Stránka 2 z 2

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 08:27
od Márty84
Zdravim :wink:
Omlouvam se za vstup :oops:

Rozdelte log na casti a dejte do vice prispevku. Jen pozor, abyste neco nevynechal :)

Preji uspesne vyleceni :James008:

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 09:06
od scuser
OTL logfile created on: 13.2.2011 21:46:33 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\randula\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 48,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 71,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 140,92 Gb Total Space | 60,45 Gb Free Space | 42,89% Space Free | Partition Type: NTFS
Drive D: | 6,58 Gb Total Space | 0,74 Gb Free Space | 11,32% Space Free | Partition Type: NTFS
Drive E: | 1,55 Gb Total Space | 1,31 Gb Free Space | 84,19% Space Free | Partition Type: NTFS

Computer Name: HP-NOTEBOOK-PR | User Name: randula | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011.02.13 21:40:44 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\randula\Desktop\OTL.exe
PRC - [2011.02.12 18:49:48 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox 4.0 Beta 9\plugin-container.exe
PRC - [2011.02.12 18:49:46 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox 4.0 Beta 9\firefox.exe
PRC - [2010.11.30 13:20:36 | 000,997,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010.11.11 12:26:42 | 000,206,360 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
PRC - [2010.11.11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010.10.19 19:29:18 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Users\randula\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
PRC - [2010.04.14 10:28:44 | 000,073,728 | ---- | M] (Software602 a.s.) -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\conime.exe
PRC - [2009.01.14 14:18:52 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008.01.16 15:49:00 | 000,542,744 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe
PRC - [2008.01.16 15:48:58 | 000,330,264 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsty.exe
PRC - [2007.11.19 10:36:08 | 000,160,136 | ---- | M] (Broadgun Software) -- C:\WINDOWS\System32\bgsmsnd.exe
PRC - [2007.04.27 10:58:58 | 000,221,184 | ---- | M] (SafeBoot International) -- C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
PRC - [2007.04.10 14:10:20 | 001,489,688 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\AMT\UNS.exe
PRC - [2007.04.10 14:10:16 | 000,183,064 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\AMT\atchksrv.exe
PRC - [2007.04.10 14:10:06 | 000,121,624 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\AMT\LMS.exe
PRC - [2007.03.09 15:24:12 | 000,715,912 | ---- | M] () -- C:\WINDOWS\SMINST\Scheduler.exe
PRC - [2007.02.21 14:14:24 | 001,183,744 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2007.02.15 13:55:18 | 000,140,832 | ---- | M] (Infineon Technologies AG) -- C:\WINDOWS\System32\IfxPsdSv.exe
PRC - [2007.02.07 02:30:00 | 000,065,536 | R--- | M] (Cognizance Corporation) -- C:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe
PRC - [2007.02.06 07:44:24 | 000,069,632 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\AEADISRV.EXE
PRC - [2007.01.23 21:15:14 | 000,181,792 | ---- | M] (Infineon Technologies AG) -- C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
PRC - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2005.08.18 09:55:00 | 000,099,328 | ---- | M] () -- C:\Program Files\OpenVPN\bin\openvpn-gui.exe


========== Modules (SafeList) ==========

MOD - [2011.02.13 21:40:44 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\randula\Desktop\OTL.exe
MOD - [2010.08.31 16:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
MOD - [2007.02.26 04:49:00 | 000,070,144 | ---- | M] (Bioscrypt Inc.) -- C:\WINDOWS\System32\APSHook.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (TLSW)
SRV - File not found [On_Demand | Stopped] -- -- (QVKRD)
SRV - File not found [On_Demand | Stopped] -- -- (FNU)
SRV - [2011.01.20 14:44:03 | 000,797,184 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\System32\FntCache.dll -- (FontCache)
SRV - [2011.01.06 08:33:54 | 003,129,432 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_dbc0250.dll -- (Akamai)
SRV - [2010.11.11 12:26:42 | 000,206,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV - [2010.11.11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010.04.14 10:28:44 | 000,073,728 | ---- | M] (Software602 a.s.) [Auto | Running] -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe -- (602XML Updater)
SRV - [2010.03.18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.04.11 07:28:18 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\System32\AxInstSv.dll -- (AxInstSV) Instalační program ovládacích prvků ActiveX (AxInstSV)
SRV - [2008.01.19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.19 08:34:43 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\System32\lpdsvc.dll -- (LPDSVC)
SRV - [2008.01.16 15:49:00 | 000,542,744 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2007.04.30 07:28:34 | 000,172,131 | ---- | M] (Hewlett-Packard Ltd) [On_Demand | Stopped] -- C:\WINDOWS\System32\flcdlock.exe -- (FLCDLOCK)
SRV - [2007.04.27 10:58:58 | 000,221,184 | ---- | M] (SafeBoot International) [Auto | Running] -- C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe -- (HpFkCryptService)
SRV - [2007.04.10 14:10:20 | 001,489,688 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\AMT\UNS.exe -- (UNS) Intel(R)
SRV - [2007.04.10 14:10:16 | 000,183,064 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\AMT\atchksrv.exe -- (atchksrv) Intel(R)
SRV - [2007.04.10 14:10:06 | 000,121,624 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\AMT\LMS.exe -- (LMS) Intel(R)
SRV - [2007.03.05 09:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)
SRV - [2007.02.15 13:55:18 | 000,140,832 | ---- | M] (Infineon Technologies AG) [Auto | Running] -- C:\WINDOWS\System32\IfxPsdSv.exe -- (PersonalSecureDriveService)
SRV - [2007.02.07 02:30:00 | 000,074,240 | R--- | M] (Cognizance Corporation) [Auto | Running] -- C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll -- (ASBroker)
SRV - [2007.02.06 07:44:24 | 000,069,632 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\WINDOWS\System32\AEADISRV.EXE -- (AEADIFilters)
SRV - [2007.01.04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006.10.01 13:37:42 | 000,016,384 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2006.06.22 06:14:00 | 000,131,584 | R--- | M] (Cognizance Corporation) [Auto | Running] -- C:\Program Files\Hewlett-Packard\IAM\Bin\ASChnl.dll -- (ASChannel)


========== Driver Services (SafeList) ==========

DRV - [2011.02.13 21:29:02 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{89DB202A-9A9E-4454-ACB9-29592CA06008}\MpKsl8bd48446.sys -- (MpKsl8bd48446)
DRV - [2011.02.11 21:27:29 | 000,273,920 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\afd.sys -- (AFD)
DRV - [2010.12.04 05:45:00 | 010,370,152 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010.10.24 21:25:38 | 000,054,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2010.10.24 21:25:38 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2009.12.15 13:05:42 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009.12.15 13:05:42 | 000,101,120 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009.12.15 13:05:42 | 000,023,424 | ---- | M] (Huawei Tech. Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ewdcsc.sys -- (Huawei)
DRV - [2008.11.17 15:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel(R)
DRV - [2008.08.07 14:42:12 | 000,025,392 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\hpdskflt.sys -- (hpdskflt)
DRV - [2008.08.07 14:31:52 | 000,034,608 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2008.04.24 16:26:28 | 000,309,248 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV - [2008.03.29 10:20:55 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2008.03.29 10:20:55 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2008.03.28 02:06:00 | 000,199,472 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2008.01.19 08:42:12 | 000,045,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\tpm.sys -- (TPM)
DRV - [2008.01.19 05:25:05 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2007.09.26 12:12:22 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\NETw4v32.sys -- (NETw4v32) Ovladač adaptéru Intel(R)
DRV - [2007.04.26 19:23:36 | 000,005,808 | ---- | M] (SafeBoot International) [Kernel | System | Running] -- C:\Windows\System32\drivers\rsvlock.sys -- (RsvLock)
DRV - [2007.04.26 19:23:06 | 000,100,095 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SafeBoot.sys -- (SafeBoot)
DRV - [2007.04.16 02:00:06 | 000,985,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HSX_DPV.sys -- (HSF_DPV)
DRV - [2007.04.16 02:00:06 | 000,659,968 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HSX_CNXT.sys -- (winachsf)
DRV - [2007.04.16 02:00:06 | 000,207,360 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HSXHWAZL.sys -- (HSXHWAZL)
DRV - [2007.04.16 02:00:06 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007.04.10 14:55:28 | 000,140,808 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\atswpdrv.sys -- (ATSWPDRV) (****DEBUG****) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2007.04.06 10:27:36 | 000,044,800 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HECI.sys -- (HECI) Intel(R)
DRV - [2007.03.29 16:54:00 | 000,013,696 | ---- | M] (SafeBoot International) [File_System | Boot | Running] -- C:\Windows\System32\drivers\SbFsLock.sys -- (SbFsLock)
DRV - [2007.03.21 12:58:56 | 000,304,920 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2007.03.01 14:52:32 | 000,534,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\BCMWL6.SYS -- (BCM43XX)
DRV - [2007.03.01 14:52:32 | 000,534,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\BCMWL6.SYS -- (BCM43XV)
DRV - [2007.02.24 15:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007.01.23 21:07:30 | 000,039,080 | ---- | M] (Infineon Technologies AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\psd.sys -- (PersonalSecureDrive)
DRV - [2007.01.23 18:03:28 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007.01.23 17:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006.12.20 04:58:26 | 000,097,920 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\adusbser.sys -- (adusbser)
DRV - [2006.12.20 02:08:00 | 000,047,616 | ---- | M] (RICOH Company, Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\rismc32.sys -- (rismc32)
DRV - [2006.11.30 10:24:58 | 000,008,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\eabfiltr.sys -- (eabfiltr)
DRV - [2006.11.22 10:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2006.11.22 10:01:46 | 000,327,168 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\akshasp.sys -- (akshasp)
DRV - [2006.11.17 02:22:00 | 000,100,096 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\aksusb.sys -- (aksusb)
DRV - [2006.11.02 10:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006.11.02 10:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006.11.02 10:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006.11.02 10:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006.11.02 10:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006.11.02 10:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006.11.02 10:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006.11.02 10:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006.11.02 10:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006.11.02 10:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006.11.02 10:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006.11.02 10:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2006.11.02 10:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006.11.02 10:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006.11.02 10:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2006.11.02 10:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006.11.02 10:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006.11.02 10:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006.11.02 10:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006.11.02 10:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006.11.02 10:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006.11.02 10:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006.11.02 10:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006.11.02 10:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006.11.02 10:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006.11.02 10:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006.11.02 10:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006.11.02 10:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006.11.02 10:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006.11.02 10:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006.11.02 10:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2006.11.02 10:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2006.11.02 10:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2006.11.02 09:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006.11.02 09:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006.11.02 09:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006.11.02 09:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006.11.02 09:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006.11.02 09:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006.11.02 08:41:49 | 000,200,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS -- (HSFHWAZL)
DRV - [2006.11.02 08:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006.11.02 08:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006.11.02 08:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2006.11.02 08:30:53 | 000,167,936 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2006.11.02 00:50:52 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2006.10.09 13:31:46 | 000,044,720 | ---- | M] (SafeBoot N.V.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SbAlg.sys -- (SbAlg)
DRV - [2006.10.01 13:37:02 | 000,026,624 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\tap0801.sys -- (tap0801)
DRV - [2006.06.28 09:54:00 | 000,009,472 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2005.11.03 12:17:34 | 000,016,896 | ---- | M] (SIA Syncrosoft) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\synasUSB.sys -- (SynasUSB)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.softconsult.tv/
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\randula\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008.05.04 17:25:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.12.18 14:57:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.02.10 12:57:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b11\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 9\components [2011.02.12 18:49:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b11\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 9\plugins [2011.02.10 12:57:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.7\extensions\\Components: C:\Program Files\Mozilla Sunbird\components [2010.09.27 08:27:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.7\extensions\\Plugins: C:\Program Files\Mozilla Sunbird\plugins [2011.02.10 12:57:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.11\extensions\\Components: C:\Program Files\SeaMonkey\components [2010.12.12 13:26:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\SeaMonkey 2.0.11\extensions\\Plugins: C:\Program Files\SeaMonkey\plugins [2011.02.10 12:57:44 | 000,000,000 | ---D | M]

