23:59 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-12-24 14:23:58 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-12-24 14:23:58 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-12-24 14:23:58 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-12-24 14:23:58 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-12-24 14:23:58 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-12-24 14:23:58 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-12-24 14:23:57 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-12-24 14:23:57 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-12-24 14:23:57 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-12-24 14:23:57 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-12-24 14:23:56 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-12-24 14:23:56 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-12-24 14:23:55 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-12-24 14:23:55 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-12-24 14:23:52 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-12-24 14:23:52 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-12-24 14:23:51 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-12-24 14:23:51 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-12-24 14:23:51 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-12-24 14:23:51 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-12-24 14:23:48 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-12-24 14:23:48 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-12-24 14:23:45 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-12-24 14:23:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-12-24 14:23:45 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-12-24 14:23:45 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-12-24 14:23:42 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-12-24 14:23:42 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-12-24 14:23:41 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-12-24 14:23:41 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-12-24 14:23:41 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-12-24 14:23:41 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-12-24 14:23:41 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-12-24 14:23:41 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-12-24 14:23:40 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-12-24 14:23:40 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-12-24 14:23:38 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-12-24 14:23:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-12-24 14:23:38 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-12-24 14:23:38 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-12-24 14:23:36 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-12-24 14:23:36 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-12-24 14:23:35 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-12-24 14:23:35 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-12-24 14:23:35 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-12-24 14:23:35 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-12-24 14:23:34 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-12-24 14:23:34 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-12-24 14:23:34 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-12-24 14:23:34 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-12-24 14:23:33 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-12-24 14:23:33 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-12-24 14:23:33 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-12-24 14:23:33 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-12-24 14:23:32 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-12-24 14:23:32 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-12-24 14:23:31 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-12-24 14:23:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-12-24 14:23:31 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-12-24 14:23:31 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-12-24 14:23:28 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-12-24 14:23:28 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-12-24 14:23:26 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-12-24 14:23:26 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-12-24 14:23:26 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-12-24 14:23:26 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-12-24 14:23:26 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-12-24 14:23:26 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-12-24 14:23:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-12-24 14:23:25 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-12-24 14:23:23 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-12-24 14:23:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-12-24 14:23:23 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-12-24 14:23:23 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-12-24 14:23:18 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-12-24 14:23:18 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-12-24 14:23:18 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-12-24 14:23:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-12-24 14:23:17 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-12-24 14:23:17 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-12-24 14:23:17 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-12-24 14:23:17 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-12-24 14:23:14 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-12-24 14:23:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-12-24 14:23:14 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-12-24 14:23:14 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-12-24 14:23:09 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-12-24 14:23:09 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-12-24 