Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

MBR (bootkit remover)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
petr0266
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 06 lis 2010 13:22

MBR (bootkit remover)

#1 Příspěvek od petr0266 »

Dobrý den,

Chci se zeptat, proč mi po každé nové instalaci WIN XP SP3 ukazuje bootkit remover unknown boot code?

Bootkit Remover
(c) 2009 eSage Lab
www.esagelab.com

Program version: 1.2.0.0
OS Version: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)

System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`00007e00
Boot sector MD5 is: ee7fe9f24bc949ea3a78cf7064fbe50b

Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Unknown boot code

Unknown boot code has been found on some of your physical disks.
To inspect the boot code manually, dump the master boot sector:
remover.exe dump <device_name> [output_file]
To disinfect the master boot sector, use the following command:
remover.exe fix <device_name>


Done;
Press any key to quit...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: MBR (bootkit remover)

#2 Příspěvek od Rudy »

Je to proto, že patrně nebyl odstraněn rootkit v MBR. Dejte nejprve log z RSIT: http://www.viry.cz/forum/viewtopic.php?f=13&t=105895 , máte-li systém nainstalován.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

petr0266
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 06 lis 2010 13:22

Re: MBR (bootkit remover)

#3 Příspěvek od petr0266 »

mbr disinfect pres bootkit removera jsem dával nespočekrát, ale jakmile udělám formát a novy install OS, nainstaluju ovladače + nějakéí základní programy, tak je to v :boxed: . Pres program mbr.exe s traceroutem, mám vše v pořádku, před pár dny jste mi kontroloval logy a říkal jste, že MBR je čisté a po formátu se nemusím ničeho bát. :)

Logfile of random's system information tool 1.08 (written by random/random)
Run by Lukáš at 2011-03-31 19:39:59
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 139 GB (91%) free of 153 GB
Total RAM: 2046 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:40:07, on 31.3.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\A4Tech\Mouse\Amoumain.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Lukáš\Dokumenty\Stažené soubory\RSIT.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\trend micro\Lukáš.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - c:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 1419667890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 1419732203
O17 - HKLM\System\CCS\Services\Tcpip\..\{EF757F15-66E1-4325-97FB-0FD008B2BA7A}: NameServer = 192.168.10.1
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 6409 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - c:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-30 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2010-04-16 1067872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-03-30 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2010-04-16 1067872]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2011-02-17 20029032]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-01-26 98304]
"ATICustomerCare"=C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [2010-05-04 311296]
"WheelMouse"=C:\Program Files\A4Tech\Mouse\Amoumain.exe [2007-05-15 204800]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-15 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.3.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2011-01-27 188416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 1 months======