[2009.11.10 13:05:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\randula\AppData\Roaming\Mozilla\Extensions
[2009.11.10 13:05:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\randula\AppData\Roaming\Mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2008.11.10 21:41:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\randula\AppData\Roaming\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2011.02.10 15:46:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\randula\AppData\Roaming\Mozilla\Firefox\Profiles\i6fmgzo5.default\extensions
[2010.04.27 15:22:41 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\randula\AppData\Roaming\Mozilla\Firefox\Profiles\i6fmgzo5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.11.27 18:43:48 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\randula\AppData\Roaming\Mozilla\Firefox\Profiles\i6fmgzo5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.03.23 08:51:48 | 000,000,000 | ---D | M] (QipAuthorizer) -- C:\Users\randula\AppData\Roaming\Mozilla\Firefox\Profiles\i6fmgzo5.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
[2010.02.10 22:14:40 | 000,000,000 | ---D | M] (Answers) -- C:\Users\randula\AppData\Roaming\Mozilla\Firefox\Profiles\i6fmgzo5.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2010.09.16 17:30:38 | 000,000,000 | ---D | M] (České slovníky pro kontrolu pravopisu) -- C:\Users\randula\AppData\Roaming\Mozilla\Firefox\Profiles\i6fmgzo5.default\extensions\cs@dictionaries.addons.mozilla.org
[2010.08.26 11:00:57 | 000,000,000 | ---D | M] (O2CPlayer Plugin) -- C:\Users\randula\AppData\Roaming\Mozilla\Firefox\Profiles\i6fmgzo5.default\extensions\o2cplayer@eleco.com
[2011.02.13 17:10:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\randula\AppData\Roaming\Mozilla\SeaMonkey\Profiles\3nwop3ul.default\extensions
[2010.09.08 19:07:52 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\randula\AppData\Roaming\Mozilla\SeaMonkey\Profiles\3nwop3ul.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010.09.08 19:07:52 | 000,000,000 | ---D | M] (JavaScript Debugger) -- C:\Users\randula\AppData\Roaming\Mozilla\SeaMonkey\Profiles\3nwop3ul.default\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}
[2010.09.08 19:07:52 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Users\randula\AppData\Roaming\Mozilla\SeaMonkey\Profiles\3nwop3ul.default\extensions\inspector@mozilla.org
[2011.02.11 10:48:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\randula\AppData\Roaming\Mozilla\SeaMonkey\Profiles\rw4u7ol2.Nepojmenovaný\extensions
[2010.09.09 11:25:31 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\randula\AppData\Roaming\Mozilla\SeaMonkey\Profiles\rw4u7ol2.Nepojmenovaný\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010.09.09 11:25:31 | 000,000,000 | ---D | M] (JavaScript Debugger) -- C:\Users\randula\AppData\Roaming\Mozilla\SeaMonkey\Profiles\rw4u7ol2.Nepojmenovaný\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}
[2010.09.09 11:25:31 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Users\randula\AppData\Roaming\Mozilla\SeaMonkey\Profiles\rw4u7ol2.Nepojmenovaný\extensions\inspector@mozilla.org
[2007.11.15 09:02:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\randula\AppData\Roaming\Mozilla\Sunbird\Profiles\9bjhrd3b.default\extensions
[2011.01.19 23:10:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010.10.12 21:11:24 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.10.12 21:11:24 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.10.12 21:11:24 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.10.12 21:11:24 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.10.12 21:11:24 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2011.02.10 12:28:32 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - File not found
O2 - BHO: (pdfMachine) - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\WINDOWS\System32\bgstb.dll (Broadgun Software)
O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\randula\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Credential Manager for HP ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O3 - HKLM\..\Toolbar: (Web Accessibility Toolbar) - {11352A67-0178-46B1-8855-D50B2F81C054} - C:\Program Files\Accessibility_Toolbar\Accessibility_Toolbar.dll (Web Accessibility Tools Consortium)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (pdfMachine) - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\WINDOWS\System32\bgstb.dll (Broadgun Software)
O3 - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\..\Toolbar\WebBrowser: (Web Accessibility Toolbar) - {11352A67-0178-46B1-8855-D50B2F81C054} - C:\Program Files\Accessibility_Toolbar\Accessibility_Toolbar.dll (Web Accessibility Tools Consortium)
O3 - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\..\Toolbar\WebBrowser: (pdfMachine) - {56CF4856-ECB4-4E46-A897-A378821F97B9} - C:\WINDOWS\System32\bgstb.dll (Broadgun Software)
O4 - HKLM..\Run: [bgsmsnd.exe] C:\WINDOWS\System32\bgsmsnd.exe (Broadgun Software)
O4 - HKLM..\Run: [CognizanceTS] C:\Program Files\Hewlett-Packard\IAM\Bin\ASTSVCC.dll (Cognizance Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe ()
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKU\S-1-5-21-972185092-1158475264-1021527904-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [ST Recovery Launcher] C:\WINDOWS\SMINST\Launcher.exe (soft thinks)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/sh ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {5FB60DF1-234D-4067-8A61-536E540DA81E} http://www.webplaner-innoplus.de/royals ... lstone.cab (royalstone Control)
O16 - DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} https://www.mojedatovaschranka.cz/stati ... ?3,16,13,0 (Active602XMLFiller Control)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds.microsoft.com/FTM/ ... erCtrl.cab (DLC Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} http://www.o2c.de/download/o2cplayer.cab (O2C-Player (ELECO Software GmbH))
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://googleonline.webex.com/client/T ... atgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.228.2.1 194.228.41.113
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\DeviceNP: DllName - DeviceNP.dll - C:\Windows\System32\DeviceNP.dll (Hewlett-Packard Limited)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.tscc - C:\Windows\System32\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 09:07
od scuser
========== Files/Folders - Created Within 30 Days ==========

