Prosím o kontrolu HJT

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Prosím o kontrolu HJT

#1 Příspěvek od Knotek »

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:59:25, on 19.2.2011
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\ICQ7.2\ICQ.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Knteok\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{56B58DEC-023D-498E-9B57-EED1BECC33FF}: NameServer = 192.168.2.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{56B58DEC-023D-498E-9B57-EED1BECC33FF}: NameServer = 192.168.2.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{56B58DEC-023D-498E-9B57-EED1BECC33FF}: NameServer = 192.168.2.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9269 bytes


díky :)

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu HJT

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Prectete si prosim pravidla fora

:arrow: Dejte log z RSIT - viz muj podpis - je podrobnejsi nez HJT - a poprosim o oba logy z nej - log.txt i info.txt, budou ulozeny v c:\rsit
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Re: Prosím o kontrolu HJT

#3 Příspěvek od Knotek »

pravidla mi bohužel zobrazují že požadované téma neexistuje :(

RSIT - log

Logfile of random's system information tool 1.08 (written by random/random)
Run by Knteok at 2011-02-19 15:03:11
Microsoft Windows 7 Ultimate
System drive C: has 62 GB (39%) free of 161 GB
Total RAM: 4093 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:03:14, on 19.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\ICQ7.2\ICQ.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Knteok\Downloads\hijackthis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files\trend micro\Knteok.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{56B58DEC-023D-498E-9B57-EED1BECC33FF}: NameServer = 192.168.2.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{56B58DEC-023D-498E-9B57-EED1BECC33FF}: NameServer = 192.168.2.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{56B58DEC-023D-498E-9B57-EED1BECC33FF}: NameServer = 192.168.2.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9315 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agr64svc.exe
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe"
"C:\Windows\PLFSetI.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\ICQ7.2\ICQ.exe" silent loginmode=4
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\system32\wuauclt.exe"
"taskhost.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Users\Knteok\Downloads\hijackthis.exe"
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\Knteok\Downloads\hijackthis.log
"C:\Users\Knteok\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\AWC AutoSweep.job
C:\Windows\tasks\AWC Startup.job
C:\Windows\tasks\AWC Update.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-23 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-12-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-07 1048888]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-05 186904]
"PLFSetI"=C:\Windows\PLFSetI.exe [2009-11-21 200704]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-11-18 2919168]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-01-18 11775592]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ICQ"=C:\Program Files (x86)\ICQ7.2\ICQ.exe [2011-01-05 133432]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2011-02-18 1242448]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2011-02-19 15:03:11 ----D---- C:\rsit
2011-02-19 15:03:11 ----D---- C:\Program Files\trend micro
2011-02-19 13:06:57 ----D---- C:\Users\Knteok\AppData\Roaming\NVIDIA
2011-02-19 13:01:12 ----D---- C:\Program Files (x86)\SpeedFan
2011-02-19 00:07:17 ----D---- C:\Windows\SYSWOW64\RTCOM
2011-02-19 00:07:17 ----D---- C:\Program Files\Realtek
2011-02-19 00:06:40 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-02-19 00:06:39 ----A---- C:\Windows\system32\SRSWOW64.dll
2011-02-19 00:06:39 ----A---- C:\Windows\system32\SRSTSX64.dll
2011-02-19 00:06:39 ----A---- C:\Windows\system32\SRSTSH64.dll
2011-02-19 00:06:38 ----A---- C:\Windows\system32\SRSHP64.dll
2011-02-19 00:06:37 ----A---- C:\Windows\system32\SFSS_APO.dll
2011-02-19 00:06:37 ----A---- C:\Windows\system32\SFNHK64.dll
2011-02-19 00:06:36 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2011-02-19 00:06:36 ----A---- C:\Windows\system32\SFCOM64.dll
2011-02-19 00:06:36 ----A---- C:\Windows\system32\SFAPO64.dll
2011-02-19 00:06:36 ----A---- C:\Windows\system32\RtPgEx64.dll
2011-02-19 00:06:36 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RtkCfg64.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RtkAPO64.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RtkApi64.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RTEEP64A.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RTEEL64A.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RTEEG64A.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RTEED64A.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2011-02-19 00:06:34 ----A---- C:\Windows\system32\RTCOM64.dll
2011-02-19 00:06:34 ----A---- C:\Windows\system32\RP3DHT64.dll
2011-02-19 00:06:34 ----A---- C:\Windows\system32\RP3DAA64.dll
2011-02-19 00:06:34 ----A---- C:\Windows\system32\RCoInst64.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EEP64A.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EEL64A.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EEG64A.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EED64A.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EEA64A.dll
2011-02-19 00:06:30 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2011-02-19 00:06:29 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2011-02-19 00:06:29 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-02-19 00:06:27 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2011-02-19 00:06:27 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-02-19 00:05:57 ----A---- C:\Windows\system32\FMAPO64.dll
2011-02-19 00:05:57 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2011-02-19 00:05:57 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2011-02-19 00:05:56 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2011-02-19 00:05:56 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2011-02-19 00:05:55 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2011-02-19 00:05:55 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2011-02-19 00:05:55 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2011-02-19 00:05:54 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2011-02-19 00:05:54 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2011-02-19 00:05:54 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2011-02-19 00:05:53 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2011-02-19 00:05:53 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2011-02-19 00:05:50 ----A---- C:\Windows\system32\AERTAR64.dll
2011-02-19 00:05:50 ----A---- C:\Windows\system32\AERTAC64.dll
2011-02-19 00:00:15 ----D---- C:\Program Files (x86)\Realtek
2011-02-18 23:51:19 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-02-18 23:50:38 ----N---- C:\Windows\system32\MpSigStub.exe
2011-02-18 23:49:23 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-02-18 23:49:23 ----A---- C:\Windows\system32\webio.dll
2011-02-18 23:49:22 ----A---- C:\Windows\system32\ieframe.dll
2011-02-18 23:49:19 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-02-18 23:49:19 ----A---- C:\Windows\system32\upnp.dll
2011-02-18 23:49:19 ----A---- C:\Windows\system32\msxml6.dll
2011-02-18 23:49:19 ----A---- C:\Windows\system32\msxml3.dll
2011-02-18 23:49:18 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-02-18 23:49:18 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-02-18 23:49:18 ----A---- C:\Windows\system32\urlmon.dll
2011-02-18 23:49:17 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-02-18 23:49:17 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-02-18 23:49:17 ----A---- C:\Windows\system32\wininet.dll
2011-02-18 23:49:17 ----A---- C:\Windows\system32\winhttp.dll
2011-02-18 23:49:16 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-02-18 23:49:16 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-02-18 23:49:16 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-02-18 23:49:16 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-02-18 23:49:16 ----A---- C:\Windows\system32\wscapi.dll
2011-02-18 23:49:16 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-18 23:49:16 ----A---- C:\Windows\system32\davclnt.dll
2011-02-18 23:49:15 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-02-18 23:49:15 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-02-18 23:49:15 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-02-18 23:49:15 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-02-18 23:49:15 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-18 23:49:15 ----A---- C:\Windows\system32\slwga.dll
2011-02-18 23:49:15 ----A---- C:\Windows\system32\jsproxy.dll
2011-02-18 23:49:15 ----A---- C:\Windows\system32\ieui.dll
2011-02-18 23:49:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-18 23:49:13 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-02-18 23:49:13 ----A---- C:\Windows\system32\ntdll.dll
2011-02-18 23:49:12 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-02-18 23:49:11 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-02-18 23:49:10 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-02-18 23:49:10 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-02-18 23:49:10 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-02-18 23:49:10 ----A---- C:\Windows\system32\taskschd.dll
2011-02-18 23:49:10 ----A---- C:\Windows\system32\taskeng.exe
2011-02-18 23:49:10 ----A---- C:\Windows\system32\taskcomp.dll
2011-02-18 23:49:10 ----A---- C:\Windows\system32\schtasks.exe
2011-02-18 23:49:10 ----A---- C:\Windows\system32\schedsvc.dll
2011-02-18 23:49:09 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-02-18 23:49:09 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-02-18 23:49:04 ----A---- C:\Windows\system32\kerberos.dll
2011-02-18 23:49:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-02-18 23:48:57 ----A---- C:\Windows\system32\mshtml.dll
2011-02-18 23:48:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-02-18 23:48:48 ----A---- C:\Windows\system32\iertutil.dll
2011-02-18 23:48:47 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-02-18 23:48:47 ----A---- C:\Windows\system32\mstime.dll
2011-02-18 23:48:46 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-02-18 23:48:46 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-02-18 23:48:45 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-02-18 23:48:45 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-02-18 23:48:45 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-02-18 23:48:45 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-02-18 23:48:45 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-18 23:48:45 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-18 23:48:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-02-18 23:48:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-02-18 23:48:44 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-18 23:48:44 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-18 23:48:44 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-18 23:48:44 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-18 23:48:44 ----A---- C:\Windows\system32\iepeers.dll
2011-02-18 23:48:36 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-02-18 23:48:36 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-02-18 23:48:36 ----A---- C:\Windows\system32\d3d10warp.dll
2011-02-18 23:48:35 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-02-18 23:48:34 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-02-18 23:48:34 ----A---- C:\Windows\system32\d2d1.dll
2011-02-18 23:48:33 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-02-18 23:48:33 ----A---- C:\Windows\system32\mf.dll
2011-02-18 23:48:33 ----A---- C:\Windows\system32\DWrite.dll
2011-02-18 23:48:32 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-02-18 23:48:32 ----A---- C:\Windows\system32\XpsPrint.dll
2011-02-18 23:48:32 ----A---- C:\Windows\system32\FntCache.dll
2011-02-18 23:48:31 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-02-18 23:48:31 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-02-18 23:48:31 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-02-18 23:48:30 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-02-18 23:48:30 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-18 23:48:30 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-02-18 23:48:29 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-02-18 23:48:29 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-02-18 23:48:29 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-02-18 23:48:29 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-02-18 23:48:29 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-02-18 23:48:29 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-02-18 23:48:29 ----A---- C:\Windows\system32\mfps.dll
2011-02-18 23:48:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-18 23:48:29 ----A---- C:\Windows\system32\d3d10_1.dll
2011-02-18 23:48:28 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-02-18 23:48:28 ----A---- C:\Windows\system32\cdd.dll
