Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu - problém s win 7 home security 2012

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
ChosseCV
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 27 čer 2011 00:36

Prosím o kontrolu logu - problém s win 7 home security 2012

#1 Příspěvek od ChosseCV »

ComboFix 11-06-26.02 - Chosse 27.06.2011 12:50:33.3.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.2046.1028 [GMT 2:00]
Spuštěný z: c:\users\Chosse\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-05-27 do 2011-06-27 )))))))))))))))))))))))))))))))
.
.
2011-06-27 11:01 . 2011-06-27 11:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-27 10:03 . 2011-06-27 10:03 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-06-27 10:03 . 2011-06-27 10:03 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-06-27 10:03 . 2011-06-27 10:03 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-06-27 10:03 . 2011-06-27 10:03 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2011-06-27 10:03 . 2011-06-27 10:03 8646 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2011-06-27 10:03 . 2011-06-27 10:03 8613 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2011-06-27 10:03 . 2011-06-27 10:03 5927 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2011-06-27 10:03 . 2011-06-27 10:03 1651 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2011-06-27 10:03 . 2011-06-27 10:03 6910 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2011-06-27 10:03 . 2011-06-27 10:03 8288 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2011-06-27 10:03 . 2011-06-27 10:03 6208 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2011-06-27 10:03 . 2011-06-27 10:03 18541 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2011-06-27 10:02 . 2011-06-27 10:02 51852 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2011-06-27 10:02 . 2011-06-27 10:02 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2011-06-27 10:02 . 2011-06-27 10:02 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2011-06-27 10:02 . 2011-06-27 10:02 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2011-06-27 10:02 . 2011-06-27 10:02 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2011-06-26 17:53 . 2011-06-26 19:58 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-26 17:53 . 2011-06-26 17:53 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-06-26 17:40 . 2011-06-26 17:40 -------- d-----w- c:\users\Chosse\AppData\Local\Google
2011-06-26 17:39 . 2010-01-22 07:55 767952 ----a-w- c:\windows\BDTSupport.dll
2011-06-26 17:39 . 2010-01-22 07:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-06-26 17:39 . 2011-06-26 17:40 -------- d-----w- c:\program files\Google
2011-06-26 17:39 . 2010-01-22 07:56 165840 ----a-w- c:\windows\PCTBDRes.dll
2011-06-26 17:39 . 2010-01-22 07:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
2011-06-26 17:38 . 2010-02-05 07:18 100136 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2011-06-26 17:38 . 2010-02-05 07:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-06-26 17:38 . 2010-03-29 08:06 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-06-26 17:38 . 2009-11-23 11:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-06-26 17:38 . 2010-04-08 12:29 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-06-26 17:38 . 2011-06-27 10:09 -------- d-----w- c:\program files\Spyware Doctor
2011-06-26 17:38 . 2011-06-26 17:40 -------- d-----w- c:\program files\Common Files\PC Tools
2011-06-26 17:38 . 2011-06-26 17:38 -------- d-----w- c:\users\Chosse\AppData\Roaming\PC Tools
2011-06-26 17:38 . 2011-06-26 17:38 -------- d-----w- c:\programdata\PC Tools
2011-06-26 17:05 . 2011-06-27 11:01 -------- d-----w- c:\users\Chosse\AppData\Local\temp
2011-06-26 14:51 . 2011-06-26 14:52 -------- d-----w- c:\windows\rescache
2011-06-26 11:29 . 2011-06-26 11:29 -------- d-----w- c:\program files\ESET
2011-06-26 07:05 . 2011-06-26 07:05 -------- d-----w- c:\windows\system32\SPReview
2011-06-26 07:04 . 2011-06-26 07:04 -------- d-----w- c:\windows\system32\EventProviders
2011-06-26 07:03 . 2011-06-26 07:05 -------- d-----w- C:\6f4f6007d2f29c0a14a83e1daa974a71
2011-06-25 06:07 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E88EFE08-5F38-4BC4-A19E-4D66B1797539}\mpengine.dll
2011-06-21 11:40 . 2010-11-20 12:21 653312 ----a-w- c:\windows\system32\rpcrt4.dll
2011-06-21 11:39 . 2010-11-20 12:21 87552 ----a-w- c:\windows\system32\wudriver.dll
2011-06-21 11:38 . 2010-11-20 12:18 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-06-21 11:38 . 2010-11-20 12:18 257024 ----a-w- c:\windows\system32\dpx.dll
2011-06-16 01:11 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 01:11 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-16 01:11 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-01 15:21 . 2009-06-22 16:58 89600 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HPZPPLHN.DLL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-26 07:10 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-05-21 17:53 . 2011-05-21 17:53 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-21 17:53 . 2011-05-21 17:53 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-21 17:53 . 2011-05-21 17:53 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-21 17:53 . 2011-05-21 17:53 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-05-21 17:53 . 2011-05-21 17:53 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-05-21 17:53 . 2011-05-21 17:53 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-21 17:53 . 2011-05-21 17:53 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-05-21 17:53 . 2011-05-21 17:53 367104 ----a-w- c:\windows\system32\html.iec
2011-05-21 17:53 . 2011-05-21 17:53 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-05-21 17:53 . 2011-05-21 17:53 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-21 17:53 . 2011-05-21 17:53 203776 ----a-w- c:\windows\system32\webcheck.dll
2011-05-21 17:53 . 2011-05-21 17:53 161792 ----a-w- c:\windows\system32\msls31.dll
2011-05-21 17:53 . 2011-05-21 17:53 152064 ----a-w- c:\windows\system32\wextract.exe
2011-05-21 17:53 . 2011-05-21 17:53 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-05-21 17:53 . 2011-05-21 17:53 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-21 17:53 . 2011-05-21 17:53 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-21 17:53 . 2011-05-21 17:53 11776 ----a-w- c:\windows\system32\mshta.exe
2011-05-21 17:53 . 2011-05-21 17:53 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-05-21 17:53 . 2011-05-21 17:53 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-21 17:53 . 2011-05-21 17:53 101888 ----a-w- c:\windows\system32\admparse.dll
2011-04-22 19:14 . 2011-05-25 19:41 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\system32\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\system32\xlivefnt.dll
2011-04-09 06:02 . 2011-05-11 15:55 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-11 15:55 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-14 05:23 123904 ----a-w- c:\windows\system32\poqexec.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"ICQ"="c:\program files\ICQ7.0\ICQ.exe" [2011-01-05 133432]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-10-24 178712]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.23\RivaTunerWrapper.exe" [2009-02-15 24576]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
c:\users\Chosse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R0 NVStrap;NVStrap; [x]
R1 MpKsl3b3830f4;MpKsl3b3830f4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{556BEC42-05D2-43F6-B478-C93BA2629893}\MpKsl3b3830f4.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-06-26 135664]
R3 cpuz130;cpuz130;c:\users\Chosse\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 RTCore32;RTCore32;c:\program files\RMClock\RTCore32.sys [2005-05-25 4608]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2010-03-11 366840]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-03-29 218592]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-31 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
S1 MpKsld50212ab;MpKsld50212ab;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{556BEC42-05D2-43F6-B478-C93BA2629893}\MpKsld50212ab.sys [x]
S1 TsLwWfF;WiFi Capture Driver;c:\windows\system32\DRIVERS\TsLwWfF.sys [2009-11-12 22632]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 95384]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - MpNWMon
*Deregistered* - NisDrv
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-26 17:40]
.
2011-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-26 17:40]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=101687&l=dis
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 195.113.44.11 195.113.0.2
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.teensnow.com/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=GGSV5&o=101684&locale=en_EU&apn_uid=C0236A17-4B88-45A0-B487-D58AC92BF226&apn_ptnrs=G4&apn_sauid=35F7F58D-C33E-49DD-94DB-F520FD3D302C&apn_dtid=&q=
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Ask Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
FF - Ext: Český validátor kódu: {B6533577-46BD-4520-9FF8-F0513A30C2A3} - %profile%\extensions\{B6533577-46BD-4520-9FF8-F0513A30C2A3}
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-06-27 13:04:31
ComboFix-quarantined-files.txt 2011-06-27 11:04
ComboFix2.txt 2011-06-27 10:32
ComboFix3.txt 2011-06-26 17:05
.
Před spuštěním: Volných bajtů: 82 186 747 904
Po spuštění: Volných bajtů: 82 138 816 512
.
- - End Of File - - D730820C3D4B0F821B7246A9077623CF

Děkuji

ChosseCV
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 27 čer 2011 00:36

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#2 Příspěvek od ChosseCV »

Přikládám ještě RSIT log

Logfile of random's system information tool 1.08 (written by random/random)
Run by Chosse at 2011-06-27 13:35:07
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 78 GB (53%) free of 148 GB
Total RAM: 2046 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:35:31, on 27.6.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Chosse\Desktop\RSIT.exe
C:\Program Files\trend micro\Chosse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=101687&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\20101013165841\ICQToolBar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\20101013165841\ICQToolBar.dll
O3 - Toolbar: Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.23\RivaTunerWrapper.exe" /S
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.0\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 7998 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-06-26 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-09-27 1250696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2011-06-26 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\20101013165841\ICQToolBar.dll [2010-10-04 1049912]
{D5D47440-0750-463D-BAEF-A47D02414806} - Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-06-26 279664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-10-24 178712]
"RivaTunerStartupDaemon"=C:\Program Files\RivaTuner v2.23\RivaTunerWrapper.exe [2009-02-15 24576]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-12 2219184]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"ICQ"=C:\Program Files\ICQ7.0\ICQ.exe [2011-01-05 133432]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

