Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu. Děkuji.

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Prosím o kontrolu logu. Děkuji.

#1 Příspěvek od roman7 »

Při spuštění se mi ukáže tabulka Windows script h..... c:\user\ jméno


Logfile of random's system information tool 1.08 (written by random/random)
Run by Roman at 2014-04-21 18:26:46
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 45 GB (60%) free of 76 GB
Total RAM: 2047 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:26:55, on 21.4.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16540)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Windows\SysWOW64\WScript.exe
C:\Windows\SysWOW64\WScript.exe
C:\Windows\SysWOW64\WScript.exe
C:\Windows\inf\msmainei\msmainei.exe
C:\Windows\SysWOW64\lcpmncdbwdqg.exe
C:\Windows\SysWOW64\lcpmncigfyfw.exe
C:\Windows\SysWOW64\lcpmnclarc.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\trend micro\Roman.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [mncdbwdqgSrv] C:\Windows\system32\mncdbwdqg.vbe
O4 - HKLM\..\Run: [mnclarcSrv] C:\Windows\system32\mnclarc.vbe
O4 - HKLM\..\Run: [MSStp] C:\Windows\inf\msstp.vbe
O4 - HKLM\..\Run: [mncigfyfwSrv] C:\Windows\system32\mncigfyfw.vbe
O4 - HKLM\..\Run: [NtVdmSrv] C:\Windows\inf\ntvdm.vbe
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {5852F5ED-8BF4-11D4-A245-0080C6F74284} (isInstalled Class) - http://javadl-esd.oracle.com/update/1.6 ... s-i586.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Alcohol Virtual Drive Auto-mount Service (AxAutoMntSrv) - Alcohol Soft Development Team - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7827 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Windows\System32\WScript.exe" "C:\Windows\System32\mncdbwdqg.vbe"
"C:\Windows\System32\WScript.exe" "C:\Windows\System32\mnclarc.vbe"
"C:\Windows\System32\WScript.exe" "C:\Windows\System32\mncigfyfw.vbe"
HydraDM64.exe -h:65884 "Maximalizovat na celou plochu" "Maximalizovat k rohům okna" "Obnovit pracovní plochu"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\inf\msmainei\msmainei.exe -o stratum+tcp://mint.bitminter.com:3333 -u frankfrank_frankus -p frankus575
\??\C:\Windows\system32\conhost.exe "1563815855-183033609015843731821790936412-1559521679818296888169062566-139167031
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\lcpmncdbwdqg.exe" -o stratum+tcp://stratum01.hashco.ws:8888 -u zurrsoup.1 -p x --threads=1
"C:\Windows\system32\lcpmncigfyfw.exe" -o stratum+tcp://stratum01.hashco.ws:8888 -u zurrsoup.1 -p x --threads=1
"C:\Windows\system32\lcpmnclarc.exe" -o stratum+tcp://stratum01.hashco.ws:8888 -u zurrsoup.1 -p x --threads=1
\??\C:\Windows\system32\conhost.exe "-1297399457-3660029561867219632-1445827774-1606076851514918135-162966158-1762682832
\??\C:\Windows\system32\conhost.exe "1206179556621856996-1314999583136951156518384664-203003442-18357170251613903950
\??\C:\Windows\system32\conhost.exe "2963116851994230719-20848468561540539476-1132289978-144288839-12225804811539462206
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Program Files\totalcmd\TOTALCMD.EXE"
"C:\Users\Roman\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-04-16 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-04-16 211368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2014-04-16 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 1271072]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2010-03-02 385024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2012-01-05 75624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Service 16]
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2013-09-27 801816]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-12-06 766208]
"mncdbwdqgSrv"=C:\Windows\system32\mncdbwdqg.vbe []
"mnclarcSrv"=C:\Windows\system32\mnclarc.vbe []
"MSStp"=C:\Windows\inf\msstp.vbe [2014-03-05 1584]
"mncigfyfwSrv"=C:\Windows\system32\mncigfyfw.vbe []
"NtVdmSrv"=C:\Windows\inf\ntvdm.vbe [2013-06-20 1219]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2014-04-21 18:26:47 ----D---- C:\Program Files\trend micro
2014-04-21 18:26:46 ----D---- C:\rsit
2014-04-21 18:15:17 ----A---- C:\Windows\UC.PIF
2014-04-21 18:15:17 ----A---- C:\Windows\RAR.PIF
2014-04-21 18:15:17 ----A---- C:\Windows\PKZIP.PIF
2014-04-21 18:15:17 ----A---- C:\Windows\PKUNZIP.PIF
2014-04-21 18:15:17 ----A---- C:\Windows\NOCLOSE.PIF
2014-04-21 18:15:17 ----A---- C:\Windows\LHA.PIF
2014-04-21 18:15:17 ----A---- C:\Windows\ARJ.PIF
2014-04-21 18:15:16 ----D---- C:\Program Files\totalcmd
2014-04-20 23:25:08 ----AS---- C:\Windows\SYSWOW64\lcpmncigfyfw.exe
2014-04-20 23:25:08 ----AS---- C:\Windows\SYSWOW64\dcgmncigfyfw.exe
2014-04-20 23:25:07 ----AS---- C:\Windows\SYSWOW64\acumncigfyfw.exe
2014-04-20 23:21:52 ----AS---- C:\Windows\SYSWOW64\lcpmnclarc.exe
2014-04-20 23:21:52 ----AS---- C:\Windows\SYSWOW64\dcgmnclarc.exe
2014-04-20 23:21:51 ----AS---- C:\Windows\SYSWOW64\acumnclarc.exe
2014-04-20 23:19:31 ----AS---- C:\Windows\SYSWOW64\lcpmncdbwdqg.exe
2014-04-20 23:19:31 ----AS---- C:\Windows\SYSWOW64\dcgmncdbwdqg.exe
2014-04-20 23:19:30 ----D---- C:\Windows\SYSWOW64\bitstreams
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\zlib1.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\ssleay32.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\pthreadVC2.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\pthreadGC2.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\libssh2.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\librtmp.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\libidn-11.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\libeay32.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\libcurl-4.dll
2014-04-20 23:19:30 ----AS---- C:\Windows\SYSWOW64\acumncdbwdqg.exe
2014-04-20 23:19:29 ----AS---- C:\Windows\SYSWOW64\cudart32_50_35.dll
2014-04-20 20:08:15 ----D---- C:\Program Files\CCleaner
2014-04-19 23:50:09 ----D---- C:\Program Files (x86)\Alcohol Soft
2014-04-19 23:46:44 ----A---- C:\Windows\system32\drivers\sptd.sys
2014-04-19 21:05:11 ----A---- C:\Windows\system32\drivers\cmudax3.sys
2014-04-19 21:05:10 ----A---- C:\Windows\system32\cmudax3.dll
2014-04-19 21:05:07 ----RA---- C:\Windows\system32\CmiInstallResAll64.dll
2014-04-16 16:51:09 ----A---- C:\Windows\system32\javaws.exe
2014-04-16 16:51:01 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2014-04-16 16:51:01 ----A---- C:\Windows\system32\javaw.exe
2014-04-16 16:51:01 ----A---- C:\Windows\system32\java.exe
2014-04-16 16:50:47 ----D---- C:\Program Files\Java
2014-04-16 15:52:09 ----D---- C:\ProgramData\Sun
2014-04-16 15:51:50 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-04-16 15:51:50 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-04-16 15:51:50 ----A---- C:\Windows\SYSWOW64\java.exe
2014-04-16 15:51:50 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2014-04-16 15:51:33 ----D---- C:\Program Files (x86)\Java
2014-04-10 21:41:19 ----D---- C:\Users\Roman\AppData\Roaming\vlc
2014-04-10 21:40:14 ----D---- C:\Program Files (x86)\VideoLAN
2014-04-09 16:05:31 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2014-04-09 16:05:31 ----A---- C:\Windows\system32\iologmsg.dll
2014-04-09 16:05:31 ----A---- C:\Windows\system32\drivers\storport.sys
2014-04-09 16:05:31 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-04-09 16:05:31 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-04-09 16:05:27 ----A---- C:\Windows\system32\kernel32.dll
2014-04-09 16:05:26 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-04-09 16:05:26 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-04-09 16:05:26 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-04-09 16:05:26 ----A---- C:\Windows\system32\wow64win.dll
2014-04-09 16:05:26 ----A---- C:\Windows\system32\wow64.dll
2014-04-09 16:05:26 ----A---- C:\Windows\system32\ntvdm64.dll
2014-04-09 16:05:25 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-04-09 16:05:25 ----A---- C:\Windows\system32\wow64cpu.dll
2014-04-09 16:05:24 ----A---- C:\Windows\SYSWOW64\user.exe
2014-04-09 16:05:24 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-04-09 16:05:23 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-04-06 14:30:11 ----RA---- C:\Windows\DIFxAPI.dll
2014-03-30 12:52:27 ----D---- C:\Program Files (x86)\Creative
2014-03-30 09:50:32 ----D---- C:\ProgramData\WhereIsIt
2014-03-30 09:50:32 ----D---- C:\Program Files (x86)\WhereIsIt
2014-03-27 21:55:42 ----D---- C:\Users\Roman\AppData\Roaming\Ashampoo
2014-03-27 21:45:33 ----D---- C:\ProgramData\Ashampoo
2014-03-27 21:45:30 ----D---- C:\Program Files (x86)\Ashampoo
2014-03-27 21:05:37 ----D---- C:\Users\Roman\AppData\Roaming\Macromedia
2014-03-27 21:05:31 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-03-27 21:05:27 ----D---- C:\Windows\SYSWOW64\Macromed
2014-03-27 21:05:24 ----D---- C:\Windows\system32\Macromed
2014-03-27 20:14:00 ----D---- C:\Program Files (x86)\Zoner
2014-03-27 20:13:17 ----D---- C:\Program Files (x86)\gs
2014-03-27 20:09:00 ----D---- C:\Users\Roman\AppData\Roaming\Zoner
2014-03-27 20:08:48 ----D---- C:\ProgramData\Zoner
2014-03-27 20:08:16 ----D---- C:\Program Files\Zoner
2014-03-26 22:33:25 ----A---- C:\Windows\AutoKMS.ini
2014-03-26 17:33:40 ----D---- C:\Users\Roman\AppData\Roaming\Adobe
2014-03-26 17:31:09 ----D---- C:\ProgramData\ATI
2014-03-26 17:27:41 ----D---- C:\ProgramData\AMD
2014-03-26 17:27:39 ----D---- C:\Program Files (x86)\AMD AVT
2014-03-26 17:22:45 ----D---- C:\Program Files\AMD
2014-03-26 17:16:39 ----D---- C:\ProgramData\Package Cache
2014-03-26 17:14:55 ----D---- C:\AMD
2014-03-26 17:12:14 ----D---- C:\Program Files (x86)\Adobe
2014-03-26 17:11:58 ----D---- C:\ProgramData\Adobe
2014-03-25 22:14:45 ----D---- C:\Program Files\Common Files\DESIGNER
2014-03-25 22:13:50 ----D---- C:\Program Files\Microsoft Synchronization Services
2014-03-25 22:13:11 ----D---- C:\Windows\PCHEALTH
2014-03-25 22:13:11 ----D---- C:\Program Files\Microsoft Sync Framework
2014-03-25 22:13:11 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2014-03-25 22:09:38 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2014-03-25 22:08:13 ----D---- C:\Program Files\Microsoft Analysis Services
2014-03-25 22:08:13 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2014-03-25 22:07:49 ----D---- C:\Program Files (x86)\Microsoft Office
2014-03-25 22:07:37 ----D---- C:\Program Files\Microsoft Office
2014-03-25 22:07:35 ----D---- C:\ProgramData\Microsoft Help
2014-03-25 22:07:04 ----RHD---- C:\MSOCache
2014-03-25 19:29:39 ----A---- C:\Windows\system32\drivers\revoflt.sys
2014-03-25 18:49:46 ----D---- C:\Program Files\VS Revo Group
2014-03-25 18:39:55 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-03-25 18:39:55 ----A---- C:\Windows\explorer.exe
2014-03-25 18:39:54 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2014-03-25 18:39:54 ----A---- C:\Windows\system32\WMPhoto.dll
2014-03-25 18:39:52 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-03-25 18:39:52 ----A---- C:\Windows\system32\mstscax.dll
2014-03-25 18:39:41 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-03-25 18:39:41 ----A---- C:\Windows\system32\d3d10warp.dll
2014-03-25 18:39:41 ----A---- C:\Windows\system32\d2d1.dll
2014-03-25 18:39:40 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-03-25 18:39:37 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-03-25 18:39:37 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-03-25 18:39:36 ----A---- C:\Windows\system32\spoolsv.exe
2014-03-25 18:39:36 ----A---- C:\Windows\splwow64.exe
2014-03-24 18:26:08 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-03-24 18:26:08 ----A---- C:\Windows\system32\DWrite.dll
2014-03-24 18:21:32 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-03-24 18:21:28 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-03-24 18:21:28 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-03-24 18:21:28 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-03-24 18:21:27 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2014-03-24 18:21:27 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2014-03-24 18:21:27 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-03-24 18:21:27 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2014-03-24 18:21:27 ----A---- C:\Windows\system32\wksprtPS.dll
2014-03-24 18:21:27 ----A---- C:\Windows\system32\wksprt.exe
2014-03-24 18:21:27 ----A---- C:\Windows\system32\TSWbPrxy.exe
2014-03-24 18:21:27 ----A---- C:\Windows\system32\tsgqec.dll
2014-03-24 18:21:27 ----A---- C:\Windows\system32\mstsc.exe
2014-03-24 18:21:27 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2014-03-24 18:21:26 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2014-03-24 18:21:26 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-03-24 18:20:59 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-03-24 18:20:57 ----A---- C:\Windows\system32\drivers\TsUsbGD.sys
2014-03-24 18:20:57 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2014-03-24 18:20:55 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2014-03-24 18:20:55 ----A---- C:\Windows\system32\rdpudd.dll
2014-03-24 18:20:55 ----A---- C:\Windows\system32\rdpendp_winip.dll
2014-03-24 18:20:54 ----A---- C:\Windows\system32\rdpcorets.dll
2014-03-24 18:19:16 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-03-24 18:19:15 ----A---- C:\Windows\system32\qdvd.dll
2014-03-24 18:19:09 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-03-24 18:19:08 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-03-24 14:52:14 ----A---- C:\Windows\system32\wmploc.DLL
2014-03-24 14:52:13 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-03-24 14:52:13 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-03-24 14:52:11 ----A---- C:\Windows\system32\wmp.dll
2014-03-24 14:46:30 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-03-24 14:44:08 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-03-24 14:44:06 ----D---- C:\Windows\Migration
2014-03-24 14:30:25 ----A---- C:\Windows\system32\fsutil.exe
2014-03-24 14:30:25 ----A---- C:\Windows\system32\esent.dll
2014-03-24 14:30:25 ----A---- C:\Windows\system32\drivers\amdxata.sys
2014-03-24 14:30:24 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2014-03-24 14:30:24 ----A---- C:\Windows\SYSWOW64\esent.dll
2014-03-24 14:30:24 ----A---- C:\Windows\system32\drivers\nvstor.sys
2014-03-24 14:30:24 ----A---- C:\Windows\system32\drivers\nvraid.sys
2014-03-24 14:30:24 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2014-03-24 14:30:24 ----A---- C:\Windows\system32\drivers\amdsata.sys
2014-03-24 14:30:23 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2014-03-24 14:18:43 ----D---- C:\Windows\SYSWOW64\Wat
2014-03-24 14:18:43 ----D---- C:\Windows\system32\Wat
2014-03-24 10:51:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-03-24 10:51:37 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-03-24 10:51:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-03-24 10:51:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-03-24 10:51:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-03-24 10:51:36 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-03-24 10:51:36 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-03-24 10:51:36 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-03-24 10:51:36 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-03-24 10:51:36 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2014-03-24 10:51:36 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2014-03-24 10:51:36 ----A---- C:\Windows\system32\XpsPrint.dll
2014-03-24 10:51:35 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-03-24 10:51:35 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-03-24 10:51:35 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-03-24 10:51:35 ----A---- C:\Windows\system32\dxgi.dll
2014-03-24 10:51:34 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2014-03-24 10:51:34 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2014-03-24 10:51:34 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2014-03-24 10:51:34 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2014-03-24 10:51:34 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2014-03-24 10:51:34 ----A---- C:\Windows\system32\FntCache.dll
2014-03-24 10:51:33 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2014-03-24 10:51:33 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2014-03-24 10:51:33 ----A---- C:\Windows\system32\d3d10level9.dll
2014-03-24 10:51:33 ----A---- C:\Windows\system32\d3d10core.dll
2014-03-24 10:51:33 ----A---- C:\Windows\system32\d3d10_1core.dll
2014-03-24 10:51:33 ----A---- C:\Windows\system32\d3d10_1.dll
2014-03-24 10:51:33 ----A---- C:\Windows\system32\d3d10.dll
2014-03-24 10:51:32 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2014-03-24 10:51:32 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2014-03-24 10:51:32 ----A---- C:\Windows\system32\UIAnimation.dll
2014-03-24 10:34:29 ----A---- C:\Windows\system32\browserchoice.exe
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\msls31.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\jscript.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2014-03-24 10:30:44 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-03-24 10:30:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\wextract.exe
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\url.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\inseng.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2014-03-24 10:30:42 ----A---- C:\Windows\SYSWOW64\icardie.dll
2014-03-24 10:30:41 ----A---- C:\Windows\SYSWOW64\occache.dll
2014-03-24 10:30:41 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-03-24 10:30:41 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-03-24 10:30:41 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2014-03-24 10:30:41 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-03-24 10:30:41 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2014-03-24 10:30:41 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2014-03-24 10:30:41 ----A---- C:\Windows\SYSWOW64\admparse.dll
2014-03-24 10:30:40 ----A---- C:\Windows\system32\wininet.dll
2014-03-24 10:30:40 ----A---- C:\Windows\system32\urlmon.dll
2014-03-24 10:30:40 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2014-03-24 10:30:40 ----A---- C:\Windows\system32\msls31.dll
2014-03-24 10:30:40 ----A---- C:\Windows\system32\jsproxy.dll
2014-03-24 10:30:40 ----A---- C:\Windows\system32\iertutil.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\pngfilt.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\occache.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\msrating.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\mshtml.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\mshta.exe
2014-03-24 10:30:39 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\jscript9.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\jscript.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\imgutil.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\ieUnatt.exe
2014-03-24 10:30:39 ----A---- C:\Windows\system32\iepeers.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\ieakui.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\ieaksie.dll
2014-03-24 10:30:39 ----A---- C:\Windows\system32\admparse.dll
2014-03-24 10:30:38 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2014-03-24 10:30:38 ----A---- C:\Windows\system32\mshtmler.dll
2014-03-24 10:30:38 ----A---- C:\Windows\system32\msfeedssync.exe
2014-03-24 10:30:38 ----A---- C:\Windows\system32\ieui.dll
2014-03-24 10:30:38 ----A---- C:\Windows\system32\iesysprep.dll
2014-03-24 10:30:38 ----A---- C:\Windows\system32\ieframe.dll
2014-03-24 10:30:38 ----A---- C:\Windows\system32\ieakeng.dll
2014-03-24 10:30:38 ----A---- C:\Windows\system32\IEAdvpack.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\wextract.exe
2014-03-24 10:30:37 ----A---- C:\Windows\system32\webcheck.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\vbscript.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\url.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\mshtmled.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\msfeeds.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\licmgr10.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\inseng.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\iexpress.exe
2014-03-24 10:30:37 ----A---- C:\Windows\system32\iesetup.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\iernonce.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\iedkcs32.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\ieapfltr.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\ie4uinit.exe
2014-03-24 10:30:37 ----A---- C:\Windows\system32\icardie.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\dxtrans.dll
2014-03-24 10:30:37 ----A---- C:\Windows\system32\dxtmsft.dll
2014-03-24 10:17:41 ----D---- C:\Windows\system32\MRT
2014-03-24 10:17:38 ----A---- C:\Windows\system32\MRT.exe
2014-03-24 10:15:37 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2014-03-24 10:15:37 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2014-03-24 10:15:36 ----A---- C:\Windows\system32\WUDFSvc.dll
2014-03-24 10:15:36 ----A---- C:\Windows\system32\WUDFPlatform.dll
2014-03-24 10:15:35 ----A---- C:\Windows\system32\WUDFx.dll
2014-03-24 10:15:35 ----A---- C:\Windows\system32\WUDFHost.exe
2014-03-24 10:15:35 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2014-03-24 10:10:20 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2014-03-24 10:10:19 ----A---- C:\Windows\SYSWOW64\wmi.dll
2014-03-24 10:10:19 ----A---- C:\Windows\system32\wmi.dll
2014-03-24 10:01:03 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2014-03-24 10:01:03 ----A---- C:\Windows\system32\xmllite.dll
2014-03-24 10:00:52 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-03-24 10:00:52 ----A---- C:\Windows\system32\msieftp.dll
2014-03-24 10:00:51 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2014-03-24 10:00:51 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2014-03-24 10:00:51 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2014-03-24 10:00:51 ----A---- C:\Windows\system32\odbctrac.dll
2014-03-24 10:00:51 ----A---- C:\Windows\system32\odbccu32.dll
2014-03-24 10:00:51 ----A---- C:\Windows\system32\odbccr32.dll
2014-03-24 10:00:51 ----A---- C:\Windows\system32\odbccp32.dll