[2011.02.13 21:40:26 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Users\randula\Desktop\OTL.exe
[2011.02.13 17:09:37 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011.02.13 17:09:08 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011.02.12 20:37:02 | 000,595,000 | ---- | C] (Duplex Secure Ltd.) -- C:\Users\randula\Desktop\SPTDinst-v176-x86.exe
[2011.02.12 20:01:33 | 000,000,000 | ---D | C] -- C:\rsit
[2011.02.12 02:01:13 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll
[2011.02.12 01:56:48 | 008,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2011.02.12 01:49:51 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2011.02.12 01:47:05 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll
[2011.02.12 01:46:54 | 002,039,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.02.12 01:45:31 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011.02.12 01:45:31 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
[2011.02.12 01:45:30 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll
[2011.02.12 01:45:30 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll
[2011.02.12 01:45:30 | 000,261,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2011.02.12 01:45:30 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
[2011.02.12 01:45:30 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
[2011.02.12 01:45:29 | 000,979,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll
[2011.02.12 01:45:29 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
[2011.02.12 01:45:28 | 002,873,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2011.02.12 01:45:28 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2011.02.12 01:45:27 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2011.02.12 01:45:27 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2011.02.12 01:45:27 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2011.02.12 01:45:27 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2011.02.12 01:45:26 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011.02.12 01:45:26 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2011.02.12 01:45:26 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2011.02.12 01:45:26 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2011.02.12 01:45:24 | 000,797,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll
[2011.02.12 01:45:24 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011.02.12 01:45:21 | 000,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
[2011.02.12 01:45:20 | 001,554,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
[2011.02.12 01:45:20 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011.02.12 01:45:20 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2011.02.12 01:44:18 | 000,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2011.02.12 01:44:10 | 001,169,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
[2011.02.12 01:43:44 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2011.02.12 01:43:43 | 001,696,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2011.02.12 01:43:36 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2011.02.12 01:43:29 | 000,317,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MP4SDECD.DLL
[2011.02.12 01:43:22 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll
[2011.02.12 01:43:21 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll
[2011.02.12 01:42:55 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.02.12 01:42:53 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011.02.12 01:42:53 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011.02.12 01:42:53 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011.02.12 01:42:53 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011.02.12 01:42:52 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011.02.12 01:42:50 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.02.12 01:42:49 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.02.12 01:42:49 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.02.12 01:42:49 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011.02.12 01:42:49 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011.02.12 01:42:48 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011.02.12 01:42:48 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.02.12 01:42:48 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011.02.12 01:42:47 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.02.12 01:42:46 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011.02.12 01:42:46 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2011.02.12 01:42:39 | 000,867,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll
[2011.02.12 01:42:01 | 000,345,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmicmiplugin.dll
[2011.02.12 01:42:00 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll
[2011.02.12 01:42:00 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskcomp.dll
[2011.02.12 01:41:50 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2011.02.12 01:41:10 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2011.02.12 01:40:25 | 000,292,352 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2011.02.12 01:40:25 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2011.02.12 01:40:25 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2011.02.12 01:39:55 | 000,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
[2011.02.12 01:31:11 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll
[2011.02.12 01:31:10 | 003,023,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
[2011.02.12 01:31:10 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
[2011.02.12 01:30:35 | 000,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2011.02.12 01:30:32 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
[2011.02.12 01:30:32 | 000,321,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2011.02.12 01:30:32 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiag.exe
[2011.02.12 01:30:32 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
[2011.02.12 01:30:32 | 000,189,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2011.02.12 01:30:31 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2011.02.12 01:30:04 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BthMtpContextHandler.dll
[2011.02.12 01:30:04 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDShextAutoplay.exe
[2011.02.12 01:29:57 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceConnectApi.dll
[2011.02.12 01:29:51 | 000,546,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpd_ci.dll
[2011.02.12 01:29:51 | 000,334,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2011.02.12 01:29:51 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceTypes.dll
[2011.02.12 01:29:50 | 000,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDSp.dll
[2011.02.12 01:29:50 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceWMDRM.dll
[2011.02.12 01:29:50 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceClassExtension.dll
[2011.02.12 01:28:39 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
[2011.02.12 01:28:37 | 000,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
[2011.02.12 01:19:48 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011.02.12 01:19:33 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2011.02.11 22:59:57 | 003,602,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011.02.11 22:59:56 | 003,550,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011.02.11 21:57:12 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011.02.10 23:57:14 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\gojevqmw.sys
[2011.02.10 15:47:48 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.02.10 14:54:02 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.02.10 14:53:57 | 000,000,000 | ---D | C] -- C:\Users\randula\AppData\Local\temp
[2011.02.10 11:31:37 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.02.10 11:31:36 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.02.10 11:31:36 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.02.10 11:30:12 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.02.10 11:27:21 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.02.10 11:24:55 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\cbksqquy.sys
[2011.02.10 11:22:54 | 000,000,000 | ---D | C] -- C:\Windows\System32\MpEngineStore
[2011.02.09 22:46:45 | 000,000,000 | ---D | C] -- C:\Users\randula\AppData\Local\ESET
[2011.02.09 17:45:14 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\cfoycasb.sys
[2011.02.09 17:38:04 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrrncgqf.sys
[2011.02.09 17:12:49 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\cfhksyco.sys
[2011.02.09 16:48:05 | 000,221,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2011.02.07 16:59:55 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2011.02.07 16:59:55 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2011.02.07 16:59:55 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2011.02.07 16:59:55 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2011.02.07 16:59:55 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2011.02.07 16:59:55 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2011.02.07 16:59:55 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2011.02.07 16:59:55 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2011.02.07 16:59:55 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2011.02.07 16:59:54 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2011.02.07 16:59:54 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2011.02.07 16:59:54 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2011.02.07 16:59:53 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2011.02.07 16:59:52 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2011.02.07 16:59:52 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2011.02.07 16:59:52 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2011.02.07 16:59:52 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2011.02.07 16:59:52 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2011.02.07 16:59:51 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2011.02.07 16:59:51 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2011.02.07 16:59:51 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2011.02.07 16:59:51 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2011.02.07 16:59:51 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2011.02.07 16:59:51 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2011.02.07 16:59:51 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2011.02.07 16:59:51 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2011.02.07 16:59:51 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2011.02.07 16:59:51 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2011.02.07 16:59:50 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2011.02.07 16:59:50 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2011.02.07 16:59:50 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2011.02.07 16:59:50 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2011.02.07 16:59:50 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2011.02.07 16:59:50 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2011.02.07 16:59:50 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2011.02.07 16:59:50 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2011.02.07 16:59:50 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2011.02.07 16:59:49 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2011.02.07 16:59:49 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2011.02.07 16:59:49 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2011.02.07 16:59:49 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2011.02.07 16:59:49 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2011.02.07 16:59:49 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2011.02.07 16:59:49 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2011.02.07 16:59:49 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2011.02.07 16:59:49 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2011.02.07 16:59:48 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2011.02.07 16:59:48 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2011.02.07 16:59:48 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2011.02.07 16:59:48 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2011.02.07 16:59:48 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2011.02.07 16:59:48 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2011.02.07 16:59:48 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2011.02.07 16:59:48 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2011.02.07 16:59:47 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2011.02.07 16:59:47 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2011.02.07 16:59:47 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2011.02.07 16:59:47 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2011.02.07 16:59:47 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2011.02.07 16:59:47 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2011.02.07 16:59:46 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2011.02.07 16:59:46 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2011.02.07 16:59:46 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2011.02.07 16:59:46 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2011.02.07 16:59:46 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2011.02.07 16:59:46 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2011.02.07 16:59:46 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2011.02.07 16:59:46 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2011.02.07 16:59:46 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2011.02.07 16:59:45 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2011.02.07 16:59:45 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2011.02.07 16:59:45 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2011.02.07 16:59:45 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2011.02.07 16:59:45 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2011.02.07 16:59:45 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2011.02.07 16:59:45 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2011.02.07 16:59:45 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2011.02.07 16:59:44 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2011.02.07 16:59:44 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2011.02.07 16:59:44 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2011.02.07 16:59:44 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2011.02.07 16:59:44 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2011.02.07 16:59:44 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2011.02.07 16:59:44 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2011.02.07 16:59:44 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2011.02.07 16:59:44 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2011.02.07 16:59:43 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2011.02.07 16:59:43 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2011.02.07 16:57:56 | 000,000,000 | -H-D | C] -- C:\Windows\msdownld.tmp
[2011.02.07 16:57:45 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2011.01.28 11:20:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STI International
[2011.01.28 11:20:09 | 000,000,000 | ---D | C] -- C:\Users\randula\AppData\Roaming\Softtech
[2011.01.28 11:16:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Softtech
[2011.01.26 14:49:30 | 000,000,000 | ---D | C] -- C:\Users\randula\AppData\Roaming\TeamViewer
[2011.01.20 13:48:08 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox 4.0 Beta 9
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.02.13 21:40:44 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\randula\Desktop\OTL.exe
[2011.02.13 21:34:00 | 000,000,970 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-972185092-1158475264-1021527904-1003UA.job
[2011.02.13 21:32:17 | 000,000,422 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{D5D93112-F6F4-4B41-82DF-0823431BBFAF}.job
[2011.02.13 21:31:05 | 000,037,109 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011.02.13 21:31:05 | 000,037,109 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011.02.13 21:31:00 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.02.13 21:30:44 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.02.13 21:29:04 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.02.13 21:29:03 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.02.13 21:28:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.02.13 21:28:49 | 2113,200,128 | -HS- | M] () -- C:\hiberfil.sys
[2011.02.13 18:27:10 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011.02.13 17:43:48 | 000,664,590 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.02.13 17:43:48 | 000,653,132 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.02.13 17:43:48 | 000,141,350 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2011.02.13 17:43:48 | 000,126,402 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.02.12 20:58:59 | 000,000,000 | ---- | M] () -- C:\Users\randula\defogger_reenable
[2011.02.12 20:34:00 | 000,000,918 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-972185092-1158475264-1021527904-1003Core.job
[2011.02.12 20:31:30 | 000,595,000 | ---- | M] (Duplex Secure Ltd.) -- C:\Users\randula\Desktop\SPTDinst-v176-x86.exe
[2011.02.12 07:05:18 | 000,388,240 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.02.11 21:57:57 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011.02.11 21:27:29 | 000,273,920 | ---- | M] () -- C:\Windows\System32\drivers\afd.sys
[2011.02.11 15:28:19 | 000,000,471 | ---- | M] () -- C:\Windows\System32\Datei4
[2011.02.11 15:28:19 | 000,000,470 | ---- | M] () -- C:\Windows\System32\Datei3
[2011.02.11 15:28:19 | 000,000,470 | ---- | M] () -- C:\Windows\System32\Datei2
[2011.02.11 15:28:19 | 000,000,470 | ---- | M] () -- C:\Windows\System32\Datei1
[2011.02.11 15:28:19 | 000,000,469 | ---- | M] () -- C:\Windows\System32\Datei7
[2011.02.11 15:28:19 | 000,000,469 | ---- | M] () -- C:\Windows\System32\Datei5
[2011.02.11 15:28:19 | 000,000,468 | ---- | M] () -- C:\Windows\System32\Datei0
[2011.02.11 15:28:19 | 000,000,467 | ---- | M] () -- C:\Windows\System32\Datei9
[2011.02.11 15:28:19 | 000,000,467 | ---- | M] () -- C:\Windows\System32\Datei8
[2011.02.11 15:28:19 | 000,000,465 | ---- | M] () -- C:\Windows\System32\Datei6
[2011.02.10 23:57:14 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\gojevqmw.sys
[2011.02.10 12:57:44 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011.02.10 12:28:32 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.02.10 11:24:55 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\cbksqquy.sys
[2011.02.10 08:51:02 | 520,211,420 | ---- | M] () -- C:\Windows\System32\KYNFPUFBLFR
[2011.02.09 17:45:14 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\cfoycasb.sys
[2011.02.09 17:38:04 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrrncgqf.sys
[2011.02.09 17:12:49 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\cfhksyco.sys
[2011.02.09 16:43:47 | 000,083,540 | ---- | M] () -- C:\Users\randula\Documents\cc_20110209_164334.reg
[2011.02.09 08:52:12 | 000,002,355 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.02.08 20:06:10 | 000,000,000 | ---- | M] () -- C:\Users\randula\AppData\Local\prvlcl.dat
[2011.02.02 17:11:20 | 000,222,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2011.01.28 11:20:12 | 000,001,529 | ---- | M] () -- C:\Users\Public\Desktop\SPIRIT 2010 Data.lnk
[2011.01.28 11:20:12 | 000,000,954 | ---- | M] () -- C:\Users\Public\Desktop\SPIRIT 2010.lnk
[2011.01.26 16:44:58 | 000,000,645 | ---- | M] () -- C:\Users\randula\Desktop\TeamViewer.lnk
[2011.01.26 14:52:03 | 000,000,610 | ---- | M] () -- C:\Users\randula\Desktop\TeamViewerQS.lnk
[2011.01.26 12:20:19 | 000,012,316 | ---- | M] () -- C:\Users\randula\jni-testy-3-rez.dxf
[2011.01.26 12:17:14 | 000,023,029 | ---- | M] () -- C:\Users\randula\jni-testy-3.dxf
[2011.01.26 11:41:20 | 007,857,203 | ---- | M] () -- C:\Users\randula\jni-testy-2-all.dxf
[2011.01.26 11:40:59 | 000,057,954 | ---- | M] () -- C:\Users\randula\jni-testy-2.dxf
[2011.01.24 22:42:47 | 000,017,193 | ---- | M] () -- C:\Users\randula\Desktop\domeny-server.ods
[2011.01.20 17:08:16 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2011.01.20 17:08:06 | 001,029,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2011.01.20 17:08:06 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2011.01.20 17:08:06 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2011.01.20 17:08:06 | 000,160,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2011.01.20 17:07:58 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2011.01.20 17:06:38 | 002,873,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2011.01.20 17:06:35 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
[2011.01.20 17:04:54 | 000,209,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
[2011.01.20 17:04:54 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
[2011.01.20 15:28:38 | 001,554,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
[2011.01.20 15:27:50 | 000,876,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011.01.20 15:26:30 | 000,667,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
[2011.01.20 15:25:25 | 000,847,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
[2011.01.20 15:24:32 | 000,288,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011.01.20 15:24:26 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2011.01.20 15:15:10 | 000,979,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll
[2011.01.20 15:14:39 | 000,357,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll
[2011.01.20 15:14:03 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll
[2011.01.20 15:14:03 | 000,261,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2011.01.20 15:12:46 | 001,172,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2011.01.20 15:11:34 | 000,486,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2011.01.20 14:47:51 | 000,683,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011.01.20 14:44:05 | 001,068,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011.01.20 14:44:03 | 000,797,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FntCache.dll
[2011.01.20 13:48:15 | 000,001,888 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox 4.0 Beta 9.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.02.12 20:58:59 | 000,000,000 | ---- | C] () -- C:\Users\randula\defogger_reenable
[2011.02.11 21:57:20 | 000,001,768 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011.02.10 11:31:37 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.02.10 11:31:37 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.02.10 11:31:36 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.02.10 11:31:36 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.02.10 11:31:36 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.02.10 08:35:17 | 520,211,420 | ---- | C] () -- C:\Windows\System32\KYNFPUFBLFR
[2011.02.09 16:49:21 | 000,001,912 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011.02.09 16:43:38 | 000,083,540 | ---- | C] () -- C:\Users\randula\Documents\cc_20110209_164334.reg
[2011.01.28 11:20:12 | 000,001,529 | ---- | C] () -- C:\Users\Public\Desktop\SPIRIT 2010 Data.lnk
[2011.01.28 11:20:12 | 000,000,954 | ---- | C] () -- C:\Users\Public\Desktop\SPIRIT 2010.lnk
[2011.01.27 10:59:14 | 000,001,904 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox 4.0 Beta 10.lnk
[2011.01.26 16:44:58 | 000,000,645 | ---- | C] () -- C:\Users\randula\Desktop\TeamViewer.lnk
[2011.01.26 14:51:28 | 000,000,610 | ---- | C] () -- C:\Users\randula\Desktop\TeamViewerQS.lnk
[2011.01.26 11:41:19 | 007,857,203 | ---- | C] () -- C:\Users\randula\jni-testy-2-all.dxf
[2011.01.26 11:40:54 | 000,057,954 | ---- | C] () -- C:\Users\randula\jni-testy-2.dxf
[2011.01.26 11:12:50 | 000,012,316 | ---- | C] () -- C:\Users\randula\jni-testy-3-rez.dxf
[2011.01.26 10:57:26 | 000,023,029 | ---- | C] () -- C:\Users\randula\jni-testy-3.dxf
[2011.01.20 13:48:13 | 000,001,888 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox 4.0 Beta 9.lnk
[2011.01.10 12:43:21 | 000,000,000 | ---- | C] () -- C:\Users\randula\AppData\Local\prvlcl.dat
[2010.08.26 13:37:52 | 000,000,000 | ---- | C] () -- C:\Users\randula\AppData\Local\AtStart.txt
[2010.03.22 22:19:54 | 000,004,592 | -H-- | C] () -- C:\ProgramData\scs_3.dat
[2009.11.25 14:31:00 | 000,000,232 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2009.10.06 08:48:19 | 000,000,000 | ---- | C] () -- C:\Users\randula\AppData\Local\FnF4.txt
[2009.07.04 00:43:17 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.03.13 16:06:33 | 000,000,000 | ---- | C] () -- C:\Windows\SOFTconsult screensaver 2.ini
[2008.05.20 16:30:53 | 000,273,920 | ---- | C] () -- C:\Windows\System32\drivers\afd.sys
[2008.04.29 21:09:17 | 000,037,109 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2008.04.29 21:09:17 | 000,037,109 | ---- | C] () -- C:\ProgramData\nvModes.001
[2008.02.13 21:09:11 | 000,000,680 | ---- | C] () -- C:\Users\randula\AppData\Local\d3d9caps.dat
[2007.12.13 14:43:43 | 000,001,025 | ---- | C] () -- C:\Windows\System32\sysprs7.dll
[2007.12.13 14:43:43 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth2.dll
[2007.12.13 14:43:43 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth1.dll
[2007.12.13 14:43:43 | 000,000,342 | ---- | C] () -- C:\Windows\System32\lsprst7.dll
[2007.12.13 14:43:43 | 000,000,073 | ---- | C] () -- C:\Windows\System32\ssprs.dll
[2007.11.20 17:41:17 | 000,000,644 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.11.16 11:18:42 | 000,027,136 | ---- | C] () -- C:\Users\randula\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.11.15 16:36:06 | 000,000,095 | ---- | C] () -- C:\Users\randula\AppData\Local\fusioncache.dat
[2007.11.15 11:47:35 | 000,074,120 | ---- | C] () -- C:\Windows\System32\bgsresen.dll
[2007.11.15 11:47:35 | 000,070,024 | ---- | C] () -- C:\Windows\System32\bgsresfr.dll
[2007.11.15 11:47:35 | 000,070,024 | ---- | C] () -- C:\Windows\System32\bgsreses.dll
[2007.11.15 11:47:35 | 000,070,024 | ---- | C] () -- C:\Windows\System32\bgsresde.dll
[2007.11.15 11:47:34 | 000,057,736 | ---- | C] () -- C:\Windows\System32\bgspmnt.dll
[2007.11.15 11:14:03 | 000,024,206 | ---- | C] () -- C:\Users\randula\AppData\Roaming\UserTile.png
[2007.11.14 21:19:05 | 000,000,571 | ---- | C] () -- C:\Windows\System32\FeMakro.ini
[2007.11.14 21:19:05 | 000,000,497 | ---- | C] () -- C:\Windows\System32\FeAnim.ini
[2007.11.14 17:07:20 | 000,000,148 | ---- | C] () -- C:\Windows\OPHD.INI
[2007.11.14 15:28:11 | 000,131,265 | ---- | C] () -- C:\Users\randula\AppData\Roaming\nvModes.001
[2007.11.14 15:03:14 | 000,131,265 | ---- | C] () -- C:\Users\randula\AppData\Roaming\nvModes.dat
[2007.11.13 16:31:58 | 000,000,000 | ---- | C] () -- C:\Users\randula\AppData\Local\QSwitch.txt
[2007.11.13 16:31:58 | 000,000,000 | ---- | C] () -- C:\Users\randula\AppData\Local\DSwitch.txt
[2007.11.13 16:21:58 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2007.11.13 16:21:58 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2007.11.13 16:21:58 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2007.11.13 16:21:58 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2007.11.13 16:21:58 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2007.11.13 16:21:58 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2007.04.30 07:31:14 | 000,274,432 | ---- | C] () -- C:\Windows\System32\flcdlmsg.dll
[2007.04.26 19:23:06 | 000,100,095 | ---- | C] () -- C:\Windows\System32\drivers\SafeBoot.sys
[2007.01.19 15:30:56 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
[2006.11.02 11:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.09.18 22:02:40 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006.09.18 22:02:40 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006.03.09 11:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005.05.07 13:06:00 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2002.02.27 08:41:28 | 000,024,576 | ---- | C] () -- C:\Windows\System32\nsldappr32v50.dll
[2002.02.27 08:41:26 | 000,139,264 | ---- | C] () -- C:\Windows\System32\nsldap32v50.dll
[2002.02.27 08:41:26 | 000,040,960 | ---- | C] () -- C:\Windows\System32\nsldapssl32v50.dll
[1999.12.07 00:00:00 | 000,012,288 | ---- | C] () -- C:\Windows\System32\HLINKPRX.DLL
[1999.01.22 18:46:58 | 000,065,536 | ---- | C] () -- C:\Windows\System32\MSRTEDIT.DLL
[1998.05.07 03:10:00 | 000,069,632 | R--- | C] () -- C:\Windows\System32\ODMA32.dll