14:23:09 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-12-24 14:23:09 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-12-24 14:23:06 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-12-24 14:23:06 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-12-24 14:23:06 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-12-24 14:23:06 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-12-24 14:23:02 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-12-24 14:23:02 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-12-24 14:23:02 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-12-24 14:23:02 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-12-24 14:23:00 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-12-24 14:23:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-12-24 14:23:00 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-12-24 14:23:00 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-12-24 14:22:56 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-12-24 14:22:56 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-12-24 14:22:55 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-12-24 14:22:55 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-12-24 14:22:55 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-12-24 14:22:55 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-12-24 14:22:54 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-12-24 14:22:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-12-24 14:22:54 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-12-24 14:22:54 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-12-24 14:22:49 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2012-12-24 14:22:49 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-12-24 14:22:49 ----A---- C:\Windows\system32\xinput1_3.dll
2012-12-24 14:22:49 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-12-24 14:22:48 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-12-24 14:22:48 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-12-24 14:22:46 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-12-24 14:22:46 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-12-24 14:22:46 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-12-24 14:22:46 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-12-24 14:22:43 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2012-12-24 14:22:43 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-12-24 14:22:42 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-12-24 14:22:42 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-12-24 14:22:41 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-12-24 14:22:41 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-12-24 14:22:40 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-12-24 14:22:40 ----A---- C:\Windows\system32\d3dx10.dll
2012-12-24 14:22:37 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-12-24 14:22:37 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-12-24 14:22:36 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-12-24 14:22:36 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-12-24 14:22:36 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-12-24 14:22:36 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-12-24 14:22:34 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-12-24 14:22:34 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-12-24 14:22:33 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-12-24 14:22:33 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-12-24 14:22:33 ----A---- C:\Windows\system32\xinput1_2.dll
2012-12-24 14:22:33 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-12-24 14:22:32 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2012-12-24 14:22:32 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-12-24 14:22:32 ----A---- C:\Windows\system32\xinput1_1.dll
2012-12-24 14:22:32 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-12-24 14:22:31 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2012-12-24 14:22:31 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-12-24 14:22:14 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2012-12-24 14:22:14 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-12-24 14:22:13 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-12-24 14:22:13 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2012-12-24 14:22:13 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-12-24 14:22:13 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-12-24 14:22:11 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-12-24 14:22:11 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-12-24 14:22:09 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-12-24 14:22:09 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-12-24 14:22:07 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-12-24 14:22:07 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-12-24 14:22:05 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-12-24 14:22:05 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-12-24 14:21:59 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2012-12-24 14:21:59 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-12-24 14:21:56 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-12-24 14:21:56 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-12-24 14:15:47 ----D---- C:\Program Files (x86)\Ubisoft
2012-12-10 18:10:07 ----D---- C:\Users\Ichigo\AppData\Roaming\Philips
2012-12-10 18:09:09 ----D---- C:\Users\Ichigo\AppData\Roaming\Philips-Songbird
2012-12-10 18:08:31 ----D---- C:\Program Files\DIFX
2012-12-10 18:07:08 ----D---- C:\ProgramData\{F0489EF2-D393-4114-85BA-A94D71D89543}
2012-12-10 18:07:08 ----A---- C:\Windows\SYSWOW64\GEARAspi.dll
2012-12-10 18:07:08 ----A---- C:\Windows\SYSWOW64\drivers\GEARAspiWDM.sys
2012-12-10 18:06:56 ----D---- C:\Program Files (x86)\Philips
2012-12-10 18:05:42 ----D---- C:\Philips
2012-12-10 18:05:19 ----D---- C:\Users\Ichigo\AppData\Roaming\InstallShield
2012-12-08 11:13:35 ----RD---- C:\Program Files (x86)\Skype
