
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosím o kontrolu logu.
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
prosím o kontrolu logu.
mimo jiné mám problém s tím že mi padá internet
Logfile of random's system information tool 1.06 (written by random/random)
Run by Venda at 2010-01-13 19:19:13
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 271 GB (59%) free of 461 GB
Total RAM: 4060 MB (60% free)
======Scheduled tasks folder======
C:\Windows\tasks\User_Feed_Synchronization-{9571913D-59A1-47AE-AECF-0750440F22DD}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-29 61440]
"PDVDDXSrv"=C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2008-05-23 128296]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2009-07-17 288080]
"avast!"=C:\venca\programz\Avast\AVAST_~1\ashDisp.exe [2009-11-25 81000]
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"ZoneAlarm Client"=C:\venca\programz\firewall\ZoneAlarm\zlclient.exe [2009-02-16 981384]
"SafeQ Client"=C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe [2009-02-18 188416]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 138240]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
CLS12.50.lnk - C:\venca\Edgecam\program_Edgecam\Cam\cls.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9aea2744-d51a-11de-8a8f-0026b900d528}]
shell\AutoRun\command - F:\MafiaLauncher.EXE
======File associations======
.js - edit - C:\Windows\SysWOW64\Notepad.exe %1
.js - open - C:\Windows\SysWOW64\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-01-13 19:17:04 ----D---- C:\Program Files (x86)\trend micro
2010-01-13 19:17:03 ----D---- C:\rsit
2010-01-13 14:30:32 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 14:30:32 ----A---- C:\Windows\system32\fontsub.dll
2010-01-07 09:04:13 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-01-07 09:03:44 ----A---- C:\Windows\system32\PnkBstrA.exe
2009-12-28 21:16:34 ----A---- C:\Windows\game.ini
2009-12-28 21:11:02 ----D---- C:\Program Files (x86)\Activision
2009-12-21 23:08:55 ----D---- C:\Users\Venda\AppData\Roaming\uTorrent
2009-12-17 15:24:43 ----A---- C:\Windows\WININIT.INI
2009-12-16 22:43:17 ----A---- C:\Windows\system32\XAudio2_5.dll
2009-12-16 22:43:16 ----A---- C:\Windows\system32\xactengine3_5.dll
2009-12-16 22:43:16 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2009-12-16 22:43:15 ----A---- C:\Windows\system32\d3dx11_42.dll
2009-12-16 22:43:15 ----A---- C:\Windows\system32\d3dx10_42.dll
2009-12-16 22:43:15 ----A---- C:\Windows\system32\d3dcsx_42.dll
2009-12-16 22:43:14 ----A---- C:\Windows\system32\D3DX9_42.dll
2009-12-16 22:43:13 ----A---- C:\Windows\system32\d3dx10_41.dll
2009-12-16 22:43:13 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2009-12-16 22:43:12 ----A---- C:\Windows\system32\XAudio2_4.dll
2009-12-16 22:43:12 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2009-12-16 22:43:12 ----A---- C:\Windows\system32\D3DX9_41.dll
2009-12-16 22:43:11 ----A---- C:\Windows\system32\xactengine3_4.dll
2009-12-16 22:43:11 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2009-12-16 22:43:10 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-12-16 22:43:10 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-12-16 22:43:09 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-12-16 22:43:09 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-12-16 22:43:09 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-12-16 22:43:06 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-12-16 22:43:06 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-12-16 22:43:05 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-12-16 22:43:05 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-12-16 22:43:05 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-12-16 22:43:04 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-12-16 22:43:04 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-12-16 22:43:04 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-12-16 22:43:03 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-12-16 22:43:03 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-12-16 22:43:02 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-12-16 22:43:02 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-12-16 22:43:02 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-12-16 22:43:02 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-12-16 22:43:01 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-12-16 22:43:00 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-12-16 22:43:00 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-12-16 22:43:00 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-12-16 22:42:59 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-12-16 22:42:59 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-12-16 22:42:59 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-12-16 22:42:58 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-12-16 22:42:57 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-12-16 22:42:57 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-12-16 22:42:57 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-12-16 22:42:56 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-12-16 22:42:55 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-12-16 22:42:55 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-12-16 22:42:53 ----A---- C:\Windows\system32\xinput1_3.dll
2009-12-16 22:42:53 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-12-16 22:42:52 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-12-16 22:42:52 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-12-16 22:42:52 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-12-16 22:42:52 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-12-16 22:42:51 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-12-16 22:42:50 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-12-16 22:42:50 ----A---- C:\Windows\system32\d3dx10.dll
2009-12-16 22:42:48 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-12-16 22:42:48 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-12-16 22:42:48 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-12-16 22:42:47 ----A---- C:\Windows\system32\xinput1_2.dll
2009-12-16 22:42:47 ----A---- C:\Windows\system32\xinput1_1.dll
2009-12-16 22:42:47 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-12-16 22:42:47 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-12-16 22:42:46 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-12-16 22:42:38 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-12-16 22:42:38 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-12-16 22:42:38 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-12-16 22:42:37 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-12-16 22:42:37 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-12-16 22:42:36 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-12-16 22:42:36 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-12-16 22:42:36 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-12-16 22:42:35 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-12-16 22:37:44 ----D---- C:\ProgramData\Roxio
2009-12-16 22:37:43 ----D---- C:\Users\Venda\AppData\Roaming\Roxio
======List of files/folders modified in the last 1 months======
2010-01-13 19:19:12 ----D---- C:\Windows\Temp
2010-01-13 19:17:04 ----RD---- C:\Program Files (x86)
2010-01-13 19:16:44 ----D---- C:\Windows\Prefetch
2010-01-13 19:15:27 ----D---- C:\Windows\Internet Logs
2010-01-13 19:08:23 ----D---- C:\Windows\System32
2010-01-13 18:58:12 ----D---- C:\Windows
2010-01-13 18:19:08 ----D---- C:\Users\Venda\AppData\Roaming\ICQ
2010-01-13 15:11:04 ----D---- C:\Windows\tracing
2010-01-13 15:11:02 ----D---- C:\Windows\SysWOW64
2010-01-13 14:40:09 ----D---- C:\Windows\winsxs
2010-01-13 14:39:40 ----SHD---- C:\Windows\Installer
2010-01-13 14:39:38 ----D---- C:\ProgramData\Microsoft Help
2010-01-13 14:38:10 ----D---- C:\Program Files (x86)\Windows Mail
2010-01-13 14:32:37 ----D---- C:\Windows\Debug
2010-01-13 14:32:29 ----SHD---- C:\System Volume Information
2010-01-12 16:25:58 ----D---- C:\DELL
2010-01-11 22:37:45 ----D---- C:\Users\Venda\AppData\Roaming\vlc
2010-01-11 19:43:49 ----D---- C:\Windows\Minidump
2010-01-10 22:22:39 ----D---- C:\Windows\inf
2010-01-10 11:25:23 ----D---- C:\venca
2010-01-07 00:06:27 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-01-06 23:17:41 ----D---- C:\Users\Venda\AppData\Roaming\GHISLER
2010-01-06 23:17:37 ----D---- C:\Program Files (x86)\Common Files\Roxio Shared
2010-01-06 23:17:37 ----D---- C:\Program Files (x86)\Common Files
2010-01-06 23:17:34 ----RSD---- C:\Windows\Media
2010-01-06 23:17:34 ----D---- C:\Windows\Tasks
2010-01-06 23:17:33 ----D---- C:\Windows\registration
2010-01-06 22:13:53 ----D---- C:\Windows\system32\wbem
2010-01-06 22:13:52 ----D---- C:\Windows\rescache
2010-01-06 22:13:31 ----D---- C:\Windows\system32\migration
2010-01-06 22:13:31 ----D---- C:\Windows\system32\en-US
2010-01-06 22:13:29 ----D---- C:\Program Files (x86)\Internet Explorer
2010-01-06 21:59:07 ----SD---- C:\Windows\Downloaded Program Files
2010-01-04 20:58:55 ----SD---- C:\Users\Venda\AppData\Roaming\Microsoft
2010-01-04 10:18:12 ----HD---- C:\ProgramData
2009-12-30 23:52:25 ----D---- C:\Windows\system32\drivers