2011-03-31 19:39:59 ----D---- C:\rsit
2011-03-31 19:39:59 ----D---- C:\Program Files\trend micro
2011-03-31 13:21:36 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\OpenOffice.org
2011-03-30 19:42:35 ----D---- C:\Program Files\Microsoft SQL Server
2011-03-30 19:42:19 ----D---- C:\Program Files\Microsoft Synchronization Services
2011-03-30 19:40:30 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2011-03-30 19:40:30 ----D---- C:\Program Files\Microsoft SDKs
2011-03-30 19:40:30 ----D---- C:\Program Files\Microsoft Help Viewer
2011-03-30 19:36:17 ----HDC---- C:\WINDOWS\$NtUninstallKB958655-v2$
2011-03-30 19:35:38 ----HDC---- C:\WINDOWS\$NtUninstallKB942288-v3$
2011-03-30 18:19:02 ----D---- C:\TP
2011-03-30 14:14:10 ----D---- C:\Program Files\IrfanView
2011-03-30 14:09:20 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\WinRAR
2011-03-30 14:09:00 ----D---- C:\Program Files\WinRAR
2011-03-30 14:07:36 ----D---- C:\Program Files\OpenOffice.org 3
2011-03-30 13:58:51 ----D---- C:\Program Files\Common Files\Adobe
2011-03-30 13:58:02 ----D---- C:\WINDOWS\system32\Adobe
2011-03-30 13:57:39 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-03-30 13:57:36 ----D---- C:\Program Files\Adobe
2011-03-30 13:57:35 ----D---- C:\Program Files\Common Files\Adobe AIR
2011-03-30 13:57:32 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Macromedia
2011-03-30 13:57:32 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Adobe
2011-03-30 13:57:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2011-03-30 13:57:24 ----D---- C:\Program Files\Common Files\Java
2011-03-30 13:56:50 ----A---- C:\WINDOWS\system32\javaws.exe
2011-03-30 13:56:50 ----A---- C:\WINDOWS\system32\javaw.exe
2011-03-30 13:56:50 ----A---- C:\WINDOWS\system32\java.exe
2011-03-30 13:56:50 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-03-30 13:56:37 ----D---- C:\Program Files\Java
2011-03-30 13:54:57 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Sun
2011-03-30 13:51:35 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla
2011-03-30 13:51:31 ----D---- C:\Program Files\Mozilla Firefox
2011-03-30 13:48:08 ----D---- C:\Program Files\CCleaner
2011-03-30 13:43:32 ----D---- C:\Program Files\A4Tech
2011-03-30 13:41:20 ----HD---- C:\WINDOWS\PIF
2011-03-30 13:40:31 ----A---- C:\WINDOWS\system32\drivers\AtihdXP3.sys
2011-03-30 13:38:49 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\ATI
2011-03-30 13:38:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\ATI
2011-03-30 13:37:30 ----D---- C:\Program Files\ATI Stream
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ativvamv.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atitvo32.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atiok3x2.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atioglxx.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ATIODE.exe
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ATIODCLI.exe
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atimpc32.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atikvmag.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\aticalrt.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\aticaldd.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\aticalcl.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atibtmon.exe
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2011-03-30 13:36:57 ----A---- C:\WINDOWS\system32\amdpcom32.dll
2011-03-30 13:36:31 ----D---- C:\Program Files\ATI Technologies
2011-03-30 13:36:29 ----D---- C:\Program Files\ATI
2011-03-30 13:35:22 ----D---- C:\WINDOWS\system32\Lang
2011-03-30 13:34:04 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2011-03-30 13:34:02 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2011-03-30 13:34:01 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2011-03-30 13:33:59 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2011-03-30 13:33:57 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2011-03-30 13:33:56 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2011-03-30 13:33:54 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2011-03-30 13:33:52 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2011-03-30 13:33:51 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011-03-30 13:33:49 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2011-03-30 13:33:48 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011-03-30 13:33:30 ----D---- C:\WINDOWS\system32\RTCOM
2011-03-30 13:33:26 ----A---- C:\WINDOWS\system32\ksuser.dll
2011-03-30 13:33:26 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2011-03-30 13:33:25 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2011-03-30 13:33:17 ----A---- C:\WINDOWS\vncutil.exe
2011-03-30 13:33:17 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2011-03-30 13:33:17 ----A---- C:\WINDOWS\SkyTel.exe
2011-03-30 13:33:16 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2011-03-30 13:33:16 ----A---- C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011-03-30 13:33:16 ----A---- C:\WINDOWS\RtlUpd.exe
2011-03-30 13:33:16 ----A---- C:\WINDOWS\RTLCPL.EXE
2011-03-30 13:33:15 ----A---- C:\WINDOWS\RtkAudioService.exe
2011-03-30 13:33:14 ----A---- C:\WINDOWS\system32\drivers\Monfilt.sys
2011-03-30 13:33:14 ----A---- C:\WINDOWS\RTHDCPL.EXE
2011-03-30 13:33:14 ----A---- C:\WINDOWS\MicCal.exe
2011-03-30 13:33:12 ----A---- C:\WINDOWS\system32\drivers\Ambfilt.sys
2011-03-30 13:33:12 ----A---- C:\WINDOWS\ALCWZRD.EXE
2011-03-30 13:33:12 ----A---- C:\WINDOWS\ALCMTR.EXE
2011-03-30 13:33:04 ----A---- C:\WINDOWS\RtlExUpd.dll
2011-03-30 13:33:00 ----D---- C:\Program Files\Common Files\InstallShield
2011-03-30 13:29:35 ----D---- C:\Program Files\Intel
2011-03-30 13:29:35 ----A---- C:\WINDOWS\system32\CSVer.dll
2011-03-30 13:17:13 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2011-03-30 13:13:03 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Windows Search
2011-03-30 13:09:56 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-03-30 13:09:56 ----A---- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys
2011-03-30 12:55:26 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2011-03-30 12:55:26 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-03-29 21:29:02 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2011-03-29 21:16:24 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2011-03-29 21:11:54 ----D---- C:\Program Files\Microsoft Silverlight
2011-03-29 21:11:22 ----D---- C:\Program Files\Microsoft Security Client
2011-03-29 21:10:49 ----D---- C:\Program Files\Microsoft Sync Framework
2011-03-29 21:10:41 ----D---- C:\Program Files\Microsoft
2011-03-29 21:10:28 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2011-03-29 21:10:26 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-03-29 21:10:03 ----D---- C:\Program Files\Windows Live SkyDrive
2011-03-29 21:09:52 ----D---- C:\Program Files\Windows Live
2011-03-29 21:06:29 ----D---- C:\Program Files\Common Files\Windows Live
2011-03-29 21:01:37 ----D---- C:\WINDOWS\system32\WindowsPowerShell
2011-03-29 21:01:36 ----D---- C:\WINDOWS\system32\winrm
2011-03-29 21:01:34 ----HDC---- C:\WINDOWS\$968930Uinstall_KB968930$
2011-03-29 21:01:33 ----D---- C:\WINDOWS\$NtUninstallKB968930$
2011-03-29 20:58:11 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2011-03-29 20:57:46 ----HDC---- C:\WINDOWS\$NtUninstallbasecsp$
2011-03-29 20:57:32 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2011-03-29 20:57:20 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2011-03-29 20:57:17 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2011-03-29 20:57:09 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2011-03-29 20:57:05 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Windows Desktop Search
2011-03-29 20:56:48 ----D---- C:\WINDOWS\system32\GroupPolicy
2011-03-29 20:56:48 ----D---- C:\Program Files\Windows Desktop Search
2011-03-29 20:56:40 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2011-03-29 20:56:34 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2011-03-29 20:56:02 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2011-03-29 20:55:18 ----D---- C:\WINDOWS\system32\URTTEMP