2012-12-07 21:45:57 ----D---- C:\Users\Ichigo\AppData\Roaming\Youtube Downloader HD
======List of files/folders modified in the last 1 month======
2012-12-29 14:54:55 ----D---- C:\Windows\Prefetch
2012-12-29 14:54:49 ----RD---- C:\Program Files
2012-12-29 14:54:36 ----D---- C:\Windows\Temp
2012-12-29 14:53:22 ----D---- C:\Users\Ichigo\AppData\Roaming\Skype
2012-12-29 14:47:56 ----D---- C:\Windows\System32
2012-12-29 14:47:56 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-29 14:47:55 ----D---- C:\Windows\inf
2012-12-29 14:47:47 ----D---- C:\Users\Ichigo\AppData\Roaming\DAEMON Tools Lite
2012-12-29 14:47:46 ----D---- C:\Program Files (x86)\Steam
2012-12-29 14:47:39 ----D---- C:\Windows\system32\drivers\AVG
2012-12-29 14:47:39 ----D---- C:\ProgramData\MFAData
2012-12-29 14:47:08 ----D---- C:\Users\Ichigo\AppData\Roaming\uTorrent
2012-12-29 14:46:53 ----D---- C:\Windows\Panther
2012-12-29 14:46:52 ----D---- C:\Windows\Minidump
2012-12-29 14:46:52 ----D---- C:\Windows\Logs
2012-12-29 14:46:52 ----D---- C:\Windows\Debug
2012-12-29 14:46:52 ----D---- C:\Windows
2012-12-29 14:44:02 ----D---- C:\Windows\system32\Tasks
2012-12-29 14:41:57 ----D---- C:\Users\Ichigo\AppData\Roaming\Hamachi
2012-12-29 00:44:10 ----HD---- C:\ProgramData
2012-12-28 21:42:59 ----SHD---- C:\System Volume Information
2012-12-27 00:05:21 ----D---- C:\Program Files (x86)\Electronic Arts
2012-12-27 00:05:19 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-26 23:56:19 ----D---- C:\Windows\system32\catroot2
2012-12-26 23:06:25 ----SHD---- C:\Windows\Installer
2012-12-24 22:53:58 ----RD---- C:\Program Files (x86)
2012-12-24 22:50:47 ----D---- C:\Program Files (x86)\The KMPlayer
2012-12-24 14:25:07 ----D---- C:\Windows\SysWOW64
2012-12-24 14:22:31 ----RSD---- C:\Windows\assembly
2012-12-17 19:35:14 ----D---- C:\Program Files (x86)\Google
2012-12-17 19:33:08 ----D---- C:\Windows\Tasks
2012-12-12 19:13:20 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-12-12 19:03:27 ----A---- C:\Windows\system32\mrt.exe
2012-12-12 17:55:05 ----D---- C:\Windows\system32\LogFiles
2012-12-11 17:07:31 ----D---- C:\Program Files (x86)\uTorrent
2012-12-10 18:08:54 ----D---- C:\Windows\system32\catroot
2012-12-10 18:07:09 ----D---- C:\Windows\system32\drivers
2012-12-10 18:07:08 ----D---- C:\Windows\SYSWOW64\drivers
2012-12-08 11:13:42 ----D---- C:\ProgramData\Skype
2012-12-08 11:13:35 ----D---- C:\Program Files (x86)\Common Files
2012-12-07 13:34:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-12-06 16:40:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-11-24 564824]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2012-07-26 291680]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2012-08-24 384352]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-24 283200]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdLH6.sys [2012-02-23 92176]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2011-12-23 124496]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2012-08-12 33344]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 273920]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [2012-05-23 585360]
S3 a25qr7x6;a25qr7x6; C:\Windows\system32\drivers\a25qr7x6.sys []
S3 cpudrv64;cpudrv64; \??\C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-06-02 17864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 6144]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys []
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 11008]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 7936]
S3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 97792]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 166656]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 46080]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 108032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2012-08-13 5167736]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-10-23 2848168]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-12-21 541760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-17 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-12 250808]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-17 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-12-06 115168]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: blokace PC Policií ČR
Zdravim
Este docistime.
Stiahnite na plochu OTL exe .
http://oldtimer.geekstogo.com/OTL.exe
Nastavenie necháme tak ako je, dole do okna vložte tento skript.
A kliknite na gombík OPRAVIŤ.
log vloz sem
Este docistime.
Stiahnite na plochu OTL exe .
http://oldtimer.geekstogo.com/OTL.exe
Nastavenie necháme tak ako je, dole do okna vložte tento skript.
Kód: Vybrat vše
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
"{687578b9-7132-4a7a-80e4-30ee31099e03}"=-
:Files
C:\ProgramData\dsgsdgdsgdsgw.js
ipconfig /flushdns /c
:Commands
[resethosts]
[emptytemp]log vloz sem
Re: blokace PC Policií ČR
All processes killed
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found.
========== FILES ==========
C:\ProgramData\dsgsdgdsgdsgw.js moved successfully.
< ipconfig /flushdns /c >
Konfigurace protokolu IP syst‚mu Windows
MezipamŘś pýekl d nˇ DNS byla ŁspŘçnŘ vypr zdnŘna.
C:\Users\Ichigo\Desktop\cmd.bat deleted successfully.
C:\Users\Ichigo\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: AppData
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Ichigo
->Temp folder emptied: 63586946 bytes
->Temporary Internet Files folder emptied: 691152 bytes
->Java cache emptied: 1166821 bytes
->FireFox cache emptied: 125933695 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 551 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 21538 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 4178040 bytes
Total Files Cleaned = 187,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 12292012_155028
Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z9MV9DQU\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P95SG8MA\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HGUNL4NL\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\48JOK4NS\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found.