C:\Users\Chosse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-05-21 203776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2011-06-27 13:35:08 ----D---- C:\Program Files\trend micro
2011-06-27 13:35:07 ----D---- C:\rsit
2011-06-27 13:04:33 ----D---- C:\Windows\temp
2011-06-27 13:04:32 ----A---- C:\ComboFix.txt
2011-06-27 13:03:53 ----SHD---- C:\$RECYCLE.BIN
2011-06-26 21:29:05 ----ASH---- C:\pagefile.sys
2011-06-26 19:53:44 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-06-26 19:53:44 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-06-26 19:39:48 ----A---- C:\Windows\BDTSupport.dll
2011-06-26 19:39:47 ----A---- C:\Windows\SGDetectionTool.dll
2011-06-26 19:39:46 ----D---- C:\ProgramData\Google
2011-06-26 19:39:46 ----D---- C:\Program Files\Google
2011-06-26 19:39:46 ----A---- C:\Windows\PCTBDRes.dll
2011-06-26 19:39:46 ----A---- C:\Windows\PCTBDCore.dll
2011-06-26 19:38:59 ----A---- C:\Windows\system32\drivers\pctwfpfilter.sys
2011-06-26 19:38:59 ----A---- C:\Windows\system32\drivers\pctgntdi.sys
2011-06-26 19:38:56 ----A---- C:\Windows\system32\drivers\PCTCore.sys
2011-06-26 19:38:56 ----A---- C:\Windows\system32\drivers\PCTAppEvent.sys
2011-06-26 19:38:52 ----A---- C:\Windows\system32\drivers\pctplsg.sys
2011-06-26 19:38:46 ----D---- C:\Users\Chosse\AppData\Roaming\PC Tools
2011-06-26 19:38:46 ----D---- C:\ProgramData\PC Tools
2011-06-26 19:38:46 ----D---- C:\Program Files\Spyware Doctor
2011-06-26 19:38:46 ----D---- C:\Program Files\Common Files\PC Tools
2011-06-26 19:38:38 ----AD---- C:\ProgramData\TEMP
2011-06-26 18:50:17 ----A---- C:\Windows\zip.exe
2011-06-26 18:50:17 ----A---- C:\Windows\SWSC.exe
2011-06-26 18:50:17 ----A---- C:\Windows\SWREG.exe
2011-06-26 18:50:17 ----A---- C:\Windows\sed.exe
2011-06-26 18:50:17 ----A---- C:\Windows\PEV.exe
2011-06-26 18:50:17 ----A---- C:\Windows\NIRCMD.exe
2011-06-26 18:50:17 ----A---- C:\Windows\MBR.exe
2011-06-26 18:50:17 ----A---- C:\Windows\grep.exe
2011-06-26 18:50:04 ----D---- C:\Windows\ERDNT
2011-06-26 18:49:59 ----D---- C:\Qoobox
2011-06-26 16:51:50 ----D---- C:\Windows\rescache
2011-06-26 13:29:48 ----D---- C:\ProgramData\ESET
2011-06-26 13:29:48 ----D---- C:\Program Files\ESET
2011-06-26 09:05:19 ----D---- C:\Windows\system32\SPReview
2011-06-26 09:04:10 ----D---- C:\Windows\system32\EventProviders
2011-06-26 09:03:49 ----D---- C:\6f4f6007d2f29c0a14a83e1daa974a71
2011-06-21 13:41:29 ----A---- C:\Windows\system32\dfshim.dll
2011-06-21 13:41:25 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2011-06-21 13:41:24 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-06-21 13:41:24 ----A---- C:\Windows\system32\mstscax.dll
2011-06-21 13:41:21 ----A---- C:\Windows\system32\d3d10warp.dll
2011-06-21 13:41:20 ----A---- C:\Windows\system32\mfc40u.dll
2011-06-21 13:41:20 ----A---- C:\Windows\system32\mfc40.dll
2011-06-21 13:41:19 ----A---- C:\Windows\system32\sysmain.dll
2011-06-21 13:41:18 ----A---- C:\Windows\system32\shell32.dll
2011-06-21 13:41:18 ----A---- C:\Windows\system32\secproc_isv.dll
2011-06-21 13:41:17 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-06-21 13:41:16 ----A---- C:\Windows\system32\secproc.dll
2011-06-21 13:41:15 ----A---- C:\Windows\system32\RMActivate.exe
2011-06-21 13:41:14 ----A---- C:\Windows\system32\spwizui.dll
2011-06-21 13:41:14 ----A---- C:\Windows\system32\mscoree.dll
2011-06-21 13:41:13 ----A---- C:\Windows\system32\mf.dll
2011-06-21 13:41:12 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2011-06-21 13:41:12 ----A---- C:\Windows\system32\CertEnroll.dll
2011-06-21 13:41:11 ----A---- C:\Windows\system32\wmp.dll
2011-06-21 13:41:11 ----A---- C:\Windows\system32\mssrch.dll
2011-06-21 13:41:10 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-06-21 13:41:10 ----A---- C:\Windows\system32\PresentationHost.exe
2011-06-21 13:41:10 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2011-06-21 13:41:09 ----A---- C:\Windows\system32\tquery.dll
2011-06-21 13:41:09 ----A---- C:\Windows\system32\schedsvc.dll
2011-06-21 13:41:09 ----A---- C:\Windows\system32\drivers\hwpolicy.sys
2011-06-21 13:41:08 ----A---- C:\Windows\system32\RacEngn.dll
2011-06-21 13:41:07 ----A---- C:\Windows\system32\ntdll.dll
2011-06-21 13:41:07 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2011-06-21 13:41:06 ----A---- C:\Windows\system32\rdpdd.dll
2011-06-21 13:41:05 ----A---- C:\Windows\system32\qmgr.dll
2011-06-21 13:41:05 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-06-21 13:41:04 ----A---- C:\Windows\system32\wevtsvc.dll
2011-06-21 13:41:04 ----A---- C:\Windows\system32\ole32.dll
2011-06-21 13:41:03 ----A---- C:\Windows\system32\vssapi.dll
2011-06-21 13:41:03 ----A---- C:\Windows\system32\SearchFolder.dll
2011-06-21 13:41:03 ----A---- C:\Windows\system32\d3d9.dll
2011-06-21 13:41:02 ----A---- C:\Windows\system32\taskschd.dll
2011-06-21 13:41:02 ----A---- C:\Windows\system32\IKEEXT.DLL
2011-06-21 13:41:01 ----A---- C:\Windows\system32\PushPrinterConnections.exe
2011-06-21 13:41:01 ----A---- C:\Windows\system32\mstsc.exe
2011-06-21 13:41:01 ----A---- C:\Windows\system32\kernel32.dll
2011-06-21 13:41:01 ----A---- C:\Windows\system32\crypt32.dll
2011-06-21 13:41:00 ----A---- C:\Windows\system32\wer.dll
2011-06-21 13:41:00 ----A---- C:\Windows\system32\termsrv.dll
2011-06-21 13:41:00 ----A---- C:\Windows\system32\spreview.exe
2011-06-21 13:41:00 ----A---- C:\Windows\system32\spinstall.exe
2011-06-21 13:41:00 ----A---- C:\Windows\system32\certcli.dll
2011-06-21 13:40:59 ----A---- C:\Windows\system32\rpcrt4.dll
2011-06-21 13:40:59 ----A---- C:\Windows\system32\msxml6.dll
2011-06-21 13:40:59 ----A---- C:\Windows\system32\lsasrv.dll
2011-06-21 13:40:59 ----A---- C:\Windows\system32\gpsvc.dll
2011-06-21 13:40:59 ----A---- C:\Windows\system32\dwmcore.dll
2011-06-21 13:40:58 ----A---- C:\Windows\system32\WinSAT.exe
2011-06-21 13:40:58 ----A---- C:\Windows\system32\wbengine.exe
2011-06-21 13:40:58 ----A---- C:\Windows\system32\scavengeui.dll
2011-06-21 13:40:58 ----A---- C:\Windows\system32\odbc32.dll
2011-06-21 13:40:58 ----A---- C:\Windows\system32\MPSSVC.dll
2011-06-21 13:40:58 ----A---- C:\Windows\system32\diagperf.dll
2011-06-21 13:40:57 ----A---- C:\Windows\system32\umrdp.dll
2011-06-21 13:40:57 ----A---- C:\Windows\system32\TSWorkspace.dll
2011-06-21 13:40:57 ----A---- C:\Windows\system32\tsmf.dll
2011-06-21 13:40:57 ----A---- C:\Windows\system32\quartz.dll
2011-06-21 13:40:57 ----A---- C:\Windows\system32\localspl.dll
2011-06-21 13:40:57 ----A---- C:\Windows\system32\dot3api.dll
2011-06-21 13:40:56 ----A---- C:\Windows\system32\winhttp.dll
2011-06-21 13:40:56 ----A---- C:\Windows\system32\setupapi.dll
2011-06-21 13:40:56 ----A---- C:\Windows\system32\MSVidCtl.dll
2011-06-21 13:40:56 ----A---- C:\Windows\system32\apphelp.dll
2011-06-21 13:40:55 ----A---- C:\Windows\system32\WindowsCodecs.dll
2011-06-21 13:40:55 ----A---- C:\Windows\system32\VSSVC.exe
2011-06-21 13:40:55 ----A---- C:\Windows\system32\netlogon.dll
2011-06-21 13:40:55 ----A---- C:\Windows\system32\netcfgx.dll
2011-06-21 13:40:55 ----A---- C:\Windows\system32\dbgeng.dll
2011-06-21 13:40:55 ----A---- C:\Windows\system32\d3d11.dll
2011-06-21 13:40:54 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-06-21 13:40:54 ----A---- C:\Windows\system32\winlogon.exe
2011-06-21 13:40:54 ----A---- C:\Windows\system32\webio.dll
2011-06-21 13:40:54 ----A---- C:\Windows\system32\user32.dll
2011-06-21 13:40:54 ----A---- C:\Windows\system32\Query.dll
2011-06-21 13:40:54 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2011-06-21 13:40:53 ----A---- C:\Windows\system32\WsmSvc.dll
2011-06-21 13:40:53 ----A---- C:\Windows\system32\upnp.dll
2011-06-21 13:40:53 ----A---- C:\Windows\system32\schannel.dll
2011-06-21 13:40:53 ----A---- C:\Windows\system32\netfxperf.dll
2011-06-21 13:40:53 ----A---- C:\Windows\system32\mmcndmgr.dll
2011-06-21 13:40:53 ----A---- C:\Windows\system32\gpprefcl.dll
2011-06-21 13:40:53 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2011-06-21 13:40:53 ----A---- C:\Windows\system32\advapi32.dll
2011-06-21 13:40:52 ----A---- C:\Windows\system32\msv1_0.dll
2011-06-21 13:40:52 ----A---- C:\Windows\system32\msdrm.dll
2011-06-21 13:40:52 ----A---- C:\Windows\system32\lsm.exe
2011-06-21 13:40:52 ----A---- C:\Windows\system32\imapi2fs.dll
2011-06-21 13:40:52 ----A---- C:\Windows\system32\drivers\csc.sys
2011-06-21 13:40:52 ----A---- C:\Windows\system32\authui.dll
2011-06-21 13:40:51 ----A---- C:\Windows\system32\usp10.dll
2011-06-21 13:40:51 ----A---- C:\Windows\system32\sppobjs.dll
2011-06-21 13:40:51 ----A---- C:\Windows\system32\shlwapi.dll
2011-06-21 13:40:51 ----A---- C:\Windows\system32\SessEnv.dll
2011-06-21 13:40:51 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2011-06-21 13:40:51 ----A---- C:\Windows\system32\mcbuilder.exe
2011-06-21 13:40:51 ----A---- C:\Windows\system32\KernelBase.dll
2011-06-21 13:40:50 ----A---- C:\Windows\system32\xpsservices.dll
2011-06-21 13:40:50 ----A---- C:\Windows\system32\winload.exe
2011-06-21 13:40:50 ----A---- C:\Windows\system32\userenv.dll
2011-06-21 13:40:50 ----A---- C:\Windows\system32\certmgr.dll
2011-06-21 13:40:49 ----A---- C:\Windows\system32\WebClnt.dll
2011-06-21 13:40:49 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-21 13:40:49 ----A---- C:\Windows\system32\sppwinob.dll
2011-06-21 13:40:49 ----A---- C:\Windows\system32\rpcss.dll
2011-06-21 13:40:49 ----A---- C:\Windows\system32\iphlpsvc.dll
2011-06-21 13:40:49 ----A---- C:\Windows\system32\comdlg32.dll
2011-06-21 13:40:49 ----A---- C:\Windows\system32\cmd.exe
2011-06-21 13:40:49 ----A---- C:\Windows\system32\audiosrv.dll
2011-06-21 13:40:48 ----A---- C:\Windows\system32\Wldap32.dll
2011-06-21 13:40:48 ----A---- C:\Windows\system32\win32spl.dll
2011-06-21 13:40:48 ----A---- C:\Windows\system32\rdpendp.dll
2011-06-21 13:40:48 ----A---- C:\Windows\system32\propsys.dll
2011-06-21 13:40:48 ----A---- C:\Windows\system32\nlasvc.dll
2011-06-21 13:40:48 ----A---- C:\Windows\system32\mfds.dll
2011-06-21 13:40:48 ----A---- C:\Windows\system32\framedynos.dll
2011-06-21 13:40:48 ----A---- C:\Windows\system32\drivers\volsnap.sys
2011-06-21 13:40:48 ----A---- C:\Windows\system32\BFE.DLL
2011-06-21 13:40:47 ----A---- C:\Windows\system32\wucltux.dll
2011-06-21 13:40:47 ----A---- C:\Windows\system32\wuaueng.dll
2011-06-21 13:40:47 ----A---- C:\Windows\system32\winresume.exe
2011-06-21 13:40:47 ----A---- C:\Windows\system32\werconcpl.dll
2011-06-21 13:40:47 ----A---- C:\Windows\system32\samsrv.dll
2011-06-21 13:40:47 ----A---- C:\Windows\system32\rdpclip.exe
2011-06-21 13:40:47 ----A---- C:\Windows\system32\profsvc.dll
2011-06-21 13:40:47 ----A---- C:\Windows\system32\ncsi.dll
2011-06-21 13:40:47 ----A---- C:\Windows\system32\drivers\netio.sys
2011-06-21 13:40:47 ----A---- C:\Windows\system32\drivers\ndis.sys
2011-06-21 13:40:47 ----A---- C:\Windows\system32\cscsvc.dll
2011-06-21 13:40:47 ----A---- C:\Windows\system32\azroles.dll
2011-06-21 13:40:46 ----A---- C:\Windows\system32\themeui.dll
2011-06-21 13:40:46 ----A---- C:\Windows\system32\taskeng.exe
2011-06-21 13:40:46 ----A---- C:\Windows\system32\spp.dll
2011-06-21 13:40:46 ----A---- C:\Windows\system32\dhcpcore.dll
2011-06-21 13:40:46 ----A---- C:\Windows\system32\credui.dll
2011-06-21 13:40:46 ----A---- C:\Windows\system32\appmgr.dll
2011-06-21 13:40:45 ----A---- C:\Windows\system32\wintrust.dll
2011-06-21 13:40:45 ----A---- C:\Windows\system32\msxml3.dll
2011-06-21 13:40:45 ----A---- C:\Windows\system32\mswsock.dll
2011-06-21 13:40:45 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-06-21 13:40:45 ----A---- C:\Windows\system32\dxgi.dll
2011-06-21 13:40:45 ----A---- C:\Windows\system32\drivers\http.sys
2011-06-21 13:40:45 ----A---- C:\Windows\system32\dbghelp.dll
2011-06-21 13:40:45 ----A---- C:\Windows\system32\basecsp.dll
2011-06-21 13:40:44 ----A---- C:\Windows\system32\WinSATAPI.dll
2011-06-21 13:40:44 ----A---- C:\Windows\system32\taskcomp.dll
2011-06-21 13:40:44 ----A---- C:\Windows\system32\spoolsv.exe
2011-06-21 13:40:44 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2011-06-21 13:40:44 ----A---- C:\Windows\system32\gdi32.dll
2011-06-21 13:40:44 ----A---- C:\Windows\system32\evr.dll
2011-06-21 13:40:44 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2011-06-21 13:40:43 ----A---- C:\Windows\system32\vpnike.dll
2011-06-21 13:40:43 ----A---- C:\Windows\system32\UIRibbon.dll
2011-06-21 13:40:43 ----A---- C:\Windows\system32\srvsvc.dll
2011-06-21 13:40:43 ----A---- C:\Windows\system32\sqlsrv32.dll
2011-06-21 13:40:43 ----A---- C:\Windows\system32\QAGENTRT.DLL
2011-06-21 13:40:43 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2011-06-21 13:40:43 ----A---- C:\Windows\system32\calc.exe
2011-06-21 13:40:42 ----A---- C:\Windows\system32\lpksetup.exe
2011-06-21 13:40:42 ----A---- C:\Windows\system32\fveapi.dll
2011-06-21 13:40:42 ----A---- C:\Windows\system32\cryptsvc.dll
2011-06-21 13:40:41 ----A---- C:\Windows\system32\ws2_32.dll
2011-06-21 13:40:41 ----A---- C:\Windows\system32\sxs.dll
2011-06-21 13:40:41 ----A---- C:\Windows\system32\stobject.dll
2011-06-21 13:40:41 ----A---- C:\Windows\system32\netshell.dll
2011-06-21 13:40:41 ----A---- C:\Windows\system32\hgprint.dll
2011-06-21 13:40:41 ----A---- C:\Windows\system32\drivers\msdsm.sys
2011-06-21 13:40:41 ----A---- C:\Windows\system32\drivers\fvevol.sys
2011-06-21 13:40:40 ----A---- C:\Windows\system32\prncache.dll
