Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

system jde pustit jen v nouzovem rezimu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
kazatel
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 led 2013 23:26

system jde pustit jen v nouzovem rezimu

#1 Příspěvek od kazatel »

Dobry den systém jde spustit jen v nouzovém režimu. :(
Tady je log z Rsitu.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Katka at 2013-01-26 16:36:53
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 289 GB (95%) free of 305 GB
Total RAM: 3071 MB (83% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:37:01, on 26.1.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Katka\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe
c:\users\katka\appdata\local\temp\teamviewer\version8\TeamViewer_Desktop.exe
C:\Users\Katka\Desktop\RSIT.exe
C:\Program Files\trend micro\Katka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - (no file)
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Scrybe.lnk = ?
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2D737F8-C9B8-4306-9231-13360B9EE1E8}: NameServer = 62.240.178.250,10.0.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: ICQ Service - Unknown owner - C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Aktualizátor aplikace Scrybe (ScrybeUpdater) - Synaptics, Inc. - C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 5293 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\PerfectOptimizer_home.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-16 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-01-16 192144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll [2013-01-16 1000984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-16 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-01-16 192144]
{855F3B16-6D32-4FE6-8A56-BBB695989046}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2001-04-13 94208]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2001-04-13 262144]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2012-12-14 2255360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2013-01-16 39408]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-01-08 18705664]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Scrybe.lnk - C:\Windows\Installer\{147DFAD8-34C3-4DE1-9FCA-ACEFDE9EF810}\NewShortcut11_8ACB210B42E44145A8C31F8E3DD765A3.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=serwvdrv.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-01-26 16:36:53 ----D---- C:\rsit
2013-01-26 16:36:53 ----D---- C:\Program Files\trend micro
2013-01-26 16:30:39 ----A---- C:\Windows\ntbtlog.txt
2013-01-25 18:09:38 ----D---- C:\Program Files\LogMeIn Hamachi
2013-01-24 09:05:35 ----D---- C:\Windows\Minidump
2013-01-19 23:21:33 ----D---- C:\Program Files\Perfect Optimizer
2013-01-19 22:49:38 ----D---- C:\Users\Katka\AppData\Roaming\Malwarebytes
2013-01-19 22:49:26 ----D---- C:\ProgramData\Malwarebytes
2013-01-19 22:49:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2013-01-19 22:49:25 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-01-18 23:39:44 ----D---- C:\Users\Katka\AppData\Roaming\TS3Client
2013-01-18 23:37:34 ----D---- C:\Program Files\TeamSpeak 3 Client
2013-01-17 21:06:16 ----D---- C:\Program Files\GridinSoft Trojan Killer
2013-01-17 01:21:22 ----A---- C:\Windows\ATKPF.ini
2013-01-17 01:11:35 ----D---- C:\9fea79ebc73b65699e21263d4524b994
2013-01-17 01:01:58 ----A---- C:\Windows\system32\ACEngSvr.exe
2013-01-17 01:01:50 ----D---- C:\Program Files\ASUS
2013-01-17 00:52:11 ----N---- C:\Windows\system32\agrsmdel.exe
2013-01-17 00:52:05 ----D---- C:\Program Files\LSI SoftModem
2013-01-17 00:50:08 ----N---- C:\Windows\system32\agrscoin.dll
2013-01-17 00:50:08 ----A---- C:\Windows\system32\drivers\AGRSM.sys
2013-01-17 00:50:08 ----A---- C:\Windows\agrsmdel.exe
2013-01-17 00:28:09 ----A---- C:\Windows\system32\snymsico.dll
2013-01-17 00:28:09 ----A---- C:\Windows\system32\drivers\rimsptsk.sys
2013-01-17 00:28:09 ----A---- C:\Windows\system32\drivers\rimmptsk.sys
2013-01-17 00:18:27 ----D---- C:\Program Files\Common Files\InstallShield
2013-01-16 23:15:08 ----D---- C:\33e28797011ee554cf412a10
2013-01-16 22:23:19 ----D---- C:\c482ad52215ca717189f2511b8
2013-01-16 22:20:19 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2013-01-16 22:20:19 ----A---- C:\Windows\system32\drivers\bthport.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\fsutil.exe
2013-01-16 22:20:10 ----A---- C:\Windows\system32\esent.dll
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\storport.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\nvstor.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\nvraid.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\amdxata.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\amdsata.sys
2013-01-16 22:19:51 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2013-01-16 22:19:51 ----A---- C:\Windows\system32\drivers\usbport.sys
2013-01-16 22:19:51 ----A---- C:\Windows\system32\drivers\usbhub.sys
2013-01-16 22:19:51 ----A---- C:\Windows\system32\drivers\usbehci.sys
2013-01-16 22:19:50 ----A---- C:\Windows\system32\drivers\usbohci.sys
2013-01-16 22:19:50 ----A---- C:\Windows\system32\drivers\usbd.sys
2013-01-16 22:19:50 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2013-01-16 22:13:01 ----D---- C:\Firefox
2013-01-16 22:02:35 ----D---- C:\ProgramData\Ask
2013-01-16 22:02:34 ----D---- C:\ProgramData\Sun
2013-01-16 22:02:33 ----D---- C:\Program Files\Common Files\Java
2013-01-16 22:02:15 ----A---- C:\Windows\system32\npDeployJava1.dll
2013-01-16 22:02:15 ----A---- C:\Windows\system32\javaws.exe
2013-01-16 22:02:15 ----A---- C:\Windows\system32\deployJava1.dll
2013-01-16 22:02:04 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2013-01-16 22:02:04 ----A---- C:\Windows\system32\javaw.exe
2013-01-16 22:02:04 ----A---- C:\Windows\system32\java.exe
2013-01-16 22:01:51 ----D---- C:\Program Files\Java
2013-01-16 21:54:35 ----D---- C:\Users\Katka\AppData\Roaming\.minecraft
2013-01-16 17:53:27 ----D---- C:\Program Files\Microsoft.NET
2013-01-16 17:17:19 ----D---- C:\Program Files\AuthenTec
2013-01-16 17:17:09 ----A---- C:\Windows\IsUninst.exe
2013-01-16 17:14:58 ----A---- C:\Windows\system32\MRT.exe
2013-01-16 17:14:10 ----A---- C:\Windows\system32\SynTPFcs.dll
2013-01-16 17:14:10 ----A---- C:\Windows\system32\SynTPCoI.dll
2013-01-16 17:14:10 ----A---- C:\Windows\system32\SynTPAPI.dll
2013-01-16 17:14:10 ----A---- C:\Windows\system32\drivers\SynTP.sys
2013-01-16 17:14:09 ----D---- C:\dell
2013-01-16 17:03:47 ----D---- C:\Users\Katka\AppData\Roaming\WinRAR
2013-01-16 17:03:30 ----D---- C:\Program Files\WinRAR
2013-01-16 17:02:35 ----D---- C:\ProgramData\Synaptics
2013-01-16 17:02:35 ----D---- C:\Program Files\Synaptics
2013-01-16 16:59:19 ----D---- C:\Program Files\CCleaner
2013-01-16 16:50:51 ----D---- C:\Users\Katka\AppData\Roaming\TeamViewer
2013-01-16 16:45:15 ----D---- C:\ProgramData\ICQ
2013-01-16 16:45:04 ----D---- C:\Users\Katka\AppData\Roaming\ICQ
2013-01-16 16:44:59 ----D---- C:\Program Files\ICQ7M
2013-01-16 16:39:13 ----D---- C:\Users\Katka\AppData\Roaming\Skype
2013-01-16 16:39:00 ----D---- C:\Program Files\Common Files\Skype
2013-01-16 16:38:59 ----RD---- C:\Program Files\Skype