========== FILES ==========
C:\ProgramData\dsgsdgdsgdsgw.js moved successfully.
< ipconfig /flushdns /c >
Konfigurace protokolu IP syst‚mu Windows
MezipamŘś pýekl d nˇ DNS byla ŁspŘçnŘ vypr zdnŘna.
C:\Users\Ichigo\Desktop\cmd.bat deleted successfully.
C:\Users\Ichigo\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: AppData
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Ichigo
->Temp folder emptied: 63586946 bytes
->Temporary Internet Files folder emptied: 691152 bytes
->Java cache emptied: 1166821 bytes
->FireFox cache emptied: 125933695 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 551 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 21538 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 4178040 bytes
Total Files Cleaned = 187,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 12292012_155028
Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z9MV9DQU\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P95SG8MA\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HGUNL4NL\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\48JOK4NS\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: blokace PC Policií ČR
Ok, mas este dajaky problem s pc??
Re: blokace PC Policií ČR
Pro dnešek asi vše 
Děkuji moc za pomoc a kontrolu - zatím to vypadá v pořádku
...díky a krásný večer 
Děkuji moc za pomoc a kontrolu - zatím to vypadá v pořádku
,,Poctivost nelze rozdělit na kousky.Buď je a nebo není."(Honoré de Balzac)
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: blokace PC Policií ČR
Nemas zaco.
Re: blokace PC Policií ČR
Dobry den,
dekuji za skvele forum, odkaz na viruskasino s navody na "policajtsky" ransomware. Smejd me taky postihl, postupoval jsem podle Vaseho navodu na viruskasinu. Pouzil jsem RogueKillera, potom jsem jeste manualne v nouzovem rezimu smazal DLL a JS soubory smejda, stahl jsem a spustil adware cleaner, cc cleaner, tds killera ci jak se to jmenuje a ten zbytek doporucenych software, nakonec jsem vycistil cache, zrusil obnovu systemu, restartoval, obnovil obnovu systemu. Vse se zda byt OK.
V tomto foru jsem si vsak precetl o "docisteni" pomoci OTL a nejakeho scriptu. Je toto jeste nutne provest, pokud jsem provedl cisteni a opravu registru pomoci CC Cleaneru?
Dekuji a zdravim,
matvit
dekuji za skvele forum, odkaz na viruskasino s navody na "policajtsky" ransomware. Smejd me taky postihl, postupoval jsem podle Vaseho navodu na viruskasinu. Pouzil jsem RogueKillera, potom jsem jeste manualne v nouzovem rezimu smazal DLL a JS soubory smejda, stahl jsem a spustil adware cleaner, cc cleaner, tds killera ci jak se to jmenuje a ten zbytek doporucenych software, nakonec jsem vycistil cache, zrusil obnovu systemu, restartoval, obnovil obnovu systemu. Vse se zda byt OK.
V tomto foru jsem si vsak precetl o "docisteni" pomoci OTL a nejakeho scriptu. Je toto jeste nutne provest, pokud jsem provedl cisteni a opravu registru pomoci CC Cleaneru?
Dekuji a zdravim,
matvit
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: blokace PC Policií ČR
Ano, nezaskodi vycistit s OTL,Hosts,medzi pamat, Temp, a cache, prehliadacov, pretoze tento smejd je stale aktualizovany, a nikdy nevies ze kde a co namontoval do systemu.
Mozes spustit OTL s tymto scriptom.
Stiahnite na plochu OTL exe
http://oldtimer.geekstogo.com/OTL.exe
Spust, do le do okna vloz tento script.
A klikni na tlacitko RUNFIX
Log vloz sem.
Mozes spustit OTL s tymto scriptom.
Stiahnite na plochu OTL exe
http://oldtimer.geekstogo.com/OTL.exe
Spust, do le do okna vloz tento script.
A klikni na tlacitko RUNFIX
Log vloz sem.
Kód: Vybrat vše
:Files
ipconfig /flushdns /c
:Commands
[resethosts]
[emptytemp]


Přispějete na provoz fóra?