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 09:08
od scuser
========== LOP Check ==========

[2010.08.13 08:34:18 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\602XML
[2010.12.16 11:13:01 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\aec-creative
[2008.10.01 14:41:31 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Autodesk
[2007.11.19 11:41:18 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Downloaded Installations
[2011.02.11 14:55:06 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\FileZilla
[2008.02.13 21:03:57 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Hewlett Packard
[2008.02.13 20:55:44 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Infineon
[2008.01.05 22:35:09 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\InterVideo
[2007.12.09 14:02:38 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\LockPlatePlanner
[2008.12.15 13:32:50 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\OpenOffice.org
[2007.11.14 17:07:26 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\OPHD
[2011.02.11 15:21:42 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\pdfMachine
[2007.11.15 11:14:03 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\PeerNetworking
[2009.03.23 10:02:43 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\QIP
[2010.10.05 14:00:49 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\QipGuard
[2007.11.28 21:56:29 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\SampleView
[2009.11.16 21:32:08 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\SmartDraw
[2011.01.28 11:20:09 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Softtech
[2010.05.31 20:31:09 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\SQLyog
[2010.07.09 20:06:10 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\StreamTorrent
[2011.01.26 16:13:07 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\TeamViewer
[2010.12.19 15:24:20 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Telefónica Móviles
[2009.06.04 09:54:58 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\WebEx
[2008.11.10 22:02:32 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Wings3D
[2010.12.23 13:52:06 | 000,000,000 | ---D | M] -- C:\Users\Test\AppData\Roaming\Infineon
[2011.02.13 18:27:20 | 000,032,634 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT
[2011.02.13 21:32:17 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{D5D93112-F6F4-4B41-82DF-0823431BBFAF}.job

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2009.04.11 07:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation)
"Google Update" = "C:\Users\randula\AppData\Local\Google\Update\GoogleUpdate.exe" /c -- [2008.09.05 08:02:36 | 000,133,104 | ---- | M] (Google Inc.)
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -- [2009.01.14 14:18:52 | 000,039,408 | ---- | M] (Google Inc.)
"WMPNSCFG" = C:\Program Files\Windows Media Player\WMPNSCFG.exe -- [2008.01.19 08:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation)

< c:\windows\*.* /U >
[1 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2010.08.13 08:34:18 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\602XML
[2010.04.19 08:22:26 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Adobe
[2010.12.16 11:13:01 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\aec-creative
[2008.02.10 12:02:21 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Apple Computer
[2008.10.01 14:41:31 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Autodesk
[2010.06.09 15:07:38 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\DivX
[2007.11.19 11:41:18 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Downloaded Installations
[2011.02.11 14:55:06 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\FileZilla
[2010.06.21 23:06:29 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Google
[2007.11.15 12:12:43 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Help
[2008.02.13 21:03:57 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Hewlett Packard
[2008.02.13 20:56:35 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Hewlett-Packard
[2007.11.13 16:31:06 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Identities
[2008.02.13 20:55:44 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Infineon
[2007.11.13 16:19:11 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\InstallShield
[2008.01.05 22:35:09 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\InterVideo
[2007.12.09 14:02:38 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\LockPlatePlanner
[2007.11.13 16:28:20 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Macromedia
[2011.02.09 16:47:01 | 000,000,000 | --SD | M] -- C:\Users\randula\AppData\Roaming\Microsoft
[2007.11.20 17:37:16 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Microsoft Web Folders
[2010.06.21 23:06:29 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Mozilla
[2008.12.15 13:32:50 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\OpenOffice.org
[2008.12.15 13:10:10 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\OpenOffice.org2
[2007.11.14 17:07:26 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\OPHD
[2011.02.11 15:21:42 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\pdfMachine
[2007.11.15 11:14:03 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\PeerNetworking
[2009.03.23 10:02:43 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\QIP
[2010.10.05 14:00:49 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\QipGuard
[2008.05.04 17:29:54 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Real
[2009.06.01 13:20:55 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Roxio
[2007.11.28 21:56:29 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\SampleView
[2011.02.09 16:32:23 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Skype
[2011.02.09 16:02:17 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\skypePM
[2009.11.16 21:32:08 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\SmartDraw
[2011.01.28 11:20:09 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Softtech
[2010.05.31 20:31:09 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\SQLyog
[2010.07.09 20:06:10 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\StreamTorrent
[2007.11.15 09:02:05 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Talkback
[2011.01.26 16:13:07 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\TeamViewer
[2010.12.19 15:24:20 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Telefónica Móviles
[2009.06.04 09:54:58 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\WebEx
[2008.11.10 22:02:32 | 000,000,000 | ---D | M] -- C:\Users\randula\AppData\Roaming\Wings3D

< %APPDATA%\*.exe /s >
[2009.10.12 07:25:46 | 000,303,104 | ---- | M] () -- C:\Users\randula\AppData\Roaming\Google\O3D\reporter.exe
[2010.02.01 02:45:40 | 000,038,784 | ---- | M] () -- C:\Users\randula\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2008.11.10 21:40:57 | 000,026,694 | R--- | M] () -- C:\Users\randula\AppData\Roaming\Microsoft\Installer\{D485DCBB-DBBE-4E47-B7F4-250F87A7B629}\_12db153c.exe
[2008.11.10 21:40:57 | 000,026,694 | R--- | M] () -- C:\Users\randula\AppData\Roaming\Microsoft\Installer\{D485DCBB-DBBE-4E47-B7F4-250F87A7B629}\_bb32ea6.exe
[2010.07.25 15:11:02 | 001,037,888 | ---- | M] () -- C:\Users\randula\AppData\Roaming\Mozilla\Firefox\Profiles\i6fmgzo5.default\extensions\o2cplayer@eleco.com\Plugins\dx9setup.exe


< MD5 for: AGP440.SYS >
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007.07.20 11:17:57 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=313FF294978EA6AF715722D708FB249F -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20494_none_b858f78adaed51b3\AGP440.sys
[2007.07.20 11:17:57 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f2490cb0\AGP440.sys
[2007.07.20 11:17:57 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16399_none_b7d45c31c1cb309c\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\WINDOWS\ERDNT\cache\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\WINDOWS\System32\drivers\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\System32\drivers\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.02.13 17:13:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.02.13 17:13:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.02.13 17:13:26 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2009.04.11 07:27:20 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\WINDOWS\System32\autochk.exe
[2009.04.11 07:27:20 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\WINDOWS\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6002.18005_none_e3df6655bee2ee3b\autochk.exe
[2008.01.19 08:33:01 | 000,642,560 | ---- | M] (Microsoft Corporation) MD5=2FC5BE79B51714B479809358E4908FC3 -- C:\WINDOWS\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_e1f3ed49c1c122ef\autochk.exe
[2006.11.02 10:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\WINDOWS\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_dfbd2b4dc4d6121b\autochk.exe

< MD5 for: CDROM.SYS >
[2008.01.19 06:49:51 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=1EC25CEA0DE6AC4718BF89F9E1778B57 -- C:\WINDOWS\System32\DriverStore\FileRepository\cdrom.inf_a29e71c6\cdrom.sys
[2008.01.19 06:49:51 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=1EC25CEA0DE6AC4718BF89F9E1778B57 -- C:\WINDOWS\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6001.18000_none_5fa95be2a3c76a4a\cdrom.sys
[2009.04.11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\WINDOWS\System32\drivers\cdrom.sys
[2009.04.11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\WINDOWS\System32\DriverStore\FileRepository\cdrom.inf_c949a5b6\cdrom.sys
[2009.04.11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\WINDOWS\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6002.18005_none_6194d4eea0e93596\cdrom.sys
[2006.11.02 09:51:44 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=8D1866E61AF096AE8B582454F5E4D303 -- C:\WINDOWS\System32\DriverStore\FileRepository\cdrom.inf_e487f727\cdrom.sys

< MD5 for: CNGAUDIT.DLL >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\ERDNT\cache\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: CRYPTSVC.DLL >
[2006.11.02 10:46:03 | 000,123,392 | ---- | M] (Microsoft Corporation) MD5=1C26FB097170A2A91066D1E3A24366E3 -- C:\WINDOWS\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6000.16386_none_73c8d7689de43d15\cryptsvc.dll
[2008.01.19 08:34:00 | 000,128,000 | ---- | M] (Microsoft Corporation) MD5=6DE363F9F99334514C46AEC02D3E3678 -- C:\WINDOWS\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\cryptsvc.dll
[2009.04.11 07:28:18 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=FB27772BEAF8E1D28CCD825C09DA939B -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2009.04.11 07:28:18 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=FB27772BEAF8E1D28CCD825C09DA939B -- C:\WINDOWS\System32\cryptsvc.dll
[2009.04.11 07:28:18 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=FB27772BEAF8E1D28CCD825C09DA939B -- C:\WINDOWS\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18005_none_77eb127097f11935\cryptsvc.dll

< MD5 for: EXPLORER.EXE >
[2008.10.29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 04:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007.11.15 17:20:22 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007.11.15 17:20:21 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\WINDOWS\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008.10.28 03:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006.11.02 10:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008.01.19 08:33:10 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: HAL.DLL >
[2009.04.11 07:32:46 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\WINDOWS\System32\hal.dll

< MD5 for: IASTOR.SYS >
[2007.03.21 12:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\WINDOWS\System32\drivers\iaStor.sys
[2007.03.21 12:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\WINDOWS\System32\DriverStore\FileRepository\iaahci.inf_3a63e5a6\iaStor.sys

< MD5 for: IASTORV.SYS >
[2008.01.19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\WINDOWS\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\WINDOWS\System32\drivers\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: ISAPNP.SYS >
[2006.11.02 10:50:24 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=350FCA7E73CF65BCEF43FAE1E4E91293 -- C:\WINDOWS\System32\drivers\isapnp.sys
[2006.11.02 10:50:24 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=350FCA7E73CF65BCEF43FAE1E4E91293 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_920a2c1f\isapnp.sys
[2008.01.19 08:42:15 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_51b95d75\isapnp.sys
[2008.01.19 08:42:15 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f750e484\isapnp.sys
[2008.01.19 08:42:15 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\isapnp.sys
[2008.01.19 08:42:15 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\isapnp.sys
[2007.07.20 11:17:57 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=B5B664CFE3B8C4E426B164103373DFFD -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20494_none_b858f78adaed51b3\isapnp.sys
[2007.07.20 11:17:57 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=C756DC995A7E81A66E0D59305EE4A25F -- C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f2490cb0\isapnp.sys
[2007.07.20 11:17:57 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=C756DC995A7E81A66E0D59305EE4A25F -- C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16399_none_b7d45c31c1cb309c\isapnp.sys