2013-01-16 16:38:41 ----D---- C:\ProgramData\Skype
2013-01-16 16:30:20 ----A---- C:\Windows\system32\FntCache.dll
2013-01-16 16:30:20 ----A---- C:\Windows\system32\d2d1.dll
2013-01-16 15:56:25 ----D---- C:\Windows\system32\Wat
2013-01-16 15:52:41 ----A---- C:\Windows\system32\fontsub.dll
2013-01-16 15:52:41 ----A---- C:\Windows\system32\atmlib.dll
2013-01-16 15:52:41 ----A---- C:\Windows\system32\atmfd.dll
2013-01-16 15:20:46 ----A---- C:\Windows\system32\Wdfres.dll
2013-01-16 15:20:46 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2013-01-16 15:20:46 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2013-01-16 15:19:37 ----A---- C:\Windows\system32\WUDFSvc.dll
2013-01-16 15:19:37 ----A---- C:\Windows\system32\WUDFPlatform.dll
2013-01-16 15:19:37 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2013-01-16 15:19:37 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2013-01-16 15:19:36 ----A---- C:\Windows\system32\WUDFx.dll
2013-01-16 15:19:36 ----A---- C:\Windows\system32\WUDFHost.exe
2013-01-16 15:19:36 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2013-01-16 15:18:38 ----A---- C:\Windows\system32\wmi.dll
2013-01-16 15:18:38 ----A---- C:\Windows\system32\imagehlp.dll
2013-01-16 15:18:38 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2013-01-16 15:16:29 ----A---- C:\Windows\system32\wininet.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\wextract.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\webcheck.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\vbscript.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\urlmon.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\url.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\pngfilt.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\occache.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msrating.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msls31.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\mshtmler.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\mshtmled.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\mshtml.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\mshta.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msfeedssync.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msfeeds.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\licmgr10.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\jsproxy.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\jscript9.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\jscript.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\inseng.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\imgutil.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iexpress.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieUnatt.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieui.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iesysprep.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iesetup.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iertutil.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iernonce.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iepeers.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieframe.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iedkcs32.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieapfltr.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieapfltr.dat
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieakui.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieaksie.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieakeng.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ie4uinit.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\icardie.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\dxtrans.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\dxtmsft.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\admparse.dll
2013-01-16 15:14:54 ----A---- C:\Windows\system32\browserchoice.exe
2013-01-16 14:54:23 ----A---- C:\Windows\system32\spoolsv.exe
2013-01-16 14:54:20 ----A---- C:\Windows\system32\usp10.dll
2013-01-16 14:54:18 ----A---- C:\Windows\system32\win32k.sys
2013-01-16 14:54:16 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2013-01-16 14:54:16 ----A---- C:\Windows\system32\drivers\ndis.sys
2013-01-16 14:54:09 ----A---- C:\Windows\system32\drivers\srvnet.sys
2013-01-16 14:54:09 ----A---- C:\Windows\system32\drivers\srv2.sys
2013-01-16 14:54:09 ----A---- C:\Windows\system32\drivers\srv.sys
2013-01-16 14:54:07 ----A---- C:\Windows\system32\drivers\afd.sys
2013-01-16 14:54:04 ----D---- C:\Windows\Options
2013-01-16 14:54:02 ----A---- C:\Windows\system32\ntdll.dll
2013-01-16 14:54:00 ----A---- C:\Windows\system32\wintrust.dll
2013-01-16 14:53:56 ----A---- C:\Windows\system32\dpnet.dll
2013-01-16 14:53:53 ----A---- C:\Windows\system32\xmllite.dll
2013-01-16 14:53:41 ----A---- C:\Windows\system32\prevhost.exe
2013-01-16 14:53:27 ----A---- C:\Windows\system32\win32spl.dll
2013-01-16 14:53:24 ----A---- C:\Windows\system32\dnsrslvr.dll
2013-01-16 14:53:24 ----A---- C:\Windows\system32\dnscacheugc.exe
2013-01-16 14:53:24 ----A---- C:\Windows\system32\dnsapi.dll
2013-01-16 14:53:03 ----A---- C:\Windows\system32\cryptsvc.dll
2013-01-16 14:53:03 ----A---- C:\Windows\system32\cryptnet.dll
2013-01-16 14:53:03 ----A---- C:\Windows\system32\crypt32.dll
2013-01-16 14:52:58 ----A---- C:\Windows\system32\OxpsConverter.exe
2013-01-16 14:52:55 ----A---- C:\Windows\system32\psisdecd.dll
2013-01-16 14:52:52 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2013-01-16 14:52:50 ----A---- C:\Windows\system32\umpnpmgr.dll
2013-01-16 14:52:49 ----A---- C:\Windows\system32\schannel.dll
2013-01-16 14:52:49 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-01-16 14:52:49 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-01-16 14:52:49 ----A---- C:\Windows\system32\drivers\cng.sys
2013-01-16 14:52:47 ----A---- C:\Windows\system32\msxml3r.dll
2013-01-16 14:52:47 ----A---- C:\Windows\system32\msxml3.dll
2013-01-16 14:52:46 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2013-01-16 14:52:46 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2013-01-16 14:52:46 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2013-01-16 14:52:45 ----A---- C:\Windows\system32\oleaut32.dll
2013-01-16 14:52:45 ----A---- C:\Windows\system32\oleacc.dll
2013-01-16 14:52:39 ----A---- C:\Windows\system32\msxml6.dll
2013-01-16 14:52:37 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-01-16 14:52:30 ----A---- C:\Windows\system32\inetcomm.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\nlasvc.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\nlaapi.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\netevent.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\netcorehc.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\ncsi.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\iphlpsvc.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-01-16 14:52:17 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-01-16 14:52:17 ----A---- C:\Windows\system32\drivers\netio.sys
2013-01-16 14:52:17 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-01-16 14:52:10 ----A---- C:\Windows\system32\packager.dll