2011-06-21 13:40:40 ----A---- C:\Windows\system32\inetpp.dll
2011-06-21 13:40:40 ----A---- C:\Windows\system32\drivers\rdbss.sys
2011-06-21 13:40:40 ----A---- C:\Windows\system32\comctl32.dll
2011-06-21 13:40:39 ----A---- C:\Windows\system32\printui.dll
2011-06-21 13:40:39 ----A---- C:\Windows\system32\msi.dll
2011-06-21 13:40:38 ----A---- C:\Windows\system32\WSDApi.dll
2011-06-21 13:40:38 ----A---- C:\Windows\system32\wmpeffects.dll
2011-06-21 13:40:38 ----A---- C:\Windows\system32\rpchttp.dll
2011-06-21 13:40:38 ----A---- C:\Windows\system32\net1.exe
2011-06-21 13:40:38 ----A---- C:\Windows\system32\dps.dll
2011-06-21 13:40:38 ----A---- C:\Windows\system32\ci.dll
2011-06-21 13:40:38 ----A---- C:\Windows\system32\aitagent.exe
2011-06-21 13:40:38 ----A---- C:\Windows\system32\aepdu.dll
2011-06-21 13:40:37 ----A---- C:\Windows\system32\vds.exe
2011-06-21 13:40:37 ----A---- C:\Windows\system32\scansetting.dll
2011-06-21 13:40:37 ----A---- C:\Windows\system32\MMDevAPI.dll
2011-06-21 13:40:37 ----A---- C:\Windows\system32\FXSSVC.exe
2011-06-21 13:40:37 ----A---- C:\Windows\system32\drivers\vmbus.sys
2011-06-21 13:40:37 ----A---- C:\Windows\system32\drivers\pci.sys
2011-06-21 13:40:36 ----A---- C:\Windows\system32\WMVCORE.DLL
2011-06-21 13:40:36 ----A---- C:\Windows\system32\wlangpui.dll
2011-06-21 13:40:36 ----A---- C:\Windows\system32\davclnt.dll
2011-06-21 13:40:36 ----A---- C:\Windows\system32\aaclient.dll
2011-06-21 13:40:35 ----A---- C:\Windows\system32\wpdshext.dll
2011-06-21 13:40:35 ----A---- C:\Windows\system32\webservices.dll
2011-06-21 13:40:35 ----A---- C:\Windows\system32\t2embed.dll
2011-06-21 13:40:35 ----A---- C:\Windows\system32\scrptadm.dll
2011-06-21 13:40:35 ----A---- C:\Windows\system32\QSHVHOST.DLL
2011-06-21 13:40:35 ----A---- C:\Windows\system32\pnidui.dll
2011-06-21 13:40:35 ----A---- C:\Windows\system32\IPSECSVC.DLL
2011-06-21 13:40:35 ----A---- C:\Windows\system32\drivers\termdd.sys
2011-06-21 13:40:35 ----A---- C:\Windows\system32\consent.exe
2011-06-21 13:40:34 ----A---- C:\Windows\system32\tscfgwmi.dll
2011-06-21 13:40:34 ----A---- C:\Windows\system32\SyncCenter.dll
2011-06-21 13:40:34 ----A---- C:\Windows\system32\netdiagfx.dll
2011-06-21 13:40:34 ----A---- C:\Windows\system32\fde.dll
2011-06-21 13:40:34 ----A---- C:\Windows\system32\drivers\sbp2port.sys
2011-06-21 13:40:34 ----A---- C:\Windows\system32\drivers\rdpdr.sys
2011-06-21 13:40:33 ----A---- C:\Windows\system32\wuapi.dll
2011-06-21 13:40:33 ----A---- C:\Windows\system32\wscapi.dll
2011-06-21 13:40:33 ----A---- C:\Windows\system32\WinSCard.dll
2011-06-21 13:40:33 ----A---- C:\Windows\system32\vmicsvc.exe
2011-06-21 13:40:33 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2011-06-21 13:40:33 ----A---- C:\Windows\system32\sdengin2.dll
2011-06-21 13:40:33 ----A---- C:\Windows\system32\pla.dll
2011-06-21 13:40:33 ----A---- C:\Windows\system32\cscobj.dll
2011-06-21 13:40:32 ----A---- C:\Windows\system32\wisptis.exe
2011-06-21 13:40:32 ----A---- C:\Windows\system32\winsta.dll
2011-06-21 13:40:32 ----A---- C:\Windows\system32\rdpcore.dll
2011-06-21 13:40:32 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2011-06-21 13:40:32 ----A---- C:\Windows\system32\msasn1.dll
2011-06-21 13:40:32 ----A---- C:\Windows\system32\mcmde.dll
2011-06-21 13:40:32 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2011-06-21 13:40:32 ----A---- C:\Windows\system32\drivers\msahci.sys
2011-06-21 13:40:31 ----A---- C:\Windows\system32\WUDFSvc.dll
2011-06-21 13:40:31 ----A---- C:\Windows\system32\wiaservc.dll
2011-06-21 13:40:31 ----A---- C:\Windows\system32\setupcl.exe
2011-06-21 13:40:31 ----A---- C:\Windows\system32\ntshrui.dll
2011-06-21 13:40:31 ----A---- C:\Windows\system32\imapi2.dll
2011-06-21 13:40:31 ----A---- C:\Windows\system32\gameux.dll
2011-06-21 13:40:31 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2011-06-21 13:40:31 ----A---- C:\Windows\system32\conhost.exe
2011-06-21 13:40:31 ----A---- C:\Windows\system32\aeinv.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\WMPEncEn.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\winmm.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\vaultsvc.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\TabSvc.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\shsvcs.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\rasmans.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\onex.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\mssvp.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\hbaapi.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\dwmredir.dll
2011-06-21 13:40:29 ----A---- C:\Windows\system32\drivers\udfs.sys
2011-06-21 13:40:29 ----A---- C:\Windows\system32\drivers\acpi.sys
2011-06-21 13:40:29 ----A---- C:\Windows\system32\autofmt.exe
2011-06-21 13:40:28 ----A---- C:\Windows\system32\samcli.dll
2011-06-21 13:40:28 ----A---- C:\Windows\system32\netiohlp.dll
2011-06-21 13:40:28 ----A---- C:\Windows\system32\Narrator.exe
2011-06-21 13:40:28 ----A---- C:\Windows\system32\bootres.dll
2011-06-21 13:40:28 ----A---- C:\Windows\system32\autochk.exe
2011-06-21 13:40:28 ----A---- C:\Windows\system32\audiodg.exe
2011-06-21 13:40:27 ----A---- C:\Windows\system32\thumbcache.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\tcpipcfg.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\srchadmin.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\schtasks.exe
2011-06-21 13:40:27 ----A---- C:\Windows\system32\regapi.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\proquota.exe
2011-06-21 13:40:27 ----A---- C:\Windows\system32\powercpl.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\msutb.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\msinfo32.exe
2011-06-21 13:40:27 ----A---- C:\Windows\system32\mimefilt.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\ipsmsnap.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2011-06-21 13:40:27 ----A---- C:\Windows\system32\halmacpi.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\hal.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\framedyn.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\eapphost.dll
2011-06-21 13:40:27 ----A---- C:\Windows\system32\drivers\winusb.sys
2011-06-21 13:40:27 ----A---- C:\Windows\system32\autoconv.exe
2011-06-21 13:40:27 ----A---- C:\Windows\system32\AudioSes.dll
2011-06-21 13:40:26 ----A---- C:\Windows\system32\wcncsvc.dll
2011-06-21 13:40:26 ----A---- C:\Windows\system32\sspicli.dll
2011-06-21 13:40:26 ----A---- C:\Windows\system32\QAGENT.DLL
2011-06-21 13:40:26 ----A---- C:\Windows\system32\netid.dll
2011-06-21 13:40:26 ----A---- C:\Windows\system32\msihnd.dll
2011-06-21 13:40:26 ----A---- C:\Windows\system32\mscorier.dll
2011-06-21 13:40:26 ----A---- C:\Windows\system32\drivers\volmgr.sys
2011-06-21 13:40:26 ----A---- C:\Windows\system32\drivers\partmgr.sys
2011-06-21 13:40:26 ----A---- C:\Windows\system32\drivers\netbt.sys
2011-06-21 13:40:26 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2011-06-21 13:40:25 ----A---- C:\Windows\system32\wdc.dll
2011-06-21 13:40:25 ----A---- C:\Windows\system32\untfs.dll
2011-06-21 13:40:25 ----A---- C:\Windows\system32\umpo.dll
2011-06-21 13:40:25 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-06-21 13:40:25 ----A---- C:\Windows\system32\scesrv.dll
2011-06-21 13:40:25 ----A---- C:\Windows\system32\rastls.dll
2011-06-21 13:40:25 ----A---- C:\Windows\system32\DXP.dll
2011-06-21 13:40:25 ----A---- C:\Windows\system32\actxprxy.dll
2011-06-21 13:40:24 ----A---- C:\Windows\system32\WMNetMgr.dll
2011-06-21 13:40:24 ----A---- C:\Windows\system32\wlanpref.dll
2011-06-21 13:40:24 ----A---- C:\Windows\system32\Vault.dll
2011-06-21 13:40:24 ----A---- C:\Windows\system32\sppsvc.exe
2011-06-21 13:40:24 ----A---- C:\Windows\system32\sdclt.exe
2011-06-21 13:40:24 ----A---- C:\Windows\system32\RpcRtRemote.dll
2011-06-21 13:40:24 ----A---- C:\Windows\system32\nci.dll
2011-06-21 13:40:24 ----A---- C:\Windows\system32\ListSvc.dll
2011-06-21 13:40:24 ----A---- C:\Windows\system32\drivers\ataport.sys
2011-06-21 13:40:23 ----A---- C:\Windows\system32\taskmgr.exe
2011-06-21 13:40:23 ----A---- C:\Windows\system32\Robocopy.exe
2011-06-21 13:40:23 ----A---- C:\Windows\system32\DxpTaskSync.dll
2011-06-21 13:40:23 ----A---- C:\Windows\system32\Display.dll
2011-06-21 13:40:22 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-06-21 13:40:22 ----A---- C:\Windows\system32\userinit.exe
2011-06-21 13:40:22 ----A---- C:\Windows\system32\sharemediacpl.dll
2011-06-21 13:40:22 ----A---- C:\Windows\system32\puiobj.dll
2011-06-21 13:40:22 ----A---- C:\Windows\system32\mtxclu.dll
2011-06-21 13:40:22 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-21 13:40:22 ----A---- C:\Windows\system32\msdri.dll
2011-06-21 13:40:22 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2011-06-21 13:40:22 ----A---- C:\Windows\system32\drivers\mpio.sys
2011-06-21 13:40:22 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2011-06-21 13:40:21 ----A---- C:\Windows\system32\termmgr.dll
2011-06-21 13:40:21 ----A---- C:\Windows\system32\eudcedit.exe
2011-06-21 13:40:21 ----A---- C:\Windows\system32\drivers\winhv.sys
2011-06-21 13:40:21 ----A---- C:\Windows\system32\drivers\scsiport.sys
2011-06-21 13:40:21 ----A---- C:\Windows\system32\DiagCpl.dll
2011-06-21 13:40:21 ----A---- C:\Windows\system32\cscui.dll
2011-06-21 13:40:20 ----A---- C:\Windows\system32\wiadefui.dll
2011-06-21 13:40:20 ----A---- C:\Windows\system32\sppcomapi.dll
2011-06-21 13:40:20 ----A---- C:\Windows\system32\shsetup.dll
2011-06-21 13:40:20 ----A---- C:\Windows\system32\rasppp.dll
2011-06-21 13:40:20 ----A---- C:\Windows\system32\msdtctm.dll
2011-06-21 13:40:20 ----A---- C:\Windows\system32\msconfig.exe
2011-06-21 13:40:20 ----A---- C:\Windows\system32\logoncli.dll
2011-06-21 13:40:20 ----A---- C:\Windows\system32\drivers\vmstorfl.sys
2011-06-21 13:40:20 ----A---- C:\Windows\system32\cabview.dll
2011-06-21 13:40:20 ----A---- C:\Windows\system32\biocpl.dll
2011-06-21 13:40:19 ----A---- C:\Windows\system32\wpccpl.dll
2011-06-21 13:40:19 ----A---- C:\Windows\system32\themecpl.dll
2011-06-21 13:40:19 ----A---- C:\Windows\system32\SensorsCpl.dll
2011-06-21 13:40:19 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2011-06-21 13:40:19 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2011-06-21 13:40:19 ----A---- C:\Windows\system32\drivers\storvsc.sys
2011-06-21 13:40:18 ----A---- C:\Windows\system32\hgcpl.dll
2011-06-21 13:40:18 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2011-06-21 13:40:18 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-06-21 13:40:18 ----A---- C:\Windows\system32\dnscmmc.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\wlanui.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\wkssvc.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\winsrv.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\usercpl.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\tapisrv.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\srcore.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\SndVolSSO.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\scecli.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\mscories.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\mscms.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\mprddm.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\localsec.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\KMSVC.DLL
2011-06-21 13:40:17 ----A---- C:\Windows\system32\iasacct.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\fontext.dll
2011-06-21 13:40:17 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2011-06-21 13:40:17 ----A---- C:\Windows\system32\bcdsrv.dll
2011-06-21 13:40:16 ----A---- C:\Windows\system32\w32tm.exe
2011-06-21 13:40:16 ----A---- C:\Windows\system32\VAN.dll
2011-06-21 13:40:16 ----A---- C:\Windows\system32\SndVol.exe
2011-06-21 13:40:16 ----A---- C:\Windows\system32\qedit.dll
2011-06-21 13:40:16 ----A---- C:\Windows\system32\qdvd.dll
2011-06-21 13:40:16 ----A---- C:\Windows\system32\prntvpt.dll
2011-06-21 13:40:16 ----A---- C:\Windows\system32\netcenter.dll
2011-06-21 13:40:16 ----A---- C:\Windows\system32\mblctr.exe
2011-06-21 13:40:16 ----A---- C:\Windows\system32\batmeter.dll
2011-06-21 13:40:15 ----A---- C:\Windows\system32\zipfldr.dll
2011-06-21 13:40:15 ----A---- C:\Windows\system32\wpdbusenum.dll
2011-06-21 13:40:15 ----A---- C:\Windows\system32\wksprt.exe
2011-06-21 13:40:15 ----A---- C:\Windows\system32\spwizeng.dll
2011-06-21 13:40:15 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2011-06-21 13:40:15 ----A---- C:\Windows\system32\fdeploy.dll
2011-06-21 13:40:15 ----A---- C:\Windows\system32\drivers\ks.sys
2011-06-21 13:40:15 ----A---- C:\Windows\system32\azroleui.dll
2011-06-21 13:40:15 ----A---- C:\Windows\system32\accessibilitycpl.dll
2011-06-21 13:40:14 ----A---- C:\Windows\system32\wusa.exe
2011-06-21 13:40:14 ----A---- C:\Windows\system32\networkmap.dll
2011-06-21 13:40:14 ----A---- C:\Windows\system32\netjoin.dll
2011-06-21 13:40:14 ----A---- C:\Windows\system32\mspbda.dll
2011-06-21 13:40:14 ----A---- C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2011-06-21 13:40:14 ----A---- C:\Windows\system32\Faultrep.dll
2011-06-21 13:40:14 ----A---- C:\Windows\system32\cryptui.dll
2011-06-21 13:40:14 ----A---- C:\Windows\system32\adsldp.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\taskbarcpl.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\sud.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\slui.exe
