Stránka 4 z 5

Re: ESET nedokaze odstranit vir

Napsal: 07 pro 2010 00:54
od vyosek
Mrsknete sem novy log z RSIT, vypisuje windows nejakou hlasku nebo proste vubec nic...

Re: ESET nedokaze odstranit vir

Napsal: 07 pro 2010 07:35
od jacho6380
windows nevipisuje vobec nic, len to proste nejde


Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2010-12-07 07:36:41
Microsoft Windows 7 Ultimate
System drive C: has 17 GB (11%) free of 160 GB
Total RAM: 6142 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:36:45, on 7. 12. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\EA Sports\NHL 09\nhl2009.exe
F:\NFSHP2010\NFS11.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\TRANSLAT\WebIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\TRANSLAT\WebIE.dll
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - Startup: _uninst_setup_9.0.0.722_05.12.2010_12-20.exe.lnk = Michal\AppData\Local\Temp\_uninst_setup_9.0.0.722_05.12.2010_12-20.exe.bat
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\TRANSLAT\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\TRANSLAT\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\TRANSLAT\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\TRANSLAT\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\TRANSLAT\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\TRANSLAT\WebIE.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\TRANSLAT\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\TRANSLAT\WebIE.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\TRANSLAT\WebIE.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: DroidExplorer Service (DroidExplorerService) - Ryan Conrad - C:\Program Files\Droid Explorer\DroidExplorer.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8749 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
"C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe"
"C:\Program Files\Droid Explorer\DroidExplorer.Service.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe" /watchfiles startup
"C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
"C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
"C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe"
"C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0de86835-a7a4-401a-864b-ac9519967e6a -SystemEventPortName:HostProcess-c1260578-ec8f-41ed-aecc-9742f1e6d098 -IoCancelEventPortName:HostProcess-c83e0315-7821-4c5c-af3c-5b01070e188a -NonStateChangingEventPortName:HostProcess-a380712a-15e7-4730-8303-11efda58c737 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0c7b61ee-a07c-42cf-8361-b76d28ff6e50
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\EA Sports\NHL 09\nhl2009.exe"
"F:\NFSHP2010\NFS11.exe"
"C:\Program Files\Droid Explorer\SDK\tools\adb.exe" devices
\??\C:\Windows\system32\conhost.exe
adb fork-server server
adb fork-server server
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=5068.82843c0.1877093809 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 5068 plugin \\.\pipe\gecko-crash-server-pipe.5068
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Michal\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\TRANSLAT\WebIE.dll [2010-09-24 503808]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\TRANSLAT\WebIE.dll [2010-09-24 503808]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Acronis Scheduler2 Service"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2009-09-12 357384]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2916584]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2010-05-31 57928]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"=C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2009-09-12 5048488]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"AdobeCS4ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"NokiaMServer"=C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2009-11-09 180224]
"HTC Sync Loader"=C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2010-08-18 249856]