2013-01-16 14:52:04 ----A---- C:\Windows\system32\kernel32.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-16 14:52:03 ----A---- C:\Windows\system32\winsrv.dll
2013-01-16 14:52:03 ----A---- C:\Windows\system32\KernelBase.dll
2013-01-16 14:52:03 ----A---- C:\Windows\system32\conhost.exe
2013-01-16 14:52:02 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-16 14:52:02 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-16 14:52:02 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-16 14:51:56 ----A---- C:\Windows\system32\tquery.dll
2013-01-16 14:51:56 ----A---- C:\Windows\system32\SearchIndexer.exe
2013-01-16 14:51:56 ----A---- C:\Windows\system32\mssrch.dll
2013-01-16 14:51:55 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2013-01-16 14:51:55 ----A---- C:\Windows\system32\SearchFilterHost.exe
2013-01-16 14:51:55 ----A---- C:\Windows\system32\mssvp.dll
2013-01-16 14:51:55 ----A---- C:\Windows\system32\mssphtb.dll
2013-01-16 14:51:55 ----A---- C:\Windows\system32\mssph.dll
2013-01-16 14:51:55 ----A---- C:\Windows\system32\msscntrs.dll
2013-01-16 14:51:49 ----A---- C:\Windows\system32\cdosys.dll
2013-01-16 14:51:41 ----A---- C:\Windows\system32\FXSCOVER.exe
2013-01-16 14:51:39 ----A---- C:\Windows\system32\srcore.dll
2013-01-16 14:51:37 ----A---- C:\Windows\system32\EncDec.dll
2013-01-16 14:51:35 ----A---- C:\Windows\system32\netapi32.dll
2013-01-16 14:51:35 ----A---- C:\Windows\system32\browser.dll
2013-01-16 14:51:35 ----A---- C:\Windows\system32\browcli.dll
2013-01-16 14:51:33 ----A---- C:\Windows\system32\XpsPrint.dll
2013-01-16 14:51:31 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-01-16 14:51:30 ----A---- C:\Windows\system32\csrsrv.dll
2013-01-16 14:51:29 ----A---- C:\Windows\system32\sbe.dll
2013-01-16 14:51:29 ----A---- C:\Windows\system32\CPFilters.dll
2013-01-16 14:51:27 ----A---- C:\Windows\system32\quartz.dll
2013-01-16 14:51:27 ----A---- C:\Windows\system32\qdvd.dll
2013-01-16 14:51:21 ----A---- C:\Windows\system32\kerberos.dll
2013-01-16 14:51:17 ----A---- C:\Windows\explorer.exe
2013-01-16 14:51:12 ----D---- C:\Program Files\ATI Technologies
2013-01-16 14:51:12 ----A---- C:\Windows\system32\ntkrnlpa.exe
2013-01-16 14:51:11 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-01-16 14:51:10 ----A---- C:\Windows\system32\msi.dll
2013-01-16 14:51:09 ----A---- C:\Windows\system32\d3d10level9.dll
2013-01-16 14:51:08 ----D---- C:\Program Files\ATI
2013-01-16 14:50:56 ----A---- C:\Windows\system32\gameux.dll
2013-01-16 14:50:55 ----A---- C:\Windows\system32\Wpc.dll
2013-01-16 14:50:50 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\webio.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\sspisrv.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\sspicli.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\secur32.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\lsass.exe
2013-01-16 14:50:49 ----A---- C:\Windows\system32\lsasrv.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbctrac.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbcjt32.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbccu32.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbccr32.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbccp32.dll
2013-01-16 14:50:47 ----A---- C:\Windows\system32\d3d10_1.dll
2013-01-16 14:50:46 ----A---- C:\Windows\system32\rdrmemptylst.exe
2013-01-16 14:50:46 ----A---- C:\Windows\system32\rdpwsx.dll
2013-01-16 14:50:46 ----A---- C:\Windows\system32\rdpcorekmts.dll
2013-01-16 14:50:45 ----A---- C:\Windows\system32\msvcrt.dll
2013-01-16 14:50:43 ----A---- C:\Windows\system32\drivers\partmgr.sys
2013-01-16 14:50:41 ----A---- C:\Windows\system32\profsvc.dll
2013-01-16 14:50:39 ----A---- C:\Windows\system32\synceng.dll
2013-01-16 14:50:36 ----A---- C:\Windows\system32\localspl.dll
2013-01-16 14:50:31 ----A---- C:\Windows\system32\ntshrui.dll
2013-01-16 14:50:30 ----A---- C:\Windows\system32\taskhost.exe
2013-01-16 14:50:29 ----A---- C:\Windows\system32\DWrite.dll
2013-01-16 14:50:27 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2013-01-16 14:50:27 ----A---- C:\Windows\system32\dhcpcore6.dll
2013-01-16 14:50:23 ----A---- C:\Windows\system32\mfc42u.dll
2013-01-16 14:50:23 ----A---- C:\Windows\system32\mfc42.dll
2013-01-16 14:50:13 ----A---- C:\Windows\system32\drivers\bowser.sys
2013-01-16 14:50:11 ----A---- C:\Windows\system32\shell32.dll
2013-01-16 14:50:09 ----A---- C:\Windows\system32\poqexec.exe
2013-01-16 14:50:09 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2013-01-16 14:47:14 ----D---- C:\Program Files\Realtek
2013-01-16 14:47:14 ----A---- C:\Windows\system32\SET6F3A.tmp
2013-01-16 14:47:14 ----A---- C:\Windows\system32\SET6EAC.tmp
2013-01-16 14:47:14 ----A---- C:\Windows\system32\RTNUninst32.dll
2013-01-16 14:47:14 ----A---- C:\Windows\system32\RtNicProp32.dll
2013-01-16 14:47:13 ----D---- C:\Program Files\InstallShield Installation Information
2013-01-16 14:36:26 ----A---- C:\Windows\system32\tzres.dll
2013-01-16 14:35:59 ----N---- C:\Windows\system32\MpSigStub.exe
2013-01-16 14:35:30 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-01-16 14:32:59 ----A---- C:\Windows\system32\rdpcore.dll
2013-01-16 14:32:59 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2013-01-16 14:31:29 ----D---- C:\Users\Katka\AppData\Roaming\Macromedia
2013-01-16 14:31:27 ----D---- C:\Users\Katka\AppData\Roaming\Adobe
2013-01-16 14:31:26 ----D---- C:\Users\Katka\AppData\Roaming\Google
2013-01-16 14:30:29 ----D---- C:\ProgramData\Google
2013-01-16 14:30:23 ----SHD---- C:\Windows\Installer
2013-01-16 14:30:17 ----D---- C:\Program Files\Google
2013-01-16 14:30:12 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-01-16 14:30:11 ----D---- C:\Windows\system32\Macromed
2013-01-16 14:29:41 ----D---- C:\ProgramData\Adobe
2013-01-16 14:29:00 ----A---- C:\Windows\system32\wups2.dll
2013-01-16 14:29:00 ----A---- C:\Windows\system32\wucltux.dll
2013-01-16 14:29:00 ----A---- C:\Windows\system32\wuauclt.exe
2013-01-16 14:28:59 ----A---- C:\Windows\system32\wuaueng.dll
2013-01-16 14:28:52 ----A---- C:\Windows\system32\wups.dll
2013-01-16 14:28:52 ----A---- C:\Windows\system32\wudriver.dll
2013-01-16 14:28:51 ----A---- C:\Windows\system32\wuapi.dll
2013-01-16 14:28:41 ----A---- C:\Windows\system32\wuwebv.dll
2013-01-16 14:28:41 ----A---- C:\Windows\system32\wuapp.exe
2013-01-16 14:18:31 ----D---- C:\Users\Katka\AppData\Roaming\Identities
2013-01-16 14:18:20 ----D---- C:\Users\Katka\AppData\Roaming\Media Center Programs
2013-01-16 14:18:19 ----SD---- C:\Users\Katka\AppData\Roaming\Microsoft
2013-01-16 14:18:06 ----SHD---- C:\Recovery
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Šablony
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Plocha
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Oblíbené položky
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Nabídka Start
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Dokumenty
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Data aplikací
2013-01-16 14:13:06 ----D---- C:\Windows\SoftwareDistribution
2013-01-16 14:10:59 ----D---- C:\Windows\Prefetch
2013-01-16 14:10:06 ----SHD---- C:\System Volume Information
2013-01-16 14:10:06 ----ASH---- C:\pagefile.sys
2013-01-16 14:10:05 ----ASH---- C:\hiberfil.sys
2013-01-16 14:08:46 ----D---- C:\Windows\Panther