< MD5 for: LSASS.EXE >
[2009.06.15 13:51:56 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=203D86EBD6D8E4C8501B222421E81506 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22152_none_a886901f7335e2fc\lsass.exe
[2009.09.10 15:44:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=2D3AC5E7AC01E905F3ABD2D745FE3A9B -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\lsass.exe
[2009.06.15 13:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2009.06.15 13:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\WINDOWS\System32\lsass.exe
[2009.06.15 13:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18051_none_a7fbf30a5a1929db\lsass.exe
[2009.02.13 08:26:04 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=59DE082968FDD257FFF0D209B9A5B460 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16820_none_a44eb0105fb4d975\lsass.exe
[2006.11.02 10:45:21 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=6A0E382E74280E4CC0DF17FE2661D003 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16386_none_a413c8c65fe02762\lsass.exe
[2009.06.15 14:03:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=6F1F23D3599EAE17734451936B7F17C6 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22450_none_a69e1da376115b2a\lsass.exe
[2009.06.15 13:57:59 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A911ECAC81F94ADEAFBE8E3F7873EDB0 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18272_none_a600dfae5d0228c9\lsass.exe
[2009.02.13 05:58:37 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=AFF8A58280863629CA4FFA9E0B259F1E -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21010_none_a4e2f4e978ca9090\lsass.exe
[2009.06.15 13:59:08 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=BA9A67672E025078C77967731BCFC560 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21067_none_a4b3e75378eccda6\lsass.exe
[2009.06.15 14:10:12 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=C731B1FE449D4E9CEA358C9D55B69BE9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16870_none_a418a0745fdd652a\lsass.exe
[2009.09.09 12:09:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=CB7E838C140B4087B2DA323F2D4523C5 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\lsass.exe
[2009.09.10 15:47:51 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=D09A5DA84B7C9CA9B02EBCD7FAE41C8D -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\lsass.exe
[2008.01.19 08:33:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\lsass.exe
[2008.01.19 08:33:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\lsass.exe
[2008.01.19 08:33:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\lsass.exe
[2009.02.13 09:20:29 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=F4C62B07E5BF96F1FDCA9DB393ECED22 -- C:\WINDOWS\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22376_none_a68e7da1761c2def\lsass.exe

< MD5 for: NDIS.SYS >
[2009.04.11 07:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2009.04.11 07:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\WINDOWS\System32\drivers\ndis.sys
[2009.04.11 07:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\WINDOWS\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_a9b2a4d31930d864\ndis.sys
[2006.11.02 10:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\WINDOWS\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.16386_none_a59069cb1f23fc44\ndis.sys
[2008.01.19 08:43:31 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=9BDC71790FA08F0A0B5F10462B1BD0B1 -- C:\WINDOWS\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys

< MD5 for: NETLOGON.DLL >
[2006.11.02 10:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\WINDOWS\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 08:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVRAID.SYS >
[2008.01.19 08:43:01 | 000,102,968 | ---- | M] (NVIDIA Corporation) MD5=2EDF9E7751554B42CBB60116DE727101 -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvraid.sys
[2008.01.19 08:43:01 | 000,102,968 | ---- | M] (NVIDIA Corporation) MD5=2EDF9E7751554B42CBB60116DE727101 -- C:\WINDOWS\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvraid.sys
[2006.11.02 10:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) MD5=E69E946F80C1C31C53003BFBF50CBB7C -- C:\WINDOWS\System32\drivers\nvraid.sys
[2006.11.02 10:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) MD5=E69E946F80C1C31C53003BFBF50CBB7C -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\WINDOWS\System32\drivers\nvstor.sys
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\WINDOWS\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008.01.19 08:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 10:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\WINDOWS\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< MD5 for: SMSS.EXE >
[2008.01.19 08:33:31 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=6701DDAF68BEDE6BBEEA9D514D73A35B -- C:\WINDOWS\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.18000_none_ac3aa7fd19319fba\smss.exe
[2009.04.11 07:28:04 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=98AF15A94CD6AC37248E72E5FE789B35 -- C:\WINDOWS\System32\smss.exe
[2009.04.11 07:28:04 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=98AF15A94CD6AC37248E72E5FE789B35 -- C:\WINDOWS\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.18005_none_ae26210916536b06\smss.exe
[2006.11.02 10:45:45 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=CAA75757BB3695478C23CB0624342A61 -- C:\WINDOWS\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6000.16386_none_aa03e6011c468ee6\smss.exe

< MD5 for: SVCHOST.EXE >
[2006.11.02 10:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\WINDOWS\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008.01.19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.01.19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\WINDOWS\System32\svchost.exe
[2008.01.19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\WINDOWS\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.04.26 09:08:16 | 000,891,448 | ---- | M] (Microsoft Corporation) MD5=01EC1E92595F839BEE70D439C46796E3 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36dd19b7fae39c7\tcpip.sys
[2008.01.09 16:34:21 | 000,802,816 | ---- | M] (Microsoft Corporation) MD5=028061C7F6D2D03068C72E2A27E4228A -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16567_none_5f6577ce925d75a7\tcpip.sys
[2009.04.11 07:33:02 | 000,897,000 | ---- | M] (Microsoft Corporation) MD5=0E6B0885C3D5E4643ED2D043DE3433D8 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18005_none_b5098b5e63880c42\tcpip.sys
[2009.12.08 21:52:30 | 000,897,624 | ---- | M] (Microsoft Corporation) MD5=1ACBB7A47E78F4CC82D2EFFB72901528 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18377_none_b2d96a966698ad63\tcpip.sys
[2009.08.15 22:30:53 | 000,816,640 | ---- | M] (Microsoft Corporation) MD5=2512B4D1353370D6688B1AF1F5AFA1CF -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21108_none_6030d425ab49af00\tcpip.sys
[2009.08.14 18:01:55 | 000,900,168 | ---- | M] (Microsoft Corporation) MD5=2608E71AAD54564647D4BB984E1925AA -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys
[2010.02.18 12:51:51 | 000,818,688 | ---- | M] (Microsoft Corporation) MD5=2C1F7005AA3B62721BFDB307BD5F5010 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21226_none_6019359fab5bb15b\tcpip.sys
[2010.02.18 15:49:38 | 000,898,952 | ---- | M] (Microsoft Corporation) MD5=2EAE4500984C2F8DACFB977060300A15 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18427_none_b30f7c1866701ed5\tcpip.sys
[2009.08.14 15:24:47 | 000,813,568 | ---- | M] (Microsoft Corporation) MD5=300208927321066EA53761FDC98747C6 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16908_none_5fa75f38922bdbf4\tcpip.sys
[2008.01.09 16:34:20 | 000,804,352 | ---- | M] (Microsoft Corporation) MD5=43EAE40B50FE3E60D194DD9C97EBB1FD -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20689_none_5fdb7555ab898001\tcpip.sys
[2009.12.08 21:15:00 | 000,907,832 | ---- | M] (Microsoft Corporation) MD5=46E6685F3E92AEC743773ADD4CD54F57 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22283_none_b53aaa1b7ce8560d\tcpip.sys
[2010.02.18 15:07:16 | 000,904,576 | ---- | M] (Microsoft Corporation) MD5=48CBE6D53632D0067C2D6B20F90D84CA -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18209_none_b50d905263846bec\tcpip.sys
[2010.02.18 13:05:37 | 000,815,104 | ---- | M] (Microsoft Corporation) MD5=4A82FA8F0DF67AA354580C3FAAF8BDE3 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.17021_none_5f8a957c924295b7\tcpip.sys
[2008.02.13 17:13:04 | 000,806,400 | ---- | M] (Microsoft Corporation) MD5=52A8BD6294F7D1443C6184C67AE13AF4 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20752_none_5ff4e4f9ab7777f4\tcpip.sys
[2009.12.08 21:37:09 | 000,900,696 | ---- | M] (Microsoft Corporation) MD5=5653230D480A9C54D169E1B080B72CF5 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22577_none_b36309477fb64a54\tcpip.sys
[2008.02.13 17:13:04 | 000,803,328 | ---- | M] (Microsoft Corporation) MD5=5DF77458AA92FDB36FCE79C60F74AB5D -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16627_none_5f90b964923d030a\tcpip.sys
[2010.06.16 16:55:58 | 000,902,032 | ---- | M] (Microsoft Corporation) MD5=6216A954ED7045B62880A92D6C9B9FC7 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys
[2009.08.14 17:27:34 | 000,904,776 | ---- | M] (Microsoft Corporation) MD5=65877AA1B6A7CB797488E831698973E9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18091_none_b4a43aea63d4a25f\tcpip.sys
[2010.06.16 17:39:32 | 000,912,776 | ---- | M] (Microsoft Corporation) MD5=6A10AFCE0B38371064BE41C1FBFD3C6B -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2010.06.16 17:39:32 | 000,912,776 | ---- | M] (Microsoft Corporation) MD5=6A10AFCE0B38371064BE41C1FBFD3C6B -- C:\WINDOWS\System32\drivers\tcpip.sys
[2010.06.16 17:39:32 | 000,912,776 | ---- | M] (Microsoft Corporation) MD5=6A10AFCE0B38371064BE41C1FBFD3C6B -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22425_none_b57d8e037cb5db63\tcpip.sys
[2010.06.16 16:59:54 | 000,898,952 | ---- | M] (Microsoft Corporation) MD5=782568AB6A43160A159B6215B70BCCE9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys
[2008.04.26 09:26:49 | 000,891,448 | ---- | M] (Microsoft Corporation) MD5=82E266BEE5F0167E41C6ECFDD2A79C02 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys
[2009.12.08 18:58:13 | 000,813,568 | ---- | M] (Microsoft Corporation) MD5=8734BD051FFDCBF8425CF222141C3741 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16973_none_5f56ae52926920d8\tcpip.sys
[2009.08.14 18:07:56 | 000,897,608 | ---- | M] (Microsoft Corporation) MD5=8A7AD2A214233F684242F289ED83EBC3 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_b3144862666d6db3\tcpip.sys
[2010.02.18 18:36:50 | 000,902,024 | ---- | M] (Microsoft Corporation) MD5=93A5655CD9CD2F080EF1CB71A3666215 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22636_none_b38d4a937f96be60\tcpip.sys
[2010.06.16 17:04:57 | 000,905,088 | ---- | M] (Microsoft Corporation) MD5=A474879AFA4A596B3A531F3E69730DBF -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18272_none_b4baded863c37e22\tcpip.sys
[2010.04.05 18:03:01 | 000,902,024 | ---- | M] (Microsoft Corporation) MD5=A6A02EF5B5E40FBD31A1ADC577DA54BB -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22665_none_b36bda857faff8dc\tcpip.sys
[2009.12.08 18:45:32 | 000,816,640 | ---- | M] (Microsoft Corporation) MD5=CA3A5756672013A66BB9D547A5A62DCA -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.21175_none_5fe223d3ab852692\tcpip.sys
[2010.04.05 21:00:48 | 000,910,208 | ---- | M] (Microsoft Corporation) MD5=CC9993701AC57F995554C696DDA49C12 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22377_none_b5497d157cdc9c9f\tcpip.sys
[2006.11.02 09:58:38 | 000,802,816 | ---- | M] (Microsoft Corporation) MD5=D944522B048A5FEB7700B5170D3D9423 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16386_none_5f4ed3e0926e99e4\tcpip.sys
[2010.02.18 15:22:11 | 000,910,216 | ---- | M] (Microsoft Corporation) MD5=D9F5DD5BBC8348E8F8220CCBF14C022E -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22341_none_b563eb1d7cc9b0c2\tcpip.sys
[2009.12.08 21:01:08 | 000,904,776 | ---- | M] (Microsoft Corporation) MD5=DA467E7619AE5F4588E6262C13C8940A -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18160_none_b4c3ac4a63bd325c\tcpip.sys
[2008.01.19 08:43:39 | 000,891,448 | ---- | M] (Microsoft Corporation) MD5=FC6E2835D667774D409C7C7021EAF9C4 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_b31e1252666640f6\tcpip.sys
[2009.08.14 17:33:50 | 000,905,784 | ---- | M] (Microsoft Corporation) MD5=FF71856BD4CD6D4367F9FD84BE79A874 -- C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22200_none_b58e289d7caa2a80\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\WINDOWS\System32\userinit.exe
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\WINDOWS\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WS2_32.DLL >
[2008.01.19 08:37:09 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2006.11.02 10:46:14 | 000,178,688 | ---- | M] (Microsoft Corporation) MD5=D99A071C1018BB3D4ABAAD4B62048AC2 -- C:\WINDOWS\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6000.16386_none_f080eec6d16af4f0\ws2_32.dll
[2008.01.19 08:37:09 | 000,179,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\ws2_32.dll
[2008.01.19 08:37:09 | 000,179,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_f2b7b0c2ce5605c4\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009.03.08 12:31:42 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtmsft.dll
[2009.03.08 12:31:37 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtrans.dll
[2009.04.11 07:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\rsaenh.dll
[2009.04.11 07:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.10.24 21:25:38 | 000,043,392 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\drivers\MpNWMon.sys
[2007.04.26 19:23:06 | 000,100,095 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\System32\drivers\SafeBoot.sys