2014-03-24 10:00:50 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2014-03-24 10:00:50 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2014-03-24 10:00:47 ----A---- C:\Windows\system32\wwansvc.dll
2014-03-24 10:00:47 ----A---- C:\Windows\system32\wwanprotdim.dll
2014-03-24 10:00:44 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2014-03-24 10:00:44 ----A---- C:\Windows\system32\comctl32.dll
2014-03-24 10:00:22 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2014-03-24 10:00:22 ----A---- C:\Windows\system32\poqexec.exe
2014-03-24 10:00:19 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2014-03-24 10:00:19 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2014-03-24 10:00:19 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2014-03-24 10:00:19 ----A---- C:\Windows\system32\dhcpcore6.dll
2014-03-24 09:59:46 ----A---- C:\Windows\system32\wintrust.dll
2014-03-24 09:59:45 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-03-24 09:59:28 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2014-03-24 09:59:28 ----A---- C:\Windows\system32\sbe.dll
2014-03-24 09:59:28 ----A---- C:\Windows\system32\CPFilters.dll
2014-03-24 09:59:27 ----A---- C:\Windows\SYSWOW64\sbe.dll
2014-03-24 09:59:21 ----A---- C:\Windows\SYSWOW64\quartz.dll
2014-03-24 09:59:21 ----A---- C:\Windows\system32\quartz.dll
2014-03-24 09:59:11 ----A---- C:\Windows\system32\consent.exe
2014-03-24 09:59:11 ----A---- C:\Windows\system32\appinfo.dll
2014-03-24 09:58:56 ----A---- C:\Windows\system32\tquery.dll
2014-03-24 09:58:56 ----A---- C:\Windows\system32\SearchIndexer.exe
2014-03-24 09:58:56 ----A---- C:\Windows\system32\mssrch.dll
2014-03-24 09:58:55 ----A---- C:\Windows\SYSWOW64\tquery.dll
2014-03-24 09:58:55 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2014-03-24 09:58:55 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2014-03-24 09:58:55 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2014-03-24 09:58:55 ----A---- C:\Windows\SYSWOW64\mssph.dll
2014-03-24 09:58:55 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2014-03-24 09:58:54 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2014-03-24 09:58:54 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2014-03-24 09:58:54 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2014-03-24 09:58:54 ----A---- C:\Windows\system32\SearchFilterHost.exe
2014-03-24 09:58:54 ----A---- C:\Windows\system32\mssvp.dll
2014-03-24 09:58:54 ----A---- C:\Windows\system32\mssphtb.dll
2014-03-24 09:58:54 ----A---- C:\Windows\system32\mssph.dll
2014-03-24 09:58:54 ----A---- C:\Windows\system32\msscntrs.dll
2014-03-24 09:58:53 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2014-03-24 09:58:50 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2014-03-24 09:58:50 ----A---- C:\Windows\system32\ntshrui.dll
2014-03-24 09:58:48 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-03-24 09:58:48 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2014-03-24 09:58:48 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2014-03-24 09:58:46 ----A---- C:\Windows\SYSWOW64\webio.dll
2014-03-24 09:58:46 ----A---- C:\Windows\system32\webio.dll
2014-03-24 09:58:24 ----A---- C:\Windows\system32\crypt32.dll
2014-03-24 09:58:23 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-03-24 09:58:23 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-03-24 09:58:23 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-03-24 09:58:23 ----A---- C:\Windows\system32\cryptsvc.dll
2014-03-24 09:58:23 ----A---- C:\Windows\system32\cryptnet.dll
2014-03-24 09:58:09 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-03-24 09:58:09 ----A---- C:\Windows\system32\wer.dll
2014-03-24 09:58:07 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-03-24 09:58:07 ----A---- C:\Windows\system32\imagehlp.dll
2014-03-24 09:58:03 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-03-24 09:58:03 ----A---- C:\Windows\system32\tzres.dll
2014-03-24 09:57:45 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-03-24 09:57:45 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-03-24 09:57:45 ----A---- C:\Windows\system32\msxml3r.dll
2014-03-24 09:57:45 ----A---- C:\Windows\system32\msxml3.dll
2014-03-24 09:57:19 ----A---- C:\Windows\system32\drivers\afd.sys
2014-03-24 09:57:18 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-03-24 09:57:18 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-03-24 09:57:10 ----A---- C:\Windows\system32\win32k.sys
2014-03-24 09:57:09 ----A---- C:\Windows\system32\drivers\ataport.sys
2014-03-24 09:57:03 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-03-24 09:57:03 ----A---- C:\Windows\system32\authui.dll
2014-03-24 09:57:02 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2014-03-24 09:57:02 ----A---- C:\Windows\SYSWOW64\credui.dll
2014-03-24 09:57:02 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2014-03-24 09:57:02 ----A---- C:\Windows\system32\credui.dll
2014-03-24 09:56:49 ----A---- C:\Windows\SYSWOW64\lpk.dll
2014-03-24 09:56:49 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2014-03-24 09:56:49 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2014-03-24 09:56:49 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2014-03-24 09:56:49 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2014-03-24 09:56:49 ----A---- C:\Windows\system32\lpk.dll
2014-03-24 09:56:49 ----A---- C:\Windows\system32\fontsub.dll
2014-03-24 09:56:49 ----A---- C:\Windows\system32\dciman32.dll
2014-03-24 09:56:49 ----A---- C:\Windows\system32\atmlib.dll
2014-03-24 09:56:49 ----A---- C:\Windows\system32\atmfd.dll
2014-03-24 09:56:47 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2014-03-24 09:56:47 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2014-03-24 09:56:47 ----A---- C:\Windows\system32\mfc42u.dll
2014-03-24 09:56:47 ----A---- C:\Windows\system32\mfc42.dll
2014-03-24 09:56:42 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-03-24 09:56:42 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-03-24 09:56:42 ----A---- C:\Windows\system32\schannel.dll
2014-03-24 09:56:42 ----A---- C:\Windows\system32\ncrypt.dll
2014-03-24 09:56:42 ----A---- C:\Windows\system32\lsasrv.dll
2014-03-24 09:56:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-03-24 09:56:42 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-03-24 09:56:42 ----A---- C:\Windows\system32\drivers\cng.sys
2014-03-24 09:56:41 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-03-24 09:56:41 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-03-24 09:56:41 ----A---- C:\Windows\system32\sspisrv.dll
2014-03-24 09:56:41 ----A---- C:\Windows\system32\sspicli.dll
2014-03-24 09:56:41 ----A---- C:\Windows\system32\secur32.dll
2014-03-24 09:56:41 ----A---- C:\Windows\system32\lsass.exe
2014-03-24 09:56:33 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-03-24 09:56:33 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-03-24 09:56:33 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-03-24 09:56:33 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-03-24 09:56:33 ----A---- C:\Windows\system32\RMActivate.exe
2014-03-24 09:56:32 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-03-24 09:56:32 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-03-24 09:56:32 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-03-24 09:56:31 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-03-24 09:56:31 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-03-24 09:56:31 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-03-24 09:56:31 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-03-24 09:56:31 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-03-24 09:56:31 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-03-24 09:56:31 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-03-24 09:56:31 ----A---- C:\Windows\system32\secproc_isv.dll
2014-03-24 09:56:31 ----A---- C:\Windows\system32\secproc.dll
2014-03-24 09:56:31 ----A---- C:\Windows\system32\msdrm.dll
2014-03-24 09:56:17 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2014-03-24 09:56:17 ----A---- C:\Windows\system32\d3d11.dll
2014-03-24 09:56:15 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2014-03-24 09:56:15 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-03-24 09:56:10 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-03-24 09:56:10 ----A---- C:\Windows\system32\winsrv.dll
2014-03-24 09:56:10 ----A---- C:\Windows\system32\KernelBase.dll
2014-03-24 09:56:09 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-03-24 09:56:09 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-03-24 09:56:09 ----A---- C:\Windows\system32\smss.exe
2014-03-24 09:56:09 ----A---- C:\Windows\system32\csrsrv.dll
2014-03-24 09:56:09 ----A---- C:\Windows\system32\conhost.exe
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-03-24 09:56:08 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-03-24 09:56:07 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-03-24 09:56:07 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2014-03-24 09:56:07 ----A---- C:\Windows\system32\apisetschema.dll
2014-03-24 09:56:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-03-24 09:56:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2014-03-24 09:56:06 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-03-24 09:56:06 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-03-24 09:56:03 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-03-24 09:56:03 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-03-24 09:56:02 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-03-24 09:56:00 ----A---- C:\Windows\system32\rdrmemptylst.exe
2014-03-24 09:56:00 ----A---- C:\Windows\system32\rdpwsx.dll
2014-03-24 09:56:00 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-03-24 09:55:55 ----A---- C:\Windows\system32\Wdfres.dll
2014-03-24 09:55:55 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2014-03-24 09:55:55 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2014-03-24 09:55:54 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-03-24 09:55:54 ----A---- C:\Windows\system32\rpcrt4.dll
2014-03-24 09:55:51 ----A---- C:\Windows\system32\msxml6.dll
2014-03-24 09:55:50 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-03-24 09:55:45 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2014-03-24 09:55:45 ----A---- C:\Windows\system32\nlasvc.dll
2014-03-24 09:55:45 ----A---- C:\Windows\system32\netcorehc.dll
2014-03-24 09:55:45 ----A---- C:\Windows\system32\ncsi.dll
2014-03-24 09:55:45 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-03-24 09:55:44 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2014-03-24 09:55:44 ----A---- C:\Windows\SYSWOW64\netevent.dll
2014-03-24 09:55:44 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2014-03-24 09:55:44 ----A---- C:\Windows\system32\nlaapi.dll
2014-03-24 09:55:44 ----A---- C:\Windows\system32\netevent.dll
2014-03-24 09:55:44 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2014-03-24 09:55:34 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2014-03-24 09:55:34 ----A---- C:\Windows\system32\dnsrslvr.dll
2014-03-24 09:55:34 ----A---- C:\Windows\system32\dnsapi.dll
2014-03-24 09:55:33 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2014-03-24 09:55:33 ----A---- C:\Windows\system32\dnscacheugc.exe
2014-03-24 09:55:32 ----A---- C:\Windows\system32\profsvc.dll
2014-03-24 09:54:45 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-03-24 09:54:45 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2014-03-24 09:54:45 ----A---- C:\Windows\system32\WebClnt.dll
2014-03-24 09:54:45 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2014-03-24 09:54:45 ----A---- C:\Windows\system32\davclnt.dll
2014-03-24 09:54:43 ----A---- C:\Windows\system32\dpnet.dll
2014-03-24 09:54:41 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2014-03-24 09:54:23 ----A---- C:\Windows\system32\OxpsConverter.exe
2014-03-24 09:54:00 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-03-24 09:54:00 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-03-24 09:54:00 ----A---- C:\Windows\system32\drivers\srv.sys
2014-03-24 09:53:59 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-03-24 09:53:59 ----A---- C:\Windows\system32\usp10.dll
2014-03-24 09:53:56 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-03-24 09:53:54 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2014-03-24 09:53:54 ----A---- C:\Windows\system32\mswsock.dll
2014-03-24 09:53:49 ----A---- C:\Windows\SYSWOW64\gameux.dll
2014-03-24 09:53:49 ----A---- C:\Windows\system32\Wpc.dll
2014-03-24 09:53:49 ----A---- C:\Windows\system32\gameux.dll
2014-03-24 09:53:48 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-03-24 09:53:29 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2014-03-24 09:53:29 ----A---- C:\Windows\system32\psisdecd.dll
2014-03-24 09:53:27 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-03-24 09:52:45 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-03-24 09:52:44 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-03-24 09:52:43 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-03-24 09:52:43 ----A---- C:\Windows\system32\tdh.dll
2014-03-24 09:52:43 ----A---- C:\Windows\system32\ntdll.dll
2014-03-24 09:52:43 ----A---- C:\Windows\system32\advapi32.dll
2014-03-24 09:52:42 ----A---- C:\Windows\SYSWOW64\tdh.dll
2014-03-24 09:52:42 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-03-24 09:52:41 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2014-03-24 09:52:35 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-03-24 09:52:35 ----A---- C:\Windows\system32\drivers\netio.sys
2014-03-24 09:52:34 ----A---- C:\Windows\system32\drivers\partmgr.sys
2014-03-24 09:52:33 ----A---- C:\Windows\system32\kerberos.dll
2014-03-24 09:52:32 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-03-24 09:52:31 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-03-24 09:52:31 ----A---- C:\Windows\system32\msi.dll
2014-03-24 09:51:32 ----A---- C:\Windows\SYSWOW64\synceng.dll
2014-03-24 09:51:32 ----A---- C:\Windows\system32\synceng.dll
2014-03-24 09:51:31 ----A---- C:\Windows\system32\winload.exe
2014-03-24 09:51:30 ----A---- C:\Windows\system32\winresume.exe
2014-03-24 09:51:30 ----A---- C:\Windows\system32\kdusb.dll
2014-03-24 09:51:30 ----A---- C:\Windows\system32\kdcom.dll
2014-03-24 09:51:30 ----A---- C:\Windows\system32\kd1394.dll
2014-03-24 09:51:24 ----A---- C:\Windows\system32\shell32.dll
2014-03-24 09:51:23 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-03-24 09:51:23 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-03-24 09:51:23 ----A---- C:\Windows\system32\shdocvw.dll
2014-03-24 09:51:13 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-03-24 09:51:13 ----A---- C:\Windows\system32\win32spl.dll
2014-03-24 09:51:12 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-03-24 09:51:12 ----A---- C:\Windows\system32\gdi32.dll
2014-03-24 09:51:11 ----A---- C:\Windows\system32\taskhost.exe
2014-03-24 09:51:10 ----A---- C:\Windows\system32\qedit.dll
2014-03-24 09:51:09 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-03-24 09:51:02 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2014-03-24 09:51:02 ----A---- C:\Windows\system32\cryptdlg.dll
2014-03-24 09:50:49 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2014-03-24 09:50:49 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2014-03-24 09:50:49 ----A---- C:\Windows\SYSWOW64\devobj.dll
2014-03-24 09:50:49 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2014-03-24 09:50:49 ----A---- C:\Windows\system32\umpnpmgr.dll
2014-03-24 09:50:45 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-03-24 09:50:45 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-03-24 09:50:43 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-03-24 09:50:42 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2014-03-24 09:50:42 ----A---- C:\Windows\SYSWOW64\browcli.dll
2014-03-24 09:50:42 ----A---- C:\Windows\system32\netapi32.dll
2014-03-24 09:50:42 ----A---- C:\Windows\system32\browser.dll
2014-03-24 09:50:42 ----A---- C:\Windows\system32\browcli.dll
2014-03-24 09:50:40 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2014-03-24 09:50:40 ----A---- C:\Windows\system32\prevhost.exe
2014-03-24 09:50:39 ----A---- C:\Windows\system32\drivers\fvevol.sys
2014-03-24 09:50:37 ----A---- C:\Windows\SYSWOW64\srclient.dll
2014-03-24 09:50:37 ----A---- C:\Windows\system32\srcore.dll
2014-03-24 09:50:35 ----A---- C:\Windows\system32\FXSCOVER.exe
2014-03-24 09:50:34 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2014-03-24 09:50:34 ----A---- C:\Windows\system32\inetcomm.dll
2014-03-24 09:50:33 ----A---- C:\Windows\system32\msvcrt.dll
2014-03-24 09:50:32 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2014-03-24 09:50:26 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-03-24 09:50:26 ----A---- C:\Windows\system32\certutil.exe
2014-03-24 09:50:25 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-03-24 09:50:25 ----A---- C:\Windows\system32\certenc.dll
2014-03-24 09:50:06 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-03-24 09:50:06 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-03-24 09:50:06 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-03-24 09:50:06 ----A---- C:\Windows\system32\wscript.exe
2014-03-24 09:50:06 ----A---- C:\Windows\system32\scrrun.dll
2014-03-24 09:50:06 ----A---- C:\Windows\system32\cscript.exe
2014-03-24 09:50:01 ----A---- C:\Windows\system32\localspl.dll
2014-03-24 09:49:59 ----A---- C:\Windows\system32\drivers\bowser.sys
2014-03-24 09:49:57 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-03-24 09:49:57 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2014-03-24 09:49:57 ----A---- C:\Windows\system32\oleaut32.dll
2014-03-24 09:49:57 ----A---- C:\Windows\system32\oleacc.dll
2014-03-24 09:49:55 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2014-03-24 09:49:55 ----A---- C:\Windows\system32\EncDec.dll
2014-03-24 09:49:53 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-03-24 09:49:53 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-03-24 09:49:53 ----A---- C:\Windows\system32\cdd.dll
2014-03-24 09:49:35 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2014-03-24 09:49:34 ----A---- C:\Windows\system32\cdosys.dll
2014-03-24 09:49:26 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-03-24 09:49:26 ----A---- C:\Windows\system32\nshwfp.dll
2014-03-24 09:49:26 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-03-24 09:49:26 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-03-24 09:49:25 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-03-24 09:49:24 ----A---- C:\Windows\system32\scavengeui.dll
2014-03-24 09:44:36 ----D---- C:\Users\Roman\AppData\Roaming\GHISLER
2014-03-24 09:41:53 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-03-24 09:41:53 ----A---- C:\Windows\system32\packager.dll
2014-03-24 09:41:46 ----D---- C:\Users\Roman\AppData\Roaming\WinRAR
2014-03-24 09:38:42 ----D---- C:\Program Files\WinRAR
2014-03-24 02:26:34 ----D---- C:\Windows\Panther
2014-03-24 02:26:22 ----RASH---- C:\BOOTSECT.BAK
2014-03-24 02:26:20 ----SHD---- C:\Boot
2014-03-24 02:25:56 ----RA---- C:\Windows\csup.txt
2014-03-24 02:25:56 ----D---- C:\Windows\system32\OEM
2014-03-24 02:25:56 ----D---- C:\Hotfix
2014-03-24 02:25:56 ----D---- C:\Drivers
2014-03-24 02:24:42 ----D---- C:\Windows\SYSWOW64\cs
2014-03-24 02:24:41 ----D---- C:\Windows\SYSWOW64\XPSViewer
2014-03-24 02:24:41 ----D---- C:\Windows\SYSWOW64\drivers\cs-CZ
2014-03-24 02:24:41 ----D---- C:\Windows\system32\cs
2014-03-24 02:24:41 ----D---- C:\Windows\cs-CZ
2014-03-24 02:24:40 ----D---- C:\Windows\system32\drivers\cs-CZ
2014-03-23 19:07:59 ----D---- C:\Users\Roman\AppData\Roaming\Opera Mail
2014-03-23 18:45:36 ----D---- C:\Users\Roman\AppData\Roaming\Opera Software
2014-03-23 18:45:32 ----D---- C:\Program Files (x86)\Opera
2014-03-23 18:20:38 ----D---- C:\Users\Roman\AppData\Roaming\ATI
2014-03-23 18:09:49 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-03-23 18:08:59 ----A---- C:\Windows\system32\drivers\AtiHdmi.sys
2014-03-23 18:08:13 ----A---- C:\Windows\system32\ATIDEMGX.dll
2014-03-23 18:08:12 ----A---- C:\Windows\system32\coinst.dll
2014-03-23 18:06:43 ----D---- C:\Program Files (x86)\ATI Technologies
2014-03-23 18:05:50 ----D---- C:\Program Files\ATI Technologies
2014-03-23 18:05:44 ----D---- C:\Program Files\ATI
2014-03-23 17:49:50 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2014-03-23 17:49:50 ----A---- C:\Windows\system32\rdpcore.dll
2014-03-23 17:49:50 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2014-03-23 17:49:32 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-03-23 17:49:26 ----SHD---- C:\Windows\Installer
2014-03-23 17:49:26 ----D---- C:\Program Files\Microsoft Security Client
2014-03-23 17:42:06 ----D---- C:\Windows\pss
2014-03-23 17:36:51 ----A---- C:\Windows\system32\wups2.dll
2014-03-23 17:36:51 ----A---- C:\Windows\system32\wucltux.dll
2014-03-23 17:36:51 ----A---- C:\Windows\system32\wuaueng.dll
2014-03-23 17:36:51 ----A---- C:\Windows\system32\wuauclt.exe
2014-03-23 17:36:41 ----A---- C:\Windows\system32\wups.dll
2014-03-23 17:36:41 ----A---- C:\Windows\system32\wudriver.dll
2014-03-23 17:36:41 ----A---- C:\Windows\system32\wuapi.dll
2014-03-23 17:36:32 ----A---- C:\Windows\system32\wuwebv.dll
2014-03-23 17:36:32 ----A---- C:\Windows\system32\wuapp.exe
2014-03-23 17:36:22 ----D---- C:\Users\Roman\AppData\Roaming\Identities
2014-03-23 17:36:03 ----SD---- C:\Users\Roman\AppData\Roaming\Microsoft
2014-03-23 17:36:03 ----D---- C:\Users\Roman\AppData\Roaming\Media Center Programs
2014-03-23 17:35:50 ----SHD---- C:\Recovery
2014-03-23 17:35:50 ----SHD---- C:\ProgramData\Šablony
2014-03-23 17:35:50 ----SHD---- C:\ProgramData\Plocha
2014-03-23 17:35:50 ----SHD---- C:\ProgramData\Oblíbené položky
2014-03-23 17:35:50 ----SHD---- C:\ProgramData\Nabídka Start
2014-03-23 17:35:50 ----SHD---- C:\ProgramData\Dokumenty
2014-03-23 17:35:50 ----SHD---- C:\ProgramData\Data aplikací
2014-03-23 17:31:41 ----D---- C:\ProgramData\Hewlett-Packard
2014-03-23 17:31:23 ----D---- C:\Windows\SoftwareDistribution
2014-03-23 17:29:13 ----D---- C:\Windows\Prefetch
2014-03-23 17:28:23 ----ASH---- C:\pagefile.sys
2014-03-23 17:28:22 ----SHD---- C:\System Volume Information
2014-03-23 17:28:22 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 months======