======List of files/folders modified in the last 1 month======

2013-01-26 16:36:53 ----RD---- C:\Program Files
2013-01-26 16:36:53 ----D---- C:\Windows\Temp
2013-01-26 16:30:39 ----D---- C:\Windows
2013-01-26 16:27:17 ----D---- C:\Windows\system32\config
2013-01-26 16:27:14 ----D---- C:\Windows\Tasks
2013-01-26 16:27:14 ----D---- C:\Windows\system32\wfp
2013-01-26 16:27:14 ----D---- C:\Windows\system32\DriverStore
2013-01-26 16:27:14 ----D---- C:\Windows\system32\catroot2
2013-01-26 16:27:14 ----D---- C:\Windows\System32
2013-01-26 16:27:11 ----D---- C:\Windows\registration
2013-01-25 18:09:40 ----D---- C:\Windows\system32\drivers
2013-01-25 09:03:09 ----D---- C:\Windows\system32\LogFiles
2013-01-25 02:41:00 ----D---- C:\Windows\rescache
2013-01-23 17:47:14 ----D---- C:\Windows\inf
2013-01-22 08:24:16 ----D---- C:\Windows\LiveKernelReports
2013-01-19 23:05:44 ----D---- C:\Windows\schemas
2013-01-19 22:49:26 ----D---- C:\ProgramData
2013-01-19 20:36:35 ----D---- C:\Windows\Logs
2013-01-19 20:36:35 ----D---- C:\Windows\debug
2013-01-19 20:22:29 ----D---- C:\Windows\system32\NDF
2013-01-19 20:04:51 ----D---- C:\Windows\winsxs
2013-01-19 20:04:29 ----D---- C:\Windows\system32\cs-CZ
2013-01-19 08:11:35 ----D---- C:\Windows\system32\wdi
2013-01-19 03:55:28 ----RSD---- C:\Windows\assembly
2013-01-19 03:55:28 ----D---- C:\Windows\Microsoft.NET
2013-01-18 18:49:44 ----D---- C:\Windows\system32\catroot
2013-01-18 18:24:50 ----D---- C:\Windows\system32\Tasks
2013-01-18 00:23:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-17 23:19:19 ----D---- C:\Windows\system32\drivers\etc
2013-01-17 00:18:27 ----D---- C:\Program Files\Common Files
2013-01-16 23:53:18 ----SD---- C:\ProgramData\Microsoft
2013-01-16 18:19:15 ----D---- C:\Windows\system32\wbem
2013-01-16 18:17:43 ----D---- C:\Windows\PolicyDefinitions
2013-01-16 17:53:28 ----D---- C:\Windows\system32\en-US
2013-01-16 17:17:19 ----D---- C:\Windows\system32\WinBioPlugIns
2013-01-16 17:12:24 ----D---- C:\Windows\Resources
2013-01-16 15:56:55 ----D---- C:\Program Files\Common Files\System
2013-01-16 15:56:53 ----D---- C:\Windows\AppPatch
2013-01-16 15:56:52 ----RSD---- C:\Windows\Fonts
2013-01-16 15:56:52 ----D---- C:\Windows\ehome
2013-01-16 15:56:50 ----D---- C:\Program Files\Windows Journal
2013-01-16 15:56:47 ----D---- C:\Windows\system32\migration
2013-01-16 15:56:40 ----D---- C:\Windows\system32\drivers\cs-CZ
2013-01-16 15:56:37 ----D---- C:\Program Files\Internet Explorer
2013-01-16 14:51:44 ----D---- C:\Program Files\Common Files\microsoft shared
2013-01-16 14:27:15 ----D---- C:\Windows\system32\restore
2013-01-16 14:25:24 ----D---- C:\Windows\system32\CodeIntegrity
2013-01-16 14:19:06 ----D---- C:\Windows\system32\drivers\UMDF
2013-01-16 14:18:29 ----SHD---- C:\$Recycle.Bin
2013-01-16 14:18:19 ----RD---- C:\Users
2013-01-16 14:18:06 ----D---- C:\Windows\system32\Recovery
2013-01-16 14:18:06 ----D---- C:\Program Files\Windows NT
2013-01-16 14:15:53 ----D---- C:\Windows\system32\oobe
2013-01-16 14:14:09 ----D---- C:\Windows\system32\sysprep
2013-01-16 14:08:11 ----D---- C:\Windows\Setup

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2011-06-27 2191872]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2001-04-13 229168]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 30720]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-06-25 48128]
S2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-06-25 44544]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-06-11 1161664]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
S3 ATSwpWDF;AuthenTec TruePrint WBF Driver; C:\Windows\system32\DRIVERS\ATSwpWDF.sys [2012-08-30 969192]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2012-12-14 21104]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2009-07-14 18432]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-20 84992]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2012-12-14 1436160]
S2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-03-27 14336]
S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-16 136176]
S2 ICQ Service;ICQ Service; C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE []
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
S2 ScrybeUpdater;Aktualizátor aplikace Scrybe; C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe [2011-05-27 1300264]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-01-08 161536]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-21 251400]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-16 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-01-16 194032]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-16 1343400]
S4 TlntSvr;@%SystemRoot%\system32\tlntsvr.exe,-119; C:\Windows\System32\tlntsvr.exe [2009-07-14 71680]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119524
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: system jde pustit jen v nouzovem rezimu

#2 Příspěvek od Rudy »

Zdravím!
Nejprve zkuste obnovu systému k datu, kdy korektně fungoval.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kazatel
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 led 2013 23:26

Re: system jde pustit jen v nouzovem rezimu

#3 Příspěvek od kazatel »

Odzkoušeno nic :(

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119524
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: system jde pustit jen v nouzovem rezimu

#4 Příspěvek od Rudy »

OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Google\Google Toolbar
C:\Program Files\Google\GoogleToolbarNotifier
C:\PROGRA~1\ICQ6TO~1
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Installer\{147DFAD8-34C3-4DE1-9FCA-ACEFDE9EF810}\NewShortcut11_8ACB210B42E44145A8C31F8E3DD765A3.exe
C:\ProgramData\Ask
C:\Windows\system32\SET6F3A.tmp
C:\Windows\system32\SET6F3A.tmp

:services
ICQ Service

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kazatel
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 led 2013 23:26