2011-02-18 23:48:11 ----A---- C:\Windows\system32\win32k.sys
2011-02-18 23:48:10 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-02-18 23:48:10 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-02-18 23:48:10 ----A---- C:\Windows\system32\vbscript.dll
2011-02-18 23:48:10 ----A---- C:\Windows\system32\jscript.dll
2011-02-18 23:48:08 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-02-18 23:48:08 ----A---- C:\Windows\system32\winsrv.dll
2011-02-18 23:48:08 ----A---- C:\Windows\system32\atmfd.dll
2011-02-18 23:48:07 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-02-18 23:48:07 ----A---- C:\Windows\system32\atmlib.dll
2011-02-18 23:47:59 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-02-18 23:47:59 ----A---- C:\Windows\system32\odbc32.dll
2011-02-18 23:47:57 ----A---- C:\Windows\system32\consent.exe
2011-02-18 23:39:14 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-02-18 23:37:53 ----D---- C:\ProgramData\NVIDIA Corporation
2011-02-18 23:33:22 ----A---- C:\Windows\system32\nvhdap64.dll
2011-02-18 23:33:22 ----A---- C:\Windows\system32\nvgenco64.dll
2011-02-18 23:33:22 ----A---- C:\Windows\system32\nvapo64v.dll
2011-02-18 23:33:22 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvdecodemft.dll
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvoglv64.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvgenco642030.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvdispco642050.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvdecodemft.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\OpenCL.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvcuvid.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvcuda.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvcompiler.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvapi64.dll
2011-02-18 23:31:49 ----D---- C:\Program Files\NVIDIA Corporation
2011-02-18 23:12:59 ----D---- C:\ProgramData\IObit
2011-02-18 22:59:47 ----D---- C:\Users\Knteok\AppData\Roaming\IObit
2011-02-18 22:59:46 ----D---- C:\Program Files (x86)\IObit
2011-02-18 21:48:40 ----D---- C:\Users\Knteok\AppData\Roaming\Ventrilo
2011-02-18 21:03:47 ----D---- C:\Program Files\VentriloMIX
2011-02-18 20:59:55 ----D---- C:\Program Files\TeamSpeak 3 Client
2011-02-18 20:57:19 ----D---- C:\Program Files (x86)\Steam
2011-02-09 21:15:24 ----D---- C:\Program Files (x86)\Convar
2011-02-09 15:02:19 ----A---- C:\Windows\ipuninst.exe
2011-02-09 12:46:20 ----A---- C:\Windows\IsUninst.exe
2011-02-04 12:12:18 ----D---- C:\Users\Knteok\AppData\Roaming\NeroDigital(TM)
2011-02-01 12:51:02 ----D---- C:\Users\Knteok\AppData\Roaming\Nero
2011-02-01 12:41:57 ----D---- C:\ProgramData\Nero
2011-02-01 12:41:09 ----D---- C:\Program Files (x86)\Nero
2011-01-28 11:24:11 ----D---- C:\Program Files (x86)\The KMPlayer
2011-01-25 14:59:13 ----D---- C:\Program Files (x86)\JDownloader
2011-01-24 23:16:52 ----D---- C:\Users\Knteok\AppData\Roaming\Apple Computer
2011-01-24 00:41:03 ----D---- C:\Windows\Sun
2011-01-20 14:18:30 ----D---- C:\Users\Knteok\AppData\Roaming\vlc
2010-12-26 19:22:19 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2010-12-24 23:34:24 ----D---- C:\ProgramData\Electronic Arts
2010-12-24 22:59:47 ----D---- C:\Program Files (x86)\Microsoft WSE
2010-12-24 22:34:44 ----D---- C:\Program Files (x86)\Electronic Arts
2010-12-14 15:37:47 ----D---- C:\Program Files (x86)\VideoLAN
2010-12-14 11:42:04 ----D---- C:\ProgramData\Apple Computer
2010-12-14 11:42:04 ----D---- C:\Program Files (x86)\QuickTime
2010-12-12 13:22:36 ----D---- C:\Program Files (x86)\Guitar Pro 5
2010-12-12 13:06:41 ----D---- C:\ProgramData\Sun
2010-12-12 13:06:14 ----A---- C:\Windows\SYSWOW64\javaws.exe
2010-12-12 13:06:14 ----A---- C:\Windows\SYSWOW64\javaw.exe
2010-12-12 13:06:14 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2010-12-12 13:06:13 ----A---- C:\Windows\SYSWOW64\java.exe
2010-12-12 13:05:47 ----D---- C:\Program Files (x86)\Java
2010-12-12 13:04:28 ----D---- C:\Program Files (x86)\ESET
2010-12-10 05:17:55 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2010-12-10 05:16:18 ----D---- C:\Program Files\Adobe
2010-12-10 05:12:34 ----D---- C:\Program Files\Common Files\Adobe
2010-12-10 05:11:06 ----D---- C:\Program Files (x86)\Adobe Media Player
2010-12-09 21:35:03 ----D---- C:\ProgramData\Adobe
2010-12-09 21:35:00 ----D---- C:\Program Files (x86)\Adobe
2010-12-09 21:33:35 ----D---- C:\Program Files (x86)\Consumer Update Firmware
2010-12-08 03:06:18 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2010-12-08 03:01:11 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2010-12-08 02:45:38 ----D---- C:\Program Files (x86)\Microsoft Works
2010-12-08 02:44:31 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2010-12-08 02:44:22 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2010-12-08 02:44:22 ----A---- C:\Windows\system32\drivers\ks.sys
2010-12-08 02:43:21 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2010-12-08 02:43:21 ----A---- C:\Windows\system32\oleaut32.dll
2010-12-08 02:43:08 ----A---- C:\Windows\SYSWOW64\setup16.exe
2010-12-08 02:43:08 ----A---- C:\Windows\system32\wow64.dll
2010-12-08 02:43:07 ----A---- C:\Windows\SYSWOW64\wow32.dll
2010-12-08 02:43:07 ----A---- C:\Windows\SYSWOW64\user.exe
2010-12-08 02:43:07 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2010-12-08 02:43:07 ----A---- C:\Windows\SYSWOW64\instnm.exe
2010-12-08 02:43:06 ----A---- C:\Windows\system32\drivers\fvevol.sys
2010-12-08 02:42:50 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-12-08 02:42:49 ----D---- C:\Windows\PCHEALTH
2010-12-08 02:39:04 ----D---- C:\Program Files\Microsoft Office
2010-12-08 02:38:54 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2010-12-08 02:37:27 ----D---- C:\Program Files (x86)\Microsoft Office
2010-12-08 02:37:26 ----D---- C:\ProgramData\Microsoft Help
2010-12-08 02:35:48 ----D---- C:\ProgramData\ESET
2010-12-08 02:35:48 ----D---- C:\Program Files\ESET
2010-12-08 02:09:38 ----A---- C:\Windows\UOUninst.exe
2010-12-08 02:09:20 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2010-12-08 02:09:20 ----A---- C:\Windows\system32\msv1_0.dll
2010-12-08 02:03:31 ----D---- C:\Program Files (x86)\Microsoft.NET
2010-12-08 01:58:42 ----D---- C:\Users\Knteok\AppData\Roaming\Winamp
2010-12-08 01:58:42 ----D---- C:\Program Files (x86)\Winamp
2010-12-08 01:57:24 ----D---- C:\ProgramData\Apple
2010-12-08 01:57:24 ----D---- C:\Program Files (x86)\Apple Software Update
2010-12-08 01:56:43 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2010-12-08 01:56:43 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2010-12-08 01:56:43 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2010-12-08 01:56:43 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2010-12-08 01:56:43 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2010-12-08 01:56:43 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-12-08 01:56:43 ----A---- C:\Windows\system32\PresentationHost.exe
2010-12-08 01:56:43 ----A---- C:\Windows\system32\netfxperf.dll
2010-12-08 01:56:43 ----A---- C:\Windows\system32\mscoree.dll
2010-12-08 01:56:43 ----A---- C:\Windows\system32\dfshim.dll
2010-12-08 01:55:40 ----D---- C:\Program Files (x86)\Google
2010-12-08 01:55:39 ----A---- C:\Windows\system32\browserchoice.exe
2010-12-08 01:50:07 ----A---- C:\Windows\system32\drivers\sptd.sys
2010-12-08 01:49:26 ----A---- C:\Windows\system32\MRT.exe
2010-12-08 01:48:50 ----D---- C:\Users\Knteok\AppData\Roaming\DAEMON Tools Lite
2010-12-08 01:48:49 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-12-08 01:44:32 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2010-12-08 01:44:32 ----A---- C:\Windows\SYSWOW64\secur32.dll
2010-12-08 01:44:32 ----A---- C:\Windows\system32\lsasrv.dll
2010-12-08 01:44:32 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2010-12-08 01:44:31 ----A---- C:\Windows\system32\shell32.dll
2010-12-08 01:44:30 ----A---- C:\Windows\SYSWOW64\shell32.dll
2010-12-08 01:44:25 ----A---- C:\Windows\SYSWOW64\tzres.dll
2010-12-08 01:44:25 ----A---- C:\Windows\system32\tzres.dll
2010-12-08 01:44:20 ----A---- C:\Windows\system32\msasn1.dll
2010-12-08 01:44:19 ----A---- C:\Windows\SYSWOW64\msasn1.dll
2010-12-08 01:44:10 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2010-12-08 01:44:10 ----A---- C:\Windows\system32\CertEnroll.dll
2010-12-08 01:44:08 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2010-12-08 01:44:07 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2010-12-08 01:43:59 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2010-12-08 01:43:59 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2010-12-08 01:43:59 ----A---- C:\Windows\system32\t2embed.dll
2010-12-08 01:43:59 ----A---- C:\Windows\system32\rtutils.dll
2010-12-08 01:43:47 ----A---- C:\Windows\SYSWOW64\explorer.exe
2010-12-08 01:43:47 ----A---- C:\Windows\explorer.exe
2010-12-08 01:43:46 ----A---- C:\Windows\system32\winlogon.exe
2010-12-08 01:43:46 ----A---- C:\Windows\system32\inetcomm.dll
2010-12-08 01:43:45 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2010-12-08 01:43:45 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2010-12-08 01:43:45 ----A---- C:\Windows\system32\StructuredQuery.dll
2010-12-08 01:43:37 ----A---- C:\Windows\SYSWOW64\schannel.dll
2010-12-08 01:43:37 ----A---- C:\Windows\system32\schannel.dll
2010-12-08 01:43:36 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2010-12-08 01:43:36 ----A---- C:\Windows\system32\comctl32.dll
2010-12-08 01:43:35 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2010-12-08 01:43:35 ----A---- C:\Windows\system32\spoolsv.exe
2010-12-08 01:43:35 ----A---- C:\Windows\system32\asycfilt.dll
2010-12-08 01:43:34 ----A---- C:\Windows\SYSWOW64\cabview.dll
2010-12-08 01:43:34 ----A---- C:\Windows\system32\cabview.dll
2010-12-08 01:43:33 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2010-12-08 01:43:33 ----A---- C:\Windows\SYSWOW64\quartz.dll
2010-12-08 01:43:33 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2010-12-08 01:43:33 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2010-12-08 01:43:33 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2010-12-08 01:43:33 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2010-12-08 01:43:33 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2010-12-08 01:43:33 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2010-12-08 01:43:33 ----A---- C:\Windows\system32\tsbyuv.dll
2010-12-08 01:43:33 ----A---- C:\Windows\system32\quartz.dll
2010-12-08 01:43:33 ----A---- C:\Windows\system32\msyuv.dll
2010-12-08 01:43:33 ----A---- C:\Windows\system32\msvidc32.dll
2010-12-08 01:43:33 ----A---- C:\Windows\system32\msrle32.dll
2010-12-08 01:43:33 ----A---- C:\Windows\system32\iyuv_32.dll
2010-12-08 01:43:33 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-12-08 01:43:32 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2010-12-08 01:43:32 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2010-12-08 01:43:32 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2010-12-08 01:43:31 ----A---- C:\Windows\system32\ole32.dll
2010-12-08 01:43:30 ----A---- C:\Windows\SYSWOW64\ole32.dll
2010-12-08 01:43:27 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2010-12-08 01:43:27 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2010-12-08 01:43:27 ----A---- C:\Windows\system32\wmpmde.dll
2010-12-08 01:43:27 ----A---- C:\Windows\system32\fontsub.dll
2010-12-08 01:43:25 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2010-12-08 01:43:24 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2010-12-08 01:43:24 ----A---- C:\Windows\system32\wintrust.dll
2010-12-08 01:43:23 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2010-12-08 01:43:23 ----A---- C:\Windows\system32\wmploc.DLL
2010-12-08 01:43:21 ----A---- C:\Windows\system32\wmp.dll
2010-12-08 01:43:20 ----A---- C:\Windows\SYSWOW64\wmp.dll
2010-12-08 01:41:20 ----A---- C:\Windows\SYSWOW64\sscore.dll
2010-12-08 01:41:20 ----A---- C:\Windows\system32\srvsvc.dll
2010-12-08 01:41:20 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-12-08 01:41:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-12-08 01:41:20 ----A---- C:\Windows\system32\drivers\srv.sys
2010-12-08 01:16:05 ----D---- C:\Windows\SYSWOW64\cs
2010-12-08 01:16:01 ----D---- C:\Windows\SYSWOW64\XPSViewer
2010-12-08 01:16:01 ----D---- C:\Windows\SYSWOW64\drivers\cs-CZ
2010-12-08 01:16:00 ----D---- C:\Windows\cs-CZ
2010-12-08 01:15:56 ----D---- C:\Windows\system32\cs
2010-12-08 01:15:42 ----D---- C:\Windows\system32\drivers\cs-CZ
2010-12-08 01:05:02 ----D---- C:\Users\Knteok\AppData\Roaming\TuneUp Software
2010-12-08 01:04:36 ----D---- C:\ProgramData\TuneUp Software
2010-12-08 01:04:29 ----SHD---- C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2010-12-08 01:02:42 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2010-12-08 01:02:42 ----A---- C:\Windows\system32\XAudio2_5.dll
2010-12-08 01:02:39 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2010-12-08 01:02:39 ----A---- C:\Windows\system32\xactengine3_5.dll
2010-12-08 01:02:36 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2010-12-08 01:02:36 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2010-12-08 01:02:34 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2010-12-08 01:02:34 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2010-12-08 01:02:34 ----A---- C:\Windows\system32\d3dx11_42.dll