2014-04-21 18:26:47 ----RD---- C:\Program Files
2014-04-21 18:26:14 ----D---- C:\Windows\Temp
2014-04-21 18:15:17 ----D---- C:\Windows
2014-04-21 16:32:52 ----D---- C:\Windows\system32\config
2014-04-21 16:30:54 ----D---- C:\Windows\System32
2014-04-21 16:30:54 ----D---- C:\Windows\inf
2014-04-21 16:30:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-04-20 23:31:18 ----RD---- C:\Program Files (x86)
2014-04-20 23:25:08 ----D---- C:\Windows\SysWOW64
2014-04-20 20:10:36 ----D---- C:\Windows\Logs
2014-04-20 20:10:36 ----D---- C:\Windows\debug
2014-04-20 20:08:20 ----D---- C:\Windows\system32\Tasks
2014-04-19 23:46:44 ----D---- C:\Windows\system32\drivers
2014-04-19 21:05:49 ----D---- C:\Windows\system32\catroot
2014-04-19 21:05:48 ----D---- C:\Windows\system32\DriverStore
2014-04-19 21:05:07 ----D---- C:\Windows\system
2014-04-19 19:58:48 ----D---- C:\Windows\system32\catroot2
2014-04-16 15:52:09 ----HD---- C:\ProgramData
2014-04-16 15:52:09 ----D---- C:\Windows\Downloaded Program Files
2014-04-16 15:52:08 ----D---- C:\Program Files (x86)\Common Files
2014-04-13 15:15:44 ----D---- C:\Windows\rescache
2014-04-10 21:25:35 ----D---- C:\Windows\Tasks
2014-04-09 19:03:42 ----D---- C:\Windows\winsxs
2014-04-09 19:02:10 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-04-09 19:02:10 ----D---- C:\Windows\system32\cs-CZ
2014-04-09 19:02:10 ----D---- C:\Windows\AppPatch
2014-03-30 12:52:43 ----D---- C:\Windows\SYSWOW64\drivers
2014-03-27 22:03:50 ----D---- C:\Windows\system32\NDF
2014-03-27 18:19:47 ----A---- C:\Windows\win.ini
2014-03-26 22:23:50 ----D---- C:\Windows\system32\wdi
2014-03-26 21:19:34 ----D---- C:\Windows\Microsoft.NET
2014-03-26 21:18:23 ----RSD---- C:\Windows\assembly
2014-03-26 17:56:02 ----D---- C:\Program Files\Common Files\System
2014-03-25 22:20:06 ----D---- C:\Program Files (x86)\Windows Sidebar
2014-03-25 22:20:06 ----D---- C:\Program Files (x86)\Windows Media Player
2014-03-25 22:20:06 ----D---- C:\Program Files (x86)\Windows Mail
2014-03-25 22:20:05 ----D---- C:\Windows\SYSWOW64\winrm
2014-03-25 22:20:05 ----D---- C:\Windows\SYSWOW64\slmgr
2014-03-25 22:20:05 ----D---- C:\Windows\SYSWOW64\migwiz
2014-03-25 22:20:05 ----D---- C:\Windows\SYSWOW64\en
2014-03-25 22:20:05 ----D---- C:\Windows\SYSWOW64\drivers\en-US
2014-03-25 22:20:05 ----D---- C:\Windows\servicing
2014-03-25 22:20:05 ----D---- C:\Program Files\Windows Sidebar
2014-03-25 22:20:05 ----D---- C:\Program Files\Windows Photo Viewer
2014-03-25 22:20:05 ----D---- C:\Program Files\Windows Media Player
2014-03-25 22:20:05 ----D---- C:\Program Files\Windows Mail
2014-03-25 22:20:05 ----D---- C:\Program Files\Windows Journal
2014-03-25 22:20:05 ----D---- C:\Program Files\Windows Defender
2014-03-25 22:20:05 ----D---- C:\Program Files\DVD Maker
2014-03-25 22:20:05 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2014-03-25 22:20:05 ----D---- C:\Program Files (x86)\Windows Defender
2014-03-25 22:20:04 ----D---- C:\Windows\SYSWOW64\en-US
2014-03-25 22:19:55 ----D---- C:\Windows\SYSWOW64\WCN
2014-03-25 22:19:55 ----D---- C:\Windows\SYSWOW64\DriverStore
2014-03-25 22:19:55 ----D---- C:\Windows\SYSWOW64\Dism
2014-03-25 22:19:54 ----D---- C:\Windows\SYSWOW64\Printing_Admin_Scripts
2014-03-25 22:19:54 ----D---- C:\Windows\en-US
2014-03-25 22:19:53 ----D---- C:\Windows\system32\winrm
2014-03-25 22:19:53 ----D---- C:\Windows\system32\slmgr
2014-03-25 22:19:53 ----D---- C:\Windows\system32\migwiz
2014-03-25 22:19:53 ----D---- C:\Windows\system32\en
2014-03-25 22:19:53 ----D---- C:\Windows\system32\drivers\en-US
2014-03-25 22:19:53 ----D---- C:\Windows\system32\Boot
2014-03-25 22:19:51 ----D---- C:\Windows\system32\en-US
2014-03-25 22:19:44 ----D---- C:\Windows\system32\WCN
2014-03-25 22:19:44 ----D---- C:\Windows\system32\Dism
2014-03-25 22:19:43 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2014-03-25 22:19:43 ----D---- C:\Windows\Speech
2014-03-25 22:15:01 ----RSD---- C:\Windows\Fonts
2014-03-25 22:14:47 ----D---- C:\Windows\ShellNew
2014-03-25 22:14:45 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-03-25 22:14:45 ----D---- C:\Program Files\Common Files
2014-03-25 22:13:36 ----D---- C:\Program Files (x86)\MSBuild
2014-03-25 22:13:11 ----SD---- C:\ProgramData\Microsoft
2014-03-24 19:36:59 ----D---- C:\Windows\system32\LogFiles
2014-03-24 18:44:27 ----D---- C:\Windows\SYSWOW64\wbem
2014-03-24 18:44:27 ----D---- C:\Windows\system32\wbem
2014-03-24 18:44:27 ----D---- C:\Windows\PolicyDefinitions
2014-03-24 15:04:55 ----D---- C:\Windows\ehome
2014-03-24 14:19:07 ----D---- C:\Windows\SYSWOW64\pt-PT
2014-03-24 14:19:07 ----D---- C:\Windows\SYSWOW64\pt-BR
2014-03-24 14:19:07 ----D---- C:\Windows\SYSWOW64\pl-PL
2014-03-24 14:19:07 ----D---- C:\Windows\SYSWOW64\ko-KR
2014-03-24 14:19:07 ----D---- C:\Windows\SYSWOW64\it-IT
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\zh-TW
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\zh-HK
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\zh-CN
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\tr-TR
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\sv-SE
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\ru-RU
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\nl-NL
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\nb-NO
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\ja-JP
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\hu-HU
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\fr-FR
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\fi-FI
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\es-ES
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\el-GR
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\de-DE
2014-03-24 14:19:06 ----D---- C:\Windows\SYSWOW64\da-DK
2014-03-24 14:19:05 ----D---- C:\Windows\system32\zh-TW
2014-03-24 14:19:05 ----D---- C:\Windows\system32\zh-HK
2014-03-24 14:19:05 ----D---- C:\Windows\system32\zh-CN
2014-03-24 14:19:05 ----D---- C:\Windows\system32\tr-TR
2014-03-24 14:19:05 ----D---- C:\Windows\system32\sv-SE
2014-03-24 14:19:05 ----D---- C:\Windows\system32\ru-RU
2014-03-24 14:19:05 ----D---- C:\Windows\system32\pt-PT
2014-03-24 14:19:05 ----D---- C:\Windows\system32\pt-BR
2014-03-24 14:19:05 ----D---- C:\Windows\system32\pl-PL
2014-03-24 14:19:05 ----D---- C:\Windows\system32\nl-NL
2014-03-24 14:19:05 ----D---- C:\Windows\system32\nb-NO
2014-03-24 14:19:05 ----D---- C:\Windows\system32\ko-KR
2014-03-24 14:19:05 ----D---- C:\Windows\system32\ja-JP
2014-03-24 14:19:05 ----D---- C:\Windows\system32\it-IT
2014-03-24 14:19:05 ----D---- C:\Windows\system32\hu-HU
2014-03-24 14:19:05 ----D---- C:\Windows\system32\fr-FR
2014-03-24 14:19:05 ----D---- C:\Windows\system32\fi-FI
2014-03-24 14:19:05 ----D---- C:\Windows\system32\es-ES
2014-03-24 14:19:05 ----D---- C:\Windows\system32\el-GR
2014-03-24 14:19:05 ----D---- C:\Windows\system32\de-DE
2014-03-24 14:19:05 ----D---- C:\Windows\system32\da-DK
2014-03-24 14:18:54 ----D---- C:\Windows\SYSWOW64\migration
2014-03-24 14:18:54 ----D---- C:\Program Files\Internet Explorer
2014-03-24 14:18:54 ----D---- C:\Program Files (x86)\Internet Explorer
2014-03-24 14:18:49 ----D---- C:\Windows\system32\migration
2014-03-24 09:37:36 ----D---- C:\Windows\system32\drivers\UMDF
2014-03-24 02:25:56 ----D---- C:\Windows\system32\Recovery
2014-03-24 02:25:56 ----D---- C:\Windows\system32\oobe
2014-03-24 02:25:56 ----D---- C:\Windows\Setup
2014-03-24 02:24:41 ----D---- C:\Windows\SYSWOW64\MUI
2014-03-24 02:24:41 ----D---- C:\Windows\SYSWOW64\com
2014-03-24 02:24:41 ----D---- C:\Windows\IME
2014-03-24 02:24:40 ----D---- C:\Windows\system32\MUI
2014-03-24 02:24:39 ----D---- C:\Windows\system32\com
2014-03-23 17:52:55 ----D---- C:\Windows\system32\CodeIntegrity
2014-03-23 17:36:18 ----SHD---- C:\$Recycle.Bin
2014-03-23 17:36:04 ----D---- C:\Windows\system32\restore
2014-03-23 17:36:00 ----RD---- C:\Users
2014-03-23 17:35:50 ----D---- C:\Program Files\Windows NT
2014-03-23 17:31:51 ----D---- C:\Windows\system32\sysprep
2014-03-23 17:29:08 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 268512]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2014-04-19 386680]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 MpKsl9885c38e;MpKsl9885c38e; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8320492-4E89-49BF-8F36-BC4FD3F27B35}\MpKsl9885c38e.sys [2014-04-21 45352]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 133928]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 13207552]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-12-06 626176]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet - adaptér; C:\Windows\system32\DRIVERS\l160x64.sys [2009-06-25 58368]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-09-24 94208]
R3 cmuda3;C-Media PCI Audio Interface; C:\Windows\system32\drivers\cmudax3.sys [2009-05-20 1154560]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2005-03-29 8192]
R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
S3 a6pesuhk;a6pesuhk; C:\Windows\system32\drivers\a6pesuhk.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 116736]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\drivers\nusb3hub.sys [2010-09-30 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\drivers\nusb3xhc.sys [2010-09-30 180736]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 31800]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-12-06 239616]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
S2 AxAutoMntSrv;Alcohol Virtual Drive Auto-mount Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2012-01-05 75624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-10 257712]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-03-24 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu. Děkuji.