Re: system jde pustit jen v nouzovem rezimu

#5 Příspěvek od kazatel »

nový log z RSitu

Logfile of random's system information tool 1.09 (written by random/random)
Run by Katka at 2013-01-26 20:11:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 290 GB (95%) free of 305 GB
Total RAM: 3071 MB (83% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:11:22, on 26.1.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Users\Katka\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\Skype\Phone\Skype.exe
c:\users\katka\appdata\local\temp\teamviewer\version8\TeamViewer_Desktop.exe
C:\Users\Katka\Desktop\RSIT.exe
C:\Program Files\trend micro\Katka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - Global Startup: Scrybe.lnk = ?
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2D737F8-C9B8-4306-9231-13360B9EE1E8}: NameServer = 62.240.178.250,10.0.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Aktualizátor aplikace Scrybe (ScrybeUpdater) - Synaptics, Inc. - C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 4167 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\PerfectOptimizer_home.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-16 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-16 170912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2001-04-13 94208]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2001-04-13 262144]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2012-12-14 2255360]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""= []
"GrpConv"=grpconv -o []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-01-08 18705664]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Scrybe.lnk - C:\Windows\Installer\{147DFAD8-34C3-4DE1-9FCA-ACEFDE9EF810}\NewShortcut11_8ACB210B42E44145A8C31F8E3DD765A3.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=serwvdrv.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-01-26 20:01:55 ----D---- C:\_OTM
2013-01-26 19:00:29 ----SHD---- C:\$RECYCLE.BIN
2013-01-26 18:16:31 ----SD---- C:\ComboFix
2013-01-26 17:26:42 ----A---- C:\Windows\zip.exe
2013-01-26 17:26:42 ----A---- C:\Windows\SWSC.exe
2013-01-26 17:26:42 ----A---- C:\Windows\SWREG.exe
2013-01-26 17:26:42 ----A---- C:\Windows\sed.exe
2013-01-26 17:26:42 ----A---- C:\Windows\PEV.exe
2013-01-26 17:26:42 ----A---- C:\Windows\NIRCMD.exe
2013-01-26 17:26:42 ----A---- C:\Windows\MBR.exe
2013-01-26 17:26:42 ----A---- C:\Windows\grep.exe
2013-01-26 17:26:34 ----D---- C:\Qoobox
2013-01-26 17:26:20 ----D---- C:\Windows\erdnt
2013-01-26 16:36:53 ----D---- C:\rsit
2013-01-26 16:36:53 ----D---- C:\Program Files\trend micro
2013-01-26 16:30:39 ----A---- C:\Windows\ntbtlog.txt
2013-01-25 18:09:38 ----D---- C:\Program Files\LogMeIn Hamachi
2013-01-24 09:05:35 ----D---- C:\Windows\Minidump
2013-01-19 23:21:33 ----D---- C:\Program Files\Perfect Optimizer
2013-01-19 22:49:38 ----D---- C:\Users\Katka\AppData\Roaming\Malwarebytes
2013-01-19 22:49:26 ----D---- C:\ProgramData\Malwarebytes
2013-01-19 22:49:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2013-01-19 22:49:25 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-01-18 23:39:44 ----D---- C:\Users\Katka\AppData\Roaming\TS3Client
2013-01-18 23:37:34 ----D---- C:\Program Files\TeamSpeak 3 Client
2013-01-17 21:06:16 ----D---- C:\Program Files\GridinSoft Trojan Killer
2013-01-17 01:21:22 ----A---- C:\Windows\ATKPF.ini
2013-01-17 01:11:35 ----D---- C:\9fea79ebc73b65699e21263d4524b994
2013-01-17 01:01:58 ----A---- C:\Windows\system32\ACEngSvr.exe
2013-01-17 01:01:50 ----D---- C:\Program Files\ASUS
2013-01-17 00:52:11 ----N---- C:\Windows\system32\agrsmdel.exe
2013-01-17 00:52:05 ----D---- C:\Program Files\LSI SoftModem
2013-01-17 00:50:08 ----N---- C:\Windows\system32\agrscoin.dll
2013-01-17 00:50:08 ----A---- C:\Windows\system32\drivers\AGRSM.sys
2013-01-17 00:50:08 ----A---- C:\Windows\agrsmdel.exe
2013-01-17 00:28:09 ----A---- C:\Windows\system32\snymsico.dll
2013-01-17 00:28:09 ----A---- C:\Windows\system32\drivers\rimsptsk.sys
2013-01-17 00:28:09 ----A---- C:\Windows\system32\drivers\rimmptsk.sys
2013-01-17 00:18:27 ----D---- C:\Program Files\Common Files\InstallShield
2013-01-16 23:15:08 ----D---- C:\33e28797011ee554cf412a10
2013-01-16 22:23:19 ----D---- C:\c482ad52215ca717189f2511b8
2013-01-16 22:20:19 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2013-01-16 22:20:19 ----A---- C:\Windows\system32\drivers\bthport.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\fsutil.exe
2013-01-16 22:20:10 ----A---- C:\Windows\system32\esent.dll
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\storport.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\nvstor.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\nvraid.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\amdxata.sys
2013-01-16 22:20:10 ----A---- C:\Windows\system32\drivers\amdsata.sys
2013-01-16 22:19:51 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2013-01-16 22:19:51 ----A---- C:\Windows\system32\drivers\usbport.sys
2013-01-16 22:19:51 ----A---- C:\Windows\system32\drivers\usbhub.sys
2013-01-16 22:19:51 ----A---- C:\Windows\system32\drivers\usbehci.sys
2013-01-16 22:19:50 ----A---- C:\Windows\system32\drivers\usbohci.sys
2013-01-16 22:19:50 ----A---- C:\Windows\system32\drivers\usbd.sys
2013-01-16 22:19:50 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2013-01-16 22:13:01 ----D---- C:\Firefox
2013-01-16 22:02:34 ----D---- C:\ProgramData\Sun
2013-01-16 22:02:33 ----D---- C:\Program Files\Common Files\Java
2013-01-16 22:02:15 ----A---- C:\Windows\system32\npDeployJava1.dll
2013-01-16 22:02:15 ----A---- C:\Windows\system32\javaws.exe
2013-01-16 22:02:15 ----A---- C:\Windows\system32\deployJava1.dll
2013-01-16 22:02:04 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2013-01-16 22:02:04 ----A---- C:\Windows\system32\javaw.exe
2013-01-16 22:02:04 ----A---- C:\Windows\system32\java.exe
2013-01-16 22:01:51 ----D---- C:\Program Files\Java
2013-01-16 21:54:35 ----D---- C:\Users\Katka\AppData\Roaming\.minecraft
2013-01-16 17:53:27 ----D---- C:\Program Files\Microsoft.NET
2013-01-16 17:17:19 ----D---- C:\Program Files\AuthenTec
2013-01-16 17:17:09 ----A---- C:\Windows\IsUninst.exe
2013-01-16 17:14:58 ----A---- C:\Windows\system32\MRT.exe
2013-01-16 17:14:10 ----A---- C:\Windows\system32\SynTPFcs.dll
2013-01-16 17:14:10 ----A---- C:\Windows\system32\SynTPCoI.dll
2013-01-16 17:14:10 ----A---- C:\Windows\system32\SynTPAPI.dll
2013-01-16 17:14:10 ----A---- C:\Windows\system32\drivers\SynTP.sys
2013-01-16 17:14:09 ----D---- C:\dell
2013-01-16 17:03:47 ----D---- C:\Users\Katka\AppData\Roaming\WinRAR
2013-01-16 17:03:30 ----D---- C:\Program Files\WinRAR
2013-01-16 17:02:35 ----D---- C:\ProgramData\Synaptics
2013-01-16 17:02:35 ----D---- C:\Program Files\Synaptics
2013-01-16 16:59:19 ----D---- C:\Program Files\CCleaner
2013-01-16 16:50:51 ----D---- C:\Users\Katka\AppData\Roaming\TeamViewer
2013-01-16 16:45:15 ----D---- C:\ProgramData\ICQ
2013-01-16 16:45:04 ----D---- C:\Users\Katka\AppData\Roaming\ICQ
2013-01-16 16:44:59 ----D---- C:\Program Files\ICQ7M
2013-01-16 16:39:13 ----D---- C:\Users\Katka\AppData\Roaming\Skype
2013-01-16 16:39:00 ----D---- C:\Program Files\Common Files\Skype
2013-01-16 16:38:59 ----RD---- C:\Program Files\Skype