2011-03-29 20:43:19 ----D---- C:\Program Files\Microsoft.NET
2011-03-29 20:40:34 ----N---- C:\WINDOWS\system32\spmsg2.dll
2011-03-29 20:40:33 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2011-03-29 20:33:09 ----D---- C:\WINDOWS\system32\XPSViewer
2011-03-29 20:33:06 ----D---- C:\Program Files\MSBuild
2011-03-29 20:33:05 ----D---- C:\WINDOWS\system32\en-US
2011-03-29 20:33:02 ----D---- C:\Program Files\Reference Assemblies
2011-03-29 20:32:46 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2011-03-29 20:32:46 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2011-03-29 20:32:46 ----N---- C:\WINDOWS\system32\prntvpt.dll
2011-03-29 20:32:23 ----RSD---- C:\WINDOWS\assembly
2011-03-29 20:32:10 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-29 20:31:09 ----N---- C:\WINDOWS\system32\spmsg.dll
2011-03-29 20:31:08 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2011-03-29 20:30:59 ----D---- C:\Program Files\Windows Media Connect 2
2011-03-29 20:30:52 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2011-03-29 20:30:35 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2011-03-29 20:30:24 ----D---- C:\WINDOWS\system32\LogFiles
2011-03-29 20:30:24 ----D---- C:\WINDOWS\system32\drivers\UMDF
2011-03-29 20:30:21 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2011-03-29 20:22:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
2011-03-29 20:22:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2011-03-29 20:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-03-29 20:21:53 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2011-03-29 20:21:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2476687$
2011-03-29 20:21:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2485376$
2011-03-29 20:21:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-03-29 20:21:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-03-29 20:21:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2479628$
2011-03-29 20:21:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-03-29 20:21:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-03-29 20:21:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-03-29 20:20:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-03-29 20:20:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2443685$
2011-03-29 20:20:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-03-29 20:20:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-03-29 20:20:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2011-03-29 20:20:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2011-03-29 20:20:38 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-03-29 20:20:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-03-29 20:20:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2011-03-29 20:20:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-03-29 20:20:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-03-29 20:20:20 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-03-29 20:20:17 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2011-03-29 20:20:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-03-29 20:20:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2011-03-29 20:20:08 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-03-29 20:20:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2011-03-29 20:20:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2011-03-29 20:19:58 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2011-03-29 20:19:55 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2011-03-29 20:19:51 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2011-03-29 20:19:48 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2011-03-29 20:19:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2011-03-29 20:19:32 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2011-03-29 20:19:29 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2011-03-29 20:19:16 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2011-03-29 20:19:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2011-03-29 20:19:08 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2011-03-29 20:11:40 ----D---- C:\WINDOWS\Prefetch
2011-03-29 20:10:28 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2011-03-29 20:10:25 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2011-03-29 20:10:20 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2011-03-29 20:10:16 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2011-03-29 20:10:12 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-03-29 20:10:09 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-03-29 20:10:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2011-03-29 20:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-03-29 20:09:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-03-29 20:09:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-03-29 20:09:52 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2011-03-29 20:09:48 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-03-29 20:09:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-03-29 20:09:41 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2011-03-29 20:09:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2011-03-29 20:09:33 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-03-29 20:09:30 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2011-03-29 20:09:26 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2011-03-29 20:09:22 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2011-03-29 20:09:19 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2011-03-29 20:09:15 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2011-03-29 20:09:12 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2011-03-29 20:09:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2011-03-29 20:09:04 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2011-03-29 20:09:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2011-03-29 20:08:56 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2011-03-29 20:08:53 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2011-03-29 20:08:50 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2011-03-29 20:08:46 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2011-03-29 20:08:43 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2011-03-29 20:08:39 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2011-03-29 20:08:35 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2011-03-29 20:08:30 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2011-03-29 20:08:26 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2011-03-29 20:08:23 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2011-03-29 20:08:19 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2011-03-29 20:08:15 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2011-03-29 20:08:11 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2011-03-29 20:08:08 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2011-03-29 20:08:05 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2011-03-29 20:08:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2011-03-29 20:07:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2011-03-29 20:07:51 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2011-03-29 20:07:47 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2011-03-29 20:07:42 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2011-03-29 20:07:39 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2011-03-29 20:07:36 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2011-03-29 20:07:32 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2011-03-29 20:07:28 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2011-03-29 20:07:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2011-03-29 20:07:21 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2011-03-29 20:07:17 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2011-03-29 20:07:14 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2011-03-29 20:07:10 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2011-03-29 20:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2011-03-29 20:07:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-03-29 20:04:34 ----D---- C:\WINDOWS\system32\cs
2011-03-29 20:04:34 ----D---- C:\WINDOWS\system32\bits
2011-03-29 20:04:34 ----D---- C:\WINDOWS\l2schemas
2011-03-29 20:02:31 ----D---- C:\WINDOWS\network diagnostic
2011-03-29 20:01:39 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-03-29 20:00:27 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2011-03-29 20:00:27 ----D---- C:\WINDOWS\EHome
2011-03-29 19:58:22 ----N---- C:\WINDOWS\system32\wmphoto.dll
2011-03-29 19:58:21 ----N---- C:\WINDOWS\system32\wlanapi.dll
2011-03-29 19:58:21 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2011-03-29 19:58:21 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\verclsid.exe
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\wacompen.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\viaagp.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\vchnt5.dll
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\usbvideo.sys
2011-03-29 19:58:20 ----N---- C:\WINDOWS\system32\drivers\usb8023x.sys
2011-03-29 19:58:19 ----N---- C:\WINDOWS\system32\tspkg.dll
2011-03-29 19:58:19 ----N---- C:\WINDOWS\system32\tsgqec.dll
2011-03-29 19:58:19 ----N---- C:\WINDOWS\system32\drivers\uagp35.sys
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\spupdwxp.exe
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\slserv.exe
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\slrundll.exe
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\slgen.dll
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\slextspk.dll
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\slcoinst.dll
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\drivers\smbali.sys
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\drivers\sisagp.sys
2011-03-29 19:58:18 ----N---- C:\WINDOWS\system32\drivers\siint5.dll
2011-03-29 19:58:18 ----N---- C:\WINDOWS\slrundll.exe
2011-03-29 19:58:18 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2011-03-29 19:58:17 ----N---- C:\WINDOWS\system32\setupn.exe
2011-03-29 19:58:17 ----N---- C:\WINDOWS\system32\s3gnb.dll
2011-03-29 19:58:17 ----N---- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2011-03-29 19:58:17 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\rasqec.dll
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\qutil.dll
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\qcliprov.dll
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\qagentrt.dll
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\qagent.dll
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\drivers\rndismpx.sys
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\drivers\rfcomm.sys
2011-03-29 19:58:16 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2011-03-29 19:58:15 ----N---- C:\WINDOWS\system32\onex.dll
2011-03-29 19:58:15 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2011-03-29 19:58:15 ----N---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2011-03-29 19:58:15 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\napstat.exe
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\napmontr.dll
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\napipsec.dll
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\msxml6r.dll
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\msxml6.dll
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\drivers\mutohpen.sys
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2011-03-29 19:58:14 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2011-03-29 19:58:13 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2011-03-29 19:58:13 ----N---- C:\WINDOWS\system32\mssha.dll
2011-03-29 19:58:11 ----N---- C:\WINDOWS\system32\mmcperf.exe
2011-03-29 19:58:11 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2011-03-29 19:58:11 ----N---- C:\WINDOWS\system32\mmcex.dll
2011-03-29 19:58:11 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2011-03-29 19:58:11 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2011-03-29 19:58:11 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2011-03-29 19:58:07 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2011-03-29 19:58:07 ----N---- C:\WINDOWS\system32\kmsvc.dll
2011-03-29 19:58:07 ----N---- C:\WINDOWS\system32\kbdpash.dll
2011-03-29 19:58:07 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2011-03-29 19:58:07 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2011-03-29 19:58:07 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2011-03-29 19:58:07 ----N---- C:\WINDOWS\system32\ieencode.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\faxpatch.exe
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\eapsvc.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\eapqec.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\eappprxy.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\eapphost.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\eappgnui.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\eappcfg.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\eapolqec.dll
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\drivers\hidir.sys
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\drivers\hidbth.sys
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2011-03-29 19:58:06 ----N---- C:\WINDOWS\system32\drivers\gagp30kx.sys
2011-03-29 19:58:06 ----A---- C:\WINDOWS\002532_.tmp
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dot3ui.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dot3svc.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dot3msm.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dot3api.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dimsroam.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2011-03-29 19:58:05 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2011-03-29 19:58:04 ----N---- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2011-03-29 19:58:04 ----N---- C:\WINDOWS\system32\drivers\bthusb.sys
2011-03-29 19:58:04 ----N---- C:\WINDOWS\system32\drivers\bthprint.sys
2011-03-29 19:58:04 ----N---- C:\WINDOWS\system32\drivers\bthpan.sys
2011-03-29 19:58:04 ----N---- C:\WINDOWS\system32\drivers\bthmodem.sys
2011-03-29 19:58:04 ----N---- C:\WINDOWS\system32\drivers\bthenum.sys
2011-03-29 19:58:04 ----N---- C:\WINDOWS\system32\credssp.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atv10nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atv06nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atv04nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atv02nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atv01nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\amdagp.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\alim1541.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\agpcpq.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\agp440.sys
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\adv11nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\adv09nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\adv08nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\adv07nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\adv05nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\adv02nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\drivers\adv01nt5.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\azroles.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2011-03-29 19:58:03 ----N---- C:\WINDOWS\system32\aaclient.dll
2011-03-29 19:58:03 ----A---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2011-03-29 19:58:03 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2011-03-29 19:58:03 ----A---- C:\WINDOWS\system32\ati3duag.dll
2011-03-29 19:58:03 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2011-03-29 19:58:03 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2011-03-29 19:53:51 ----D---- C:\WINDOWS\ie8updates
2011-03-29 19:53:25 ----D---- C:\WINDOWS\WBEM
2011-03-29 19:52:45 ----HDC---- C:\WINDOWS\ie8
2011-03-29 19:52:45 ----D---- C:\WINDOWS\system32\cs-CZ
2011-03-29 19:50:50 ----SHD---- C:\RECYCLER
2011-03-29 19:48:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593_0$
2011-03-29 19:48:09 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2011-03-29 19:48:04 ----HDC---- C:\WINDOWS\$NtUninstallKB979559_0$
2011-03-29 19:48:00 ----HDC---- C:\WINDOWS\$NtUninstallKB975562_0$
2011-03-29 19:47:57 ----HDC---- C:\WINDOWS\$NtUninstallKB979482_0$
2011-03-29 19:47:54 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2011-03-29 19:47:51 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-03-29 19:47:48 ----HDC---- C:\WINDOWS\$NtUninstallKB980218_0$
2011-03-29 19:47:45 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2011-03-29 19:47:42 ----HDC---- C:\WINDOWS\$NtUninstallKB978542_0$
2011-03-29 19:47:37 ----HDC---- C:\WINDOWS\$NtUninstallKB978601_0$
2011-03-29 19:47:33 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2011-03-29 19:47:28 ----HDC---- C:\WINDOWS\$NtUninstallKB979683_0$
2011-03-29 19:47:24 ----HDC---- C:\WINDOWS\$NtUninstallKB978338_0$
2011-03-29 19:47:20 ----HDC---- C:\WINDOWS\$NtUninstallKB979309_0$
2011-03-29 19:47:17 ----HDC---- C:\WINDOWS\$NtUninstallKB981350$
2011-03-29 19:47:14 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-03-29 19:47:11 ----HDC---- C:\WINDOWS\$NtUninstallKB980232_0$
2011-03-29 19:47:07 ----HDC---- C:\WINDOWS\$NtUninstallKB975561_0$
2011-03-29 19:47:03 ----HDC---- C:\WINDOWS\$NtUninstallKB978706_0$
2011-03-29 19:47:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971468_0$
2011-03-29 19:46:57 ----HDC---- C:\WINDOWS\$NtUninstallKB977914_0$
2011-03-29 19:46:53 ----HDC---- C:\WINDOWS\$NtUninstallKB975560_0$
2011-03-29 19:46:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978037_0$
2011-03-29 19:46:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975713_0$
2011-03-29 19:46:42 ----HDC---- C:\WINDOWS\$NtUninstallKB972270_0$
2011-03-29 19:46:39 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2011-03-29 19:46:35 ----HDC---- C:\WINDOWS\$NtUninstallKB955759_0$
2011-03-29 19:46:31 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2011-03-29 19:46:27 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2011-03-29 19:46:24 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2011-03-29 19:46:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2011-03-29 19:46:17 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2011-03-29 19:46:12 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2011-03-29 19:46:08 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2011-03-29 19:46:06 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2011-03-29 19:46:03 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2011-03-29 19:45:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2011-03-29 19:45:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2011-03-29 19:45:53 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2011-03-29 19:45:50 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2011-03-29 19:45:47 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2011-03-29 19:45:17 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-29 19:45:12 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$
2011-03-29 19:43:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2011-03-29 19:43:25 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2011-03-29 19:43:19 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2011-03-29 19:43:15 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2011-03-29 19:43:11 ----D---- C:\WINDOWS\ServicePackFiles
2011-03-29 19:43:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2011-03-29 19:43:06 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2011-03-29 19:42:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2011-03-29 19:42:55 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2011-03-29 19:42:51 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2011-03-29 19:42:47 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2011-03-29 19:42:43 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2011-03-29 19:42:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2011-03-29 19:42:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2011-03-29 19:42:14 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2011-03-29 19:42:03 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2011-03-29 19:41:59 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2011-03-29 19:41:55 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2011-03-29 19:41:51 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2011-03-29 19:41:46 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2011-03-29 19:41:41 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2011-03-29 19:41:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2011-03-29 19:41:33 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2011-03-29 19:41:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2011-03-29 19:41:26 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2011-03-29 19:41:22 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2011-03-29 19:41:18 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2011-03-29 19:41:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2011-03-29 19:41:05 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2011-03-29 19:39:45 ----N---- C:\WINDOWS\system32\browserchoice.exe
2011-03-29 19:37:11 ----N---- C:\WINDOWS\system32\tzchange.exe
2011-03-29 19:34:33 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2011-03-29 19:32:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2011-03-29 19:31:20 ----D---- C:\WINDOWS\system32\PreInstall
2011-03-29 19:31:20 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2011-03-29 19:31:19 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-03-29 19:31:02 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2011-03-29 19:28:18 ----A---- C:\WINDOWS\system32\wups2.dll
2011-03-29 19:28:18 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2011-03-29 19:28:18 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2011-03-29 19:28:18 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2011-03-29 19:28:17 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-03-29 19:27:09 ----A---- C:\WINDOWS\system32\wpa.bak
2011-03-29 19:15:31 ----A---- C:\WINDOWS\system32\RTNUninst32.dll
2011-03-29 19:15:31 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2011-03-29 19:15:31 ----A---- C:\WINDOWS\system32\drivers\Rtenicxp.sys
2011-03-29 19:15:27 ----HD---- C:\Program Files\InstallShield Installation Information
2011-03-29 19:15:27 ----D---- C:\Program Files\Realtek
2011-03-28 23:12:10 ----A---- C:\WINDOWS\system32\h323log.txt
2011-03-28 23:11:12 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2011-03-28 23:10:18 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2011-03-28 23:09:29 ----A---- C:\WINDOWS\system32\usbui.dll
2011-03-28 23:08:39 ----SHD---- C:\WINDOWS\Installer
2011-03-28 23:08:39 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-28 23:08:38 ----D---- C:\Program Files\Common Files\ODBC
2011-03-28 23:08:38 ----A---- C:\WINDOWS\ODBCINST.INI
2011-03-28 23:08:36 ----RD---- C:\Program Files
2011-03-28 23:08:36 ----D---- C:\Program Files\Common Files\SpeechEngines
2011-03-28 23:08:36 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-03-28 23:08:36 ----D---- C:\Program Files\Common Files
2011-03-28 23:08:33 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2011-03-28 23:08:33 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2011-03-28 23:08:33 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdur.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdru.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2011-03-28 23:08:32 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2011-03-28 23:08:31 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2011-03-28 23:08:31 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2011-03-28 23:08:30 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2011-03-28 23:08:30 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2011-03-28 23:08:30 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2011-03-28 23:08:30 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2011-03-28 23:08:30 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2011-03-28 23:08:30 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2011-03-28 23:08:30 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2011-03-28 23:08:29 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2011-03-28 23:08:29 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2011-03-28 23:08:29 ----RA---- C:\WINDOWS\system32\kbdest.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdycl.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdsl1.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdsl.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdro.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdpl1.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdpl.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdhu1.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdhu.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\kbdcr.dll
2011-03-28 23:08:27 ----A---- C:\WINDOWS\system32\KBDAL.DLL
2011-03-28 23:08:26 ----A---- C:\WINDOWS\system32\spxcoins.dll
2011-03-28 23:08:26 ----A---- C:\WINDOWS\system32\irclass.dll
2011-03-28 23:08:26 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2011-03-28 23:08:26 ----A---- C:\WINDOWS\system32\dgsetup.dll
2011-03-28 23:08:26 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2011-03-28 23:08:25 ----A---- C:\WINDOWS\TASKMAN.EXE
2011-03-28 23:08:24 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2011-03-28 23:08:24 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2011-03-28 23:08:24 ----A---- C:\WINDOWS\system32\batt.dll
2011-03-28 23:08:24 ----A---- C:\WINDOWS\notepad.exe
2011-03-28 23:08:21 ----A---- C:\WINDOWS\system32\storprop.dll
2011-03-28 23:08:15 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2011-03-28 23:07:04 ----RA---- C:\WINDOWS\SET21.tmp
2011-03-28 23:06:34 ----RA---- C:\WINDOWS\SET8.tmp
2011-03-28 23:06:32 ----RA---- C:\WINDOWS\SET4.tmp
2011-03-28 23:06:30 ----RA---- C:\WINDOWS\SET3.tmp
2011-03-28 23:06:26 ----D---- C:\WINDOWS\system32\CatRoot2
2011-03-28 23:06:26 ----D---- C:\WINDOWS\system32\CatRoot
2011-03-28 23:06:20 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-03-28 23:06:02 ----D---- C:\Documents and Settings
2011-03-28 23:06:01 ----SHD---- C:\System Volume Information
2011-03-28 23:05:10 ----SH---- C:\boot.ini
2011-03-28 23:00:46 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-28 23:00:46 ----RSD---- C:\WINDOWS\Fonts
2011-03-28 23:00:46 ----RD---- C:\WINDOWS\Web
2011-03-28 23:00:46 ----HD---- C:\WINDOWS\inf
2011-03-28 23:00:46 ----D---- C:\WINDOWS\WinSxS
2011-03-28 23:00:46 ----D---- C:\WINDOWS\twain_32
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Temp
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\wins
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\wbem
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\usmt
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\spool
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\ShellExt
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\Setup
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\ras
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\oobe
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\npp
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\mui
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\inetsrv
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\IME
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\icsxml
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\ias
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\export
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\drivers\etc
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\drivers\disdn
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\drivers
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\dhcp
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\config
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\3com_dmi
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\3076
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\2052
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1054
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1042
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1041
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1037
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1033
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1031
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1029
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1028
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32\1025
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system32
2011-03-28 23:00:46 ----D---- C:\WINDOWS\system
2011-03-28 23:00:46 ----D---- C:\WINDOWS\security
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Resources
2011-03-28 23:00:46 ----D---- C:\WINDOWS\repair
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Provisioning
2011-03-28 23:00:46 ----D---- C:\WINDOWS\pchealth
2011-03-28 23:00:46 ----D---- C:\WINDOWS\PeerNet
2011-03-28 23:00:46 ----D---- C:\WINDOWS\mui
2011-03-28 23:00:46 ----D---- C:\WINDOWS\msapps
2011-03-28 23:00:46 ----D---- C:\WINDOWS\msagent
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Media
2011-03-28 23:00:46 ----D---- C:\WINDOWS\java
2011-03-28 23:00:46 ----D---- C:\WINDOWS\ime
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Help
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Driver Cache
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Debug
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Cursors
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Connection Wizard
2011-03-28 23:00:46 ----D---- C:\WINDOWS\Config
2011-03-28 23:00:46 ----D---- C:\WINDOWS\AppPatch
2011-03-28 23:00:46 ----D---- C:\WINDOWS\addins
2011-03-28 23:00:46 ----D---- C:\WINDOWS
2011-03-28 23:00:46 ----ASH---- C:\pagefile.sys
2011-03-28 21:19:38 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Identities
2011-03-28 21:19:37 ----HD---- C:\Program Files\Uninstall Information
2011-03-28 21:19:27 ----ASH---- C:\Documents and Settings\Lukáš\Data aplikací\desktop.ini
2011-03-28 21:19:26 ----SD---- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft
2011-03-28 21:18:46 ----D---- C:\WINDOWS\SoftwareDistribution
2011-03-28 21:18:44 ----SD---- C:\WINDOWS\system32\Microsoft
2011-03-28 21:18:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-03-28 21:16:42 ----D---- C:\WINDOWS\system32\xircom
2011-03-28 21:16:42 ----D---- C:\Program Files\xerox
2011-03-28 21:16:42 ----D---- C:\Program Files\microsoft frontpage
2011-03-28 21:16:32 ----HD---- C:\WINDOWS\$hf_mig$
2011-03-28 21:16:19 ----RASH---- C:\MSDOS.SYS
2011-03-28 21:16:19 ----RASH---- C:\IO.SYS
2011-03-28 21:16:19 ----A---- C:\WINDOWS\control.ini
2011-03-28 21:16:19 ----A---- C:\CONFIG.SYS
2011-03-28 21:16:19 ----A---- C:\AUTOEXEC.BAT
2011-03-28 21:16:07 ----A---- C:\WINDOWS\system32\mapi32.dll
2011-03-28 21:15:31 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-03-28 21:15:31 ----RD---- C:\WINDOWS\Offline Web Pages
2011-03-28 21:15:31 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2011-03-28 21:15:27 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2011-03-28 21:15:23 ----HD---- C:\Program Files\WindowsUpdate
2011-03-28 21:15:20 ----D---- C:\Program Files\Online Services
2011-03-28 21:15:07 ----D---- C:\WINDOWS\system32\DirectX
2011-03-28 21:14:54 ----A---- C:\WINDOWS\system32\atrace.dll
2011-03-28 21:14:52 ----A---- C:\WINDOWS\system32\desktop.ini
2011-03-28 21:14:52 ----A---- C:\WINDOWS\desktop.ini
2011-03-28 21:14:47 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2011-03-28 21:14:46 ----D---- C:\Program Files\Common Files\Services
2011-03-28 21:14:46 ----A---- C:\WINDOWS\system32\acctres.dll
2011-03-28 21:14:44 ----SD---- C:\WINDOWS\Tasks
2011-03-28 21:14:44 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2011-03-28 21:14:43 ----D---- C:\Program Files\Common Files\MSSoap
2011-03-28 21:14:41 ----D---- C:\WINDOWS\system32\Macromed
2011-03-28 21:14:41 ----D---- C:\WINDOWS\srchasst
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wuweb.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wups.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wucltui.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wuauserv.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wuaueng.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wuauclt.exe
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\wuapi.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\qmgr.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2011-03-28 21:14:38 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2011-03-28 21:14:35 ----D---- C:\Program Files\Movie Maker
2011-03-28 21:14:32 ----A---- C:\WINDOWS\system32\safrslv.dll
2011-03-28 21:14:32 ----A---- C:\WINDOWS\system32\safrdm.dll
2011-03-28 21:14:32 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2011-03-28 21:14:32 ----A---- C:\WINDOWS\system32\racpldlg.dll
2011-03-28 21:14:30 ----D---- C:\WINDOWS\system32\Restore
2011-03-28 21:14:30 ----A---- C:\WINDOWS\system32\srsvc.dll
2011-03-28 21:14:30 ----A---- C:\WINDOWS\system32\srrstr.dll
2011-03-28 21:14:30 ----A---- C:\WINDOWS\system32\srclient.dll
2011-03-28 21:14:30 ----A---- C:\WINDOWS\system32\fltmc.exe
2011-03-28 21:14:30 ----A---- C:\WINDOWS\system32\fltlib.dll
2011-03-28 21:14:30 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2011-03-28 21:14:30 ----A---- C:\WINDOWS\system32\drivers\fltmgr.sys
2011-03-28 21:14:29 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2011-03-28 21:14:29 ----A---- C:\WINDOWS\system32\msconf.dll
2011-03-28 21:14:29 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2011-03-28 21:14:29 ----A---- C:\WINDOWS\system32\mnmdd.dll
2011-03-28 21:14:29 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2011-03-28 21:14:29 ----A---- C:\WINDOWS\system32\ils.dll
2011-03-28 21:14:27 ----D---- C:\Program Files\NetMeeting
2011-03-28 21:14:27 ----A---- C:\WINDOWS\system32\msoert2.dll
2011-03-28 21:14:27 ----A---- C:\WINDOWS\system32\msoeacct.dll
2011-03-28 21:14:26 ----A---- C:\WINDOWS\system32\inetres.dll
2011-03-28 21:14:26 ----A---- C:\WINDOWS\system32\inetcomm.dll
2011-03-28 21:14:25 ----D---- C:\Program Files\Outlook Express
2011-03-28 21:14:25 ----A---- C:\WINDOWS\system32\schedsvc.dll
2011-03-28 21:14:25 ----A---- C:\WINDOWS\system32\mstinit.exe
2011-03-28 21:14:25 ----A---- C:\WINDOWS\system32\mstask.dll
2011-03-28 21:14:24 ----A---- C:\WINDOWS\system32\isign32.dll
2011-03-28 21:14:24 ----A---- C:\WINDOWS\system32\inetcfg.dll
2011-03-28 21:14:24 ----A---- C:\WINDOWS\system32\icwphbk.dll
2011-03-28 21:14:24 ----A---- C:\WINDOWS\system32\icwdial.dll
2011-03-28 21:14:20 ----D---- C:\Program Files\Internet Explorer
2011-03-28 21:14:20 ----D---- C:\Program Files\Common Files\System
2011-03-28 21:14:09 ----D---- C:\Program Files\ComPlus Applications
2011-03-28 21:14:07 ----A---- C:\WINDOWS\vbaddin.ini
2011-03-28 21:14:07 ----A---- C:\WINDOWS\vb.ini
2011-03-28 21:14:03 ----D---- C:\WINDOWS\Registration
2011-03-28 21:13:40 ----D---- C:\Program Files\Windows Media Player
2011-03-28 21:13:36 ----D---- C:\Program Files\Messenger
2011-03-28 21:13:34 ----D---- C:\Program Files\MSN Gaming Zone
2011-03-28 21:13:34 ----A---- C:\WINDOWS\system32\write.exe
2011-03-28 21:13:28 ----A---- C:\WINDOWS\system32\sndvol32.exe
2011-03-28 21:13:27 ----A---- C:\WINDOWS\system32\winchat.exe
2011-03-28 21:13:27 ----A---- C:\WINDOWS\system32\hticons.dll
2011-03-28 21:13:27 ----A---- C:\WINDOWS\system32\avwav.dll
2011-03-28 21:13:27 ----A---- C:\WINDOWS\system32\avtapi.dll
2011-03-28 21:13:27 ----A---- C:\WINDOWS\system32\avmeter.dll
2011-03-28 21:13:22 ----A---- C:\WINDOWS\system32\winmine.exe
2011-03-28 21:13:22 ----A---- C:\WINDOWS\system32\sol.exe
2011-03-28 21:13:22 ----A---- C:\WINDOWS\system32\charmap.exe
2011-03-28 21:13:22 ----A---- C:\WINDOWS\system32\getuname.dll
2011-03-28 21:13:22 ----A---- C:\WINDOWS\system32\calc.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\tslabels.ini
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\tskill.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\tscon.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\shadow.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\rwinsta.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\reset.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\regini.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\qwinsta.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\qappsrv.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\mshearts.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\msg.exe
2011-03-28 21:13:21 ----A---- C:\WINDOWS\system32\freecell.exe
2011-03-28 21:13:20 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2011-03-28 21:13:20 ----A---- C:\WINDOWS\system32\mtxex.dll
2011-03-28 21:13:20 ----A---- C:\WINDOWS\system32\mtxdm.dll
2011-03-28 21:13:20 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2011-03-28 21:13:20 ----A---- C:\WINDOWS\system32\logoff.exe
2011-03-28 21:13:20 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2011-03-28 21:13:20 ----A---- C:\WINDOWS\system32\cdmodem.dll
2011-03-28 21:13:19 ----A---- C:\WINDOWS\system32\stclient.dll
2011-03-28 21:13:19 ----A---- C:\WINDOWS\system32\comsnap.dll
2011-03-28 21:13:19 ----A---- C:\WINDOWS\system32\comrepl.dll
2011-03-28 21:13:19 ----A---- C:\WINDOWS\system32\comaddin.dll
2011-03-28 21:13:16 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2011-03-28 21:13:15 ----D---- C:\Program Files\Windows NT
2011-03-28 21:13:15 ----A---- C:\WINDOWS\system32\sndrec32.exe
2011-03-28 21:13:15 ----A---- C:\WINDOWS\system32\mspaint.exe
2011-03-28 21:13:15 ----A---- C:\WINDOWS\system32\mplay32.exe
2011-03-28 21:13:15 ----A---- C:\WINDOWS\system32\hypertrm.dll
2011-03-28 21:13:15 ----A---- C:\WINDOWS\system32\accwiz.exe
2011-03-28 21:13:14 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2011-03-28 21:13:14 ----A---- C:\WINDOWS\system32\spider.exe
2011-03-28 21:13:14 ----A---- C:\WINDOWS\system32\mstscax.dll
2011-03-28 21:13:14 ----A---- C:\WINDOWS\system32\mstsc.exe
2011-03-28 21:13:14 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2011-03-28 21:13:14 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2011-03-28 21:13:14 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2011-03-28 21:13:14 ----A---- C:\WINDOWS\system32\clipbrd.exe
2011-03-28 21:13:13 ----D---- C:\WINDOWS\system32\MsDtc
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\termsrv.dll
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\sessmgr.exe
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\remotepg.dll
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\rdshost.exe
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\rdpclip.exe
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\rdchost.dll
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\qprocess.exe
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\icaapi.dll
2011-03-28 21:13:13 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2011-03-28 21:13:12 ----A---- C:\WINDOWS\system32\xolehlp.dll
2011-03-28 21:13:12 ----A---- C:\WINDOWS\system32\mtxoci.dll
2011-03-28 21:13:12 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2011-03-28 21:13:12 ----A---- C:\WINDOWS\system32\msdtctm.dll
2011-03-28 21:13:12 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2011-03-28 21:13:12 ----A---- C:\WINDOWS\system32\msdtclog.dll
2011-03-28 21:13:12 ----A---- C:\WINDOWS\system32\msdtc.exe
2011-03-28 21:13:11 ----D---- C:\WINDOWS\system32\Com
2011-03-28 21:13:11 ----A---- C:\WINDOWS\system32\comuid.dll
2011-03-28 21:13:11 ----A---- C:\WINDOWS\system32\comsvcs.dll
2011-03-28 21:13:11 ----A---- C:\WINDOWS\system32\colbact.dll
2011-03-28 21:13:11 ----A---- C:\WINDOWS\system32\clbcatex.dll
2011-03-28 21:13:11 ----A---- C:\WINDOWS\system32\catsrvut.dll
2011-03-28 21:13:11 ----A---- C:\WINDOWS\system32\catsrvps.dll
2011-03-28 21:13:11 ----A---- C:\WINDOWS\system32\catsrv.dll
2011-03-28 21:13:10 ----A---- C:\WINDOWS\system32\clbcatq.dll
2011-03-28 21:13:07 ----A---- C:\WINDOWS\system32\servdeps.dll
2011-03-28 21:13:07 ----A---- C:\WINDOWS\system32\mmfutil.dll
2011-03-28 21:13:07 ----A---- C:\WINDOWS\system32\licwmi.dll
2011-03-28 21:13:07 ----A---- C:\WINDOWS\system32\cmprops.dll
2011-03-28 21:13:03 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2011-03-28 21:13:03 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 months======

2011-03-29 20:31:03 ----A---- C:\WINDOWS\win.ini
2011-03-28 23:08:35 ----A---- C:\WINDOWS\system.ini
2011-03-28 21:16:00 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Amfilter;A4Tech Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\Amfilter.sys [2007-05-14 9216]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsld0a4b2f0;MpKsld0a4b2f0; \??\c:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{8EAA4360-707C-4564-9D9A-807F6792CA50}\MpKsld0a4b2f0.sys []
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2010-04-28 54760]
R3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:\WINDOWS\system32\DRIVERS\Amusbprt.sys [2007-05-14 14336]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2011-01-27 6406656]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdXP3.sys [2010-11-17 101904]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-02-24 6340200]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2011-01-14 277352]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2011-01-27 638976]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-03-30 153376]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 SeaPort;SeaPort; c:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-04-28 704872]
S3 idsvc;Služba Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

petr0266
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 06 lis 2010 13:22

Re: MBR (bootkit remover)

#4 Příspěvek od petr0266 »

Možná by nebylo od věci MBRFIX přes záchranou konzoly z instalačního CD po bootu.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR (bootkit remover)

#5 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Omlouvam se kolegovi za vstup, pisu na zadost uzivatele pres PMku

:arrow: Bootkit remover obcas hlasi unknow boot code, i kdyz tam mbr havet neni - proc tomu tam je nevim. Tato utilita je vhodna predevsim na whistler bootkita, na kontrolu mbr sektoru je vhodny mbr.exe spusteny s prislusnymi parametry - vizte nize

:arrow: Stahnete SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte z uvedene stranky verzi dle sveho operacniho systemu (32(x86)bit ci 64(x64)bit)
  • Ulozte na plochu a spustte
  • Zvolte moznost Uninstall a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete Defogger http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Ulozte na plochu a spustte
  • Kliknete na Disable a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete MBR na plochu http://www2.gmer.net/mbr/mbr.exe ale nespoustejte

:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    "%userprofile%\plocha\mbr" -t -s
  • Kliknete na OK
  • Na plose se Vam vytvori log s nazvem mbr.txt, jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

petr0266
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 06 lis 2010 13:22

Re: MBR (bootkit remover)

#6 Příspěvek od petr0266 »

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD1600AAJS-00PSA0 rev.05.06H05 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-16

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x89DD8AB8]
3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000062[0x89E23C80]
5 ACPI[0xB9F7F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Ide\IdeDeviceP2T0L0-16[0x89E09CF0]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
user & kernel MBR OK

petr0266
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 06 lis 2010 13:22

Re: MBR (bootkit remover)

#7 Příspěvek od petr0266 »

Můžu se zeptat, jaký je rozdíl mezi disinfectem přes bootkit remover a mbrfix ze zotavovační konzole přes bootovaci CD Windowsů?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR (bootkit remover)

#8 Příspěvek od vyosek »

Pres Konzolu je vetsi sance ze se fixnuti povede, jelikoz takto bootkit remover bezi jako aplikace winu - pripadny mbr rootkit ji muze omezovat, kdezto fixmbr pres Konzolu je system mrtvy...

mbr sektor vypada cisty
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: MBR (bootkit remover)

#9 Příspěvek od motji »

Omlouvám se za vstup :)

Abych Vás uklidnila, mě bootkit remover hlásí to samé, na obou discích a systémech. Bootkit remover v tomhle má nějaký bug, nevím, zda třeba detekuje prázdnou particii, nebo čím to je, ale mbr rootkita vůbec nemusíte mít, pokud jsou ostatní skenery na mbr ok. Takže se tím netrapte. :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

MiliNess
Přítel fóra
Přítel fóra
Příspěvky: 4144
Registrován: 15 říj 2009 18:15
Bydliště: Cheb

Re: MBR (bootkit remover)

#10 Příspěvek od MiliNess »

Bootkit remover totiž asi porovnává MD5 hash kódu zavaděče v MBR i s tabulkou stringů, která je na konci kódu.
(chybové zprávy Invalid partition table, Error loading operating system, Missing operating system)
Autor pak zřejmé porovnává hash MBR zavaděče s anglickými zprávami s hashem MBR zavaděče s českými zprávami.
I když je kód u obou verzí stejný, výsledný hash je u obou rozdílný, díky jinému textu chybových zpráv.
Pokud jste s naší pomocí spokojeni, můžete nás podpořit. Informace zde

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: MBR (bootkit remover)

#11 Příspěvek od vyosek »

Dekuji kolegum za doplneni, ja jsem na tom podobne jako motji (jak stolni PC, tak ntb) my hlasili pres bootkita uknow code. A myslim ze Millines vystihl i pricinu...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

petr0266
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 06 lis 2010 13:22

Re: MBR (bootkit remover)

#12 Příspěvek od petr0266 »

děkuji za vysvětlení ;). Budu si to tedy kontrolovat přes prográmek výše uvedený (mbr.exe s parametry -t a -s). Jen tak pro vtip zkusím udělat přes nabootovani WIN XP CD dát mbrfix přes zotavovací konzoly, co na mě vyblafne bootkit.

petr0266
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 06 lis 2010 13:22

Re: MBR (bootkit remover)

#13 Příspěvek od petr0266 »

Dal jsem konzoli pro zotavení, potom jsem dal FIXMBR a FIXBOOT.... u fixmbr mi to psalo, že je s ní něco špatně.... po restartu (příkaz exit), jsem zkusil bootkita a ukazuje OK.

MiliNess
Přítel fóra
Přítel fóra
Příspěvky: 4144
Registrován: 15 říj 2009 18:15
Bydliště: Cheb

Re: MBR (bootkit remover)

#14 Příspěvek od MiliNess »

FIXMBR to někdy píše. Ignorovat, přepsat.
Pokud jste s naší pomocí spokojeni, můžete nás podpořit. Informace zde

Odpovědět