2011-06-21 13:40:13 ----A---- C:\Windows\system32\prnfldr.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\photowiz.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\OnLineIDCpl.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\msieftp.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\credssp.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\cfgmgr32.dll
2011-06-21 13:40:13 ----A---- C:\Windows\system32\ActionCenter.dll
2011-06-21 13:40:12 ----A---- C:\Windows\system32\taskhost.exe
2011-06-21 13:40:12 ----A---- C:\Windows\system32\rdpcorekmts.dll
2011-06-21 13:40:12 ----A---- C:\Windows\system32\iprtrmgr.dll
2011-06-21 13:40:12 ----A---- C:\Windows\system32\iasrad.dll
2011-06-21 13:40:12 ----A---- C:\Windows\system32\halacpi.dll
2011-06-21 13:40:12 ----A---- C:\Windows\system32\ftp.exe
2011-06-21 13:40:12 ----A---- C:\Windows\system32\drivers\hidclass.sys
2011-06-21 13:40:12 ----A---- C:\Windows\system32\dot3cfg.dll
2011-06-21 13:40:12 ----A---- C:\Windows\system32\defaultlocationcpl.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\wpd_ci.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\syncui.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\sisbkup.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\shwebsvc.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\sdcpl.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\recovery.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\rdpwsx.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\odbcjt32.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\ifsutil.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\fsquirt.exe
2011-06-21 13:40:11 ----A---- C:\Windows\system32\efscore.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\bcdedit.exe
2011-06-21 13:40:11 ----A---- C:\Windows\system32\autoplay.dll
2011-06-21 13:40:11 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2011-06-21 13:40:10 ----A---- C:\Windows\system32\wmpmde.dll
2011-06-21 13:40:10 ----A---- C:\Windows\system32\sppnp.dll
2011-06-21 13:40:10 ----A---- C:\Windows\system32\rtutils.dll
2011-06-21 13:40:10 ----A---- C:\Windows\system32\ntlanman.dll
2011-06-21 13:40:10 ----A---- C:\Windows\system32\dskquoui.dll
2011-06-21 13:40:10 ----A---- C:\Windows\system32\DeviceCenter.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\vdsutil.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\systemcpl.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\sethc.exe
2011-06-21 13:40:09 ----A---- C:\Windows\system32\rstrui.exe
2011-06-21 13:40:09 ----A---- C:\Windows\system32\riched20.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\recdisc.exe
2011-06-21 13:40:09 ----A---- C:\Windows\system32\OobeFldr.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\ntprint.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\nshwfp.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\drivers\tdx.sys
2011-06-21 13:40:09 ----A---- C:\Windows\system32\blackbox.dll
2011-06-21 13:40:09 ----A---- C:\Windows\system32\bcdboot.exe
2011-06-21 13:40:09 ----A---- C:\Windows\system32\AxInstSv.dll
2011-06-21 13:40:08 ----A---- C:\Windows\system32\wmpsrcwp.dll
2011-06-21 13:40:08 ----A---- C:\Windows\system32\netplwiz.dll
2011-06-21 13:40:08 ----A---- C:\Windows\system32\NAPHLPR.DLL
2011-06-21 13:40:08 ----A---- C:\Windows\system32\migisol.dll
2011-06-21 13:40:08 ----A---- C:\Windows\system32\fms.dll
2011-06-21 13:40:08 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2011-06-21 13:40:08 ----A---- C:\Windows\system32\activeds.dll
2011-06-21 13:40:07 ----A---- C:\Windows\system32\wsqmcons.exe
2011-06-21 13:40:07 ----A---- C:\Windows\system32\nshipsec.dll
2011-06-21 13:40:07 ----A---- C:\Windows\system32\nlaapi.dll
2011-06-21 13:40:07 ----A---- C:\Windows\system32\msftedit.dll
2011-06-21 13:40:07 ----A---- C:\Windows\system32\isoburn.exe
2011-06-21 13:40:07 ----A---- C:\Windows\system32\httpapi.dll
2011-06-21 13:40:07 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2011-06-21 13:40:07 ----A---- C:\Windows\system32\dot3svc.dll
2011-06-21 13:40:07 ----A---- C:\Windows\system32\cdosys.dll
2011-06-21 13:40:07 ----A---- C:\Windows\system32\asycfilt.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\wvc.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\wuwebv.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\wtsapi32.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\wlanmsm.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\wimgapi.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\wavemsp.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\tzutil.exe
2011-06-21 13:40:06 ----A---- C:\Windows\system32\sysclass.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\ReAgent.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\provsvc.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\ocsetup.exe
2011-06-21 13:40:06 ----A---- C:\Windows\system32\dsuiext.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\drivers\ndproxy.sys
2011-06-21 13:40:06 ----A---- C:\Windows\system32\dot3ui.dll
2011-06-21 13:40:06 ----A---- C:\Windows\system32\dfrgui.exe
2011-06-21 13:40:06 ----A---- C:\Windows\system32\appinfo.dll
2011-06-21 13:40:05 ----A---- C:\Windows\twain_32.dll
2011-06-21 13:40:05 ----A---- C:\Windows\system32\twext.dll
2011-06-21 13:40:05 ----A---- C:\Windows\system32\shdocvw.dll
2011-06-21 13:40:05 ----A---- C:\Windows\system32\setupugc.exe
2011-06-21 13:40:05 ----A---- C:\Windows\system32\qcap.dll
2011-06-21 13:40:05 ----A---- C:\Windows\system32\qasf.dll
2011-06-21 13:40:05 ----A---- C:\Windows\system32\mstask.dll
2011-06-21 13:40:05 ----A---- C:\Windows\system32\certprop.dll
2011-06-21 13:40:05 ----A---- C:\Windows\system32\AdmTmpl.dll
2011-06-21 13:40:04 ----A---- C:\Windows\system32\wwanconn.dll
2011-06-21 13:40:04 ----A---- C:\Windows\system32\uxlib.dll
2011-06-21 13:40:04 ----A---- C:\Windows\system32\srrstr.dll
2011-06-21 13:40:04 ----A---- C:\Windows\system32\slwga.dll
2011-06-21 13:40:04 ----A---- C:\Windows\system32\PresentationSettings.exe
2011-06-21 13:40:04 ----A---- C:\Windows\system32\msvfw32.dll
2011-06-21 13:40:04 ----A---- C:\Windows\system32\imm32.dll
2011-06-21 13:40:03 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2011-06-21 13:40:03 ----A---- C:\Windows\system32\wmdrmsdk.dll
2011-06-21 13:40:03 ----A---- C:\Windows\system32\nslookup.exe
2011-06-21 13:40:03 ----A---- C:\Windows\system32\msscp.dll
2011-06-21 13:40:03 ----A---- C:\Windows\system32\mciavi32.dll
2011-06-21 13:40:03 ----A---- C:\Windows\system32\diskraid.exe
2011-06-21 13:40:03 ----A---- C:\Windows\system32\DevicePairingFolder.dll
2011-06-21 13:40:03 ----A---- C:\Windows\system32\clusapi.dll
2011-06-21 13:40:03 ----A---- C:\Windows\system32\audiodev.dll
2011-06-21 13:40:02 ----A---- C:\Windows\system32\wimserv.exe
2011-06-21 13:40:02 ----A---- C:\Windows\system32\TSpkg.dll
2011-06-21 13:40:02 ----A---- C:\Windows\system32\remotepg.dll
2011-06-21 13:40:02 ----A---- C:\Windows\system32\rdpencom.dll
2011-06-21 13:40:02 ----A---- C:\Windows\system32\raschap.dll
2011-06-21 13:40:02 ----A---- C:\Windows\system32\QUTIL.DLL
2011-06-21 13:40:02 ----A---- C:\Windows\system32\perfmon.exe
2011-06-21 13:40:02 ----A---- C:\Windows\system32\NAPCRYPT.DLL
2011-06-21 13:40:02 ----A---- C:\Windows\system32\input.dll
2011-06-21 13:40:02 ----A---- C:\Windows\system32\drmmgrtn.dll
2011-06-21 13:40:02 ----A---- C:\Windows\system32\browser.dll
2011-06-21 13:40:02 ----A---- C:\Windows\system32\acppage.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\wpdwcn.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\wmpdxm.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2011-06-21 13:40:01 ----A---- C:\Windows\system32\vpnikeapi.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\vdsbas.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\UserAccountControlSettings.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\sdrsvc.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\runonce.exe
2011-06-21 13:40:01 ----A---- C:\Windows\system32\onexui.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\olepro32.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\odbccp32.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\ocsetapi.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\nltest.exe
2011-06-21 13:40:01 ----A---- C:\Windows\system32\networkexplorer.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\iTVData.dll
2011-06-21 13:40:01 ----A---- C:\Windows\system32\dxdiagn.dll
2011-06-21 13:40:01 ----A---- C:\Windows\bfsvc.exe
2011-06-21 13:40:00 ----A---- C:\Windows\system32\sspisrv.dll
2011-06-21 13:40:00 ----A---- C:\Windows\system32\msvidc32.dll
2011-06-21 13:40:00 ----A---- C:\Windows\system32\MFPlay.dll
2011-06-21 13:40:00 ----A---- C:\Windows\system32\Mcx2Svc.dll
2011-06-21 13:40:00 ----A---- C:\Windows\system32\logagent.exe
2011-06-21 13:40:00 ----A---- C:\Windows\system32\drivers\sdbus.sys
2011-06-21 13:39:59 ----A---- C:\Windows\system32\wudriver.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\wmpshell.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\wmdrmdev.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\unimdmat.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\shacct.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\PnPUnattend.exe
2011-06-21 13:39:59 ----A---- C:\Windows\system32\msiexec.exe
2011-06-21 13:39:59 ----A---- C:\Windows\system32\lsmproxy.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\iscsium.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\eapp3hst.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\drivers\rmcast.sys
2011-06-21 13:39:59 ----A---- C:\Windows\system32\d3d10level9.dll
2011-06-21 13:39:59 ----A---- C:\Windows\system32\bitsadmin.exe
2011-06-21 13:39:58 ----A---- C:\Windows\system32\WUDFPlatform.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\WPDSp.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\tabcal.exe
2011-06-21 13:39:58 ----A---- C:\Windows\system32\srvcli.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\sqlcese30.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\rdpd3d.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\PortableDeviceSyncProvider.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\pdh.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\OpcServices.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\olethk32.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\ncryptui.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\mprapi.dll
2011-06-21 13:39:58 ----A---- C:\Windows\system32\logman.exe
2011-06-21 13:39:58 ----A---- C:\Windows\system32\djoin.exe
2011-06-21 13:39:58 ----A---- C:\Windows\system32\cscapi.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\wwanprotdim.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\WMPhoto.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\WMADMOD.DLL
2011-06-21 13:39:57 ----A---- C:\Windows\system32\utildll.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\tsgqec.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\QSVRMGMT.DLL
2011-06-21 13:39:57 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\odbctrac.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\MdSched.exe
2011-06-21 13:39:57 ----A---- C:\Windows\system32\mapistub.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\mapi32.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\lpremove.exe
2011-06-21 13:39:57 ----A---- C:\Windows\system32\fphc.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\dot3msm.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\CscMig.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\avifil32.dll
2011-06-21 13:39:57 ----A---- C:\Windows\system32\ActionQueue.dll
2011-06-21 13:39:56 ----A---- C:\Windows\system32\WMVSDECD.DLL
2011-06-21 13:39:56 ----A---- C:\Windows\system32\wmdrmnet.dll
2011-06-21 13:39:56 ----A---- C:\Windows\system32\WindowsAnytimeUpgrade.exe
2011-06-21 13:39:56 ----A---- C:\Windows\system32\wiavideo.dll
2011-06-21 13:39:56 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2011-06-21 13:39:56 ----A---- C:\Windows\system32\takeown.exe
2011-06-21 13:39:56 ----A---- C:\Windows\system32\sqmapi.dll
2011-06-21 13:39:56 ----A---- C:\Windows\system32\qdv.dll
2011-06-21 13:39:56 ----A---- C:\Windows\system32\msnetobj.dll
2011-06-21 13:39:56 ----A---- C:\Windows\system32\iyuv_32.dll
2011-06-21 13:39:56 ----A---- C:\Windows\system32\imagehlp.dll
2011-06-21 13:39:56 ----A---- C:\Windows\system32\EhStorAPI.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\WUDFx.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\WUDFHost.exe
2011-06-21 13:39:55 ----A---- C:\Windows\system32\wsnmp32.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\vfwwdm32.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\unattend.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\sppinst.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\RelPost.exe
2011-06-21 13:39:55 ----A---- C:\Windows\system32\qprocess.exe
2011-06-21 13:39:55 ----A---- C:\Windows\system32\QCLIPROV.DLL
2011-06-21 13:39:55 ----A---- C:\Windows\system32\pdhui.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\MuiUnattend.exe
2011-06-21 13:39:55 ----A---- C:\Windows\system32\msyuv.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\msrle32.dll