2013-01-16 16:38:41 ----D---- C:\ProgramData\Skype
2013-01-16 16:30:20 ----A---- C:\Windows\system32\FntCache.dll
2013-01-16 16:30:20 ----A---- C:\Windows\system32\d2d1.dll
2013-01-16 15:56:25 ----D---- C:\Windows\system32\Wat
2013-01-16 15:52:41 ----A---- C:\Windows\system32\fontsub.dll
2013-01-16 15:52:41 ----A---- C:\Windows\system32\atmlib.dll
2013-01-16 15:52:41 ----A---- C:\Windows\system32\atmfd.dll
2013-01-16 15:20:46 ----A---- C:\Windows\system32\Wdfres.dll
2013-01-16 15:20:46 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2013-01-16 15:20:46 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2013-01-16 15:19:37 ----A---- C:\Windows\system32\WUDFSvc.dll
2013-01-16 15:19:37 ----A---- C:\Windows\system32\WUDFPlatform.dll
2013-01-16 15:19:37 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2013-01-16 15:19:37 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2013-01-16 15:19:36 ----A---- C:\Windows\system32\WUDFx.dll
2013-01-16 15:19:36 ----A---- C:\Windows\system32\WUDFHost.exe
2013-01-16 15:19:36 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2013-01-16 15:18:38 ----A---- C:\Windows\system32\wmi.dll
2013-01-16 15:18:38 ----A---- C:\Windows\system32\imagehlp.dll
2013-01-16 15:18:38 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2013-01-16 15:16:29 ----A---- C:\Windows\system32\wininet.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\wextract.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\webcheck.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\vbscript.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\urlmon.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\url.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\pngfilt.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\occache.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msrating.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msls31.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\mshtmler.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\mshtmled.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\mshtml.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\mshta.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msfeedssync.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\msfeeds.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\licmgr10.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\jsproxy.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\jscript9.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\jscript.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\inseng.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\imgutil.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iexpress.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieUnatt.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieui.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iesysprep.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iesetup.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iertutil.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iernonce.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iepeers.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieframe.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\iedkcs32.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieapfltr.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieapfltr.dat
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieakui.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieaksie.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ieakeng.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\ie4uinit.exe
2013-01-16 15:16:29 ----A---- C:\Windows\system32\icardie.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\dxtrans.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\dxtmsft.dll
2013-01-16 15:16:29 ----A---- C:\Windows\system32\admparse.dll
2013-01-16 15:14:54 ----A---- C:\Windows\system32\browserchoice.exe
2013-01-16 14:54:23 ----A---- C:\Windows\system32\spoolsv.exe
2013-01-16 14:54:20 ----A---- C:\Windows\system32\usp10.dll
2013-01-16 14:54:18 ----A---- C:\Windows\system32\win32k.sys
2013-01-16 14:54:16 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2013-01-16 14:54:16 ----A---- C:\Windows\system32\drivers\ndis.sys
2013-01-16 14:54:09 ----A---- C:\Windows\system32\drivers\srvnet.sys
2013-01-16 14:54:09 ----A---- C:\Windows\system32\drivers\srv2.sys
2013-01-16 14:54:09 ----A---- C:\Windows\system32\drivers\srv.sys
2013-01-16 14:54:07 ----A---- C:\Windows\system32\drivers\afd.sys
2013-01-16 14:54:04 ----D---- C:\Windows\Options
2013-01-16 14:54:02 ----A---- C:\Windows\system32\ntdll.dll
2013-01-16 14:54:00 ----A---- C:\Windows\system32\wintrust.dll
2013-01-16 14:53:56 ----A---- C:\Windows\system32\dpnet.dll
2013-01-16 14:53:53 ----A---- C:\Windows\system32\xmllite.dll
2013-01-16 14:53:41 ----A---- C:\Windows\system32\prevhost.exe
2013-01-16 14:53:27 ----A---- C:\Windows\system32\win32spl.dll
2013-01-16 14:53:24 ----A---- C:\Windows\system32\dnsrslvr.dll
2013-01-16 14:53:24 ----A---- C:\Windows\system32\dnscacheugc.exe
2013-01-16 14:53:24 ----A---- C:\Windows\system32\dnsapi.dll
2013-01-16 14:53:03 ----A---- C:\Windows\system32\cryptsvc.dll
2013-01-16 14:53:03 ----A---- C:\Windows\system32\cryptnet.dll
2013-01-16 14:53:03 ----A---- C:\Windows\system32\crypt32.dll
2013-01-16 14:52:58 ----A---- C:\Windows\system32\OxpsConverter.exe
2013-01-16 14:52:55 ----A---- C:\Windows\system32\psisdecd.dll
2013-01-16 14:52:52 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2013-01-16 14:52:50 ----A---- C:\Windows\system32\umpnpmgr.dll
2013-01-16 14:52:49 ----A---- C:\Windows\system32\schannel.dll
2013-01-16 14:52:49 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-01-16 14:52:49 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-01-16 14:52:49 ----A---- C:\Windows\system32\drivers\cng.sys
2013-01-16 14:52:47 ----A---- C:\Windows\system32\msxml3r.dll
2013-01-16 14:52:47 ----A---- C:\Windows\system32\msxml3.dll
2013-01-16 14:52:46 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2013-01-16 14:52:46 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2013-01-16 14:52:46 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2013-01-16 14:52:45 ----A---- C:\Windows\system32\oleaut32.dll
2013-01-16 14:52:45 ----A---- C:\Windows\system32\oleacc.dll
2013-01-16 14:52:39 ----A---- C:\Windows\system32\msxml6.dll
2013-01-16 14:52:37 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-01-16 14:52:30 ----A---- C:\Windows\system32\inetcomm.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\nlasvc.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\nlaapi.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\netevent.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\netcorehc.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\ncsi.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\iphlpsvc.dll
2013-01-16 14:52:17 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-01-16 14:52:17 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-01-16 14:52:17 ----A---- C:\Windows\system32\drivers\netio.sys
2013-01-16 14:52:17 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-01-16 14:52:10 ----A---- C:\Windows\system32\packager.dll
