Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

RSIT log

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
deny95
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 lis 2008 09:11

RSIT log

#1 Příspěvek od deny95 »

pomaly boot ....mam na 14 čiarok = ako bootuje windows.......reinstal win pred tyždnom......použ. programy : CCleaner , Tune Up Utilities 2010


Logfile of random's system information tool 1.06 (written by random/random)
Run by Denisko at 2010-05-04 18:24:30
Microsoft Windows XP Professional Service Pack 3
System drive D: has 66 GB (86%) free of 76 GB
Total RAM: 1918 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:24:50, on 4. 5. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\LClock\LClock.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\Denisko\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
D:\Documents and Settings\Denisko\Desktop\RSIT.exe
D:\Program Files\trend micro\Denisko.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [LClock] D:\Program Files\LClock\LClock.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [TaskSwitchXP] D:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TaskSwitchXP] D:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TaskSwitchXP] D:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - D:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - D:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 4225 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1979792683-1801674531-1004Core.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1979792683-1801674531-1004UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-01 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-05-01 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"LClock"=D:\Program Files\LClock\LClock.exe [2004-09-19 65536]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-03-21 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
D:\Documents and Settings\Denisko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-27 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskSwitchXP]
D:\Program Files\TaskSwitchXP\TaskSwitchXP.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VisualTooltip]
D:\Program Files\Utilities\VisualTooltip\VisualToolTip.exe [2007-04-25 956928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^Denisko^Start Menu^Programs^Startup^Styler.lnk]
D:\Documents and Settings\Denisko\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2008-10-27 131072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
D:\WINDOWS\system32\WgaLogon.dll [2009-02-12 190976]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\REALTEK\RTL8187B Wireless LAN Utility\RtWLan.exe"="D:\Program Files\REALTEK\RTL8187B Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.bat - edit - D:\WINDOWS\system32\Notepad2.exe %1
.cmd - edit - D:\WINDOWS\system32\Notepad2.exe %1
.inf - open - D:\WINDOWS\system32\Notepad2.exe %1
.ini - open - D:\WINDOWS\system32\Notepad2.exe %1
.js - edit - D:\WINDOWS\system32\Notepad2.exe %1
.reg - edit - D:\WINDOWS\system32\Notepad2.exe %1
.txt - open - D:\WINDOWS\system32\Notepad2.exe %1
.vbs - edit - D:\WINDOWS\system32\Notepad2.exe %1

======List of files/folders created in the last 1 months======

2010-05-04 18:24:30 ----D---- D:\rsit
2010-05-04 18:24:30 ----D---- D:\Program Files\trend micro
2010-05-04 15:21:10 ----D---- D:\WINDOWS\LastGood
2010-05-03 17:49:33 ----D---- D:\Program Files\Microsoft Bootvis
2010-05-03 17:01:49 ----D---- D:\Documents and Settings\Denisko\Application Data\Avira
2010-05-01 19:42:52 ----D---- D:\Documents and Settings\Denisko\Application Data\dvdcss
2010-05-01 15:30:24 ----D---- D:\WINDOWS\Sun
2010-05-01 15:30:20 ----D---- D:\Documents and Settings\All Users\Application Data\Sun
2010-05-01 15:30:19 ----D---- D:\Program Files\Common Files\Java
2010-05-01 15:30:06 ----A---- D:\WINDOWS\system32\javaws.exe
2010-05-01 15:30:06 ----A---- D:\WINDOWS\system32\javaw.exe
2010-05-01 15:30:06 ----A---- D:\WINDOWS\system32\java.exe
2010-05-01 15:30:06 ----A---- D:\WINDOWS\system32\deployJava1.dll
2010-05-01 15:29:53 ----D---- D:\Program Files\Java
2010-05-01 15:28:58 ----D---- D:\Documents and Settings\Denisko\Application Data\Sun
2010-04-30 22:11:51 ----D---- D:\WINDOWS\system32\NtmsData
2010-04-30 21:11:15 ----D---- D:\Program Files\Avira
2010-04-30 21:11:15 ----D---- D:\Documents and Settings\All Users\Application Data\Avira
2010-04-30 19:46:59 ----D---- D:\Documents and Settings\Denisko\Application Data\ATI
2010-04-30 19:46:59 ----D---- D:\Documents and Settings\All Users\Application Data\ATI
2010-04-30 19:42:03 ----A---- D:\WINDOWS\system32\Oemdspif.dll
2010-04-30 19:42:03 ----A---- D:\WINDOWS\system32\ativvaxx.dll
2010-04-30 19:42:03 ----A---- D:\WINDOWS\system32\ativcoxx.dll
2010-04-30 19:42:03 ----A---- D:\WINDOWS\system32\atitvo32.dll
2010-04-30 19:42:03 ----A---- D:\WINDOWS\system32\atipdlxx.dll
2010-04-30 19:42:03 ----A---- D:\WINDOWS\system32\atiok3x2.dll
2010-04-30 19:42:03 ----A---- D:\WINDOWS\system32\atioglxx.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\atioglx2.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\atikvmag.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\atiiiexx.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\ATIDEMGX.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\ATIDDC.DLL
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\ati3duag.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\Ati2mdxx.exe
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\ati2evxx.exe
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\ati2evxx.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\ati2edxx.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\ati2dvag.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\ati2cqag.dll
2010-04-30 19:42:02 ----A---- D:\WINDOWS\system32\amdpcom32.dll
2010-04-30 16:13:05 ----D---- D:\Program Files\ATI Technologies
2010-04-30 14:54:55 ----D---- D:\WINDOWS\system32\Lang
2010-04-30 14:53:27 ----D---- D:\WINDOWS\system32\RTCOM
2010-04-30 14:53:17 ----A---- D:\WINDOWS\vncutil.exe
2010-04-30 14:53:17 ----A---- D:\WINDOWS\system32\RtkCoInstXP.dll
2010-04-30 14:53:17 ----A---- D:\WINDOWS\SOUNDMAN.EXE
2010-04-30 14:53:17 ----A---- D:\WINDOWS\SkyTel.exe
2010-04-30 14:53:17 ----A---- D:\WINDOWS\RtlUpd.exe
2010-04-30 14:53:17 ----A---- D:\WINDOWS\RTLCPL.EXE
2010-04-30 14:53:17 ----A---- D:\WINDOWS\RtkAudioService.exe
2010-04-30 14:53:16 ----A---- D:\WINDOWS\RTHDCPL.EXE
2010-04-30 14:53:16 ----A---- D:\WINDOWS\MicCal.exe
2010-04-30 14:53:15 ----A---- D:\WINDOWS\ALCWZRD.EXE
2010-04-30 14:53:15 ----A---- D:\WINDOWS\ALCMTR.EXE
2010-04-30 14:53:10 ----A---- D:\WINDOWS\RtlExUpd.dll
2010-04-29 22:22:00 ----A---- D:\WINDOWS\system32\TUKernel.exe
2010-04-29 18:51:52 ----A---- D:\WINDOWS\system32\TURegOpt.exe
2010-04-29 18:51:50 ----A---- D:\WINDOWS\system32\uxtuneup.dll
2010-04-29 18:51:42 ----D---- D:\Documents and Settings\Denisko\Application Data\TuneUp Software
2010-04-29 18:51:30 ----D---- D:\Program Files\TuneUp Utilities 2010
2010-04-29 18:51:17 ----D---- D:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-04-29 18:51:09 ----SHD---- D:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-04-28 17:05:00 ----D---- D:\WINDOWS\SxsCaPendDel
2010-04-28 16:34:08 ----D---- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-04-28 16:11:12 ----A---- D:\WINDOWS\system32\MRT.exe
2010-04-28 16:00:07 ----D---- D:\WINDOWS\ie7updates
2010-04-28 15:10:48 ----D---- D:\WINDOWS\system32\CatRoot_bak
2010-04-28 14:57:17 ----N---- D:\WINDOWS\system32\browserchoice.exe
2010-04-28 14:52:28 ----N---- D:\WINDOWS\system32\xpsp4res.dll
2010-04-28 14:50:37 ----D---- D:\WINDOWS\system32\PreInstall
2010-04-28 14:50:35 ----HD---- D:\WINDOWS\$hf_mig$
2010-04-28 14:41:24 ----D---- D:\WINDOWS\system32\SoftwareDistribution
2010-04-27 20:25:26 ----D---- D:\Documents and Settings\Denisko\Application Data\Macromedia
2010-04-27 19:15:00 ----D---- D:\Documents and Settings\Denisko\Application Data\Adobe
2010-04-27 19:13:55 ----D---- D:\Documents and Settings\All Users\Application Data\Adobe
2010-04-27 19:13:52 ----D---- D:\Program Files\Common Files\Adobe
2010-04-27 19:13:52 ----D---- D:\Program Files\Adobe
2010-04-27 18:51:04 ----D---- D:\ATI
2010-04-27 16:51:03 ----D---- D:\WINDOWS\pss
2010-04-27 15:26:44 ----D---- D:\WINDOWS\system32\appmgmt
2010-04-27 15:19:59 ----D---- D:\Program Files\Lavalys
2010-04-27 00:11:08 ----D---- D:\Documents and Settings\Denisko\Application Data\vlc
2010-04-27 00:10:10 ----D---- D:\Program Files\VideoLAN
2010-04-27 00:00:24 ----D---- D:\Documents and Settings\All Users\Application Data\Innovative Solutions
2010-04-26 23:59:54 ----A---- D:\WINDOWS\system32\h323log.txt
2010-04-26 23:57:42 ----A---- D:\WINDOWS\system32\vfwwdm32.dll
2010-04-26 23:57:42 ----A---- D:\WINDOWS\system32\ksuser.dll
2010-04-26 23:56:46 ----A---- D:\WINDOWS\system32\usbui.dll
2010-04-26 23:54:43 ----ASH---- D:\Documents and Settings\All Users\Application Data\desktop.ini
2010-04-26 23:54:38 ----RA---- D:\WINDOWS\SET44.tmp
2010-04-26 23:54:35 ----RA---- D:\WINDOWS\SET38.tmp
2010-04-26 23:54:33 ----RA---- D:\WINDOWS\SET35.tmp
2010-04-26 23:54:12 ----SD---- D:\Documents and Settings\All Users\Application Data\Microsoft
2010-04-26 23:51:08 ----A---- D:\WINDOWS\iun6002.exe
2010-04-26 23:51:04 ----D---- D:\Program Files\Codec Pack - All In 1
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\vxblock.dll
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\pxwave.dll
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\pxsfs.dll
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\pxmas.dll
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\pxinsa64.exe
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\pxhpinst.exe
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\pxdrv.dll
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\pxcpya64.exe
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\pxafs.dll
2010-04-26 23:35:57 ----N---- D:\WINDOWS\system32\px.dll
2010-04-26 23:35:56 ----D---- D:\Program Files\Winamp
2010-04-26 23:35:56 ----D---- D:\Documents and Settings\Denisko\Application Data\Winamp
2010-04-26 23:30:13 ----A---- D:\WINDOWS\MyDrivers.ini
2010-04-26 23:23:35 ----SHD---- D:\WINDOWS\Installer
2010-04-26 23:23:35 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-04-26 23:23:34 ----D---- D:\Program Files\Common Files\ODBC
2010-04-26 23:23:34 ----A---- D:\WINDOWS\ODBCINST.INI
2010-04-26 23:23:30 ----D---- D:\Program Files\Common Files\SpeechEngines
2010-04-26 23:23:29 ----RD---- D:\Program Files
2010-04-26 23:23:29 ----D---- D:\Program Files\Common Files\Microsoft Shared
2010-04-26 23:23:29 ----D---- D:\Program Files\Common Files
2010-04-26 23:23:26 ----RA---- D:\WINDOWS\system32\kbdtuq.dll
2010-04-26 23:23:26 ----RA---- D:\WINDOWS\system32\kbdtuf.dll
2010-04-26 23:23:26 ----RA---- D:\WINDOWS\system32\kbdazel.dll
2010-04-26 23:23:24 ----RA---- D:\WINDOWS\system32\kbdtat.dll
2010-04-26 23:23:24 ----RA---- D:\WINDOWS\system32\kbdmon.dll
2010-04-26 23:23:24 ----RA---- D:\WINDOWS\system32\kbdkyr.dll
2010-04-26 23:23:24 ----RA---- D:\WINDOWS\system32\kbdaze.dll
2010-04-26 23:23:23 ----RA---- D:\WINDOWS\system32\kbdycc.dll
2010-04-26 23:23:23 ----RA---- D:\WINDOWS\system32\kbduzb.dll
2010-04-26 23:23:23 ----RA---- D:\WINDOWS\system32\kbdur.dll
2010-04-26 23:23:23 ----RA---- D:\WINDOWS\system32\kbdru1.dll
2010-04-26 23:23:23 ----RA---- D:\WINDOWS\system32\kbdru.dll
2010-04-26 23:23:23 ----RA---- D:\WINDOWS\system32\kbdkaz.dll
2010-04-26 23:23:23 ----RA---- D:\WINDOWS\system32\kbdbu.dll
2010-04-26 23:23:23 ----RA---- D:\WINDOWS\system32\kbdblr.dll
2010-04-26 23:23:21 ----RA---- D:\WINDOWS\system32\kbdhept.dll
2010-04-26 23:23:21 ----RA---- D:\WINDOWS\system32\kbdhela3.dll
2010-04-26 23:23:21 ----RA---- D:\WINDOWS\system32\kbdhela2.dll
2010-04-26 23:23:21 ----RA---- D:\WINDOWS\system32\kbdhe319.dll
2010-04-26 23:23:21 ----RA---- D:\WINDOWS\system32\kbdhe220.dll
2010-04-26 23:23:21 ----RA---- D:\WINDOWS\system32\kbdhe.dll
2010-04-26 23:23:21 ----RA---- D:\WINDOWS\system32\kbdgkl.dll
2010-04-26 23:23:19 ----RA---- D:\WINDOWS\system32\kbdlv1.dll
2010-04-26 23:23:19 ----RA---- D:\WINDOWS\system32\kbdlv.dll
2010-04-26 23:23:19 ----RA---- D:\WINDOWS\system32\kbdlt1.dll
2010-04-26 23:23:19 ----RA---- D:\WINDOWS\system32\kbdlt.dll
2010-04-26 23:23:19 ----RA---- D:\WINDOWS\system32\kbdest.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdycl.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdsl1.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdsl.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdro.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdpl1.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdpl.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdhu1.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdhu.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdcz2.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdcz1.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdcz.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\kbdcr.dll
2010-04-26 23:23:17 ----RA---- D:\WINDOWS\system32\KBDAL.DLL
2010-04-26 23:23:12 ----A---- D:\WINDOWS\system32\irclass.dll
2010-04-26 23:23:11 ----A---- D:\WINDOWS\system32\spxcoins.dll
2010-04-26 23:23:11 ----A---- D:\WINDOWS\system32\EqnClass.Dll
2010-04-26 23:23:11 ----A---- D:\WINDOWS\system32\dgsetup.dll
2010-04-26 23:23:11 ----A---- D:\WINDOWS\system32\dgrpsetu.dll
2010-04-26 23:23:09 ----N---- D:\WINDOWS\system32\CONFIG.TMP
2010-04-26 23:23:09 ----A---- D:\WINDOWS\TASKMAN.EXE
2010-04-26 23:23:08 ----A---- D:\WINDOWS\system32\storprop.dll
2010-04-26 23:23:08 ----A---- D:\WINDOWS\system32\batt.dll
2010-04-26 23:23:08 ----A---- D:\WINDOWS\NOTEPAD.EXE
2010-04-26 23:22:54 ----RA---- D:\WINDOWS\SET8.tmp
2010-04-26 23:22:51 ----RA---- D:\WINDOWS\SET4.tmp
2010-04-26 23:22:50 ----RA---- D:\WINDOWS\SET3.tmp
2010-04-26 23:22:45 ----D---- D:\WINDOWS\system32\CatRoot2
2010-04-26 23:22:45 ----D---- D:\WINDOWS\system32\CatRoot
2010-04-26 23:20:18 ----D---- D:\Documents and Settings
2010-04-26 23:20:17 ----SHD---- D:\System Volume Information
2010-04-26 23:14:55 ----A---- D:\WINDOWS\swupdate.INI
2010-04-26 23:14:25 ----RSD---- D:\WINDOWS\Fonts
2010-04-26 23:14:25 ----RD---- D:\WINDOWS\Web
2010-04-26 23:14:25 ----HD---- D:\WINDOWS\inf
2010-04-26 23:14:25 ----D---- D:\WINDOWS\WinSxS
2010-04-26 23:14:25 ----D---- D:\WINDOWS\twain_32
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Temp
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\wins
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\wbem
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\usmt
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\spool
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\ShellExt
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\Setup
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\scripting
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\ras
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\oobe
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\npp
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\mui
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\inetsrv
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\IME
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\icsxml
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\ias
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\export
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\en
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\drivers
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\dhcp
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\config
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\3com_dmi
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\3076
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\2052
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\1054
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\1042
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\1041
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\1037
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\1033
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\1031
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\1028
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32\1025
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system32
2010-04-26 23:14:25 ----D---- D:\WINDOWS\system
2010-04-26 23:14:25 ----D---- D:\WINDOWS\security
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Resources
2010-04-26 23:14:25 ----D---- D:\WINDOWS\repair
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Provisioning
2010-04-26 23:14:25 ----D---- D:\WINDOWS\pchealth
2010-04-26 23:14:25 ----D---- D:\WINDOWS\PeerNet
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Network Diagnostic
2010-04-26 23:14:25 ----D---- D:\WINDOWS\mui
2010-04-26 23:14:25 ----D---- D:\WINDOWS\msapps
2010-04-26 23:14:25 ----D---- D:\WINDOWS\msagent
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Media
2010-04-26 23:14:25 ----D---- D:\WINDOWS\L2Schemas
2010-04-26 23:14:25 ----D---- D:\WINDOWS\java
2010-04-26 23:14:25 ----D---- D:\WINDOWS\ime
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Help
2010-04-26 23:14:25 ----D---- D:\WINDOWS\ehome
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Driver Cache
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Debug
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Cursors
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Connection Wizard
2010-04-26 23:14:25 ----D---- D:\WINDOWS\Config
2010-04-26 23:14:25 ----D---- D:\WINDOWS\AppPatch
2010-04-26 23:14:25 ----D---- D:\WINDOWS\addins
2010-04-26 23:14:25 ----D---- D:\WINDOWS
2010-04-26 23:10:44 ----D---- D:\Program Files\Common Files\InstallShield
2010-04-26 22:57:11 ----D---- D:\Documents and Settings\Denisko\Application Data\WinBatch
2010-04-26 22:47:00 ----SHD---- D:\RECYCLER
2010-04-26 22:42:59 ----D---- D:\WINDOWS\system32\RtlGina
2010-04-26 22:42:59 ----D---- D:\Program Files\REALTEK
2010-04-26 22:42:59 ----A---- D:\WINDOWS\system32\ISSRemoveSP.exe
2010-04-26 22:32:14 ----D---- D:\WINDOWS\OPTIONS
2010-04-26 22:32:13 ----HD---- D:\Program Files\InstallShield Installation Information
2010-04-26 22:32:10 ----D---- D:\Documents and Settings\Denisko\Application Data\InstallShield
2010-04-26 22:30:00 ----D---- D:\Documents and Settings\Denisko\Application Data\Talkback
2010-04-26 22:29:50 ----D---- D:\Documents and Settings\Denisko\Application Data\Mozilla
2010-04-26 22:28:36 ----D---- D:\Documents and Settings\Denisko\Application Data\Styler
2010-04-26 22:28:18 ----D---- D:\Documents and Settings\Denisko\Application Data\Identities
2010-04-26 22:28:16 ----HD---- D:\Program Files\Uninstall Information
2010-04-26 22:27:09 ----ASH---- D:\Documents and Settings\Denisko\Application Data\desktop.ini
2010-04-26 22:26:53 ----SD---- D:\Documents and Settings\Denisko\Application Data\Microsoft
2010-04-26 22:26:53 ----D---- D:\Documents and Settings\Denisko\Application Data\WinRAR
2010-04-26 22:26:13 ----D---- D:\WINDOWS\SoftwareDistribution
2010-04-26 22:26:11 ----D---- D:\WINDOWS\Prefetch
2010-04-26 22:26:10 ----SD---- D:\WINDOWS\system32\Microsoft
2010-04-26 22:26:10 ----A---- D:\WINDOWS\SchedLgU.Txt
2010-04-26 22:23:10 ----N---- D:\WINDOWS\system32\spmsg.dll
2010-04-26 22:23:09 ----HDC---- D:\WINDOWS\$NtUninstallMSCompPackV1$
2010-04-26 22:22:58 ----A---- D:\WINDOWS\system32\wmpns.dll
2010-04-26 22:22:54 ----D---- D:\Program Files\Windows Media Connect 2
2010-04-26 22:22:09 ----D---- D:\WINDOWS\system32\LogFiles
2010-04-26 22:22:06 ----HDC---- D:\WINDOWS\$NtUninstallWudf01000$
2010-04-26 22:20:56 ----D---- D:\Program Files\Kristanix
2010-04-26 22:20:48 ----D---- D:\Program Files\Stardock
2010-04-26 22:20:12 ----D---- D:\Program Files\Sysinternals
2010-04-26 22:19:29 ----D---- D:\Program Files\Mozilla Firefox
2010-04-26 22:19:18 ----D---- D:\Program Files\CCleaner
2010-04-26 22:16:25 ----D---- D:\WINDOWS\system32\XPSViewer
2010-04-26 22:16:25 ----D---- D:\Program Files\MSBuild
2010-04-26 22:16:22 ----D---- D:\Program Files\Reference Assemblies
2010-04-26 22:16:13 ----N---- D:\WINDOWS\system32\spmsg2.dll
2010-04-26 22:16:13 ----A---- D:\WINDOWS\system32\spupdsvc.exe
2010-04-26 22:14:01 ----RSD---- D:\WINDOWS\assembly
2010-04-26 22:14:01 ----D---- D:\WINDOWS\Microsoft.NET
2010-04-26 22:14:00 ----D---- D:\WINDOWS\system32\URTTemp
2010-04-26 22:13:54 ----A---- D:\WINDOWS\system32\xpssvcs.dll
2010-04-26 22:13:54 ----A---- D:\WINDOWS\system32\xpsshhdr.dll
2010-04-26 22:13:42 ----A---- D:\WINDOWS\system32\prntvpt.dll
2010-04-26 22:12:28 ----A---- D:\WINDOWS\control.ini
2010-04-26 22:12:06 ----D---- D:\WINDOWS\system32\dllcache
2010-04-26 22:12:06 ----A---- D:\WINDOWS\system32\mapi32.dll
2010-04-26 22:11:15 ----RAH---- D:\WINDOWS\system32\logonui.exe.manifest
2010-04-26 22:11:10 ----RAH---- D:\WINDOWS\system32\cdplayer.exe.manifest
2010-04-26 22:11:05 ----HD---- D:\Program Files\WindowsUpdate
2010-04-26 22:11:00 ----D---- D:\Program Files\Online Services
2010-04-26 22:10:41 ----A---- D:\WINDOWS\system32\desktop.ini
2010-04-26 22:10:41 ----A---- D:\WINDOWS\system32\atrace.dll
2010-04-26 22:10:41 ----A---- D:\WINDOWS\desktop.ini
2010-04-26 22:10:36 ----A---- D:\WINDOWS\system32\acctres.dll
2010-04-26 22:10:35 ----D---- D:\Program Files\Common Files\Services
2010-04-26 22:10:32 ----SD---- D:\WINDOWS\Tasks
2010-04-26 22:10:32 ----A---- D:\WINDOWS\system32\icfgnt5.dll
2010-04-26 22:10:31 ----D---- D:\Program Files\Common Files\MSSoap
2010-04-26 22:10:25 ----D---- D:\WINDOWS\srchasst
2010-04-26 22:10:24 ----D---- D:\WINDOWS\system32\Macromed
2010-04-26 22:10:21 ----A---- D:\WINDOWS\system32\wuweb.dll
2010-04-26 22:10:21 ----A---- D:\WINDOWS\system32\wups.dll
2010-04-26 22:10:21 ----A---- D:\WINDOWS\system32\wucltui.dll
2010-04-26 22:10:21 ----A---- D:\WINDOWS\system32\wuauserv.dll
2010-04-26 22:10:21 ----A---- D:\WINDOWS\system32\wuaueng1.dll
2010-04-26 22:10:21 ----A---- D:\WINDOWS\system32\wuaueng.dll
2010-04-26 22:10:20 ----A---- D:\WINDOWS\system32\wuauclt1.exe
2010-04-26 22:10:20 ----A---- D:\WINDOWS\system32\wuauclt.exe
2010-04-26 22:10:20 ----A---- D:\WINDOWS\system32\wuapi.dll
2010-04-26 22:10:20 ----A---- D:\WINDOWS\system32\qmgrprxy.dll
2010-04-26 22:10:20 ----A---- D:\WINDOWS\system32\bitsprx4.dll
2010-04-26 22:10:20 ----A---- D:\WINDOWS\system32\bitsprx3.dll
2010-04-26 22:10:20 ----A---- D:\WINDOWS\system32\bitsprx2.dll
2010-04-26 22:10:19 ----A---- D:\WINDOWS\system32\qmgr.dll
2010-04-26 22:09:54 ----A---- D:\WINDOWS\system32\safrslv.dll
2010-04-26 22:09:54 ----A---- D:\WINDOWS\system32\safrdm.dll
2010-04-26 22:09:54 ----A---- D:\WINDOWS\system32\safrcdlg.dll
2010-04-26 22:09:54 ----A---- D:\WINDOWS\system32\racpldlg.dll
2010-04-26 22:09:49 ----A---- D:\WINDOWS\system32\fltMc.exe
2010-04-26 22:09:49 ----A---- D:\WINDOWS\system32\fltlib.dll
2010-04-26 22:09:48 ----D---- D:\WINDOWS\system32\Restore
2010-04-26 22:09:48 ----A---- D:\WINDOWS\system32\srsvc.dll
2010-04-26 22:09:48 ----A---- D:\WINDOWS\system32\srrstr.dll
2010-04-26 22:09:48 ----A---- D:\WINDOWS\system32\srclient.dll
2010-04-26 22:09:47 ----A---- D:\WINDOWS\system32\msoert2.dll
2010-04-26 22:09:47 ----A---- D:\WINDOWS\system32\msoeacct.dll
2010-04-26 22:09:45 ----A---- D:\WINDOWS\system32\inetres.dll
2010-04-26 22:09:45 ----A---- D:\WINDOWS\system32\inetcomm.dll
2010-04-26 22:09:42 ----D---- D:\Program Files\Outlook Express
2010-04-26 22:09:42 ----A---- D:\WINDOWS\system32\schedsvc.dll
2010-04-26 22:09:42 ----A---- D:\WINDOWS\system32\mstinit.exe
2010-04-26 22:09:42 ----A---- D:\WINDOWS\system32\mstask.dll
2010-04-26 22:09:41 ----A---- D:\WINDOWS\system32\isign32.dll
2010-04-26 22:09:41 ----A---- D:\WINDOWS\system32\inetcfg.dll
2010-04-26 22:09:41 ----A---- D:\WINDOWS\system32\icwphbk.dll
2010-04-26 22:09:41 ----A---- D:\WINDOWS\system32\icwdial.dll
2010-04-26 22:09:33 ----D---- D:\Program Files\Common Files\System
2010-04-26 22:08:48 ----D---- D:\Program Files\ComPlus Applications
2010-04-26 22:08:46 ----A---- D:\WINDOWS\vbaddin.ini
2010-04-26 22:08:46 ----A---- D:\WINDOWS\vb.ini
2010-04-26 22:08:41 ----D---- D:\WINDOWS\Registration
2010-04-26 22:08:32 ----D---- D:\Program Files\Windows Media Player
2010-04-26 22:08:23 ----A---- D:\WINDOWS\system32\advpack.dll.mui
2010-04-26 22:08:20 ----RD---- D:\WINDOWS\Offline Web Pages
2010-04-26 22:08:20 ----A---- D:\WINDOWS\system32\winfxdocobj.exe
2010-04-26 22:08:19 ----SD---- D:\WINDOWS\Downloaded Program Files
2010-04-26 22:08:18 ----D---- D:\WINDOWS\wbem
2010-04-26 22:08:18 ----A---- D:\WINDOWS\system32\msfeedssync.exe
2010-04-26 22:08:18 ----A---- D:\WINDOWS\system32\msfeedsbs.dll
2010-04-26 22:08:16 ----A---- D:\WINDOWS\system32\ieframe.dll.mui
2010-04-26 22:08:13 ----D---- D:\Program Files\Internet Explorer
2010-04-26 22:03:36 ----D---- D:\Program Files\LClock
2010-04-26 22:03:25 ----D---- D:\Program Files\Styler
2010-04-26 22:03:04 ----A---- D:\WINDOWS\system32\msvcr80.dll
2010-04-26 22:03:04 ----A---- D:\WINDOWS\system32\engine.dll
2010-04-26 22:02:04 ----D---- D:\Program Files\WinRAR
2010-04-26 22:01:58 ----A---- D:\WINDOWS\system32\WhyReboot.exe
2010-04-26 22:01:58 ----A---- D:\WINDOWS\system32\WC.com
2010-04-26 22:01:58 ----A---- D:\WINDOWS\system32\WallChan.exe
2010-04-26 22:01:57 ----A---- D:\WINDOWS\system32\UpxGui.exe
2010-04-26 22:01:55 ----A---- D:\WINDOWS\system32\Replacer.cmd
2010-04-26 22:01:55 ----A---- D:\WINDOWS\system32\Reg2InfHandler.cmd
2010-04-26 22:01:55 ----A---- D:\WINDOWS\system32\Reg2Inf.exe
2010-04-26 22:01:54 ----A---- D:\WINDOWS\system32\Refresh.exe
2010-04-26 22:01:54 ----A---- D:\WINDOWS\system32\PCalc.exe
2010-04-26 22:01:54 ----A---- D:\WINDOWS\system32\Notepad2_License.txt
2010-04-26 22:01:54 ----A---- D:\WINDOWS\system32\Notepad2.txt
2010-04-26 22:01:54 ----A---- D:\WINDOWS\system32\Notepad2.ini
2010-04-26 22:01:53 ----A---- D:\WINDOWS\system32\Notepad2.exe
2010-04-26 22:01:53 ----A---- D:\WINDOWS\system32\modifyPE.exe
2010-04-26 22:01:52 ----A---- D:\WINDOWS\system32\metapath.exe
2010-04-26 22:01:51 ----A---- D:\WINDOWS\system32\RegFileMerger.exe
2010-04-26 22:01:51 ----A---- D:\WINDOWS\system32\makeiso.cmd
2010-04-26 22:01:51 ----A---- D:\WINDOWS\system32\LCISOCreator.exe
2010-04-26 22:01:50 ----A---- D:\WINDOWS\system32\HFExtract.exe
2010-04-26 22:01:49 ----D---- D:\Program Files\TaskSwitchXP
2010-04-26 22:01:49 ----A---- D:\WINDOWS\system32\FGCBAHandler.exe
2010-04-26 22:01:49 ----A---- D:\WINDOWS\system32\FGCBA.exe
2010-04-26 22:01:49 ----A---- D:\WINDOWS\system32\EXPander.exe
2010-04-26 22:01:48 ----D---- D:\Program Files\Unlocker
2010-04-26 22:01:48 ----A---- D:\WINDOWS\system32\cdimage.exe
2010-04-26 22:01:48 ----A---- D:\WINDOWS\system32\Cabtool.exe
2010-04-26 22:01:48 ----A---- D:\WINDOWS\system32\Cabarc.exe
2010-04-26 22:01:47 ----D---- D:\Program Files\Utilities
2010-04-26 22:01:47 ----D---- D:\Program Files\Attribute Changer
2010-04-26 22:01:34 ----A---- D:\WINDOWS\system32\write.exe
2010-04-26 22:01:33 ----A---- D:\WINDOWS\system32\sndvol32.exe
2010-04-26 22:01:33 ----A---- D:\WINDOWS\system32\hticons.dll
2010-04-26 22:01:33 ----A---- D:\WINDOWS\system32\avwav.dll
2010-04-26 22:01:33 ----A---- D:\WINDOWS\system32\avtapi.dll
2010-04-26 22:01:33 ----A---- D:\WINDOWS\system32\avmeter.dll
2010-04-26 22:01:32 ----A---- D:\WINDOWS\system32\winchat.exe
2010-04-26 22:01:29 ----A---- D:\WINDOWS\system32\charmap.exe
2010-04-26 22:01:29 ----A---- D:\WINDOWS\system32\getuname.dll
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\usrlogon.cmd
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\tsshutdn.exe
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\tslabels.ini
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\tskill.exe
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\tsdiscon.exe
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\tscon.exe
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\shadow.exe
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\rwinsta.exe
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\reset.exe
2010-04-26 22:01:28 ----A---- D:\WINDOWS\system32\calc.exe
2010-04-26 22:01:27 ----A---- D:\WINDOWS\system32\regini.exe
2010-04-26 22:01:27 ----A---- D:\WINDOWS\system32\rdpcfgex.dll
2010-04-26 22:01:27 ----A---- D:\WINDOWS\system32\qwinsta.exe
2010-04-26 22:01:27 ----A---- D:\WINDOWS\system32\qappsrv.exe
2010-04-26 22:01:27 ----A---- D:\WINDOWS\system32\msg.exe
2010-04-26 22:01:27 ----A---- D:\WINDOWS\system32\logoff.exe
2010-04-26 22:01:27 ----A---- D:\WINDOWS\system32\cdmodem.dll
2010-04-26 22:01:26 ----A---- D:\WINDOWS\system32\msdtcprf.ini
2010-04-26 22:01:19 ----A---- D:\WINDOWS\system32\wmimgmt.msc
2010-04-26 22:01:18 ----A---- D:\WINDOWS\system32\mplay32.exe
2010-04-26 22:01:18 ----A---- D:\WINDOWS\system32\hypertrm.dll
2010-04-26 22:01:18 ----A---- D:\WINDOWS\system32\accwiz.exe
2010-04-26 22:01:17 ----D---- D:\Program Files\Windows NT
2010-04-26 22:01:17 ----A---- D:\WINDOWS\system32\mspaint.exe
2010-04-26 22:01:17 ----A---- D:\WINDOWS\system32\clipbrd.exe
2010-04-26 22:01:16 ----D---- D:\WINDOWS\system32\en-US
2010-04-26 22:01:15 ----A---- D:\WINDOWS\system32\tsgqec.dll
2010-04-26 22:01:15 ----A---- D:\WINDOWS\system32\tscfgwmi.dll
2010-04-26 22:01:15 ----A---- D:\WINDOWS\system32\rhttpaa.dll
2010-04-26 22:01:15 ----A---- D:\WINDOWS\system32\aaclient.dll
2010-04-26 22:01:14 ----A---- D:\WINDOWS\system32\mstscax.dll
2010-04-26 22:01:14 ----A---- D:\WINDOWS\system32\mstsc.exe
2010-04-26 22:01:13 ----A---- D:\WINDOWS\system32\sessmgr.exe
2010-04-26 22:01:13 ----A---- D:\WINDOWS\system32\remotepg.dll
2010-04-26 22:01:13 ----A---- D:\WINDOWS\system32\rdshost.exe
2010-04-26 22:01:13 ----A---- D:\WINDOWS\system32\rdsaddin.exe
2010-04-26 22:01:13 ----A---- D:\WINDOWS\system32\rdchost.dll
2010-04-26 22:01:12 ----D---- D:\WINDOWS\system32\MsDtc
2010-04-26 22:01:12 ----A---- D:\WINDOWS\system32\termsrv.dll
2010-04-26 22:01:12 ----A---- D:\WINDOWS\system32\rdpwsx.dll
2010-04-26 22:01:12 ----A---- D:\WINDOWS\system32\rdpsnd.dll
2010-04-26 22:01:12 ----A---- D:\WINDOWS\system32\rdpclip.exe
2010-04-26 22:01:12 ----A---- D:\WINDOWS\system32\qprocess.exe
2010-04-26 22:01:12 ----A---- D:\WINDOWS\system32\msdtcuiu.dll
2010-04-26 22:01:12 ----A---- D:\WINDOWS\system32\icaapi.dll
2010-04-26 22:01:12 ----A---- D:\WINDOWS\system32\cfgbkend.dll
2010-04-26 22:01:11 ----A---- D:\WINDOWS\system32\xolehlp.dll
2010-04-26 22:01:11 ----A---- D:\WINDOWS\system32\mtxoci.dll
2010-04-26 22:01:11 ----A---- D:\WINDOWS\system32\msdtctm.dll
2010-04-26 22:01:11 ----A---- D:\WINDOWS\system32\msdtcprx.dll
2010-04-26 22:01:10 ----A---- D:\WINDOWS\system32\msdtclog.dll
2010-04-26 22:01:10 ----A---- D:\WINDOWS\system32\msdtc.exe
2010-04-26 22:01:10 ----A---- D:\WINDOWS\system32\dcomcnfg.exe
2010-04-26 22:01:09 ----D---- D:\WINDOWS\system32\Com
2010-04-26 22:01:09 ----A---- D:\WINDOWS\system32\stclient.dll
2010-04-26 22:01:09 ----A---- D:\WINDOWS\system32\mtxlegih.dll
2010-04-26 22:01:09 ----A---- D:\WINDOWS\system32\mtxex.dll
2010-04-26 22:01:09 ----A---- D:\WINDOWS\system32\mtxdm.dll
2010-04-26 22:01:09 ----A---- D:\WINDOWS\system32\comrepl.dll
2010-04-26 22:01:09 ----A---- D:\WINDOWS\system32\comaddin.dll
2010-04-26 22:01:09 ----A---- D:\WINDOWS\system32\colbact.dll
2010-04-26 22:01:08 ----A---- D:\WINDOWS\system32\clbcatex.dll
2010-04-26 22:01:08 ----A---- D:\WINDOWS\system32\catsrvut.dll
2010-04-26 22:01:08 ----A---- D:\WINDOWS\system32\catsrvps.dll
2010-04-26 22:01:08 ----A---- D:\WINDOWS\system32\catsrv.dll
2010-04-26 22:01:07 ----A---- D:\WINDOWS\system32\comuid.dll
2010-04-26 22:01:07 ----A---- D:\WINDOWS\system32\comsvcs.dll
2010-04-26 22:01:07 ----A---- D:\WINDOWS\system32\comsnap.dll
2010-04-26 22:01:07 ----A---- D:\WINDOWS\system32\clbcatq.dll
2010-04-26 22:00:58 ----A---- D:\WINDOWS\system32\servdeps.dll
2010-04-26 22:00:58 ----A---- D:\WINDOWS\system32\mmfutil.dll
2010-04-26 22:00:58 ----A---- D:\WINDOWS\system32\licwmi.dll
2010-04-26 22:00:58 ----A---- D:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2010-05-03 16:53:01 ----A---- D:\WINDOWS\win.ini
2010-05-03 16:53:01 ----A---- D:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\D:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; D:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 ssmdrv;ssmdrv; D:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; D:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-04-26 21361]
R2 avgntflt;avgntflt; D:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R3 ati2mtag;ati2mtag; D:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-10-27 2881536]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; D:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-03-21 13952]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-03-21 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-04-06 5912096]
R3 RTL8187B;Sieťový adaptér bezdrôtového pripojenia RTL8187B Wireless 802.11b/g 54Mbps USB 2.0; D:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2009-04-16 340736]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\D:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-03-21 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-03-21 30208]
R3 usbhub;USB2 Enabled Hub; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-03-21 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; D:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-03-21 17152]
R3 usbvideo;USB Video Device (WDM); D:\WINDOWS\System32\Drivers\usbvideo.sys [2008-03-21 121984]
S3 Ambfilt;Ambfilt; D:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 CCDECODE;Closed Caption Decoder; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-03-21 17024]
S3 Monfilt;Monfilt; D:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2008-03-21 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-03-21 85248]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-03-21 10880]
S3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; D:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2010-03-08 220112]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-03-21 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-03-21 15232]
S3 USBSTOR;USB Mass Storage Driver; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-03-21 26368]
S3 WSTCODEC;World Standard Teletext Codec; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-03-21 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; D:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\system32\Ati2evxx.exe [2008-10-27 540672]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2010-05-01 153376]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; D:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-04-19 1050440]
R2 UxTuneUp;TuneUp Theme Extension; D:\WINDOWS\System32\svchost.exe [2008-03-21 14336]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; d:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; D:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-04-29 435016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2008-03-21 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


//Edit : Avira mi furt hlasi malware na C/System dačo Information.........no ked dam preskenovať cečko tak nič mi nenajde

Uživatelský avatar
1danab
Nováček
Nováček
Příspěvky: 1412
Registrován: 21 říj 2007 13:04
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: RSIT log

#2 Příspěvek od 1danab »

zdravím :)
na Vašem logu se pracuje
RSIT CureIt CCleaner CleanUp DDS GMER OTL
POKUD JSTE S NAŠÍM FÓREM SPOKOJENI, MŮŽETE HO PODPOŘIT ZDE Obrázek

Mějte vždy zazálohovaná všechna důležitá data !


Obrázek

Uživatelský avatar
1danab
Nováček
Nováček
Příspěvky: 1412
Registrován: 21 říj 2007 13:04
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: RSIT log

#3 Příspěvek od 1danab »

otestujte na VIRUSTOTALu

D:\WINDOWS\system32\xpsp4res.dll

a další úkol
stahnete GMER , rozbalte a spustte

probehne sken, po jehoz ukonceni na vas bafnou vysledky

pote kliknete na Save a ulozite tak log, jehoz obsah sem vlozte

pote dle tohoto navodu absolvujte druhy sken a opet obsah logu sem
RSIT CureIt CCleaner CleanUp DDS GMER OTL
POKUD JSTE S NAŠÍM FÓREM SPOKOJENI, MŮŽETE HO PODPOŘIT ZDE Obrázek

Mějte vždy zazálohovaná všechna důležitá data !


Obrázek

deny95
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 lis 2008 09:11

Re: RSIT log

#4 Příspěvek od deny95 »


Uživatelský avatar
1danab
Nováček
Nováček
Příspěvky: 1412
Registrován: 21 říj 2007 13:04
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: RSIT log

#5 Příspěvek od 1danab »

klikněte na otestovat soubor znovu...je tam stará analýza
RSIT CureIt CCleaner CleanUp DDS GMER OTL
POKUD JSTE S NAŠÍM FÓREM SPOKOJENI, MŮŽETE HO PODPOŘIT ZDE Obrázek

Mějte vždy zazálohovaná všechna důležitá data !


Obrázek

Odpovědět