2011-06-21 13:39:55 ----A---- C:\Windows\system32\cmstp.exe
2011-06-21 13:39:55 ----A---- C:\Windows\system32\cca.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\wuauclt.exe
2011-06-21 13:39:54 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2011-06-21 13:39:54 ----A---- C:\Windows\system32\WavDest.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\umb.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\tsbyuv.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\setupcln.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\relog.exe
2011-06-21 13:39:54 ----A---- C:\Windows\system32\qwinsta.exe
2011-06-21 13:39:54 ----A---- C:\Windows\system32\PrintIsolationProxy.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\netiougc.exe
2011-06-21 13:39:54 ----A---- C:\Windows\system32\msorcl32.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\msg.exe
2011-06-21 13:39:54 ----A---- C:\Windows\system32\iscsicli.exe
2011-06-21 13:39:54 ----A---- C:\Windows\system32\iasrecst.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\chglogon.exe
2011-06-21 13:39:54 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2011-06-21 13:39:54 ----A---- C:\Windows\system32\drivers\ndisuio.sys
2011-06-21 13:39:54 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-06-21 13:39:54 ----A---- C:\Windows\system32\basesrv.dll
2011-06-21 13:39:54 ----A---- C:\Windows\system32\AzSqlExt.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\wkscli.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\syssetup.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\sppuinotify.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\spbcd.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\setbcdlocale.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\secproc_ssp.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\resutils.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\rastapi.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\quser.exe
2011-06-21 13:39:53 ----A---- C:\Windows\system32\nrpsrv.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\netbtugc.exe
2011-06-21 13:39:53 ----A---- C:\Windows\system32\mydocs.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\MultiDigiMon.exe
2011-06-21 13:39:53 ----A---- C:\Windows\system32\itircl.dll
2011-06-21 13:39:53 ----A---- C:\Windows\system32\diskpart.exe
2011-06-21 13:39:53 ----A---- C:\Windows\system32\amstream.dll
2011-06-21 13:39:52 ----A---- C:\Windows\system32\wuapp.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\wmpps.dll
2011-06-21 13:39:52 ----A---- C:\Windows\system32\WerFaultSecure.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\tsdiscon.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\tscon.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\secur32.dll
2011-06-21 13:39:52 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\ReAgentc.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\qappsrv.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\PrintBrmUi.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\chgusr.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\chgport.exe
2011-06-21 13:39:52 ----A---- C:\Windows\system32\FXSTIFF.dll
2011-06-21 13:39:52 ----A---- C:\Windows\system32\eappgnui.dll
2011-06-21 13:39:52 ----A---- C:\Windows\system32\CertPolEng.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\wiarpc.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\tskill.exe
2011-06-21 13:39:51 ----A---- C:\Windows\system32\tlscsp.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\sppc.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\spopk.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\shimgvw.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\shadow.exe
2011-06-21 13:39:51 ----A---- C:\Windows\system32\rwinsta.exe
2011-06-21 13:39:51 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2011-06-21 13:39:51 ----A---- C:\Windows\system32\netutils.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\netapi32.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\muifontsetup.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\mobsync.exe
2011-06-21 13:39:51 ----A---- C:\Windows\system32\mciqtz32.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\logoff.exe
2011-06-21 13:39:51 ----A---- C:\Windows\system32\iccvid.dll
2011-06-21 13:39:51 ----A---- C:\Windows\system32\findstr.exe
2011-06-21 13:39:51 ----A---- C:\Windows\system32\drivers\tdi.sys
2011-06-21 13:39:51 ----A---- C:\Windows\system32\dosx.exe
2011-06-21 13:39:51 ----A---- C:\Windows\system32\cabinet.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\wdiasqmmodule.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\vmstorfltres.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\vmicres.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\unlodctr.exe
2011-06-21 13:39:50 ----A---- C:\Windows\system32\reset.exe
2011-06-21 13:39:50 ----A---- C:\Windows\system32\repair-bde.exe
2011-06-21 13:39:50 ----A---- C:\Windows\system32\rdprefdrvapi.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\query.exe
2011-06-21 13:39:50 ----A---- C:\Windows\system32\netcfg.exe
2011-06-21 13:39:50 ----A---- C:\Windows\system32\msdmo.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\manage-bde.exe
2011-06-21 13:39:50 ----A---- C:\Windows\system32\luainstall.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\inetmib1.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\HotStartUserAgent.dll
2011-06-21 13:39:50 ----A---- C:\Windows\system32\drivers\usbrpm.sys
2011-06-21 13:39:50 ----A---- C:\Windows\system32\drivers\CompositeBus.sys
2011-06-21 13:39:49 ----A---- C:\Windows\system32\wups.dll
2011-06-21 13:39:49 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2011-06-21 13:39:49 ----A---- C:\Windows\system32\vmbusres.dll
2011-06-21 13:39:49 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-06-21 13:39:49 ----A---- C:\Windows\system32\profprov.dll
2011-06-21 13:39:49 ----A---- C:\Windows\system32\perfts.dll
2011-06-21 13:39:49 ----A---- C:\Windows\system32\odbcconf.dll
2011-06-21 13:39:49 ----A---- C:\Windows\system32\change.exe
2011-06-21 13:39:49 ----A---- C:\Windows\system32\drivers\cdrom.sys
2011-06-21 13:39:49 ----A---- C:\Windows\system32\browcli.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\wshbth.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\TRAPI.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\schedcli.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\RDPENCDD.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\napdsnap.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\icaapi.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\FXSMON.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\elsTrans.dll
2011-06-21 13:39:48 ----A---- C:\Windows\system32\drivers\tunnel.sys
2011-06-21 13:39:48 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-21 13:39:48 ----A---- C:\Windows\system32\bitsperf.dll
2011-06-21 13:39:47 ----A---- C:\Windows\system32\wsdchngr.dll
2011-06-21 13:39:47 ----A---- C:\Windows\system32\sscore.dll
2011-06-21 13:39:47 ----A---- C:\Windows\system32\LogonUI.exe
2011-06-21 13:39:47 ----A---- C:\Windows\system32\dsauth.dll
2011-06-21 13:39:47 ----A---- C:\Windows\system32\drivers\acpipmi.sys
2011-06-21 13:39:47 ----A---- C:\Windows\system32\cscdll.dll
2011-06-21 13:39:46 ----A---- C:\Windows\system32\wups2.dll
2011-06-21 13:39:46 ----A---- C:\Windows\system32\shgina.dll
2011-06-21 13:39:46 ----A---- C:\Windows\system32\riched32.dll
2011-06-21 13:39:46 ----A---- C:\Windows\system32\rdpcfgex.dll
2011-06-21 13:39:46 ----A---- C:\Windows\system32\drivers\VMBusHID.sys
2011-06-21 13:39:46 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2011-06-21 13:39:46 ----A---- C:\Windows\system32\drivers\hidusb.sys
2011-06-21 13:39:46 ----A---- C:\Windows\system32\drivers\appid.sys
2011-06-21 13:39:45 ----A---- C:\Windows\system32\wshirda.dll
2011-06-21 13:39:45 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2011-06-21 13:39:45 ----A---- C:\Windows\system32\drivers\usbser.sys
2011-06-21 13:39:45 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2011-06-21 13:39:44 ----A---- C:\Windows\system32\VmdCoinstall.dll
2011-06-21 13:39:44 ----A---- C:\Windows\system32\vmbuspipe.dll
2011-06-21 13:39:44 ----A---- C:\Windows\system32\VmbusCoinstaller.dll
2011-06-21 13:39:44 ----A---- C:\Windows\system32\spwmp.dll
2011-06-21 13:39:44 ----A---- C:\Windows\system32\IcCoinstall.dll
2011-06-21 13:39:44 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2011-06-21 13:39:44 ----A---- C:\Windows\system32\drivers\USBCAMD.sys
2011-06-21 13:39:44 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2011-06-21 13:39:44 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2011-06-21 13:39:44 ----A---- C:\Windows\system32\browseui.dll
2011-06-21 13:39:43 ----A---- C:\Windows\system32\shunimpl.dll
2011-06-21 13:39:43 ----A---- C:\Windows\system32\RDPREFDD.dll
2011-06-21 13:39:43 ----A---- C:\Windows\system32\dxmasf.dll
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\wanarp.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\umbus.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\tdpipe.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\scfilter.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\RDPCDD.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2011-06-21 13:39:43 ----A---- C:\Windows\system32\C_ISCII.DLL
2011-06-21 13:39:42 ----A---- C:\Windows\system32\wmploc.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\tzres.dll
2011-06-21 13:39:41 ----A---- C:\Windows\system32\spwizres.dll
2011-06-21 13:39:41 ----A---- C:\Windows\system32\pifmgr.dll
2011-06-21 13:39:41 ----A---- C:\Windows\system32\nlsbres.dll
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDUS.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDUGHR1.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDTURME.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDTUQ.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDTUF.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDTAJIK.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDSG.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDSF.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDPO.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDNEPR.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDMON.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDMAORI.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDLT1.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\kbdlk41a.dll
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDINTEL.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDINTAM.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDINORI.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDINMAR.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDINKAN.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDINHIN.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDINBEN.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDGR1.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDGKL.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDGEO.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDCZ1.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDBULG.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDBLR.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\KBDBASH.DLL
2011-06-21 13:39:41 ----A---- C:\Windows\system32\drivers\vms3cap.sys
2011-06-21 13:39:41 ----A---- C:\Windows\system32\dpnaddr.dll
2011-06-21 13:39:41 ----A---- C:\Windows\system32\BlbEvents.dll
2011-06-21 13:39:19 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-06-21 13:39:19 ----A---- C:\Windows\system32\wbemcomn.dll
2011-06-21 13:39:10 ----A---- C:\Windows\system32\SmiEngine.dll
2011-06-21 13:39:04 ----A---- C:\Windows\system32\wdscore.dll
2011-06-21 13:39:04 ----A---- C:\Windows\system32\PkgMgr.exe
2011-06-21 13:38:33 ----A---- C:\Windows\system32\drvstore.dll
2011-06-21 13:38:33 ----A---- C:\Windows\system32\dpx.dll
2011-06-16 03:11:28 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-16 03:11:27 ----A---- C:\Windows\system32\jscript9.dll
2011-06-16 03:11:27 ----A---- C:\Windows\system32\jscript.dll
2011-06-16 03:11:27 ----A---- C:\Windows\system32\ieui.dll
2011-06-16 03:11:27 ----A---- C:\Windows\system32\iertutil.dll
2011-06-16 03:11:25 ----A---- C:\Windows\system32\mshtml.dll
2011-06-16 03:11:25 ----A---- C:\Windows\system32\ieframe.dll
2011-06-16 03:11:24 ----A---- C:\Windows\system32\urlmon.dll
2011-06-15 19:48:43 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-15 19:48:42 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-15 19:48:42 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-15 19:48:32 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-15 19:48:32 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-15 19:48:32 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-15 19:48:26 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-15 19:48:26 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2011-06-15 19:48:26 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-15 19:48:20 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-15 19:48:17 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-15 19:48:16 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-06-15 19:48:16 ----A---- C:\Windows\system32\d3d10_1.dll