2013-01-16 14:52:04 ----A---- C:\Windows\system32\kernel32.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-16 14:52:03 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-16 14:52:03 ----A---- C:\Windows\system32\winsrv.dll
2013-01-16 14:52:03 ----A---- C:\Windows\system32\KernelBase.dll
2013-01-16 14:52:03 ----A---- C:\Windows\system32\conhost.exe
2013-01-16 14:52:02 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-16 14:52:02 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-16 14:52:02 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-16 14:51:56 ----A---- C:\Windows\system32\tquery.dll
2013-01-16 14:51:56 ----A---- C:\Windows\system32\SearchIndexer.exe
2013-01-16 14:51:56 ----A---- C:\Windows\system32\mssrch.dll
2013-01-16 14:51:55 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2013-01-16 14:51:55 ----A---- C:\Windows\system32\SearchFilterHost.exe
2013-01-16 14:51:55 ----A---- C:\Windows\system32\mssvp.dll
2013-01-16 14:51:55 ----A---- C:\Windows\system32\mssphtb.dll
2013-01-16 14:51:55 ----A---- C:\Windows\system32\mssph.dll
2013-01-16 14:51:55 ----A---- C:\Windows\system32\msscntrs.dll
2013-01-16 14:51:49 ----A---- C:\Windows\system32\cdosys.dll
2013-01-16 14:51:41 ----A---- C:\Windows\system32\FXSCOVER.exe
2013-01-16 14:51:39 ----A---- C:\Windows\system32\srcore.dll
2013-01-16 14:51:37 ----A---- C:\Windows\system32\EncDec.dll
2013-01-16 14:51:35 ----A---- C:\Windows\system32\netapi32.dll
2013-01-16 14:51:35 ----A---- C:\Windows\system32\browser.dll
2013-01-16 14:51:35 ----A---- C:\Windows\system32\browcli.dll
2013-01-16 14:51:33 ----A---- C:\Windows\system32\XpsPrint.dll
2013-01-16 14:51:31 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-01-16 14:51:30 ----A---- C:\Windows\system32\csrsrv.dll
2013-01-16 14:51:29 ----A---- C:\Windows\system32\sbe.dll
2013-01-16 14:51:29 ----A---- C:\Windows\system32\CPFilters.dll
2013-01-16 14:51:27 ----A---- C:\Windows\system32\quartz.dll
2013-01-16 14:51:27 ----A---- C:\Windows\system32\qdvd.dll
2013-01-16 14:51:21 ----A---- C:\Windows\system32\kerberos.dll
2013-01-16 14:51:17 ----A---- C:\Windows\explorer.exe
2013-01-16 14:51:12 ----D---- C:\Program Files\ATI Technologies
2013-01-16 14:51:12 ----A---- C:\Windows\system32\ntkrnlpa.exe
2013-01-16 14:51:11 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-01-16 14:51:10 ----A---- C:\Windows\system32\msi.dll
2013-01-16 14:51:09 ----A---- C:\Windows\system32\d3d10level9.dll
2013-01-16 14:51:08 ----D---- C:\Program Files\ATI
2013-01-16 14:50:56 ----A---- C:\Windows\system32\gameux.dll
2013-01-16 14:50:55 ----A---- C:\Windows\system32\Wpc.dll
2013-01-16 14:50:50 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\webio.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\sspisrv.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\sspicli.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\secur32.dll
2013-01-16 14:50:49 ----A---- C:\Windows\system32\lsass.exe
2013-01-16 14:50:49 ----A---- C:\Windows\system32\lsasrv.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbctrac.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbcjt32.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbccu32.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbccr32.dll
2013-01-16 14:50:48 ----A---- C:\Windows\system32\odbccp32.dll
2013-01-16 14:50:47 ----A---- C:\Windows\system32\d3d10_1.dll
2013-01-16 14:50:46 ----A---- C:\Windows\system32\rdrmemptylst.exe
2013-01-16 14:50:46 ----A---- C:\Windows\system32\rdpwsx.dll
2013-01-16 14:50:46 ----A---- C:\Windows\system32\rdpcorekmts.dll
2013-01-16 14:50:45 ----A---- C:\Windows\system32\msvcrt.dll
2013-01-16 14:50:43 ----A---- C:\Windows\system32\drivers\partmgr.sys
2013-01-16 14:50:41 ----A---- C:\Windows\system32\profsvc.dll
2013-01-16 14:50:39 ----A---- C:\Windows\system32\synceng.dll
2013-01-16 14:50:36 ----A---- C:\Windows\system32\localspl.dll
2013-01-16 14:50:31 ----A---- C:\Windows\system32\ntshrui.dll
2013-01-16 14:50:30 ----A---- C:\Windows\system32\taskhost.exe
2013-01-16 14:50:29 ----A---- C:\Windows\system32\DWrite.dll
2013-01-16 14:50:27 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2013-01-16 14:50:27 ----A---- C:\Windows\system32\dhcpcore6.dll
2013-01-16 14:50:23 ----A---- C:\Windows\system32\mfc42u.dll
2013-01-16 14:50:23 ----A---- C:\Windows\system32\mfc42.dll
2013-01-16 14:50:13 ----A---- C:\Windows\system32\drivers\bowser.sys
2013-01-16 14:50:11 ----A---- C:\Windows\system32\shell32.dll
2013-01-16 14:50:09 ----A---- C:\Windows\system32\poqexec.exe
2013-01-16 14:50:09 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2013-01-16 14:47:14 ----D---- C:\Program Files\Realtek
2013-01-16 14:47:14 ----A---- C:\Windows\system32\RTNUninst32.dll
2013-01-16 14:47:14 ----A---- C:\Windows\system32\RtNicProp32.dll
2013-01-16 14:47:13 ----D---- C:\Program Files\InstallShield Installation Information
2013-01-16 14:36:26 ----A---- C:\Windows\system32\tzres.dll
2013-01-16 14:35:59 ----N---- C:\Windows\system32\MpSigStub.exe
2013-01-16 14:35:30 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-01-16 14:32:59 ----A---- C:\Windows\system32\rdpcore.dll
2013-01-16 14:32:59 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2013-01-16 14:31:29 ----D---- C:\Users\Katka\AppData\Roaming\Macromedia
2013-01-16 14:31:27 ----D---- C:\Users\Katka\AppData\Roaming\Adobe
2013-01-16 14:31:26 ----D---- C:\Users\Katka\AppData\Roaming\Google
2013-01-16 14:30:29 ----D---- C:\ProgramData\Google
2013-01-16 14:30:23 ----SHD---- C:\Windows\Installer
2013-01-16 14:30:17 ----D---- C:\Program Files\Google
2013-01-16 14:30:12 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-01-16 14:30:11 ----D---- C:\Windows\system32\Macromed
2013-01-16 14:29:41 ----D---- C:\ProgramData\Adobe
2013-01-16 14:29:00 ----A---- C:\Windows\system32\wups2.dll
2013-01-16 14:29:00 ----A---- C:\Windows\system32\wucltux.dll
2013-01-16 14:29:00 ----A---- C:\Windows\system32\wuauclt.exe
2013-01-16 14:28:59 ----A---- C:\Windows\system32\wuaueng.dll
2013-01-16 14:28:52 ----A---- C:\Windows\system32\wups.dll
2013-01-16 14:28:52 ----A---- C:\Windows\system32\wudriver.dll
2013-01-16 14:28:51 ----A---- C:\Windows\system32\wuapi.dll
2013-01-16 14:28:41 ----A---- C:\Windows\system32\wuwebv.dll
2013-01-16 14:28:41 ----A---- C:\Windows\system32\wuapp.exe
2013-01-16 14:18:31 ----D---- C:\Users\Katka\AppData\Roaming\Identities
2013-01-16 14:18:20 ----D---- C:\Users\Katka\AppData\Roaming\Media Center Programs
2013-01-16 14:18:19 ----SD---- C:\Users\Katka\AppData\Roaming\Microsoft
2013-01-16 14:18:06 ----SHD---- C:\Recovery
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Šablony
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Plocha
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Oblíbené položky
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Nabídka Start
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Dokumenty
2013-01-16 14:18:06 ----SHD---- C:\ProgramData\Data aplikací
2013-01-16 14:13:06 ----D---- C:\Windows\SoftwareDistribution
2013-01-16 14:10:59 ----D---- C:\Windows\Prefetch
2013-01-16 14:10:06 ----SHD---- C:\System Volume Information
2013-01-16 14:10:06 ----ASH---- C:\pagefile.sys
2013-01-16 14:10:05 ----ASH---- C:\hiberfil.sys
2013-01-16 14:08:46 ----D---- C:\Windows\Panther

======List of files/folders modified in the last 1 month======

2013-01-26 20:11:18 ----D---- C:\Windows\Temp
2013-01-26 20:02:35 ----D---- C:\Windows\System32
2013-01-26 20:01:56 ----D---- C:\Windows\Tasks
2013-01-26 20:01:56 ----D---- C:\ProgramData
2013-01-26 18:17:42 ----D---- C:\Windows\system32\drivers
2013-01-26 18:17:17 ----D---- C:\Windows
2013-01-26 18:11:24 ----D---- C:\Windows\AppPatch
2013-01-26 18:11:23 ----D---- C:\Program Files\Common Files
2013-01-26 16:36:53 ----RD---- C:\Program Files
2013-01-26 16:27:17 ----D---- C:\Windows\system32\config
2013-01-26 16:27:14 ----D---- C:\Windows\system32\wfp
2013-01-26 16:27:14 ----D---- C:\Windows\system32\DriverStore
2013-01-26 16:27:14 ----D---- C:\Windows\system32\catroot2
2013-01-26 16:27:11 ----D---- C:\Windows\registration
2013-01-25 09:03:09 ----D---- C:\Windows\system32\LogFiles
2013-01-25 02:41:00 ----D---- C:\Windows\rescache
2013-01-23 17:47:14 ----D---- C:\Windows\inf
2013-01-22 08:24:16 ----D---- C:\Windows\LiveKernelReports
2013-01-19 23:05:44 ----D---- C:\Windows\schemas
2013-01-19 20:36:35 ----D---- C:\Windows\Logs
2013-01-19 20:36:35 ----D---- C:\Windows\debug
2013-01-19 20:22:29 ----D---- C:\Windows\system32\NDF
2013-01-19 20:04:51 ----D---- C:\Windows\winsxs
2013-01-19 20:04:29 ----D---- C:\Windows\system32\cs-CZ
2013-01-19 08:11:35 ----D---- C:\Windows\system32\wdi
2013-01-19 03:55:28 ----RSD---- C:\Windows\assembly
2013-01-19 03:55:28 ----D---- C:\Windows\Microsoft.NET
2013-01-18 18:49:44 ----D---- C:\Windows\system32\catroot
2013-01-18 18:24:50 ----D---- C:\Windows\system32\Tasks
2013-01-18 00:23:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-17 23:19:19 ----D---- C:\Windows\system32\drivers\etc
2013-01-16 23:53:18 ----SD---- C:\ProgramData\Microsoft
2013-01-16 18:19:15 ----D---- C:\Windows\system32\wbem
2013-01-16 18:17:43 ----D---- C:\Windows\PolicyDefinitions
2013-01-16 17:53:28 ----D---- C:\Windows\system32\en-US
2013-01-16 17:17:19 ----D---- C:\Windows\system32\WinBioPlugIns
2013-01-16 17:12:24 ----D---- C:\Windows\Resources
2013-01-16 15:56:55 ----D---- C:\Program Files\Common Files\System
2013-01-16 15:56:52 ----RSD---- C:\Windows\Fonts
2013-01-16 15:56:52 ----D---- C:\Windows\ehome
2013-01-16 15:56:50 ----D---- C:\Program Files\Windows Journal
2013-01-16 15:56:47 ----D---- C:\Windows\system32\migration
2013-01-16 15:56:40 ----D---- C:\Windows\system32\drivers\cs-CZ
2013-01-16 15:56:37 ----D---- C:\Program Files\Internet Explorer
2013-01-16 14:51:44 ----D---- C:\Program Files\Common Files\microsoft shared
2013-01-16 14:27:15 ----D---- C:\Windows\system32\restore
2013-01-16 14:25:24 ----D---- C:\Windows\system32\CodeIntegrity
2013-01-16 14:19:06 ----D---- C:\Windows\system32\drivers\UMDF
2013-01-16 14:18:19 ----RD---- C:\Users
2013-01-16 14:18:06 ----D---- C:\Windows\system32\Recovery
2013-01-16 14:18:06 ----D---- C:\Program Files\Windows NT
2013-01-16 14:15:53 ----D---- C:\Windows\system32\oobe
2013-01-16 14:14:09 ----D---- C:\Windows\system32\sysprep
2013-01-16 14:08:11 ----D---- C:\Windows\Setup

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2011-06-27 2191872]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2001-04-13 229168]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 30720]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-06-25 48128]
S2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-06-25 44544]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-06-11 1161664]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
S3 ATSwpWDF;AuthenTec TruePrint WBF Driver; C:\Windows\system32\DRIVERS\ATSwpWDF.sys [2012-08-30 969192]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 catchme;catchme; \??\C:\Users\Katka\AppData\Local\Temp\catchme.sys []
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2012-12-14 21104]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2009-07-14 18432]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-20 84992]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2012-12-14 1436160]
S2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-03-27 14336]
S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-16 136176]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
S2 ScrybeUpdater;Aktualizátor aplikace Scrybe; C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe [2011-05-27 1300264]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-01-08 161536]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-21 251400]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-16 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-01-16 194032]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-16 1343400]
S4 TlntSvr;@%SystemRoot%\system32\tlntsvr.exe,-119; C:\Windows\System32\tlntsvr.exe [2009-07-14 71680]

-----------------EOF-----------------

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: system jde pustit jen v nouzovem rezimu

#6 Příspěvek od stell »

Len zaskok,
restartuj pocitac do Núdzový režim s príkazovým riadkom
Safe Mode with Command Prompt
a skus zadat tieto prikazy:
bcdedit.exe /deletevalue safeboot
Enter.
shutdown -r -t 0
Enter
A nechaj nabehnut windows.
A napis co je noveho.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

kazatel
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 led 2013 23:26

Re: system jde pustit jen v nouzovem rezimu

#7 Příspěvek od kazatel »

při prvním pokusu freez po napsani shutdown .... a ani druhý pokus nebyl lepší. žádná změna. pořád nouzovy režim :(

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: system jde pustit jen v nouzovem rezimu

#8 Příspěvek od stell »

Mozes prezradit ze skadial si zadaval prikazy,?? z nudzoveho rezimu, alebo ??
V nudzovom rezime stlac klaves Logo win+R a napis tam msconfig klik na zalozku Boot, a vloz sem screenshot.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

kazatel
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 led 2013 23:26

Re: system jde pustit jen v nouzovem rezimu

#9 Příspěvek od kazatel »

přikazy psány z " Núdzový režim s príkazovým riadkom "

Obrázek 1
Obrázek 2

nejsem si jistej co ste myslel tim Boot :( tak sem vyfotil tyto 2, snad je jeden správny

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: system jde pustit jen v nouzovem rezimu

#10 Příspěvek od stell »

ok, stiahni na Flashku tento subor,
http://download.bleepingcomputer.com/farbar/FRST.exe
A nieze to zakopes , musi byt priamo na flashke, napriklad ak flashka ma pimenko F: takto bude ,F:\FRST.ex.

Znovu Restartuj pocitac do nudzoveho rezimu s prikazovym riadkom.
Napis tam prikaz notepad ENTER, najdi flashku kde mas program FRST.exe, a zisti pismenko flasky.
Ak pismenko Flashky je F:, tak do prikazoveho riadku teraz napis prikaz.
F:\frst.exe
Enter
a stlac Scan>>o chvilku sa ti na USB sa ulozi log s nazvom FRST.txt
vloz sem.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Zamčeno