C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
_uninst_setup_9.0.0.722_05.12.2010_12-20.exe.lnk - C:\Users\Michal\AppData\Local\Temp\_uninst_setup_9.0.0.722_05.12.2010_12-20.exe.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-12-07 07:34:05 ----D---- C:\rsit
2010-12-05 20:12:21 ----A---- C:\Windows\system32\drivers\sptd.sys
2010-12-05 20:03:04 ----SHD---- C:\$RECYCLE.BIN
2010-12-05 16:41:36 ----D---- C:\Windows\ERDNT
2010-12-05 11:30:50 ----D---- C:\ProgramData\Kaspersky Lab
2010-11-25 22:41:07 ----D---- C:\Program Files (x86)\EA Sports
2010-11-25 16:47:30 ----D---- C:\Users\Michal\AppData\Roaming\Leadertech
2010-11-25 14:47:22 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2010-11-25 14:47:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2010-11-25 14:47:22 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-11-25 14:47:22 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-11-25 14:47:21 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2010-11-25 14:47:21 ----A---- C:\Windows\system32\D3DX9_39.dll
2010-11-25 14:46:42 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2010-11-25 14:46:42 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2010-11-25 14:46:42 ----A---- C:\Windows\system32\wrap_oal.dll
2010-11-25 14:46:42 ----A---- C:\Windows\system32\OpenAL32.dll
2010-11-25 13:44:16 ----A---- C:\Windows\DIIUnin.pif
2010-11-25 13:44:16 ----A---- C:\Windows\DIIUnin.exe
2010-11-25 13:31:39 ----D---- C:\Program Files (x86)\Diablo II
2010-11-23 20:59:41 ----D---- C:\Users\Michal\AppData\Roaming\Need for Speed World
2010-11-23 12:26:30 ----A---- C:\Windows\SYSWOW64\javaws.exe
2010-11-23 12:26:30 ----A---- C:\Windows\SYSWOW64\javaw.exe
2010-11-23 12:26:30 ----A---- C:\Windows\SYSWOW64\java.exe
2010-11-23 11:42:56 ----D---- C:\Users\Michal\AppData\Roaming\Malwarebytes
2010-11-23 11:42:47 ----D---- C:\ProgramData\Malwarebytes
2010-11-23 11:42:47 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-11-22 18:07:41 ----D---- C:\Program Files\trend micro
2010-11-20 18:00:02 ----D---- C:\Users\Michal\AppData\Roaming\Media Player Classic
2010-11-20 08:58:14 ----D---- C:\ProgramData\EA Core
2010-11-20 08:34:31 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2010-11-20 08:34:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2010-11-20 08:34:31 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2010-11-20 08:34:31 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2010-11-20 08:34:31 ----A---- C:\Windows\system32\XAudio2_6.dll
2010-11-20 08:34:31 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2010-11-20 08:34:31 ----A---- C:\Windows\system32\xactengine3_6.dll
2010-11-20 08:34:31 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2010-11-20 08:34:30 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2010-11-20 08:34:30 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2010-11-20 08:34:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2010-11-20 08:34:30 ----A---- C:\Windows\system32\XAudio2_5.dll
2010-11-20 08:34:30 ----A---- C:\Windows\system32\xactengine3_5.dll
2010-11-20 08:34:30 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2010-11-20 08:34:29 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2010-11-20 08:34:29 ----A---- C:\Windows\system32\d3dcsx_42.dll
2010-11-20 08:34:28 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2010-11-20 08:34:28 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2010-11-20 08:34:28 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2010-11-20 08:34:28 ----A---- C:\Windows\system32\D3DX9_42.dll
2010-11-20 08:34:28 ----A---- C:\Windows\system32\d3dx11_42.dll
2010-11-20 08:34:28 ----A---- C:\Windows\system32\d3dx10_42.dll
2010-11-20 08:34:27 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2010-11-20 08:34:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2010-11-20 08:34:27 ----A---- C:\Windows\system32\d3dx10_41.dll
2010-11-20 08:34:27 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2010-11-20 08:34:26 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2010-11-20 08:34:26 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2010-11-20 08:34:26 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2010-11-20 08:34:26 ----A---- C:\Windows\system32\XAudio2_4.dll
2010-11-20 08:34:26 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2010-11-20 08:34:26 ----A---- C:\Windows\system32\D3DX9_41.dll
2010-11-20 08:34:25 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2010-11-20 08:34:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2010-11-20 08:34:25 ----A---- C:\Windows\system32\xactengine3_4.dll
2010-11-20 08:34:25 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2010-11-20 08:34:24 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2010-11-20 08:34:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2010-11-20 08:34:24 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-11-20 08:34:24 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-11-20 08:34:23 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2010-11-20 08:34:23 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-11-20 08:34:22 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2010-11-20 08:34:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2010-11-20 08:34:22 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2010-11-20 08:34:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2010-11-20 08:34:22 ----A---- C:\Windows\system32\XAudio2_3.dll
2010-11-20 08:34:22 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2010-11-20 08:34:22 ----A---- C:\Windows\system32\xactengine3_3.dll
2010-11-20 08:34:22 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2010-11-20 08:34:21 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2010-11-20 08:34:21 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2010-11-20 08:34:21 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2010-11-20 08:34:21 ----A---- C:\Windows\system32\XAudio2_2.dll
2010-11-20 08:34:21 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2010-11-20 08:34:21 ----A---- C:\Windows\system32\xactengine3_2.dll