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Re: Prosím o kontrolu logu. Děkuji.

#3 Příspěvek od roman7 »

Taky Vás zdravím a tady je log z Rkill. Combofix jsem ještě nezpouštěl u Rkillse píše Teď nerestartujte PC - prišli byste o učinek RKillu
tak nevím.
Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 04/21/2014 07:12:39 PM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\Windows\inf\msmainei\msmainei.exe (PID: 3112) [WD-HEUR]
* C:\Windows\SysWOW64\lcpmncdbwdqg.exe (PID: 3492) [WD-HEUR]
* C:\Windows\SysWOW64\lcpmncigfyfw.exe (PID: 3452) [WD-HEUR]
* C:\Windows\SysWOW64\lcpmnclarc.exe (PID: 1708) [WD-HEUR]

4 proccesses terminated!

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 04/21/2014 07:13:25 PM
Execution time: 0 hours(s), 0 minute(s), and 45 seconds(s)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu. Děkuji.

#4 Příspěvek od vyosek »

Nyni tam pustte ComboFix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Re: Prosím o kontrolu logu. Děkuji.

#5 Příspěvek od roman7 »

ComboFix 14-04-20.01 - Roman 21.04.2014 19:44:37.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.2047.1035 [GMT 2:00]
Spuštěný z: c:\users\Roman\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\inf\ntvdm.vbe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-21 do 2014-04-21 )))))))))))))))))))))))))))))))
.
.
2014-04-21 17:49 . 2014-04-21 17:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-21 16:26 . 2014-04-21 16:26 -------- d-----w- c:\program files\trend micro
2014-04-21 16:26 . 2014-04-21 16:26 -------- d-----w- C:\rsit
2014-04-21 16:15 . 2009-09-24 05:50 545 ----a-w- c:\windows\UC.PIF
2014-04-21 16:15 . 2009-09-24 05:50 545 ----a-w- c:\windows\RAR.PIF
2014-04-21 16:15 . 2009-09-24 05:50 545 ----a-w- c:\windows\NOCLOSE.PIF
2014-04-21 16:15 . 2009-09-24 05:50 545 ----a-w- c:\windows\LHA.PIF
2014-04-21 16:15 . 2009-09-24 05:50 545 ----a-w- c:\windows\ARJ.PIF
2014-04-21 16:15 . 2014-04-21 17:05 -------- d-----w- c:\program files\totalcmd
2014-04-21 14:24 . 2014-04-21 14:24 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B8320492-4E89-49BF-8F36-BC4FD3F27B35}\offreg.dll
2014-04-21 14:24 . 2014-04-21 14:24 45352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B8320492-4E89-49BF-8F36-BC4FD3F27B35}\MpKsl9885c38e.sys
2014-04-20 21:25 . 2014-03-05 20:19 7670 --s-a-w- c:\windows\SysWow64\mncigfyfw.vbe
2014-04-20 21:25 . 2013-10-26 18:30 972814 --s-a-w- c:\windows\SysWow64\dcgmncigfyfw.exe
2014-04-20 21:25 . 2013-07-18 14:06 187904 --s-a-w- c:\windows\SysWow64\lcpmncigfyfw.exe
2014-04-20 21:25 . 2013-12-09 22:30 10236928 --s-a-w- c:\windows\SysWow64\acumncigfyfw.exe
2014-04-20 21:21 . 2014-03-05 20:19 7670 --s-a-w- c:\windows\SysWow64\mnclarc.vbe
2014-04-20 21:21 . 2013-10-26 18:30 972814 --s-a-w- c:\windows\SysWow64\dcgmnclarc.exe
2014-04-20 21:21 . 2013-07-18 14:06 187904 --s-a-w- c:\windows\SysWow64\lcpmnclarc.exe
2014-04-20 21:21 . 2013-12-09 22:30 10236928 --s-a-w- c:\windows\SysWow64\acumnclarc.exe
2014-04-20 18:13 . 2014-04-16 10:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B8320492-4E89-49BF-8F36-BC4FD3F27B35}\mpengine.dll
2014-04-20 18:08 . 2014-04-20 18:08 -------- d-----w- c:\program files\CCleaner
2014-04-19 21:50 . 2014-04-20 13:27 -------- d-----w- c:\program files (x86)\Alcohol Soft
2014-04-19 21:46 . 2014-04-19 21:46 386680 ----a-w- c:\windows\system32\drivers\sptd.sys
2014-04-19 19:05 . 2009-05-20 05:26 1154560 ----a-w- c:\windows\system32\drivers\cmudax3.sys
2014-04-19 19:05 . 2007-02-27 09:30 36864 ----a-w- c:\windows\system32\cmudax3.dll
2014-04-19 19:05 . 2009-04-09 03:22 354304 ----a-r- c:\windows\system32\CmiInstallResAll64.dll
2014-04-19 17:59 . 2014-04-16 10:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-04-19 05:11 . 2014-03-23 15:52 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8F2C4EC3-1D64-45D3-9164-C4E6241A66D2}\gapaengine.dll
2014-04-16 14:51 . 2014-04-16 14:50 313256 ----a-w- c:\windows\system32\javaws.exe
2014-04-16 14:51 . 2014-04-16 14:50 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-04-16 14:51 . 2014-04-16 14:50 189352 ----a-w- c:\windows\system32\javaw.exe
2014-04-16 14:51 . 2014-04-16 14:50 189352 ----a-w- c:\windows\system32\java.exe
2014-04-16 14:50 . 2014-04-16 14:50 -------- d-----w- c:\program files\Java
2014-04-16 13:52 . 2014-04-16 13:52 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-04-16 13:51 . 2014-04-16 13:51 411368 ----a-w- c:\windows\SysWow64\deployJava1.dll
2014-04-16 13:51 . 2014-04-16 13:51 -------- d-----w- c:\program files (x86)\Java
2014-04-10 19:40 . 2014-04-10 19:40 -------- d-----w- c:\program files (x86)\VideoLAN
2014-04-06 12:30 . 2006-10-06 18:45 524768 ----a-r- c:\windows\DIFxAPI.dll
2014-03-30 10:52 . 2014-03-30 10:52 -------- d-----w- c:\program files (x86)\Creative
2014-03-30 07:50 . 2014-03-30 07:52 -------- d-----w- c:\program files (x86)\WhereIsIt
2014-03-30 07:50 . 2014-03-30 07:50 -------- d-----w- c:\programdata\WhereIsIt
2014-03-27 19:45 . 2014-03-27 19:46 -------- d-----w- c:\programdata\Ashampoo
2014-03-27 19:45 . 2014-03-27 19:45 -------- d-----w- c:\program files (x86)\Ashampoo
2014-03-27 19:05 . 2014-04-10 19:29 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-27 19:05 . 2014-04-10 19:29 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-27 19:05 . 2014-03-27 19:05 -------- d-----w- c:\windows\SysWow64\Macromed
2014-03-27 19:05 . 2014-03-27 19:05 -------- d-----w- c:\windows\system32\Macromed
2014-03-27 18:14 . 2014-03-27 18:14 -------- d-----w- c:\program files (x86)\Zoner
2014-03-27 18:13 . 2014-03-27 18:13 -------- d-----w- c:\program files (x86)\gs
2014-03-27 18:08 . 2014-03-27 18:08 -------- d-----w- c:\programdata\Zoner
2014-03-27 18:08 . 2014-03-27 18:08 -------- d-----w- c:\program files\Zoner
2014-03-26 15:51 . 2014-03-26 15:51 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2014-03-26 15:31 . 2014-03-26 15:31 -------- d-----w- c:\programdata\ATI
2014-03-26 15:27 . 2014-03-26 15:27 -------- d-----w- c:\programdata\AMD
2014-03-26 15:27 . 2014-03-26 15:27 -------- d-----w- c:\program files (x86)\AMD AVT
2014-03-26 15:27 . 2014-03-26 15:27 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2014-03-26 15:22 . 2014-03-26 15:22 -------- d-----w- c:\program files\AMD
2014-03-26 15:16 . 2014-03-26 15:18 -------- d-----w- c:\programdata\Package Cache
2014-03-26 15:14 . 2014-03-26 15:14 -------- d-----w- C:\AMD
2014-03-26 15:12 . 2014-03-26 15:12 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2014-03-25 20:14 . 2014-03-25 20:14 -------- d-----w- c:\program files\Common Files\DESIGNER
2014-03-25 20:13 . 2014-03-25 20:13 -------- d-----w- c:\program files\Microsoft Synchronization Services
2014-03-25 20:13 . 2014-03-25 20:13 -------- d-----w- c:\windows\PCHEALTH
2014-03-25 20:13 . 2014-03-25 20:13 -------- d-----w- c:\program files\Microsoft Sync Framework
2014-03-25 20:13 . 2014-03-25 20:13 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2014-03-25 20:09 . 2014-03-25 20:09 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2014-03-25 20:08 . 2014-03-25 20:08 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-03-25 20:08 . 2014-03-25 20:08 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2014-03-25 20:07 . 2014-03-25 20:13 -------- d-----w- c:\program files\Microsoft Office
2014-03-25 20:07 . 2014-04-09 14:18 -------- d-----w- c:\programdata\Microsoft Help
2014-03-25 20:07 . 2014-03-25 20:07 -------- d-----r- C:\MSOCache
2014-03-25 17:29 . 2009-12-30 11:21 31800 ----a-w- c:\windows\system32\drivers\revoflt.sys
2014-03-25 16:49 . 2014-03-25 16:49 -------- d-----w- c:\program files\VS Revo Group
2014-03-25 16:42 . 2014-03-23 15:52 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-03-24 16:26 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2014-03-24 16:26 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2014-03-24 16:20 . 2012-08-23 13:24 15360 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-03-24 16:20 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2014-03-24 16:20 . 2012-08-23 14:08 30208 ----a-w- c:\windows\system32\drivers\TsUsbGD.sys
2014-03-24 16:20 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll
2014-03-24 16:20 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2014-03-24 16:20 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2014-03-24 16:20 . 2012-08-23 09:51 3174912 ----a-w- c:\windows\system32\rdpcorets.dll
2014-03-24 16:19 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-03-24 16:19 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2014-03-24 16:19 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-03-24 16:19 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-03-24 12:52 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-03-24 12:52 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-03-24 12:52 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2014-03-24 12:52 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2014-03-24 12:52 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2014-03-24 12:44 . 2014-03-25 20:13 -------- d-----w- c:\program files (x86)\Microsoft.NET
2014-03-24 12:44 . 2014-03-24 12:44 -------- d-----w- c:\windows\Migration
2014-03-24 12:30 . 2011-03-11 06:41 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys
2014-03-24 12:30 . 2011-03-11 06:33 2565632 ----a-w- c:\windows\system32\esent.dll
2014-03-24 12:30 . 2011-03-11 06:30 96768 ----a-w- c:\windows\system32\fsutil.exe
2014-03-24 12:30 . 2011-03-11 06:41 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys
2014-03-24 12:30 . 2011-03-11 06:41 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys
2014-03-24 12:30 . 2011-03-11 06:41 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2014-03-24 12:30 . 2011-03-11 06:41 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys
2014-03-24 12:30 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\SysWow64\esent.dll
2014-03-24 12:30 . 2011-03-11 05:31 74240 ----a-w- c:\windows\SysWow64\fsutil.exe
2014-03-24 12:30 . 2011-03-11 04:37 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS
2014-03-24 12:18 . 2014-03-24 12:18 -------- d-----w- c:\windows\SysWow64\Wat
2014-03-24 12:18 . 2014-03-24 12:18 -------- d-----w- c:\windows\system32\Wat
2014-03-24 08:34 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-03-24 08:17 . 2014-04-09 14:17 -------- d-----w- c:\windows\system32\MRT
2014-03-24 08:15 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-03-24 08:15 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-03-24 08:15 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-03-24 08:15 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-03-24 08:15 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2014-03-24 08:15 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2014-03-24 08:15 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-03-24 08:10 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-03-24 08:10 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-03-24 08:10 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-03-24 08:01 . 2011-06-16 05:49 199680 ----a-w- c:\windows\system32\xmllite.dll
2014-03-24 07:59 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll
2014-03-24 07:59 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2014-03-24 07:59 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
2014-03-24 07:59 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll
2014-03-24 07:59 . 2010-12-23 05:54 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2014-03-24 07:59 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-24 08:30 . 2014-03-24 08:30 203776 ----a-w- c:\windows\SysWow64\webcheck.dll
2014-03-24 08:30 . 2014-03-24 08:30 249344 ----a-w- c:\windows\system32\webcheck.dll
2014-03-11 07:52 . 2013-09-27 08:53 133928 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-04 09:17 . 2014-04-09 14:05 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-01-24 23:19 . 2014-01-24 23:19 268512 ----a-w- c:\windows\system32\drivers\MpFilter.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2010-03-02 385024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-12-06 766208]
"mncdbwdqgSrv"="c:\windows\system32\mncdbwdqg.vbe" [2014-03-05 7670]
"mnclarcSrv"="c:\windows\system32\mnclarc.vbe" [2014-03-05 7670]
"MSStp"="c:\windows\inf\msstp.vbe" [2014-03-05 1584]
"mncigfyfwSrv"="c:\windows\system32\mncigfyfw.vbe" [2014-03-05 7670]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 AxAutoMntSrv;Alcohol Virtual Drive Auto-mount Service;c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe;c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 MpKsl9885c38e;MpKsl9885c38e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B8320492-4E89-49BF-8F36-BC4FD3F27B35}\MpKsl9885c38e.sys;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B8320492-4E89-49BF-8F36-BC4FD3F27B35}\MpKsl9885c38e.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet - adaptér;c:\windows\system32\DRIVERS\l160x64.sys;c:\windows\SYSNATIVE\DRIVERS\l160x64.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver;c:\windows\system32\DRIVERS\Rtnic64.sys;c:\windows\SYSNATIVE\DRIVERS\Rtnic64.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL9885C38E
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-27 19:29]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 213.194.204.126 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-NtVdmSrv - c:\windows\inf\ntvdm.vbe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-04-21 19:52:09
ComboFix-quarantined-files.txt 2014-04-21 17:52
.
Před spuštěním: Volných bajtů: 47 404 904 448
Po spuštění: Volných bajtů: 47 024 943 104
.
- - End Of File - - C8C6DBC1EE3C7BCA9B5EB0F1D974453E
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu. Děkuji.

#6 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Collect::
    c:\windows\SysWow64\mncigfyfw.vbe
    c:\windows\SysWow64\dcgmncigfyfw.exe
    c:\windows\SysWow64\lcpmncigfyfw.exe
    c:\windows\SysWow64\acumncigfyfw.exe
    c:\windows\SysWow64\mnclarc.vbe
    c:\windows\SysWow64\dcgmnclarc.exe
    c:\windows\SysWow64\lcpmnclarc.exe
    c:\windows\SysWow64\acumnclarc.exe
    c:\windows\inf\msstp.vbe
    c:\windows\system32\mnclarc.vbe
    c:\windows\system32\mncdbwdqg.vbe
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Adobe ARM"=-
    "mncdbwdqgSrv"=-
    "mnclarcSrv"=-
    "MSStp"=-
    "mncigfyfwSrv"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BCSSync"=-
    
    File::
    c:\windows\Tasks\Adobe Flash Player Updater.job
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Re: Prosím o kontrolu logu. Děkuji.

#7 Příspěvek od roman7 »

ComboFix 14-04-20.01 - Roman 21.04.2014 20:16:20.2.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.2047.1133 [GMT 2:00]
Spuštěný z: C:\Users\Roman\Desktop\ComboFix.exe
Použité ovládací přepínače :: C:\Users\Roman\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FILE ::
"c:\windows\Tasks\Adobe Flash Player Updater.job"



((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))


c:\windows\inf\msstp.vbe
c:\windows\SysWow64\acumncigfyfw.exe
c:\windows\SysWow64\acumnclarc.exe
c:\windows\SysWow64\dcgmncigfyfw.exe
c:\windows\SysWow64\dcgmnclarc.exe
c:\windows\SysWow64\lcpmncigfyfw.exe
c:\windows\SysWow64\lcpmnclarc.exe
c:\windows\SysWow64\mncigfyfw.vbe
c:\windows\SysWow64\mnclarc.vbe
c:\windows\Tasks\Adobe Flash Player Updater.job


((((((((((((((((((((((((( Soubory vytvořené od 2014-03-21 do 2014-04-21 )))))))))))))))))))))))))))))))

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu. Děkuji.

#8 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Re: Prosím o kontrolu logu. Děkuji.

#9 Příspěvek od roman7 »

Nespustil jsem program jako správce. Doufám, že to nevadí.
Zoek.exe v5.0.0.0 Updated 14-April-2014
Tool run by Roman on út 22.04.2014 at 20:26:19,83.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Roman\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

22.4.2014 20:27:10 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~3\Package Cache deleted

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{F2603DCA-5AAB-4083-B08A-D6B4BC0B0331} Google Url="http://www.google.com/search?q={searchT ... utEncoding?}"

==== Reset Google Chrome ======================

Nothing found to reset

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Roman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Roman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=13 folders=15 14060574 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\Roman\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Roman\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on út 22.04.2014 at 20:39:08,58 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu. Děkuji.

#10 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Re: Prosím o kontrolu logu. Děkuji.

#11 Příspěvek od roman7 »

část 1
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by Roman (administrator) on ROMAN-PC on 23-04-2014 16:12:14
Running from C:\Users\Roman\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(forum.viry.cz) C:\Users\Roman\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-3906988839-2094668275-1455417225-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [385024 2010-03-02] (AMD)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
DPF: HKLM-x32 {5852F5ED-8BF4-11D4-A245-0080C6F74284} http://javadl-esd.oracle.com/update/1.6 ... s-i586.cab
Tcpip\Parameters: [DhcpNameServer] 213.194.204.126 192.168.0.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