2010-12-08 01:02:34 ----A---- C:\Windows\system32\d3dcsx_42.dll
2010-12-08 01:02:33 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2010-12-08 01:02:33 ----A---- C:\Windows\system32\d3dx10_42.dll
2010-12-08 01:02:32 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2010-12-08 01:02:32 ----A---- C:\Windows\system32\D3DX9_42.dll
2010-12-08 01:02:29 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2010-12-08 01:02:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2010-12-08 01:02:29 ----A---- C:\Windows\system32\d3dx10_41.dll
2010-12-08 01:02:29 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2010-12-08 01:02:28 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2010-12-08 01:02:28 ----A---- C:\Windows\system32\D3DX9_41.dll
2010-12-08 01:02:25 ----D---- C:\Users\Knteok\AppData\Roaming\WinRAR
2010-12-08 01:02:25 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2010-12-08 01:02:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2010-12-08 01:02:25 ----A---- C:\Windows\system32\XAudio2_4.dll
2010-12-08 01:02:25 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2010-12-08 01:02:21 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2010-12-08 01:02:21 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2010-12-08 01:02:21 ----A---- C:\Windows\system32\xactengine3_4.dll
2010-12-08 01:02:21 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2010-12-08 01:02:20 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2010-12-08 01:02:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2010-12-08 01:02:20 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-12-08 01:02:20 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-12-08 01:02:18 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2010-12-08 01:02:18 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-12-08 01:02:12 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2010-12-08 01:02:12 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2010-12-08 01:02:12 ----A---- C:\Windows\system32\XAudio2_3.dll
2010-12-08 01:02:12 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2010-12-08 01:02:09 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2010-12-08 01:02:09 ----A---- C:\Windows\system32\xactengine3_3.dll
2010-12-08 01:02:07 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2010-12-08 01:02:07 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2010-12-08 01:02:03 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2010-12-08 01:02:03 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2010-12-08 01:02:03 ----A---- C:\Windows\system32\XAudio2_2.dll
2010-12-08 01:02:03 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2010-12-08 01:01:59 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2010-12-08 01:01:59 ----A---- C:\Windows\system32\xactengine3_2.dll
2010-12-08 01:01:57 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2010-12-08 01:01:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2010-12-08 01:01:57 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-12-08 01:01:57 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-12-08 01:01:56 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2010-12-08 01:01:56 ----A---- C:\Windows\system32\D3DX9_39.dll
2010-12-08 01:01:52 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2010-12-08 01:01:52 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2010-12-08 01:01:52 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-12-08 01:01:52 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-12-08 01:01:48 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2010-12-08 01:01:48 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-12-08 01:01:47 ----D---- C:\Program Files (x86)\WinRAR
2010-12-08 01:01:45 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2010-12-08 01:01:45 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2010-12-08 01:01:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2010-12-08 01:01:45 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-12-08 01:01:45 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-12-08 01:01:45 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-12-08 01:01:41 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2010-12-08 01:01:41 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-12-08 01:01:39 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2010-12-08 01:01:39 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-12-08 01:01:36 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2010-12-08 01:01:36 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-12-08 01:01:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2010-12-08 01:01:35 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-12-08 01:01:34 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2010-12-08 01:01:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2010-12-08 01:01:34 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-12-08 01:01:34 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-12-08 01:01:33 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2010-12-08 01:01:33 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-12-08 01:01:29 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2010-12-08 01:01:29 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-12-08 01:01:25 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2010-12-08 01:01:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2010-12-08 01:01:25 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-12-08 01:01:25 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-12-08 01:01:24 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2010-12-08 01:01:24 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-12-08 01:01:16 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2010-12-08 01:01:16 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2010-12-08 01:01:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2010-12-08 01:01:16 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-12-08 01:01:16 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-12-08 01:01:16 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-12-08 01:01:15 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2010-12-08 01:01:15 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-12-08 01:01:10 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2010-12-08 01:01:10 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2010-12-08 01:01:10 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2010-12-08 01:01:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2010-12-08 01:01:10 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-12-08 01:01:10 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-12-08 01:01:10 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-12-08 01:01:10 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-12-08 01:01:06 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2010-12-08 01:01:06 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2010-12-08 01:01:06 ----A---- C:\Windows\system32\xinput1_3.dll
2010-12-08 01:01:06 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-12-08 01:01:03 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2010-12-08 01:01:03 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-12-08 01:01:02 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2010-12-08 01:01:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2010-12-08 01:01:02 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-12-08 01:01:02 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-12-08 01:01:00 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2010-12-08 01:01:00 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-12-08 01:00:54 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2010-12-08 01:00:54 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-12-08 01:00:50 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2010-12-08 01:00:50 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-12-08 01:00:49 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2010-12-08 01:00:49 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2010-12-08 01:00:49 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-12-08 01:00:49 ----A---- C:\Windows\system32\d3dx10.dll
2010-12-08 01:00:46 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2010-12-08 01:00:46 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2010-12-08 01:00:46 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-12-08 01:00:46 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-12-08 01:00:45 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2010-12-08 01:00:45 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-12-08 01:00:41 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2010-12-08 01:00:41 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2010-12-08 01:00:41 ----A---- C:\Windows\system32\xinput1_2.dll
2010-12-08 01:00:41 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-12-08 01:00:39 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2010-12-08 01:00:39 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-12-08 01:00:38 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2010-12-08 01:00:38 ----A---- C:\Windows\system32\xinput1_1.dll
2010-12-08 01:00:36 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2010-12-08 01:00:36 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-12-08 01:00:07 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2010-12-08 01:00:07 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-12-08 01:00:05 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2010-12-08 01:00:05 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2010-12-08 01:00:05 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-12-08 01:00:05 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-12-08 01:00:04 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2010-12-08 01:00:04 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2010-12-08 01:00:04 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-12-08 01:00:04 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-12-08 01:00:03 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2010-12-08 01:00:03 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-12-08 01:00:02 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2010-12-08 01:00:02 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2010-12-08 01:00:02 ----A---- C:\Windows\system32\d3dx9_26.dll
2010-12-08 01:00:02 ----A---- C:\Windows\system32\d3dx9_25.dll
2010-12-08 00:59:59 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2010-12-08 00:59:59 ----A---- C:\Windows\system32\d3dx9_24.dll
2010-12-08 00:37:40 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-12-08 00:36:11 ----D---- C:\Users\Knteok\AppData\Roaming\Macromedia
2010-12-08 00:36:11 ----D---- C:\Users\Knteok\AppData\Roaming\Adobe
2010-12-08 00:32:51 ----D---- C:\ProgramData\NVIDIA
2010-12-08 00:18:53 ----D---- C:\Windows\SYSWOW64\Macromed
2010-12-08 00:18:41 ----D---- C:\Program Files (x86)\7-Zip
2010-12-08 00:15:59 ----N---- C:\Windows\SYSWOW64\agrsmdel.exe
2010-12-08 00:15:59 ----N---- C:\Windows\SYSWOW64\agrsco64.dll
2010-12-08 00:15:46 ----D---- C:\Windows\Options
2010-12-08 00:14:11 ----D---- C:\Program Files (x86)\ITE
2010-12-08 00:13:17 ----A---- C:\Windows\system32\drivers\btwl2cap.sys
2010-12-08 00:13:16 ----A---- C:\Windows\system32\drivers\btwavdt.sys
2010-12-08 00:13:15 ----A---- C:\Windows\system32\drivers\btwrchid.sys
2010-12-08 00:13:15 ----A---- C:\Windows\system32\drivers\btwaudio.sys
2010-12-08 00:13:04 ----A---- C:\Windows\xUninstall.bat
2010-12-08 00:12:55 ----D---- C:\Windows\JMCR_DIR
2010-12-08 00:12:08 ----D---- C:\Program Files\WIDCOMM
2010-12-08 00:11:30 ----A---- C:\Windows\USB_VIDEO_REG.exe
2010-12-08 00:11:30 ----A---- C:\Windows\PLFSetI.exe
2010-12-08 00:10:39 ----A---- C:\Windows\usbvideo_reg.exe
2010-12-08 00:10:39 ----A---- C:\Windows\PidList.ini
2010-12-08 00:10:39 ----A---- C:\Windows\Image.dll
2010-12-08 00:10:39 ----A---- C:\Windows\Acer Crystal Eye webcam.EXE
2010-12-08 00:07:11 ----SHD---- C:\Windows\Installer
2010-12-08 00:05:19 ----HD---- C:\Program Files (x86)\Temp
2010-12-08 00:05:17 ----A---- C:\Windows\RtlExUpd.dll
2010-12-08 00:04:00 ----A---- C:\Windows\system32\drivers\iaStor.sys
2010-12-08 00:03:56 ----D---- C:\Program Files (x86)\Intel
2010-12-08 00:03:55 ----D---- C:\Users\Knteok\AppData\Roaming\InstallShield
2010-12-07 23:40:30 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2010-12-07 23:40:28 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-12-07 23:40:28 ----D---- C:\Users\Knteok\AppData\Roaming\Mozilla
2010-12-07 23:40:28 ----D---- C:\ProgramData\ICQ
2010-12-07 23:40:20 ----D---- C:\Users\Knteok\AppData\Roaming\ICQ
2010-12-07 23:40:16 ----D---- C:\Program Files (x86)\ICQ7.2
2010-12-07 18:36:24 ----D---- C:\Users\Knteok\AppData\Roaming\Identities
2010-12-07 18:35:31 ----SD---- C:\Users\Knteok\AppData\Roaming\Microsoft
2010-12-07 18:35:31 ----D---- C:\Users\Knteok\AppData\Roaming\Media Center Programs
2010-12-07 11:17:20 ----D---- C:\Windows\SoftwareDistribution
2010-12-07 11:14:52 ----D---- C:\Windows\Prefetch
2010-12-07 11:13:10 ----ASH---- C:\hiberfil.sys
2010-12-07 11:12:24 ----D---- C:\Windows\Panther
2010-12-07 09:36:14 ----SHD---- C:\Recovery
2010-11-21 22:57:45 ----D---- C:\Consumer Update Firmware