2010-11-20 08:34:18 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2010-11-20 08:34:18 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2010-11-20 08:34:18 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2010-11-20 08:34:18 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-11-20 08:34:18 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-11-20 08:34:18 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-11-20 08:34:17 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2010-11-20 08:34:17 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-11-20 08:34:16 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2010-11-20 08:34:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2010-11-20 08:34:16 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-11-20 08:34:16 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-11-20 08:34:15 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2010-11-20 08:34:15 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-11-20 08:34:14 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2010-11-20 08:34:14 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2010-11-20 08:34:14 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2010-11-20 08:34:14 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-11-20 08:34:14 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-11-20 08:34:14 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-11-20 08:34:12 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2010-11-20 08:34:12 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2010-11-20 08:34:12 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-11-20 08:34:12 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-11-20 08:34:10 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2010-11-20 08:34:10 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2010-11-20 08:34:10 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-11-20 08:34:10 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-11-20 08:34:08 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2010-11-20 08:34:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2010-11-20 08:34:08 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-11-20 08:34:08 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-11-20 08:34:07 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2010-11-20 08:34:07 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2010-11-20 08:34:07 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-11-20 08:34:07 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-11-20 08:34:06 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2010-11-20 08:34:06 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2010-11-20 08:34:06 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-11-20 08:34:06 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-11-20 08:34:05 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2010-11-20 08:34:05 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-11-20 08:34:04 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2010-11-20 08:34:04 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2010-11-20 08:34:04 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2010-11-20 08:34:04 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2010-11-20 08:34:04 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-11-20 08:34:04 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-11-20 08:34:04 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-11-20 08:34:04 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-11-20 08:34:03 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2010-11-20 08:34:03 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2010-11-20 08:34:03 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2010-11-20 08:34:03 ----A---- C:\Windows\system32\xinput1_3.dll
2010-11-20 08:34:03 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-11-20 08:34:03 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-11-20 08:34:02 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2010-11-20 08:34:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2010-11-20 08:34:02 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-11-20 08:34:02 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-11-20 08:34:01 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2010-11-20 08:34:01 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2010-11-20 08:34:01 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-11-20 08:34:01 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-11-20 08:34:00 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2010-11-20 08:34:00 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2010-11-20 08:34:00 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2010-11-20 08:34:00 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-11-20 08:34:00 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-11-20 08:34:00 ----A---- C:\Windows\system32\d3dx10.dll
2010-11-20 08:33:59 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2010-11-20 08:33:59 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2010-11-20 08:33:59 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2010-11-20 08:33:59 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2010-11-20 08:33:59 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-11-20 08:33:59 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-11-20 08:33:59 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-11-20 08:33:59 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-11-20 08:33:58 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2010-11-20 08:33:58 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2010-11-20 08:33:58 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2010-11-20 08:33:58 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2010-11-20 08:33:58 ----A---- C:\Windows\system32\xinput1_2.dll
2010-11-20 08:33:58 ----A---- C:\Windows\system32\xinput1_1.dll
2010-11-20 08:33:58 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-11-20 08:33:58 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-11-20 08:33:54 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2010-11-20 08:33:54 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2010-11-20 08:33:54 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2010-11-20 08:33:54 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-11-20 08:33:54 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-11-20 08:33:54 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-11-20 08:33:53 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2010-11-20 08:33:53 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2010-11-20 08:33:53 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-11-20 08:33:53 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-11-20 08:33:52 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2010-11-20 08:33:52 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2010-11-20 08:33:52 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-11-20 08:33:52 ----A---- C:\Windows\system32\d3dx9_26.dll
2010-11-20 08:33:50 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2010-11-20 08:33:50 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2010-11-20 08:33:50 ----A---- C:\Windows\system32\d3dx9_25.dll
2010-11-20 08:33:50 ----A---- C:\Windows\system32\d3dx9_24.dll
2010-11-14 16:00:12 ----D---- C:\Program Files (x86)\Activision
2010-11-13 12:33:25 ----D---- C:\Games
2010-11-10 20:08:47 ----D---- C:\Users\Michal\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
2010-11-10 20:08:16 ----D---- C:\Users\Michal\AppData\Roaming\HTC