==================== Services (Whitelisted) =================

S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R3 AtcL001; C:\Windows\System32\DRIVERS\l160x64.sys [58368 2009-06-25] (Atheros Communications, Inc.)
R3 cmuda3; C:\Windows\System32\drivers\cmudax3.sys [1154560 2009-05-20] (C-Media Inc)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-04-19] (Duplex Secure Ltd.)
U3 a3lxrvfk; C:\Windows\System32\Drivers\a3lxrvfk.sys [0 ] (Advanced Micro Devices)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-23 16:12 - 2014-04-23 16:12 - 00006708 _____ () C:\Users\Roman\Desktop\FRST.txt
2014-04-23 16:07 - 2014-04-23 16:12 - 00000000 ____D () C:\FRST
2014-04-23 16:05 - 2014-04-23 16:05 - 02061312 _____ (Farbar) C:\Users\Roman\Desktop\FRST64.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00112640 _____ (forum.viry.cz) C:\Users\Roman\Desktop\FRSTLauncher.exe
2014-04-22 20:37 - 2014-04-22 20:26 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-04-22 20:26 - 2014-04-22 20:39 - 00004862 _____ () C:\zoek-results.log
2014-04-22 20:26 - 2014-04-22 20:36 - 00000000 ____D () C:\zoek_backup
2014-04-22 20:25 - 2014-04-22 20:25 - 01285120 _____ () C:\Users\Roman\Desktop\zoek.exe
2014-04-21 20:14 - 2014-04-21 20:22 - 00000000 ____D () C:\ComboFix
2014-04-21 20:13 - 2014-04-21 20:13 - 00000829 _____ () C:\Users\Roman\Documents\CFScript.txt
2014-04-21 19:43 - 2014-04-21 20:21 - 00000000 ____D () C:\Windows\erdnt
2014-04-21 19:43 - 2014-04-21 20:16 - 00000000 ____D () C:\Qoobox
2014-04-21 19:43 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-21 19:43 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-21 19:43 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-21 19:43 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-21 19:43 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-21 19:43 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-21 19:43 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-21 19:43 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-21 19:12 - 2014-04-21 19:13 - 00002516 _____ () C:\Users\Roman\Desktop\Rkill.txt
2014-04-21 19:09 - 2014-04-21 19:09 - 05196870 ____R (Swearware) C:\Users\Roman\Desktop\ComboFix.exe
2014-04-21 19:09 - 2014-04-21 19:09 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Roman\Desktop\rkill.com
2014-04-21 18:26 - 2014-04-21 18:26 - 00000000 ____D () C:\rsit
2014-04-21 18:26 - 2014-04-21 18:26 - 00000000 ____D () C:\Program Files\trend micro
2014-04-21 18:25 - 2014-04-21 18:26 - 00832273 _____ () C:\Users\Roman\Downloads\RSITx64.exe
2014-04-21 18:15 - 2014-04-21 19:05 - 00000000 ____D () C:\Program Files\totalcmd
2014-04-21 18:15 - 2009-09-24 07:50 - 00000545 _____ () C:\Windows\UC.PIF
2014-04-21 18:15 - 2009-09-24 07:50 - 00000545 _____ () C:\Windows\RAR.PIF
2014-04-21 18:15 - 2009-09-24 07:50 - 00000545 _____ () C:\Windows\NOCLOSE.PIF
2014-04-21 18:15 - 2009-09-24 07:50 - 00000545 _____ () C:\Windows\LHA.PIF
2014-04-21 18:15 - 2009-09-24 07:50 - 00000545 _____ () C:\Windows\ARJ.PIF
2014-04-21 15:57 - 2014-04-21 15:57 - 10212608 _____ (CCCP Project ) C:\Users\Roman\Downloads\Combined-Community-Codec-Pack-2014-04-20.exe
2014-04-21 14:55 - 2013-01-13 16:27 - 00082944 _____ () C:\Users\Roman\Documents\Kalkulace záloh 2013 pro shromáždění I.varianta.xls
2014-04-21 14:45 - 2014-04-21 14:45 - 00000003 _____ () C:\Users\Roman\stut
2014-04-21 14:43 - 2014-04-21 16:24 - 00000062 _____ () C:\Users\Roman\rgut
2014-04-21 14:43 - 2014-04-21 14:43 - 00000000 ____D () C:\Users\Roman\AppData\Local\CrashDumps
2014-04-21 14:42 - 2014-04-21 14:42 - 00000000 _____ () C:\Users\Roman\regbcm
2014-04-21 14:41 - 2014-04-23 15:52 - 00000560 _____ () C:\Windows\setupact.log
2014-04-21 14:41 - 2014-04-22 20:38 - 00002154 _____ () C:\Windows\PFRO.log
2014-04-21 14:41 - 2014-04-21 14:41 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-20 23:19 - 2014-04-20 23:25 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams
2014-04-20 23:19 - 2014-03-05 22:19 - 00007670 ____S () C:\Windows\SysWOW64\mncdbwdqg.vbe
2014-04-20 23:19 - 2013-12-10 00:30 - 10236928 ____S () C:\Windows\SysWOW64\acumncdbwdqg.exe
2014-04-20 23:19 - 2013-10-26 20:30 - 01704448 ____S (The OpenSSL Project, http://www.openssl.org/) C:\Windows\SysWOW64\libeay32.dll
2014-04-20 23:19 - 2013-10-26 20:30 - 00972814 ____S () C:\Windows\SysWOW64\dcgmncdbwdqg.exe
2014-04-20 23:19 - 2013-10-26 20:30 - 00538126 ____S () C:\Windows\SysWOW64\libcurl-4.dll
2014-04-20 23:19 - 2013-10-26 20:30 - 00364544 ____S (The OpenSSL Project, http://www.openssl.org/) C:\Windows\SysWOW64\ssleay32.dll
2014-04-20 23:19 - 2013-10-26 20:30 - 00192512 ____S () C:\Windows\SysWOW64\libidn-11.dll
2014-04-20 23:19 - 2013-10-26 20:30 - 00171008 ____S (The libssh2 library, http://www.libssh2.org/) C:\Windows\SysWOW64\libssh2.dll
2014-04-20 23:19 - 2013-10-26 20:30 - 00133632 ____S () C:\Windows\SysWOW64\librtmp.dll
2014-04-20 23:19 - 2013-10-26 20:30 - 00044727 ____S () C:\Windows\SysWOW64\diablo130302.cl
2014-04-20 23:19 - 2013-10-26 20:30 - 00043810 ____S () C:\Windows\SysWOW64\poclbm130302.cl
2014-04-20 23:19 - 2013-10-26 20:30 - 00030802 ____S () C:\Windows\SysWOW64\diakgcn121016.cl
2014-04-20 23:19 - 2013-10-26 20:30 - 00023825 ____S () C:\Windows\SysWOW64\scrypt130511.cl
2014-04-20 23:19 - 2013-10-26 20:30 - 00013062 ____S () C:\Windows\SysWOW64\phatk121016.cl
2014-04-20 23:19 - 2013-07-18 16:06 - 00187904 ____S () C:\Windows\SysWOW64\lcpmncdbwdqg.exe
2014-04-20 23:19 - 2013-06-12 15:15 - 00119888 ____S (Open Source Software community LGPL) C:\Windows\SysWOW64\pthreadGC2.dll
2014-04-20 23:19 - 2013-06-12 15:15 - 00100864 ____S () C:\Windows\SysWOW64\zlib1.dll
2014-04-20 23:19 - 2012-09-25 23:46 - 00472424 ____S (NVIDIA Corporation) C:\Windows\SysWOW64\cudart32_50_35.dll
2014-04-20 23:19 - 2012-05-27 01:36 - 00055808 ____S (Open Source Software community LGPL) C:\Windows\SysWOW64\pthreadVC2.dll
2014-04-20 20:11 - 2014-04-20 20:11 - 00031564 _____ () C:\Users\Roman\Documents\cc_20140420_201126.reg
2014-04-20 20:11 - 2014-04-20 20:11 - 00005264 _____ () C:\Users\Roman\Documents\cc_20140420_201153.reg
2014-04-20 20:08 - 2014-04-20 20:08 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-04-20 20:08 - 2014-04-20 20:08 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-04-20 20:08 - 2014-04-20 20:08 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-20 15:26 - 2014-04-20 15:26 - 00001184 _____ () C:\Users\Public\Desktop\Alcohol 120%.lnk
2014-04-20 15:12 - 2014-04-20 15:12 - 00074921 _____ () C:\Users\Roman\Downloads\TR4KTOR Simulátor CZ Zobrazit téma - W.A.R. fórum.htm
2014-04-20 14:55 - 2014-04-20 14:55 - 00137266 _____ () C:\Users\Roman\Downloads\Daniel Landa Zobrazit téma - W.A.R. fórum.htm
2014-04-20 14:53 - 2014-04-20 15:06 - 227968150 _____ () C:\Users\Roman\Downloads\TANGO---Komplet-(CZ-2CD-1999).rar
2014-04-19 23:59 - 2014-04-21 15:40 - 00000124 _____ () C:\Users\Roman\Documents\ax_files.xml
2014-04-19 23:50 - 2014-04-20 15:27 - 00000000 ____D () C:\Program Files (x86)\Alcohol Soft
2014-04-19 23:46 - 2014-04-19 23:46 - 00386680 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys
2014-04-19 22:41 - 2014-04-19 22:41 - 00014267 _____ () C:\Users\Roman\Downloads\Ceník obkladačských prací - Koupelny Vála.htm
2014-04-19 21:05 - 2009-05-20 07:26 - 01154560 _____ (C-Media Inc) C:\Windows\system32\Drivers\cmudax3.sys
2014-04-19 21:05 - 2009-04-09 05:22 - 00354304 ____R () C:\Windows\system32\CmiInstallResAll64.dll
2014-04-19 21:05 - 2007-02-27 11:30 - 00036864 _____ (C-Media Electronics Ins.) C:\Windows\system32\cmudax3.dll
2014-04-17 23:09 - 2014-04-17 23:09 - 00000219 _____ () C:\Users\Roman\Documents\tabl.txt
2014-04-16 16:51 - 2014-04-16 16:50 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-04-16 16:51 - 2014-04-16 16:50 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-04-16 16:51 - 2014-04-16 16:50 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-04-16 16:51 - 2014-04-16 16:50 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-04-16 16:50 - 2014-04-16 16:50 - 00000000 ____D () C:\Program Files\Java
2014-04-16 15:52 - 2014-04-16 15:52 - 00000000 ____D () C:\ProgramData\Sun
2014-04-16 15:51 - 2014-04-16 15:51 - 00411368 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2014-04-16 15:51 - 2014-04-16 15:51 - 00153376 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2014-04-16 15:51 - 2014-04-16 15:51 - 00145184 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2014-04-16 15:51 - 2014-04-16 15:51 - 00145184 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2014-04-16 15:51 - 2014-04-16 15:51 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-10 21:41 - 2014-04-21 15:30 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\vlc
2014-04-10 21:40 - 2014-04-10 21:40 - 00001070 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-10 21:40 - 2014-04-10 21:40 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-04-10 21:25 - 2014-04-10 21:29 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-09 16:05 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 16:05 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 16:05 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 16:05 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 16:05 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 16:05 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 16:05 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 16:05 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 16:05 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 16:05 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 16:05 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 16:05 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 16:05 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 16:05 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 16:05 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 16:05 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 16:05 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-06 14:30 - 2006-10-06 20:45 - 00524768 ____R (Microsoft Corporation) C:\Windows\DIFxAPI.dll
2014-04-06 11:19 - 2014-04-06 11:19 - 00000000 ____D () C:\Users\Roman\Documents\Ashampoo Burning Studio 14
2014-03-30 12:52 - 2014-03-30 12:52 - 00000000 ____D () C:\Program Files (x86)\Creative
2014-03-30 12:52 - 1999-01-21 11:35 - 08292462 ____N () C:\Windows\SysWOW64\Drivers\Eapci8m.Ecw
2014-03-30 12:52 - 1999-01-21 11:33 - 04987002 ____N () C:\Windows\SysWOW64\Drivers\Eapci4m.Ecw
2014-03-30 09:50 - 2014-03-30 09:52 - 00000000 ____D () C:\Program Files (x86)\WhereIsIt
2014-03-30 09:50 - 2014-03-30 09:50 - 00000957 _____ () C:\Users\Public\Desktop\WhereIsIt.lnk
2014-03-30 09:50 - 2014-03-30 09:50 - 00000000 ____D () C:\ProgramData\WhereIsIt
2014-03-27 21:55 - 2014-03-27 21:55 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Ashampoo
2014-03-27 21:46 - 2014-03-27 21:55 - 00000000 ____D () C:\Users\Roman\AppData\Local\ashampoo
2014-03-27 21:45 - 2014-03-27 21:46 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-03-27 21:45 - 2014-03-27 21:45 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-03-27 21:05 - 2014-04-10 21:29 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-27 21:05 - 2014-04-10 21:29 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-27 21:05 - 2014-03-27 21:05 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-03-27 21:05 - 2014-03-27 21:05 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-27 21:05 - 2014-03-27 21:05 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Macromedia
2014-03-27 20:14 - 2014-03-27 20:14 - 00000000 ____D () C:\Program Files (x86)\Zoner
2014-03-27 20:13 - 2014-03-27 20:13 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ghostscript
2014-03-27 20:13 - 2014-03-27 20:13 - 00000000 ____D () C:\Program Files (x86)\gs
2014-03-27 20:09 - 2014-03-27 20:09 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Zoner
2014-03-27 20:08 - 2014-03-27 20:09 - 00000000 ____D () C:\Users\Roman\AppData\Local\Zoner
2014-03-27 20:08 - 2014-03-27 20:08 - 00001878 _____ () C:\Users\Public\Desktop\Zoner Photo Studio 16 x64.lnk
2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\ProgramData\Zoner
2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Program Files\Zoner
2014-03-26 22:57 - 2014-03-26 22:57 - 00001828 _____ () C:\Users\Roman\Desktop\Microsoft Office – zástupce.lnk
2014-03-26 22:33 - 2014-03-26 22:33 - 00000161 _____ () C:\Windows\AutoKMS.ini
2014-03-26 17:51 - 2014-03-26 17:51 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-03-26 17:51 - 2014-03-26 17:51 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-03-26 17:33 - 2014-03-26 17:33 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Adobe
2014-03-26 17:31 - 2014-03-26 17:31 - 00000000 ____D () C:\ProgramData\ATI
2014-03-26 17:27 - 2014-03-26 17:27 - 00055445 _____ () C:\Windows\SysWOW64\CCCInstall_201403261627244493.log
2014-03-26 17:27 - 2014-03-26 17:27 - 00000000 ____D () C:\ProgramData\AMD
2014-03-26 17:27 - 2014-03-26 17:27 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-26 17:24 - 2014-03-26 17:24 - 00018637 _____ () C:\Windows\SysWOW64\CCCInstall_201403261624409611.log
2014-03-26 17:22 - 2014-03-26 17:22 - 00000000 ____D () C:\Program Files\AMD
2014-03-26 17:14 - 2014-03-26 17:14 - 00000000 ____D () C:\AMD
2014-03-26 17:12 - 2014-03-26 17:12 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-03-26 17:12 - 2014-03-26 17:12 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-03-26 17:11 - 2014-04-10 21:28 - 00000000 ____D () C:\Users\Roman\AppData\Local\Adobe
2014-03-26 17:11 - 2014-03-30 09:02 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-25 22:16 - 2014-03-25 22:16 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-03-25 22:14 - 2014-03-25 22:14 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-03-25 22:13 - 2014-03-25 22:13 - 00000000 ____D () C:\Windows\PCHEALTH
2014-03-25 22:13 - 2014-03-25 22:13 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services
2014-03-25 22:13 - 2014-03-25 22:13 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
2014-03-25 22:13 - 2014-03-25 22:13 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2014-03-25 22:09 - 2014-03-25 22:09 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-03-25 22:08 - 2014-03-25 22:08 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2014-03-25 22:08 - 2014-03-25 22:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services
2014-03-25 22:07 - 2014-04-09 16:18 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-25 22:07 - 2014-03-25 22:13 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-03-25 22:07 - 2014-03-25 22:07 - 00000000 ___RD () C:\MSOCache
2014-03-25 22:07 - 2014-03-25 22:07 - 00000000 ____D () C:\Users\Roman\AppData\Local\Microsoft Help
2014-03-25 22:07 - 2014-03-25 22:07 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-03-25 19:30 - 2014-03-25 19:30 - 00003184 _____ () C:\Windows\System32\Tasks\{5CAFF9C2-01F8-4824-B3BF-EEF7450C1E8C}
2014-03-25 19:29 - 2014-03-25 19:29 - 00000973 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2014-03-25 19:29 - 2009-12-30 13:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2014-03-25 18:49 - 2014-03-25 18:49 - 00000000 ____D () C:\Users\Roman\AppData\Local\VS Revo Group
2014-03-25 18:49 - 2014-03-25 18:49 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-03-25 18:39 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-25 18:39 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-25 18:39 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-03-25 18:39 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-03-25 18:39 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-03-25 18:39 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-03-25 18:39 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-03-25 18:39 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-03-25 18:39 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-03-25 18:39 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-03-25 18:39 - 2012-02-11 08:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-03-25 18:39 - 2012-02-11 08:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2014-03-25 18:39 - 2011-02-25 08:19 - 02871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-03-25 18:39 - 2011-02-25 07:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-03-24 18:26 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-03-24 18:26 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-03-24 18:21 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-03-24 18:21 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-03-24 18:21 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-03-24 18:21 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-03-24 18:21 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-03-24 18:21 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-03-24 18:21 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-03-24 18:21 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-03-24 18:21 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-03-24 18:21 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-03-24 18:21 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-03-24 18:21 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-03-24 18:21 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-03-24 18:21 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-03-24 18:21 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-03-24 18:21 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-03-24 18:20 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-03-24 18:20 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-03-24 18:20 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2014-03-24 18:20 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-03-24 18:20 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2014-03-24 18:20 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-03-24 18:20 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-03-24 18:19 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-03-24 18:19 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-03-24 18:19 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-03-24 18:19 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-03-24 14:52 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-03-24 14:52 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-03-24 14:52 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-03-24 14:52 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-03-24 14:46 - 2014-03-25 19:10 - 01557208 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-24 14:30 - 2011-03-11 08:41 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2014-03-24 14:30 - 2011-03-11 08:41 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2014-03-24 14:30 - 2011-03-11 08:41 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2014-03-24 14:30 - 2011-03-11 08:41 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2014-03-24 14:30 - 2011-03-11 08:41 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2014-03-24 14:30 - 2011-03-11 08:33 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2014-03-24 14:30 - 2011-03-11 08:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2014-03-24 14:30 - 2011-03-11 07:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2014-03-24 14:30 - 2011-03-11 07:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2014-03-24 14:30 - 2011-03-11 06:37 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-03-24 10:51 - 2014-03-24 10:51 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-03-24 10:34 - 2010-02-23 10:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 12347904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 10926592 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-03-24 10:30 - 2014-03-24 10:30 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-03-24 10:30 - 2014-03-24 10:30 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-24 10:30 - 2014-03-24 10:30 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-24 10:30 - 2014-03-24 10:30 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-24 10:30 - 2014-03-24 10:30 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-24 10:30 - 2014-03-24 10:30 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-03-24 10:30 - 2014-03-24 10:30 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-03-24 10:30 - 2014-03-24 10:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-03-24 10:30 - 2014-03-24 10:30 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-03-24 10:30 - 2014-03-24 10:30 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-03-24 10:17 - 2014-04-09 16:17 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-24 10:17 - 2014-04-09 16:16 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-24 10:15 - 2012-07-26 05:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-03-24 10:15 - 2012-07-26 05:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-03-24 10:15 - 2012-07-26 05:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-03-24 10:15 - 2012-07-26 05:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-03-24 10:15 - 2012-07-26 05:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-03-24 10:15 - 2012-07-26 04:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-03-24 10:15 - 2012-07-26 04:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-03-24 10:15 - 2012-06-02 16:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-03-24 10:10 - 2012-03-01 08:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-03-24 10:10 - 2012-03-01 08:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-03-24 10:10 - 2012-03-01 07:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-03-24 10:02 - 2014-04-13 22:38 - 00000000 ____D () C:\Users\Roman\AppData\Local\GHISLER
2014-03-24 10:01 - 2011-06-16 07:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2014-03-24 10:01 - 2011-06-16 06:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
2014-03-24 10:00 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-24 10:00 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-03-24 10:00 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-03-24 10:00 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-03-24 10:00 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-03-24 10:00 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-03-24 10:00 - 2012-10-09 20:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-03-24 10:00 - 2012-10-09 20:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-03-24 10:00 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-03-24 10:00 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-03-24 10:00 - 2011-06-15 12:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-03-24 10:00 - 2011-06-15 12:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-03-24 10:00 - 2011-06-15 12:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-03-24 10:00 - 2011-06-15 12:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-03-24 10:00 - 2011-06-15 10:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-03-24 10:00 - 2011-06-15 10:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-03-24 10:00 - 2011-06-15 10:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-03-24 10:00 - 2011-06-15 10:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-03-24 10:00 - 2011-06-15 10:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-03-24 10:00 - 2011-04-09 08:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-03-24 10:00 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-03-24 09:59 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-03-24 09:59 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-03-24 09:59 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-03-24 09:59 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-03-24 09:59 - 2011-10-26 07:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-03-24 09:59 - 2011-10-26 06:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-03-24 09:59 - 2010-12-23 12:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-03-24 09:59 - 2010-12-23 12:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-03-24 09:59 - 2010-12-23 12:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-03-24 09:59 - 2010-12-23 07:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-03-24 09:59 - 2010-12-23 07:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-03-24 09:59 - 2010-12-23 07:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-03-24 09:58 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-24 09:58 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-24 09:58 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-03-24 09:58 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-03-24 09:58 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-03-24 09:58 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-03-24 09:58 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-03-24 09:58 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-03-24 09:58 - 2013-10-05 22:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-03-24 09:58 - 2013-10-05 21:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-03-24 09:58 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-03-24 09:58 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-03-24 09:58 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-03-24 09:58 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-03-24 09:58 - 2012-01-04 12:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-03-24 09:58 - 2012-01-04 10:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2014-03-24 09:58 - 2011-11-17 08:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-03-24 09:58 - 2011-11-17 07:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-03-24 09:58 - 2011-07-09 04:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-03-24 09:58 - 2011-05-04 07:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-03-24 09:58 - 2011-05-04 07:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-03-24 09:58 - 2011-05-04 07:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-03-24 09:58 - 2011-05-04 07:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-03-24 09:58 - 2011-05-04 07:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2014-03-24 09:58 - 2011-05-04 07:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2014-03-24 09:58 - 2011-05-04 07:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-03-24 09:58 - 2011-05-04 07:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-03-24 09:58 - 2011-05-04 07:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-03-24 09:58 - 2011-05-04 06:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2014-03-24 09:58 - 2011-05-04 06:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2014-03-24 09:58 - 2011-05-04 06:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2014-03-24 09:58 - 2011-05-04 06:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2014-03-24 09:58 - 2011-05-04 06:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2014-03-24 09:58 - 2011-05-04 06:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2014-03-24 09:58 - 2011-05-04 06:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2014-03-24 09:58 - 2011-05-04 06:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2014-03-24 09:58 - 2011-05-04 06:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2014-03-24 09:58 - 2011-04-27 04:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-03-24 09:58 - 2011-04-27 04:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-03-24 09:57 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-24 09:57 - 2013-12-06 04:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-03-24 09:57 - 2013-12-06 04:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-03-24 09:57 - 2013-12-06 04:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-03-24 09:57 - 2013-12-06 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-03-24 09:57 - 2013-10-04 04:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-03-24 09:57 - 2013-10-04 04:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-03-24 09:57 - 2013-10-04 04:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-03-24 09:57 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-03-24 09:57 - 2013-10-04 03:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2014-03-24 09:57 - 2013-10-04 03:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-03-24 09:57 - 2013-10-04 03:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2014-03-24 09:57 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-03-24 09:57 - 2013-09-28 03:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-03-24 09:57 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-03-24 09:57 - 2011-12-30 08:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-03-24 09:57 - 2011-12-30 07:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2014-03-24 09:56 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-03-24 09:56 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-03-24 09:56 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-03-24 09:56 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-03-24 09:56 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-03-24 09:56 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-03-24 09:56 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-03-24 09:56 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-03-24 09:56 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-03-24 09:56 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-03-24 09:56 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-03-24 09:56 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-03-24 09:56 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-03-24 09:56 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-03-24 09:56 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-03-24 09:56 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-03-24 09:56 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-03-24 09:56 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-03-24 09:56 - 2013-09-25 04:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-03-24 09:56 - 2013-09-25 04:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-03-24 09:56 - 2013-09-25 04:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-03-24 09:56 - 2013-09-25 04:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-03-24 09:56 - 2013-09-25 04:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-03-24 09:56 - 2013-09-25 04:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-03-24 09:56 - 2013-09-25 04:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-03-24 09:56 - 2013-09-25 04:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-03-24 09:56 - 2013-09-25 03:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-03-24 09:56 - 2013-09-25 03:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-03-24 09:56 - 2013-09-25 03:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-03-24 09:56 - 2013-09-25 03:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-03-24 09:56 - 2013-09-25 03:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-03-24 09:56 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-03-24 09:56 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-03-24 09:56 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-03-24 09:56 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-03-24 09:56 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-03-24 09:56 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-03-24 09:56 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-03-24 09:56 - 2013-07-04 14:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-03-24 09:56 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-03-24 09:56 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-03-24 09:56 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-03-24 09:56 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-03-24 09:56 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-03-24 09:56 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-03-24 09:56 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-03-24 09:56 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-03-24 09:56 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-03-24 09:56 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-03-24 09:56 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-03-24 09:56 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-03-24 09:56 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-03-24 09:56 - 2012-08-22 20:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-03-24 09:56 - 2012-07-04 22:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-03-24 09:56 - 2012-04-26 07:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-03-24 09:56 - 2012-04-26 07:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-03-24 09:56 - 2012-04-26 07:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-03-24 09:56 - 2011-03-11 08:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-03-24 09:56 - 2011-03-11 08:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-03-24 09:56 - 2011-03-11 07:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-03-24 09:56 - 2011-03-11 07:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-03-24 09:55 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-03-24 09:55 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-03-24 09:55 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-03-24 09:55 - 2012-11-29 00:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-03-24 09:55 - 2012-11-29 00:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-03-24 09:55 - 2012-11-29 00:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-03-24 09:55 - 2012-11-01 07:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-03-24 09:55 - 2012-11-01 06:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-03-24 09:55 - 2012-10-03 19:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-03-24 09:55 - 2012-10-03 19:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-03-24 09:55 - 2012-10-03 19:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-03-24 09:55 - 2012-10-03 19:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-03-24 09:55 - 2012-10-03 19:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-03-24 09:55 - 2012-10-03 19:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-03-24 09:55 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2014-03-24 09:55 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2014-03-24 09:55 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2014-03-24 09:55 - 2012-10-03 18:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-03-24 09:55 - 2012-05-01 07:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-03-24 09:55 - 2012-01-13 09:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2014-03-24 09:55 - 2011-03-03 08:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-03-24 09:55 - 2011-03-03 08:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-03-24 09:55 - 2011-03-03 08:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-03-24 09:55 - 2011-03-03 07:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-03-24 09:55 - 2011-03-03 07:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-03-24 09:54 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-03-24 09:54 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-03-24 09:54 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-03-24 09:54 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-03-24 09:54 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-03-24 09:54 - 2012-11-02 07:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-03-24 09:54 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-03-24 09:54 - 2012-08-21 23:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-03-24 09:54 - 2011-04-29 05:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-03-24 09:54 - 2011-04-29 05:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-03-24 09:54 - 2011-04-29 05:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-03-24 09:53 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-03-24 09:53 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-03-24 09:53 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-03-24 09:53 - 2012-12-07 15:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-03-24 09:53 - 2012-12-07 15:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-03-24 09:53 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-03-24 09:53 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-03-24 09:53 - 2012-12-07 13:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-03-24 09:53 - 2012-12-07 13:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-03-24 09:53 - 2012-12-07 13:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-03-24 09:53 - 2012-12-07 13:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-03-24 09:53 - 2012-12-07 13:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-03-24 09:53 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-03-24 09:53 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-03-24 09:53 - 2012-12-07 13:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-03-24 09:53 - 2012-12-07 13:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-03-24 09:53 - 2012-12-07 13:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-03-24 09:53 - 2012-12-07 13:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-03-24 09:53 - 2012-12-07 13:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-03-24 09:53 - 2012-12-07 13:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-03-24 09:53 - 2012-12-07 13:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2014-03-24 09:53 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2014-03-24 09:53 - 2012-11-22 07:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-03-24 09:53 - 2012-11-22 06:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-03-24 09:53 - 2012-04-28 05:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-03-24 09:53 - 2011-08-17 07:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-03-24 09:53 - 2011-08-17 07:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-03-24 09:53 - 2011-08-17 06:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-03-24 09:53 - 2011-08-17 06:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-03-24 09:52 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-03-24 09:52 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-03-24 09:52 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-03-24 09:52 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-03-24 09:52 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-03-24 09:52 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-03-24 09:52 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-03-24 09:52 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-03-24 09:52 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-03-24 09:52 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-03-24 09:52 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-03-24 09:52 - 2012-08-11 02:56 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-03-24 09:52 - 2012-08-11 01:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-03-24 09:52 - 2012-04-07 14:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-03-24 09:52 - 2012-04-07 13:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-03-24 09:52 - 2012-03-17 09:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-03-24 09:51 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-24 09:51 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-24 09:51 - 2013-10-03 04:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-03-24 09:51 - 2013-10-03 04:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-03-24 09:51 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-03-24 09:51 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-03-24 09:51 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-03-24 09:51 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-03-24 09:51 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-03-24 09:51 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2014-03-24 09:51 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-03-24 09:51 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-03-24 09:51 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-03-24 09:51 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-03-24 09:51 - 2012-09-26 00:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-03-24 09:51 - 2011-02-05 19:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-03-24 09:51 - 2011-02-05 19:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-03-24 09:51 - 2011-02-05 19:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-03-24 09:51 - 2011-02-05 19:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-03-24 09:51 - 2011-02-05 19:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-03-24 09:51 - 2011-02-05 19:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-03-24 09:51 - 2011-02-05 19:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-03-24 09:50 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-03-24 09:50 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-03-24 09:50 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-03-24 09:50 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-03-24 09:50 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-03-24 09:50 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-03-24 09:50 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-03-24 09:50 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-03-24 09:50 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-03-24 09:50 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-03-24 09:50 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-03-24 09:50 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-03-24 09:50 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-03-24 09:50 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-03-24 09:50 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-03-24 09:50 - 2013-01-03 08:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-03-24 09:50 - 2012-07-05 00:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-03-24 09:50 - 2012-07-05 00:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-03-24 09:50 - 2012-07-05 00:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-03-24 09:50 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-03-24 09:50 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-03-24 09:50 - 2012-05-14 07:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-03-24 09:50 - 2012-05-05 10:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-03-24 09:50 - 2012-05-05 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-03-24 09:50 - 2011-12-16 10:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-03-24 09:50 - 2011-12-16 09:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-03-24 09:50 - 2011-05-24 13:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-03-24 09:50 - 2011-05-24 12:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-03-24 09:50 - 2011-05-24 12:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-03-24 09:50 - 2011-05-24 12:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-03-24 09:50 - 2011-05-24 12:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-03-24 09:50 - 2011-05-03 07:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-03-24 09:50 - 2011-05-03 06:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-03-24 09:50 - 2011-02-18 12:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2014-03-24 09:50 - 2011-02-18 07:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2014-03-24 09:50 - 2011-02-12 13:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-03-24 09:49 - 2013-10-12 04:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-03-24 09:49 - 2013-10-12 04:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-03-24 09:49 - 2013-10-12 04:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-03-24 09:49 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-03-24 09:49 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-03-24 09:49 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-03-24 09:49 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-03-24 09:49 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-03-24 09:49 - 2012-06-06 08:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-03-24 09:49 - 2012-06-06 07:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-03-24 09:49 - 2011-10-15 08:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-03-24 09:49 - 2011-10-15 07:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-03-24 09:49 - 2011-08-27 07:37 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-03-24 09:49 - 2011-08-27 07:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-03-24 09:49 - 2011-08-27 06:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-03-24 09:49 - 2011-08-27 06:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-03-24 09:49 - 2011-02-23 06:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-03-24 09:49 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-03-24 09:44 - 2014-03-24 09:45 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\GHISLER
2014-03-24 09:44 - 2014-03-24 09:44 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-03-24 09:41 - 2014-03-24 09:41 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\WinRAR
2014-03-24 09:41 - 2011-11-19 16:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-03-24 09:41 - 2011-11-19 16:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-03-24 09:38 - 2014-03-24 09:41 - 00000000 ____D () C:\Program Files\WinRAR
2014-03-24 09:38 - 2014-03-24 09:38 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-03-24 09:37 - 2014-03-24 09:37 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-03-24 02:26 - 2014-04-20 20:10 - 00000000 ____D () C:\Windows\Panther
2014-03-24 02:26 - 2014-03-24 02:26 - 00008192 __RSH () C:\BOOTSECT.BAK
2014-03-24 02:26 - 2011-02-16 04:16 - 00000029 ___RH () C:\Windows\version
2014-03-24 02:26 - 2010-11-21 05:23 - 00383786 __RSH () C:\bootmgr
2014-03-24 02:25 - 2014-04-22 20:20 - 00668138 _____ () C:\Windows\system32\perfh005.dat
2014-03-24 02:25 - 2014-04-22 20:20 - 00140798 _____ () C:\Windows\system32\perfc005.dat
2014-03-24 02:25 - 2014-03-24 02:25 - 00000000 ____D () C:\Hotfix
2014-03-24 02:25 - 2014-03-24 02:24 - 00292004 _____ () C:\Windows\system32\perfi005.dat
2014-03-24 02:25 - 2014-03-24 02:24 - 00036232 _____ () C:\Windows\system32\perfd005.dat
2014-03-24 02:25 - 2011-02-16 04:16 - 00000013 ____R () C:\Windows\csup.txt
2014-03-24 02:24 - 2014-03-24 02:24 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-03-24 02:24 - 2014-03-24 02:24 - 00000000 ____D () C:\Windows\SysWOW64\cs
2014-03-24 02:24 - 2014-03-24 02:24 - 00000000 ____D () C:\Windows\system32\cs

roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Re: Prosím o kontrolu logu. Děkuji.

#12 Příspěvek od roman7 »

část 2

==================== One Month Modified Files and Folders =======

2014-04-23 16:12 - 2014-04-23 16:12 - 00006708 _____ () C:\Users\Roman\Desktop\FRST.txt
2014-04-23 16:12 - 2014-04-23 16:07 - 00000000 ____D () C:\FRST
2014-04-23 16:05 - 2014-04-23 16:05 - 02061312 _____ (Farbar) C:\Users\Roman\Desktop\FRST64.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00112640 _____ (forum.viry.cz) C:\Users\Roman\Desktop\FRSTLauncher.exe
2014-04-23 15:59 - 2009-07-14 06:45 - 00025696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-23 15:59 - 2009-07-14 06:45 - 00025696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-23 15:58 - 2014-03-23 17:31 - 01770346 _____ () C:\Windows\WindowsUpdate.log
2014-04-23 15:52 - 2014-04-21 14:41 - 00000560 _____ () C:\Windows\setupact.log
2014-04-23 15:52 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-22 20:39 - 2014-04-22 20:26 - 00004862 _____ () C:\zoek-results.log
2014-04-22 20:38 - 2014-04-21 14:41 - 00002154 _____ () C:\Windows\PFRO.log
2014-04-22 20:36 - 2014-04-22 20:26 - 00000000 ____D () C:\zoek_backup
2014-04-22 20:26 - 2014-04-22 20:37 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-04-22 20:25 - 2014-04-22 20:25 - 01285120 _____ () C:\Users\Roman\Desktop\zoek.exe
2014-04-22 20:20 - 2014-03-24 02:25 - 00668138 _____ () C:\Windows\system32\perfh005.dat
2014-04-22 20:20 - 2014-03-24 02:25 - 00140798 _____ () C:\Windows\system32\perfc005.dat
2014-04-22 20:20 - 2009-07-14 07:13 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-21 20:22 - 2014-04-21 20:14 - 00000000 ____D () C:\ComboFix
2014-04-21 20:22 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-21 20:21 - 2014-04-21 19:43 - 00000000 ____D () C:\Windows\erdnt
2014-04-21 20:16 - 2014-04-21 19:43 - 00000000 ____D () C:\Qoobox
2014-04-21 20:13 - 2014-04-21 20:13 - 00000829 _____ () C:\Users\Roman\Documents\CFScript.txt
2014-04-21 19:52 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-21 19:13 - 2014-04-21 19:12 - 00002516 _____ () C:\Users\Roman\Desktop\Rkill.txt
2014-04-21 19:09 - 2014-04-21 19:09 - 05196870 ____R (Swearware) C:\Users\Roman\Desktop\ComboFix.exe
2014-04-21 19:09 - 2014-04-21 19:09 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Roman\Desktop\rkill.com
2014-04-21 19:05 - 2014-04-21 18:15 - 00000000 ____D () C:\Program Files\totalcmd
2014-04-21 18:26 - 2014-04-21 18:26 - 00000000 ____D () C:\rsit
2014-04-21 18:26 - 2014-04-21 18:26 - 00000000 ____D () C:\Program Files\trend micro
2014-04-21 18:26 - 2014-04-21 18:25 - 00832273 _____ () C:\Users\Roman\Downloads\RSITx64.exe
2014-04-21 16:24 - 2014-04-21 14:43 - 00000062 _____ () C:\Users\Roman\rgut
2014-04-21 15:57 - 2014-04-21 15:57 - 10212608 _____ (CCCP Project ) C:\Users\Roman\Downloads\Combined-Community-Codec-Pack-2014-04-20.exe
2014-04-21 15:40 - 2014-04-19 23:59 - 00000124 _____ () C:\Users\Roman\Documents\ax_files.xml
2014-04-21 15:30 - 2014-04-10 21:41 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\vlc
2014-04-21 14:45 - 2014-04-21 14:45 - 00000003 _____ () C:\Users\Roman\stut
2014-04-21 14:45 - 2014-03-23 17:36 - 00000000 ____D () C:\Users\Roman
2014-04-21 14:43 - 2014-04-21 14:43 - 00000000 ____D () C:\Users\Roman\AppData\Local\CrashDumps
2014-04-21 14:42 - 2014-04-21 14:42 - 00000000 _____ () C:\Users\Roman\regbcm
2014-04-21 14:41 - 2014-04-21 14:41 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-20 23:25 - 2014-04-20 23:19 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams
2014-04-20 22:56 - 2014-03-23 17:36 - 00000000 ____D () C:\Users\Roman\AppData\Local\VirtualStore
2014-04-20 20:11 - 2014-04-20 20:11 - 00031564 _____ () C:\Users\Roman\Documents\cc_20140420_201126.reg
2014-04-20 20:11 - 2014-04-20 20:11 - 00005264 _____ () C:\Users\Roman\Documents\cc_20140420_201153.reg
2014-04-20 20:10 - 2014-03-24 02:26 - 00000000 ____D () C:\Windows\Panther
2014-04-20 20:08 - 2014-04-20 20:08 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-04-20 20:08 - 2014-04-20 20:08 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-04-20 20:08 - 2014-04-20 20:08 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-20 15:27 - 2014-04-19 23:50 - 00000000 ____D () C:\Program Files (x86)\Alcohol Soft
2014-04-20 15:26 - 2014-04-20 15:26 - 00001184 _____ () C:\Users\Public\Desktop\Alcohol 120%.lnk
2014-04-20 15:12 - 2014-04-20 15:12 - 00074921 _____ () C:\Users\Roman\Downloads\TR4KTOR Simulátor CZ Zobrazit téma - W.A.R. fórum.htm
2014-04-20 15:06 - 2014-04-20 14:53 - 227968150 _____ () C:\Users\Roman\Downloads\TANGO---Komplet-(CZ-2CD-1999).rar
2014-04-20 14:55 - 2014-04-20 14:55 - 00137266 _____ () C:\Users\Roman\Downloads\Daniel Landa Zobrazit téma - W.A.R. fórum.htm
2014-04-19 23:46 - 2014-04-19 23:46 - 00386680 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys
2014-04-19 22:41 - 2014-04-19 22:41 - 00014267 _____ () C:\Users\Roman\Downloads\Ceník obkladačských prací - Koupelny Vála.htm
2014-04-19 21:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system
2014-04-19 21:05 - 2007-10-20 03:01 - 00000073 _____ () C:\Windows\system\Cmicnfg3.ini
2014-04-17 23:09 - 2014-04-17 23:09 - 00000219 _____ () C:\Users\Roman\Documents\tabl.txt
2014-04-16 16:50 - 2014-04-16 16:51 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-04-16 16:50 - 2014-04-16 16:51 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-04-16 16:50 - 2014-04-16 16:51 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-04-16 16:50 - 2014-04-16 16:51 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-04-16 16:50 - 2014-04-16 16:50 - 00000000 ____D () C:\Program Files\Java
2014-04-16 15:52 - 2014-04-16 15:52 - 00000000 ____D () C:\ProgramData\Sun
2014-04-16 15:51 - 2014-04-16 15:51 - 00411368 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2014-04-16 15:51 - 2014-04-16 15:51 - 00153376 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2014-04-16 15:51 - 2014-04-16 15:51 - 00145184 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2014-04-16 15:51 - 2014-04-16 15:51 - 00145184 _____ (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2014-04-16 15:51 - 2014-04-16 15:51 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-13 22:38 - 2014-03-24 10:02 - 00000000 ____D () C:\Users\Roman\AppData\Local\GHISLER
2014-04-13 15:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-10 21:40 - 2014-04-10 21:40 - 00001070 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-10 21:40 - 2014-04-10 21:40 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-04-10 21:29 - 2014-04-10 21:25 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-10 21:29 - 2014-03-27 21:05 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-10 21:29 - 2014-03-27 21:05 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-10 21:28 - 2014-03-26 17:11 - 00000000 ____D () C:\Users\Roman\AppData\Local\Adobe
2014-04-09 16:18 - 2014-03-25 22:07 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 16:17 - 2014-03-24 10:17 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 16:16 - 2014-03-24 10:17 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-06 11:19 - 2014-04-06 11:19 - 00000000 ____D () C:\Users\Roman\Documents\Ashampoo Burning Studio 14
2014-04-06 11:11 - 2010-11-21 09:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-04-03 16:26 - 2014-03-23 17:49 - 00001945 _____ () C:\Windows\epplauncher.mif
2014-04-03 16:26 - 2014-03-23 17:49 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-03 16:25 - 2014-03-23 17:49 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-03 16:23 - 2014-03-23 18:45 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-03-30 12:52 - 2014-03-30 12:52 - 00000000 ____D () C:\Program Files (x86)\Creative
2014-03-30 09:52 - 2014-03-30 09:50 - 00000000 ____D () C:\Program Files (x86)\WhereIsIt
2014-03-30 09:50 - 2014-03-30 09:50 - 00000957 _____ () C:\Users\Public\Desktop\WhereIsIt.lnk
2014-03-30 09:50 - 2014-03-30 09:50 - 00000000 ____D () C:\ProgramData\WhereIsIt
2014-03-30 09:02 - 2014-03-26 17:11 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-27 22:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-27 21:55 - 2014-03-27 21:55 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Ashampoo
2014-03-27 21:55 - 2014-03-27 21:46 - 00000000 ____D () C:\Users\Roman\AppData\Local\ashampoo
2014-03-27 21:46 - 2014-03-27 21:45 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-03-27 21:45 - 2014-03-27 21:45 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-03-27 21:05 - 2014-03-27 21:05 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-03-27 21:05 - 2014-03-27 21:05 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-27 21:05 - 2014-03-27 21:05 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Macromedia
2014-03-27 20:14 - 2014-03-27 20:14 - 00000000 ____D () C:\Program Files (x86)\Zoner
2014-03-27 20:13 - 2014-03-27 20:13 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ghostscript
2014-03-27 20:13 - 2014-03-27 20:13 - 00000000 ____D () C:\Program Files (x86)\gs
2014-03-27 20:09 - 2014-03-27 20:09 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Zoner
2014-03-27 20:09 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Roman\AppData\Local\Zoner
2014-03-27 20:08 - 2014-03-27 20:08 - 00001878 _____ () C:\Users\Public\Desktop\Zoner Photo Studio 16 x64.lnk
2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\ProgramData\Zoner
2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Program Files\Zoner
2014-03-27 18:19 - 2009-07-14 04:34 - 00000478 _____ () C:\Windows\win.ini
2014-03-26 22:57 - 2014-03-26 22:57 - 00001828 _____ () C:\Users\Roman\Desktop\Microsoft Office – zástupce.lnk
2014-03-26 22:33 - 2014-03-26 22:33 - 00000161 _____ () C:\Windows\AutoKMS.ini
2014-03-26 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-03-26 17:51 - 2014-03-26 17:51 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-03-26 17:51 - 2014-03-26 17:51 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-03-26 17:33 - 2014-03-26 17:33 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Adobe
2014-03-26 17:31 - 2014-03-26 17:31 - 00000000 ____D () C:\ProgramData\ATI
2014-03-26 17:27 - 2014-03-26 17:27 - 00055445 _____ () C:\Windows\SysWOW64\CCCInstall_201403261627244493.log
2014-03-26 17:27 - 2014-03-26 17:27 - 00000000 ____D () C:\ProgramData\AMD
2014-03-26 17:27 - 2014-03-26 17:27 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-26 17:26 - 2014-03-23 18:05 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-03-26 17:25 - 2014-03-23 18:06 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2014-03-26 17:24 - 2014-03-26 17:24 - 00018637 _____ () C:\Windows\SysWOW64\CCCInstall_201403261624409611.log
2014-03-26 17:22 - 2014-03-26 17:22 - 00000000 ____D () C:\Program Files\AMD
2014-03-26 17:14 - 2014-03-26 17:14 - 00000000 ____D () C:\AMD
2014-03-26 17:12 - 2014-03-26 17:12 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-03-26 17:12 - 2014-03-26 17:12 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-03-25 22:23 - 2014-03-23 17:49 - 00109280 _____ () C:\Users\Roman\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-25 22:22 - 2009-07-14 06:45 - 00416952 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-25 22:20 - 2010-11-21 09:17 - 00000000 ____D () C:\Program Files\Windows Journal
2014-03-25 22:20 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2014-03-25 22:20 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2014-03-25 22:20 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-03-25 22:20 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-03-25 22:20 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-25 22:20 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\DVD Maker
2014-03-25 22:20 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2014-03-25 22:20 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-03-25 22:20 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-03-25 22:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2014-03-25 22:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\servicing
2014-03-25 22:19 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2014-03-25 22:19 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2014-03-25 22:19 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\winrm
2014-03-25 22:19 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\WCN
2014-03-25 22:19 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\slmgr
2014-03-25 22:19 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2014-03-25 22:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-03-25 22:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\migwiz
2014-03-25 22:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-03-25 22:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech
2014-03-25 22:16 - 2014-03-25 22:16 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-03-25 22:14 - 2014-03-25 22:14 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-03-25 22:14 - 2010-11-21 09:17 - 00000000 ____D () C:\Windows\ShellNew
2014-03-25 22:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-25 22:13 - 2014-03-25 22:13 - 00000000 ____D () C:\Windows\PCHEALTH
2014-03-25 22:13 - 2014-03-25 22:13 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services
2014-03-25 22:13 - 2014-03-25 22:13 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
2014-03-25 22:13 - 2014-03-25 22:13 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2014-03-25 22:13 - 2014-03-25 22:07 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-03-25 22:13 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-03-25 22:09 - 2014-03-25 22:09 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-03-25 22:08 - 2014-03-25 22:08 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2014-03-25 22:08 - 2014-03-25 22:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services
2014-03-25 22:07 - 2014-03-25 22:07 - 00000000 ___RD () C:\MSOCache
2014-03-25 22:07 - 2014-03-25 22:07 - 00000000 ____D () C:\Users\Roman\AppData\Local\Microsoft Help
2014-03-25 22:07 - 2014-03-25 22:07 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-03-25 19:30 - 2014-03-25 19:30 - 00003184 _____ () C:\Windows\System32\Tasks\{5CAFF9C2-01F8-4824-B3BF-EEF7450C1E8C}
2014-03-25 19:29 - 2014-03-25 19:29 - 00000973 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2014-03-25 19:10 - 2014-03-24 14:46 - 01557208 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-25 18:49 - 2014-03-25 18:49 - 00000000 ____D () C:\Users\Roman\AppData\Local\VS Revo Group
2014-03-25 18:49 - 2014-03-25 18:49 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-03-24 20:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-24 18:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-03-24 14:23 - 2014-03-23 17:36 - 00001447 _____ () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-24 14:23 - 2014-03-23 17:36 - 00001413 _____ () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-03-24 14:23 - 2014-03-23 17:36 - 00000000 ___RD () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-24 14:23 - 2014-03-23 17:36 - 00000000 ___RD () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-24 14:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-03-24 14:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-03-24 14:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-03-24 14:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-03-24 10:51 - 2014-03-24 10:51 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-03-24 10:51 - 2014-03-24 10:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 17847808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 12347904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 10926592 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-03-24 10:30 - 2014-03-24 10:30 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-03-24 10:30 - 2014-03-24 10:30 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-24 10:30 - 2014-03-24 10:30 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-24 10:30 - 2014-03-24 10:30 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-24 10:30 - 2014-03-24 10:30 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-24 10:30 - 2014-03-24 10:30 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-03-24 10:30 - 2014-03-24 10:30 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-03-24 10:30 - 2014-03-24 10:30 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-03-24 10:30 - 2014-03-24 10:30 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-03-24 10:30 - 2014-03-24 10:30 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-03-24 10:30 - 2014-03-24 10:30 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-03-24 10:30 - 2014-03-24 10:30 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-03-24 09:45 - 2014-03-24 09:44 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\GHISLER
2014-03-24 09:44 - 2014-03-24 09:44 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-03-24 09:41 - 2014-03-24 09:41 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\WinRAR
2014-03-24 09:41 - 2014-03-24 09:38 - 00000000 ____D () C:\Program Files\WinRAR
2014-03-24 09:38 - 2014-03-24 09:38 - 00000000 ____D () C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-03-24 09:37 - 2014-03-24 09:37 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-03-24 02:26 - 2014-03-24 02:26 - 00008192 __RSH () C:\BOOTSECT.BAK
2014-03-24 02:26 - 2009-07-14 07:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-03-24 02:26 - 2009-07-14 07:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-03-24 02:25 - 2014-03-24 02:25 - 00000000 ____D () C:\Hotfix
2014-03-24 02:25 - 2009-07-14 06:45 - 00000000 ____D () C:\Windows\Setup
2014-03-24 02:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Recovery
2014-03-24 02:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\oobe
2014-03-24 02:24 - 2014-03-24 02:25 - 00292004 _____ () C:\Windows\system32\perfi005.dat
2014-03-24 02:24 - 2014-03-24 02:25 - 00036232 _____ () C:\Windows\system32\perfd005.dat
2014-03-24 02:24 - 2014-03-24 02:24 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-03-24 02:24 - 2014-03-24 02:24 - 00000000 ____D () C:\Windows\SysWOW64\cs
2014-03-24 02:24 - 2014-03-24 02:24 - 00000000 ____D () C:\Windows\system32\cs
2014-03-24 02:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2014-03-24 02:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\com
2014-03-24 02:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\MUI
2014-03-24 02:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\com
2014-03-24 02:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\IME

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-20 13:44




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:74.52 GB) (Free:45.54 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:37.26 GB) (Free:3.5 GB) NTFS

Available physical RAM: 1310.41 MB
Total physical RAM: 2047.24 MB
Percentage of memory in use: 35%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: F93FF93F)
Partition 1: (Active) - (Size=75 GB) - (Type=07 NTFS)
Disk: 1 (Size: 37 GB) (Disk ID: C901C901)
Partition 1: (Not Active) - (Size=37 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================


==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Roman\Desktop" je 10 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Service 16
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe" [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Přílohy
Addition.rar
(5.54 KiB) Staženo 60 x

roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Re: Prosím o kontrolu logu. Děkuji.

#13 Příspěvek od roman7 »

Ještě jsem se chtěl zeptat začalo blbnout PC při spouštění. Zapnu pc to 3x zapípá (to už vím, že je špatně protože normálně píplo 1x ) myš svítí, klávesnice taky pc jako pracuje, ale monitor se nerožne. Když ho zapnu sám tak se vypne. Vypnu pc takz. natvrdo, pc se zrestartuje (1x pípne) a vše funguje. Akorát skočí obrazovka jak se má spustit. To mi začalo dělat právě, až teď. Tak nevím jestli to nějak souvisí.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu. Děkuji.

#14 Příspěvek od vyosek »

To pipani je BIOSu a signalizuje nejaky HW problem - zreme grafika nebo monitor
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

roman7
Návštěvník
Návštěvník
Příspěvky: 339
Registrován: 25 bře 2008 23:09

Re: Prosím o kontrolu logu. Děkuji.

#15 Příspěvek od roman7 »

Zdravím, problém se startem pc jsem možná prozatím odstranil (aspoň to tak vypadá). Budeme pokračovat nebo budeme uklízet?

Odpovědět