2009-12-28 21:00:38 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2009-12-16 22:49:47 ----RSD---- C:\Windows\assembly
2009-12-16 22:42:39 ----D---- C:\Windows\Microsoft.NET
2009-12-16 22:41:23 ----D---- C:\Windows\Logs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys []
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys []
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys []
R1 LUMDriver;LUMDriver; \??\C:\Windows\system32\drivers\LUMDriver.sys []
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys []
R2 {1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7};{1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}; \??\C:\Program Files (x86)\CyberLink\PowerDVD DX\000.fcl [2008-06-26 32240]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys []
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys []
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmpx64.sys []
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimspx64.sys []
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys []
R3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\Windows\system32\DRIVERS\CtClsFlt.sys []
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys []
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys []
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys []
R3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\NETw5v64.sys []
R3 OA008Ufd;Creative Camera OA008 Upper Filter Driver; C:\Windows\system32\DRIVERS\OA008Ufd.sys []
R3 OA008Vid;Creative Camera OA008 Function Driver; C:\Windows\system32\DRIVERS\OA008Vid.sys []
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys []
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys []
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys []
S2 Sentinel;Sentinel; C:\Windows\System32\Drivers\SENTINEL.SYS [2008-01-02 76288]
S3 agswk8vc;agswk8vc; C:\Windows\system32\drivers\agswk8vc.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys []
S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032e.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys []
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys []
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys []
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys []
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys []
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys []
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe []
R2 aswUpdSv;avast! iAVS4 Control Service; C:\venca\programz\Avast\avast_instal\aswUpdSv.exe [2009-11-25 18752]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe []
R2 avast! Antivirus;avast! Antivirus; C:\venca\programz\Avast\avast_instal\ashServ.exe [2009-11-25 138680]
R2 DockLoginService;Dock Login Service; C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
R2 MSSQL$ECSQLEXPRESS;SQL Server (ECSQLEXPRESS); c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-01-07 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2010-01-11 214520]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-25 153952]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe []
R2 vsmon;TrueVector Internet Monitor; C:\Windows\SysWOW64\ZoneLabs\vsmon.exe [2009-02-16 2402184]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 2297216]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\venca\programz\Avast\avast_instal\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\venca\programz\Avast\avast_instal\ashWebSv.exe [2009-11-25 352920]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-03-29 89920]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-21 19968]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Venda at 2010-01-13 19:19:13
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 271 GB (59%) free of 461 GB
Total RAM: 4060 MB (60% free)
======Scheduled tasks folder======
C:\Windows\tasks\User_Feed_Synchronization-{9571913D-59A1-47AE-AECF-0750440F22DD}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-29 61440]
"PDVDDXSrv"=C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2008-05-23 128296]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2009-07-17 288080]
"avast!"=C:\venca\programz\Avast\AVAST_~1\ashDisp.exe [2009-11-25 81000]
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"ZoneAlarm Client"=C:\venca\programz\firewall\ZoneAlarm\zlclient.exe [2009-02-16 981384]
"SafeQ Client"=C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe [2009-02-18 188416]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 138240]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
CLS12.50.lnk - C:\venca\Edgecam\program_Edgecam\Cam\cls.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9aea2744-d51a-11de-8a8f-0026b900d528}]
shell\AutoRun\command - F:\MafiaLauncher.EXE
======File associations======
.js - edit - C:\Windows\SysWOW64\Notepad.exe %1
.js - open - C:\Windows\SysWOW64\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-01-13 19:17:04 ----D---- C:\Program Files (x86)\trend micro
2010-01-13 19:17:03 ----D---- C:\rsit
2010-01-13 14:30:32 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 14:30:32 ----A---- C:\Windows\system32\fontsub.dll
2010-01-07 09:04:13 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-01-07 09:03:44 ----A---- C:\Windows\system32\PnkBstrA.exe
2009-12-28 21:16:34 ----A---- C:\Windows\game.ini
2009-12-28 21:11:02 ----D---- C:\Program Files (x86)\Activision
2009-12-21 23:08:55 ----D---- C:\Users\Venda\AppData\Roaming\uTorrent
2009-12-17 15:24:43 ----A---- C:\Windows\WININIT.INI
2009-12-16 22:43:17 ----A---- C:\Windows\system32\XAudio2_5.dll
2009-12-16 22:43:16 ----A---- C:\Windows\system32\xactengine3_5.dll
2009-12-16 22:43:16 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2009-12-16 22:43:15 ----A---- C:\Windows\system32\d3dx11_42.dll
2009-12-16 22:43:15 ----A---- C:\Windows\system32\d3dx10_42.dll
2009-12-16 22:43:15 ----A---- C:\Windows\system32\d3dcsx_42.dll
2009-12-16 22:43:14 ----A---- C:\Windows\system32\D3DX9_42.dll
2009-12-16 22:43:13 ----A---- C:\Windows\system32\d3dx10_41.dll
2009-12-16 22:43:13 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2009-12-16 22:43:12 ----A---- C:\Windows\system32\XAudio2_4.dll
2009-12-16 22:43:12 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2009-12-16 22:43:12 ----A---- C:\Windows\system32\D3DX9_41.dll
2009-12-16 22:43:11 ----A---- C:\Windows\system32\xactengine3_4.dll
2009-12-16 22:43:11 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2009-12-16 22:43:10 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-12-16 22:43:10 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-12-16 22:43:09 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-12-16 22:43:09 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-12-16 22:43:09 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-12-16 22:43:06 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-12-16 22:43:06 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-12-16 22:43:05 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-12-16 22:43:05 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-12-16 22:43:05 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-12-16 22:43:04 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-12-16 22:43:04 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-12-16 22:43:04 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-12-16 22:43:03 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-12-16 22:43:03 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-12-16 22:43:02 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-12-16 22:43:02 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-12-16 22:43:02 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-12-16 22:43:02 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-12-16 22:43:01 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-12-16 22:43:00 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-12-16 22:43:00 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-12-16 22:43:00 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-12-16 22:42:59 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-12-16 22:42:59 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-12-16 22:42:59 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-12-16 22:42:58 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-12-16 22:42:57 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-12-16 22:42:57 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-12-16 22:42:57 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-12-16 22:42:56 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-12-16 22:42:55 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-12-16 22:42:55 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-12-16 22:42:54 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-12-16 22:42:53 ----A---- C:\Windows\system32\xinput1_3.dll
2009-12-16 22:42:53 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-12-16 22:42:52 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-12-16 22:42:52 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-12-16 22:42:52 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-12-16 22:42:52 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-12-16 22:42:51 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-12-16 22:42:50 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-12-16 22:42:50 ----A---- C:\Windows\system32\d3dx10.dll
2009-12-16 22:42:48 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-12-16 22:42:48 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-12-16 22:42:48 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-12-16 22:42:47 ----A---- C:\Windows\system32\xinput1_2.dll
2009-12-16 22:42:47 ----A---- C:\Windows\system32\xinput1_1.dll
2009-12-16 22:42:47 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-12-16 22:42:47 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-12-16 22:42:46 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-12-16 22:42:38 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-12-16 22:42:38 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-12-16 22:42:38 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-12-16 22:42:37 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-12-16 22:42:37 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-12-16 22:42:36 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-12-16 22:42:36 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-12-16 22:42:36 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-12-16 22:42:35 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-12-16 22:37:44 ----D---- C:\ProgramData\Roxio
2009-12-16 22:37:43 ----D---- C:\Users\Venda\AppData\Roaming\Roxio
======List of files/folders modified in the last 1 months======
2010-01-13 19:19:12 ----D---- C:\Windows\Temp
2010-01-13 19:17:04 ----RD---- C:\Program Files (x86)
2010-01-13 19:16:44 ----D---- C:\Windows\Prefetch
2010-01-13 19:15:27 ----D---- C:\Windows\Internet Logs
2010-01-13 19:08:23 ----D---- C:\Windows\System32
2010-01-13 18:58:12 ----D---- C:\Windows
2010-01-13 18:19:08 ----D---- C:\Users\Venda\AppData\Roaming\ICQ
2010-01-13 15:11:04 ----D---- C:\Windows\tracing
2010-01-13 15:11:02 ----D---- C:\Windows\SysWOW64
2010-01-13 14:40:09 ----D---- C:\Windows\winsxs
2010-01-13 14:39:40 ----SHD---- C:\Windows\Installer
2010-01-13 14:39:38 ----D---- C:\ProgramData\Microsoft Help
2010-01-13 14:38:10 ----D---- C:\Program Files (x86)\Windows Mail
2010-01-13 14:32:37 ----D---- C:\Windows\Debug
2010-01-13 14:32:29 ----SHD---- C:\System Volume Information
2010-01-12 16:25:58 ----D---- C:\DELL
2010-01-11 22:37:45 ----D---- C:\Users\Venda\AppData\Roaming\vlc
2010-01-11 19:43:49 ----D---- C:\Windows\Minidump
2010-01-10 22:22:39 ----D---- C:\Windows\inf
2010-01-10 11:25:23 ----D---- C:\venca
2010-01-07 00:06:27 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-01-06 23:17:41 ----D---- C:\Users\Venda\AppData\Roaming\GHISLER
2010-01-06 23:17:37 ----D---- C:\Program Files (x86)\Common Files\Roxio Shared
2010-01-06 23:17:37 ----D---- C:\Program Files (x86)\Common Files
2010-01-06 23:17:34 ----RSD---- C:\Windows\Media
2010-01-06 23:17:34 ----D---- C:\Windows\Tasks
2010-01-06 23:17:33 ----D---- C:\Windows\registration
2010-01-06 22:13:53 ----D---- C:\Windows\system32\wbem
2010-01-06 22:13:52 ----D---- C:\Windows\rescache
2010-01-06 22:13:31 ----D---- C:\Windows\system32\migration
2010-01-06 22:13:31 ----D---- C:\Windows\system32\en-US
2010-01-06 22:13:29 ----D---- C:\Program Files (x86)\Internet Explorer
2010-01-06 21:59:07 ----SD---- C:\Windows\Downloaded Program Files
2010-01-04 20:58:55 ----SD---- C:\Users\Venda\AppData\Roaming\Microsoft
2010-01-04 10:18:12 ----HD---- C:\ProgramData
2009-12-30 23:52:25 ----D---- C:\Windows\system32\drivers
2009-12-28 21:00:38 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2009-12-16 22:49:47 ----RSD---- C:\Windows\assembly
2009-12-16 22:42:39 ----D---- C:\Windows\Microsoft.NET
2009-12-16 22:41:23 ----D---- C:\Windows\Logs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys []
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys []
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys []
R1 LUMDriver;LUMDriver; \??\C:\Windows\system32\drivers\LUMDriver.sys []
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys []
R2 {1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7};{1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}; \??\C:\Program Files (x86)\CyberLink\PowerDVD DX\000.fcl [2008-06-26 32240]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys []
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys []
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmpx64.sys []
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimspx64.sys []
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys []
R3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\Windows\system32\DRIVERS\CtClsFlt.sys []
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys []
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys []
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys []
R3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\NETw5v64.sys []
R3 OA008Ufd;Creative Camera OA008 Upper Filter Driver; C:\Windows\system32\DRIVERS\OA008Ufd.sys []
R3 OA008Vid;Creative Camera OA008 Function Driver; C:\Windows\system32\DRIVERS\OA008Vid.sys []
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys []
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys []
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys []
S2 Sentinel;Sentinel; C:\Windows\System32\Drivers\SENTINEL.SYS [2008-01-02 76288]
S3 agswk8vc;agswk8vc; C:\Windows\system32\drivers\agswk8vc.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys []
S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032e.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys []
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys []
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys []
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys []
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys []
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys []
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe []
R2 aswUpdSv;avast! iAVS4 Control Service; C:\venca\programz\Avast\avast_instal\aswUpdSv.exe [2009-11-25 18752]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe []
R2 avast! Antivirus;avast! Antivirus; C:\venca\programz\Avast\avast_instal\ashServ.exe [2009-11-25 138680]
R2 DockLoginService;Dock Login Service; C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
R2 MSSQL$ECSQLEXPRESS;SQL Server (ECSQLEXPRESS); c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-01-07 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2010-01-11 214520]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-25 153952]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe []
R2 vsmon;TrueVector Internet Monitor; C:\Windows\SysWOW64\ZoneLabs\vsmon.exe [2009-02-16 2402184]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 2297216]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\venca\programz\Avast\avast_instal\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\venca\programz\Avast\avast_instal\ashWebSv.exe [2009-11-25 352920]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-03-29 89920]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-21 19968]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
-----------------EOF-----------------
Re: prosím o kontrolu logu.
Dobrý večer
Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken
NIC NEMAZAT
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.


-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu.
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3565
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
14.1.2010 23:48:16
mbam-log-2010-01-14 (23-48-02).txt
Typ kontroly: Kompletní kontrola (C:\|D:\|E:\|G:\|)
Zkontrolované objekty: 394165
Uplynulý čas: 1 hour(s), 16 minute(s), 10 second(s)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 1
Infikované adresáře: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované datové položky registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
(Nebyly nalezeny žádné škodlivé položky)
Verze databáze: 3565
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
14.1.2010 23:48:16
mbam-log-2010-01-14 (23-48-02).txt
Typ kontroly: Kompletní kontrola (C:\|D:\|E:\|G:\|)
Zkontrolované objekty: 394165
Uplynulý čas: 1 hour(s), 16 minute(s), 10 second(s)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 1
Infikované adresáře: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované datové položky registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
(Nebyly nalezeny žádné škodlivé položky)
Re: prosím o kontrolu logu.
Co našel mbam, smažte
Z mého podpisu stahněte Ccleaner
-nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
-nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
-po analýze klikněte na Spustit Ccleaner
záložka Registry
-klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy
udělat zálohu registrů - nemusíte
-kliknete opravit všechny problémy
ok
zavřít
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
Poprosím o nový log ze Rsitu. Problém přetrvává?

-nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
-nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
-po analýze klikněte na Spustit Ccleaner
záložka Registry
-klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy

-kliknete opravit všechny problémy


Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu.
Zdravím. Co našel MBAM jsem smazal. CaC Cleaner používám často. Problém s tím že mi padá net bych viděl možná i v tom že zapnu více programů co se připojují k internetu. Potom nastane problém, že mi ani Firefox neřekne, že se nemohl připojit a prostě jen načítá a nic nenačte. Jediný problém jak se toho zbavit je restart PC, ale ten mi při těchto problémech trvá asi 5 minut (5 min. se vypíná), někdy i déle. Jinak jsem se toho chtěl zbavit třeba obnovením ze zálohy windows, ale ať si vyberu jakou chci, tak mi to vždy po naběhnutí hodí chybu, že to nelze provést.
Děkuji, přeji pěkný den.
Děkuji, přeji pěkný den.
Re: prosím o kontrolu logu.

- ComboFix je třeba spustit pod účtem s právy administrátora
- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary
- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano
- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, skopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu.
zdravím
Combofix mi hodí error Win 32 only. A že to je pouze pro Windows 2000 a XP.
Já mám Wisty 64bit
Combofix mi hodí error Win 32 only. A že to je pouze pro Windows 2000 a XP.
Já mám Wisty 64bit

Re: prosím o kontrolu logu.
Teoreticky by fungovat mohl, ale bohužel..nefunguje
Stahněte AVZ http://z-oleg.com/avz4.zip na plochu
- rozbalte tak aby byla jen jedna slozka avz4
- spusťe AVZ.exe
-klikněte na file-customscripts
-do okna vložte text
-klikněte na Run
-log pak vložte zde jako přílohu v zipu


- rozbalte tak aby byla jen jedna slozka avz4
- spusťe AVZ.exe
-klikněte na file-customscripts
-do okna vložte text
Kód: Vybrat vše
begin
ExecuteStdScr(1);
ExecuteStdScr(3);
RebootWindows(true);
end.
-log pak vložte zde jako přílohu v zipu
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu.

napíše to mezi tím textem nějaké řádky červené, s tím že v tom jsou 2 errory. Končí to tím druhým errorem (error: cannot load driver)
a pak celý program zamrzne a windows mi ho nabídne pouze zavřít.
moc nerozumím tomu- aby se pouze jedna složka jmenovala avz4.
Mám na ploše tu složku avz4, tu otevřu a spustím avz4.exe
díky
Re: prosím o kontrolu logu.
To zamrzání - to se děje při programu AVZ?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu.
ano, zamrzne jen AVZ, jinak vše v pohodě, ani to nezpomalí rychlost PC
Re: prosím o kontrolu logu.

- v menu File -> Standard script zvolte možnost "6"
- klikněte na Execute selected scripts, potvrďte "Yes"

-všechno odoznačte - nebo dejte na none.
- nastavte file created a file modified... na File age.
- do bílého pole zkopirujte tento skript:
Kód: Vybrat vše
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
ndis.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
/md5stop
c:\windows\*.* /JN
c:\windows\*.* /HL
c:\windows\*.* /RP
-objeví se log, zkopírujte ho zde




-Podle návodu nainstalujte a proveďte sken
-co najde nechejte léčit, mazat
-sken může trvat několik hodin
-vložte zde log z výsledky
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu.
co to je OTL? prosim
Re: prosím o kontrolu logu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu.
OTL logfile created on: 16.1.2010 22:33:36 - Run 1
OTL by OldTimer - Version 3.1.25.2 Folder = C:\Users\Venda\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000405 | Country: Czech Republic | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 66,00% Memory free
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450,65 Gb Total Space | 264,03 Gb Free Space | 58,59% Space Free | Partition Type: NTFS
Drive D: | 15,00 Gb Total Space | 8,28 Gb Free Space | 55,20% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DOMOV
Current User Name: Venda
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Files/Folders - Created Within 30 Days ==========
[2010.01.16 22:01:15 | 00,000,000 | ---D | C] -- C:\Users\Venda\Desktop\avz4
[2010.01.16 12:27:31 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010.01.14 22:23:22 | 00,000,000 | ---D | C] -- C:\Users\Venda\AppData\Roaming\Malwarebytes
[2010.01.14 22:23:15 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010.01.14 22:23:12 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.01.14 22:23:11 | 00,022,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.01.13 19:17:04 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro
[2010.01.13 19:17:03 | 00,000,000 | ---D | C] -- C:\rsit
[2010.01.13 14:30:33 | 00,189,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2010.01.13 14:30:32 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2010.01.13 14:30:32 | 00,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2010.01.13 14:30:32 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2010.01.08 21:18:49 | 00,000,000 | ---D | C] -- C:\Users\Venda\Documents\SightSpeed Recordings
[2010.01.07 09:03:43 | 00,000,000 | ---D | C] -- C:\Users\Venda\AppData\Local\PunkBuster
[2009.12.29 00:24:48 | 00,000,000 | ---D | C] -- C:\Users\Venda\Desktop\mp3
[2009.12.28 21:11:02 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2009.12.28 17:47:15 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\DAEMON Tools Images
[2009.12.21 23:08:55 | 00,000,000 | ---D | C] -- C:\Users\Venda\AppData\Roaming\uTorrent
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.01.16 22:36:25 | 01,835,008 | -HS- | M] () -- C:\Users\Venda\NTUSER.DAT
[2010.01.16 22:12:24 | 00,350,192 | ---- | M] () -- C:\Windows\SysNative\drivers\vsconfig.xml
[2010.01.16 21:11:58 | 00,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2010.01.16 21:11:57 | 00,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.01.16 21:11:57 | 00,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.01.16 21:11:57 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.01.16 21:11:50 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.01.16 21:11:46 | 42,581,11488 | -HS- | M] () -- C:\hiberfil.sys
[2010.01.16 21:10:38 | 00,524,288 | -HS- | M] () -- C:\Users\Venda\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010.01.16 21:10:38 | 00,065,536 | -HS- | M] () -- C:\Users\Venda\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010.01.16 21:10:37 | 01,677,996 | -H-- | M] () -- C:\Users\Venda\AppData\Local\IconCache.db
[2010.01.16 18:08:51 | 00,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{9571913D-59A1-47AE-AECF-0750440F22DD}.job
[2010.01.16 12:15:42 | 03,826,563 | ---- | M] () -- C:\Users\Venda\Desktop\ComboFix.exe
[2010.01.15 21:01:49 | 00,000,554 | ---- | M] () -- C:\Users\Venda\Desktop\elm - Shortcut.lnk
[2010.01.15 17:29:17 | 00,756,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.01.15 17:29:17 | 00,633,886 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.01.15 17:29:17 | 00,119,012 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.01.14 22:23:18 | 00,000,801 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.01.14 12:26:44 | 00,029,184 | ---- | M] () -- C:\Users\Venda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.01.11 21:32:33 | 00,214,520 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2010.01.11 21:32:33 | 00,214,520 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.01.07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010.01.07 16:07:06 | 00,022,104 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.01.07 09:03:44 | 00,075,064 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.01.06 23:59:30 | 00,001,574 | ---- | M] () -- C:\Users\Venda\Desktop\GamePark.lnk
[2010.01.03 09:54:06 | 13,928,154 | ---- | M] () -- C:\Users\Venda\Desktop\Turning 2009 CZSK screen.zip
[2010.01.03 09:18:16 | 00,320,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010.01.02 20:59:19 | 00,079,792 | ---- | M] () -- C:\Users\Venda\AppData\Local\GDIPFONTCACHEV1.DAT
[2009.12.28 21:17:06 | 00,001,717 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 2 Singleplayer.lnk
[2009.12.28 21:16:34 | 00,000,293 | ---- | M] () -- C:\Windows\game.ini
[2009.12.28 17:07:05 | 00,000,162 | -H-- | M] () -- C:\Users\Venda\Desktop\~$ostup2.docx
[2009.12.28 17:05:05 | 00,000,162 | -H-- | M] () -- C:\Users\Venda\Desktop\~$ostup1.docx
[2009.12.28 16:43:30 | 00,000,162 | -H-- | M] () -- C:\Users\Venda\Desktop\~$vod_VP.doc
[2009.12.21 23:10:41 | 00,000,849 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2009.12.20 18:38:25 | 00,000,057 | ---- | M] () -- C:\Users\Venda\Desktop\Ocko.tv.URL
[2009.12.20 18:37:07 | 00,000,169 | ---- | M] () -- C:\Users\Venda\Desktop\Facebook Hlavní stránka.URL
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.01.16 12:15:25 | 03,826,563 | ---- | C] () -- C:\Users\Venda\Desktop\ComboFix.exe
[2010.01.15 21:01:49 | 00,000,554 | ---- | C] () -- C:\Users\Venda\Desktop\elm - Shortcut.lnk
[2010.01.14 22:23:18 | 00,000,801 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.01.07 09:15:43 | 00,214,520 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2010.01.07 09:04:13 | 00,214,520 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.01.07 09:03:44 | 00,075,064 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.01.06 23:59:30 | 00,001,574 | ---- | C] () -- C:\Users\Venda\Desktop\GamePark.lnk
[2010.01.03 09:52:31 | 13,928,154 | ---- | C] () -- C:\Users\Venda\Desktop\Turning 2009 CZSK screen.zip
[2009.12.28 21:17:06 | 00,001,717 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 2 Singleplayer.lnk
[2009.12.28 21:16:34 | 00,000,293 | ---- | C] () -- C:\Windows\game.ini
[2009.12.28 17:07:05 | 00,000,162 | -H-- | C] () -- C:\Users\Venda\Desktop\~$ostup2.docx
[2009.12.28 17:05:05 | 00,000,162 | -H-- | C] () -- C:\Users\Venda\Desktop\~$ostup1.docx
[2009.12.28 16:43:30 | 00,000,162 | -H-- | C] () -- C:\Users\Venda\Desktop\~$vod_VP.doc
[2009.12.28 13:57:05 | 00,000,418 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{9571913D-59A1-47AE-AECF-0750440F22DD}.job
[2009.12.21 23:10:41 | 00,000,849 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2009.12.20 18:38:25 | 00,000,057 | ---- | C] () -- C:\Users\Venda\Desktop\Ocko.tv.URL
[2009.12.20 18:37:07 | 00,000,169 | ---- | C] () -- C:\Users\Venda\Desktop\Facebook Hlavní stránka.URL
[2009.12.17 15:24:43 | 00,000,146 | ---- | C] () -- C:\Windows\WININIT.INI
[2009.11.18 22:06:21 | 00,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.11.16 18:43:59 | 00,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.11.16 18:43:06 | 00,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009.11.15 16:08:42 | 00,700,730 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009.11.13 10:26:59 | 00,029,184 | ---- | C] () -- C:\Users\Venda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.09.24 00:46:04 | 00,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009.05.29 16:52:26 | 00,204,800 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009.05.29 16:47:06 | 00,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2008.09.12 16:21:02 | 00,000,547 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll.manifest
[2008.01.21 03:50:05 | 00,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2007.09.04 12:56:10 | 00,164,352 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2007.02.05 20:05:26 | 00,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2002.08.29 17:33:56 | 00,319,488 | R--- | C] () -- C:\Users\Venda\AppData\Roaming\MafiaSetup.exe
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ehTray.exe" = C:\Windows\ehome\ehTray.exe -- [2008.01.21 03:51:33 | 00,138,240 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
< MD5 for: AGP440.SYS >
[2008.01.21 03:46:51 | 00,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.21 03:46:51 | 00,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008.01.21 03:46:50 | 00,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009.04.25 04:26:24 | 00,022,584 | ---- | M] (Microsoft Corporation) MD5=5EB9EF6EEC5D873E94992095A1719BF6 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_39c3f1ccf31998cb\atapi.sys
[2009.04.11 00:15:02 | 00,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
[2009.04.25 04:26:24 | 00,022,584 | ---- | M] (Microsoft Corporation) MD5=F988BB0690CD660318037908E9B8DBF7 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_393a5501d9fbf901\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006.11.02 12:16:48 | 00,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2008.01.21 03:46:59 | 00,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
< MD5 for: NDIS.SYS >
[2008.01.21 03:50:38 | 00,739,384 | ---- | M] (Microsoft Corporation) MD5=2A2EE457AF36C5C9A6808C768BD3A12B -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_03e5c74ad46c7e4e\ndis.sys
[2008.02.08 05:41:30 | 00,643,640 | ---- | M] (Microsoft Corporation) MD5=37A917C8586225B0D04E407C11639B7E -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.20768_none_02504837f08cff85\ndis.sys
[2009.04.11 00:15:36 | 00,738,264 | ---- | M] (Microsoft Corporation) MD5=65950E07329FCEE8E6516B17C8D0ABB6 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_05d14056d18e499a\ndis.sys
[2008.02.08 18:31:28 | 00,739,384 | ---- | M] (Microsoft Corporation) MD5=F9A3AE5C9F047D71A36A99F9ABCA7D02 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.22110_none_04649429ed923a09\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.01.21 03:51:03 | 00,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009.04.10 23:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.10 23:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.10 23:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 00:11:18 | 00,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.21 03:48:28 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2008.01.21 03:46:54 | 00,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008.01.21 03:50:28 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008.01.21 03:49:49 | 00,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009.04.10 23:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.10 23:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.10 23:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 00:11:24 | 00,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
< c:\windows\*.* /JN >
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\ARJ.PIF
[2008.11.27 14:45:52 | 00,014,849 | ---- | M] () -- c:\Windows\atiogl.xml
[2009.10.08 16:01:31 | 00,000,000 | ---- | M] () -- c:\Windows\ativpsrm.bin
[2007.02.05 20:05:26 | 00,000,038 | ---- | M] () -- c:\Windows\AviSplitter.INI
[2008.01.21 03:49:18 | 00,065,536 | ---- | M] (Microsoft Corporation) -- c:\Windows\bfsvc.exe
[2010.01.16 21:11:50 | 00,067,584 | --S- | M] () -- c:\Windows\bootstat.dat
[2009.10.09 00:44:14 | 00,000,012 | ---- | M] () -- c:\Windows\csup.txt
[2009.10.08 16:25:43 | 00,000,075 | RHS- | M] () -- c:\Windows\CT4CET.bin
[2008.08.01 09:21:26 | 00,102,912 | ---- | M] (Creative Technology Ltd.) -- c:\Windows\CtDrvIns.exe
[2009.11.17 14:30:55 | 00,561,090 | ---- | M] () -- c:\Windows\dd_ATL80SP1_KB973923MSI4377.txt
[2009.11.17 14:30:55 | 00,011,680 | ---- | M] () -- c:\Windows\dd_ATL80SP1_KB973923UI4377.txt
[2009.12.06 14:19:45 | 00,001,905 | ---- | M] () -- c:\Windows\diagerr.xml
[2009.12.06 14:19:45 | 00,001,905 | ---- | M] () -- c:\Windows\diagwrn.xml
[2009.04.11 00:10:18 | 03,079,168 | ---- | M] (Microsoft Corporation) -- c:\Windows\explorer.exe
[2008.01.21 03:48:58 | 00,014,848 | ---- | M] (Microsoft Corporation) -- c:\Windows\fveupdate.exe
[2009.12.28 21:16:34 | 00,000,293 | ---- | M] () -- c:\Windows\game.ini
[2008.01.21 03:50:57 | 00,734,720 | ---- | M] (Microsoft Corporation) -- c:\Windows\HelpPane.exe
[2006.11.02 12:15:53 | 00,015,872 | ---- | M] (Microsoft Corporation) -- c:\Windows\hh.exe
[2006.09.19 12:41:43 | 00,008,328 | ---- | M] () -- c:\Windows\HomePremium.xml
[1998.10.29 16:45:06 | 00,306,688 | ---- | M] (InstallShield Software Corporation) -- c:\Windows\IsUninst.exe
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\LHA.PIF
[2006.11.02 09:26:50 | 00,043,131 | ---- | M] () -- c:\Windows\mib.bin
[2006.09.18 22:30:24 | 00,001,405 | ---- | M] () -- c:\Windows\msdfmap.ini
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\NOCLOSE.PIF
[2008.01.21 03:47:53 | 00,169,472 | ---- | M] (Microsoft Corporation) -- c:\Windows\notepad.exe
[2009.06.01 03:17:36 | 00,004,661 | ---- | M] () -- c:\Windows\OA008.uns
[2009.05.26 17:02:00 | 00,053,360 | ---- | M] (Creative Technology Ltd.) -- c:\Windows\OA008Cfg.exe
[2009.05.31 17:00:00 | 00,024,576 | ---- | M] (Creative Technology Ltd.) -- c:\Windows\OA008Mon.exe
[2009.10.08 16:13:50 | 00,065,536 | ---- | M] () -- c:\Windows\ocsetup_cbs_install_OEMHelpCustomization.dpx
[2009.10.08 16:13:50 | 00,196,608 | ---- | M] () -- c:\Windows\ocsetup_cbs_install_OEMHelpCustomization.perf
[2009.10.08 16:13:50 | 81,723,392 | ---- | M] () -- c:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\PKUNZIP.PIF
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\PKZIP.PIF
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\RAR.PIF
[2008.01.21 03:49:53 | 00,161,792 | ---- | M] (Microsoft Corporation) -- c:\Windows\regedit.exe
[2008.01.21 03:49:02 | 00,039,936 | ---- | M] (Microsoft Corporation) -- c:\Windows\splwow64.exe
[2006.09.18 22:44:42 | 00,000,219 | ---- | M] () -- c:\Windows\system.ini
[2006.11.02 16:02:26 | 00,094,784 | ---- | M] (Twain Working Group) -- c:\Windows\twain.dll
[2006.11.02 16:02:26 | 00,050,688 | ---- | M] (Twain Working Group) -- c:\Windows\twain_32.dll
[2006.11.02 16:02:26 | 00,049,680 | ---- | M] (Twain Working Group) -- c:\Windows\twunk_16.exe
[2006.11.02 16:02:26 | 00,031,232 | ---- | M] (Twain Working Group) -- c:\Windows\twunk_32.exe
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\UC.PIF
[2006.11.02 16:44:42 | 00,000,144 | ---- | M] () -- c:\Windows\win.ini
[2008.01.21 04:21:59 | 00,000,749 | RH-- | M] () -- c:\Windows\WindowsShell.Manifest
[2010.01.16 22:12:36 | 00,032,382 | ---- | M] () -- c:\Windows\WindowsUpdate.log
[2006.11.02 10:45:57 | 00,009,216 | ---- | M] (Microsoft Corporation) -- c:\Windows\winhlp32.exe
[2009.12.17 15:24:43 | 00,000,146 | ---- | M] () -- c:\Windows\WININIT.INI
[2009.07.10 12:15:46 | 00,306,544 | ---- | M] (Microsoft Corporation) -- c:\Windows\WLXPGSS.SCR
[2006.11.02 16:04:27 | 00,316,640 | ---- | M] () -- c:\Windows\WMSysPr9.prx
< c:\windows\*.* /HL >
< c:\windows\*.* /RP >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[bfsvc.exe] -> c:\windows\bfsvc.exe -> HardLink
[explorer.exe] -> c:\windows\explorer.exe -> HardLink
[fveupdate.exe] -> c:\windows\fveupdate.exe -> HardLink
[HelpPane.exe] -> c:\windows\HelpPane.exe -> HardLink
[hh.exe] -> c:\windows\hh.exe -> HardLink
[mib.bin] -> c:\windows\mib.bin -> HardLink
[notepad.exe] -> c:\windows\notepad.exe -> HardLink
[regedit.exe] -> c:\windows\regedit.exe -> HardLink
[splwow64.exe] -> c:\windows\splwow64.exe -> HardLink
[twain.dll] -> c:\windows\twain.dll -> HardLink
[twain_32.dll] -> c:\windows\twain_32.dll -> HardLink
[twunk_16.exe] -> c:\windows\twunk_16.exe -> HardLink
[twunk_32.exe] -> c:\windows\twunk_32.exe -> HardLink
[winhlp32.exe] -> c:\windows\winhlp32.exe -> HardLink
[WMSysPr9.prx] -> c:\windows\WMSysPr9.prx -> HardLink
< End of report >
OTL by OldTimer - Version 3.1.25.2 Folder = C:\Users\Venda\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000405 | Country: Czech Republic | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 66,00% Memory free
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450,65 Gb Total Space | 264,03 Gb Free Space | 58,59% Space Free | Partition Type: NTFS
Drive D: | 15,00 Gb Total Space | 8,28 Gb Free Space | 55,20% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DOMOV
Current User Name: Venda
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Files/Folders - Created Within 30 Days ==========
[2010.01.16 22:01:15 | 00,000,000 | ---D | C] -- C:\Users\Venda\Desktop\avz4
[2010.01.16 12:27:31 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010.01.14 22:23:22 | 00,000,000 | ---D | C] -- C:\Users\Venda\AppData\Roaming\Malwarebytes
[2010.01.14 22:23:15 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010.01.14 22:23:12 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.01.14 22:23:11 | 00,022,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.01.13 19:17:04 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro
[2010.01.13 19:17:03 | 00,000,000 | ---D | C] -- C:\rsit
[2010.01.13 14:30:33 | 00,189,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2010.01.13 14:30:32 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2010.01.13 14:30:32 | 00,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2010.01.13 14:30:32 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2010.01.08 21:18:49 | 00,000,000 | ---D | C] -- C:\Users\Venda\Documents\SightSpeed Recordings
[2010.01.07 09:03:43 | 00,000,000 | ---D | C] -- C:\Users\Venda\AppData\Local\PunkBuster
[2009.12.29 00:24:48 | 00,000,000 | ---D | C] -- C:\Users\Venda\Desktop\mp3
[2009.12.28 21:11:02 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2009.12.28 17:47:15 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\DAEMON Tools Images
[2009.12.21 23:08:55 | 00,000,000 | ---D | C] -- C:\Users\Venda\AppData\Roaming\uTorrent
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.01.16 22:36:25 | 01,835,008 | -HS- | M] () -- C:\Users\Venda\NTUSER.DAT
[2010.01.16 22:12:24 | 00,350,192 | ---- | M] () -- C:\Windows\SysNative\drivers\vsconfig.xml
[2010.01.16 21:11:58 | 00,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2010.01.16 21:11:57 | 00,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.01.16 21:11:57 | 00,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.01.16 21:11:57 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.01.16 21:11:50 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.01.16 21:11:46 | 42,581,11488 | -HS- | M] () -- C:\hiberfil.sys
[2010.01.16 21:10:38 | 00,524,288 | -HS- | M] () -- C:\Users\Venda\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010.01.16 21:10:38 | 00,065,536 | -HS- | M] () -- C:\Users\Venda\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010.01.16 21:10:37 | 01,677,996 | -H-- | M] () -- C:\Users\Venda\AppData\Local\IconCache.db
[2010.01.16 18:08:51 | 00,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{9571913D-59A1-47AE-AECF-0750440F22DD}.job
[2010.01.16 12:15:42 | 03,826,563 | ---- | M] () -- C:\Users\Venda\Desktop\ComboFix.exe
[2010.01.15 21:01:49 | 00,000,554 | ---- | M] () -- C:\Users\Venda\Desktop\elm - Shortcut.lnk
[2010.01.15 17:29:17 | 00,756,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.01.15 17:29:17 | 00,633,886 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.01.15 17:29:17 | 00,119,012 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.01.14 22:23:18 | 00,000,801 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.01.14 12:26:44 | 00,029,184 | ---- | M] () -- C:\Users\Venda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.01.11 21:32:33 | 00,214,520 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2010.01.11 21:32:33 | 00,214,520 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.01.07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010.01.07 16:07:06 | 00,022,104 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.01.07 09:03:44 | 00,075,064 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.01.06 23:59:30 | 00,001,574 | ---- | M] () -- C:\Users\Venda\Desktop\GamePark.lnk
[2010.01.03 09:54:06 | 13,928,154 | ---- | M] () -- C:\Users\Venda\Desktop\Turning 2009 CZSK screen.zip
[2010.01.03 09:18:16 | 00,320,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010.01.02 20:59:19 | 00,079,792 | ---- | M] () -- C:\Users\Venda\AppData\Local\GDIPFONTCACHEV1.DAT
[2009.12.28 21:17:06 | 00,001,717 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 2 Singleplayer.lnk
[2009.12.28 21:16:34 | 00,000,293 | ---- | M] () -- C:\Windows\game.ini
[2009.12.28 17:07:05 | 00,000,162 | -H-- | M] () -- C:\Users\Venda\Desktop\~$ostup2.docx
[2009.12.28 17:05:05 | 00,000,162 | -H-- | M] () -- C:\Users\Venda\Desktop\~$ostup1.docx
[2009.12.28 16:43:30 | 00,000,162 | -H-- | M] () -- C:\Users\Venda\Desktop\~$vod_VP.doc
[2009.12.21 23:10:41 | 00,000,849 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2009.12.20 18:38:25 | 00,000,057 | ---- | M] () -- C:\Users\Venda\Desktop\Ocko.tv.URL
[2009.12.20 18:37:07 | 00,000,169 | ---- | M] () -- C:\Users\Venda\Desktop\Facebook Hlavní stránka.URL
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.01.16 12:15:25 | 03,826,563 | ---- | C] () -- C:\Users\Venda\Desktop\ComboFix.exe
[2010.01.15 21:01:49 | 00,000,554 | ---- | C] () -- C:\Users\Venda\Desktop\elm - Shortcut.lnk
[2010.01.14 22:23:18 | 00,000,801 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.01.07 09:15:43 | 00,214,520 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2010.01.07 09:04:13 | 00,214,520 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.01.07 09:03:44 | 00,075,064 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.01.06 23:59:30 | 00,001,574 | ---- | C] () -- C:\Users\Venda\Desktop\GamePark.lnk
[2010.01.03 09:52:31 | 13,928,154 | ---- | C] () -- C:\Users\Venda\Desktop\Turning 2009 CZSK screen.zip
[2009.12.28 21:17:06 | 00,001,717 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 2 Singleplayer.lnk
[2009.12.28 21:16:34 | 00,000,293 | ---- | C] () -- C:\Windows\game.ini
[2009.12.28 17:07:05 | 00,000,162 | -H-- | C] () -- C:\Users\Venda\Desktop\~$ostup2.docx
[2009.12.28 17:05:05 | 00,000,162 | -H-- | C] () -- C:\Users\Venda\Desktop\~$ostup1.docx
[2009.12.28 16:43:30 | 00,000,162 | -H-- | C] () -- C:\Users\Venda\Desktop\~$vod_VP.doc
[2009.12.28 13:57:05 | 00,000,418 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{9571913D-59A1-47AE-AECF-0750440F22DD}.job
[2009.12.21 23:10:41 | 00,000,849 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2009.12.20 18:38:25 | 00,000,057 | ---- | C] () -- C:\Users\Venda\Desktop\Ocko.tv.URL
[2009.12.20 18:37:07 | 00,000,169 | ---- | C] () -- C:\Users\Venda\Desktop\Facebook Hlavní stránka.URL
[2009.12.17 15:24:43 | 00,000,146 | ---- | C] () -- C:\Windows\WININIT.INI
[2009.11.18 22:06:21 | 00,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.11.16 18:43:59 | 00,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.11.16 18:43:06 | 00,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009.11.15 16:08:42 | 00,700,730 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009.11.13 10:26:59 | 00,029,184 | ---- | C] () -- C:\Users\Venda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.09.24 00:46:04 | 00,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009.05.29 16:52:26 | 00,204,800 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009.05.29 16:47:06 | 00,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2008.09.12 16:21:02 | 00,000,547 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll.manifest
[2008.01.21 03:50:05 | 00,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2007.09.04 12:56:10 | 00,164,352 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2007.02.05 20:05:26 | 00,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2002.08.29 17:33:56 | 00,319,488 | R--- | C] () -- C:\Users\Venda\AppData\Roaming\MafiaSetup.exe
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ehTray.exe" = C:\Windows\ehome\ehTray.exe -- [2008.01.21 03:51:33 | 00,138,240 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
< MD5 for: AGP440.SYS >
[2008.01.21 03:46:51 | 00,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.21 03:46:51 | 00,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008.01.21 03:46:50 | 00,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009.04.25 04:26:24 | 00,022,584 | ---- | M] (Microsoft Corporation) MD5=5EB9EF6EEC5D873E94992095A1719BF6 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_39c3f1ccf31998cb\atapi.sys
[2009.04.11 00:15:02 | 00,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
[2009.04.25 04:26:24 | 00,022,584 | ---- | M] (Microsoft Corporation) MD5=F988BB0690CD660318037908E9B8DBF7 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_393a5501d9fbf901\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006.11.02 12:16:48 | 00,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2008.01.21 03:46:59 | 00,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
< MD5 for: NDIS.SYS >
[2008.01.21 03:50:38 | 00,739,384 | ---- | M] (Microsoft Corporation) MD5=2A2EE457AF36C5C9A6808C768BD3A12B -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_03e5c74ad46c7e4e\ndis.sys
[2008.02.08 05:41:30 | 00,643,640 | ---- | M] (Microsoft Corporation) MD5=37A917C8586225B0D04E407C11639B7E -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.20768_none_02504837f08cff85\ndis.sys
[2009.04.11 00:15:36 | 00,738,264 | ---- | M] (Microsoft Corporation) MD5=65950E07329FCEE8E6516B17C8D0ABB6 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_05d14056d18e499a\ndis.sys
[2008.02.08 18:31:28 | 00,739,384 | ---- | M] (Microsoft Corporation) MD5=F9A3AE5C9F047D71A36A99F9ABCA7D02 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.22110_none_04649429ed923a09\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.01.21 03:51:03 | 00,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009.04.10 23:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.10 23:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.10 23:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 00:11:18 | 00,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.21 03:48:28 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2008.01.21 03:46:54 | 00,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008.01.21 03:50:28 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008.01.21 03:49:49 | 00,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009.04.10 23:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.10 23:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.10 23:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 00:11:24 | 00,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
< c:\windows\*.* /JN >
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\ARJ.PIF
[2008.11.27 14:45:52 | 00,014,849 | ---- | M] () -- c:\Windows\atiogl.xml
[2009.10.08 16:01:31 | 00,000,000 | ---- | M] () -- c:\Windows\ativpsrm.bin
[2007.02.05 20:05:26 | 00,000,038 | ---- | M] () -- c:\Windows\AviSplitter.INI
[2008.01.21 03:49:18 | 00,065,536 | ---- | M] (Microsoft Corporation) -- c:\Windows\bfsvc.exe
[2010.01.16 21:11:50 | 00,067,584 | --S- | M] () -- c:\Windows\bootstat.dat
[2009.10.09 00:44:14 | 00,000,012 | ---- | M] () -- c:\Windows\csup.txt
[2009.10.08 16:25:43 | 00,000,075 | RHS- | M] () -- c:\Windows\CT4CET.bin
[2008.08.01 09:21:26 | 00,102,912 | ---- | M] (Creative Technology Ltd.) -- c:\Windows\CtDrvIns.exe
[2009.11.17 14:30:55 | 00,561,090 | ---- | M] () -- c:\Windows\dd_ATL80SP1_KB973923MSI4377.txt
[2009.11.17 14:30:55 | 00,011,680 | ---- | M] () -- c:\Windows\dd_ATL80SP1_KB973923UI4377.txt
[2009.12.06 14:19:45 | 00,001,905 | ---- | M] () -- c:\Windows\diagerr.xml
[2009.12.06 14:19:45 | 00,001,905 | ---- | M] () -- c:\Windows\diagwrn.xml
[2009.04.11 00:10:18 | 03,079,168 | ---- | M] (Microsoft Corporation) -- c:\Windows\explorer.exe
[2008.01.21 03:48:58 | 00,014,848 | ---- | M] (Microsoft Corporation) -- c:\Windows\fveupdate.exe
[2009.12.28 21:16:34 | 00,000,293 | ---- | M] () -- c:\Windows\game.ini
[2008.01.21 03:50:57 | 00,734,720 | ---- | M] (Microsoft Corporation) -- c:\Windows\HelpPane.exe
[2006.11.02 12:15:53 | 00,015,872 | ---- | M] (Microsoft Corporation) -- c:\Windows\hh.exe
[2006.09.19 12:41:43 | 00,008,328 | ---- | M] () -- c:\Windows\HomePremium.xml
[1998.10.29 16:45:06 | 00,306,688 | ---- | M] (InstallShield Software Corporation) -- c:\Windows\IsUninst.exe
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\LHA.PIF
[2006.11.02 09:26:50 | 00,043,131 | ---- | M] () -- c:\Windows\mib.bin
[2006.09.18 22:30:24 | 00,001,405 | ---- | M] () -- c:\Windows\msdfmap.ini
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\NOCLOSE.PIF
[2008.01.21 03:47:53 | 00,169,472 | ---- | M] (Microsoft Corporation) -- c:\Windows\notepad.exe
[2009.06.01 03:17:36 | 00,004,661 | ---- | M] () -- c:\Windows\OA008.uns
[2009.05.26 17:02:00 | 00,053,360 | ---- | M] (Creative Technology Ltd.) -- c:\Windows\OA008Cfg.exe
[2009.05.31 17:00:00 | 00,024,576 | ---- | M] (Creative Technology Ltd.) -- c:\Windows\OA008Mon.exe
[2009.10.08 16:13:50 | 00,065,536 | ---- | M] () -- c:\Windows\ocsetup_cbs_install_OEMHelpCustomization.dpx
[2009.10.08 16:13:50 | 00,196,608 | ---- | M] () -- c:\Windows\ocsetup_cbs_install_OEMHelpCustomization.perf
[2009.10.08 16:13:50 | 81,723,392 | ---- | M] () -- c:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\PKUNZIP.PIF
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\PKZIP.PIF
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\RAR.PIF
[2008.01.21 03:49:53 | 00,161,792 | ---- | M] (Microsoft Corporation) -- c:\Windows\regedit.exe
[2008.01.21 03:49:02 | 00,039,936 | ---- | M] (Microsoft Corporation) -- c:\Windows\splwow64.exe
[2006.09.18 22:44:42 | 00,000,219 | ---- | M] () -- c:\Windows\system.ini
[2006.11.02 16:02:26 | 00,094,784 | ---- | M] (Twain Working Group) -- c:\Windows\twain.dll
[2006.11.02 16:02:26 | 00,050,688 | ---- | M] (Twain Working Group) -- c:\Windows\twain_32.dll
[2006.11.02 16:02:26 | 00,049,680 | ---- | M] (Twain Working Group) -- c:\Windows\twunk_16.exe
[2006.11.02 16:02:26 | 00,031,232 | ---- | M] (Twain Working Group) -- c:\Windows\twunk_32.exe
[2009.09.24 07:50:10 | 00,000,545 | ---- | M] () -- c:\windows\UC.PIF
[2006.11.02 16:44:42 | 00,000,144 | ---- | M] () -- c:\Windows\win.ini
[2008.01.21 04:21:59 | 00,000,749 | RH-- | M] () -- c:\Windows\WindowsShell.Manifest
[2010.01.16 22:12:36 | 00,032,382 | ---- | M] () -- c:\Windows\WindowsUpdate.log
[2006.11.02 10:45:57 | 00,009,216 | ---- | M] (Microsoft Corporation) -- c:\Windows\winhlp32.exe
[2009.12.17 15:24:43 | 00,000,146 | ---- | M] () -- c:\Windows\WININIT.INI
[2009.07.10 12:15:46 | 00,306,544 | ---- | M] (Microsoft Corporation) -- c:\Windows\WLXPGSS.SCR
[2006.11.02 16:04:27 | 00,316,640 | ---- | M] () -- c:\Windows\WMSysPr9.prx
< c:\windows\*.* /HL >
< c:\windows\*.* /RP >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[bfsvc.exe] -> c:\windows\bfsvc.exe -> HardLink
[explorer.exe] -> c:\windows\explorer.exe -> HardLink
[fveupdate.exe] -> c:\windows\fveupdate.exe -> HardLink
[HelpPane.exe] -> c:\windows\HelpPane.exe -> HardLink
[hh.exe] -> c:\windows\hh.exe -> HardLink
[mib.bin] -> c:\windows\mib.bin -> HardLink
[notepad.exe] -> c:\windows\notepad.exe -> HardLink
[regedit.exe] -> c:\windows\regedit.exe -> HardLink
[splwow64.exe] -> c:\windows\splwow64.exe -> HardLink
[twain.dll] -> c:\windows\twain.dll -> HardLink
[twain_32.dll] -> c:\windows\twain_32.dll -> HardLink
[twunk_16.exe] -> c:\windows\twunk_16.exe -> HardLink
[twunk_32.exe] -> c:\windows\twunk_32.exe -> HardLink
[winhlp32.exe] -> c:\windows\winhlp32.exe -> HardLink
[WMSysPr9.prx] -> c:\windows\WMSysPr9.prx -> HardLink
< End of report >