======List of files/folders modified in the last 1 months======

2010-12-07 07:36:45 ----D---- C:\Windows\Temp
2010-12-07 07:34:42 ----D---- C:\Windows\Prefetch
2010-12-07 07:25:54 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2010-12-07 01:39:06 ----D---- C:\Windows\system32\config
2010-12-07 01:03:38 ----D---- C:\Program Files (x86)\LogMeIn
2010-12-06 18:43:25 ----D---- C:\Windows\System32
2010-12-06 18:43:25 ----D---- C:\Windows\inf
2010-12-06 18:43:25 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-06 11:42:31 ----D---- C:\ProgramData\NVIDIA
2010-12-06 11:42:19 ----D---- C:\Windows
2010-12-06 05:49:44 ----SHD---- C:\System Volume Information
2010-12-05 20:12:21 ----D---- C:\Windows\system32\drivers
2010-12-05 20:11:32 ----D---- C:\Windows\SYSWOW64\drivers
2010-12-05 20:11:32 ----D---- C:\Program Files (x86)
2010-12-05 20:09:42 ----D---- C:\Program Files (x86)\CCleaner
2010-12-05 16:46:30 ----A---- C:\Windows\system.ini
2010-12-05 16:44:24 ----D---- C:\Windows\SysWOW64
2010-12-05 16:44:24 ----D---- C:\Windows\AppPatch
2010-12-05 16:44:22 ----D---- C:\Program Files\Common Files
2010-12-05 16:44:22 ----D---- C:\Program Files (x86)\Common Files
2010-12-05 12:04:42 ----D---- C:\Users\Michal\AppData\Roaming\MyPhoneExplorer
2010-12-05 11:30:50 ----D---- C:\ProgramData
2010-12-02 05:13:00 ----D---- C:\Windows\system32\drivers\etc
2010-12-01 15:41:30 ----SHD---- C:\Windows\Installer
2010-12-01 15:41:23 ----D---- C:\Windows\Tasks
2010-11-25 22:43:02 ----D---- C:\Config.Msi
2010-11-25 22:40:47 ----RSD---- C:\Windows\assembly
2010-11-25 22:40:18 ----D---- C:\Windows\system32\catroot2
2010-11-25 18:28:08 ----D---- C:\Windows\Help
2010-11-25 18:27:08 ----D---- C:\ProgramData\NVIDIA Corporation
2010-11-25 18:27:08 ----D---- C:\Program Files\NVIDIA Corporation
2010-11-25 18:27:02 ----D---- C:\Windows\system32\catroot
2010-11-25 18:26:56 ----D---- C:\Windows\system32\DriverStore
2010-11-25 13:07:16 ----RD---- C:\Program Files
2010-11-25 09:38:36 ----D---- C:\Users\Michal\AppData\Roaming\Dropbox
2010-11-25 09:05:32 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2010-11-25 07:05:56 ----D---- C:\Windows\WindowsMobile
2010-11-25 07:05:05 ----D---- C:\Program Files (x86)\Electronic Arts
2010-11-25 07:04:18 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2010-11-25 07:03:47 ----D---- C:\Program Files (x86)\muCommander
2010-11-25 07:03:31 ----D---- C:\ProgramData\Electronic Arts
2010-11-25 07:02:57 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2010-11-25 07:02:16 ----D---- C:\Program Files (x86)\QuickTime
2010-11-25 06:57:38 ----D---- C:\Program Files (x86)\StarCraft II
2010-11-25 03:00:32 ----D---- C:\Program Files\Internet Explorer
2010-11-25 03:00:32 ----D---- C:\Program Files (x86)\Internet Explorer
2010-11-25 03:00:31 ----D---- C:\Windows\winsxs
2010-11-24 20:34:34 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-11-23 12:26:17 ----D---- C:\Program Files (x86)\Java
2010-11-23 11:53:02 ----D---- C:\Program Files (x86)\FLV Pro Player
2010-11-20 08:31:13 ----D---- C:\ProgramData\Solidshield
2010-11-17 20:52:37 ----D---- C:\Windows\Minidump
2010-11-17 20:52:37 ----D---- C:\Windows\debug
2010-11-13 03:01:59 ----D---- C:\ProgramData\Microsoft Help
2010-11-13 03:00:41 ----A---- C:\Windows\system32\MRT.exe
2010-11-10 20:08:11 ----D---- C:\Program Files (x86)\HTC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hotcore3;hc3ServiceName; C:\Windows\system32\DRIVERS\hotcore3.sys [2010-01-17 37392]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2010-09-10 254496]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-12-05 508472]
R0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251); C:\Windows\system32\DRIVERS\tdrpm251.sys [2010-09-10 1455648]
R0 timounter;Acronis Backup Archive Explorer; C:\Windows\system32\DRIVERS\timntr.sys [2010-09-10 929312]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-11-09 91568]
R1 Uim_IM;Universal Image Mounter Plugin; C:\Windows\System32\Drivers\Uim_IMx64.sys [2010-01-17 158736]
R1 UimBus;Universal Image Mounter Controller; C:\Windows\system32\DRIVERS\uimx64.sys [2010-01-17 48144]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-06-27 88632]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 168544]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [2010-05-31 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2010-05-31 72216]
R3 afcdp;afcdp; C:\Windows\system32\DRIVERS\afcdp.sys [2010-09-10 250400]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2010-05-31 11552]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2010-09-26 34032]
S3 a6uhvfxr;a6uhvfxr; C:\Windows\system32\drivers\a6uhvfxr.sys []
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2009-11-01 33736]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2010-09-26 13352]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2010-09-26 27176]
S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-11-01 33736]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys []
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys []
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys []
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys []
S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;Sony Ericsson USB Serial Port; C:\Windows\system32\DRIVERS\usbser.sys [2009-07-14 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys []
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2009-09-12 891432]
R2 afcdpsrv;Acronis Nonstop Backup service; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-09-10 2326920]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DroidExplorerService;DroidExplorer Service; C:\Program Files\Droid Explorer\DroidExplorer.Service.exe [2010-08-21 253440]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-09-27 373640]
R2 LMIMaint;LogMeIn Maintenance Service; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [2010-09-27 120712]
R2 LogMeIn;LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [2010-05-31 57920]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 989800]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 42360]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-09-26 1038088]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-26 655624]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-09-11 1255736]

-----------------EOF-----------------

Re: ESET nedokaze odstranit vir

Napsal: 07 pro 2010 23:21
od vyosek
Havet nevidno, udelejte preventivne MBAM
:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) (viz muj podpis)
  • Provedte aktualizaci - treti zalozka
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni

Re: ESET nedokaze odstranit vir

Napsal: 08 pro 2010 17:59
od jacho6380
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verzia databázy: 5272

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

8. 12. 2010 17:58:35
mbam-log-2010-12-08 (17-58-28).txt

Typ kontroly: Úplná kontrola (C:\|D:\|F:\|G:\|)
Objektov kontrolovaných: 384734
Uplynutý čas: 39 min, 50 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 1

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
(Škodlivé položky neboli zistené)

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
d:\Lara\lcgollauncher.exe (Trojan.FakeAlert) -> No action taken.

Re: ESET nedokaze odstranit vir

Napsal: 08 pro 2010 18:55
od vyosek
Otestujte soubor na www.virustotal.com a napiste jake byly vysledky...

Re: ESET nedokaze odstranit vir

Napsal: 08 pro 2010 20:41
od jacho6380
File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis:
MD5: 3e569ce3607019a8f49db4cd645a0a4b
Date first seen: 2010-09-28 22:12:39 (UTC)
Date last seen: 2010-12-07 15:11:08 (UTC)
Detection ratio: 0/43

Re: ESET nedokaze odstranit vir

Napsal: 08 pro 2010 22:10
od vyosek
Takze nemazat...zkusim se poptat kolegu cim by to mohlo byt jelikoz haveti to nevypada...

Zkuste jeste spusti spravce uloh kliknutim pravym tlacitkem na spodni listu ve windows...

Re: ESET nedokaze odstranit vir

Napsal: 09 pro 2010 00:04
od jacho6380
tak ide...

Re: ESET nedokaze odstranit vir

Napsal: 09 pro 2010 01:27
od vyosek
Mam taktez W7 a kdyz dal ctrl+alt+delete tak mi tez nespusti spravce uloh, ale hodi me to na obrazovku kde je na vyber nekolik voleb (uzamknout, odhlasit...), tohle u vas nefunguje :???:

Re: ESET nedokaze odstranit vir

Napsal: 09 pro 2010 19:42
od jacho6380
nie, ale fungovalo to pred tym normalne

Re: ESET nedokaze odstranit vir

Napsal: 09 pro 2010 19:55
od vyosek
Zkusim se poptat kolegu...

Re: ESET nedokaze odstranit vir

Napsal: 10 pro 2010 19:59
od jacho6380
zistili ste nieco?

Re: ESET nedokaze odstranit vir

Napsal: 10 pro 2010 20:22
od vyosek
Zatim bohuzel nee, badame :o

Re: ESET nedokaze odstranit vir

Napsal: 12 pro 2010 06:58
od vyosek
:arrow: Stahnete SytemLook (viz muj podpis) a ulozte jej na plochu
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :reg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system /sub
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon /sub
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /sub
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
:arrow: Log mi prosim uploadnete na LP http://leteckaposta.cz/

Re: ESET nedokaze odstranit vir

Napsal: 12 pro 2010 12:20
od jacho6380
SystemLook 04.09.10 by jpshortstuff
Log created at 12:19 on 12/12/2010 by Michal
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.

========== reg ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"ConsentPromptBehaviorAdmin"= 0x0000000005 (5)
"ConsentPromptBehaviorUser"= 0x0000000003 (3)
"EnableInstallerDetection"= 0x0000000001 (1)
"EnableLUA"= 0x0000000001 (1)
"EnableSecureUIAPaths"= 0x0000000001 (1)
"EnableUIADesktopToggle"= 0x0000000000 (0)
"EnableVirtualization"= 0x0000000001 (1)
"PromptOnSecureDesktop"= 0x0000000001 (1)
"ValidateAdminCodeSignatures"= 0x0000000000 (0)
"dontdisplaylastusername"= 0x0000000000 (0)
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"= 0x0000000000 (0)
"shutdownwithoutlogon"= 0x0000000001 (1)
"undockwithoutlogon"= 0x0000000001 (1)
"FilterAdministratorToken"= 0x0000000000 (0)
"DisableRegistryTools"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\UIPI]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\UIPI\Clipboard]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"= 0x0000000001 (1)
"CF_BITMAP"= 0x0000000002 (2)
"CF_OEMTEXT"= 0x0000000007 (7)
"CF_DIB"= 0x0000000008 (8)
"CF_PALETTE"= 0x0000000009 (9)
"CF_UNICODETEXT"= 0x000000000d (13)
"CF_DIBV5"= 0x0000000011 (17)


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"ReportBootOk"="1"
"Shell"="Explorer.exe"
"PreCreateKnownFolders"="{A520A1A4-1780-4FF6-BD18-167343C5AF16}"
"DefaultDomainName"=""
"DefaultUserName"=""
"Userinit"="C:\Windows\system32\userinit.exe,"
"VMApplet"="SystemPropertiesPerformance.exe /pagefile"
"LegalNoticeCaption"=""
"LegalNotice Text"=""
"AutoRestartShell"= 0x0000000001 (1)
"SFCDisable"= 0x0000000000 (0)
"System"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}]
@="Wireless Group Policy"
"DisplayName"="@wlgpclnt.dll,-100"
"ProcessGroupPolicyEx"="ProcessWLANPolicyEx"
"GenerateGroupPolicy"="GenerateWLANPolicy"
"DllName"="wlgpclnt.dll"
"NoUserPolicy"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0E28E245-9368-4853-AD84-6DA3BA35BB75}]
@="Group Policy Environment"
"ProcessGroupPolicy"="ProcessGroupPolicyEnviron"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyEnviron"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExEnviron"
"EventSources"="(Group Policy Environment,Application)"
"DisplayName"="@gpprefcl.dll,-1"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{17D89FEC-5C44-4972-B12D-241CAEF74509}]
@="Group Policy Local Users and Groups"
"ProcessGroupPolicy"="ProcessGroupPolicyLocUsAndGroups"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyLocUsAndGroups"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExLocUsAndGroups"
"EventSources"="(Group Policy Local Users and Groups,Application)"
"DisplayName"="@gpprefcl.dll,-2"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{1A6364EB-776B-4120-ADE1-B63A406A76B5}]
@="Group Policy Device Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyDevices"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDevices"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDevices"
"EventSources"="(Group Policy Device Settings,Application)"
"DisplayName"="@gpprefcl.dll,-3"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
@="Folder Redirection"
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"DllName"="fdeploy.dll"
"NoMachinePolicy"= 0x0000000001 (1)
"NoSlowLink"= 0x0000000001 (1)
"PerUserLocalSettings"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000000 (0)
"NoBackgroundPolicy"= 0x0000000000 (0)
"GenerateGroupPolicy"="GenerateGroupPolicy"
"EventSources"="(Folder Redirection,Application)"
"DisplayName"="@fdeploy.dll,-261"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@="Microsoft Disk Quota"
"DisplayName"="@%SystemRoot%\System32\dskquota.dll,-100"
"NoMachinePolicy"= 0x0000000000 (0)
"NoUserPolicy"= 0x0000000001 (1)
"NoSlowLink"= 0x0000000001 (1)
"NoBackgroundPolicy"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000001 (1)
"PerUserLocalSettings"= 0x0000000000 (0)
"RequiresSuccessfulRegistry"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000000 (0)
"DllName"="%SystemRoot%\System32\dskquota.dll"
"ProcessGroupPolicy"="ProcessGroupPolicy"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F}]
@="Group Policy Network Options"
"ProcessGroupPolicy"="ProcessGroupPolicyNetworkOptions"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyNetworkOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExNetworkOptions"
"EventSources"="(Group Policy Network Options,Application)"
"DisplayName"="@gpprefcl.dll,-4"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
@="QoS Packet Scheduler"
"DisplayName"="@gptext.dll,-201"
"ProcessGroupPolicy"="ProcessPSCHEDPolicy"
"DllName"="gptext.dll"
"NoUserPolicy"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}]
@="Scripts"
"ProcessGroupPolicy"="ProcessScriptsGroupPolicy"
"DllName"="gpscript.dll"
"GenerateGroupPolicy"="GenerateScriptsGroupPolicy"
"NoSlowLink"= 0x0000000001 (1)
"ProcessGroupPolicyEx"="ProcessScriptsGroupPolicyEx"
"NoGPOListChanges"= 0x0000000001 (1)
"NotifyLinkTransition"= 0x0000000001 (1)
"DisplayName"="@gpscript.dll,-1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
@="Internet Explorer Zonemapping"
"ProcessGroupPolicy"="ProcessGroupPolicyForZoneMap"
"DllName"="C:\Windows\SysWOW64\iedkcs32.dll"
"RequiresSuccessfulRegistry"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000001 (1)
"DisplayName"="@C:\Windows\SysWOW64\iedkcs32.dll,-3051"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{5794DAFD-BE60-433f-88A2-1A31939AC01F}]
@="Group Policy Drive Maps"
"ProcessGroupPolicy"="ProcessGroupPolicyDrives"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDrives"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDrives"
"EventSources"="(Group Policy Drive Maps,Application)"
"NoMachinePolicy"= 0x0000000001 (1)
"DisplayName"="@gpprefcl.dll,-5"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)
"NoBackgroundPolicy"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6232C319-91AC-4931-9385-E70C2B099F0E}]
@="Group Policy Folders"
"ProcessGroupPolicy"="ProcessGroupPolicyFolders"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFolders"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFolders"
"EventSources"="(Group Policy Folders,Application)"
"DisplayName"="@gpprefcl.dll,-6"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6A4C88C6-C502-4f74-8F60-2CB23EDC24E2}]
@="Group Policy Network Shares"
"ProcessGroupPolicy"="ProcessGroupPolicyNetShares"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyNetShares"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExNetShares"
"EventSources"="(Group Policy Network Shares,Application)"
"NoUserPolicy"= 0x0000000001 (1)
"DisplayName"="@gpprefcl.dll,-7"
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7150F9BF-48AD-4da4-A49C-29EF4A8369BA}]
@="Group Policy Files"
"ProcessGroupPolicy"="ProcessGroupPolicyFiles"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFiles"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFiles"
"EventSources"="(Group Policy Files,Application)"
"DisplayName"="@gpprefcl.dll,-8"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{728EE579-943C-4519-9EF7-AB56765798ED}]
@="Group Policy Data Sources"
"ProcessGroupPolicy"="ProcessGroupPolicyDataSources"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyDataSources"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExDataSources"
"EventSources"="(Group Policy Data Sources,Application)"
"DisplayName"="@gpprefcl.dll,-9"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{74EE6C03-5363-4554-B161-627540339CAB}]
@="Group Policy Ini Files"
"ProcessGroupPolicy"="ProcessGroupPolicyIniFile"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyIniFile"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExIniFile"
"EventSources"="(Group Policy Ini Files,Application)"
"DisplayName"="@gpprefcl.dll,-10"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7933F41E-56F8-41d6-A31C-4148A711EE93}]
@="Windows Search Group Policy Extension"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"="%SystemRoot%\System32\srchadmin.dll"
"RequiresSuccessfulRegistry"= 0x0000000001 (1)
"NoSlowLink"= 0x0000000000 (0)
"NoGPOListChanges"= 0x0000000001 (1)
"NoUserPolicy"= 0x0000000000 (0)
"NoMachinePolicy"= 0x0000000000 (0)
"PerUserLocalSettings"= 0x0000000000 (0)
"EnableAsynchronousProcessing"= 0x0000000001 (1)
"NoBackgroundPolicy"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}]
@="Internet Explorer User Accelerators"
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"DllName"="C:\Windows\SysWOW64\iedkcs32.dll"
"RequiresSuccessfulRegistry"= 0x0000000001 (1)
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"NoGPOListChanges"= 0x0000000001 (1)
"DisplayName"="@C:\Windows\SysWOW64\iedkcs32.dll,-3051"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
@="Security"
"DisplayName"="@(runtime.system32)\scecli.dll,-7650"
"ProcessGroupPolicy"="SceProcessSecurityPolicyGPO"
"GenerateGroupPolicy"="SceGenerateGroupPolicy"
"ExtensionRsopPlanningDebugLevel"= 0x0000000001 (1)
"ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx"
"ExtensionDebugLevel"= 0x0000000001 (1)
"DllName"="scecli.dll"
"NoUserPolicy"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)
"MaxNoGPOListChangesInterval"= 0x00000003c0 (960)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{8A28E2C5-8D06-49A4-A08C-632DAA493E17}]
@="Deployed Printer Connections"
"DisplayName"="@%systemroot%\system32\gpprnext.dll,-1"
"DllName"="%systemroot%\system32\gpprnext.dll"
"EnableAsynchronousProcessing"= 0x0000000001 (1)
"ExtensionEventSource"=""
"GenerateGroupPolicy"="PrinterGenerateGroupPolicy"
"MaxNoGPOListChangesInterval"= 0x0000000000 (0)
"NoBackgroundPolicy"= 0x0000000000 (0)
"NoGPOListChanges"= 0x0000000000 (0)
"NoMachinePolicy"= 0x0000000000 (0)
"NoSlowLink"= 0x0000000001 (1)
"NotifyLinkTransition"= 0x0000000000 (0)
"NoUserPolicy"= 0x0000000000 (0)
"PerUserLocalSettings"= 0x0000000000 (0)
"ProcessGroupPolicy"="PrinterProcessGroupPolicy"
"ProcessGroupPolicyEx"="PrinterProcessGroupPolicyEx"
"RequiresSuccessfulRegistry"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{91FBB303-0CD5-4055-BF42-E512A681B325}]
@="Group Policy Services"
"ProcessGroupPolicy"="ProcessGroupPolicyServices"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyServices"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExServices"
"EventSources"="(Group Policy Services,Application)"
"DisplayName"="@gpprefcl.dll,-11"
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
@="Internet Explorer Branding"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"="C:\Windows\SysWOW64\iedkcs32.dll"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"NoSlowLink"= 0x0000000001 (1)
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"NoGPOListChanges"= 0x0000000001 (1)
"NoMachinePolicy"= 0x0000000001 (1)
"DisplayName"="@C:\Windows\SysWOW64\iedkcs32.dll,-3014"
"NoBackgroundPolicy"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A3F3E39B-5D83-4940-B954-28315B82F0A8}]
@="Group Policy Folder Options"
"ProcessGroupPolicy"="ProcessGroupPolicyFolderOptions"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyFolderOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExFolderOptions"
"EventSources"="(Group Policy Folder Options,Application)"
"DisplayName"="@gpprefcl.dll,-12"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{AADCED64-746C-4633-A97C-D61349046527}]
@="Group Policy Scheduled Tasks"
"ProcessGroupPolicy"="ProcessGroupPolicySchedTasks"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicySchedTasks"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExSchedTasks"
"EventSources"="(Group Policy Scheduled Tasks,Application)"
"DisplayName"="@gpprefcl.dll,-13"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B087BE9D-ED37-454f-AF9C-04291E351182}]
@="Group Policy Registry"
"ProcessGroupPolicy"="ProcessGroupPolicyRegistry"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyRegistry"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExRegistry"
"EventSources"="(Group Policy Registry,Application)"
"DisplayName"="@gpprefcl.dll,-14"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}]
@="802.3 Group Policy"
"DisplayName"="@dot3gpclnt.dll,-100"
"ProcessGroupPolicyEx"="ProcessLANPolicyEx"
"GenerateGroupPolicy"="GenerateLANPolicy"
"DllName"="dot3gpclnt.dll"
"NoUserPolicy"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{BC75B1ED-5833-4858-9BB8-CBF0B166DF9D}]
@="Group Policy Printers"
"ProcessGroupPolicy"="ProcessGroupPolicyPrinters"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyPrinters"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExPrinters"
"EventSources"="(Group Policy Printers,Application)"
"DisplayName"="@gpprefcl.dll,-16"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7}]
@="Group Policy Shortcuts"
"ProcessGroupPolicy"="ProcessGroupPolicyShortcuts"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyShortcuts"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExShortcuts"
"EventSources"="(Group Policy Shortcuts,Application)"
"DisplayName"="@gpprefcl.dll,-17"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}]
@="Microsoft Offline Files"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"="%SystemRoot%\System32\cscobj.dll"
"RequiresSuccessfulRegistry"= 0x0000000001 (1)
"NoSlowLink"= 0x0000000000 (0)
"NoGPOListChanges"= 0x0000000000 (0)
"NoUserPolicy"= 0x0000000000 (0)
"NoMachinePolicy"= 0x0000000000 (0)
"PerUserLocalSettings"= 0x0000000000 (0)
"EnableAsynchronousProcessing"= 0x0000000001 (1)
"NoBackgroundPolicy"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
@="Software Installation"
"RequiresSucessfulRegistry"= 0x0000000000 (0)
"DllName"="appmgmts.dll"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"NoSlowLink"= 0x0000000001 (1)
"ProcessGroupPolicyEx"="ProcessGroupPolicyObjectsEx"
"EventSources"="(Application Management,Application) (MsiInstaller,Application)"
"NoUserPolicy"= 0x0000000000 (0)
"DisplayName"="@appmgmts.dll,-3252"
"PerUserLocalSettings"= 0x0000000001 (1)
"NoBackgroundPolicy"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{cdeafc3d-948d-49dd-ab12-e578ba4af7aa}]
@="TCPIP"
"DisplayName"="@gptext.dll,-204"
"ProcessGroupPolicy"="ProcessTCPIPPolicy"
"DllName"="gptext.dll"
"NoUserPolicy"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000001 (1)
"RequiresSuccessfulRegistry"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}]
@="Internet Explorer Machine Accelerators"
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"DllName"="C:\Windows\SysWOW64\iedkcs32.dll"
"RequiresSuccessfulRegistry"= 0x0000000001 (1)
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"NoGPOListChanges"= 0x0000000001 (1)
"DisplayName"="@C:\Windows\SysWOW64\iedkcs32.dll,-3051"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
@="IP Security"
"ProcessGroupPolicyEx"="ProcessIPSECPolicyEx"
"GenerateGroupPolicy"="GenerateIPSECPolicy"
"DllName"="%SystemRoot%\System32\polstore.dll"
"NoUserPolicy"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E47248BA-94CC-49c4-BBB5-9EB7F05183D0}]
@="Group Policy Internet Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyInternet"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyInternet"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExInternet"
"EventSources"="(Group Policy Internet Settings,Application)"
"NoMachinePolicy"= 0x0000000001 (1)
"DisplayName"="@gpprefcl.dll,-18"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E4F48E54-F38D-4884-BFB9-D4D2E5729C18}]
@="Group Policy Start Menu Settings"
"ProcessGroupPolicy"="ProcessGroupPolicyStartMenu"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyStartMenu"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExStartMenu"
"EventSources"="(Group Policy Start Menu Settings,Application)"
"DisplayName"="@gpprefcl.dll,-19"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E5094040-C46C-4115-B030-04FB2E545B00}]
@="Group Policy Regional Options"
"ProcessGroupPolicy"="ProcessGroupPolicyRegionOptions"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyRegionOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExRegionOptions"
"EventSources"="(Group Policy Regional Options,Application)"
"DisplayName"="@gpprefcl.dll,-20"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E62688F0-25FD-4c90-BFF5-F508B9D2E31F}]
@="Group Policy Power Options"
"ProcessGroupPolicy"="ProcessGroupPolicyPowerOptions"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyPowerOptions"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExPowerOptions"
"EventSources"="(Group Policy Power Options,Application)"
"DisplayName"="@gpprefcl.dll,-21"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{F9C77450-3A41-477E-9310-9ACD617BD9E3}]
@="Group Policy Applications"
"ProcessGroupPolicy"="ProcessGroupPolicyApplications"
"DllName"="gpprefcl.dll"
"GenerateGroupPolicy"="GenerateGroupPolicyApplications"
"ProcessGroupPolicyEx"="ProcessGroupPolicyExApplications"
"EventSources"="(Group Policy Applications,Application)"
"NoMachinePolicy"= 0x0000000001 (1)
"DisplayName"="@gpprefcl.dll,-15"
"PerUserLocalSettings"= 0x0000000001 (1)
"EnableAsynchronousProcessing"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{FB2CA36D-0B40-4307-821B-A13B252DE56C}]
@="Enterprise QoS"
"DisplayName"="@gptext.dll,-203"
"ProcessGroupPolicy"="ProcessEQoSPolicy"
"DllName"="gptext.dll"
"RequiresSuccessfulRegistry"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f}]
@="CP"
"DisplayName"="@gptext.dll,-205"
"ProcessGroupPolicy"="ProcessConnectivityPlatformPolicy"
"DllName"="gptext.dll"
"NoUserPolicy"= 0x0000000001 (1)
"NoGPOListChanges"= 0x0000000001 (1)
"RequiresSuccessfulRegistry"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList]
(No values found)


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"= 0x0000000000 (0)


-= EOF =-