======List of files/folders modified in the last 3 months======

2011-02-19 15:03:12 ----D---- C:\Windows\Temp
2011-02-19 15:03:11 ----RD---- C:\Program Files
2011-02-19 14:46:29 ----D---- C:\Windows\system32\Tasks
2011-02-19 14:43:11 ----D---- C:\Windows\system32\config
2011-02-19 14:02:19 ----D---- C:\Windows\winsxs
2011-02-19 13:44:34 ----D---- C:\Windows\SysWOW64
2011-02-19 13:44:34 ----D---- C:\Windows\System32
2011-02-19 13:44:34 ----D---- C:\Program Files\Internet Explorer
2011-02-19 13:44:34 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-19 13:28:21 ----SHD---- C:\System Volume Information
2011-02-19 13:27:35 ----D---- C:\Windows\system32\catroot
2011-02-19 13:27:34 ----D---- C:\Windows\system32\catroot2
2011-02-19 13:01:12 ----RD---- C:\Program Files (x86)
2011-02-19 12:53:17 ----D---- C:\Windows\Tasks
2011-02-19 12:45:50 ----D---- C:\Windows\inf
2011-02-19 12:45:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-19 00:10:15 ----D---- C:\Windows
2011-02-19 00:07:17 ----D---- C:\Windows\system32\drivers
2011-02-19 00:07:10 ----D---- C:\Windows\system32\DriverStore
2011-02-19 00:02:39 ----D---- C:\Windows\SYSWOW64\migration
2011-02-19 00:02:38 ----D---- C:\Windows\system32\migration
2011-02-19 00:02:38 ----D---- C:\Program Files\Windows Mail
2011-02-19 00:02:38 ----D---- C:\Program Files (x86)\Windows Mail
2011-02-18 23:38:45 ----D---- C:\Windows\Help
2011-02-18 23:37:53 ----HD---- C:\ProgramData
2011-02-18 20:57:20 ----D---- C:\Program Files (x86)\Common Files
2011-02-17 10:24:50 ----D---- C:\Windows\system32\NDF
2011-02-01 12:26:27 ----RSD---- C:\Windows\assembly
2011-01-13 20:25:04 ----SHD---- C:\$Recycle.Bin
2011-01-13 20:24:46 ----RD---- C:\Users
2010-12-24 22:30:37 ----D---- C:\Windows\system32\wdi
2010-12-12 13:22:42 ----RSD---- C:\Windows\Fonts
2010-12-10 06:50:57 ----D---- C:\Windows\system32\drivers\UMDF
2010-12-10 05:12:34 ----D---- C:\Program Files\Common Files
2010-12-08 21:39:41 ----D---- C:\Windows\rescache
2010-12-08 21:02:42 ----D---- C:\Windows\Microsoft.NET
2010-12-08 20:30:23 ----SD---- C:\ProgramData\Microsoft
2010-12-08 03:01:53 ----D---- C:\Windows\SYSWOW64\cs-CZ
2010-12-08 03:01:53 ----D---- C:\Windows\system32\cs-CZ
2010-12-08 03:01:53 ----D---- C:\Windows\AppPatch
2010-12-08 02:45:22 ----D---- C:\Program Files (x86)\MSBuild
2010-12-08 02:44:24 ----D---- C:\Windows\ShellNew
2010-12-08 02:40:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-12-08 02:38:24 ----A---- C:\Windows\win.ini
2010-12-08 02:26:03 ----D---- C:\Windows\ehome
2010-12-08 02:26:00 ----D---- C:\Windows\SYSWOW64\en-US
2010-12-08 02:26:00 ----D---- C:\Windows\system32\en-US
2010-12-08 02:25:58 ----D---- C:\Program Files\Windows Media Player
2010-12-08 02:25:58 ----D---- C:\Program Files (x86)\Windows Media Player
2010-12-08 01:49:31 ----D---- C:\Windows\debug
2010-12-08 01:16:10 ----D---- C:\Program Files (x86)\Windows Sidebar
2010-12-08 01:16:09 ----D---- C:\Program Files\Windows Sidebar
2010-12-08 01:16:09 ----D---- C:\Program Files\Windows Photo Viewer
2010-12-08 01:16:09 ----D---- C:\Program Files\Windows Journal
2010-12-08 01:16:09 ----D---- C:\Program Files\DVD Maker
2010-12-08 01:16:09 ----D---- C:\Program Files\Common Files\System
2010-12-08 01:16:09 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2010-12-08 01:16:09 ----D---- C:\Program Files (x86)\Windows Defender
2010-12-08 01:16:08 ----D---- C:\Windows\servicing
2010-12-08 01:16:08 ----D---- C:\Program Files\Windows Defender
2010-12-08 01:16:05 ----D---- C:\Windows\SYSWOW64\winrm
2010-12-08 01:16:05 ----D---- C:\Windows\SYSWOW64\slmgr
2010-12-08 01:16:05 ----D---- C:\Windows\SYSWOW64\migwiz
2010-12-08 01:16:01 ----D---- C:\Windows\SYSWOW64\WCN
2010-12-08 01:16:01 ----D---- C:\Windows\SYSWOW64\Printing_Admin_Scripts
2010-12-08 01:16:01 ----D---- C:\Windows\SYSWOW64\MUI
2010-12-08 01:16:01 ----D---- C:\Windows\SYSWOW64\DriverStore
2010-12-08 01:16:01 ----D---- C:\Windows\SYSWOW64\drivers
2010-12-08 01:16:01 ----D---- C:\Windows\SYSWOW64\Dism
2010-12-08 01:16:00 ----D---- C:\Windows\SYSWOW64\wbem
2010-12-08 01:16:00 ----D---- C:\Windows\SYSWOW64\com
2010-12-08 01:16:00 ----D---- C:\Windows\IME
2010-12-08 01:15:57 ----D---- C:\Windows\system32\winrm
2010-12-08 01:15:57 ----D---- C:\Windows\system32\sysprep
2010-12-08 01:15:57 ----D---- C:\Windows\system32\slmgr
2010-12-08 01:15:57 ----D---- C:\Windows\system32\oobe
2010-12-08 01:15:57 ----D---- C:\Windows\system32\migwiz
2010-12-08 01:15:57 ----D---- C:\Windows\system32\Boot
2010-12-08 01:15:57 ----D---- C:\Windows\PolicyDefinitions
2010-12-08 01:15:42 ----D---- C:\Windows\system32\WCN
2010-12-08 01:15:42 ----D---- C:\Windows\system32\MUI
2010-12-08 01:15:42 ----D---- C:\Windows\system32\Dism
2010-12-08 01:15:37 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2010-12-08 01:15:35 ----D---- C:\Windows\system32\wbem
2010-12-08 01:15:35 ----D---- C:\Windows\system32\com
2010-12-08 01:08:30 ----D---- C:\Windows\Logs
2010-12-08 00:36:04 ----D---- C:\Windows\Downloaded Program Files
2010-12-08 00:12:56 ----SD---- C:\Windows\system32\Microsoft
2010-12-07 23:40:02 ----D---- C:\Windows\system32\LogFiles
2010-12-07 19:07:27 ----D---- C:\Windows\system32\restore
2010-12-07 18:32:49 ----D---- C:\Windows\system32\Recovery
2010-12-07 11:22:58 ----D---- C:\Windows\system32\CodeIntegrity
2010-12-07 11:14:44 ----D---- C:\Windows\CSC
2010-12-07 11:11:35 ----D---- C:\Windows\Setup
2010-12-07 10:01:28 ----D---- C:\b6e4f2d5b0aa761801cd84b23b3304
2010-12-07 10:01:28 ----D---- C:\0f6c02f8d2b8e7410fdead77921938e7

Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Re: Prosím o kontrolu HJT

#4 Příspěvek od Knotek »

pokračování

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 408600]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2007-02-07 14104]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-12-08 834544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-09-03 170104]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2008-02-29 1252352]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-01-25 2727912]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2010-07-13 69736]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x64.sys [2009-08-23 56320]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2010-07-14 7821312]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-09-07 155752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 a6b90gtn;a6b90gtn; C:\Windows\system32\drivers\a6b90gtn.sys []
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-12-08 98344]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-12-08 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-12-08 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-12-08 21160]
S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-16 6952960]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\Windows\system32\DRIVERS\s116bus.sys [2007-04-03 108296]
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s116mdfl.sys [2007-04-03 19720]
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s116mdm.sys [2007-04-03 144648]
S3 s116mgmt;Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s116mgmt.sys [2007-04-03 126216]
S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS); C:\Windows\system32\DRIVERS\s116nd5.sys [2007-04-03 31496]
S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s116obex.sys [2007-04-03 123656]
S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM); C:\Windows\system32\DRIVERS\s116unic.sys [2007-04-03 130824]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agr64svc.exe [2007-12-11 15872]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-18 864032]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-11-18 810144]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-07 247096]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-01-26 573224]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 989800]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-11-18 42360]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-27 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2009-07-16 316664]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------


RSIT - Info

info.txt logfile of random's system information tool 1.08 2011-02-19 15:03:17

======Uninstall list======

-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
7-Zip 4.65-->"C:\Program Files (x86)\7-Zip\Uninstall.exe"
Acer Crystal Eye Webcam 3.0.6.3-->C:\Program Files (x86)\InstallShield Installation Information\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}\setup.exe -runfromtemp -l0x0009 -removeonly
Acer Crystal Eye Webcam-->C:\Program Files (x86)\InstallShield Installation Information\{7760D94E-B1B5-40A0-9AA0-ABF942108755}\setup.exe -runfromtemp -l0x0009 -removeonly
Adobe AIR-->C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Community Help-->msiexec /qb /x {0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Community Help-->MsiExec.exe /I{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_Plugin.exe -maintain plugin
Adobe Media Player-->msiexec /qb /x {DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Media Player-->MsiExec.exe /I{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Photoshop CS5-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader 9.4.1 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Advanced SystemCare 3-->"C:\Program Files (x86)\IObit\Advanced SystemCare 3\unins000.exe"
Agere Systems HDA Modem-->agrsmdel
Apple Application Support-->MsiExec.exe /I{EE6097DD-05F4-4178-9719-D3170BF098E8}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver-->"C:\Program Files (x86)\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe" -runfromtemp -l0x0009 -removeonly
ConsumerUpdate-->MsiExec.exe /I{7C6999B2-1A35-4F2C-8DB7-3CB46B640CC9}
Counter-Strike-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/10
EA Download Manager-->C:\Program Files (x86)\Electronic Arts\EADM\EADMUI\EADMUninstall.exe
ESET Antivirus License Finder (MiNODLogin)-->"C:\Program Files (x86)\ESET\MiNODLogin\MiNODLoginUninst.exe"
Guitar Pro 5.2-->"C:\Program Files (x86)\Guitar Pro 5\unins000.exe"
High-Definition Video Playback 10-->MsiExec.exe /X{237CCB62-8454-43E3-B158-3ACD0134852E}
HijackThis 2.0.2-->"C:\Users\Knteok\Downloads\HijackThis.exe" /uninstall
ICQ Toolbar-->C:\Program Files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
ICQ7.2-->"C:\Program Files (x86)\InstallShield Installation Information\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
Intel® Matrix Storage Manager-->C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
ITECIR-->C:\Program Files (x86)\InstallShield Installation Information\{40580068-9B10-40B5-9548-536CE88AB23C}\setup.exe -runfromtemp -l0x0005 -removeonly
Java(TM) 6 Update 22-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216022FF}
JDownloader-->C:\Program Files (x86)\JDownloader\uninstall.exe
JMicron JMB38X Flash Media Controller-->"C:\Program Files (x86)\InstallShield Installation Information\{26604C7E-A313-4D12-867F-7C6E7820BE4C}\setup.exe" delpkg
Kolekce The Sims™ 3 Na plný plyn-->"C:\Program Files (x86)\InstallShield Installation Information\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}\Sims3SP02Setup.exe" -runfromtemp -l0x0005 -removeonly
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office Office 64-bit Components 2007-->MsiExec.exe /X{90120000-002A-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared 64-bit MUI (Czech) 2007-->MsiExec.exe /X{90120000-002A-0405-1000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Primary Interoperability Assemblies 2005-->MsiExec.exe /X{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft WSE 3.0 Runtime-->MsiExec.exe /X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}
Microsoft_VC80_ATL_x86_x64-->MsiExec.exe /I{925D058B-564A-443A-B4B2-7E90C6432E55}
Microsoft_VC80_ATL_x86-->MsiExec.exe /I{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}
Microsoft_VC80_CRT_x86_x64-->MsiExec.exe /I{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86_x64-->MsiExec.exe /I{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86_x64-->MsiExec.exe /I{1E9FC118-651D-4934-97BE-E53CAE5C7D45}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86_x64-->MsiExec.exe /I{8557397C-A42D-486F-97B3-A2CBC2372593}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86_x64-->MsiExec.exe /I{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86_x64-->MsiExec.exe /I{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Mozilla Firefox (3.6.13)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nero 10 Menu TemplatePack Basic-->MsiExec.exe /X{63AA3EAB-23BB-48B2-9AD0-44F878075604}
Nero 10 Movie ThemePack Basic-->MsiExec.exe /X{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}
Nero BackItUp 10 Help (CHM)-->MsiExec.exe /X{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}
Nero Burning ROM 10-->MsiExec.exe /X{7A5D731D-B4B3-490E-B339-75685712BAAB}
Nero BurningROM 10 Help (CHM)-->MsiExec.exe /X{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}
Nero BurnRights 10 Help (CHM)-->MsiExec.exe /X{555868C6-49FB-484F-BB43-8980651A1B00}
Nero BurnRights 10-->MsiExec.exe /X{943CFD7D-5336-47AF-9418-E02473A5A517}
Nero Control Center 10-->MsiExec.exe /X{6DFB899F-17A2-48F0-A533-ED8D6866CF38}
Nero ControlCenter 10 Help (CHM)-->MsiExec.exe /X{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}
Nero Core Components 10-->MsiExec.exe /X{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}
Nero CoverDesigner 10 Help (CHM)-->MsiExec.exe /X{C3273C55-E1E4-41FF-8D69-0158090DB8D8}
Nero DiscSpeed 10 Help (CHM)-->MsiExec.exe /X{C18A0418-442A-4186-AF98-D08F5054A2FC}
Nero Dolby Files 10-->MsiExec.exe /X{C3580AC4-C827-4332-B935-9A282ED5BB97}
Nero Express 10 Help (CHM)-->MsiExec.exe /X{33643918-7957-4839-92C7-EA96CB621A98}
Nero Express 10-->MsiExec.exe /X{70550193-1C22-445C-8FA4-564E155DB1A7}
Nero InfoTool 10 Help (CHM)-->MsiExec.exe /X{66049135-9659-4AAD-9169-9CCA269EBB3E}
Nero InfoTool 10-->MsiExec.exe /X{F412B4AF-388C-4FF5-9B2F-33DB1C536953}
Nero MediaHub 10 Help (CHM)-->MsiExec.exe /X{F467862A-D9CA-47ED-8D81-B4B3C9399272}
Nero Multimedia Suite 10-->MsiExec.exe /I{277C1559-4CF7-44FF-8D07-98AA9C13AABD}
Nero Recode 10 Help (CHM)-->MsiExec.exe /X{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}
Nero Recode 10-->MsiExec.exe /X{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}
Nero RescueAgent 10 Help (CHM)-->MsiExec.exe /X{92E25238-61A3-4ACD-A407-3C480EEF47A7}
Nero RescueAgent 10-->MsiExec.exe /X{E337E787-CF61-4B7B-B84F-509202A54023}
Nero SoundTrax 10 Help (CHM)-->MsiExec.exe /X{16987E99-C95C-4513-9239-7B44A0A71DB5}
Nero StartSmart 10 Help (CHM)-->MsiExec.exe /X{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}
Nero StartSmart 10-->MsiExec.exe /X{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}
Nero Update-->MsiExec.exe /X{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}
Nero Vision 10 Help (CHM)-->MsiExec.exe /X{329411A0-19F3-4740-874F-17400B126F27}
Nero WaveEditor 10 Help (CHM)-->MsiExec.exe /X{7A295D8F-484B-4FFB-89AB-C1FD497591FE}
NVIDIA Ovladač HD audia 1.1.9.0-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage HDAudio.Driver
NVIDIA Ovladače grafiky 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
NVIDIA Systémový software PhysX 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.PhysX
PDF Settings CS5-->MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
Picasa 3-->"C:\Program Files (x86)\Google\Picasa3\Uninstall.exe"
QuickTime-->MsiExec.exe /I{57752979-A1C9-4C02-856B-FBB27AC4E02C}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD8D7C9A-E56A-3E7B-BA6D-FE68F13296E3} /parameterfolder Client
SpeedFan (remove only)-->"C:\Program Files (x86)\SpeedFan\uninstall.exe"
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
The KMPlayer (remove only)-->"C:\Program Files (x86)\The KMPlayer\uninstall.exe"
The Sims™ 3 Cestovní horečka-->"C:\Program Files (x86)\InstallShield Installation Information\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}\Sims3EP01Setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3 Luxusní bydlení – Kolekce-->"C:\Program Files (x86)\InstallShield Installation Information\{71828142-5A24-4BD0-97E7-976DA08CE6CF}\Sims3SP01Setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3 Povolání snů-->"C:\Program Files (x86)\InstallShield Installation Information\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}\Sims3EP02Setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3-->"C:\Program Files (x86)\InstallShield Installation Information\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3 Po setmění-->"C:\Program Files (x86)\InstallShield Installation Information\{45057FCE-5784-48BE-8176-D9D00AF56C3C}\setup.exe" -runfromtemp -l0x0005 -removeonly
Ultima Online 2D-->C:\Windows\UOUninst.exe
VentriloMIX-->C:\Program Files\VentriloMIX\Uninstal.exe
WIDCOMM Bluetooth Software-->MsiExec.exe /X{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
WinRAR-->C:\Program Files (x86)\WinRAR\uninstall.exe

======System event log======

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Cryptographic Services byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714051424.262212-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Windows Modules Installer byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714051424.168612-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Software Protection byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714051424.059412-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Windows Event Log byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714051424.012612-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Volume Shadow Copy byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714051423.934612-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247E29-32
Event Code: 900
Message: Služba Ochrana softwaru se spouští.

Record Number: 5
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20101207101703.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20101207101504.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20101207101456.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 2
Source Name: Microsoft-Windows-EventSystem
Time Written: 20101207101446.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 1
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20101207101446.411400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

=====Security event log=====

Computer Name: 37L4247E29-32
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin

Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -

Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101351.109303-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin

Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -

Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101351.109303-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.

Počet prvků: 0
ID zásady: 0x32743
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101350.485301-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101347.536896-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101347.349696-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\WIDCOMM\Bluetooth Software\;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"CLASSPATH"=.;C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu HJT

#5 Příspěvek od vyosek »

Co budem delat s tim nelegalnim NOD32?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Re: Prosím o kontrolu HJT

#6 Příspěvek od Knotek »

no...

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu HJT

#7 Příspěvek od vyosek »

no co? hodlate si jej nechat? Dle pravidel fora (viz zde a a zde bod c.3 ) se vsak nelegalnim SW nezabyvame, jelikoz nelegalni programy jsou vetsinou zdrojem haveti. Navic tim porusujete i autorska prava Obrázek, pachate trestny cin a ten jako takovy nebude nasim forem podporovan. Uvedomte si, ze jste na bezpecnostnim foru - podpora warezu (zvlaste bezpecnostnich programu) by byla zcela proti logice fora :!:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Re: Prosím o kontrolu HJT

#8 Příspěvek od Knotek »

Půjde pryč -> pro kotrolu potom vypíšu znovu log RSITu :( jak jsem říkal pravidla mi nešly spustit :?:

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu HJT

#9 Příspěvek od vyosek »

Obstarejte si legalni ochranu Vaseho PC (antivir+firewall), pote sem vlozte novy log z RSITu a CKScanneru - viz nize.

Osobne Vam doporucuji Avast, Aviru nebo MSE. Prehled antiviru mate ZDE.

:arrow: Log z RSITu - viz muj podpis
:arrow: Stahnete na plochu CKScanner
  • Spustte a kliknete na Search for files
  • Po dokonceni skenu kliknete na Save List to File a nasledne OK
  • Na plose se Vam vytvori log s nazvem ckfiles.txt, jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Re: Prosím o kontrolu HJT

#10 Příspěvek od Knotek »

taaak CKscan

CKScanner - Additional Security Risks - These are not necessarily bad
c:\users\knteok\downloads\ascpro.plus.crack.tlf\asc-setup.exe
c:\users\knteok\downloads\ascpro.plus.crack.tlf\advanced.systemcare.pro.keygen.and.patch\keys.txt
c:\users\knteok\downloads\ascpro.plus.crack.tlf\advanced.systemcare.pro.keygen.and.patch\keygen\keygen.exe
scanner sequence 3.GL.11
----- EOF -----


RSIT info

info.txt logfile of random's system information tool 1.08 2011-02-19 15:03:17

======Uninstall list======

-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
7-Zip 4.65-->"C:\Program Files (x86)\7-Zip\Uninstall.exe"
Acer Crystal Eye Webcam 3.0.6.3-->C:\Program Files (x86)\InstallShield Installation Information\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}\setup.exe -runfromtemp -l0x0009 -removeonly
Acer Crystal Eye Webcam-->C:\Program Files (x86)\InstallShield Installation Information\{7760D94E-B1B5-40A0-9AA0-ABF942108755}\setup.exe -runfromtemp -l0x0009 -removeonly
Adobe AIR-->C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Community Help-->msiexec /qb /x {0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Community Help-->MsiExec.exe /I{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_Plugin.exe -maintain plugin
Adobe Media Player-->msiexec /qb /x {DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Media Player-->MsiExec.exe /I{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Photoshop CS5-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader 9.4.1 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Advanced SystemCare 3-->"C:\Program Files (x86)\IObit\Advanced SystemCare 3\unins000.exe"
Agere Systems HDA Modem-->agrsmdel
Apple Application Support-->MsiExec.exe /I{EE6097DD-05F4-4178-9719-D3170BF098E8}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver-->"C:\Program Files (x86)\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe" -runfromtemp -l0x0009 -removeonly
ConsumerUpdate-->MsiExec.exe /I{7C6999B2-1A35-4F2C-8DB7-3CB46B640CC9}
Counter-Strike-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/10
EA Download Manager-->C:\Program Files (x86)\Electronic Arts\EADM\EADMUI\EADMUninstall.exe
ESET Antivirus License Finder (MiNODLogin)-->"C:\Program Files (x86)\ESET\MiNODLogin\MiNODLoginUninst.exe"
Guitar Pro 5.2-->"C:\Program Files (x86)\Guitar Pro 5\unins000.exe"
High-Definition Video Playback 10-->MsiExec.exe /X{237CCB62-8454-43E3-B158-3ACD0134852E}
HijackThis 2.0.2-->"C:\Users\Knteok\Downloads\HijackThis.exe" /uninstall
ICQ Toolbar-->C:\Program Files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
ICQ7.2-->"C:\Program Files (x86)\InstallShield Installation Information\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
Intel® Matrix Storage Manager-->C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
ITECIR-->C:\Program Files (x86)\InstallShield Installation Information\{40580068-9B10-40B5-9548-536CE88AB23C}\setup.exe -runfromtemp -l0x0005 -removeonly
Java(TM) 6 Update 22-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216022FF}
JDownloader-->C:\Program Files (x86)\JDownloader\uninstall.exe
JMicron JMB38X Flash Media Controller-->"C:\Program Files (x86)\InstallShield Installation Information\{26604C7E-A313-4D12-867F-7C6E7820BE4C}\setup.exe" delpkg
Kolekce The Sims™ 3 Na plný plyn-->"C:\Program Files (x86)\InstallShield Installation Information\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}\Sims3SP02Setup.exe" -runfromtemp -l0x0005 -removeonly
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office Office 64-bit Components 2007-->MsiExec.exe /X{90120000-002A-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared 64-bit MUI (Czech) 2007-->MsiExec.exe /X{90120000-002A-0405-1000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Primary Interoperability Assemblies 2005-->MsiExec.exe /X{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft WSE 3.0 Runtime-->MsiExec.exe /X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}
Microsoft_VC80_ATL_x86_x64-->MsiExec.exe /I{925D058B-564A-443A-B4B2-7E90C6432E55}
Microsoft_VC80_ATL_x86-->MsiExec.exe /I{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}
Microsoft_VC80_CRT_x86_x64-->MsiExec.exe /I{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86_x64-->MsiExec.exe /I{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86_x64-->MsiExec.exe /I{1E9FC118-651D-4934-97BE-E53CAE5C7D45}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86_x64-->MsiExec.exe /I{8557397C-A42D-486F-97B3-A2CBC2372593}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86_x64-->MsiExec.exe /I{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86_x64-->MsiExec.exe /I{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Mozilla Firefox (3.6.13)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nero 10 Menu TemplatePack Basic-->MsiExec.exe /X{63AA3EAB-23BB-48B2-9AD0-44F878075604}
Nero 10 Movie ThemePack Basic-->MsiExec.exe /X{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}
Nero BackItUp 10 Help (CHM)-->MsiExec.exe /X{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}
Nero Burning ROM 10-->MsiExec.exe /X{7A5D731D-B4B3-490E-B339-75685712BAAB}
Nero BurningROM 10 Help (CHM)-->MsiExec.exe /X{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}
Nero BurnRights 10 Help (CHM)-->MsiExec.exe /X{555868C6-49FB-484F-BB43-8980651A1B00}
Nero BurnRights 10-->MsiExec.exe /X{943CFD7D-5336-47AF-9418-E02473A5A517}
Nero Control Center 10-->MsiExec.exe /X{6DFB899F-17A2-48F0-A533-ED8D6866CF38}
Nero ControlCenter 10 Help (CHM)-->MsiExec.exe /X{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}
Nero Core Components 10-->MsiExec.exe /X{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}
Nero CoverDesigner 10 Help (CHM)-->MsiExec.exe /X{C3273C55-E1E4-41FF-8D69-0158090DB8D8}
Nero DiscSpeed 10 Help (CHM)-->MsiExec.exe /X{C18A0418-442A-4186-AF98-D08F5054A2FC}
Nero Dolby Files 10-->MsiExec.exe /X{C3580AC4-C827-4332-B935-9A282ED5BB97}
Nero Express 10 Help (CHM)-->MsiExec.exe /X{33643918-7957-4839-92C7-EA96CB621A98}
Nero Express 10-->MsiExec.exe /X{70550193-1C22-445C-8FA4-564E155DB1A7}
Nero InfoTool 10 Help (CHM)-->MsiExec.exe /X{66049135-9659-4AAD-9169-9CCA269EBB3E}
Nero InfoTool 10-->MsiExec.exe /X{F412B4AF-388C-4FF5-9B2F-33DB1C536953}
Nero MediaHub 10 Help (CHM)-->MsiExec.exe /X{F467862A-D9CA-47ED-8D81-B4B3C9399272}
Nero Multimedia Suite 10-->MsiExec.exe /I{277C1559-4CF7-44FF-8D07-98AA9C13AABD}
Nero Recode 10 Help (CHM)-->MsiExec.exe /X{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}
Nero Recode 10-->MsiExec.exe /X{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}
Nero RescueAgent 10 Help (CHM)-->MsiExec.exe /X{92E25238-61A3-4ACD-A407-3C480EEF47A7}
Nero RescueAgent 10-->MsiExec.exe /X{E337E787-CF61-4B7B-B84F-509202A54023}
Nero SoundTrax 10 Help (CHM)-->MsiExec.exe /X{16987E99-C95C-4513-9239-7B44A0A71DB5}
Nero StartSmart 10 Help (CHM)-->MsiExec.exe /X{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}
Nero StartSmart 10-->MsiExec.exe /X{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}
Nero Update-->MsiExec.exe /X{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}
Nero Vision 10 Help (CHM)-->MsiExec.exe /X{329411A0-19F3-4740-874F-17400B126F27}
Nero WaveEditor 10 Help (CHM)-->MsiExec.exe /X{7A295D8F-484B-4FFB-89AB-C1FD497591FE}
NVIDIA Ovladač HD audia 1.1.9.0-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage HDAudio.Driver
NVIDIA Ovladače grafiky 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
NVIDIA Systémový software PhysX 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.PhysX
PDF Settings CS5-->MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
Picasa 3-->"C:\Program Files (x86)\Google\Picasa3\Uninstall.exe"
QuickTime-->MsiExec.exe /I{57752979-A1C9-4C02-856B-FBB27AC4E02C}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD8D7C9A-E56A-3E7B-BA6D-FE68F13296E3} /parameterfolder Client
SpeedFan (remove only)-->"C:\Program Files (x86)\SpeedFan\uninstall.exe"
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
The KMPlayer (remove only)-->"C:\Program Files (x86)\The KMPlayer\uninstall.exe"
The Sims™ 3 Cestovní horečka-->"C:\Program Files (x86)\InstallShield Installation Information\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}\Sims3EP01Setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3 Luxusní bydlení – Kolekce-->"C:\Program Files (x86)\InstallShield Installation Information\{71828142-5A24-4BD0-97E7-976DA08CE6CF}\Sims3SP01Setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3 Povolání snů-->"C:\Program Files (x86)\InstallShield Installation Information\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}\Sims3EP02Setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3-->"C:\Program Files (x86)\InstallShield Installation Information\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3 Po setmění-->"C:\Program Files (x86)\InstallShield Installation Information\{45057FCE-5784-48BE-8176-D9D00AF56C3C}\setup.exe" -runfromtemp -l0x0005 -removeonly
Ultima Online 2D-->C:\Windows\UOUninst.exe
VentriloMIX-->C:\Program Files\VentriloMIX\Uninstal.exe
WIDCOMM Bluetooth Software-->MsiExec.exe /X{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
WinRAR-->C:\Program Files (x86)\WinRAR\uninstall.exe

======System event log======

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Cryptographic Services byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714051424.262212-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Windows Modules Installer byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714051424.168612-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Software Protection byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714051424.059412-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Windows Event Log byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714051424.012612-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Volume Shadow Copy byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714051423.934612-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247E29-32
Event Code: 900
Message: Služba Ochrana softwaru se spouští.

Record Number: 5
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20101207101703.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20101207101504.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20101207101456.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 2
Source Name: Microsoft-Windows-EventSystem
Time Written: 20101207101446.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 1
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20101207101446.411400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

=====Security event log=====

Computer Name: 37L4247E29-32
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin

Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -

Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101351.109303-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin

Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -

Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101351.109303-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.

Počet prvků: 0
ID zásady: 0x32743
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101350.485301-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101347.536896-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101207101347.349696-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\WIDCOMM\Bluetooth Software\;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"CLASSPATH"=.;C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------

Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Re: Prosím o kontrolu HJT

#11 Příspěvek od Knotek »

RSIT log

Logfile of random's system information tool 1.08 (written by random/random)
Run by Knteok at 2011-02-20 13:08:13
Microsoft Windows 7 Ultimate
System drive C: has 61 GB (38%) free of 161 GB
Total RAM: 4093 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:08:16, on 20.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\ICQ7.2\ICQ.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Java\jre6\bin\javaw.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Knteok.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10352 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\SysWOW64\ZoneLabs\vsmon.exe -service
"C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe"
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agr64svc.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000007cc
\??\C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"taskhost.exe"
"C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
taskeng.exe {FB2EAB60-90DE-4757-916C-E1756E493764}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe"
"C:\Windows\PLFSetI.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\ICQ7.2\ICQ.exe" silent loginmode=4
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
ctfmon.exe
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Java\jre6\bin\javaw.exe" -Xmx512m -jar "C:\Program Files (x86)\JDownloader\JDownloader.jar"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Knteok\Desktop\kotrola\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\AWC AutoSweep.job
C:\Windows\tasks\AWC Startup.job
C:\Windows\tasks\AWC Update.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Security Engine Registrar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2010-11-05 903672]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-23 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Security Engine Registrar - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll [2010-11-05 599544]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
ZoneAlarm Security Toolbar - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll [2010-12-01 2735200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-12-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2010-11-05 903672]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-07 1048888]
{91da5e8a-3318-4f8c-b67e-5964de3ab546} - ZoneAlarm Security Toolbar - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll [2010-12-01 2735200]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll [2010-11-05 599544]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-05 186904]
"PLFSetI"=C:\Windows\PLFSetI.exe [2009-11-21 200704]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-01-18 11775592]
"ISW"=C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [2010-11-05 1123320]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ICQ"=C:\Program Files (x86)\ICQ7.2\ICQ.exe [2011-01-05 133432]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2011-02-18 1242448]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"ZoneAlarm Client"=C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe [2010-11-16 1043968]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2011-01-10 281768]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-02-20 11:12:26 ----D---- C:\Users\Knteok\AppData\Roaming\CheckPoint
2011-02-20 11:11:42 ----D---- C:\Program Files (x86)\Conduit
2011-02-20 11:11:39 ----D---- C:\Program Files (x86)\ZoneAlarm_Security
2011-02-20 11:11:34 ----A---- C:\Windows\system32\drivers\avipbb.sys
2011-02-20 11:11:34 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2011-02-20 11:11:33 ----D---- C:\ProgramData\Avira
2011-02-20 11:11:33 ----D---- C:\Program Files (x86)\Avira
2011-02-20 11:11:23 ----D---- C:\Program Files\CheckPoint
2011-02-20 11:11:04 ----A---- C:\Windows\SYSWOW64\vsregexp.dll
2011-02-20 11:10:32 ----A---- C:\Windows\system32\drivers\netio.sys
2011-02-20 11:09:25 ----A---- C:\Windows\SYSWOW64\zlcommdb.dll
2011-02-20 11:09:25 ----A---- C:\Windows\SYSWOW64\zlcomm.dll
2011-02-20 11:09:17 ----A---- C:\Windows\SYSWOW64\vswmi.dll
2011-02-20 11:09:13 ----A---- C:\Windows\SYSWOW64\zpeng25.dll
2011-02-20 11:09:12 ----A---- C:\Windows\SYSWOW64\vsxml.dll
2011-02-20 11:09:10 ----D---- C:\Windows\SYSWOW64\ZoneLabs
2011-02-20 11:09:10 ----A---- C:\Windows\SYSWOW64\vspubapi.dll
2011-02-20 11:09:10 ----A---- C:\Windows\SYSWOW64\vsmonapi.dll
2011-02-20 11:09:08 ----A---- C:\Windows\system32\drivers\~GLH0023.TMP
2011-02-20 11:09:07 ----A---- C:\Windows\SYSWOW64\vsdata.dll
2011-02-20 11:08:58 ----N---- C:\Windows\system32\drivers\vsdatant.sys
2011-02-20 11:08:56 ----D---- C:\Program Files (x86)\Zone Labs
2011-02-20 11:08:17 ----D---- C:\ProgramData\CheckPoint
2011-02-20 11:08:15 ----D---- C:\Windows\Internet Logs
2011-02-20 11:08:14 ----A---- C:\Windows\SYSWOW64\vsutil.dll
2011-02-20 11:08:14 ----A---- C:\Windows\SYSWOW64\vsinit.dll
2011-02-19 15:03:11 ----D---- C:\rsit
2011-02-19 15:03:11 ----D---- C:\Program Files\trend micro
2011-02-19 13:28:11 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-02-19 13:28:11 ----A---- C:\Windows\system32\tzres.dll
2011-02-19 13:06:57 ----D---- C:\Users\Knteok\AppData\Roaming\NVIDIA
2011-02-19 13:01:12 ----D---- C:\Program Files (x86)\SpeedFan
2011-02-19 00:07:17 ----D---- C:\Windows\SYSWOW64\RTCOM
2011-02-19 00:07:17 ----D---- C:\Program Files\Realtek
2011-02-19 00:06:40 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-02-19 00:06:39 ----A---- C:\Windows\system32\SRSWOW64.dll
2011-02-19 00:06:39 ----A---- C:\Windows\system32\SRSTSX64.dll
2011-02-19 00:06:39 ----A---- C:\Windows\system32\SRSTSH64.dll
2011-02-19 00:06:38 ----A---- C:\Windows\system32\SRSHP64.dll
2011-02-19 00:06:37 ----A---- C:\Windows\system32\SFSS_APO.dll
2011-02-19 00:06:37 ----A---- C:\Windows\system32\SFNHK64.dll
2011-02-19 00:06:36 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2011-02-19 00:06:36 ----A---- C:\Windows\system32\SFCOM64.dll
2011-02-19 00:06:36 ----A---- C:\Windows\system32\SFAPO64.dll
2011-02-19 00:06:36 ----A---- C:\Windows\system32\RtPgEx64.dll
2011-02-19 00:06:36 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RtkCfg64.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RtkAPO64.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RtkApi64.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RTEEP64A.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RTEEL64A.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RTEEG64A.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\RTEED64A.dll
2011-02-19 00:06:35 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2011-02-19 00:06:34 ----A---- C:\Windows\system32\RTCOM64.dll
2011-02-19 00:06:34 ----A---- C:\Windows\system32\RP3DHT64.dll
2011-02-19 00:06:34 ----A---- C:\Windows\system32\RP3DAA64.dll
2011-02-19 00:06:34 ----A---- C:\Windows\system32\RCoInst64.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EEP64A.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EEL64A.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EEG64A.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EED64A.dll
2011-02-19 00:06:33 ----A---- C:\Windows\system32\R4EEA64A.dll
2011-02-19 00:06:30 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2011-02-19 00:06:29 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2011-02-19 00:06:29 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-02-19 00:06:27 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2011-02-19 00:06:27 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-02-19 00:05:57 ----A---- C:\Windows\system32\FMAPO64.dll
2011-02-19 00:05:57 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2011-02-19 00:05:57 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2011-02-19 00:05:56 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2011-02-19 00:05:56 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2011-02-19 00:05:55 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2011-02-19 00:05:55 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2011-02-19 00:05:55 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2011-02-19 00:05:54 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2011-02-19 00:05:54 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2011-02-19 00:05:54 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2011-02-19 00:05:53 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2011-02-19 00:05:53 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2011-02-19 00:05:50 ----A---- C:\Windows\system32\AERTAR64.dll
2011-02-19 00:05:50 ----A---- C:\Windows\system32\AERTAC64.dll
2011-02-19 00:00:15 ----D---- C:\Program Files (x86)\Realtek
2011-02-18 23:51:19 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-02-18 23:50:38 ----N---- C:\Windows\system32\MpSigStub.exe
2011-02-18 23:49:23 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-02-18 23:49:23 ----A---- C:\Windows\system32\webio.dll
2011-02-18 23:49:22 ----A---- C:\Windows\system32\ieframe.dll
2011-02-18 23:49:19 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-02-18 23:49:19 ----A---- C:\Windows\system32\upnp.dll
2011-02-18 23:49:19 ----A---- C:\Windows\system32\msxml6.dll
2011-02-18 23:49:19 ----A---- C:\Windows\system32\msxml3.dll
2011-02-18 23:49:18 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-02-18 23:49:18 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-02-18 23:49:18 ----A---- C:\Windows\system32\urlmon.dll
2011-02-18 23:49:17 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-02-18 23:49:17 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-02-18 23:49:17 ----A---- C:\Windows\system32\wininet.dll
2011-02-18 23:49:17 ----A---- C:\Windows\system32\winhttp.dll
2011-02-18 23:49:16 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-02-18 23:49:16 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-02-18 23:49:16 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-02-18 23:49:16 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-02-18 23:49:16 ----A---- C:\Windows\system32\wscapi.dll
2011-02-18 23:49:16 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-18 23:49:16 ----A---- C:\Windows\system32\davclnt.dll
2011-02-18 23:49:15 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-02-18 23:49:15 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-02-18 23:49:15 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-02-18 23:49:15 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-02-18 23:49:15 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-18 23:49:15 ----A---- C:\Windows\system32\slwga.dll
2011-02-18 23:49:15 ----A---- C:\Windows\system32\jsproxy.dll
2011-02-18 23:49:15 ----A---- C:\Windows\system32\ieui.dll
2011-02-18 23:49:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-18 23:49:13 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-02-18 23:49:13 ----A---- C:\Windows\system32\ntdll.dll
2011-02-18 23:49:12 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-02-18 23:49:11 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-02-18 23:49:10 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-02-18 23:49:10 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-02-18 23:49:10 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-02-18 23:49:10 ----A---- C:\Windows\system32\taskschd.dll
2011-02-18 23:49:10 ----A---- C:\Windows\system32\taskeng.exe
2011-02-18 23:49:10 ----A---- C:\Windows\system32\taskcomp.dll
2011-02-18 23:49:10 ----A---- C:\Windows\system32\schtasks.exe
2011-02-18 23:49:10 ----A---- C:\Windows\system32\schedsvc.dll
2011-02-18 23:49:09 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-02-18 23:49:09 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-02-18 23:49:04 ----A---- C:\Windows\system32\kerberos.dll
2011-02-18 23:49:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-02-18 23:48:57 ----A---- C:\Windows\system32\mshtml.dll
2011-02-18 23:48:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-02-18 23:48:48 ----A---- C:\Windows\system32\iertutil.dll
2011-02-18 23:48:47 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-02-18 23:48:47 ----A---- C:\Windows\system32\mstime.dll
2011-02-18 23:48:46 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-02-18 23:48:46 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-02-18 23:48:45 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-02-18 23:48:45 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-02-18 23:48:45 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-02-18 23:48:45 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-02-18 23:48:45 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-18 23:48:45 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-18 23:48:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-02-18 23:48:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-02-18 23:48:44 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-18 23:48:44 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-18 23:48:44 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-18 23:48:44 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-18 23:48:44 ----A---- C:\Windows\system32\iepeers.dll
2011-02-18 23:48:36 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-02-18 23:48:36 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-02-18 23:48:36 ----A---- C:\Windows\system32\d3d10warp.dll
2011-02-18 23:48:35 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-02-18 23:48:34 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-02-18 23:48:34 ----A---- C:\Windows\system32\d2d1.dll
2011-02-18 23:48:33 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-02-18 23:48:33 ----A---- C:\Windows\system32\mf.dll
2011-02-18 23:48:33 ----A---- C:\Windows\system32\DWrite.dll
2011-02-18 23:48:32 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-02-18 23:48:32 ----A---- C:\Windows\system32\XpsPrint.dll
2011-02-18 23:48:32 ----A---- C:\Windows\system32\FntCache.dll
2011-02-18 23:48:31 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-02-18 23:48:31 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-02-18 23:48:31 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-02-18 23:48:30 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-02-18 23:48:30 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-18 23:48:30 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-02-18 23:48:29 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-02-18 23:48:29 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-02-18 23:48:29 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-02-18 23:48:29 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-02-18 23:48:29 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-02-18 23:48:29 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-02-18 23:48:29 ----A---- C:\Windows\system32\mfps.dll
2011-02-18 23:48:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-18 23:48:29 ----A---- C:\Windows\system32\d3d10_1.dll
2011-02-18 23:48:28 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-02-18 23:48:28 ----A---- C:\Windows\system32\cdd.dll
2011-02-18 23:48:11 ----A---- C:\Windows\system32\win32k.sys
2011-02-18 23:48:10 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-02-18 23:48:10 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-02-18 23:48:10 ----A---- C:\Windows\system32\vbscript.dll
2011-02-18 23:48:10 ----A---- C:\Windows\system32\jscript.dll
2011-02-18 23:48:08 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-02-18 23:48:08 ----A---- C:\Windows\system32\winsrv.dll
2011-02-18 23:48:08 ----A---- C:\Windows\system32\atmfd.dll
2011-02-18 23:48:07 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-02-18 23:48:07 ----A---- C:\Windows\system32\atmlib.dll
2011-02-18 23:47:59 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-02-18 23:47:59 ----A---- C:\Windows\system32\odbc32.dll
2011-02-18 23:47:57 ----A---- C:\Windows\system32\consent.exe
2011-02-18 23:39:14 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-02-18 23:37:53 ----D---- C:\ProgramData\NVIDIA Corporation
2011-02-18 23:33:22 ----A---- C:\Windows\system32\nvhdap64.dll
2011-02-18 23:33:22 ----A---- C:\Windows\system32\nvgenco64.dll
2011-02-18 23:33:22 ----A---- C:\Windows\system32\nvapo64v.dll
2011-02-18 23:33:22 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvdecodemft.dll
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-02-18 23:33:21 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvoglv64.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvgenco642030.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvdispco642050.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvdecodemft.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-02-18 23:33:21 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-02-18 23:33:20 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\OpenCL.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvcuvid.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvcuda.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvcompiler.dll
2011-02-18 23:33:20 ----A---- C:\Windows\system32\nvapi64.dll
2011-02-18 23:31:49 ----D---- C:\Program Files\NVIDIA Corporation
2011-02-18 23:12:59 ----D---- C:\ProgramData\IObit
2011-02-18 22:59:47 ----D---- C:\Users\Knteok\AppData\Roaming\IObit
2011-02-18 22:59:46 ----D---- C:\Program Files (x86)\IObit
2011-02-18 21:48:40 ----D---- C:\Users\Knteok\AppData\Roaming\Ventrilo
2011-02-18 21:03:47 ----D---- C:\Program Files\VentriloMIX
2011-02-18 20:59:55 ----D---- C:\Program Files\TeamSpeak 3 Client
2011-02-18 20:57:19 ----D---- C:\Program Files (x86)\Steam
2011-02-09 21:15:24 ----D---- C:\Program Files (x86)\Convar
2011-02-09 15:02:19 ----A---- C:\Windows\ipuninst.exe
2011-02-09 12:46:20 ----A---- C:\Windows\IsUninst.exe
2011-02-04 12:12:18 ----D---- C:\Users\Knteok\AppData\Roaming\NeroDigital(TM)
2011-02-01 12:51:02 ----D---- C:\Users\Knteok\AppData\Roaming\Nero
2011-02-01 12:41:57 ----D---- C:\ProgramData\Nero
2011-02-01 12:41:09 ----D---- C:\Program Files (x86)\Nero
2011-01-28 11:24:11 ----D---- C:\Program Files (x86)\The KMPlayer
2011-01-25 14:59:13 ----D---- C:\Program Files (x86)\JDownloader
2011-01-24 23:16:52 ----D---- C:\Users\Knteok\AppData\Roaming\Apple Computer
2011-01-24 00:41:03 ----D---- C:\Windows\Sun

======List of files/folders modified in the last 1 months======

2011-02-20 13:03:48 ----D---- C:\Windows\Temp
2011-02-20 13:01:42 ----D---- C:\Windows\winsxs
2011-02-20 13:01:33 ----D---- C:\Windows\SYSWOW64\en-US
2011-02-20 13:01:33 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-02-20 13:01:33 ----D---- C:\Windows\SysWOW64
2011-02-20 13:01:33 ----D---- C:\Windows\system32\en-US
2011-02-20 13:01:33 ----D---- C:\Windows\system32\cs-CZ
2011-02-20 13:01:33 ----D---- C:\Windows\System32
2011-02-20 13:01:06 ----SHD---- C:\System Volume Information
2011-02-20 12:58:50 ----D---- C:\Users\Knteok\AppData\Roaming\ICQ
2011-02-20 12:55:37 ----D---- C:\Windows\system32\config
2011-02-20 12:54:31 ----D---- C:\Windows\system32\drivers
2011-02-20 11:11:45 ----D---- C:\Windows\system32\catroot
2011-02-20 11:11:42 ----RD---- C:\Program Files (x86)
2011-02-20 11:11:33 ----HD---- C:\ProgramData
2011-02-20 11:11:23 ----RD---- C:\Program Files
2011-02-20 11:10:55 ----D---- C:\Windows
2011-02-20 11:09:28 ----D---- C:\Windows\SoftwareDistribution
2011-02-20 11:09:07 ----D---- C:\Windows\SYSWOW64\drivers
2011-02-20 11:09:05 ----D---- C:\Windows\inf
2011-02-20 11:09:01 ----D---- C:\Windows\system32\DriverStore
2011-02-20 11:01:50 ----SHD---- C:\Windows\Installer
2011-02-20 11:00:24 ----D---- C:\Program Files (x86)\ESET
2011-02-19 15:07:16 ----D---- C:\Windows\system32\NDF
2011-02-19 14:46:29 ----D---- C:\Windows\system32\Tasks
2011-02-19 13:44:34 ----D---- C:\Program Files\Internet Explorer
2011-02-19 13:44:34 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-19 13:27:34 ----D---- C:\Windows\system32\catroot2
2011-02-19 13:01:12 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-19 12:53:17 ----D---- C:\Windows\Tasks
2011-02-19 12:45:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-19 00:07:43 ----HD---- C:\Program Files (x86)\Temp
2011-02-19 00:05:42 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-02-19 00:02:39 ----D---- C:\Windows\SYSWOW64\migration
2011-02-19 00:02:38 ----D---- C:\Windows\system32\migration
2011-02-19 00:02:38 ----D---- C:\Program Files\Windows Mail
2011-02-19 00:02:38 ----D---- C:\Program Files (x86)\Windows Mail
2011-02-18 23:40:44 ----D---- C:\ProgramData\NVIDIA
2011-02-18 23:38:45 ----D---- C:\Windows\Help
2011-02-18 22:59:23 ----D---- C:\Windows\Prefetch
2011-02-18 21:49:28 ----SD---- C:\Users\Knteok\AppData\Roaming\Microsoft
2011-02-18 20:57:20 ----D---- C:\Program Files (x86)\Common Files
2011-02-04 17:51:18 ----A---- C:\Windows\system32\MRT.exe
2011-02-01 12:26:27 ----RSD---- C:\Windows\assembly
2011-01-24 13:29:00 ----A---- C:\Windows\RtlExUpd.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 408600]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2007-02-07 14104]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-12-08 834544]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-01-10 116568]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2010-05-15 458840]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-01-10 83120]
R2 ISWKL;ZoneAlarm Toolbar ISWKL; \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [2010-11-05 33528]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2008-02-29 1252352]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-01-25 2727912]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2010-07-13 69736]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x64.sys [2009-08-23 56320]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2010-07-14 7821312]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-09-07 155752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 ajp5i3ol;ajp5i3ol; C:\Windows\system32\drivers\ajp5i3ol.sys []
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-12-08 98344]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-12-08 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-12-08 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-12-08 21160]
S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-16 6952960]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\Windows\system32\DRIVERS\s116bus.sys [2007-04-03 108296]
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s116mdfl.sys [2007-04-03 19720]
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s116mdm.sys [2007-04-03 144648]
S3 s116mgmt;Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s116mgmt.sys [2007-04-03 126216]
S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS); C:\Windows\system32\DRIVERS\s116nd5.sys [2007-04-03 31496]
S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s116obex.sys [2007-04-03 123656]
S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM); C:\Windows\system32\DRIVERS\s116unic.sys [2007-04-03 130824]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agr64svc.exe [2007-12-11 15872]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-01-10 267944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-01-10 135336]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-18 864032]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-07 247096]
R2 IswSvc;ZoneAlarm Toolbar IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [2010-11-05 822264]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-01-26 573224]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 989800]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\SysWOW64\ZoneLabs\vsmon.exe [2010-11-16 2435592]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-27 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2009-07-16 316664]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu HJT

#12 Příspěvek od vyosek »

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "AdobeAAMUpdater-1.0"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
    "{855F3B16-6D32-4FE6-8A56-BBB695989046}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    "ICQ"=-
    "Steam"=-
    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "SwitchBoard"=-
    "AdobeCS5ServiceManager"=-
    
    :services
    ICQ Service
    
    :files
    c:\users\knteok\downloads\ascpro.plus.crack.tlf /d
    C:\Windows\tasks\AWC AutoSweep.job
    C:\Windows\tasks\AWC Startup.job
    C:\Windows\tasks\AWC Update.job
    C:\Program Files (x86)\ESET
    C:\Program Files (x86)\ICQ6Toolbar
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp /s
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Re: Prosím o kontrolu HJT

#13 Příspěvek od Knotek »

provedl jsem přesně postup který jste řekl ale ani pomocí vyhledávače nemohu najít "MovedFiles" ani složku "OTM" tudíž nemůžu postnout log. Nějaká rada ? Opakovat postup ?

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu HJT

#14 Příspěvek od vyosek »

Opakujte postup ale v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Knotek
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 19 Ún 2011 15:00

Re: Prosím o kontrolu HJT

#15 Příspěvek od Knotek »

log OTM

All processes killed
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4FE6-8A56-BBB695989046} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ICQ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Steam not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS5ServiceManager not found.
========== SERVICES/DRIVERS ==========
Error: No service named ICQ Service was found to stop!
Service\Driver key ICQ Service not found.
========== FILES ==========
File/Folder c:\users\knteok\downloads\ascpro.plus.crack.tlf not found.
File/Folder C:\Windows\tasks\AWC AutoSweep.job not found.
File/Folder C:\Windows\tasks\AWC Startup.job not found.
File/Folder C:\Windows\tasks\AWC Update.job not found.
File/Folder C:\Program Files (x86)\ESET not found.
File/Folder C:\Program Files (x86)\ICQ6Toolbar not found.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 359241 bytes
->Temporary Internet Files folder emptied: 5628162 bytes
->Flash cache emptied: 41620 bytes

User: Knteok
->Temp folder emptied: 10224850 bytes
->Temporary Internet Files folder emptied: 1917876 bytes
->Java cache emptied: 1940954 bytes
->FireFox cache emptied: 73676428 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 14408 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2059514 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67563 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 92.00 mb


OTM by OldTimer - Version 3.1.17.2 log created on 02202011_215714

Files moved on Reboot...
C:\Users\Knteok\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Odpovědět