< %systemroot%\System32\config\*.sav >
[2006.11.02 11:34:05 | 000,008,192 | ---- | M] () -- C:\WINDOWS\System32\config\COMPONENTS.SAV
[2006.11.02 11:34:05 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\config\DEFAULT.SAV
[2006.11.02 11:34:05 | 000,008,192 | ---- | M] () -- C:\WINDOWS\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\WINDOWS\System32\config\SYSTEM.SAV

< %systemroot%\system32\*.dll /lockedfiles >
[2009.03.08 12:31:42 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtmsft.dll
[2009.03.08 12:31:37 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtrans.dll
[2009.04.11 07:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\rsaenh.dll
[2009.04.11 07:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\SLC.dll

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *

< %systemroot%\system32\drivers\*.sys /3 >
[2011.02.11 21:27:29 | 000,273,920 | ---- | M] () -- C:\WINDOWS\System32\drivers\afd.sys
[2011.02.10 23:57:14 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gojevqmw.sys

< %systemroot%\system32\*.* /3 >
[2011.02.13 21:29:03 | 000,003,296 | -H-- | M] () -- C:\WINDOWS\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.02.13 21:29:04 | 000,003,296 | -H-- | M] () -- C:\WINDOWS\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.02.11 15:28:19 | 000,000,468 | ---- | M] () -- C:\WINDOWS\System32\Datei0
[2011.02.11 15:28:19 | 000,000,470 | ---- | M] () -- C:\WINDOWS\System32\Datei1
[2011.02.11 15:28:19 | 000,000,470 | ---- | M] () -- C:\WINDOWS\System32\Datei2
[2011.02.11 15:28:19 | 000,000,470 | ---- | M] () -- C:\WINDOWS\System32\Datei3
[2011.02.11 15:28:19 | 000,000,471 | ---- | M] () -- C:\WINDOWS\System32\Datei4
[2011.02.11 15:28:19 | 000,000,469 | ---- | M] () -- C:\WINDOWS\System32\Datei5
[2011.02.11 15:28:19 | 000,000,465 | ---- | M] () -- C:\WINDOWS\System32\Datei6
[2011.02.11 15:28:19 | 000,000,469 | ---- | M] () -- C:\WINDOWS\System32\Datei7
[2011.02.11 15:28:19 | 000,000,467 | ---- | M] () -- C:\WINDOWS\System32\Datei8
[2011.02.11 15:28:19 | 000,000,467 | ---- | M] () -- C:\WINDOWS\System32\Datei9
[2011.02.12 07:05:18 | 000,388,240 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.02.13 21:29:09 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\log.txt
[2011.02.13 17:43:48 | 000,141,350 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.02.13 17:43:48 | 000,126,402 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.02.13 17:43:48 | 000,664,590 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.02.13 17:43:48 | 000,653,132 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.02.13 17:43:48 | 001,581,866 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

< End of report >

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 13:33
od Caroprd111
Obrázek Spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:OTL
SRV - File not found [On_Demand | Stopped] -- -- (TLSW)
SRV - File not found [On_Demand | Stopped] -- -- (QVKRD)
SRV - File not found [On_Demand | Stopped] -- -- (FNU)
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\randula\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
IE - HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
[2011.02.10 23:57:14 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\gojevqmw.sys
[2011.02.10 11:24:55 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\cbksqquy.sys
[2011.02.10 08:51:02 | 520,211,420 | ---- | M] () -- C:\Windows\System32\KYNFPUFBLFR
[2011.02.09 17:45:14 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\cfoycasb.sys
[2011.02.09 17:38:04 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrrncgqf.sys
[2011.02.09 17:12:49 | 000,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\cfhksyco.sys
[2011.02.10 11:24:55 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\cbksqquy.sys
[2007.12.13 14:43:43 | 000,001,025 | ---- | C] () -- C:\Windows\System32\sysprs7.dll
[2007.12.13 14:43:43 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth2.dll
[2007.12.13 14:43:43 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth1.dll
[2007.12.13 14:43:43 | 000,000,342 | ---- | C] () -- C:\Windows\System32\lsprst7.dll
[2007.12.13 14:43:43 | 000,000,073 | ---- | C] () -- C:\Windows\System32\ssprs.dll
[2007.11.15 11:47:35 | 000,074,120 | ---- | C] () -- C:\Windows\System32\bgsresen.dll
[2007.11.15 11:47:35 | 000,070,024 | ---- | C] () -- C:\Windows\System32\bgsresfr.dll
[2007.11.15 11:47:35 | 000,070,024 | ---- | C] () -- C:\Windows\System32\bgsreses.dll
[2007.11.15 11:47:35 | 000,070,024 | ---- | C] () -- C:\Windows\System32\bgsresde.dll
[2007.11.15 11:47:34 | 000,057,736 | ---- | C] () -- C:\Windows\System32\bgspmnt.dll

:Commands
[EMPTYTEMP] 
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
Klikněte na Opravit, PC se restartuje, log vložte sem.

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 14:25
od scuser
All processes killed
========== OTL ==========
Service TLSW stopped successfully!
Service TLSW deleted successfully!
Service QVKRD stopped successfully!
Service QVKRD deleted successfully!
Service FNU stopped successfully!
Service FNU deleted successfully!
Registry key HKEY_USERS\S-1-5-21-972185092-1158475264-1021527904-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-972185092-1158475264-1021527904-1003\Software\Microsoft\Internet Explorer\URLSearchHooks not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95289393-33EA-4F8D-B952-483415B9C955}\ deleted successfully.
C:\Users\randula\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll moved successfully.
HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-972185092-1158475264-1021527904-1003\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53707962-6F74-2D53-2644-206D7942484F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\Windows\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
C:\WINDOWS\System32\drivers\gojevqmw.sys moved successfully.
C:\WINDOWS\System32\drivers\cbksqquy.sys moved successfully.
C:\WINDOWS\System32\KYNFPUFBLFR moved successfully.
C:\WINDOWS\System32\drivers\cfoycasb.sys moved successfully.
C:\WINDOWS\System32\drivers\mrrncgqf.sys moved successfully.
C:\WINDOWS\System32\drivers\cfhksyco.sys moved successfully.
File C:\Windows\System32\drivers\cbksqquy.sys not found.
C:\WINDOWS\System32\sysprs7.dll moved successfully.
C:\WINDOWS\System32\clauth2.dll moved successfully.
C:\WINDOWS\System32\clauth1.dll moved successfully.
C:\WINDOWS\System32\lsprst7.dll moved successfully.
C:\WINDOWS\System32\ssprs.dll moved successfully.
C:\WINDOWS\System32\bgsresen.dll moved successfully.
C:\WINDOWS\System32\bgsresfr.dll moved successfully.
C:\WINDOWS\System32\bgsreses.dll moved successfully.
C:\WINDOWS\System32\bgsresde.dll moved successfully.
C:\WINDOWS\System32\bgspmnt.dll moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: randula
->Temp folder emptied: 34903006 bytes
->Temporary Internet Files folder emptied: 1539042 bytes
->Java cache emptied: 202287781 bytes
->FireFox cache emptied: 95768128 bytes
->Flash cache emptied: 46355 bytes

User: Test
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41620 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8418663 bytes
RecycleBin emptied: 32759464 bytes

Total Files Cleaned = 358,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: randula
->Flash cache emptied: 0 bytes

User: Test
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb



OTL by OldTimer - Version 3.2.20.6 log created on 02142011_141844

Files\Folders moved on Reboot...
File move failed. C:\Windows\temp\atchksrv.log scheduled to be moved on reboot.
File move failed. C:\Windows\temp\hlktmp scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 14:32
od Caroprd111
Jak se chová PC?

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 14:45
od scuser
Zdravím,

myslím že je naprosto svěží. Jediné co nechápu je že win Defender se nechce zapnout a hlásí
0800106ba (což je všehochuť odpovědí) a nepomáhá ani ručně zapnout službu.

Ty adresáře které pracovně vznikly mohu asi klidně odstranit ?

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 15:57
od Caroprd111
Defender nechte vypnutý, NOD32 obsahuje antispyware.


Obrázek Odinstalujte ComboFix přes:
Start >> Spustit, zkopírujte do okénka:

ComboFix /Uninstall

stiskněte Enter

Obrázek Stáhněte TFC http://oldtimer.geekstogo.com/TFC.exe
  • Spusťte.
  • Klikněte na "Start". Potvrďte hlášku kliknutím na "Ok" (Bude následovat restart)

Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky kliknutím na "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít

Obrázek Dejte log z RSIT.

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 20:04
od scuser
Zdravim, posílám Log. Vypadá to dobře.

Logfile of random's system information tool 1.08 (written by random/random)
Run by randula at 2011-02-14 20:01:42
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 58 GB (40%) free of 144 GB
Total RAM: 2015 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:02:00, on 14.2.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19019)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Hewlett-Packard\IAM\bin\asghost.exe
C:\Windows\Explorer.EXE
C:\WINDOWS\SMINST\scheduler.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\PDF Complete\pdfsty.exe
C:\WINDOWS\System32\bgsmsnd.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\randula\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 9\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\randula\Downloads\unvir\RSIT.exe
C:\Program Files\trend micro\randula.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.softconsult.tv/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: pdfMachine - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\Windows\system32\bgstb.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O3 - Toolbar: Web Accessibility Toolbar - {11352A67-0178-46B1-8855-D50B2F81C054} - C:\PROGRA~1\ACCESS~1\ACCESS~1.DLL
O3 - Toolbar: pdfMachine - {56CF4856-ECB4-4e46-A897-A378821F97B9} - C:\Windows\system32\bgstb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\ifxspmgt.exe /NotifyLogon
O4 - HKLM\..\Run: [PDF Complete] "C:\Program Files\PDF Complete\pdfsty.exe"
O4 - HKLM\..\Run: [bgsmsnd.exe] C:\Windows\system32\bgsmsnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\RunOnce: [ST Recovery Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\randula\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O16 - DPF: {5FB60DF1-234D-4067-8A61-536E540DA81E} (royalstone Control) - http://www.webplaner-innoplus.de/royals ... lstone.cab
O16 - DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} (Active602XMLFiller Control) - https://www.mojedatovaschranka.cz/stati ... ?3,16,13,0
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/ ... erCtrl.cab
O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} (O2C-Player (ELECO Software GmbH)) - http://www.o2c.de/download/o2cplayer.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://googleonline.webex.com/client/T ... atgpc1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5F80D403-E85B-4897-B8D7-4D1DD9827591}: NameServer = 217.11.224.1,217.11.224.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: Google Update Service (gupdate1c9c974a3a17236) (gupdate1c9c974a3a17236) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\AMT\UNS.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9942 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-972185092-1158475264-1021527904-1003Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-972185092-1158475264-1021527904-1003UA.job
C:\Windows\tasks\User_Feed_Synchronization-{D5D93112-F6F4-4B41-82DF-0823431BBFAF}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-05-04 308856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56CF4856-ECB4-4e46-A897-A378821F97B9}]
pdfMachine - C:\Windows\system32\bgstb.dll [2007-11-19 270728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-26 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-09-17 842296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-08-26 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
Credential Manager for HP ProtectTools - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll [2006-11-21 71192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{11352A67-0178-46B1-8855-D50B2F81C054} - Web Accessibility Toolbar - C:\PROGRA~1\ACCESS~1\ACCESS~1.DLL [2007-10-26 429056]
{56CF4856-ECB4-4e46-A897-A378821F97B9} - pdfMachine - C:\Windows\system32\bgstb.dll [2007-11-19 270728]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-26 256112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PTHOSTTR"=C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2007-01-09 145184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-28 1045800]
"HP Health Check Scheduler"=C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2007-03-12 50696]
"CognizanceTS"=C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll [2003-12-22 17920]
"HP Software Update"=c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-16 49152]
"WatchDog"=C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2007-05-23 192512]
"openvpn-gui"=C:\Program Files\OpenVPN\bin\openvpn-gui.exe [2005-08-18 99328]
"IFXSPMGT"=C:\Windows\system32\ifxspmgt.exe [2007-02-15 677408]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2008-01-16 330264]
"bgsmsnd.exe"=C:\Windows\system32\bgsmsnd.exe [2007-11-19 160136]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-11-04 1753192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ST Recovery Launcher"=C:\Windows\SMINST\launcher.exe [2007-03-09 44168]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"Google Update"=C:\Users\randula\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-05 133104]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-01-14 39408]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
DVD Check.lnk - C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\Windows\system32\DeviceNP.dll [2007-04-30 49152]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-02-14 19:33:18 ----D---- C:\Program Files\CCleaner
2011-02-14 14:18:44 ----D---- C:\_OTL
2011-02-12 20:01:33 ----D---- C:\rsit
2011-02-12 07:16:44 ----A---- C:\Windows\system32\shsvcs.dll
2011-02-12 02:01:15 ----A---- C:\Windows\system32\srvsvc.dll
2011-02-12 02:01:14 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-02-12 02:01:14 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-02-12 02:01:14 ----A---- C:\Windows\system32\drivers\srv.sys
2011-02-12 02:01:13 ----A---- C:\Windows\system32\netevent.dll
2011-02-12 01:56:48 ----A---- C:\Windows\system32\wmploc.DLL
2011-02-12 01:56:48 ----A---- C:\Windows\system32\wmp.dll
2011-02-12 01:49:51 ----D---- C:\Program Files\Windows Portable Devices
2011-02-12 01:47:50 ----A---- C:\Windows\system32\usp10.dll
2011-02-12 01:47:24 ----A---- C:\Windows\system32\schannel.dll
2011-02-12 01:47:05 ----A---- C:\Windows\system32\odbc32.dll
2011-02-12 01:46:54 ----A---- C:\Windows\system32\win32k.sys
2011-02-12 01:45:32 ----A---- C:\Windows\system32\stobject.dll
2011-02-12 01:45:31 ----A---- C:\Windows\system32\XpsPrint.dll
2011-02-12 01:45:31 ----A---- C:\Windows\system32\shdocvw.dll
2011-02-12 01:45:31 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2011-02-12 01:45:30 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2011-02-12 01:45:30 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-02-12 01:45:30 ----A---- C:\Windows\system32\mfplat.dll
2011-02-12 01:45:30 ----A---- C:\Windows\system32\mfmp4src.dll
2011-02-12 01:45:30 ----A---- C:\Windows\system32\MFHEAACdec.dll
2011-02-12 01:45:29 ----A---- C:\Windows\system32\mfps.dll
2011-02-12 01:45:29 ----A---- C:\Windows\system32\MFH264Dec.dll
2011-02-12 01:45:28 ----A---- C:\Windows\system32\mf.dll
2011-02-12 01:45:28 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-12 01:45:28 ----A---- C:\Windows\system32\cdd.dll
2011-02-12 01:45:27 ----A---- C:\Windows\system32\dxgi.dll
2011-02-12 01:45:27 ----A---- C:\Windows\system32\d3d10warp.dll
2011-02-12 01:45:27 ----A---- C:\Windows\system32\d3d10core.dll
2011-02-12 01:45:27 ----A---- C:\Windows\system32\d3d10.dll
2011-02-12 01:45:26 ----A---- C:\Windows\system32\DWrite.dll
2011-02-12 01:45:26 ----A---- C:\Windows\system32\d3d10level9.dll
2011-02-12 01:45:26 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-02-12 01:45:26 ----A---- C:\Windows\system32\d3d10_1.dll
2011-02-12 01:45:24 ----A---- C:\Windows\system32\FntCache.dll
2011-02-12 01:45:24 ----A---- C:\Windows\system32\d2d1.dll
2011-02-12 01:45:21 ----A---- C:\Windows\system32\OpcServices.dll
2011-02-12 01:45:20 ----A---- C:\Windows\system32\xpsservices.dll
2011-02-12 01:45:20 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-02-12 01:45:20 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-02-12 01:45:03 ----A---- C:\Windows\system32\ole32.dll
2011-02-12 01:44:31 ----A---- C:\Windows\system32\spoolsv.exe
2011-02-12 01:44:18 ----A---- C:\Windows\system32\t2embed.dll
2011-02-12 01:44:10 ----A---- C:\Windows\system32\sdclt.exe
2011-02-12 01:43:44 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2011-02-12 01:43:43 ----A---- C:\Windows\system32\gameux.dll
2011-02-12 01:43:36 ----A---- C:\Windows\system32\Apphlpdm.dll
2011-02-12 01:43:29 ----A---- C:\Windows\system32\MP4SDECD.DLL
2011-02-12 01:43:22 ----A---- C:\Windows\system32\mfc40.dll
2011-02-12 01:43:21 ----A---- C:\Windows\system32\mfc40u.dll
2011-02-12 01:42:55 ----A---- C:\Windows\system32\ieui.dll
2011-02-12 01:42:54 ----A---- C:\Windows\system32\ieframe.dll
2011-02-12 01:42:53 ----A---- C:\Windows\system32\iesysprep.dll
2011-02-12 01:42:53 ----A---- C:\Windows\system32\iesetup.dll
2011-02-12 01:42:53 ----A---- C:\Windows\system32\iertutil.dll
2011-02-12 01:42:53 ----A---- C:\Windows\system32\iernonce.dll
2011-02-12 01:42:53 ----A---- C:\Windows\system32\ie4uinit.exe
2011-02-12 01:42:52 ----A---- C:\Windows\system32\occache.dll
2011-02-12 01:42:52 ----A---- C:\Windows\system32\ieUnatt.exe
2011-02-12 01:42:50 ----A---- C:\Windows\system32\mshtml.dll
2011-02-12 01:42:49 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-12 01:42:49 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-12 01:42:49 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-12 01:42:49 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-12 01:42:48 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-12 01:42:48 ----A---- C:\Windows\system32\iepeers.dll
2011-02-12 01:42:48 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-12 01:42:47 ----A---- C:\Windows\system32\wininet.dll
2011-02-12 01:42:47 ----A---- C:\Windows\system32\jsproxy.dll
2011-02-12 01:42:46 ----A---- C:\Windows\system32\urlmon.dll
2011-02-12 01:42:46 ----A---- C:\Windows\system32\mstime.dll
2011-02-12 01:42:39 ----A---- C:\Windows\system32\wmpmde.dll
2011-02-12 01:42:21 ----A---- C:\Windows\system32\shlwapi.dll
2011-02-12 01:42:19 ----A---- C:\Windows\system32\shell32.dll
2011-02-12 01:42:01 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-02-12 01:42:01 ----A---- C:\Windows\system32\taskeng.exe
2011-02-12 01:42:01 ----A---- C:\Windows\system32\schedsvc.dll
2011-02-12 01:42:00 ----A---- C:\Windows\system32\taskschd.dll
2011-02-12 01:42:00 ----A---- C:\Windows\system32\taskcomp.dll
2011-02-12 01:41:50 ----A---- C:\Windows\system32\consent.exe
2011-02-12 01:41:10 ----A---- C:\Windows\system32\tzres.dll
2011-02-12 01:40:25 ----A---- C:\Windows\system32\fontsub.dll
2011-02-12 01:40:25 ----A---- C:\Windows\system32\atmlib.dll
2011-02-12 01:40:25 ----A---- C:\Windows\system32\atmfd.dll
2011-02-12 01:40:14 ----A---- C:\Windows\system32\inetcomm.dll
2011-02-12 01:40:02 ----A---- C:\Windows\system32\comctl32.dll
2011-02-12 01:39:55 ----A---- C:\Windows\system32\msshsq.dll
2011-02-12 01:31:11 ----A---- C:\Windows\system32\UIAnimation.dll
2011-02-12 01:31:10 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-02-12 01:31:10 ----A---- C:\Windows\system32\UIRibbon.dll
2011-02-12 01:30:35 ----A---- C:\Windows\system32\WMPhoto.dll
2011-02-12 01:30:32 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2011-02-12 01:30:32 ----A---- C:\Windows\system32\WindowsCodecs.dll
2011-02-12 01:30:32 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2011-02-12 01:30:32 ----A---- C:\Windows\system32\dxdiagn.dll
2011-02-12 01:30:32 ----A---- C:\Windows\system32\dxdiag.exe
2011-02-12 01:30:31 ----A---- C:\Windows\system32\d3d11.dll
2011-02-12 01:30:04 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2011-02-12 01:30:04 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2011-02-12 01:30:03 ----A---- C:\Windows\system32\wpdbusenum.dll
2011-02-12 01:29:57 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2011-02-12 01:29:51 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2011-02-12 01:29:51 ----A---- C:\Windows\system32\wpdshext.dll
2011-02-12 01:29:51 ----A---- C:\Windows\system32\wpd_ci.dll
2011-02-12 01:29:51 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2011-02-12 01:29:51 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2011-02-12 01:29:50 ----A---- C:\Windows\system32\WPDSp.dll
2011-02-12 01:29:50 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2011-02-12 01:29:50 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2011-02-12 01:28:39 ----A---- C:\Windows\system32\oleaccrc.dll
2011-02-12 01:28:38 ----A---- C:\Windows\system32\oleacc.dll
2011-02-12 01:28:37 ----A---- C:\Windows\system32\UIAutomationCore.dll
2011-02-12 01:19:48 ----D---- C:\ProgramData\NVIDIA Corporation
2011-02-12 01:19:33 ----D---- C:\Program Files\NVIDIA Corporation
2011-02-11 22:59:57 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-02-11 22:59:57 ----A---- C:\Windows\system32\ntdll.dll
2011-02-11 22:59:56 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-11 21:57:12 ----D---- C:\Program Files\Microsoft Security Client
2011-02-11 21:31:38 ----A---- C:\TDSSKiller.2.4.17.0_11.02.2011_21.31.38_log.txt
2011-02-11 21:25:03 ----A---- C:\TDSSKiller.2.4.17.0_11.02.2011_21.25.03_log.txt
2011-02-10 15:47:48 ----D---- C:\Program Files\trend micro
2011-02-10 14:54:02 ----SHD---- C:\$RECYCLE.BIN
2011-02-10 11:30:12 ----D---- C:\Windows\ERDNT
2011-02-10 11:22:54 ----D---- C:\Windows\system32\MpEngineStore
2011-02-09 16:48:05 ----A---- C:\Windows\system32\drivers\netio.sys
2011-02-07 16:59:55 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-02-07 16:59:55 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-02-07 16:59:55 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-02-07 16:59:55 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-02-07 16:59:55 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-02-07 16:59:55 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-02-07 16:59:55 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-02-07 16:59:55 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-02-07 16:59:55 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-02-07 16:59:54 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-02-07 16:59:54 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-02-07 16:59:54 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-02-07 16:59:53 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-02-07 16:59:52 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-02-07 16:59:52 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-02-07 16:59:52 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-02-07 16:59:52 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-02-07 16:59:52 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-02-07 16:59:51 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-02-07 16:59:50 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-02-07 16:59:49 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-02-07 16:59:48 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-02-07 16:59:48 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-02-07 16:59:48 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-02-07 16:59:48 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-02-07 16:59:48 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-02-07 16:59:48 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-02-07 16:59:48 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-02-07 16:59:48 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-02-07 16:59:47 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-02-07 16:59:47 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-02-07 16:59:47 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-02-07 16:59:47 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-02-07 16:59:47 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-02-07 16:59:47 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\xinput1_3.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-02-07 16:59:46 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-02-07 16:59:45 ----A---- C:\Windows\system32\xinput1_2.dll
2011-02-07 16:59:45 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-02-07 16:59:45 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-02-07 16:59:45 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-02-07 16:59:45 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-02-07 16:59:45 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-02-07 16:59:45 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-02-07 16:59:45 ----A---- C:\Windows\system32\d3dx10.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\xinput1_1.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-02-07 16:59:44 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-02-07 16:59:43 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-02-07 16:59:43 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-02-07 16:57:45 ----D---- C:\Windows\system32\directx
2011-01-28 11:20:09 ----D---- C:\Users\randula\AppData\Roaming\Softtech
2011-01-28 11:16:30 ----D---- C:\ProgramData\Softtech
2011-01-26 14:49:30 ----D---- C:\Users\randula\AppData\Roaming\TeamViewer
2011-01-20 13:48:08 ----D---- C:\Program Files\Mozilla Firefox 4.0 Beta 9

======List of files/folders modified in the last 1 months======

2011-02-14 20:02:00 ----D---- C:\Windows\Prefetch
2011-02-14 19:57:07 ----D---- C:\Windows\Temp
2011-02-14 19:57:07 ----D---- C:\Windows\Debug
2011-02-14 19:57:07 ----D---- C:\WINDOWS
2011-02-14 19:35:45 ----SHD---- C:\System Volume Information
2011-02-14 19:33:18 ----D---- C:\Program Files
2011-02-14 19:24:01 ----D---- C:\Windows\system32\Tasks
2011-02-14 19:22:56 ----D---- C:\Windows\SMINST
2011-02-14 19:22:37 ----D---- C:\Program Files\Common Files\Akamai
2011-02-14 19:22:37 ----A---- C:\Windows\system32\log.txt
2011-02-14 19:17:00 ----D---- C:\Windows\system32\drivers
2011-02-14 14:52:57 ----D---- C:\Users\randula\AppData\Roaming\aec-creative
2011-02-14 14:47:09 ----D---- C:\Users\randula\AppData\Roaming\FileZilla
2011-02-14 14:31:35 ----D---- C:\Program Files\SeaMonkey
2011-02-14 14:28:01 ----D---- C:\Program Files\QIP Infium
2011-02-14 14:18:54 ----D---- C:\Windows\System32
2011-02-14 14:18:53 ----SD---- C:\Windows\Downloaded Program Files
2011-02-14 13:48:57 ----D---- C:\Users\randula\AppData\Roaming\Skype
2011-02-14 12:38:24 ----D---- C:\Users\randula\AppData\Roaming\skypePM
2011-02-14 12:29:20 ----D---- C:\Windows\inf
2011-02-14 12:29:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-14 02:35:57 ----D---- C:\Windows\system32\config
2011-02-14 02:35:45 ----D---- C:\Windows\Tasks
2011-02-14 02:35:45 ----D---- C:\Windows\system32\cs-CZ
2011-02-14 02:35:44 ----D---- C:\Windows\system32\spool
2011-02-14 02:35:44 ----D---- C:\Windows\system32\Msdtc
2011-02-14 02:35:44 ----D---- C:\Windows\system32\drivers\etc
2011-02-14 02:35:44 ----D---- C:\Windows\system32\CodeIntegrity
2011-02-14 02:35:44 ----D---- C:\Windows\system32\catroot2
2011-02-14 02:35:42 ----D---- C:\Windows\system32\wbem
2011-02-14 02:35:42 ----D---- C:\Windows\registration
2011-02-13 17:22:01 ----D---- C:\Windows\AppPatch
2011-02-13 17:22:01 ----D---- C:\Program Files\Common Files
2011-02-12 21:25:01 ----D---- C:\Windows\Minidump
2011-02-12 19:05:03 ----D---- C:\Windows\rescache
2011-02-12 16:17:37 ----D---- C:\Windows\winsxs
2011-02-12 08:46:29 ----D---- C:\Program Files\Common Files\Services
2011-02-12 08:46:21 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-02-12 07:59:13 ----D---- C:\Windows\Microsoft.NET
2011-02-12 07:59:12 ----RSD---- C:\Windows\assembly
2011-02-12 07:45:54 ----SHD---- C:\Windows\Installer
2011-02-12 07:41:50 ----D---- C:\Windows\system32\en-US
2011-02-12 07:41:46 ----D---- C:\Program Files\Microsoft.NET
2011-02-12 07:14:08 ----D---- C:\Windows\system32\catroot
2011-02-12 07:10:35 ----D---- C:\Program Files\Windows Mail
2011-02-12 07:04:01 ----D---- C:\Program Files\Microsoft Silverlight
2011-02-12 07:01:58 ----D---- C:\Program Files\Windows Media Player
2011-02-12 07:01:54 ----D---- C:\Program Files\Internet Explorer
2011-02-12 07:01:53 ----D---- C:\Windows\system32\migration
2011-02-12 02:15:38 ----D---- C:\Program Files\Microsoft SQL Server
2011-02-12 01:52:49 ----D---- C:\ProgramData\NVIDIA
2011-02-12 01:49:52 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-02-12 01:49:50 ----D---- C:\Windows\system32\pt-PT
2011-02-12 01:49:50 ----D---- C:\Windows\system32\pt-BR
2011-02-12 01:49:50 ----D---- C:\Windows\system32\pl-PL
2011-02-12 01:49:50 ----D---- C:\Windows\system32\it-IT
2011-02-12 01:49:50 ----D---- C:\Windows\system32\he-IL
2011-02-12 01:49:50 ----D---- C:\Windows\system32\bg-BG
2011-02-12 01:49:49 ----D---- C:\Windows\system32\zh-TW
2011-02-12 01:49:49 ----D---- C:\Windows\system32\zh-HK
2011-02-12 01:49:49 ----D---- C:\Windows\system32\zh-CN
2011-02-12 01:49:49 ----D---- C:\Windows\system32\uk-UA
2011-02-12 01:49:49 ----D---- C:\Windows\system32\tr-TR
2011-02-12 01:49:49 ----D---- C:\Windows\system32\th-TH
2011-02-12 01:49:49 ----D---- C:\Windows\system32\sv-SE
2011-02-12 01:49:49 ----D---- C:\Windows\system32\sr-Latn-CS
2011-02-12 01:49:49 ----D---- C:\Windows\system32\sl-SI
2011-02-12 01:49:49 ----D---- C:\Windows\system32\sk-SK
2011-02-12 01:49:49 ----D---- C:\Windows\system32\ru-RU
2011-02-12 01:49:49 ----D---- C:\Windows\system32\ro-RO
2011-02-12 01:49:49 ----D---- C:\Windows\system32\nl-NL
2011-02-12 01:49:49 ----D---- C:\Windows\system32\nb-NO
2011-02-12 01:49:49 ----D---- C:\Windows\system32\lv-LV
2011-02-12 01:49:49 ----D---- C:\Windows\system32\lt-LT
2011-02-12 01:49:49 ----D---- C:\Windows\system32\ko-KR
2011-02-12 01:49:49 ----D---- C:\Windows\system32\ja-JP
2011-02-12 01:49:49 ----D---- C:\Windows\system32\hu-HU
2011-02-12 01:49:49 ----D---- C:\Windows\system32\hr-HR
2011-02-12 01:49:49 ----D---- C:\Windows\system32\fr-FR
2011-02-12 01:49:49 ----D---- C:\Windows\system32\fi-FI
2011-02-12 01:49:49 ----D---- C:\Windows\system32\et-EE
2011-02-12 01:49:49 ----D---- C:\Windows\system32\es-ES
2011-02-12 01:49:49 ----D---- C:\Windows\system32\el-GR
2011-02-12 01:49:49 ----D---- C:\Windows\system32\de-DE
2011-02-12 01:49:49 ----D---- C:\Windows\system32\da-DK
2011-02-12 01:49:49 ----D---- C:\Windows\system32\ar-SA
2011-02-12 01:49:02 ----D---- C:\Windows\system32\drivers\UMDF
2011-02-12 01:20:47 ----D---- C:\Windows\Help
2011-02-12 01:19:48 ----D---- C:\ProgramData
2011-02-11 15:21:42 ----D---- C:\Users\randula\AppData\Roaming\pdfMachine
2011-02-11 13:46:13 ----D---- C:\ProgramData\aec-creative
2011-02-10 16:10:41 ----D---- C:\Program Files\BioAdmin
2011-02-10 14:50:15 ----A---- C:\Windows\system.ini
2011-02-09 21:25:34 ----HD---- C:\Windows\system32\GroupPolicy
2011-02-09 16:48:30 ----SD---- C:\ProgramData\Microsoft
2011-02-09 16:47:01 ----SD---- C:\Users\randula\AppData\Roaming\Microsoft
2011-02-07 16:59:44 ----D---- C:\Windows\Logs
2011-02-07 16:57:46 ----D---- C:\temp
2011-02-04 17:34:02 ----A---- C:\Windows\system32\mrt.exe
2011-02-02 17:11:20 ----N---- C:\Windows\system32\MpSigStub.exe
2011-02-02 14:35:13 ----D---- C:\ProgramData\Roxio
2011-01-26 11:21:47 ----RD---- C:\Users
2011-01-24 20:55:51 ----D---- C:\Program Files\FAMADA

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2008-08-07 25392]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-03-21 304920]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2006-07-24 36528]
R0 SafeBoot;SafeBoot; C:\Windows\system32\drivers\SafeBoot.sys [2007-04-26 100095]
R0 SbAlg;SbAlg; C:\Windows\system32\drivers\SbAlg.sys [2006-10-09 44720]
R0 SbFsLock;SbFsLock; C:\Windows\system32\drivers\SbFsLock.sys [2007-03-29 13696]
R1 eabfiltr;eabfiltr; C:\Windows\system32\DRIVERS\eabfiltr.sys [2006-11-30 8192]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 PersonalSecureDrive;PersonalSecureDrive; C:\Windows\System32\drivers\psd.sys [2007-01-23 39080]
R1 RsvLock;RsvLock; C:\Windows\system32\drivers\RsvLock.sys [2007-04-26 5808]
R2 Hardlock;Hardlock; C:\Windows\system32\drivers\hardlock.sys [2006-11-22 693760]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2007-04-16 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-01-23 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-04-16 8192]
R3 Accelerometer;HP Accelerometer; C:\Windows\system32\DRIVERS\Accelerometer.sys [2008-08-07 34608]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-19 220672]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2007-04-06 44800]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-04-16 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-04-16 207360]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-12-04 10370152]
R3 rismc32;RICOH Smart Card Reader; C:\Windows\system32\DRIVERS\rismc32.sys [2006-12-20 47616]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-03-28 199472]
R3 tap0801;TAP-Win32 Adapter V8; C:\Windows\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2008-01-19 45624]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-04-16 659968]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\Windows\system32\DRIVERS\adusbser.sys [2006-12-20 97920]
S3 akshasp;Aladdin HASP Key; C:\Windows\system32\DRIVERS\akshasp.sys [2006-11-22 327168]
S3 aksusb;Aladdin USB Key; C:\Windows\system32\DRIVERS\aksusb.sys [2006-11-17 100096]
S3 ATSWPDRV;(****DEBUG****) AuthenTec TruePrint USB Driver (SwipeSensor); C:\Windows\system32\DRIVERS\ATSwpDrv.sys [2007-04-10 140808]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 167936]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-03-01 534016]
S3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-03-01 534016]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
S3 catchme;catchme; \??\C:\Users\randula\AppData\Local\Temp\catchme.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 23424]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 102912]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 101120]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-03-29 21248]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-03-29 20096]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NETw4v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 SynasUSB;SynasUSB; C:\Windows\system32\drivers\SynasUSB.sys [2005-11-03 16896]
S3 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2006-11-02 128104]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 ASBroker;Logon Session Broker; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 ASChannel;Local Communication Channel; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 atchksrv;Intel(R) Active Management Technology System Status Service; C:\Program Files\Intel\AMT\atchksrv.exe [2007-04-10 183064]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-03-14 62984]
R2 HpFkCryptService;Drive Encryption Service; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2007-04-27 221184]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2008-08-07 24880]
R2 IFXSpMgtSrv;Security Platform Management Service; C:\Windows\system32\ifxspmgt.exe [2007-02-15 677408]
R2 IFXTCS;Trusted Platform Core Service; C:\Windows\system32\ifxtcs.exe [2007-01-23 849440]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-04-19 75304]
R2 LMS;Intel(R) Active Management Technology Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2007-04-10 121624]
R2 LPDSVC;@%systemroot%\system32\lpdsvc.dll,-500; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 MySQL;MySQL; C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld --defaults-file=C:\Program Files\MySQL\MySQL Server 5.1\my.ini MySQL []
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-12-04 129640]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2008-01-16 542744]
R2 PersonalSecureDriveService;Personal Secure Drive service; C:\Windows\system32\IfxPsdSv.exe [2007-02-15 140832]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 UNS;Intel(R) Active Management Technology User Notification Service; C:\Program Files\Intel\AMT\UNS.exe [2007-04-10 1489688]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-04-16 386560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate1c9c974a3a17236;Google Update Service (gupdate1c9c974a3a17236); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-30 133104]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 Com4Qlb;Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [2007-03-05 110592]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\Windows\system32\flcdlock.exe [2007-04-30 172131]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-05 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2006-10-01 16384]
S3 RoxMediaDB9;RoxMediaDB9; c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2006-11-06 887544]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2006-11-01 73728]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]

-----------------EOF-----------------

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 20:32
od Caroprd111
Log je v pořádku, jen nevidím antivir. :)

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 20:53
od scuser
Zdravím,
mám nakonec MS Essentials (avg mě zklamalo) a node32 jsem jen zkoušel.

Ještě jednou díky za profi přístup.

Pracujeme na novém portálu pro download 3D objektů a bude tam sekce hot news (od výrobců co poskytují data zdarma) + fórum kolem rad 3D sw. Myslím si že by tito uživatelé uvítali služby vašeho portálu (nějakou formou propojení). Jak to vidíte ?

Re: Problém s odstraněním "Olmarik trojský kůň"

Napsal: 14 úno 2011 20:57
od Caroprd111
Pomocí SZ mi to trochu upřesněte a já to projednám s moderátory.

Děkuji. :)