======List of files/folders modified in the last 1 months======

2011-06-27 13:35:08 ----RD---- C:\Program Files
2011-06-27 13:05:03 ----SHD---- C:\Windows\Installer
2011-06-27 13:04:33 ----D---- C:\Windows
2011-06-27 13:01:46 ----A---- C:\Windows\system.ini
2011-06-27 12:56:48 ----D---- C:\Windows\system32\drivers
2011-06-27 12:56:48 ----D---- C:\Windows\AppPatch
2011-06-27 12:56:48 ----AD---- C:\Windows\System32
2011-06-27 12:56:44 ----D---- C:\Program Files\Common Files
2011-06-27 12:52:44 ----D---- C:\Windows\system32\config
2011-06-27 12:46:43 ----D---- C:\Windows\inf
2011-06-27 12:46:31 ----HD---- C:\Windows\system32\GroupPolicy
2011-06-27 12:08:37 ----D---- C:\Windows\Prefetch
2011-06-27 12:08:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-27 12:06:02 ----D---- C:\Users\Chosse\AppData\Roaming\ICQ
2011-06-27 12:02:54 ----D---- C:\ProgramData\NVIDIA
2011-06-26 23:49:21 ----D---- C:\Windows\Microsoft.NET
2011-06-26 23:34:25 ----RSD---- C:\Windows\assembly
2011-06-26 22:38:39 ----D---- C:\Windows\system32\Tasks
2011-06-26 22:37:20 ----D---- C:\Windows\winsxs
2011-06-26 22:11:12 ----D---- C:\Windows\system32\catroot
2011-06-26 22:10:40 ----SD---- C:\ProgramData\Microsoft
2011-06-26 22:09:15 ----SHD---- C:\System Volume Information
2011-06-26 22:08:26 ----D---- C:\Windows\system32\catroot2
2011-06-26 21:32:18 ----D---- C:\Fraps
2011-06-26 21:32:18 ----D---- C:\Fraos
2011-06-26 20:56:13 ----D---- C:\ProgramData
2011-06-26 19:40:20 ----D---- C:\Windows\Tasks
2011-06-26 19:03:16 ----D---- C:\Windows\system32\drivers\etc
2011-06-26 13:30:21 ----D---- C:\Windows\system32\DriverStore
2011-06-26 13:10:34 ----D---- C:\Windows\system32\sysprep
2011-06-26 12:47:13 ----D---- C:\Boot
2011-06-26 12:41:30 ----D---- C:\Program Files\Windows Sidebar
2011-06-26 12:41:30 ----D---- C:\Program Files\Windows Portable Devices
2011-06-26 12:41:30 ----D---- C:\Program Files\Windows Photo Viewer
2011-06-26 12:41:30 ----D---- C:\Program Files\Windows Media Player
2011-06-26 12:41:30 ----D---- C:\Program Files\Windows Mail
2011-06-26 12:41:30 ----D---- C:\Program Files\Windows Journal
2011-06-26 12:41:30 ----D---- C:\Program Files\Internet Explorer
2011-06-26 12:41:30 ----D---- C:\Program Files\DVD Maker
2011-06-26 12:41:29 ----D---- C:\Windows\servicing
2011-06-26 12:41:29 ----D---- C:\Windows\ehome
2011-06-26 12:41:29 ----D---- C:\Program Files\Windows Defender
2011-06-26 12:41:26 ----D---- C:\Windows\system32\Setup
2011-06-26 12:41:26 ----D---- C:\Windows\system32\oobe
2011-06-26 12:41:26 ----D---- C:\Windows\system32\migration
2011-06-26 12:41:26 ----D---- C:\Windows\system32\en-US
2011-06-26 12:41:26 ----D---- C:\Windows\system32\da-DK
2011-06-26 12:41:26 ----D---- C:\Windows\system32\cs-CZ
2011-06-26 12:41:26 ----D---- C:\Windows\system32\cs
2011-06-26 12:41:26 ----D---- C:\Windows\system32\AdvancedInstallers
2011-06-26 12:41:26 ----D---- C:\Windows\PolicyDefinitions
2011-06-26 12:41:25 ----D---- C:\Windows\system32\wbem
2011-06-26 12:41:25 ----D---- C:\Windows\system32\sppui
2011-06-26 12:41:25 ----D---- C:\Windows\system32\migwiz
2011-06-26 12:41:25 ----D---- C:\Windows\system32\manifeststore
2011-06-26 12:41:25 ----D---- C:\Windows\system32\es-ES
2011-06-26 12:41:25 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-06-26 12:41:25 ----D---- C:\Windows\system32\Dism
2011-06-26 12:41:19 ----RSD---- C:\Windows\Fonts
2011-06-26 12:41:12 ----D---- C:\Windows\system32\Boot
2011-06-26 12:40:35 ----D---- C:\Windows\system32\drivers\UMDF
2011-06-26 09:10:46 ----A---- C:\Windows\system32\msclmd.dll
2011-06-24 13:27:43 ----D---- C:\Users\Chosse\AppData\Roaming\Skype
2011-06-24 11:10:38 ----D---- C:\Users\Chosse\AppData\Roaming\skypePM
2011-06-16 03:34:34 ----D---- C:\Program Files\Microsoft Silverlight
2011-06-16 03:16:52 ----D---- C:\ProgramData\Microsoft Help
2011-06-16 03:14:03 ----A---- C:\Windows\system32\MRT.exe
2011-06-13 15:26:24 ----D---- C:\Windows\system32\NDF
2011-06-05 20:56:01 ----D---- C:\Program Files\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-09-30 308248]
R0 PCTCore;PCTools KDS; C:\Windows\system32\drivers\PCTCore.sys [2010-03-29 218592]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-01-31 691696]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
R1 MpKsld50212ab;MpKsld50212ab; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{556BEC42-05D2-43F6-B478-C93BA2629893}\MpKsld50212ab.sys []
R1 TsLwWfF;WiFi Capture Driver; C:\Windows\system32\DRIVERS\TsLwWfF.sys [2009-11-12 22632]
R2 cpuz132;cpuz132; \??\C:\Windows\system32\drivers\cpuz132_x32.sys [2009-03-27 12672]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 95384]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-14 1035776]
R3 catchme;catchme; \??\C:\Users\Chosse\AppData\Local\Temp\catchme.sys []
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20); C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-07-14 47104]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]
S0 NVStrap;NVStrap; C:\Windows\system32\drivers\NVStrap.sys [2009-02-15 4224]
S1 MpKsl3b3830f4;MpKsl3b3830f4; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{556BEC42-05D2-43F6-B478-C93BA2629893}\MpKsl3b3830f4.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 adtuk3ox;adtuk3ox; C:\Windows\system32\drivers\adtuk3ox.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
S3 cpuz130;cpuz130; \??\C:\Users\Chosse\AppData\Local\Temp\cpuz130\cpuz_x32.sys []
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2007-08-20 27672]
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\nmwcd.sys [2007-06-28 137216]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2008-05-02 20864]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RivaTuner32;RivaTuner32; \??\C:\Program Files\RivaTuner v2.23\RivaTuner32.sys [2009-02-15 9088]
S3 RTCore32;RTCore32; \??\C:\Program Files\RMClock\RTCore32.sys [2005-05-25 4608]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 84992]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2008-05-02 8064]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2008-05-02 8064]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-01-12 810144]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2007-10-24 358936]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-11-20 122984]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-26 135664]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-12 33584]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-06-26 182768]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2010-03-11 366840]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2010-03-15 1142224]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#3 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Vy umite aplikovat a pouzivat ComboFix, znate jeho funkce, cteni logu a vytvareni docistovacich skriptu :???:

:arrow: Poprosim i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit

:arrow: Prepokladam, ze ten NOD32 mate legalni = zakoupena licence :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ChosseCV
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 27 čer 2011 00:36

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#4 Příspěvek od ChosseCV »

Zdravíčko, předem děkuji za čas, který mi obětujete. :)

ComboFix aplikovat a používat neumim, na vláknech zde jsem četl, že výstup z ComboFixu je třeba k dalšímu postupu boje proti virů. Takže jsem ho nainstalovat povypínal ochrany a nechal vytvořit log.

NOD 32 mi běží ve 30 denní zkušební verzi, včera instalovaný.


info.txt logfile of random's system information tool 1.08 2011-06-27 13:35:37

======Uninstall list======

Update for Microsoft Office 2007 (KB2508958)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}
-->MsiExec /X{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}
3DMark06-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F3AD00A-1819-4B15-BB7D-08B3586336D7}\setup.exe" -l0x9 -removeonly
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10n_Plugin.exe -maintain plugin
Adobe Reader 9.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A93000000001}
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0405-0000-0000000FF1CE} /uninstall {0A1FAC46-B899-421D-B1A2-470896DC45DB}
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0405-0000-0000000FF1CE} /uninstall {5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0405-0000-0000000FF1CE} /uninstall {E68DD413-B834-4923-8181-0A03B7555187}
Ask Toolbar-->MsiExec.exe /I{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Browser Defender 2.0.6.15-->"C:\Program Files\Spyware Doctor\BDT\unins000.exe"
Bulletstorm-->MsiExec.exe /I{45410935-3E72-472B-8C35-AB1000008200}
BulletStorm-->MsiExec.exe /I{45410935-B52C-468A-A836-0D1000018201}
BulletStorm-->MsiExec.exe /I{45410935-B52C-468A-A836-0D1000018202}
Bulletstorm-->MsiExec.exe /X{45410935-3E72-472B-8C35-AB1000008200}
Centrum.cz Toolbar 1.201.029.002-->"C:\Program Files\CentrumczToolbar\unins000.exe"
CommView for WiFi-->C:\PROGRA~1\FISTIN~1\COMMVI~1\COMMVI~1\CV.exe /u
Commview for Wifi-->MsiExec.exe /I{021602B7-7BF4-4D32-88F1-82D62371F2CF}
CPUID HWMonitor 1.15-->"C:\Program Files\CPUID\HWMonitor\unins000.exe"
DriverMax 5-->"C:\Program Files\Innovative Solutions\DriverMax\unins000.exe"
Excellence Html Compress 2.2-->"C:\Program Files\Excellence Html Compress\unins000.exe"
FindGraph 2.28-->"C:\Program Files\FindGraph\unins000.exe"
FormatFactory 2.30-->C:\Program Files\FreeTime\FormatFactory\uninst.exe
Fraps-->"C:\Fraps\uninstall.exe"
Futuremark SystemInfo-->"C:\Program Files\InstallShield Installation Information\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}\setup.exe" -runfromtemp -l0x0009 -removeonly
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E85CDE7661A53A6A.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
ICQ Toolbar-->C:\Program Files\ICQ6Toolbar\ICQUnToolbar.exe
ICQ7-->"C:\Program Files\InstallShield Installation Information\{88EB38EF-4D2C-436D-ABD3-56B232674062}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
Intel® Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
Java DB 10.5.3.0-->MsiExec.exe /X{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}
Java(TM) 6 Update 23-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216023FF}
Java(TM) SE Development Kit 6 Update 23-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160230}
Mass Effect 2-->"C:\Program Files\Common Files\BioWare\Uninstall Mass Effect 2.exe"
Mass Effect-->C:\Program Files\Common Files\BioWare\Uninstall Mass Effect.exe
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{F2508213-9989-4E85-A078-72BE483917EF}
Microsoft Games for Windows Marketplace-->MsiExec.exe /X{4CB0307C-565E-4441-86BE-0DF2E4FB828C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0405-0000-0000000FF1CE} /uninstall {E12F9D31-4025-4BC6-B1B2-AB262C5580B0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0405-0000-0000000FF1CE} /uninstall {294B4278-CF7B-40B9-86A1-2D3FF0C2C524}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-041B-0000-0000000FF1CE} /uninstall {10EC59E5-9BCE-4884-BB1A-E28627220232}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570-->MsiExec.exe /X{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual J# 2.0 Redistributable Package-->C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft Visual J# 2.0 Redistributable Package\install.exe
Microsoft WSE 3.0 Runtime-->MsiExec.exe /X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}
Mozilla Firefox (3.6.17)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Network Stumbler 0.4.0 (remove only)-->"C:\Program Files\Network Stumbler\uninst.exe"
Nokia Connectivity Cable Driver-->RUNDLL32.EXE nsesetup.dll,DoNTUninst
NVIDIA Display Control Panel-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe DisplayControlPanel
NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
NVIDIA PhysX-->MsiExec.exe /X{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
Opera 11.10-->"C:\Program Files\Opera\Opera.exe" /uninstall
Oxygen XML Editor 11.2-->C:\Program Files\Oxygen XML Editor 11\uninstall.exe
PCMark Vantage-->"C:\Program Files\InstallShield Installation Information\{F241EC95-C81A-466E-8006-6B0B364B07A0}\setup.exe" -runfromtemp -l0x0009 -removeonly
PSPad editor-->"C:\Program Files\PSPad editor\Uninst\unins000.exe"
RivaTuner v2.23-->"C:\Program Files\RivaTuner v2.23\uninstall.exe"
Rome - Total War Anthology-->C:\Program Files\InstallShield Installation Information\{29BA43D8-07F9-4D78-A682-91BAAA98A302}\setup.exe -runfromtemp -l0x0405
Screen Video Recorder 1.5-->"C:\Program Files\ScreenVCR\unins000.exe"
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2288931)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CD769337-C8AC-46DB-A7DC-643E50089263}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB2509488)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {AD0DE453-0804-4495-9C91-33D0F9AA5463}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {3E0806DB-3085-378A-840A-F0D3AE3609D1} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP
Security Update for Microsoft Office 2007 System (KB2541012)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CD907315-705A-4475-A1A0-2A1245803E4D}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5A4E43D5-858F-49BD-BA72-8F30E1793060}
Security Update for Microsoft Office Excel 2007 (KB2541007)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A0173254-F442-4D04-9154-43FA157B83D0}
Security Update for Microsoft Office Groove 2007 (KB2494047)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B91E2AEC-7F93-4E33-ACF6-EC90640CBE4F}
Security Update for Microsoft Office InfoPath 2007 (KB2510061)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5D930261-AA5B-48D1-931F-425C9D767490}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8588DD11-6BD7-4400-B55C-DD5AB74B43E1}
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
Security Update for Microsoft Office Publisher 2007 (KB2284697)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3A4CDE54-2403-483D-8D9A-15E3264410DF}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Sencha Animator-->C:\Program Files\SenchaAnimator\uninstall.exe
Skype Toolbars-->MsiExec.exe /I{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spyware Doctor 7.0-->C:\Program Files\Spyware Doctor\unins000.exe /LOG
StarCraft II-->C:\Program Files\Common Files\Blizzard Entertainment\StarCraft II\Uninstall.exe
Starcraft-->C:\Windows\SCunin.exe C:\Windows\SCunin.dat
Sybase PowerDesigner 11.1 Evaluation-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52D26283-9C30-4A30-8EA8-34791A116DF5}\setup.exe" -l0x9
Sybase PowerDesigner 15.1-->C:\Program Files\InstallShield Installation Information\{D88DF8F0-B749-4D26-AFBC-A6E588099793}\setup.exe -runfromtemp -l0x0009 -removeonly
The KMPlayer (remove only)-->"C:\Program Files\The KMPlayer\uninstall.exe"
The Sims™ 3 Luxusní bydlení – Kolekce-->"C:\Program Files\InstallShield Installation Information\{71828142-5A24-4BD0-97E7-976DA08CE6CF}\Sims3SP01Setup.exe" -runfromtemp -l0x0005 -removeonly
The Sims™ 3 Povolání snů-->"C:\Program Files\InstallShield Installation Information\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}\Sims3EP02Setup.exe" -runfromtemp -l0x0005 -removeonly
Tortuga - Two Treasures-->"C:\Program Files\Ascaron Entertainment\Tortuga - Two Treasures\unins000.exe"
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
Ubisoft Game Launcher-->"C:\Program Files\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe" -runfromtemp -l0x0409 -removeonly
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft Office 2007 System (KB2539530)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B4CEEAE-AA88-490C-BCB2-AAC3421981A4}
Update for Microsoft Office OneNote 2007 (KB980729)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {329050A9-EF80-40F9-B633-74508F54C1FF}
Update for Microsoft Office Outlook 2007 (KB2509470)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1365864D-4C58-489D-9982-844D75691CCC}
Update for Outlook 2007 Junk Email Filter (KB2536413)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {95DF5260-331D-4FFD-A2D5-C64164751945}
UpdateMyDrivers-->"C:\ProgramData\{1D9C6AA9-C251-41F3-BAB3-E3991E1BC67A}\UpdateMyDrivers.exe" REMOVE=TRUE MODIFY=FALSE
UpdateMyDrivers-->C:\ProgramData\{1D9C6AA9-C251-41F3-BAB3-E3991E1BC67A}\UpdateMyDrivers.exe
VideoLAN VLC media player 0.8.5-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live ID Sign-in Assistant-->MsiExec.exe /X{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Wireshark 1.4.4-->"C:\Program Files\Wireshark\uninstall.exe"

======System event log======

Computer Name: Chosse-PC
Event Code: 1074
Message: Proces Explorer.EXE inicioval Napájení vypnuto počítače CHOSSE-PC jménem uživatele Chosse-PC\Chosse z následujícího důvodu: Jiný (neplánovaný)
Kód důvodu: 0x0
Typ vypnutí: Napájení vypnuto
Komentář:
Record Number: 87453
Source Name: USER32
Time Written: 20101114234453.000000-000
Event Type: Informace
User: Chosse-PC\Chosse

Computer Name: Chosse-PC
Event Code: 7036
Message: Stav služby Služba Zasílání zpráv o chybách systému Windows byl změněn na: Zastaveno
Record Number: 87452
Source Name: Service Control Manager
Time Written: 20101114234438.065329-000
Event Type: Informace
User:

Computer Name: Chosse-PC
Event Code: 7036
Message: Stav služby Windows Update byl změněn na: Spuštěno
Record Number: 87451
Source Name: Service Control Manager
Time Written: 20101114234405.570472-000
Event Type: Informace
User:

Computer Name: Chosse-PC
Event Code: 7036
Message: Stav služby Služba Výčet přenosných zařízení byl změněn na: Zastaveno
Record Number: 87450
Source Name: Service Control Manager
Time Written: 20101114234404.930871-000
Event Type: Informace
User:

Computer Name: Chosse-PC
Event Code: 14206
Message: Server médií CHOSSE-PC: Chosse: byl úspěšně inicializován a sdílí média se síťovými zařízeními médií.
Record Number: 87449
Source Name: Microsoft-Windows-WMPNSS-Service
Time Written: 20101114234403.000000-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: Chosse-PC
Event Code: 300
Message: Windows (2496) Windows: Databázový stroj provádí inicializaci jednotlivých kroků obnovení.
Record Number: 5054
Source Name: ESENT
Time Written: 20100323084838.000000-000
Event Type: Informace
User:

Computer Name: Chosse-PC
Event Code: 102
Message: Windows (2496) Windows: Databázový stroj (6.01.7600.0000) spustil novou instanci (0).
Record Number: 5053
Source Name: ESENT
Time Written: 20100323084837.000000-000
Event Type: Informace
User:

Computer Name: Chosse-PC
Event Code: 1
Message: Služba Centrum zabezpečení systému Windows byla spuštěna.
Record Number: 5052
Source Name: SecurityCenter
Time Written: 20100323084835.000000-000
Event Type: Informace
User:

Computer Name: Chosse-PC
Event Code: 902
Message: Služba Ochrana softwaru byla spuštěna.
6.1.7600.16385
Record Number: 5051
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20100323084835.000000-000
Event Type: Informace
User:

Computer Name: Chosse-PC
Event Code: 1003
Message: Služba Ochrana softwaru dokončila kontrolu stavu licencování.
ID aplikace=55c92734-d682-4d71-983e-d6ec3f16059f
Stav licencování=
1: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )]
12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]


Record Number: 5050
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20100323084835.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: Chosse-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 26799
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101023140501.803297-000
Event Type: Úspěšný audit
User:

Computer Name: Chosse-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: CHOSSE-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 26798
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101023140501.803297-000
Event Type: Úspěšný audit
User:

Computer Name: Chosse-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 26797
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101023130504.661267-000
Event Type: Úspěšný audit
User:

Computer Name: Chosse-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: CHOSSE-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 26796
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101023130504.661267-000
Event Type: Úspěšný audit
User:

Computer Name: Chosse-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 26795
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101023120507.296164-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;%CommonProgramFiles%\Microsoft Shared\Windows Live;C:\Program Files\NVIDIA Corporation\PhysX\Common;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#5 Příspěvek od vyosek »

:arrow: Jenze se tez vsude pise, aby se pouzival jen na doporuceni - neni to hracka - vizte nize

:arrow: Nebezpeci CFka
  • Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
  • Maze stopy po haveti, takze v logu z RSIT neni nic videt
  • Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
  • CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
  • CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
:arrow: Odinstalujte Spybot - Search & Destroy a taktez Spyware Doctor - nejsou to vhodne antispy programy, po ukonceni leceni, tam dame neco lepcejciho :)

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    "ICQ"=-
    "SpybotSD TeaTimer"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    "SunJavaUpdateSched"=-
    
    Driver::
    NVStrap
    MpNWMon
    NisDrv
    ICQ Service
    
    Folder::
    c:\program files\ICQ6Toolbar
    
    File::
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    
    DDS::
    uStart Page = hxxp://eu.ask.com?o=101687&l=dis
    
    Firefox::
    FF - ProfilePath - c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?clien ... n_dtid=&q=
    FF - Ext: Ask Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ChosseCV
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 27 čer 2011 00:36

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#6 Příspěvek od ChosseCV »

ComboFix 11-06-26.02 - Chosse 27.06.2011 16:39:45.4.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.2046.1169 [GMT 2:00]
Spuštěný z: c:\users\Chosse\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Chosse\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\20101013165841\Config.xml
c:\program files\ICQ6Toolbar\20101013165841\filesplace.txt
c:\program files\ICQ6Toolbar\20101013165841\Icons.bmp
c:\program files\ICQ6Toolbar\20101013165841\ICQToolBar.dll
c:\program files\ICQ6Toolbar\20101013165841\voucher.bmp
c:\program files\ICQ6Toolbar\20101013165841\voucher2.bmp
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\datastore\cache.sqlite
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\defaults.js.bak
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\defaults\preferences\defaults.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome.manifest
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\about.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\about.xul
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\cache.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\constants.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\core.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\events.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\feeds.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\json.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\lifecycle.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\listeners.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\locale.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\logger.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\network.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\observer.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\options.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\options.xul
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\preferences.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\prefetch.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\ss-popup-bindings.xml
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\suggestions.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\update.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\utilities.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\widget-controller.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\widget-popup.xul
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\content\widgets.js
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\abc.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\amazon_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\as.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\ask_16x16.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\ask_32x32.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\ask_browser_ff_chrome.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\asklogo.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\bbc_news.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\beppe_grillo.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\bg.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\bild.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\blogs.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\business.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\celebrity.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\close.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\cnn_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\corriere_della_sera.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\dictionary.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\el_mundo.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\email_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\expansion.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\facebook_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\folha.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\ft.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\ftd.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\g1.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\games_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\gazzetta_dello_sport.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\globe_18x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\gripper.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\highlight_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\highlighter_off.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\highlighter_on.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\hola.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\chevron.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icon_film1_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icon_history_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icon_news_ru_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icon_nu_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icon_radiodigital_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icon_sports_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icon_sportsru_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icon_vk_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\icons_business_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\images.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\kicker.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\labels-de.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\labels-en.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\labels-es.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\labels-fr.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\labels-it.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\labels-nl.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\labels-pt.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\labels-ru.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\laposte.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\lemonde.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\lequipe.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\libero_it.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-BR.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-DE.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-ES.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-EU.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-FR.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-IT.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-NL.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-RU.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-UK.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\links-US.properties
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\logo_32x32.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\magnify_search.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\magnify_search_grey_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\maps.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\marmiton.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\meebo_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\mtv.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\news.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\oglobo.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\orkut.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\preferences.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask_de.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask_es.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask_fr.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask_it.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask_nl.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask_pl.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask_pt.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ask_ru.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_cobrand.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_current_site.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_de.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_es.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_fr.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_grey_73x24.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_it.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_nl.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_pl.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_pt.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\search_ru.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\shopping.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\sports.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\stocks.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\terra.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\titlebar_bg.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\toolbar.css
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\toolbar.xul
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\tv.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\tv_movie_de.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\uol.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\voici_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\weather.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\weather_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\web.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\web_de.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\wordoftheday_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\youtube_16x.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\skin\zoomall.png
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Fri-23-Apr-2010-23-59-12-GMT\ff-config.zip
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Sat-07-Aug-2010-15-20-01-GMT\ff-config.zip
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Sat-25-Sep-2010-15-02-40-GMT\ff-config.zip
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Thu-04-Nov-2010-18-41-40-GMT\ff-config.zip
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Thu-20-May-2010-20-22-44-GMT\ff-config.zip
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Tue-08-Jun-2010-20-28-51-GMT\ff-config.zip
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Tue-22-Jun-2010-14-31-55-GMT\ff-config.zip
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Wed-19-May-2010-19-44-39-GMT\ff-config.zip
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\install.rdf
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1308737851011.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1308844825775.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1308844909554.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1308925604345.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1308941970286.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1308942051172.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1308943067897.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1308975074619.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1309019001379.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1309038572328.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1309125890030.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1309173360261.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1309173411321.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\logs\asktb-log-1309178808872.html
c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\extensions\toolbar@ask.com\searchplugins\askcom.xml
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MPNWMON
-------\Legacy_NISDRV
-------\Service_ICQ Service
-------\Service_NVStrap
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-05-27 do 2011-06-27 )))))))))))))))))))))))))))))))
.
.
2011-06-27 14:49 . 2011-06-27 14:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-27 11:35 . 2011-06-27 11:35 -------- d-----w- c:\program files\trend micro
2011-06-27 11:35 . 2011-06-27 11:35 -------- d-----w- C:\rsit
2011-06-26 17:53 . 2011-06-27 14:32 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-06-26 17:53 . 2011-06-27 14:32 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-26 17:40 . 2011-06-26 17:40 -------- d-----w- c:\users\Chosse\AppData\Local\Google
2011-06-26 17:39 . 2011-06-26 17:40 -------- d-----w- c:\program files\Google
2011-06-26 17:05 . 2011-06-27 14:58 -------- d-----w- c:\users\Chosse\AppData\Local\temp
2011-06-26 14:51 . 2011-06-26 14:52 -------- d-----w- c:\windows\rescache
2011-06-26 11:29 . 2011-06-26 11:29 -------- d-----w- c:\program files\ESET
2011-06-26 07:05 . 2011-06-26 07:05 -------- d-----w- c:\windows\system32\SPReview
2011-06-26 07:04 . 2011-06-26 07:04 -------- d-----w- c:\windows\system32\EventProviders
2011-06-26 07:03 . 2011-06-26 07:05 -------- d-----w- C:\6f4f6007d2f29c0a14a83e1daa974a71
2011-06-25 06:07 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E88EFE08-5F38-4BC4-A19E-4D66B1797539}\mpengine.dll
2011-06-21 11:40 . 2010-11-20 12:21 653312 ----a-w- c:\windows\system32\rpcrt4.dll
2011-06-21 11:39 . 2010-11-20 12:21 87552 ----a-w- c:\windows\system32\wudriver.dll
2011-06-21 11:38 . 2010-11-20 12:18 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-06-21 11:38 . 2010-11-20 12:18 257024 ----a-w- c:\windows\system32\dpx.dll
2011-06-16 01:11 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 01:11 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-16 01:11 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-01 15:21 . 2009-06-22 16:58 89600 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HPZPPLHN.DLL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-26 07:10 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-05-21 17:53 . 2011-05-21 17:53 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-21 17:53 . 2011-05-21 17:53 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-21 17:53 . 2011-05-21 17:53 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-21 17:53 . 2011-05-21 17:53 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-05-21 17:53 . 2011-05-21 17:53 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-05-21 17:53 . 2011-05-21 17:53 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-21 17:53 . 2011-05-21 17:53 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-05-21 17:53 . 2011-05-21 17:53 367104 ----a-w- c:\windows\system32\html.iec
2011-05-21 17:53 . 2011-05-21 17:53 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-05-21 17:53 . 2011-05-21 17:53 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-21 17:53 . 2011-05-21 17:53 203776 ----a-w- c:\windows\system32\webcheck.dll
2011-05-21 17:53 . 2011-05-21 17:53 161792 ----a-w- c:\windows\system32\msls31.dll
2011-05-21 17:53 . 2011-05-21 17:53 152064 ----a-w- c:\windows\system32\wextract.exe
2011-05-21 17:53 . 2011-05-21 17:53 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-05-21 17:53 . 2011-05-21 17:53 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-21 17:53 . 2011-05-21 17:53 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-21 17:53 . 2011-05-21 17:53 11776 ----a-w- c:\windows\system32\mshta.exe
2011-05-21 17:53 . 2011-05-21 17:53 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-05-21 17:53 . 2011-05-21 17:53 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-21 17:53 . 2011-05-21 17:53 101888 ----a-w- c:\windows\system32\admparse.dll
2011-04-22 19:14 . 2011-05-25 19:41 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\system32\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\system32\xlivefnt.dll
2011-04-09 06:02 . 2011-05-11 15:55 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-11 15:55 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56 . 2011-05-14 05:23 123904 ----a-w- c:\windows\system32\poqexec.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-10-24 178712]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.23\RivaTunerWrapper.exe" [2009-02-15 24576]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
c:\users\Chosse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 MpKsl3b3830f4;MpKsl3b3830f4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{556BEC42-05D2-43F6-B478-C93BA2629893}\MpKsl3b3830f4.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-06-26 135664]
R3 cpuz130;cpuz130;c:\users\Chosse\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 RTCore32;RTCore32;c:\program files\RMClock\RTCore32.sys [2005-05-25 4608]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-31 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
S1 TsLwWfF;WiFi Capture Driver;c:\windows\system32\DRIVERS\TsLwWfF.sys [2009-11-12 22632]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 95384]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
.
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 195.113.44.11 195.113.0.2
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Chosse\AppData\Roaming\Mozilla\Firefox\Profiles\jkicm8tx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.teensnow.com/
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
FF - Ext: Český validátor kódu: {B6533577-46BD-4520-9FF8-F0513A30C2A3} - %profile%\extensions\{B6533577-46BD-4520-9FF8-F0513A30C2A3}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
.
**************************************************************************
.
Celkový čas: 2011-06-27 17:01:23 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-06-27 15:01
ComboFix2.txt 2011-06-27 11:04
ComboFix3.txt 2011-06-27 10:32
ComboFix4.txt 2011-06-26 17:05
.
Před spuštěním: Volných bajtů: 82 583 429 120
Po spuštění: Volných bajtů: 82 359 521 280
.
- - End Of File - - 80ED8BC91D082B7715790B1F8979EDD2

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#7 Příspěvek od vyosek »

Jak se chova PC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ChosseCV
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 27 čer 2011 00:36

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#8 Příspěvek od ChosseCV »

Běží hladce, žádné zasekávání, zdlouhavé načítání i prohlížeče šlapou tak jak mají :).

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#9 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: Odinstalujte Combofix
  • Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
  • Napiste ComboFix /Uninstall
  • Stisknete Enter
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Poprosim o novy log z RSIT
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ChosseCV
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 27 čer 2011 00:36

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#10 Příspěvek od ChosseCV »

Mockrát děkuji za pomoc, super forum to tu je :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu - problém s win 7 home security 2

#11 Příspěvek od vyosek »

Jeste poprosim o novy log z RSIT pro zaverecnou kontrolu...jinak nemate zac :)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět