Stránka 2 z 4

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 11 kvě 2014 18:35
od jindra.paryzek
RogueKiller V8.8.15 [Mar 27 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Jindra M 5010 [Práva správce]
Mód : Oprava HOSTS -- Datum : 05/11/2014 19:33:05
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost


Dokončeno : << RKreport[0]_H_05112014_193305.txt >>
RKreport[0]_D_05112014_192913.txt;RKreport[0]_S_05112014_192012.txt;RKreport[0]_S_05112014_193224.txt

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 11 kvě 2014 18:39
od Márty84
:!: Pokud nemate, zazalohujte si radeji dulezita data (fotky, dokumenty, atd.) :!:

:!: Nepouzivejte ComboFix bez predchozi domluvy! Je to poruseni pravidel fora a ztratite tim narok na pomoc!

:arrow: Stahnete ComboFix http://download.bleepingcomputer.com/sUBs/ComboFix.exe a ulozte ho na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Kliknete na ComboFix pravym mysidlem a levym na Spustit jako spravce
Odsouhlaste licencni podminky a nechte program pracovat. Jestli vam nabidne instalaci Konzoly pro zotaveni, souhlaste.
Po dobu skenu nic nespoustejte, nikam neklikejte.
Po dokonceni skenovani (muze dojit i k restartu pc) by se mel vytvorit log, ktery bude umisteny zde C:\ComboFix.txt
Jeho obsah sem zkopirujte

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 11 kvě 2014 18:54
od jindra.paryzek
ComboFix 14-05-10.01 - Jindra M 5010 11.05.2014 19:43:43.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3068.1915 [GMT 2:00]
Spuštěný z: c:\users\Jindra M 5010\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-04-11 do 2014-05-11 )))))))))))))))))))))))))))))))
.
.
2014-05-11 17:50 . 2014-05-11 17:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-05-11 11:39 . 2014-05-11 11:39 -------- d-----w- c:\program files (x86)\HD Tune
2014-05-11 08:00 . 2014-05-11 09:55 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-11 08:00 . 2014-05-11 08:00 -------- d-----w- c:\programdata\Malwarebytes
2014-05-10 19:45 . 2014-05-10 19:46 -------- d-----w- C:\rsit
2014-05-10 19:45 . 2014-05-10 19:45 -------- d-----w- c:\program files\trend micro
2014-05-10 18:13 . 2014-05-10 14:46 -------- d-----w- c:\windows\Panther
2014-05-10 18:12 . 2014-05-10 08:33 -------- d-----w- c:\windows\system32\OEM
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\SysWow64\XPSViewer
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\SysWow64\drivers\cs-CZ
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\SysWow64\cs
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\system32\cs
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\cs-CZ
2014-05-10 18:11 . 2014-05-10 12:59 -------- d-----w- c:\windows\SysWow64\wbem\cs-CZ
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\system32\drivers\UMDF\cs-CZ
2014-05-10 18:11 . 2014-05-10 12:59 -------- d-----w- c:\windows\system32\wbem\cs-CZ
2014-05-10 18:11 . 2014-05-10 12:59 -------- d-----w- c:\windows\system32\drivers\cs-CZ
2014-05-10 18:07 . 2009-07-14 03:04 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\cs-CZ\LXKPTPRC.DLL.mui
2014-05-10 17:54 . 2014-05-10 17:54 -------- d-----w- C:\Windows.old.000
2014-05-10 15:54 . 2014-05-10 15:55 -------- d-----w- c:\program files (x86)\Dell
2014-05-10 15:49 . 2014-04-16 01:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{319C07B2-724E-46C0-A6FA-367F6EDC22CE}\mpengine.dll
2014-05-10 15:44 . 2014-05-10 15:44 -------- d-----w- c:\program files (x86)\MSXML 4.0
2014-05-10 14:57 . 2014-05-10 14:58 -------- d-----w- c:\programdata\Nokia
2014-05-10 14:57 . 2014-05-10 14:57 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2014-05-10 14:52 . 2014-05-10 14:52 -------- d-----w- c:\programdata\PC Suite
2014-05-10 14:52 . 2014-05-10 14:52 -------- d-----w- c:\program files (x86)\Common Files\PCSuite
2014-05-10 14:52 . 2014-05-10 14:57 -------- d-----w- c:\program files (x86)\Common Files\Nokia
2014-05-10 14:52 . 2014-05-10 14:52 -------- d-----w- c:\program files\DIFX
2014-05-10 14:52 . 2012-10-17 12:53 26112 ----a-w- c:\windows\system32\drivers\pccsmcfdx64.sys
2014-05-10 14:52 . 2014-05-10 14:57 -------- dc----w- c:\windows\system32\DRVSTORE
2014-05-10 14:51 . 2013-01-23 08:31 57856 ----a-w- c:\windows\system32\nmwcdclsX64.dll
2014-05-10 14:51 . 2014-05-10 14:57 -------- d-----w- c:\program files (x86)\Nokia
2014-05-10 14:50 . 2014-05-10 14:50 -------- d-----w- c:\programdata\Installations
2014-05-10 14:36 . 2014-05-10 14:36 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2014-05-10 14:25 . 2014-04-29 14:01 23547904 ----a-w- c:\windows\system32\mshtml.dll
2014-05-10 14:25 . 2014-04-29 13:40 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-10 14:25 . 2014-04-29 12:34 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-10 14:23 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-05-10 14:23 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll
2014-05-10 14:05 . 2014-03-06 08:15 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-05-10 13:52 . 2014-05-10 15:56 -------- d-----w- c:\program files\Microsoft Silverlight
2014-05-10 13:52 . 2014-05-10 15:56 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2014-05-10 13:51 . 2012-08-23 13:24 15360 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-05-10 13:51 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2014-05-10 13:51 . 2012-08-23 14:08 30208 ----a-w- c:\windows\system32\drivers\TsUsbGD.sys
2014-05-10 13:51 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2014-05-10 13:51 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll
2014-05-10 13:51 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2014-05-10 13:51 . 2012-08-23 09:51 3174912 ----a-w- c:\windows\system32\rdpcorets.dll
2014-05-10 13:50 . 2014-04-16 01:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-05-10 13:46 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-05-10 13:46 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-05-10 13:46 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2014-05-10 13:46 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-05-10 13:45 . 2014-04-24 18:00 127488 ----a-w- c:\windows\system32\ff_vfw.dll
2014-05-10 13:45 . 2013-03-17 17:22 3554304 ----a-w- c:\windows\system32\x264vfw64.dll
2014-05-10 13:45 . 2013-03-17 16:21 3649536 ----a-w- c:\windows\SysWow64\x264vfw.dll
2014-05-10 13:45 . 2011-12-07 17:37 148992 ----a-w- c:\windows\system32\lagarith.dll
2014-05-10 13:45 . 2011-12-07 17:32 216064 ----a-w- c:\windows\SysWow64\lagarith.dll
2014-05-10 13:44 . 2011-06-24 14:45 258560 ----a-w- c:\windows\system32\xvidvfw.dll
2014-05-10 13:44 . 2011-06-24 14:44 243200 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2014-05-10 13:44 . 2011-06-24 14:31 703488 ----a-w- c:\windows\system32\xvidcore.dll
2014-05-10 13:44 . 2011-06-24 14:28 650752 ----a-w- c:\windows\SysWow64\xvidcore.dll
2014-05-10 13:44 . 2012-07-21 10:55 180736 ----a-w- c:\windows\system32\ac3acm.acm
2014-05-10 13:44 . 2012-07-21 10:54 122880 ----a-w- c:\windows\SysWow64\ac3acm.acm
2014-05-10 13:44 . 2013-12-01 12:10 257624 ----a-w- c:\windows\system32\unrar64.dll
2014-05-10 13:44 . 2013-12-01 12:10 218200 ----a-w- c:\windows\SysWow64\unrar.dll
2014-05-10 13:44 . 2014-04-24 18:00 112640 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2014-05-10 13:44 . 2014-05-10 13:44 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack
2014-05-10 13:24 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2014-05-10 13:24 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2014-05-10 12:59 . 2014-05-10 12:59 -------- d-s---w- c:\windows\system32\CompatTel
2014-05-10 12:59 . 2014-05-10 12:59 -------- d-----w- c:\windows\SysWow64\Wat
2014-05-10 12:59 . 2014-05-10 12:59 -------- d-----w- c:\windows\system32\Wat
2014-05-10 12:35 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-05-10 12:35 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-05-10 12:35 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2014-05-10 12:35 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2014-05-10 12:35 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2014-05-10 12:18 . 2014-05-10 12:18 -------- d-----w- c:\program files (x86)\Microsoft.NET
2014-05-10 12:18 . 2014-05-10 12:18 -------- d-----w- c:\windows\Migration
2014-05-10 12:09 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2014-05-10 11:53 . 2014-05-10 11:53 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-10 11:14 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2014-05-10 11:05 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-05-10 10:33 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-05-10 10:33 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-05-10 10:33 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-05-10 10:33 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-05-10 10:33 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2014-05-10 10:33 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2014-05-10 10:33 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-05-10 10:26 . 2014-05-10 10:28 -------- d-----w- c:\windows\system32\MRT
2014-05-10 10:25 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-05-10 10:25 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-05-10 10:25 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-05-10 10:04 . 2013-07-04 12:50 633856 ----a-w- c:\windows\system32\comctl32.dll
2014-05-10 10:03 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2014-05-10 10:02 . 2013-10-05 20:25 1474048 ----a-w- c:\windows\system32\crypt32.dll
2014-05-10 10:01 . 2013-09-28 01:09 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-10 10:00 . 2013-09-25 02:22 340992 ----a-w- c:\windows\system32\schannel.dll
2014-05-10 09:59 . 2013-07-04 12:57 259584 ----a-w- c:\windows\system32\WebClnt.dll
2014-05-10 09:59 . 2013-07-04 12:50 102400 ----a-w- c:\windows\system32\davclnt.dll
2014-05-10 09:59 . 2013-07-04 11:57 205824 ----a-w- c:\windows\SysWow64\WebClnt.dll
2014-05-10 09:59 . 2013-07-04 11:51 81920 ----a-w- c:\windows\SysWow64\davclnt.dll
2014-05-10 09:59 . 2013-07-04 10:11 140800 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-05-10 09:59 . 2012-11-02 05:59 478208 ----a-w- c:\windows\system32\dpnet.dll
2014-05-10 09:59 . 2012-11-02 05:11 376832 ----a-w- c:\windows\SysWow64\dpnet.dll
2014-05-10 09:59 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2014-05-10 09:57 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2014-05-10 09:57 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2014-05-10 09:57 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2014-05-10 09:57 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2014-05-10 09:57 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-05-10 09:55 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys
2014-05-10 09:54 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll
2014-05-10 09:53 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2014-05-10 09:52 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2014-05-10 09:48 . 2014-05-10 09:48 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2014-05-10 09:47 . 2014-05-10 09:47 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2014-05-10 09:46 . 2009-03-17 09:07 14848 ----a-w- c:\windows\system32\Spool\prtprocs\x64\MIMFPR0H.DLL
2014-05-10 09:45 . 2014-05-10 09:45 -------- d-----w- c:\program files\KONICA MINOLTA
2014-05-10 09:29 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2014-05-10 09:29 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2014-05-10 09:21 . 2014-05-10 14:38 -------- d-----w- c:\program files\WinRAR
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-10 12:00 . 2014-05-10 12:00 208384 ----a-w- c:\windows\SysWow64\webcheck.dll
2014-05-10 12:00 . 2014-05-10 12:00 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-03-11 07:52 . 2014-03-11 07:52 133928 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-04 09:17 . 2014-05-10 09:54 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-05-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-10 09:19]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2014-05-10 6301696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.dell.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Jindra M 5010\AppData\Roaming\Mozilla\Firefox\Profiles\hn4xlcky.default\
FF - prefs.js: browser.search.selectedEngine - Seznam
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=undefined&q=
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-05-11 19:53:28
ComboFix-quarantined-files.txt 2014-05-11 17:53
.
Před spuštěním: Volných bajtů: 547 215 863 808
Po spuštění: Volných bajtů: 547 194 716 160
.
- - End Of File - - 7EB603F146966541851EAC22D134BF1E
A36C5E4F47E84449FF07ED3517B43A31

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 11 kvě 2014 19:03
od Márty84
:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

KillAll::

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Reboot::
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev CFScript a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Pretahntete mysi tento vytvoreny textovy dokument nad ikonu ComboFix a pustte.
ComboFix by se mel spustit a vykonat prikazy.
Az skonci (muze dojit k restartu pc), mel by se objevit novy log, ten mi sem zase zkopirujte.

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 11 kvě 2014 19:22
od jindra.paryzek
ComboFix 14-05-10.01 - Jindra M 5010 11.05.2014 20:08:30.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3068.2003 [GMT 2:00]
Spuštěný z: c:\users\Jindra M 5010\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jindra M 5010\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-04-11 do 2014-05-11 )))))))))))))))))))))))))))))))
.
.
2014-05-11 18:14 . 2014-05-11 18:14 -------- d-----w- c:\users\Jindra M5010\AppData\Local\temp
2014-05-11 11:39 . 2014-05-11 11:39 -------- d-----w- c:\program files (x86)\HD Tune
2014-05-11 08:00 . 2014-05-11 09:55 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-11 08:00 . 2014-05-11 08:00 -------- d-----w- c:\programdata\Malwarebytes
2014-05-10 19:45 . 2014-05-10 19:46 -------- d-----w- C:\rsit
2014-05-10 19:45 . 2014-05-10 19:45 -------- d-----w- c:\program files\trend micro
2014-05-10 18:13 . 2014-05-10 14:46 -------- d-----w- c:\windows\Panther
2014-05-10 18:12 . 2014-05-10 08:33 -------- d-----w- c:\windows\system32\OEM
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\SysWow64\XPSViewer
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\SysWow64\drivers\cs-CZ
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\SysWow64\cs
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\system32\cs
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\cs-CZ
2014-05-10 18:11 . 2014-05-10 12:59 -------- d-----w- c:\windows\SysWow64\wbem\cs-CZ
2014-05-10 18:11 . 2014-05-10 18:11 -------- d-----w- c:\windows\system32\drivers\UMDF\cs-CZ
2014-05-10 18:11 . 2014-05-10 12:59 -------- d-----w- c:\windows\system32\wbem\cs-CZ
2014-05-10 18:11 . 2014-05-10 12:59 -------- d-----w- c:\windows\system32\drivers\cs-CZ
2014-05-10 18:07 . 2009-07-14 03:04 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\cs-CZ\LXKPTPRC.DLL.mui
2014-05-10 17:54 . 2014-05-10 17:54 -------- d-----w- C:\Windows.old.000
2014-05-10 15:54 . 2014-05-10 15:55 -------- d-----w- c:\program files (x86)\Dell
2014-05-10 15:44 . 2014-05-10 15:44 -------- d-----w- c:\program files (x86)\MSXML 4.0
2014-05-10 14:57 . 2014-05-10 14:58 -------- d-----w- c:\programdata\Nokia
2014-05-10 14:57 . 2014-05-10 14:57 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2014-05-10 14:52 . 2014-05-10 14:52 -------- d-----w- c:\programdata\PC Suite
2014-05-10 14:52 . 2014-05-10 14:52 -------- d-----w- c:\program files (x86)\Common Files\PCSuite
2014-05-10 14:52 . 2014-05-10 14:57 -------- d-----w- c:\program files (x86)\Common Files\Nokia
2014-05-10 14:52 . 2014-05-10 14:52 -------- d-----w- c:\program files\DIFX
2014-05-10 14:52 . 2012-10-17 12:53 26112 ----a-w- c:\windows\system32\drivers\pccsmcfdx64.sys
2014-05-10 14:52 . 2014-05-10 14:57 -------- dc----w- c:\windows\system32\DRVSTORE
2014-05-10 14:51 . 2013-01-23 08:31 57856 ----a-w- c:\windows\system32\nmwcdclsX64.dll
2014-05-10 14:51 . 2014-05-10 14:57 -------- d-----w- c:\program files (x86)\Nokia
2014-05-10 14:50 . 2014-05-10 14:50 -------- d-----w- c:\programdata\Installations
2014-05-10 14:36 . 2014-05-10 14:36 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2014-05-10 14:25 . 2014-04-29 14:01 23547904 ----a-w- c:\windows\system32\mshtml.dll
2014-05-10 14:25 . 2014-04-29 13:40 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-10 14:25 . 2014-04-29 12:34 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-10 14:23 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-05-10 14:23 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll
2014-05-10 14:05 . 2014-03-06 08:15 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-05-10 13:52 . 2014-05-10 15:56 -------- d-----w- c:\program files\Microsoft Silverlight
2014-05-10 13:52 . 2014-05-10 15:56 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2014-05-10 13:51 . 2012-08-23 13:24 15360 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-05-10 13:51 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2014-05-10 13:51 . 2012-08-23 14:08 30208 ----a-w- c:\windows\system32\drivers\TsUsbGD.sys
2014-05-10 13:51 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2014-05-10 13:51 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll
2014-05-10 13:51 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2014-05-10 13:51 . 2012-08-23 09:51 3174912 ----a-w- c:\windows\system32\rdpcorets.dll
2014-05-10 13:50 . 2014-04-16 01:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-05-10 13:46 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-05-10 13:46 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-05-10 13:46 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2014-05-10 13:46 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-05-10 13:45 . 2014-04-24 18:00 127488 ----a-w- c:\windows\system32\ff_vfw.dll
2014-05-10 13:45 . 2013-03-17 17:22 3554304 ----a-w- c:\windows\system32\x264vfw64.dll
2014-05-10 13:45 . 2013-03-17 16:21 3649536 ----a-w- c:\windows\SysWow64\x264vfw.dll
2014-05-10 13:45 . 2011-12-07 17:37 148992 ----a-w- c:\windows\system32\lagarith.dll
2014-05-10 13:45 . 2011-12-07 17:32 216064 ----a-w- c:\windows\SysWow64\lagarith.dll
2014-05-10 13:44 . 2011-06-24 14:45 258560 ----a-w- c:\windows\system32\xvidvfw.dll
2014-05-10 13:44 . 2011-06-24 14:44 243200 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2014-05-10 13:44 . 2011-06-24 14:31 703488 ----a-w- c:\windows\system32\xvidcore.dll
2014-05-10 13:44 . 2011-06-24 14:28 650752 ----a-w- c:\windows\SysWow64\xvidcore.dll
2014-05-10 13:44 . 2012-07-21 10:55 180736 ----a-w- c:\windows\system32\ac3acm.acm
2014-05-10 13:44 . 2012-07-21 10:54 122880 ----a-w- c:\windows\SysWow64\ac3acm.acm
2014-05-10 13:44 . 2013-12-01 12:10 257624 ----a-w- c:\windows\system32\unrar64.dll
2014-05-10 13:44 . 2013-12-01 12:10 218200 ----a-w- c:\windows\SysWow64\unrar.dll
2014-05-10 13:44 . 2014-04-24 18:00 112640 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2014-05-10 13:44 . 2014-05-10 13:44 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack
2014-05-10 13:24 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2014-05-10 13:24 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2014-05-10 12:59 . 2014-05-10 12:59 -------- d-s---w- c:\windows\system32\CompatTel
2014-05-10 12:59 . 2014-05-10 12:59 -------- d-----w- c:\windows\SysWow64\Wat
2014-05-10 12:59 . 2014-05-10 12:59 -------- d-----w- c:\windows\system32\Wat
2014-05-10 12:35 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-05-10 12:35 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-05-10 12:35 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2014-05-10 12:35 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2014-05-10 12:35 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2014-05-10 12:18 . 2014-05-10 12:18 -------- d-----w- c:\program files (x86)\Microsoft.NET
2014-05-10 12:18 . 2014-05-10 12:18 -------- d-----w- c:\windows\Migration
2014-05-10 12:09 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2014-05-10 11:53 . 2014-05-10 11:53 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-10 11:14 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2014-05-10 11:05 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-05-10 10:33 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-05-10 10:33 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-05-10 10:33 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-05-10 10:33 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-05-10 10:33 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2014-05-10 10:33 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2014-05-10 10:33 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-05-10 10:26 . 2014-05-10 10:28 -------- d-----w- c:\windows\system32\MRT
2014-05-10 10:25 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-05-10 10:25 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-05-10 10:25 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-05-10 10:04 . 2013-07-04 12:50 633856 ----a-w- c:\windows\system32\comctl32.dll
2014-05-10 10:03 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2014-05-10 10:02 . 2013-10-05 20:25 1474048 ----a-w- c:\windows\system32\crypt32.dll
2014-05-10 10:01 . 2013-09-28 01:09 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-10 10:00 . 2013-09-25 02:22 340992 ----a-w- c:\windows\system32\schannel.dll
2014-05-10 09:59 . 2013-07-04 12:57 259584 ----a-w- c:\windows\system32\WebClnt.dll
2014-05-10 09:59 . 2013-07-04 12:50 102400 ----a-w- c:\windows\system32\davclnt.dll
2014-05-10 09:59 . 2013-07-04 11:57 205824 ----a-w- c:\windows\SysWow64\WebClnt.dll
2014-05-10 09:59 . 2013-07-04 11:51 81920 ----a-w- c:\windows\SysWow64\davclnt.dll
2014-05-10 09:59 . 2013-07-04 10:11 140800 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-05-10 09:59 . 2012-11-02 05:59 478208 ----a-w- c:\windows\system32\dpnet.dll
2014-05-10 09:59 . 2012-11-02 05:11 376832 ----a-w- c:\windows\SysWow64\dpnet.dll
2014-05-10 09:59 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2014-05-10 09:57 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2014-05-10 09:57 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2014-05-10 09:57 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2014-05-10 09:57 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2014-05-10 09:57 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-05-10 09:55 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys
2014-05-10 09:54 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll
2014-05-10 09:53 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2014-05-10 09:52 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2014-05-10 09:48 . 2014-05-10 09:48 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2014-05-10 09:47 . 2014-05-10 09:47 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2014-05-10 09:46 . 2009-03-17 09:07 14848 ----a-w- c:\windows\system32\Spool\prtprocs\x64\MIMFPR0H.DLL
2014-05-10 09:45 . 2014-05-10 09:45 -------- d-----w- c:\program files\KONICA MINOLTA
2014-05-10 09:29 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2014-05-10 09:29 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2014-05-10 09:21 . 2014-05-10 14:38 -------- d-----w- c:\program files\WinRAR
2014-05-10 09:19 . 2014-05-10 09:19 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-10 12:00 . 2014-05-10 12:00 208384 ----a-w- c:\windows\SysWow64\webcheck.dll
2014-05-10 12:00 . 2014-05-10 12:00 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-03-11 07:52 . 2014-03-11 07:52 133928 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-04 09:17 . 2014-05-10 09:54 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2014-05-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-10 09:19]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2014-05-10 6301696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.dell.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Jindra M 5010\AppData\Roaming\Mozilla\Firefox\Profiles\hn4xlcky.default\
FF - prefs.js: browser.search.selectedEngine - Seznam
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=undefined&q=
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
.
**************************************************************************
.
Celkový čas: 2014-05-11 20:21:12 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-05-11 18:21
ComboFix2.txt 2014-05-11 17:53
.
Před spuštěním: Volných bajtů: 547 267 555 328
Po spuštění: Volných bajtů: 546 967 437 312
.
- - End Of File - - 4C23206C1E586E7B4E2FF07D5152225F
A36C5E4F47E84449FF07ED3517B43A31

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 11 kvě 2014 19:48
od Márty84
Dejte novy log z RSIT

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 11 kvě 2014 19:52
od jindra.paryzek
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jindra M 5010 at 2014-05-11 20:51:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 522 GB (85%) free of 610 GB
Total RAM: 3068 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:51:41, on 11.5.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17041)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
C:\Program Files\trend micro\Jindra M 5010.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office10\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: DW WLAN Tray Service (wltrysvc) - Dell Inc. - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 5336 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE" "C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe"
C:\Windows\system32\WLANExt.exe 4659552
\??\C:\Windows\system32\conhost.exe "1201379838-1641614378-17199003-419007082-151074431933860709519374543651323974814
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"taskhost.exe"
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Windows\system32\Dwm.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\explorer.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1304.14116ae0.255229384 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 1304 "\\.\pipe\gecko-crash-server-pipe.1304" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe" --proxy-stub-channel=Flash2436.70E56010.17090 --host-broker-channel=Flash2436.70E56010.11700 --host-pid=2436 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe" --channel=2864.0029F8B8.285750264 --proxy-stub-channel=Flash2436.70E56010.17090 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll" --host-npapi-version=27 --type=renderer
"C:\Users\Jindra M 5010\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Jindra M 5010\AppData\Roaming\Mozilla\Firefox\Profiles\hn4xlcky.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=undefined&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.206 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.206 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll


C:\Users\Jindra M 5010\AppData\Roaming\Mozilla\Firefox\Profiles\hn4xlcky.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [2014-05-10 6301696]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 1271072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Download Assistant]
C:\Windows\System32\LogiLDA.dll [2012-09-20 1832760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mnclidrkSrv]
C:\Windows\system32\mnclidrk.vbe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp]
C:\Windows\inf\msstp.vbe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2013-10-02 1090912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~2\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-05-11 20:21:16 ----D---- C:\Windows\temp
2014-05-11 20:21:13 ----A---- C:\ComboFix.txt
2014-05-11 20:16:16 ----D---- C:\$RECYCLE.BIN
2014-05-11 19:41:49 ----A---- C:\Windows\PEV.exe
2014-05-11 19:41:49 ----A---- C:\Windows\NIRCMD.exe
2014-05-11 19:41:49 ----A---- C:\Windows\MBR.exe
2014-05-11 19:41:48 ----A---- C:\Windows\zip.exe
2014-05-11 19:41:48 ----A---- C:\Windows\SWSC.exe
2014-05-11 19:41:48 ----A---- C:\Windows\SWREG.exe
2014-05-11 19:41:48 ----A---- C:\Windows\sed.exe
2014-05-11 19:41:48 ----A---- C:\Windows\grep.exe
2014-05-11 19:41:21 ----D---- C:\Windows\erdnt
2014-05-11 13:39:46 ----D---- C:\Program Files (x86)\HD Tune
2014-05-11 10:00:45 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-05-11 10:00:09 ----D---- C:\ProgramData\Malwarebytes
2014-05-10 21:45:50 ----D---- C:\rsit
2014-05-10 21:45:50 ----D---- C:\Program Files\trend micro
2014-05-10 20:13:17 ----D---- C:\Windows\Panther
2014-05-10 20:12:39 ----RA---- C:\Windows\csup.txt
2014-05-10 20:12:39 ----D---- C:\Windows\system32\OEM
2014-05-10 20:11:29 ----A---- C:\Windows\system32\perfi005.dat
2014-05-10 20:11:29 ----A---- C:\Windows\system32\perfh005.dat
2014-05-10 20:11:29 ----A---- C:\Windows\system32\perfd005.dat
2014-05-10 20:11:29 ----A---- C:\Windows\system32\perfc005.dat
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\XPSViewer
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\drivers\cs-CZ
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\cs
2014-05-10 20:11:01 ----D---- C:\Windows\system32\cs
2014-05-10 20:11:01 ----D---- C:\Windows\cs-CZ
2014-05-10 20:11:00 ----D---- C:\Windows\system32\drivers\cs-CZ
2014-05-10 19:54:06 ----D---- C:\Windows.old.000
2014-05-10 17:54:44 ----D---- C:\Program Files (x86)\Dell
2014-05-10 17:44:04 ----D---- C:\Program Files (x86)\MSXML 4.0
2014-05-10 17:01:58 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\Nokia Suite
2014-05-10 16:57:45 ----D---- C:\ProgramData\Nokia
2014-05-10 16:57:13 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2014-05-10 16:55:10 ----D---- C:\ProgramData\NokiaInstallerCache
2014-05-10 16:52:59 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\PC Suite
2014-05-10 16:52:59 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\Nokia
2014-05-10 16:52:58 ----D---- C:\ProgramData\PC Suite
2014-05-10 16:52:22 ----D---- C:\Program Files\DIFX
2014-05-10 16:52:22 ----A---- C:\Windows\system32\drivers\pccsmcfdx64.sys
2014-05-10 16:52:18 ----DC---- C:\Windows\system32\DRVSTORE
2014-05-10 16:51:39 ----A---- C:\Windows\system32\nmwcdclsX64.dll
2014-05-10 16:51:38 ----D---- C:\Program Files (x86)\Nokia
2014-05-10 16:50:09 ----D---- C:\ProgramData\Installations
2014-05-10 16:36:43 ----D---- C:\Program Files (x86)\Adobe
2014-05-10 16:36:04 ----D---- C:\ProgramData\Adobe
2014-05-10 16:25:41 ----A---- C:\Windows\system32\mshtml.dll
2014-05-10 16:25:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-05-10 16:23:06 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-05-10 16:23:06 ----A---- C:\Windows\system32\mstscax.dll
2014-05-10 16:10:50 ----D---- C:\Program Files (x86)\WinRAR
2014-05-10 16:05:22 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-10 15:53:41 ----D---- C:\Windows\SYSWOW64\bitstreams
2014-05-10 15:53:41 ----AS---- C:\Windows\SYSWOW64\zlib1.dll
2014-05-10 15:53:41 ----AS---- C:\Windows\SYSWOW64\ssleay32.dll
2014-05-10 15:53:41 ----AS---- C:\Windows\SYSWOW64\pthreadVC2.dll
2014-05-10 15:53:41 ----AS---- C:\Windows\SYSWOW64\pthreadGC2.dll
2014-05-10 15:53:41 ----AS---- C:\Windows\SYSWOW64\libssh2.dll
2014-05-10 15:53:41 ----AS---- C:\Windows\SYSWOW64\librtmp.dll
2014-05-10 15:53:41 ----AS---- C:\Windows\SYSWOW64\libidn-11.dll
2014-05-10 15:53:40 ----AS---- C:\Windows\SYSWOW64\libeay32.dll
2014-05-10 15:53:40 ----AS---- C:\Windows\SYSWOW64\libcurl-4.dll
2014-05-10 15:53:39 ----AS---- C:\Windows\SYSWOW64\cudart32_50_35.dll
2014-05-10 15:53:37 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-05-10 15:53:33 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-10 15:53:33 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-10 15:53:33 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-05-10 15:53:32 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2014-05-10 15:53:32 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2014-05-10 15:53:32 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2014-05-10 15:53:32 ----A---- C:\Windows\system32\wksprtPS.dll
2014-05-10 15:53:32 ----A---- C:\Windows\system32\wksprt.exe
2014-05-10 15:53:32 ----A---- C:\Windows\system32\TSWbPrxy.exe
2014-05-10 15:53:32 ----A---- C:\Windows\system32\tsgqec.dll
2014-05-10 15:53:32 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2014-05-10 15:53:31 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-05-10 15:53:31 ----A---- C:\Windows\system32\mstsc.exe
2014-05-10 15:53:30 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2014-05-10 15:53:30 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-05-10 15:52:01 ----D---- C:\Program Files\Microsoft Silverlight
2014-05-10 15:52:00 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-05-10 15:51:16 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-05-10 15:51:14 ----A---- C:\Windows\system32\drivers\TsUsbGD.sys
2014-05-10 15:51:14 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2014-05-10 15:51:13 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2014-05-10 15:51:12 ----A---- C:\Windows\system32\rdpudd.dll
2014-05-10 15:51:12 ----A---- C:\Windows\system32\rdpendp_winip.dll
2014-05-10 15:51:11 ----A---- C:\Windows\system32\rdpcorets.dll
2014-05-10 15:46:56 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-05-10 15:46:56 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-05-10 15:46:49 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-05-10 15:46:49 ----A---- C:\Windows\system32\qdvd.dll
2014-05-10 15:46:24 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\WinRAR
2014-05-10 15:45:04 ----A---- C:\Windows\system32\ff_vfw.dll
2014-05-10 15:45:00 ----A---- C:\Windows\SYSWOW64\x264vfw.dll
2014-05-10 15:45:00 ----A---- C:\Windows\SYSWOW64\lagarith.dll
2014-05-10 15:45:00 ----A---- C:\Windows\system32\x264vfw64.dll
2014-05-10 15:45:00 ----A---- C:\Windows\system32\lagarith.dll
2014-05-10 15:44:59 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2014-05-10 15:44:59 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2014-05-10 15:44:59 ----A---- C:\Windows\system32\xvidvfw.dll
2014-05-10 15:44:59 ----A---- C:\Windows\system32\xvidcore.dll
2014-05-10 15:44:56 ----A---- C:\Windows\SYSWOW64\unrar.dll
2014-05-10 15:44:56 ----A---- C:\Windows\system32\unrar64.dll
2014-05-10 15:44:54 ----A---- C:\Windows\SYSWOW64\ff_vfw.dll
2014-05-10 15:44:49 ----D---- C:\Program Files (x86)\K-Lite Codec Pack
2014-05-10 15:26:49 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-05-10 15:26:49 ----A---- C:\Windows\explorer.exe
2014-05-10 15:26:40 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-05-10 15:26:40 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-05-10 15:26:40 ----A---- C:\Windows\system32\d3d10warp.dll
2014-05-10 15:26:40 ----A---- C:\Windows\system32\d2d1.dll
2014-05-10 15:26:28 ----A---- C:\Windows\SYSWOW64\esent.dll
2014-05-10 15:26:28 ----A---- C:\Windows\system32\fsutil.exe
2014-05-10 15:26:28 ----A---- C:\Windows\system32\esent.dll
2014-05-10 15:26:28 ----A---- C:\Windows\system32\drivers\amdxata.sys
2014-05-10 15:26:27 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2014-05-10 15:26:27 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2014-05-10 15:26:27 ----A---- C:\Windows\system32\drivers\nvstor.sys
2014-05-10 15:26:27 ----A---- C:\Windows\system32\drivers\nvraid.sys
2014-05-10 15:26:27 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2014-05-10 15:26:27 ----A---- C:\Windows\system32\drivers\amdsata.sys
2014-05-10 15:26:13 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2014-05-10 15:26:13 ----A---- C:\Windows\system32\WMPhoto.dll
2014-05-10 15:26:04 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-05-10 15:26:04 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-05-10 15:24:04 ----A---- C:\Windows\system32\spoolsv.exe
2014-05-10 15:24:04 ----A---- C:\Windows\splwow64.exe
2014-05-10 15:13:46 ----D---- C:\Windows\pss
2014-05-10 14:59:36 ----SD---- C:\Windows\system32\CompatTel
2014-05-10 14:59:27 ----D---- C:\Windows\SYSWOW64\Wat
2014-05-10 14:59:27 ----D---- C:\Windows\system32\Wat
2014-05-10 14:35:53 ----A---- C:\Windows\system32\wmploc.DLL
2014-05-10 14:35:52 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-05-10 14:35:52 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-05-10 14:35:50 ----A---- C:\Windows\system32\wmp.dll
2014-05-10 14:21:40 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-05-10 14:18:41 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-05-10 14:18:35 ----D---- C:\Windows\Migration
2014-05-10 14:09:56 ----A---- C:\Windows\system32\IEUDINIT.EXE
2014-05-10 14:00:48 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2014-05-10 14:00:45 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2014-05-10 14:00:45 ----A---- C:\Windows\SYSWOW64\msls31.dll
2014-05-10 14:00:45 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2014-05-10 14:00:45 ----A---- C:\Windows\system32\elshyph.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\wextract.exe
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\url.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\inseng.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\icardie.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-05-10 14:00:44 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\occache.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\jscript.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-05-10 14:00:43 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\wininet.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\urlmon.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2014-05-10 14:00:42 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2014-05-10 14:00:42 ----A---- C:\Windows\system32\msrating.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\msls31.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\mshtmler.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\msfeedssync.exe
2014-05-10 14:00:42 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\jsproxy.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\jsIntl.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\jscript9diag.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\jscript9.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\ieui.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\iesysprep.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\iertutil.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\ieframe.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\ieapfltr.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\ieapfltr.dat
2014-05-10 14:00:42 ----A---- C:\Windows\system32\IEAdvpack.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\dxtrans.dll
2014-05-10 14:00:42 ----A---- C:\Windows\system32\dxtmsft.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\wextract.exe
2014-05-10 14:00:41 ----A---- C:\Windows\system32\webcheck.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\vbscript.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\url.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\pngfilt.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\occache.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\mshtmled.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\mshta.exe
2014-05-10 14:00:41 ----A---- C:\Windows\system32\msfeeds.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\licmgr10.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\jscript.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\inseng.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\imgutil.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\iexpress.exe
2014-05-10 14:00:41 ----A---- C:\Windows\system32\ieUnatt.exe
2014-05-10 14:00:41 ----A---- C:\Windows\system32\iesetup.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\iernonce.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-05-10 14:00:41 ----A---- C:\Windows\system32\iedkcs32.dll
2014-05-10 14:00:41 ----A---- C:\Windows\system32\ie4uinit.exe
2014-05-10 14:00:41 ----A---- C:\Windows\system32\icardie.dll
2014-05-10 14:00:40 ----A---- C:\Windows\system32\iepeers.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-05-10 13:53:53 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-05-10 13:53:52 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-05-10 13:53:52 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2014-05-10 13:53:52 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\XpsPrint.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\FntCache.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\dxgi.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\DWrite.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\d3d10level9.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\d3d10core.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\d3d10_1core.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\d3d10_1.dll
2014-05-10 13:53:52 ----A---- C:\Windows\system32\d3d10.dll
2014-05-10 13:53:51 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2014-05-10 13:53:51 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2014-05-10 13:53:51 ----A---- C:\Windows\system32\UIAnimation.dll
2014-05-10 13:05:19 ----A---- C:\Windows\system32\browserchoice.exe
2014-05-10 12:33:52 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2014-05-10 12:33:51 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2014-05-10 12:33:50 ----A---- C:\Windows\system32\WUDFSvc.dll
2014-05-10 12:33:50 ----A---- C:\Windows\system32\WUDFPlatform.dll
2014-05-10 12:33:49 ----A---- C:\Windows\system32\WUDFx.dll
2014-05-10 12:33:49 ----A---- C:\Windows\system32\WUDFHost.exe
2014-05-10 12:33:49 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2014-05-10 12:26:56 ----D---- C:\Windows\system32\MRT
2014-05-10 12:26:54 ----A---- C:\Windows\system32\MRT.exe
2014-05-10 12:25:11 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2014-05-10 12:25:10 ----A---- C:\Windows\SYSWOW64\wmi.dll
2014-05-10 12:25:10 ----A---- C:\Windows\system32\wmi.dll
2014-05-10 12:05:14 ----A---- C:\Windows\system32\xmllite.dll
2014-05-10 12:05:13 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2014-05-10 12:05:07 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-05-10 12:05:07 ----A---- C:\Windows\system32\msieftp.dll
2014-05-10 12:05:06 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2014-05-10 12:05:06 ----A---- C:\Windows\system32\odbctrac.dll
2014-05-10 12:05:06 ----A---- C:\Windows\system32\odbccu32.dll
2014-05-10 12:05:06 ----A---- C:\Windows\system32\odbccr32.dll
2014-05-10 12:05:06 ----A---- C:\Windows\system32\odbccp32.dll
2014-05-10 12:05:05 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2014-05-10 12:05:05 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2014-05-10 12:05:05 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2014-05-10 12:05:05 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2014-05-10 12:05:04 ----A---- C:\Windows\system32\wwansvc.dll
2014-05-10 12:05:04 ----A---- C:\Windows\system32\wwanprotdim.dll
2014-05-10 12:04:59 ----A---- C:\Windows\system32\comctl32.dll
2014-05-10 12:04:58 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2014-05-10 12:04:43 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2014-05-10 12:04:43 ----A---- C:\Windows\system32\poqexec.exe
2014-05-10 12:04:40 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2014-05-10 12:04:40 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2014-05-10 12:04:40 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2014-05-10 12:04:40 ----A---- C:\Windows\system32\dhcpcore6.dll
2014-05-10 12:04:21 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-05-10 12:04:21 ----A---- C:\Windows\system32\wintrust.dll
2014-05-10 12:04:08 ----A---- C:\Windows\SYSWOW64\sbe.dll
2014-05-10 12:04:08 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2014-05-10 12:04:08 ----A---- C:\Windows\system32\sbe.dll
2014-05-10 12:04:08 ----A---- C:\Windows\system32\CPFilters.dll
2014-05-10 12:04:02 ----A---- C:\Windows\system32\quartz.dll
2014-05-10 12:04:01 ----A---- C:\Windows\SYSWOW64\quartz.dll
2014-05-10 12:03:57 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2014-05-10 12:03:57 ----A---- C:\Windows\system32\ntshrui.dll
2014-05-10 12:03:55 ----A---- C:\Windows\system32\tquery.dll
2014-05-10 12:03:55 ----A---- C:\Windows\system32\mssrch.dll
2014-05-10 12:03:54 ----A---- C:\Windows\SYSWOW64\tquery.dll
2014-05-10 12:03:54 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2014-05-10 12:03:54 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2014-05-10 12:03:54 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2014-05-10 12:03:54 ----A---- C:\Windows\SYSWOW64\mssph.dll
2014-05-10 12:03:54 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2014-05-10 12:03:54 ----A---- C:\Windows\system32\SearchIndexer.exe
2014-05-10 12:03:53 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2014-05-10 12:03:53 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2014-05-10 12:03:53 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2014-05-10 12:03:53 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2014-05-10 12:03:53 ----A---- C:\Windows\system32\SearchFilterHost.exe
2014-05-10 12:03:53 ----A---- C:\Windows\system32\mssvp.dll
2014-05-10 12:03:53 ----A---- C:\Windows\system32\mssphtb.dll
2014-05-10 12:03:53 ----A---- C:\Windows\system32\mssph.dll
2014-05-10 12:03:53 ----A---- C:\Windows\system32\msscntrs.dll
2014-05-10 12:03:44 ----A---- C:\Windows\system32\consent.exe
2014-05-10 12:03:44 ----A---- C:\Windows\system32\appinfo.dll
2014-05-10 12:03:30 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-05-10 12:03:30 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2014-05-10 12:03:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2014-05-10 12:03:28 ----A---- C:\Windows\SYSWOW64\webio.dll
2014-05-10 12:03:28 ----A---- C:\Windows\system32\webio.dll
2014-05-10 12:02:42 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-05-10 12:02:42 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-05-10 12:02:42 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-05-10 12:02:42 ----A---- C:\Windows\system32\cryptsvc.dll
2014-05-10 12:02:42 ----A---- C:\Windows\system32\cryptnet.dll
2014-05-10 12:02:42 ----A---- C:\Windows\system32\crypt32.dll
2014-05-10 12:02:26 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-05-10 12:02:26 ----A---- C:\Windows\system32\wer.dll
2014-05-10 12:02:25 ----A---- C:\Windows\system32\imagehlp.dll
2014-05-10 12:02:24 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-05-10 12:02:22 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-05-10 12:02:22 ----A---- C:\Windows\system32\tzres.dll
2014-05-10 12:02:13 ----A---- C:\Windows\system32\drivers\usbser.sys
2014-05-10 12:02:12 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-05-10 12:02:12 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-05-10 12:02:12 ----A---- C:\Windows\system32\msxml3r.dll
2014-05-10 12:02:12 ----A---- C:\Windows\system32\msxml3.dll
2014-05-10 12:01:46 ----A---- C:\Windows\system32\drivers\afd.sys
2014-05-10 12:01:43 ----A---- C:\Windows\system32\aepdu.dll
2014-05-10 12:01:42 ----A---- C:\Windows\system32\aeinv.dll
2014-05-10 12:01:41 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-05-10 12:01:41 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-05-10 12:01:30 ----A---- C:\Windows\system32\win32k.sys
2014-05-10 12:01:29 ----A---- C:\Windows\system32\drivers\ataport.sys
2014-05-10 12:01:25 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2014-05-10 12:01:25 ----A---- C:\Windows\SYSWOW64\credui.dll
2014-05-10 12:01:25 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-05-10 12:01:25 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2014-05-10 12:01:25 ----A---- C:\Windows\system32\credui.dll
2014-05-10 12:01:25 ----A---- C:\Windows\system32\authui.dll
2014-05-10 12:01:16 ----A---- C:\Windows\SYSWOW64\lpk.dll
2014-05-10 12:01:16 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2014-05-10 12:01:16 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2014-05-10 12:01:16 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2014-05-10 12:01:16 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2014-05-10 12:01:16 ----A---- C:\Windows\system32\lpk.dll
2014-05-10 12:01:16 ----A---- C:\Windows\system32\fontsub.dll
2014-05-10 12:01:16 ----A---- C:\Windows\system32\dciman32.dll
2014-05-10 12:01:16 ----A---- C:\Windows\system32\atmlib.dll
2014-05-10 12:01:16 ----A---- C:\Windows\system32\atmfd.dll
2014-05-10 12:01:15 ----A---- C:\Windows\system32\mfc42u.dll
2014-05-10 12:01:14 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2014-05-10 12:01:14 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2014-05-10 12:01:14 ----A---- C:\Windows\system32\mfc42.dll
2014-05-10 12:01:08 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-05-10 12:01:08 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-05-10 12:01:08 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-05-10 12:01:08 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-05-10 12:01:08 ----A---- C:\Windows\system32\RMActivate.exe
2014-05-10 12:01:07 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-05-10 12:01:07 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-05-10 12:01:07 ----A---- C:\Windows\system32\secproc_isv.dll
2014-05-10 12:01:07 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-05-10 12:01:07 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-05-10 12:01:06 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-05-10 12:01:06 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-05-10 12:01:06 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-05-10 12:01:06 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-05-10 12:01:06 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-05-10 12:01:06 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-05-10 12:01:06 ----A---- C:\Windows\system32\secproc.dll
2014-05-10 12:01:06 ----A---- C:\Windows\system32\msdrm.dll
2014-05-10 12:00:55 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-05-10 12:00:55 ----A---- C:\Windows\system32\schannel.dll
2014-05-10 12:00:55 ----A---- C:\Windows\system32\drivers\cng.sys
2014-05-10 12:00:54 ----A---- C:\Windows\system32\ncrypt.dll
2014-05-10 12:00:54 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-05-10 12:00:53 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-05-10 12:00:53 ----A---- C:\Windows\system32\lsasrv.dll
2014-05-10 12:00:53 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-05-10 12:00:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-05-10 12:00:52 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-05-10 12:00:52 ----A---- C:\Windows\system32\sspisrv.dll
2014-05-10 12:00:52 ----A---- C:\Windows\system32\sspicli.dll
2014-05-10 12:00:52 ----A---- C:\Windows\system32\secur32.dll
2014-05-10 12:00:52 ----A---- C:\Windows\system32\lsass.exe
2014-05-10 12:00:46 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-05-10 12:00:46 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-05-10 12:00:46 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2014-05-10 12:00:45 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-05-10 12:00:45 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-05-10 12:00:45 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-05-10 12:00:43 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2014-05-10 12:00:43 ----A---- C:\Windows\system32\d3d11.dll
2014-05-10 12:00:42 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-05-10 12:00:41 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2014-05-10 12:00:33 ----A---- C:\Windows\system32\smss.exe
2014-05-10 12:00:33 ----A---- C:\Windows\system32\csrsrv.dll
2014-05-10 12:00:31 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2014-05-10 12:00:31 ----A---- C:\Windows\system32\apisetschema.dll
2014-05-10 12:00:29 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-05-10 12:00:28 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-05-10 12:00:28 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-05-10 12:00:26 ----A---- C:\Windows\system32\rdrmemptylst.exe
2014-05-10 12:00:26 ----A---- C:\Windows\system32\rdpwsx.dll
2014-05-10 12:00:26 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-05-10 12:00:20 ----A---- C:\Windows\system32\Wdfres.dll
2014-05-10 12:00:20 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2014-05-10 12:00:20 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2014-05-10 12:00:18 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-05-10 12:00:18 ----A---- C:\Windows\system32\rpcrt4.dll
2014-05-10 12:00:17 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2014-05-10 12:00:17 ----A---- C:\Windows\system32\drivers\usbcir.sys
2014-05-10 12:00:16 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-05-10 12:00:16 ----A---- C:\Windows\system32\drivers\hidclass.sys
2014-05-10 12:00:14 ----A---- C:\Windows\system32\ncsi.dll
2014-05-10 12:00:13 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2014-05-10 12:00:13 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2014-05-10 12:00:13 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2014-05-10 12:00:13 ----A---- C:\Windows\system32\nlasvc.dll
2014-05-10 12:00:13 ----A---- C:\Windows\system32\nlaapi.dll
2014-05-10 12:00:13 ----A---- C:\Windows\system32\netcorehc.dll
2014-05-10 12:00:13 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-05-10 12:00:13 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2014-05-10 12:00:12 ----A---- C:\Windows\SYSWOW64\netevent.dll
2014-05-10 12:00:12 ----A---- C:\Windows\system32\netevent.dll
2014-05-10 12:00:06 ----A---- C:\Windows\system32\msxml6.dll
2014-05-10 12:00:05 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-05-10 12:00:03 ----A---- C:\Windows\system32\profsvc.dll
2014-05-10 12:00:01 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2014-05-10 12:00:01 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2014-05-10 12:00:01 ----A---- C:\Windows\system32\dnsrslvr.dll
2014-05-10 12:00:01 ----A---- C:\Windows\system32\dnscacheugc.exe
2014-05-10 12:00:01 ----A---- C:\Windows\system32\dnsapi.dll
2014-05-10 11:59:18 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-05-10 11:59:18 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2014-05-10 11:59:18 ----A---- C:\Windows\system32\WebClnt.dll
2014-05-10 11:59:18 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2014-05-10 11:59:18 ----A---- C:\Windows\system32\davclnt.dll
2014-05-10 11:59:14 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2014-05-10 11:59:14 ----A---- C:\Windows\system32\dpnet.dll
2014-05-10 11:59:08 ----A---- C:\Windows\system32\OxpsConverter.exe
2014-05-10 11:58:35 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-05-10 11:58:35 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-05-10 11:58:35 ----A---- C:\Windows\system32\drivers\srv.sys
2014-05-10 11:58:33 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-05-10 11:58:33 ----A---- C:\Windows\system32\usp10.dll
2014-05-10 11:58:29 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-05-10 11:58:27 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2014-05-10 11:58:27 ----A---- C:\Windows\system32\mswsock.dll
2014-05-10 11:58:21 ----A---- C:\Windows\system32\Wpc.dll
2014-05-10 11:58:20 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-05-10 11:58:20 ----A---- C:\Windows\SYSWOW64\gameux.dll
2014-05-10 11:58:20 ----A---- C:\Windows\system32\gameux.dll
2014-05-10 11:57:58 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2014-05-10 11:57:58 ----A---- C:\Windows\system32\psisdecd.dll
2014-05-10 11:57:56 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-05-10 11:56:59 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-05-10 11:56:58 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-05-10 11:56:57 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-05-10 11:56:56 ----A---- C:\Windows\system32\tdh.dll
2014-05-10 11:56:56 ----A---- C:\Windows\system32\ntdll.dll
2014-05-10 11:56:56 ----A---- C:\Windows\system32\advapi32.dll
2014-05-10 11:56:55 ----A---- C:\Windows\SYSWOW64\tdh.dll
2014-05-10 11:56:55 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-05-10 11:56:55 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2014-05-10 11:56:50 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-05-10 11:56:50 ----A---- C:\Windows\system32\drivers\netio.sys
2014-05-10 11:56:49 ----A---- C:\Windows\system32\drivers\partmgr.sys
2014-05-10 11:56:47 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-05-10 11:56:47 ----A---- C:\Windows\system32\kerberos.dll
2014-05-10 11:56:44 ----A---- C:\Windows\system32\msi.dll
2014-05-10 11:56:43 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-05-10 11:55:34 ----A---- C:\Windows\system32\drivers\storport.sys
2014-05-10 11:55:34 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-05-10 11:55:34 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-05-10 11:55:33 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2014-05-10 11:55:33 ----A---- C:\Windows\system32\iologmsg.dll
2014-05-10 11:55:24 ----A---- C:\Windows\SYSWOW64\synceng.dll
2014-05-10 11:55:24 ----A---- C:\Windows\system32\synceng.dll
2014-05-10 11:55:22 ----A---- C:\Windows\system32\winresume.exe
2014-05-10 11:55:22 ----A---- C:\Windows\system32\winload.exe
2014-05-10 11:55:22 ----A---- C:\Windows\system32\kdusb.dll
2014-05-10 11:55:22 ----A---- C:\Windows\system32\kdcom.dll
2014-05-10 11:55:22 ----A---- C:\Windows\system32\kd1394.dll
2014-05-10 11:55:17 ----A---- C:\Windows\system32\shell32.dll
2014-05-10 11:55:16 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-05-10 11:55:16 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-05-10 11:55:16 ----A---- C:\Windows\system32\shdocvw.dll
2014-05-10 11:54:56 ----A---- C:\Windows\system32\win32spl.dll
2014-05-10 11:54:55 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-05-10 11:54:53 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-05-10 11:54:53 ----A---- C:\Windows\system32\gdi32.dll
2014-05-10 11:54:52 ----A---- C:\Windows\system32\taskhost.exe
2014-05-10 11:54:51 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-05-10 11:54:51 ----A---- C:\Windows\system32\qedit.dll
2014-05-10 11:54:50 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2014-05-10 11:54:50 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2014-05-10 11:54:50 ----A---- C:\Windows\SYSWOW64\devobj.dll
2014-05-10 11:54:50 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2014-05-10 11:54:50 ----A---- C:\Windows\system32\umpnpmgr.dll
2014-05-10 11:54:46 ----A---- C:\Windows\system32\cryptdlg.dll
2014-05-10 11:54:45 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2014-05-10 11:54:26 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-05-10 11:54:26 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-05-10 11:54:25 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-05-10 11:54:23 ----A---- C:\Windows\system32\netapi32.dll
2014-05-10 11:54:23 ----A---- C:\Windows\system32\browser.dll
2014-05-10 11:54:23 ----A---- C:\Windows\system32\browcli.dll
2014-05-10 11:54:22 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2014-05-10 11:54:22 ----A---- C:\Windows\SYSWOW64\browcli.dll
2014-05-10 11:54:19 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-05-10 11:54:19 ----A---- C:\Windows\system32\wow64win.dll
2014-05-10 11:54:19 ----A---- C:\Windows\system32\wow64.dll
2014-05-10 11:54:19 ----A---- C:\Windows\system32\winsrv.dll
2014-05-10 11:54:19 ----A---- C:\Windows\system32\KernelBase.dll
2014-05-10 11:54:19 ----A---- C:\Windows\system32\kernel32.dll
2014-05-10 11:54:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-05-10 11:54:18 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-05-10 11:54:18 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-05-10 11:54:18 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-05-10 11:54:18 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-05-10 11:54:18 ----A---- C:\Windows\system32\wow64cpu.dll
2014-05-10 11:54:18 ----A---- C:\Windows\system32\ntvdm64.dll
2014-05-10 11:54:18 ----A---- C:\Windows\system32\conhost.exe
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-05-10 11:54:17 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-05-10 11:54:17 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-05-10 11:54:17 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-05-10 11:54:16 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-05-10 11:54:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-05-10 11:54:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-05-10 11:54:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-05-10 11:54:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2014-05-10 11:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-05-10 11:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-05-10 11:54:15 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-05-10 11:54:15 ----A---- C:\Windows\SYSWOW64\user.exe
2014-05-10 11:54:13 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2014-05-10 11:54:13 ----A---- C:\Windows\system32\prevhost.exe
2014-05-10 11:54:12 ----A---- C:\Windows\system32\drivers\fvevol.sys
2014-05-10 11:54:11 ----A---- C:\Windows\SYSWOW64\srclient.dll
2014-05-10 11:54:11 ----A---- C:\Windows\system32\srcore.dll
2014-05-10 11:54:09 ----A---- C:\Windows\system32\FXSCOVER.exe
2014-05-10 11:54:08 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2014-05-10 11:54:08 ----A---- C:\Windows\system32\inetcomm.dll
2014-05-10 11:54:06 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2014-05-10 11:54:06 ----A---- C:\Windows\system32\msvcrt.dll
2014-05-10 11:54:04 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-05-10 11:54:00 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-05-10 11:54:00 ----A---- C:\Windows\system32\certutil.exe
2014-05-10 11:53:59 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-05-10 11:53:59 ----A---- C:\Windows\system32\certenc.dll
2014-05-10 11:53:42 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-05-10 11:53:42 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-05-10 11:53:42 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-05-10 11:53:42 ----A---- C:\Windows\system32\wscript.exe
2014-05-10 11:53:42 ----A---- C:\Windows\system32\scrrun.dll
2014-05-10 11:53:42 ----A---- C:\Windows\system32\cscript.exe
2014-05-10 11:53:38 ----A---- C:\Windows\system32\localspl.dll
2014-05-10 11:53:36 ----A---- C:\Windows\system32\drivers\bowser.sys
2014-05-10 11:53:34 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-05-10 11:53:34 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2014-05-10 11:53:34 ----A---- C:\Windows\system32\oleaut32.dll
2014-05-10 11:53:34 ----A---- C:\Windows\system32\oleacc.dll
2014-05-10 11:53:32 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2014-05-10 11:53:32 ----A---- C:\Windows\system32\EncDec.dll
2014-05-10 11:53:31 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-05-10 11:53:30 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-05-10 11:53:30 ----A---- C:\Windows\system32\cdd.dll
2014-05-10 11:53:10 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2014-05-10 11:53:09 ----A---- C:\Windows\system32\cdosys.dll
2014-05-10 11:53:01 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-05-10 11:53:01 ----A---- C:\Windows\system32\nshwfp.dll
2014-05-10 11:53:01 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-05-10 11:53:01 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-05-10 11:53:00 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-05-10 11:52:54 ----A---- C:\Windows\system32\scavengeui.dll
2014-05-10 11:48:21 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-05-10 11:45:07 ----D---- C:\Program Files\KONICA MINOLTA
2014-05-10 11:41:39 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-05-10 11:29:55 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-05-10 11:29:55 ----A---- C:\Windows\system32\packager.dll
2014-05-10 11:21:25 ----D---- C:\Program Files\WinRAR
2014-05-10 11:19:30 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\Macromedia
2014-05-10 11:19:30 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\Adobe
2014-05-10 11:19:15 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-05-10 11:19:09 ----D---- C:\Windows\SYSWOW64\Macromed
2014-05-10 11:19:06 ----D---- C:\Windows\system32\Macromed
2014-05-10 11:15:30 ----A---- C:\Windows\ODBC.INI
2014-05-10 11:13:03 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\Mozilla
2014-05-10 11:12:53 ----D---- C:\ProgramData\Mozilla
2014-05-10 11:12:52 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 11:10:08 ----D---- C:\Windows\Msagent
2014-05-10 11:10:03 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2014-05-10 11:10:03 ----A---- C:\Windows\system32\rdpcore.dll
2014-05-10 11:10:03 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2014-05-10 11:09:59 ----D---- C:\Program Files (x86)\Microsoft Office
2014-05-10 11:05:38 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-05-10 11:05:21 ----D---- C:\Program Files\Microsoft Security Client
2014-05-10 11:03:26 ----A---- C:\Windows\system32\wups2.dll
2014-05-10 11:03:26 ----A---- C:\Windows\system32\wucltux.dll
2014-05-10 11:03:26 ----A---- C:\Windows\system32\wuaueng.dll
2014-05-10 11:03:26 ----A---- C:\Windows\system32\wuauclt.exe
2014-05-10 11:03:15 ----A---- C:\Windows\system32\wups.dll
2014-05-10 11:03:15 ----A---- C:\Windows\system32\wudriver.dll
2014-05-10 11:03:15 ----A---- C:\Windows\system32\wuapi.dll
2014-05-10 11:03:01 ----A---- C:\Windows\system32\wuwebv.dll
2014-05-10 11:03:01 ----A---- C:\Windows\system32\wuapp.exe
2014-05-10 10:58:04 ----D---- C:\Program Files (x86)\Cisco
2014-05-10 10:56:53 ----SHD---- C:\Windows\Installer
2014-05-10 10:56:09 ----A---- C:\Windows\system32\BCMLogon.dll
2014-05-10 10:55:56 ----A---- C:\Windows\SYSWOW64\vcredist_x64.bat
2014-05-10 10:55:56 ----A---- C:\Windows\system32\drivers\npf.sys
2014-05-10 10:55:56 ----A---- C:\Windows\system32\drivers\bcm42rly.sys
2014-05-10 10:55:56 ----A---- C:\Windows\system32\bcmwlrc.dll
2014-05-10 10:55:55 ----A---- C:\Windows\SYSWOW64\vcredist_x64.exe
2014-05-10 10:55:55 ----A---- C:\Windows\system32\wltrynt.dll
2014-05-10 10:55:55 ----A---- C:\Windows\system32\bcmttls.dll
2014-05-10 10:55:54 ----A---- C:\Windows\system32\vcredist_x64.exe
2014-05-10 10:55:54 ----A---- C:\Windows\system32\vcredist_x64.bat
2014-05-10 10:55:52 ----A---- C:\Windows\system32\drivers\BCMWL664.SYS
2014-05-10 10:55:52 ----A---- C:\Windows\system32\bcmwlcoi.dll
2014-05-10 10:55:52 ----A---- C:\Windows\system32\bcmihvui64.dll
2014-05-10 10:55:52 ----A---- C:\Windows\system32\bcmihvsrv64.dll
2014-05-10 10:55:51 ----D---- C:\Program Files\Dell
2014-05-10 10:35:34 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\Identities
2014-05-10 10:35:17 ----SD---- C:\Users\Jindra M 5010\AppData\Roaming\Microsoft
2014-05-10 10:35:17 ----D---- C:\Users\Jindra M 5010\AppData\Roaming\Media Center Programs
2014-05-10 10:35:04 ----SHD---- C:\ProgramData\Šablony
2014-05-10 10:35:04 ----SHD---- C:\ProgramData\Plocha
2014-05-10 10:35:04 ----SHD---- C:\ProgramData\Oblíbené položky
2014-05-10 10:35:04 ----SHD---- C:\ProgramData\Nabídka Start
2014-05-10 10:35:04 ----SHD---- C:\ProgramData\Dokumenty
2014-05-10 10:35:04 ----SHD---- C:\ProgramData\Data aplikací
2014-05-10 10:17:12 ----D---- C:\Windows\SoftwareDistribution
2014-05-10 10:14:57 ----D---- C:\Windows\Prefetch

======List of files/folders modified in the last 1 month======

2014-05-11 20:30:25 ----D---- C:\Windows\system32\config
2014-05-11 20:21:19 ----D---- C:\Windows\System32
2014-05-11 20:21:19 ----D---- C:\Windows\inf
2014-05-11 20:21:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-05-11 20:21:18 ----D---- C:\Qoobox
2014-05-11 20:21:17 ----D---- C:\Windows\system32\drivers
2014-05-11 20:21:16 ----D---- C:\Windows
2014-05-11 20:16:18 ----A---- C:\Windows\system.ini
2014-05-11 20:16:13 ----D---- C:\Windows\system32\drivers\etc
2014-05-11 20:11:40 ----D---- C:\Windows\SYSWOW64\drivers
2014-05-11 20:11:40 ----D---- C:\Windows\SysWOW64
2014-05-11 20:11:40 ----D---- C:\Windows\AppPatch
2014-05-11 20:11:38 ----D---- C:\Program Files (x86)\Common Files
2014-05-11 19:08:41 ----D---- C:\Windows\system32\wdi
2014-05-11 19:08:30 ----D---- C:\AdwCleaner
2014-05-11 15:31:32 ----D---- C:\Windows\Microsoft.NET
2014-05-11 14:28:42 ----RSD---- C:\Windows\assembly
2014-05-11 13:40:52 ----RD---- C:\Program Files (x86)
2014-05-11 10:00:09 ----D---- C:\ProgramData
2014-05-10 21:45:50 ----RD---- C:\Program Files
2014-05-10 20:13:04 ----RASH---- C:\BOOTSECT.BAK
2014-05-10 20:13:02 ----D---- C:\Boot
2014-05-10 20:12:39 ----D---- C:\Windows\system32\oobe
2014-05-10 20:12:39 ----D---- C:\Windows\Setup
2014-05-10 20:12:38 ----D---- C:\Drivers
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\winrm
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\WCN
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\slmgr
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\Printing_Admin_Scripts
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\MUI
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\migwiz
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\DriverStore
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\Dism
2014-05-10 20:11:01 ----D---- C:\Windows\SYSWOW64\com
2014-05-10 20:11:01 ----D---- C:\Windows\system32\winrm
2014-05-10 20:11:01 ----D---- C:\Windows\system32\slmgr
2014-05-10 20:11:01 ----D---- C:\Windows\system32\migwiz
2014-05-10 20:11:01 ----D---- C:\Windows\servicing
2014-05-10 20:11:01 ----D---- C:\Windows\IME
2014-05-10 20:11:01 ----D---- C:\Program Files\Windows Sidebar
2014-05-10 20:11:01 ----D---- C:\Program Files\Windows Photo Viewer
2014-05-10 20:11:01 ----D---- C:\Program Files\Windows Mail
2014-05-10 20:11:01 ----D---- C:\Program Files\DVD Maker
2014-05-10 20:11:01 ----D---- C:\Program Files (x86)\Windows Sidebar
2014-05-10 20:11:01 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2014-05-10 20:11:01 ----D---- C:\Program Files (x86)\Windows Mail
2014-05-10 20:11:00 ----D---- C:\Windows\system32\WCN
2014-05-10 20:11:00 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2014-05-10 20:11:00 ----D---- C:\Windows\system32\MUI
2014-05-10 20:11:00 ----D---- C:\Windows\system32\Dism
2014-05-10 20:11:00 ----D---- C:\Windows\system32\com
2014-05-10 17:55:50 ----D---- C:\Windows\system32\catroot
2014-05-10 17:55:18 ----D---- C:\Config.Msi
2014-05-10 17:54:31 ----SHD---- C:\System Volume Information
2014-05-10 17:44:41 ----D---- C:\Windows\winsxs
2014-05-10 16:57:18 ----D---- C:\Windows\system32\DriverStore
2014-05-10 16:56:38 ----D---- C:\Windows\system32\catroot2
2014-05-10 16:53:35 ----SD---- C:\ProgramData\Microsoft
2014-05-10 16:53:29 ----D---- C:\Windows\system32\drivers\UMDF
2014-05-10 16:25:33 ----D---- C:\Windows\SYSWOW64\en-US
2014-05-10 16:25:33 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-05-10 16:25:33 ----D---- C:\Windows\system32\cs-CZ
2014-05-10 16:25:32 ----D---- C:\Windows\system32\en-US
2014-05-10 15:55:12 ----D---- C:\Windows\SYSWOW64\wbem
2014-05-10 15:55:11 ----D---- C:\Windows\system32\drivers\en-US
2014-05-10 15:55:10 ----D---- C:\Windows\system32\wbem
2014-05-10 15:55:10 ----D---- C:\Windows\PolicyDefinitions
2014-05-10 15:28:26 ----A---- C:\Windows\win.ini
2014-05-10 15:00:00 ----D---- C:\Program Files\Windows Media Player
2014-05-10 15:00:00 ----D---- C:\Program Files (x86)\Windows Media Player
2014-05-10 14:59:56 ----D---- C:\Program Files\Common Files\System
2014-05-10 14:59:54 ----D---- C:\Program Files\Internet Explorer
2014-05-10 14:59:54 ----D---- C:\Program Files (x86)\Internet Explorer
2014-05-10 14:59:53 ----D---- C:\Windows\SYSWOW64\migration
2014-05-10 14:59:48 ----D---- C:\Windows\system32\migration
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\zh-TW
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\zh-HK
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\zh-CN
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\tr-TR
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\sv-SE
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\pt-PT
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\pt-BR
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\pl-PL
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\nl-NL
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\ko-KR
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\it-IT
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\hu-HU
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\fr-FR
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\fi-FI
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\es-ES
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\el-GR
2014-05-10 14:59:45 ----D---- C:\Windows\SYSWOW64\de-DE
2014-05-10 14:59:44 ----D---- C:\Windows\SYSWOW64\ru-RU
2014-05-10 14:59:44 ----D---- C:\Windows\SYSWOW64\nb-NO
2014-05-10 14:59:44 ----D---- C:\Windows\SYSWOW64\ja-JP
2014-05-10 14:59:44 ----D---- C:\Windows\SYSWOW64\da-DK
2014-05-10 14:59:43 ----D---- C:\Windows\system32\zh-TW
2014-05-10 14:59:43 ----D---- C:\Windows\system32\zh-HK
2014-05-10 14:59:43 ----D---- C:\Windows\system32\zh-CN
2014-05-10 14:59:43 ----D---- C:\Windows\system32\tr-TR
2014-05-10 14:59:43 ----D---- C:\Windows\system32\sv-SE
2014-05-10 14:59:43 ----D---- C:\Windows\system32\pt-PT
2014-05-10 14:59:43 ----D---- C:\Windows\system32\pt-BR
2014-05-10 14:59:43 ----D---- C:\Windows\system32\pl-PL
2014-05-10 14:59:43 ----D---- C:\Windows\system32\nl-NL
2014-05-10 14:59:43 ----D---- C:\Windows\system32\ko-KR
2014-05-10 14:59:43 ----D---- C:\Windows\system32\ja-JP
2014-05-10 14:59:43 ----D---- C:\Windows\system32\it-IT
2014-05-10 14:59:43 ----D---- C:\Windows\system32\hu-HU
2014-05-10 14:59:43 ----D---- C:\Windows\system32\fr-FR
2014-05-10 14:59:43 ----D---- C:\Windows\system32\fi-FI
2014-05-10 14:59:43 ----D---- C:\Windows\system32\es-ES
2014-05-10 14:59:43 ----D---- C:\Windows\system32\el-GR
2014-05-10 14:59:43 ----D---- C:\Windows\system32\de-DE
2014-05-10 14:59:42 ----D---- C:\Windows\system32\ru-RU
2014-05-10 14:59:42 ----D---- C:\Windows\system32\nb-NO
2014-05-10 14:59:42 ----D---- C:\Windows\system32\da-DK
2014-05-10 14:59:40 ----D---- C:\Windows\ehome
2014-05-10 14:59:35 ----RSD---- C:\Windows\Fonts
2014-05-10 14:59:35 ----D---- C:\Program Files\Windows Defender
2014-05-10 14:59:35 ----D---- C:\Program Files (x86)\Windows Defender
2014-05-10 14:59:14 ----D---- C:\Windows\system32\Boot
2014-05-10 14:59:10 ----D---- C:\Program Files\Windows Journal
2014-05-10 14:21:16 ----D---- C:\Windows\Logs
2014-05-10 14:21:15 ----D---- C:\Windows\debug
2014-05-10 11:19:17 ----D---- C:\Windows\system32\Tasks
2014-05-10 11:19:16 ----D---- C:\Windows\Tasks
2014-05-10 11:14:42 ----D---- C:\Windows\ShellNew
2014-05-10 11:10:08 ----D---- C:\Windows\Help
2014-05-10 11:08:43 ----D---- C:\Windows\system
2014-05-10 11:02:35 ----D---- C:\Windows\system32\restore
2014-05-10 11:00:51 ----D---- C:\Windows\system32\NDF
2014-05-10 10:57:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-05-10 10:56:01 ----D---- C:\Windows\system32\th-TH
2014-05-10 10:56:01 ----D---- C:\Windows\system32\sl-SI
2014-05-10 10:56:01 ----D---- C:\Windows\system32\sk-SK
2014-05-10 10:56:01 ----D---- C:\Windows\system32\ro-RO
2014-05-10 10:55:59 ----D---- C:\Windows\system32\lv-LV
2014-05-10 10:55:59 ----D---- C:\Windows\system32\lt-LT
2014-05-10 10:55:58 ----D---- C:\Windows\system32\hr-HR
2014-05-10 10:55:58 ----D---- C:\Windows\system32\he-IL
2014-05-10 10:55:58 ----D---- C:\Windows\system32\et-EE
2014-05-10 10:55:56 ----D---- C:\Windows\system32\bg-BG
2014-05-10 10:55:56 ----D---- C:\Windows\system32\ar-SA
2014-05-10 10:38:16 ----RD---- C:\Users
2014-05-10 10:35:04 ----D---- C:\Windows\system32\Recovery
2014-05-10 10:35:04 ----D---- C:\Recovery
2014-05-10 10:35:04 ----D---- C:\Program Files\Windows NT
2014-05-10 10:35:03 ----D---- C:\Windows\rescache
2014-05-10 10:23:40 ----D---- C:\Windows\system32\CodeIntegrity
2014-05-10 10:19:31 ----D---- C:\Windows\system32\sysprep

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 268512]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 6037504]
R3 BCM43XX;Ovladač pro bezdrátovou síťovou kartu DW WLAN; C:\Windows\system32\DRIVERS\bcmwl664.sys [2014-05-10 4716608]
S3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2014-05-10 22592]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-05-11 119512]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 133928]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\drivers\nusb3hub.sys [2010-09-30 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\drivers\nusb3xhc.sys [2010-09-30 180736]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 203264]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 wltrysvc;DW WLAN Tray Service; C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE [2014-05-10 48128]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-10 257712]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-05-10 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-05-10 119408]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-10 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 12 kvě 2014 04:08
od Márty84
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 12 kvě 2014 09:01
od jindra.paryzek
Program hlásí chybu...screen
Bez názvu.png
Bez názvu.png (87.4 KiB) Zobrazeno 1635 x

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 12 kvě 2014 09:34
od Márty84
Zkuste to jeste v nouzovem rezimu.

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 12 kvě 2014 10:04
od jindra.paryzek
Výsledek je stejný...viz screene v předcházející zprávě :?:

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 12 kvě 2014 11:16
od Márty84
:!: Vypnete antivir, at nebrani programu v praci.
:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe a ulozte nejlepe na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Do leveho okna zkopirujte tento skript (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]
[CreateRestorePoint]

:services
AdobeARMservice
AdobeFlashPlayerUpdateSvc

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\system32\mnclidrk.vbe
C:\Windows\inf\msstp.vbe

:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mnclidrkSrv] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe] /64
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery na vas vyskoci, nebo bude zde C:\_OTM\MovedFiles\xxxxxxxx_xxxxxx (misto tech x budou cisla, predstavujici datum a cas spusteni)

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 12 kvě 2014 11:23
od jindra.paryzek
All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Jindra M 5010
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 293 bytes
->FireFox cache emptied: 373016919 bytes
->Flash cache emptied: 1967 bytes

User: Jindra M5010
->Temp folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 5007112 bytes
->Flash cache emptied: 506 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 14180 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33298 bytes
RecycleBin emptied: 19959355 bytes

Total Files Cleaned = 380,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Jindra M 5010
->Flash cache emptied: 0 bytes

User: Jindra M5010
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb

Restore point Set: OTM Restore Point
========== SERVICES/DRIVERS ==========
Service AdobeARMservice stopped successfully!
Service AdobeARMservice deleted successfully!
Service AdobeFlashPlayerUpdateSvc stopped successfully!
Service AdobeFlashPlayerUpdateSvc deleted successfully!
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
C:\Windows\tasks\Adobe Flash Player Updater.job moved successfully.
C:\Windows\system32\mnclidrk.vbe moved successfully.
File/Folder C:\Windows\inf\msstp.vbe not found.
========== REGISTRY ==========
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mnclidrkSrv\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe\ deleted successfully.

OTM by OldTimer - Version 3.1.21.0 log created on 05122014_121853

Files moved on Reboot...
C:\Users\Jindra M 5010\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Jindra M 5010\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

Registry entries deleted on Reboot...

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 12 kvě 2014 11:26
od Márty84
:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Malwarebytes Anti-Rootkit http://www.bleepingcomputer.com/downloa ... i-rootkit/
  • Ulozte nejlepe na Plochu a rozbalte
  • Spustte kliknutim na mbar
  • Nyni postupne kliknete na Next a Update
  • Po dokonceni update (aktualizace) databaze kliknete opet na Next
  • Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
  • Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
  • Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
  • Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
  • PC bude restartovan
  • Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte

Re: Prosím o kontrolu...Pc je divné,seká se atd...

Napsal: 12 kvě 2014 13:16
od jindra.paryzek
Tak dělalo se to dost dlouho,poprvé to zamrzlo,tak jsem to udělal znovu...
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1009

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17105

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.500000 GHz
Memory total: 3216969728, free: 2088652800

Downloaded database version: v2014.05.12.01
Downloaded database version: v2014.03.27.01
=======================================
Initializing...
------------ Kernel report ------------
05/12/2014 12:29:46
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_AuthenticAMD.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\compbatt.sys
\SystemRoot\system32\DRIVERS\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\system32\DRIVERS\MpFilter.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\bcmwl664.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\usbohci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\amdppm.sys
\SystemRoot\system32\DRIVERS\wmiacpi.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_msahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8003014530
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-0\
Lower Device Object: 0xfffffa8002ee5060
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8003014530, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8003015040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8003014530, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8002ee5060, DeviceName: \Device\Ide\IdeDeviceP0T0L0-0\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: DBB33D5E

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 1250258944
Partition file system is NTFS
Partition is bootable

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 640135028736 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1250243728-1250263728)...
Done!
Scan Interrupted
Scan Interrupted
Scan Interrupted
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1009

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17105

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.500000 GHz
Memory total: 3216969728, free: 2087100416

Downloaded database version: v2014.05.12.02
Downloaded database version: v2014.03.27.01
=======================================
Initializing...
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8003014530
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-0\
Lower Device Object: 0xfffffa8002ee5060
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: DBB33D5E

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 1250258944
Partition file system is NTFS
Partition is bootable

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 640135028736 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1250243728-1250263728)...
Done!
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished