Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu - Blue screen hpfile.sys

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Prosim o kontrolu - Blue screen hpfile.sys

#1 Příspěvek od BOnioo1775 »

Prosim o kontrolu a pomoc s odvirovanim ,na pc nahodne vyskakuje bsod,nekdy se neukaze a jen tak se restartuje pocitac ,ale z logu vychazi ze ho zapricinil proces hpfile.sys. Pravdepodobne je z noveho softwaru ,ktery jsem nainstaloval pro monitorovani cinnosti na PC - Hlídací Pes. ALe to neni vse,mam pocit ,ze to není jen to

Zde je log z CF:
ComboFix 10-08-27.03 - Butterfly 2010-08-28 19:40:26.11.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1029.18.1022.705 [GMT 2:00]
Spuštěný z: c:\documents and settings\Butterfly\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-07-28 do 2010-08-28 )))))))))))))))))))))))))))))))
.

2010-08-28 17:35 . 2010-08-28 17:35 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-08-28 16:50 . 2010-08-28 16:50 -------- d-----w- c:\documents and settings\Butterfly\DoctorWeb
2010-08-28 16:29 . 2010-08-28 16:39 -------- d-----w- C:\SFOCWXGI
2010-08-28 14:09 . 2010-08-28 17:31 -------- d-----w- C:\BDYGBOUQ
2010-08-27 22:03 . 2010-08-27 22:03 -------- d-----w- C:\pear
2010-08-27 21:33 . 2010-08-27 22:00 -------- d-----w- C:\PROTOKOL
2010-08-27 21:33 . 2010-08-27 21:33 -------- d-----w- C:\SKRYTY
2010-08-27 21:33 . 2010-08-28 16:29 57344 ----a-w- c:\windows\system32\wmsprog.dll
2010-08-27 21:33 . 2010-08-28 16:29 53248 ----a-w- c:\windows\system32\wshxt.dll
2010-08-27 21:33 . 2010-08-28 16:29 131072 ----a-w- c:\windows\system32\kernell.dll
2010-08-27 21:33 . 2010-08-28 10:58 -------- d-----w- C:\QWDVXMPO
2010-08-27 21:21 . 2010-08-27 21:22 -------- d-----w- c:\program files\Hide My IP
2010-08-27 18:51 . 2010-08-28 17:40 -------- d-----w- c:\windows\system32\CatRoot2
2010-08-27 16:31 . 2010-08-27 16:36 -------- d-----w- C:\Hotspot Shield
2010-08-27 16:28 . 2010-08-27 16:28 -------- d-----w- c:\program files\Secunia
2010-08-27 14:53 . 2010-08-27 14:53 -------- d-----w- c:\windows\XSxS
2010-08-27 11:23 . 2010-08-27 11:24 -------- d-----w- C:\Shoty
2010-08-27 11:23 . 2010-08-27 11:23 -------- d-----w- c:\program files\ScreenShots
2010-08-27 07:35 . 2010-08-27 07:35 -------- d-----w- c:\program files\Two Pilots
2010-08-27 07:35 . 2010-08-27 07:35 -------- d-----w- c:\program files\Cosmetic Guide
2010-08-26 20:13 . 2004-03-29 14:23 90112 ----a-w- c:\windows\unvise32.exe
2010-08-26 20:11 . 2010-08-26 20:11 -------- d-----w- c:\program files\MAXON
2010-08-25 10:10 . 2010-08-25 10:10 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-08-23 18:07 . 2010-08-23 18:09 -------- d-----w- c:\program files\Elecard
2010-08-23 16:30 . 2010-08-23 16:30 -------- d-----w- c:\windows\system32\Adobe
2010-08-23 11:11 . 2010-08-23 11:11 -------- d-----w- c:\program files\Common Files\Java
2010-08-23 08:56 . 2003-03-31 05:00 138752 ----a-w- c:\windows\sndvol32.exe
2010-08-23 08:39 . 2010-08-23 08:39 -------- d-----w- c:\windows\system32\wbem\Repository
2010-08-23 08:38 . 2010-08-23 08:38 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-08-23 08:36 . 2010-08-23 08:36 -------- d-----w- C:\PFiles
2010-08-22 20:21 . 2010-08-23 08:37 -------- d-----w- c:\program files\Common Files\Java(3)
2010-08-22 14:49 . 2010-08-23 08:38 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-08-22 14:33 . 2010-08-22 14:33 2999 ----a-w- c:\program files\Common Files\unins000.dat
2010-08-22 13:16 . 2010-08-22 13:16 55572 ---ha-w- c:\windows\system32\mlfcache.dat
2010-08-22 10:33 . 2010-08-22 10:33 -------- d-----w- c:\program files\Common Files\Futuremark Shared
2010-08-22 10:06 . 2010-08-22 10:06 0 ----a-w- c:\windows\ativpsrm.bin
2010-08-19 20:12 . 2010-08-19 20:12 -------- d-----w- C:\VritualRoot
2010-08-19 19:14 . 2010-08-19 19:29 -------- d-----w- c:\program files\Sunbelt Software
2010-08-19 17:54 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-19 17:50 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-19 17:50 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-19 17:50 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-19 17:50 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-19 17:50 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-19 17:50 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-19 17:50 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-19 17:49 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-19 17:47 . 2010-08-19 17:49 -------- d-----w- c:\program files\Alwil Software
2010-08-19 12:51 . 2010-07-27 11:54 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-08-18 14:13 . 2010-08-18 14:13 -------- d-----w- C:\ATI
2010-08-18 13:00 . 2010-08-26 16:12 -------- d-----w- c:\program files\ATI
2010-08-18 12:39 . 2010-08-26 16:14 -------- d-----w- c:\program files\ATI Technologies
2010-08-15 10:50 . 2010-08-18 12:12 -------- d-----w- c:\program files\NVIDIA Corporation
2010-08-07 08:19 . 2009-06-16 17:28 46592 ----a-w- c:\windows\system32\drivers\fetnd5bv.sys
2010-08-07 08:19 . 2006-11-02 06:21 319456 ----a-w- c:\windows\system32\difxapi.dll
2010-08-07 08:19 . 2006-10-27 15:26 69632 ----a-w- c:\windows\system32\vuins32.dll
2010-08-06 21:55 . 2010-08-06 22:00 217 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2010-08-05 07:14 . 2010-08-05 07:15 -------- d-----w- c:\windows\NV35361800.TMP
2010-08-04 08:12 . 2010-08-04 08:12 -------- d-----w- c:\windows\NV23721612.TMP
2010-08-01 12:53 . 2010-08-01 13:00 -------- d-----w- c:\windows\NV33763424.TMP
2010-08-01 11:58 . 2010-08-01 11:58 -------- d-----w- c:\windows\NV40402576.TMP
2010-07-30 21:04 . 2006-06-20 08:56 225280 ----a-w- c:\windows\system32\rewire.dll
2010-07-30 20:58 . 2010-07-30 21:49 -------- d-----w- c:\program files\Image-Line
2010-07-30 16:16 . 2010-07-30 16:18 -------- d-----w- c:\program files\Sony
2010-07-30 16:12 . 2010-07-30 16:12 -------- d-----w- c:\program files\Sony Setup

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-28 16:43 . 2010-03-08 11:38 -------- d-----w- c:\program files\Steam
2010-08-28 12:01 . 2010-02-11 16:04 -------- d-----w- c:\program files\Debugging Tools for Windows (x86)
2010-08-26 14:02 . 2010-02-19 15:16 -------- d-----w- c:\program files\AIMP2
2010-08-26 09:19 . 2010-02-10 22:42 -------- d-----w- c:\program files\CCleaner
2010-08-26 08:23 . 2010-07-17 17:53 -------- d-----w- c:\program files\Mozilla Firefox 4.0 Beta 1
2010-08-25 20:28 . 2010-04-09 16:40 -------- d-----w- c:\program files\WhoCrashed
2010-08-25 11:46 . 2010-03-01 20:31 -------- d-----w- c:\program files\SystemRequirementsLab
2010-08-23 11:10 . 2010-04-24 08:02 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-23 10:24 . 2010-04-24 08:05 -------- d-----w- c:\program files\DivX
2010-08-23 09:16 . 2010-08-23 09:16 4764 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2010-08-22 10:33 . 2010-02-09 21:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-19 19:47 . 2010-02-12 21:12 -------- d-----w- c:\program files\Google
2010-08-19 19:35 . 2010-07-01 09:01 -------- d-----w- c:\program files\QuickTime
2010-08-19 12:52 . 2010-08-19 12:52 -------- d-----w- c:\program files\Realtek
2010-08-19 09:01 . 2010-06-06 07:45 -------- d-----w- c:\program files\Defraggler
2010-08-19 08:58 . 2010-07-04 12:24 -------- d-----w- c:\program files\FileHippo.com
2010-08-18 21:09 . 2010-03-04 21:09 -------- d-----w- c:\program files\Samsung
2010-08-18 20:31 . 2010-02-12 04:39 -------- d-----w- c:\program files\Opera
2010-08-07 15:13 . 2010-03-27 20:28 -------- d-----w- c:\program files\Trillian
2010-08-06 22:00 . 2010-02-17 18:37 133520 ----a-w- c:\windows\BricoPackUninst.cmd
2010-08-04 02:20 . 2010-04-11 19:18 5243392 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-08-04 01:59 . 2010-08-18 14:14 53248 ----a-w- c:\windows\system32\aticalrt.dll
2010-08-04 01:59 . 2010-08-18 14:14 53248 ----a-w- c:\windows\system32\aticalcl.dll
2010-08-04 01:57 . 2010-08-18 14:14 4358144 ----a-w- c:\windows\system32\aticaldd.dll
2010-08-04 01:53 . 2010-08-18 14:14 15900672 ----a-w- c:\windows\system32\atioglxx.dll
2010-08-04 01:47 . 2010-08-18 14:14 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-08-04 01:47 . 2010-08-18 14:14 450560 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-08-04 01:46 . 2010-04-11 19:23 300544 ----a-w- c:\windows\system32\ati2dvag.dll
2010-08-04 01:41 . 2010-04-11 19:23 3901280 ----a-w- c:\windows\system32\ati3duag.dll
2010-08-04 01:31 . 2010-08-18 14:14 208896 ----a-w- c:\windows\system32\atipdlxx.dll
2010-08-04 01:31 . 2010-08-18 14:14 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-08-04 01:30 . 2010-08-18 14:14 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-08-04 01:30 . 2010-08-18 14:14 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-08-04 01:30 . 2010-08-18 14:14 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-08-04 01:29 . 2010-08-18 14:14 606208 ----a-w- c:\windows\system32\ati2evxx.exe
2010-08-04 01:28 . 2010-08-18 14:14 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-08-04 01:28 . 2010-04-11 19:23 2537728 ----a-w- c:\windows\system32\ativvaxx.dll
2010-08-04 01:27 . 2010-08-18 14:14 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-08-04 01:27 . 2010-08-18 14:14 3 ----a-w- c:\windows\system32\ativva5x.dat
2010-08-04 01:27 . 2010-08-18 14:14 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-08-04 01:24 . 2010-08-18 14:14 610304 ----a-w- c:\windows\system32\atikvmag.dll
2010-08-04 01:23 . 2010-08-18 14:14 393216 ----a-w- c:\windows\system32\atiok3x2.dll
2010-08-04 01:22 . 2010-08-18 14:14 188416 ----a-w- c:\windows\system32\atiadlxx.dll
2010-08-04 01:22 . 2010-08-18 14:14 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-08-04 01:16 . 2010-04-11 19:23 700416 ----a-w- c:\windows\system32\ati2cqag.dll
2010-08-04 01:15 . 2010-08-18 14:14 65024 ----a-w- c:\windows\system32\atimpc32.dll
2010-08-04 01:15 . 2010-08-18 14:14 65024 ----a-w- c:\windows\system32\amdpcom32.dll
2010-08-04 01:14 . 2010-08-18 14:14 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-08-02 09:54 . 2010-06-13 09:04 -------- d-----w- c:\program files\Safari
2010-07-29 18:29 . 2010-02-27 09:18 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-07-28 19:50 . 2010-03-04 16:17 86016 ----a-w- c:\windows\system32\OpenAL32.dll
2010-07-28 19:50 . 2010-03-04 16:17 262144 ----a-w- c:\windows\system32\wrap_oal.dll
2010-07-28 19:47 . 2010-07-28 19:47 -------- d-----w- c:\program files\Futuremark
2010-07-27 21:21 . 2010-07-27 21:21 -------- d-----w- c:\program files\Zoner
2010-07-25 09:18 . 2010-07-25 09:18 -------- d-----w- c:\program files\GIMP-2.0
2010-07-24 20:08 . 2010-07-24 17:17 -------- d-----w- c:\program files\Yahoo!
2010-07-22 20:01 . 2010-02-12 21:53 -------- d-----w- c:\program files\QIP
2010-07-22 08:03 . 2010-07-22 08:03 -------- d-----w- c:\program files\Microsoft Fix it Center
2010-07-21 09:03 . 2010-02-28 21:24 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-07-17 17:38 . 2010-07-10 09:16 -------- d-----w- c:\program files\Mozilla Firefox 4.0 Beta 1(2)
2010-07-17 17:38 . 2010-07-10 09:24 -------- d-----w- c:\program files\Common Files\Java(2)
2010-07-17 17:37 . 2010-07-17 17:37 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-07-17 17:34 . 2010-07-17 17:34 -------- d-----w- c:\program files\All Ten Fingers
2010-07-17 17:34 . 2010-07-15 17:58 -------- d-----w- c:\program files\All Ten Fingers(2)
2010-07-15 14:36 . 2010-04-12 18:53 -------- d-----w- c:\program files\Valve
2010-07-09 22:38 . 2010-08-15 13:29 10604128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys-nv1245
2010-07-09 11:18 . 2010-02-12 21:17 -------- d-----w- c:\program files\Common Files\CyberLink
2010-07-09 11:17 . 2010-03-20 11:58 -------- d-----w- c:\program files\IObit
2010-07-06 11:58 . 2010-02-27 09:19 30528 ----a-w- c:\windows\system32\TURegOpt.exe
2010-07-06 11:52 . 2010-07-17 20:21 30016 ----a-w- c:\windows\system32\uxtuneup.dll
2010-07-04 21:18 . 2010-07-01 10:25 -------- d-----w- c:\program files\Trend Micro
2010-07-04 13:01 . 2010-02-16 20:34 -------- d-----w- c:\program files\7-Zip
2010-07-04 12:40 . 2010-02-20 09:19 -------- d-----w- c:\program files\Windows Media Connect 2
2010-07-04 12:33 . 2010-07-04 12:33 -------- d-----r- c:\program files\Skype
2010-07-04 12:33 . 2010-07-04 12:33 -------- d-----w- c:\program files\Common Files\Skype
2010-07-02 20:25 . 2010-06-07 18:39 -------- d-----w- c:\program files\WinUtilities
2010-07-02 20:08 . 2010-07-02 20:08 -------- d-----w- c:\program files\FreeTime
2010-07-01 08:49 . 2010-02-12 13:43 -------- d-----w- c:\program files\MSECache
2010-07-01 08:39 . 2010-06-17 14:05 -------- d-----w- c:\program files\Opera 10.60 Beta
2010-06-30 12:33 . 2010-03-21 11:47 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-28 17:25 . 2010-02-24 16:13 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-06-24 12:27 . 2004-08-17 13:49 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2010-03-21 11:47 1851904 ----a-w- c:\windows\system32\win32old.sys
2010-06-24 09:02 . 2009-08-14 15:15 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-23 02:47 . 2010-06-23 02:47 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2010-06-21 15:27 . 2010-03-21 11:47 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-17 13:49 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-16 13:22 . 2010-08-18 14:14 219348 ----a-w- c:\windows\system32\atiicdxx.dat
2010-06-14 14:31 . 2010-02-09 21:13 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:43 . 2004-08-17 13:49 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-13 21:07 . 2010-06-13 21:07 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-06-08 16:10 . 2010-06-30 08:34 790528 ----a-w- c:\windows\system32\xvidcore.dll
2010-06-08 16:10 . 2010-06-30 08:34 134144 ----a-w- c:\windows\system32\xvidvfw.dll
2010-06-08 15:16 . 2010-02-14 08:00 52840 ----a-w- c:\windows\system32\RtkCoInstXP(6).dll
2010-06-08 15:16 . 2010-02-14 08:00 52840 ----a-w- c:\windows\system32\RtkCoInstXP(5).dll
2010-06-08 15:16 . 2010-02-14 08:00 52840 ----a-w- c:\windows\system32\RtkCoInstXP(4).dll
2010-06-08 15:16 . 2010-02-14 08:00 52840 ----a-w- c:\windows\system32\RtkCoInstXP(3).dll
2010-06-08 15:16 . 2010-02-14 08:00 52840 ----a-w- c:\windows\system32\RtkCoInstXP(2).dll
2010-06-07 23:57 . 2010-07-15 11:00 1359872 ----a-w- c:\windows\system32\nvapi(16).dll
2010-06-07 23:57 . 2010-07-15 11:00 1359872 ----a-w- c:\windows\system32\nvapi(15).dll
.

------- Sigcheck -------

[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0011\DriverFiles\i386\atapi.sys
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0137\DriverFiles\i386\atapi.sys
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys

[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\asyncmac.sys
[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys

[-] 2001-10-25 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
[-] 2001-10-25 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys

[-] 2008-04-14 . 1B6162FE7F66B1A71A4B70F941C4AA9B . 24576 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\kbdclass.sys
[-] 2008-04-14 . 1B6162FE7F66B1A71A4B70F941C4AA9B . 24576 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys
[-] 2008-04-14 . 1B6162FE7F66B1A71A4B70F941C4AA9B . 24576 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys

[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys
[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys

[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntfs.sys
[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys

[-] 2001-10-25 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys
[-] 2001-10-25 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys

[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys

[-] 2008-04-14 . 249276D3EF1E74B992299CB96099E4D7 . 77824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\browser.dll
[-] 2008-04-14 . 249276D3EF1E74B992299CB96099E4D7 . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll

[-] 2008-04-14 . ED0A176354487CEED65B80A7148AB739 . 13312 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe
[-] 2008-04-14 . ED0A176354487CEED65B80A7148AB739 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe

[-] 2008-04-14 . 72E1E9E2977BE08BDEEDB6D8FD9D4D40 . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
[-] 2008-04-14 . 72E1E9E2977BE08BDEEDB6D8FD9D4D40 . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll

[-] 2008-04-14 . 19395D092FD85DDC2D9C7729CF5A2AC8 . 409088 . . [6.7.2600.5512] . . c:\windows\ServicePackFiles\i386\qmgr.dll
[-] 2008-04-14 . 19395D092FD85DDC2D9C7729CF5A2AC8 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll
[-] 2008-04-14 . 19395D092FD85DDC2D9C7729CF5A2AC8 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\bits\qmgr.dll

[-] 2009-02-09 . C0BD34A62508BA68F146E22CE45919F9 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[-] 2009-02-09 . BE27674D1CBC3214AEC84B4336A38BBF . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\rpcss.dll
[-] 2009-02-09 . BE27674D1CBC3214AEC84B4336A38BBF . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll
[-] 2009-02-09 . BE27674D1CBC3214AEC84B4336A38BBF . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll
[-] 2009-02-09 . BEF7BB41E666EAA34BE7E99C2B107DB8 . 401408 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\rpcss.dll
[-] 2008-04-14 . C868F3AE15CF71A93F2AA3A32856D839 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll

[-] 2009-02-09 . 9EF697AF07BB8DD82C3B02CA953A95B7 . 111104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\services.exe
[-] 2009-02-09 . 9EF697AF07BB8DD82C3B02CA953A95B7 . 111104 . . [5.1.2600.5755] . . c:\windows\system32\services.exe
[-] 2009-02-09 . 9EF697AF07BB8DD82C3B02CA953A95B7 . 111104 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe
[-] 2009-02-09 . 3D107D45CCFDB266E91D84B52CD7F430 . 111104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2009-02-09 . 33081FED75032291EE0E008D5385E86F . 111104 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\services.exe
[-] 2008-04-14 . F0D2AE69035092BF22DAD6B50FAB85C2 . 108544 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\services.exe

[-] 2008-04-14 . CB1090BCA0E7B40D0B5B4E4D66531809 . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2008-04-14 . CB1090BCA0E7B40D0B5B4E4D66531809 . 57856 . . [5.1.2600.5512] . . c:\windows\system32\spoolsv.exe

[-] 2008-04-14 . CDDB1F8E1AEA356F3AD106F2CF9B7FEA . 507904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 . CDDB1F8E1AEA356F3AD106F2CF9B7FEA . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

[-] 2009-08-06 . A089AB141D4E25E543EEC2230CB50BD6 . 68832 . . [7.4.7600.226] . . c:\windows\ServicePackFiles\i386\wuauclt.exe
[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\system32\dllcache\wuauclt.exe

[-] 2008-04-14 . 4F993463DC5F3F80D77A3D34D7BFBFED . 617472 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-14 . 4F993463DC5F3F80D77A3D34D7BFBFED . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll

[-] 2008-04-14 . F3AB0933CBD166D271992F411C27CCAF . 62464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\cryptsvc.dll
[-] 2008-04-14 . F3AB0933CBD166D271992F411C27CCAF . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll

[-] 2008-07-07 20:29 . A371F11EF07653591C8DE26AFB13CE7F . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
[-] 2008-07-07 20:29 . A371F11EF07653591C8DE26AFB13CE7F . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll
[-] 2008-07-07 20:29 . A371F11EF07653591C8DE26AFB13CE7F . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[-] 2008-07-07 20:25 . BE68EA4457E2E5717231CF91BE5448E0 . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[-] 2008-07-07 20:19 . 3440C414044935B124B5821C0994B37F . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
[-] 2008-04-14 06:51 . 260C69FD67687B0DC062FC3D31655857 . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll

[-] 2008-04-14 . 6C60CA8AC7470AC01CFD3D24C7283CD1 . 110080 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\imm32.dll
[-] 2008-04-14 . 6C60CA8AC7470AC01CFD3D24C7283CD1 . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll

[-] 2009-03-21 . 545C653E8FE241CA6200798AA94FE5C7 . 988160 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3GDR\kernel32.dll
[-] 2009-03-21 . 545C653E8FE241CA6200798AA94FE5C7 . 988160 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll
[-] 2009-03-21 . 545C653E8FE241CA6200798AA94FE5C7 . 988160 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll
[-] 2009-03-21 . 0D8F61460F84139BBE5E391D8DE18D9A . 990208 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2009-03-21 . 8D18BA8E854890074B6FB92D7D0C02FA . 987648 . . [5.1.2600.3541] . . c:\windows\$hf_mig$\KB959426\SP2QFE\kernel32.dll
[-] 2008-04-14 . FD91CD95A1C663DF54DD371CC8A234DE . 988160 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kernel32.dll

[-] 2008-04-14 . 7FDE9FC15765E02B23E1756930165AD1 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2008-04-14 . 7FDE9FC15765E02B23E1756930165AD1 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll

[-] 2008-04-14 . C66BA7BD13C8FB8BEC4863B88641C763 . 22016 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lpk.dll
[-] 2008-04-14 . C66BA7BD13C8FB8BEC4863B88641C763 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll

[-] 2010-06-24 . C082E5EC8E50C92E23E3464EF7F05410 . 5954560 . . [8.00.6001.23037] . . c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\mshtml.dll
[-] 2010-06-24 . 5110C2044FF335AC363EECEA920F6DF2 . 5951488 . . [8.00.6001.18939] . . c:\windows\system32\mshtml.dll
[-] 2010-06-24 . 5110C2044FF335AC363EECEA920F6DF2 . 5951488 . . [8.00.6001.18939] . . c:\windows\system32\dllcache\mshtml.dll
[-] 2010-05-06 . 05379DF185A4199865D8B1AA169C3FD3 . 6224896 . . [8.00.6001.18928] . . c:\windows\ie8updates\KB2183461-IE8\mshtml.dll
[-] 2010-05-06 . 05379DF185A4199865D8B1AA169C3FD3 . 6224896 . . [8.00.6001.18928] . . c:\windows\ServicePackFiles\i386\mshtml.dll
[-] 2010-05-06 . 3F88F981AA7BC20744E0D2C699F500EF . 5953024 . . [8.00.6001.23019] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll
[-] 2010-02-26 . 23CB63CC448E14C4069E9CE40483E987 . 3094528 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\mshtml.dll
[-] 2010-02-25 . AC93856CC1D10E74986EA4E70D90748F . 5946880 . . [8.00.6001.22995] . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll
[-] 2010-01-05 . 5DA02EE50F8FC661964857F21A2AE606 . 3602944 . . [7.00.6000.21183] . . c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\mshtml.dll
[-] 2009-12-22 . 25B289964AE031D4ECF189B8CD50F306 . 3092480 . . [6.00.2900.3660] . . c:\windows\$hf_mig$\KB978207\SP2QFE\mshtml.dll
[-] 2009-12-22 . 41A55A865F00CE20284132E8FDE1FFB3 . 3092480 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\mshtml.dll
[-] 2009-12-22 . BD2EE2BDF5954172F509A16EBEA06D85 . 3094528 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\mshtml.dll
[-] 2009-12-21 . BD424F12E808F3AA345C4816F7124F7C . 5945856 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
[-] 2009-10-29 . 00EC3DE6B7C581CC2675CCD549B692D7 . 5940736 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\mshtml.dll
[-] 2009-10-29 . FC883BC594F028EF5D77B645AE91C914 . 5944320 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll
[-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\mshtml.dll
[-] 2007-08-13 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13] . . c:\windows\ie7updates\KB978207-IE7\mshtml.dll

[-] 2008-04-14 . D165DFCB4EA452510E53416F573018BB . 343040 . . [7.0.2600.5512] . . c:\windows\ServicePackFiles\i386\msvcrt.dll
[-] 2008-04-14 . D165DFCB4EA452510E53416F573018BB . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll

[-] 2008-06-20 . 1289B7611CCD6CB27596AE92CBF03E35 . 247296 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll
[-] 2008-06-20 . 1289B7611CCD6CB27596AE92CBF03E35 . 247296 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll
[-] 2008-06-20 . 1289B7611CCD6CB27596AE92CBF03E35 . 247296 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll
[-] 2008-06-20 . B6CEC406351EA5EF131416D5F52D006F . 247296 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
[-] 2008-06-20 . 37BABA5DBD9027837FDC27E5D6EF33E1 . 247296 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
[-] 2008-04-14 . AAC97DAB5F8A0573CF10E0EAC42A7724 . 247296 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\mswsock.dll

[-] 2009-02-06 . 1F43B8C0F4C767FBED89711C30E704D9 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[-] 2009-02-06 . 1F43B8C0F4C767FBED89711C30E704D9 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[-] 2008-04-14 . C2ED0E3408F50BBC149D4F0936E67832 . 407040 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netlogon.dll
[-] 2008-04-14 . C2ED0E3408F50BBC149D4F0936E67832 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll

[-] 2010-04-28 . EF1542C4875CAA34484A7BCB998B6BC4 . 2192128 . . [5.1.2600.5973] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2010-04-28 . EF1542C4875CAA34484A7BCB998B6BC4 . 2192128 . . [5.1.2600.5973] . . c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2010-04-28 . 431278D0EF7518BA499720122F4ED86F . 2148352 . . [5.1.2600.5973] . . c:\windows\system32\ntoskrnl.exe
[-] 2010-04-28 . 91FE668957FF51A2DBCEE0D8637BA77E . 2192256 . . [5.1.2600.5973] . . c:\windows\$hf_mig$\KB981852\SP3QFE\ntoskrnl.exe
[-] 2010-02-16 . CD79AD67BF88021BB60B2602D1947FB3 . 2148352 . . [5.1.2600.5938] . . c:\windows\$NtUninstallKB981852$\ntoskrnl.exe
[-] 2010-02-16 . 6B2312D847BA95F4E858CB4C3B5F51E1 . 2192256 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe
[-] 2009-12-10 . 7782F11AE957B736585870CD2671227B . 2191488 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntoskrnl.exe
[-] 2009-12-09 . 7782F11AE957B736585870CD2671227B . 2191488 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe
[-] 2009-12-09 . B214F89473F73C0733D9C402F36E2125 . 2188160 . . [5.1.2600.3654] . . c:\windows\$hf_mig$\KB977165-v2\SP2QFE\ntoskrnl.exe
[-] 2009-12-09 . 3B0DC252A20C8A938ED21073EE736AEA . 2191360 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165-v2\SP3GDR\ntoskrnl.exe
[-] 2009-08-04 . 3502DBBC657001D7A2A2768BD7DE1483 . 2191488 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe
[-] 2009-02-10 . 97480EBFE1D4B547657BAD75AAAB1325 . 2191360 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2009-02-09 . C424407DDD99223BF3248044CBBE91F6 . 2188288 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntoskrnl.exe
[-] 2009-02-09 . F48662F55CD8DDD4DBBBCB69DE197725 . 2191232 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntoskrnl.exe
[-] 2008-04-14 . C1536014AC1CB1D5397E31D9735E6571 . 2191104 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe

[-] 2008-04-14 . 9FA69781CAA7A1DA981A24F240A61A60 . 17408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\powrprof.dll
[-] 2008-04-14 . 9FA69781CAA7A1DA981A24F240A61A60 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll

[-] 2008-04-14 . 830CE8951C71F361D7D2F38416CC8BC1 . 185856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\scecli.dll
[-] 2008-04-14 . 830CE8951C71F361D7D2F38416CC8BC1 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll

[-] 2008-04-14 . 5EE949255BABC0B17C09DDB2E59E3878 . 5120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfc.dll
[-] 2008-04-14 . 5EE949255BABC0B17C09DDB2E59E3878 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll

[-] 2008-04-14 . BE4A520E29B6391F49E79CCC52044D93 . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe
[-] 2008-04-14 . BE4A520E29B6391F49E79CCC52044D93 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe

[-] 2008-04-14 . C2546CD7A398476F9DF5614B2AE160E8 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2008-04-14 . C2546CD7A398476F9DF5614B2AE160E8 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll

[-] 2008-04-14 . E16E0990967374E76F3E40CACAFD3D53 . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-14 . E16E0990967374E76F3E40CACAFD3D53 . 578560 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

[-] 2008-04-14 . 7DC1830F22E7D275B438127B68030239 . 26112 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-14 . 7DC1830F22E7D275B438127B68030239 . 26112 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe

[-] 2010-06-24 . D2B5FCDB99A3321C1B9B8A12A6D56AD8 . 919040 . . [8.00.6001.23037] . . c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\wininet.dll
[-] 2010-06-24 . EF345C39AD3FBBD239627EDD99793CF1 . 916480 . . [8.00.6001.18939] . . c:\windows\system32\wininet.dll
[-] 2010-06-24 . EF345C39AD3FBBD239627EDD99793CF1 . 916480 . . [8.00.6001.18939] . . c:\windows\system32\dllcache\wininet.dll
[-] 2010-05-06 . C9C1E562FE51D92193AD5F19AB5F9E36 . 907264 . . [8.00.6001.18923] . . c:\windows\ie8updates\KB2183461-IE8\wininet.dll
[-] 2010-05-06 . C9C1E562FE51D92193AD5F19AB5F9E36 . 907264 . . [8.00.6001.18923] . . c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2010-05-06 . 72064DA077E9D6912F39438D97CC0C60 . 919040 . . [8.00.6001.23014] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll
[-] 2010-02-26 . FD0F4E4BC28B18715BC1323ACD48E1A6 . 669696 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\wininet.dll
[-] 2010-02-25 . 2E6504E28C7E0F753F68731861A94214 . 919040 . . [8.00.6001.22995] . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll
[-] 2010-01-05 . 0D90D150ED0DD4C673C627C52D3F7149 . 841216 . . [7.00.6000.21183] . . c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\wininet.dll
[-] 2009-12-22 . A0C158A24DA9F9C48B5B067948B31AA4 . 669696 . . [6.00.2900.3660] . . c:\windows\$hf_mig$\KB978207\SP2QFE\wininet.dll
[-] 2009-12-22 . 50C587017A3F2FB5B1B1B4267CB2EA91 . 668160 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\wininet.dll
[-] 2009-12-22 . 5F072B7F1CF448D6ED5FF79511890E60 . 669696 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\wininet.dll
[-] 2009-12-21 . 9256DA4AEE5E2C20FC6C126BDBC11997 . 916480 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll
[-] 2009-10-29 . F651D2A69B7037D6063BC697CF296D8C . 916480 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\wininet.dll
[-] 2009-10-29 . 4941ADD731725AF468342E42B71F776C . 916480 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll
[-] 2009-03-08 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\wininet.dll
[-] 2007-08-13 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . c:\windows\ie7updates\KB978207-IE7\wininet.dll

[-] 2008-04-14 . 951D473917C51F21496D914CF6E5DDD1 . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-14 . 951D473917C51F21496D914CF6E5DDD1 . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll

[-] 2008-04-14 . 859F7735F199C90403340183A3DDFB78 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2help.dll
[-] 2008-04-14 . 859F7735F199C90403340183A3DDFB78 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\ws2help.dll

[-] 2008-04-14 . 71C54FF181A2C03921A74DB4D9ADD20E . 976384 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 71C54FF181A2C03921A74DB4D9ADD20E . 976384 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe

[-] 2008-04-14 . 21F836AAB269FF644E0E708B794B0DF7 . 1287168 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll
[-] 2008-04-14 . 21F836AAB269FF644E0E708B794B0DF7 . 1287168 . . [5.1.2600.5512] . . c:\windows\system32\ole32.dll

[-] 2008-04-14 . 35B91147124F64AC8081A2EDB9EA4DEE . 171008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-14 . 35B91147124F64AC8081A2EDB9EA4DEE . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll

[-] 2008-04-14 . 278A14BEDEF58687EAF8BEC056A78D8B . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
[-] 2008-04-14 . 278A14BEDEF58687EAF8BEC056A78D8B . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe

[-] 2008-04-14 . EAA4BB9EDB3FB10CF8979FE65E63658F . 129024 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\xmlprov.dll
[-] 2008-04-14 . EAA4BB9EDB3FB10CF8979FE65E63658F . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll

[-] 2008-04-14 . 2EE99F67C930931EB404DADCE57E976E . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[-] 2008-04-14 . 2EE99F67C930931EB404DADCE57E976E . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll

[-] 2008-04-14 . 56A6034E7764E23D9114223EB3523925 . 1571840 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll
[-] 2008-04-14 . 56A6034E7764E23D9114223EB3523925 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

[-] 2008-04-14 . A756B8F0F7BAFBA6DFE39F7D169F2519 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . A756B8F0F7BAFBA6DFE39F7D169F2519 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe

[-] 2008-04-14 . B927443008910B412BEC72FC41C1BAD0 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2008-04-14 . B927443008910B412BEC72FC41C1BAD0 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\shsvcs.dll

[-] 2008-04-14 . 8F31505484A190D5B22274708799F4EC . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll
[-] 2008-04-14 . 8F31505484A190D5B22274708799F4EC . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll

[-] 2008-04-14 . 3FF232A7731621B8902D81D42418C93C . 192512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\schedsvc.dll
[-] 2008-04-14 . 3FF232A7731621B8902D81D42418C93C . 192512 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll

[-] 2008-04-14 . BECD5271DC4E3B7C3D035F790FCBC1E5 . 71680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ssdpsrv.dll
[-] 2008-04-14 . BECD5271DC4E3B7C3D035F790FCBC1E5 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll

[-] 2008-04-14 . A75DD6FC3DBEE4FFF5EBC9F2C28BB66E . 295936 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-04-14 . A75DD6FC3DBEE4FFF5EBC9F2C28BB66E . 295936 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll

[-] 2008-04-14 . 6B8E7A90E576D4FE308F97C69060A171 . 171008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\appmgmts.dll
[-] 2008-04-14 . 6B8E7A90E576D4FE308F97C69060A171 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\appmgmts.dll

[-] 2001-10-25 . AFDFF022A01F0B11C776F0860C3B282F . 11776 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

[-] 2008-04-13 20:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ServicePackFiles\i386\aec.sys
[-] 2008-04-13 20:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys

[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\agp440.sys
[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\system32\drivers\agp440.sys

[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ip6fw.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys

[-] 2008-04-14 06:51 . 7C3351F60B759D5D917E68342AE3307C . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll
[-] 2008-04-14 06:51 . 7C3351F60B759D5D917E68342AE3307C . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll

[-] 2008-04-14 . 221CD1C815B8A6B79389C3F5D1018DE8 . 33792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\msgsvc.dll
[-] 2008-04-14 . 221CD1C815B8A6B79389C3F5D1018DE8 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll

[-] 2009-01-30 18:33 . 051B1BDECD6DEE18C771B5D5EC7F044D . 27136 . . [11.0.5721.5262] . . c:\windows\system32\mspmsnsv.dll
[-] 2009-01-30 18:33 . 051B1BDECD6DEE18C771B5D5EC7F044D . 27136 . . [11.0.5721.5262] . . c:\windows\system32\dllcache\mspmsnsv.dll

[-] 2010-04-28 . 2FA1EF498F026847CF276DF9099ABE79 . 2069120 . . [5.1.2600.5973] . . c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrnlpa.exe
[-] 2010-04-28 . E4D3DB21C20749B8776B3E2C4B880404 . 2068992 . . [5.1.2600.5973] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2010-04-28 . E4D3DB21C20749B8776B3E2C4B880404 . 2068992 . . [5.1.2600.5973] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2010-04-28 . F7648719DB795F098BA7F2AE67150182 . 2026496 . . [5.1.2600.5973] . . c:\windows\system32\ntkrnlpa.exe
[-] 2010-02-16 . D46E1BB887F3340430D10DA536FE79E1 . 2026496 . . [5.1.2600.5938] . . c:\windows\$NtUninstallKB981852$\ntkrnlpa.exe
[-] 2010-02-16 . DCC3D91A3DEDBBA9ECFFA6028D872CF5 . 2069120 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe
[-] 2009-12-10 . 58516936F00D10D4B615C458A8A4AB71 . 2068352 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrnlpa.exe
[-] 2009-12-09 . 58516936F00D10D4B615C458A8A4AB71 . 2068352 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe
[-] 2009-12-09 . D9FB61F23249B39EE9922A2CC3001DD0 . 2065280 . . [5.1.2600.3654] . . c:\windows\$hf_mig$\KB977165-v2\SP2QFE\ntkrnlpa.exe
[-] 2009-12-09 . 166530C022AB3A0F9EADB20633AE034E . 2068224 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165-v2\SP3GDR\ntkrnlpa.exe
[-] 2009-08-04 . 97815C93200676C727CE951AE5C78137 . 2068352 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe
[-] 2009-02-10 . D721665942F74CA7FF4162A0761CBB0A . 2068224 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntkrnlpa.exe
[-] 2009-02-09 . BB64DC108F8C4EE4D4B7998AA19E5FA7 . 2065152 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntkrnlpa.exe
[-] 2009-02-09 . FF8A3F180A224AA27EBAB937CA027F4D . 2068352 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-04-14 . 4DEE41C45E803DB91A72FD1BA69C05EE . 2067968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe

[-] 2008-04-14 06:51 . 023DD70573D644F3D9C8B1258A7BFD08 . 435712 . . [5.1.2400.5512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll
[-] 2008-04-14 06:51 . 023DD70573D644F3D9C8B1258A7BFD08 . 435712 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll

[-] 2008-04-14 . 651BD90DCEE5B7BDC74A2EB7C9266F9E . 186368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\upnphost.dll
[-] 2008-04-14 . 651BD90DCEE5B7BDC74A2EB7C9266F9E . 186368 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll

[-] 2008-04-14 . 8E009E7AC012823845D5F39A77F4A27F . 367616 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\dsound.dll
[-] 2008-04-14 . 8E009E7AC012823845D5F39A77F4A27F . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dsound.dll
[-] 2004-07-09 02:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound.dll
[-] 2004-07-09 02:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\dsound.dll

[-] 2008-04-14 . 3B8AE11A3419DF8239183E94888702FA . 1689088 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\d3d9.dll
[-] 2008-04-14 . 3B8AE11A3419DF8239183E94888702FA . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\d3d9.dll

[-] 2008-04-14 . EDAD701F01FFD9B5799B8FCF1CF6BDA7 . 279552 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\ddraw.dll
[-] 2008-04-14 . EDAD701F01FFD9B5799B8FCF1CF6BDA7 . 279552 . . [5.03.2600.5512] . . c:\windows\system32\ddraw.dll
[-] 2004-07-09 02:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddraw.dll
[-] 2004-07-09 02:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\ddraw.dll

[-] 2008-04-14 06:51 . 16C195EBC0A3EC35C48D0C2D9A346BAB . 84992 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\olepro32.dll
[-] 2008-04-14 06:51 . 16C195EBC0A3EC35C48D0C2D9A346BAB . 84992 . . [5.1.2600.5512] . . c:\windows\system32\olepro32.dll

[-] 2008-04-14 . 1682285F7C0934C764A0EBBC568153CA . 39936 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\perfctrs.dll
[-] 2008-04-14 . 1682285F7C0934C764A0EBBC568153CA . 39936 . . [5.1.2600.5512] . . c:\windows\system32\perfctrs.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-07-28 19557480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Butterfly\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AvastUI.lnk - c:\program files\Alwil Software\Avast5\AvastUI.exe [2010-8-19 2837864]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{DAE0285D-0788-4E87-985E-01DF2EDE4ACD}"= "c:\windows\system32\Wshxt.dll" [2010-08-28 53248]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 06:52 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2009-01-30 15:46 204288 ------w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HLSW\\hlsw.exe"=
"c:\\Documents and Settings\\Butterfly\\Dokumenty\\My DAP Downloads\\TeamViewerPortable_en\\TeamViewer.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Valve\\hltv.exe"=
"c:\\Program Files\\Flow\\Flow.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Steam\\steamapps\\cleverboy\\condition zero\\hl.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\steamapps\\cleverboy\\counter-strike\\hl.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [2010-02-21 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [2010-02-21 52224]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-08-19 165456]
S1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2010-02-09 13696]
S1 Winhpfile;Winhpfile;\??\c:\qwdvxmpo\HPFile.sys --> c:\qwdvxmpo\HPFile.sys [?]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-08-19 17744]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-21 136176]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-07-06 1051968]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-08-19 1691480]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-06-13 23456]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [2010-03-17 18944]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [2010-03-17 11520]
S3 HideMyIpSRV;HideMyIpSRV;c:\program files\Hide My IP\HideMyIpSrv.exe [2010-08-27 2752816]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S3 tap0901_2gm;VPN Anonymizer Adapter;c:\windows\system32\drivers\tap0901_2gm.sys [2007-06-21 30720]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2010-02-28 697328]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-08-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-796845957-879983540-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]

2010-08-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-879983540-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://google.cz/
IE: &Download with &DAP
IE: Download &all with DAP
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Zobrazit originál
LSP: c:\windows\system32\HMIPCore.dll
.

**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-796845957-879983540-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1048)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll

- - - - - - - > 'explorer.exe'(276)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
Celkový čas: 2010-08-28 19:49:51
ComboFix-quarantined-files.txt 2010-08-28 17:49
ComboFix2.txt 2010-08-27 20:35

Před spuštěním: Volných bajtů: 75,922,952,192
Po spuštění: Volných bajtů: 75,881,132,032

Current=50 Default=50 Failed=49 LastKnownGood=51 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51
- - End Of File - - BFE256B4D9FF4D95DF4AE20088A82733
Naposledy upravil(a) BOnioo1775 dne 28 srp 2010 21:05, celkem upraveno 2 x.

BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Re: Prosim o kontrolu - Blue screen hpfile.sys

#2 Příspěvek od BOnioo1775 »

A zde log z RSIT.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Butterfly at 2010-08-28 19:58:46
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 72 GB (72%) free of 100 GB
Total RAM: 1022 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:59:20, on 2010-08-28
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\My Folder\My !\PC\Malware\RSIT.exe
C:\Program Files\trend micro\Butterfly.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: IHPIEHook Class - {0eceeac0-8a08-11d4-a521-0020af300fc7} - C:\sfocwxgi\HPIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AvastUI.lnk = C:\Program Files\Alwil Software\Avast5\AvastUI.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HDDlife HDD Access service - BinarySense, Inc. - C:\Program Files\Common Files\BinarySense\hldasvc.exe
O23 - Service: HideMyIpSRV - Unknown owner - C:\Program Files\Hide My IP\HideMyIpSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 5770 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-796845957-879983540-682003330-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-879983540-682003330-1003.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0eceeac0-8a08-11d4-a521-0020af300fc7}]
IHPIEHook Class - C:\sfocwxgi\HPIE.dll [2010-08-28 40960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-23 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-23 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-07-28 19557480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2009-01-30 204288]

C:\Documents and Settings\Butterfly\Nabídka Start\Programy\Po spuštění
AvastUI.lnk - C:\Program Files\Alwil Software\Avast5\AvastUI.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-08-04 159744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{DAE0285D-0788-4E87-985E-01DF2EDE4ACD}"=C:\WINDOWS\system32\Wshxt.dll [2010-08-28 53248]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"HonorAutoRunSetting"=
"NoResolveSearch"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Documents and Settings\Butterfly\Dokumenty\My DAP Downloads\TeamViewerPortable_en\TeamViewer.exe"="C:\Documents and Settings\Butterfly\Dokumenty\My DAP Downloads\TeamViewerPortable_en\TeamViewer.exe:*:Enabled:TeamViewer"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Valve\hltv.exe"="C:\Program Files\Valve\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\Flow\Flow.exe"="C:\Program Files\Flow\Flow.exe:*:Enabled:Flow"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Steam\steamapps\cleverboy\condition zero\hl.exe"="C:\Program Files\Steam\steamapps\cleverboy\condition zero\hl.exe:*:Enabled:Counter-Strike: Condition Zero"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "
"C:\Program Files\Steam\steamapps\cleverboy\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\cleverboy\counter-strike\hl.exe:*:Enabled:Counter-Strike"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-08-28 19:58:46 ----D---- C:\rsit
2010-08-28 19:49:53 ----D---- C:\WINDOWS\temp
2010-08-28 19:49:52 ----A---- C:\ComboFix.txt
2010-08-28 19:39:05 ----A---- C:\WINDOWS\zip.exe
2010-08-28 19:39:05 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-08-28 19:39:05 ----A---- C:\WINDOWS\SWSC.exe
2010-08-28 19:39:05 ----A---- C:\WINDOWS\SWREG.exe
2010-08-28 19:39:05 ----A---- C:\WINDOWS\sed.exe
2010-08-28 19:39:05 ----A---- C:\WINDOWS\PEV.exe
2010-08-28 19:39:05 ----A---- C:\WINDOWS\MBR.exe
2010-08-28 19:39:05 ----A---- C:\WINDOWS\grep.exe
2010-08-28 19:38:45 ----D---- C:\ComboFix
2010-08-28 19:36:09 ----D---- C:\Qoobox
2010-08-28 19:27:58 ----A---- C:\WINDOWS\ntbtlog.txt
2010-08-28 18:50:45 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-08-28 18:29:16 ----D---- C:\SFOCWXGI
2010-08-28 17:46:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Montpellier-Informatique
2010-08-28 16:09:51 ----D---- C:\BDYGBOUQ
2010-08-28 00:03:24 ----D---- C:\pear
2010-08-27 23:33:26 ----D---- C:\SKRYTY
2010-08-27 23:33:26 ----D---- C:\PROTOKOL
2010-08-27 23:33:16 ----A---- C:\WINDOWS\system32\wshxt.dll
2010-08-27 23:33:16 ----A---- C:\WINDOWS\system32\wmsprog.dll
2010-08-27 23:33:16 ----A---- C:\WINDOWS\system32\kernell.dll
2010-08-27 23:33:15 ----D---- C:\QWDVXMPO
2010-08-27 23:21:57 ----D---- C:\Program Files\Hide My IP
2010-08-27 22:23:54 ----A---- C:\WINDOWS\NIRCMD.exe
2010-08-27 22:23:45 ----D---- C:\WINDOWS\ERDNT
2010-08-27 20:51:23 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-27 18:31:40 ----D---- C:\Hotspot Shield
2010-08-27 18:28:58 ----D---- C:\Program Files\Secunia
2010-08-27 16:53:37 ----RSHD---- C:\Documents and Settings\Butterfly\Data aplikací\DisplayDriverTEMP
2010-08-27 16:53:32 ----D---- C:\WINDOWS\XSxS
2010-08-27 13:23:57 ----D---- C:\Shoty
2010-08-27 13:23:51 ----D---- C:\Program Files\ScreenShots
2010-08-27 09:37:41 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\CosmeticGuide
2010-08-27 09:35:29 ----D---- C:\Program Files\Two Pilots
2010-08-27 09:35:28 ----D---- C:\Program Files\Cosmetic Guide
2010-08-26 22:13:21 ----A---- C:\WINDOWS\unvise32.exe
2010-08-26 22:11:08 ----D---- C:\Program Files\MAXON
2010-08-26 18:17:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\ATI
2010-08-26 10:16:58 ----A---- C:\WINDOWS\system32\tmp_docprotector.ini
2010-08-23 20:07:36 ----D---- C:\Program Files\Elecard
2010-08-23 18:30:21 ----D---- C:\WINDOWS\system32\Adobe
2010-08-23 13:11:37 ----D---- C:\Program Files\Common Files\Java
2010-08-23 13:11:05 ----A---- C:\WINDOWS\system32\javaws.exe
2010-08-23 13:11:05 ----A---- C:\WINDOWS\system32\javaw.exe
2010-08-23 13:11:05 ----A---- C:\WINDOWS\system32\java.exe
2010-08-23 11:16:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.TMP
2010-08-23 10:56:41 ----A---- C:\WINDOWS\sndvol32.exe
2010-08-23 10:38:45 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-08-23 10:37:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
2010-08-23 10:36:42 ----D---- C:\PFiles
2010-08-22 22:21:23 ----D---- C:\Program Files\Common Files\Java(3)
2010-08-22 16:49:46 ----D---- C:\Program Files\Codec Pack - All In 1
2010-08-22 12:33:46 ----D---- C:\Program Files\Common Files\Futuremark Shared
2010-08-21 18:40:57 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\ProgSense
2010-08-21 18:40:45 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Orbit
2010-08-20 00:02:25 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Sereniti
2010-08-19 22:12:12 ----D---- C:\VritualRoot
2010-08-19 21:14:19 ----D---- C:\Program Files\Sunbelt Software
2010-08-19 19:49:32 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-08-19 19:47:48 ----D---- C:\Program Files\Alwil Software
2010-08-19 14:52:40 ----D---- C:\WINDOWS\system32\RTCOM
2010-08-19 14:52:17 ----A---- C:\WINDOWS\vncutil.exe
2010-08-19 14:52:17 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-08-19 14:52:17 ----A---- C:\WINDOWS\SkyTel.exe
2010-08-19 14:52:17 ----A---- C:\WINDOWS\RtlUpd.exe
2010-08-19 14:52:16 ----A---- C:\WINDOWS\RTLCPL.EXE
2010-08-19 14:52:14 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-08-19 14:52:11 ----A---- C:\WINDOWS\RTHDCPL.EXE
2010-08-19 14:52:11 ----A---- C:\WINDOWS\MicCal.exe
2010-08-19 14:52:04 ----D---- C:\Program Files\Realtek
2010-08-19 14:52:04 ----A---- C:\WINDOWS\ALCWZRD.EXE
2010-08-19 14:51:04 ----A---- C:\WINDOWS\RtlExUpd.dll
2010-08-19 10:45:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-08-18 16:17:25 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\ATI
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atitvo32.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atiok3x2.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atioglxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ATIODE.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ATIODCLI.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atimpc32.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atikvmag.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\aticalrt.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\aticaldd.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\aticalcl.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atibtmon.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\amdpcom32.dll
2010-08-18 16:13:11 ----D---- C:\ATI
2010-08-18 15:00:04 ----D---- C:\Program Files\ATI
2010-08-18 14:39:47 ----D---- C:\Program Files\ATI Technologies
2010-08-15 15:29:20 ----A---- C:\WINDOWS\system32\nv4_disp.dll-nv1043
2010-08-15 12:50:53 ----D---- C:\Program Files\NVIDIA Corporation
2010-08-15 12:49:50 ----A---- C:\WINDOWS\system32\opencl.dll-nv1428
2010-08-15 12:49:50 ----A---- C:\WINDOWS\system32\nvoglnt.dll-nv1206
2010-08-15 12:49:50 ----A---- C:\WINDOWS\system32\nvcuvid.dll-nv1360
2010-08-15 12:49:50 ----A---- C:\WINDOWS\system32\nvcuvenc.dll-nv1376
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvcuda.dll-nv1347
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvcompiler.dll-nv1389
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvcodins.dll-nv1281
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvcod.dll-nv1281
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvapi.dll-nv1281
2010-08-15 11:44:21 ----A---- C:\WINDOWS\system32\nsp13.tmp
2010-08-15 11:44:21 ----A---- C:\WINDOWS\system32\nsj12.tmp
2010-08-15 11:44:21 ----A---- C:\WINDOWS\system32\nsa14.tmp
2010-08-15 11:44:20 ----A---- C:\WINDOWS\system32\nsx11.tmp
2010-08-15 11:44:20 ----A---- C:\WINDOWS\system32\nsn10.tmp
2010-08-15 11:44:19 ----A---- C:\WINDOWS\system32\nswF.tmp
2010-08-15 11:44:19 ----A---- C:\WINDOWS\system32\nsqE.tmp
2010-08-15 11:44:18 ----A---- C:\WINDOWS\system32\nszC.tmp
2010-08-15 11:44:15 ----A---- C:\WINDOWS\system32\nslB.tmp
2010-08-15 11:44:14 ----A---- C:\WINDOWS\system32\nsjA.tmp
2010-08-15 11:44:13 ----A---- C:\WINDOWS\system32\nsl9.tmp
2010-08-15 11:44:10 ----A---- C:\WINDOWS\system32\nsr7.tmp
2010-08-15 11:44:10 ----A---- C:\WINDOWS\nsc8.tmp
2010-08-15 11:44:09 ----A---- C:\WINDOWS\system32\nsa6.tmp
2010-08-13 14:15:02 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-13 14:14:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-08-13 14:14:12 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-13 14:13:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-13 14:06:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-13 14:06:37 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-13 14:04:24 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-13 14:03:28 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-07 10:19:46 ----A---- C:\WINDOWS\system32\vuins32.dll
2010-08-07 10:19:46 ----A---- C:\WINDOWS\system32\difxapi.dll
2010-08-06 23:55:15 ----A---- C:\WINDOWS\BricoPackFoldersDelete.cmd
2010-08-05 09:14:47 ----D---- C:\WINDOWS\NV35361800.TMP
2010-08-04 10:12:53 ----D---- C:\WINDOWS\NV23721612.TMP
2010-08-03 09:57:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-08-02 11:39:02 ----A---- C:\WINDOWS\system32\P1131Vfw.dll
2010-08-02 11:39:02 ----A---- C:\WINDOWS\P1131Cfg.exe
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\P1131Sti.dll
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\P1131Srv.exe
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\P1131Pin.dll
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\P1131Hwx.dll
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\CtCamMgr.dll
2010-08-02 11:34:47 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-08-02 11:33:49 ----D---- C:\WINDOWS\CtDrvInstall
2010-08-02 11:33:37 ----A---- C:\WINDOWS\CtDrvIns.exe
2010-08-02 11:33:33 ----D---- C:\WebCamNXPro
2010-08-01 20:46:44 ----A---- C:\WINDOWS\system32\nvcodins.dll-nv22389
2010-08-01 20:46:43 ----A---- C:\WINDOWS\system32\nvcod.dll-nv22389
2010-08-01 20:46:35 ----A---- C:\WINDOWS\system32\nvoglnt.dll-nv22383
2010-08-01 20:46:33 ----A---- C:\WINDOWS\system32\nvcuvid.dll-nv22396
2010-08-01 20:46:31 ----A---- C:\WINDOWS\system32\nvcuvenc.dll-nv22399
2010-08-01 20:46:28 ----A---- C:\WINDOWS\system32\nvcuda.dll-nv22396
2010-08-01 20:46:25 ----A---- C:\WINDOWS\system32\nvcompiler.dll-nv22399
2010-08-01 20:46:24 ----A---- C:\WINDOWS\system32\nvapi.dll-nv22393
2010-08-01 20:46:20 ----A---- C:\WINDOWS\system32\nv4_disp.dll-nv22376
2010-08-01 20:46:19 ----A---- C:\WINDOWS\system32\opencl.dll-nv22402
2010-08-01 14:53:02 ----D---- C:\WINDOWS\NV33763424.TMP
2010-08-01 13:58:48 ----D---- C:\WINDOWS\NV40402576.TMP
2010-07-30 23:04:31 ----A---- C:\WINDOWS\system32\rewire.dll
2010-07-30 22:58:59 ----D---- C:\Program Files\Image-Line
2010-07-30 18:16:32 ----D---- C:\Program Files\Sony
2010-07-30 18:12:44 ----D---- C:\Program Files\Sony Setup

======List of files/folders modified in the last 1 months======

2010-08-28 19:59:20 ----D---- C:\Program Files\Trend Micro
2010-08-28 19:49:53 ----D---- C:\WINDOWS
2010-08-28 19:46:24 ----A---- C:\WINDOWS\system.ini
2010-08-28 19:44:56 ----D---- C:\WINDOWS\system32\drivers
2010-08-28 19:44:15 ----D---- C:\WINDOWS\system32
2010-08-28 19:44:15 ----D---- C:\WINDOWS\AppPatch
2010-08-28 19:44:13 ----D---- C:\Program Files\Common Files
2010-08-28 19:28:04 ----D---- C:\WINDOWS\Minidump
2010-08-28 19:13:44 ----D---- C:\WINDOWS\Prefetch
2010-08-28 18:43:06 ----D---- C:\Program Files\Steam
2010-08-28 18:06:48 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-08-28 18:06:17 ----D---- C:\Config.Msi
2010-08-28 17:54:07 ----SHD---- C:\WINDOWS\Installer
2010-08-28 17:54:05 ----D---- C:\Program Files
2010-08-28 14:01:03 ----D---- C:\Program Files\Debugging Tools for Windows (x86)
2010-08-27 20:52:03 ----SHD---- C:\System Volume Information
2010-08-27 20:52:03 ----D---- C:\WINDOWS\system32\Restore
2010-08-27 18:34:29 ----HD---- C:\WINDOWS\inf
2010-08-27 16:40:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-08-27 16:40:27 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Real
2010-08-26 19:01:57 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\dvdcss
2010-08-26 18:38:38 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\vlc
2010-08-26 18:13:31 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-26 18:13:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-08-26 18:12:58 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-08-26 17:58:54 ----ASH---- C:\boot.ini
2010-08-26 17:58:54 ----A---- C:\WINDOWS\win.ini
2010-08-26 16:02:32 ----D---- C:\Program Files\AIMP2
2010-08-26 11:19:25 ----D---- C:\Program Files\CCleaner
2010-08-26 10:23:48 ----D---- C:\Program Files\Mozilla Firefox 4.0 Beta 1
2010-08-25 22:28:56 ----D---- C:\Program Files\WhoCrashed
2010-08-25 13:46:54 ----D---- C:\Program Files\SystemRequirementsLab
2010-08-25 13:15:03 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Skype
2010-08-25 12:55:51 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\gtk-2.0
2010-08-25 12:09:47 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\skypePM
2010-08-24 00:53:33 ----D---- C:\WINDOWS\system32\config
2010-08-23 21:26:18 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Mozilla
2010-08-23 13:10:45 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-08-23 12:25:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2010-08-23 12:24:32 ----D---- C:\Program Files\DivX
2010-08-23 11:59:17 ----SHD---- C:\WINDOWS\CSC
2010-08-23 11:15:56 ----A---- C:\WINDOWS\UPGRADE.TXT
2010-08-23 10:39:43 ----D---- C:\WINDOWS\system32\wbem
2010-08-23 10:39:42 ----D---- C:\WINDOWS\Registration
2010-08-23 00:57:36 ----D---- C:\Program Files\Adobe
2010-08-22 17:03:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-08-22 12:33:45 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-22 11:22:43 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\KeePass
2010-08-21 10:27:00 ----D---- C:\WINDOWS\Help
2010-08-20 22:10:35 ----A---- C:\WINDOWS\system32\resetlog.txt
2010-08-20 21:59:27 ----D---- C:\WINDOWS\network diagnostic
2010-08-19 21:47:27 ----D---- C:\Program Files\Google
2010-08-19 21:35:26 ----D---- C:\Program Files\QuickTime
2010-08-19 20:22:11 ----SD---- C:\WINDOWS\Tasks
2010-08-19 19:49:57 ----D---- C:\WINDOWS\WinSxS
2010-08-19 19:49:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-08-19 11:01:16 ----D---- C:\Program Files\Defraggler
2010-08-19 10:58:11 ----D---- C:\Program Files\FileHippo.com
2010-08-18 23:12:41 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\HLSW
2010-08-18 23:09:40 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Samsung
2010-08-18 23:09:33 ----D---- C:\Program Files\Samsung
2010-08-18 22:31:21 ----D---- C:\Program Files\Opera
2010-08-18 14:09:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2010-08-13 21:06:45 ----D---- C:\WINDOWS\Debug
2010-08-13 14:19:26 ----RSD---- C:\WINDOWS\assembly
2010-08-13 14:15:00 ----HD---- C:\WINDOWS\$hf_mig$
2010-08-13 14:13:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-08-13 14:11:33 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-13 14:10:49 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-13 14:07:12 ----D---- C:\Program Files\Internet Explorer
2010-08-13 14:07:00 ----D---- C:\WINDOWS\ie8updates
2010-08-13 14:04:26 ----D---- C:\Program Files\Movie Maker
2010-08-07 17:13:55 ----D---- C:\Program Files\Trillian
2010-08-07 17:13:13 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Trillian
2010-08-07 09:30:03 ----D---- C:\WINDOWS\Cursors
2010-08-07 09:30:02 ----RSD---- C:\WINDOWS\Fonts
2010-08-07 09:30:02 ----D---- C:\WINDOWS\Media
2010-08-07 09:30:02 ----D---- C:\Program Files\Outlook Express
2010-08-07 09:30:01 ----D---- C:\WINDOWS\system32\usmt
2010-08-07 00:00:08 ----A---- C:\WINDOWS\BricoPackUninst.txt
2010-08-07 00:00:08 ----A---- C:\WINDOWS\BricoPackUninst.cmd
2010-08-06 23:54:35 ----D---- C:\WINDOWS\BricoPacks
2010-08-04 03:46:04 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2010-08-04 03:41:40 ----A---- C:\WINDOWS\system32\ati3duag.dll
2010-08-04 03:28:06 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2010-08-04 03:16:50 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2010-08-03 20:09:31 ----A---- C:\WINDOWS\system32\MRT.exe
2010-08-02 11:54:48 ----D---- C:\Program Files\Safari
2010-08-02 11:34:58 ----D---- C:\WINDOWS\twain_32
2010-07-29 20:29:23 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-07-29 10:30:05 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R3 catchme;catchme; \??\C:\DOCUME~1\BUTTER~1\LOCALS~1\Temp\catchme.sys []
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2009-06-16 46592]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2005-01-05 6912]
R3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2005-06-06 11264]
S1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-06-28 28880]
S1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-06-28 165456]
S1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-06-28 46672]
S1 BIOS;BIOS; \??\C:\WINDOWS\system32\drivers\BIOS.sys []
S1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
S1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
S1 Winhpfile;Winhpfile; \??\C:\qwdvxmpo\HPFile.sys []
S2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-06-28 17744]
S2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-06-28 100176]
S2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
S2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
S2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-06-28 23376]
S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-08-04 5243392]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2010-05-17 101904]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 DrvAgent32;DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2010-04-03 223128]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-01-09 42496]
S3 gHidPnp;USB Device Enhanced Function Driver; C:\WINDOWS\System32\Drivers\gHidPnp.Sys [2009-03-06 18944]
S3 gMouUsb;USB Mouse Device Drv; C:\WINDOWS\system32\DRIVERS\gMouUsb.sys [2009-03-04 11520]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-07-28 6108776]
S3 mbr;mbr; \??\C:\DOCUME~1\BUTTER~1\LOCALS~1\Temp\mbr.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 msloop;Microsoft Loopback Adapter Driver; C:\WINDOWS\system32\DRIVERS\loop.sys [2001-08-17 4992]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 NTSIM;NTSIM; \??\C:\WINDOWS\system32\ntsim.sys []
S3 P1131VID;Creative WebCam NX Pro (WDM); C:\WINDOWS\system32\DRIVERS\P1131Vid.sys [2004-03-26 91241]
S3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2010-03-19 19072]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-25 5888]
S3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2008-02-25 105088]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2008-02-22 87936]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2008-02-22 14976]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2008-02-22 114304]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 tap0901_2gm;VPN Anonymizer Adapter; C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 30720]
S3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2010-06-23 32768]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2009-05-23 29696]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2009-01-30 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-07-21 697328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-08-04 606208]
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
S2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-21 136176]
S2 HDDlife HDD Access service;HDDlife HDD Access service; C:\Program Files\Common Files\BinarySense\hldasvc.exe [2009-08-19 822936]
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-08-23 153376]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-07-06 1051968]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-05-31 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 HideMyIpSRV;HideMyIpSRV; C:\Program Files\Hide My IP\HideMyIpSrv.exe [2010-04-10 2752816]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MatSvc;Microsoft Automated Troubleshooting Service; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-07-17 435008]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-01-30 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu - Blue screen hpfile.sys

#3 Příspěvek od motji »

Dobrý večer :)
Bsod bude asi skutečně způsobena driverem od hlídacího psa. Pokud chcete mít jistotu, zkuste najít složku C:\WINDOWS\minidump a pokud je v ní nějaký soubor aktuálního data, vložte ho sem jako přílohu v raru. Pak budeme chytřejší.

Máte spoustu souborů, které neznám a nevím, zda nepatří právě hlídacímu psovi, tkaže budeme trochu testovat :roll: .

:arrow: Můžete zjistit, zda tyto složky patří hlídacímu psovi?
C:\SFOCWXGI
C:\BDYGBOUQ
C:\pear
C:\QWDVXMPO



:arrow: Dejte soubor otestovat na http://www.virustotal.com

C:\WINDOWS\system32\nsp13.tmp
C:\WINDOWS\system32\nsj12.tmp
C:\WINDOWS\system32\nsa14.tmp
C:\WINDOWS\nsc8.tmp
C:\WINDOWS\P1131Cfg.exe
C:\WINDOWS\system32\P1131Sti.dll
c:\windows\system32\nvapi(15).dll
c:\windows\system32\drivers\atapi.sys


-Na virustotalu dáte procházet, a do spodního okénka nakopírujete přímo cestu k souboru a dáte odeslat
-z prohlížeče zkopírujete adresu ke stránce s výsledky
-pokud se Vás zeptá, dejte soubor otestovat znovu, tak aby to byl soubor z Vašeho počítače



:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Re: Prosim o kontrolu - Blue screen hpfile.sys

#4 Příspěvek od BOnioo1775 »

C:\SFOCWXGI
C:\BDYGBOUQ
C:\QWDVXMPO

pravdepodobne ano pac v kazde slozce se nachazi 1 soubor zacinajicim nazvem HP a nic jineho s takovym nazvem jsem neinstaloval za posledni tydny.

a C:\pear nepatri k hlidacimu psovi ,je to adresar k programu Code Master pro sifrovani dat. Avast u tohoto programu nezaznamenal zadnou hrozbu.

http://www.virustotal.com/file-scan/rep ... 1283030803
http://www.virustotal.com/file-scan/rep ... 1283030808
http://www.virustotal.com/file-scan/rep ... 1283030834
http://www.virustotal.com/file-scan/rep ... 1283030851
http://www.virustotal.com/file-scan/rep ... 1283030861
http://www.virustotal.com/file-scan/rep ... 1283030895
http://www.virustotal.com/file-scan/rep ... 1283030915
http://www.virustotal.com/file-scan/rep ... 1283030938

abych vam to usnadnil ,vsechno je ČISTÉ,až na posledním je něco málo.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu - Blue screen hpfile.sys

#5 Příspěvek od motji »

To je taky ok.
Ty dočasné soubory Vám pak smažu.
Ještě poprosím o ten sken mbamem.

Ta BSOD bude skutečně od HP, nejste první, komu takto dělá problémy.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Re: Prosim o kontrolu - Blue screen hpfile.sys

#6 Příspěvek od BOnioo1775 »

udelal jsem uplny sken,ale po asi 1,5 hodině ,kdy to skenovalo něco v adresáři C/WINDOWS ,došlo k chybě ,a MBAM se sám vypl. Na druhem disku,uz jsou jen fotky,mp3ky,ovladace apod. ,myslim,ze tam malware nebude.
Naposledy upravil(a) BOnioo1775 dne 29 srp 2010 09:48, celkem upraveno 1 x.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu - Blue screen hpfile.sys

#7 Příspěvek od motji »

A do té doby to něco našlo?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Re: Prosim o kontrolu - Blue screen hpfile.sys

#8 Příspěvek od BOnioo1775 »

ne nic

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu - Blue screen hpfile.sys

#9 Příspěvek od motji »

Zkuste mbam ještě v nouzovém režimu.
Já ted musím od počítače, budu tu až večer. Pomažu Vám ty dočasné soubory.
Problémy přetrvávají? Pokud ano, asi budete muset hlídacího psa odinstalovat.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Re: Prosim o kontrolu - Blue screen hpfile.sys

#10 Příspěvek od BOnioo1775 »

hlídací pes zmizel,a bsod nevyskakuje.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu - Blue screen hpfile.sys

#11 Příspěvek od motji »

zmizel nebo jste ho sám odinstaloval? Poprosím o nový log ze rsitu, večer domažu zbytky
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Re: Prosim o kontrolu - Blue screen hpfile.sys

#12 Příspěvek od BOnioo1775 »

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4456

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2010-08-29 12:22:31
mbam-log-2010-08-29 (12-22-31).txt

Typ skenu: Úplný sken (C:\|)
Skenované objekty: 272312
Uplynulý čas: 1 hodina(y), 3 minuta(y), 41 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Re: Prosim o kontrolu - Blue screen hpfile.sys

#13 Příspěvek od BOnioo1775 »

ZMIZEL,hned po prvnim bsod,jsem smazal vsechny soubory hpfile ,co jsem nasel a smazal adresář hlidaciho psa


Logfile of random's system information tool 1.06 (written by random/random)
Run by Butterfly at 2010-08-29 12:27:41
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 73 GB (73%) free of 100 GB
Total RAM: 1022 MB (14% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:28:04, on 2010-08-29
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
D:\My Folder\My !\PC\WINDOWS\DontSleep.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hide My IP\HideMyIpSrv.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\mom.exe
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\ccc.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\SpyMyPC\smpc32.exe
C:\Documents and Settings\Butterfly\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\My Folder\My !\PC\Malware\RSIT.exe
C:\Program Files\trend micro\Butterfly.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [USB Antivirus] C:\Program Files\USB Disk Security\USBGuard.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AvastUI.lnk = C:\Program Files\Alwil Software\Avast5\AvastUI.exe
O4 - Startup: DontSleep.lnk = D:\My Folder\My !\PC\WINDOWS\DontSleep.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HDDlife HDD Access service - BinarySense, Inc. - C:\Program Files\Common Files\BinarySense\hldasvc.exe
O23 - Service: HideMyIpSRV - Unknown owner - C:\Program Files\Hide My IP\HideMyIpSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 7558 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-796845957-879983540-682003330-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-879983540-682003330-1003.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-23 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-23 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-07-28 19557480]
"USB Antivirus"=C:\Program Files\USB Disk Security\USBGuard.exe [2010-01-10 819200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2009-01-30 204288]

C:\Documents and Settings\Butterfly\Nabídka Start\Programy\Po spuštění
AvastUI.lnk - C:\Program Files\Alwil Software\Avast5\AvastUI.exe
DontSleep.lnk - D:\My Folder\My !\PC\WINDOWS\DontSleep.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-08-04 159744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{DAE0285D-0788-4E87-985E-01DF2EDE4ACD}"=C:\WINDOWS\system32\Wshxt.dll [2010-08-28 53248]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"HonorAutoRunSetting"=
"NoResolveSearch"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Documents and Settings\Butterfly\Dokumenty\My DAP Downloads\TeamViewerPortable_en\TeamViewer.exe"="C:\Documents and Settings\Butterfly\Dokumenty\My DAP Downloads\TeamViewerPortable_en\TeamViewer.exe:*:Enabled:TeamViewer"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Valve\hltv.exe"="C:\Program Files\Valve\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\Flow\Flow.exe"="C:\Program Files\Flow\Flow.exe:*:Enabled:Flow"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Steam\steamapps\cleverboy\condition zero\hl.exe"="C:\Program Files\Steam\steamapps\cleverboy\condition zero\hl.exe:*:Enabled:Counter-Strike: Condition Zero"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Steam\steamapps\cleverboy\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\cleverboy\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-08-29 12:27:41 ----D---- C:\rsit
2010-08-29 12:22:14 ----A---- C:\WINDOWS\syschecks.dll
2010-08-29 12:22:14 ----A---- C:\WINDOWS\smode.dll
2010-08-29 12:21:59 ----D---- C:\Program Files\SpyMyPC
2010-08-29 11:53:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Zbshareware Lab
2010-08-29 11:53:02 ----D---- C:\Program Files\USB Disk Security
2010-08-29 10:00:30 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-08-28 22:15:29 ----SHD---- C:\RECYCLER
2010-08-28 19:49:53 ----D---- C:\WINDOWS\temp
2010-08-28 18:50:45 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-08-28 17:46:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Montpellier-Informatique
2010-08-28 00:03:24 ----D---- C:\pear
2010-08-27 23:33:26 ----D---- C:\PROTOKOL
2010-08-27 23:33:16 ----A---- C:\WINDOWS\system32\wshxt.dll
2010-08-27 23:33:16 ----A---- C:\WINDOWS\system32\wmsprog.dll
2010-08-27 23:33:16 ----A---- C:\WINDOWS\system32\kernell.dll
2010-08-27 23:21:57 ----D---- C:\Program Files\Hide My IP
2010-08-27 20:51:23 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-27 18:28:58 ----D---- C:\Program Files\Secunia
2010-08-27 16:53:37 ----RSHD---- C:\Documents and Settings\Butterfly\Data aplikací\DisplayDriverTEMP
2010-08-27 16:53:32 ----D---- C:\WINDOWS\XSxS
2010-08-27 13:23:57 ----D---- C:\Shoty
2010-08-27 13:23:51 ----D---- C:\Program Files\ScreenShots
2010-08-27 09:37:41 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\CosmeticGuide
2010-08-27 09:35:29 ----D---- C:\Program Files\Two Pilots
2010-08-27 09:35:28 ----D---- C:\Program Files\Cosmetic Guide
2010-08-26 22:13:21 ----A---- C:\WINDOWS\unvise32.exe
2010-08-26 22:11:08 ----D---- C:\Program Files\MAXON
2010-08-26 18:17:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\ATI
2010-08-26 10:16:58 ----A---- C:\WINDOWS\system32\tmp_docprotector.ini
2010-08-23 20:07:36 ----D---- C:\Program Files\Elecard
2010-08-23 18:30:21 ----D---- C:\WINDOWS\system32\Adobe
2010-08-23 13:11:37 ----D---- C:\Program Files\Common Files\Java
2010-08-23 13:11:05 ----A---- C:\WINDOWS\system32\javaws.exe
2010-08-23 13:11:05 ----A---- C:\WINDOWS\system32\javaw.exe
2010-08-23 13:11:05 ----A---- C:\WINDOWS\system32\java.exe
2010-08-23 11:16:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.TMP
2010-08-23 10:56:41 ----A---- C:\WINDOWS\sndvol32.exe
2010-08-23 10:38:45 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-08-23 10:37:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
2010-08-23 10:36:42 ----D---- C:\PFiles
2010-08-22 22:21:23 ----D---- C:\Program Files\Common Files\Java(3)
2010-08-22 16:49:46 ----D---- C:\Program Files\Codec Pack - All In 1
2010-08-22 12:33:46 ----D---- C:\Program Files\Common Files\Futuremark Shared
2010-08-21 18:40:57 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\ProgSense
2010-08-21 18:40:45 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Orbit
2010-08-20 00:02:25 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Sereniti
2010-08-19 22:12:12 ----D---- C:\VritualRoot
2010-08-19 21:14:19 ----D---- C:\Program Files\Sunbelt Software
2010-08-19 19:49:32 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-08-19 19:47:48 ----D---- C:\Program Files\Alwil Software
2010-08-19 14:52:40 ----D---- C:\WINDOWS\system32\RTCOM
2010-08-19 14:52:17 ----A---- C:\WINDOWS\vncutil.exe
2010-08-19 14:52:17 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-08-19 14:52:17 ----A---- C:\WINDOWS\SkyTel.exe
2010-08-19 14:52:17 ----A---- C:\WINDOWS\RtlUpd.exe
2010-08-19 14:52:16 ----A---- C:\WINDOWS\RTLCPL.EXE
2010-08-19 14:52:14 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-08-19 14:52:11 ----A---- C:\WINDOWS\RTHDCPL.EXE
2010-08-19 14:52:11 ----A---- C:\WINDOWS\MicCal.exe
2010-08-19 14:52:04 ----D---- C:\Program Files\Realtek
2010-08-19 14:52:04 ----A---- C:\WINDOWS\ALCWZRD.EXE
2010-08-19 14:51:04 ----A---- C:\WINDOWS\RtlExUpd.dll
2010-08-19 10:45:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-08-18 16:17:25 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\ATI
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atitvo32.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atiok3x2.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atioglxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ATIODE.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ATIODCLI.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atimpc32.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atikvmag.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\aticalrt.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\aticaldd.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\aticalcl.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atibtmon.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2010-08-18 16:14:27 ----A---- C:\WINDOWS\system32\amdpcom32.dll
2010-08-18 16:13:11 ----D---- C:\ATI
2010-08-18 15:00:04 ----D---- C:\Program Files\ATI
2010-08-18 14:39:47 ----D---- C:\Program Files\ATI Technologies
2010-08-15 15:29:20 ----A---- C:\WINDOWS\system32\nv4_disp.dll-nv1043
2010-08-15 12:50:53 ----D---- C:\Program Files\NVIDIA Corporation
2010-08-15 12:49:50 ----A---- C:\WINDOWS\system32\opencl.dll-nv1428
2010-08-15 12:49:50 ----A---- C:\WINDOWS\system32\nvoglnt.dll-nv1206
2010-08-15 12:49:50 ----A---- C:\WINDOWS\system32\nvcuvid.dll-nv1360
2010-08-15 12:49:50 ----A---- C:\WINDOWS\system32\nvcuvenc.dll-nv1376
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvcuda.dll-nv1347
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvcompiler.dll-nv1389
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvcodins.dll-nv1281
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvcod.dll-nv1281
2010-08-15 12:49:47 ----A---- C:\WINDOWS\system32\nvapi.dll-nv1281
2010-08-15 11:44:21 ----A---- C:\WINDOWS\system32\nsp13.tmp
2010-08-15 11:44:21 ----A---- C:\WINDOWS\system32\nsj12.tmp
2010-08-15 11:44:21 ----A---- C:\WINDOWS\system32\nsa14.tmp
2010-08-15 11:44:20 ----A---- C:\WINDOWS\system32\nsx11.tmp
2010-08-15 11:44:20 ----A---- C:\WINDOWS\system32\nsn10.tmp
2010-08-15 11:44:19 ----A---- C:\WINDOWS\system32\nswF.tmp
2010-08-15 11:44:19 ----A---- C:\WINDOWS\system32\nsqE.tmp
2010-08-15 11:44:18 ----A---- C:\WINDOWS\system32\nszC.tmp
2010-08-15 11:44:15 ----A---- C:\WINDOWS\system32\nslB.tmp
2010-08-15 11:44:14 ----A---- C:\WINDOWS\system32\nsjA.tmp
2010-08-15 11:44:13 ----A---- C:\WINDOWS\system32\nsl9.tmp
2010-08-15 11:44:10 ----A---- C:\WINDOWS\system32\nsr7.tmp
2010-08-15 11:44:10 ----A---- C:\WINDOWS\nsc8.tmp
2010-08-15 11:44:09 ----A---- C:\WINDOWS\system32\nsa6.tmp
2010-08-13 14:15:02 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-13 14:14:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-08-13 14:14:12 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-13 14:13:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-13 14:06:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-13 14:06:37 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-13 14:04:24 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-13 14:03:28 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-07 10:19:46 ----A---- C:\WINDOWS\system32\vuins32.dll
2010-08-07 10:19:46 ----A---- C:\WINDOWS\system32\difxapi.dll
2010-08-06 23:55:15 ----A---- C:\WINDOWS\BricoPackFoldersDelete.cmd
2010-08-05 09:14:47 ----D---- C:\WINDOWS\NV35361800.TMP
2010-08-04 10:12:53 ----D---- C:\WINDOWS\NV23721612.TMP
2010-08-03 09:57:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-08-02 11:39:02 ----A---- C:\WINDOWS\system32\P1131Vfw.dll
2010-08-02 11:39:02 ----A---- C:\WINDOWS\P1131Cfg.exe
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\P1131Sti.dll
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\P1131Srv.exe
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\P1131Pin.dll
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\P1131Hwx.dll
2010-08-02 11:39:01 ----A---- C:\WINDOWS\system32\CtCamMgr.dll
2010-08-02 11:34:47 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-08-02 11:33:49 ----D---- C:\WINDOWS\CtDrvInstall
2010-08-02 11:33:37 ----A---- C:\WINDOWS\CtDrvIns.exe
2010-08-02 11:33:33 ----D---- C:\WebCamNXPro
2010-08-01 20:46:44 ----A---- C:\WINDOWS\system32\nvcodins.dll-nv22389
2010-08-01 20:46:43 ----A---- C:\WINDOWS\system32\nvcod.dll-nv22389
2010-08-01 20:46:35 ----A---- C:\WINDOWS\system32\nvoglnt.dll-nv22383
2010-08-01 20:46:33 ----A---- C:\WINDOWS\system32\nvcuvid.dll-nv22396
2010-08-01 20:46:31 ----A---- C:\WINDOWS\system32\nvcuvenc.dll-nv22399
2010-08-01 20:46:28 ----A---- C:\WINDOWS\system32\nvcuda.dll-nv22396
2010-08-01 20:46:25 ----A---- C:\WINDOWS\system32\nvcompiler.dll-nv22399
2010-08-01 20:46:24 ----A---- C:\WINDOWS\system32\nvapi.dll-nv22393
2010-08-01 20:46:20 ----A---- C:\WINDOWS\system32\nv4_disp.dll-nv22376
2010-08-01 20:46:19 ----A---- C:\WINDOWS\system32\opencl.dll-nv22402
2010-08-01 14:53:02 ----D---- C:\WINDOWS\NV33763424.TMP
2010-08-01 13:58:48 ----D---- C:\WINDOWS\NV40402576.TMP
2010-07-30 23:04:31 ----A---- C:\WINDOWS\system32\rewire.dll
2010-07-30 22:58:59 ----D---- C:\Program Files\Image-Line
2010-07-30 18:16:32 ----D---- C:\Program Files\Sony
2010-07-30 18:12:44 ----D---- C:\Program Files\Sony Setup

======List of files/folders modified in the last 1 months======

2010-08-29 12:28:04 ----D---- C:\Program Files\Trend Micro
2010-08-29 12:22:14 ----D---- C:\WINDOWS
2010-08-29 12:21:59 ----D---- C:\Program Files
2010-08-29 11:36:59 ----D---- C:\WINDOWS\Prefetch
2010-08-29 11:28:30 ----SD---- C:\WINDOWS\Tasks
2010-08-29 11:04:53 ----D---- C:\Program Files\Steam
2010-08-29 11:00:25 ----SHD---- C:\System Volume Information
2010-08-29 11:00:25 ----D---- C:\WINDOWS\system32\Restore
2010-08-29 10:00:50 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-08-29 10:00:38 ----SHD---- C:\WINDOWS\Installer
2010-08-29 10:00:38 ----D---- C:\Config.Msi
2010-08-29 10:00:30 ----D---- C:\WINDOWS\system32
2010-08-29 09:36:26 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-08-28 23:53:45 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Skype
2010-08-28 22:15:29 ----D---- C:\WINDOWS\Minidump
2010-08-28 22:09:01 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\skypePM
2010-08-28 19:49:54 ----D---- C:\WINDOWS\system32\drivers
2010-08-28 19:46:24 ----A---- C:\WINDOWS\system.ini
2010-08-28 19:44:15 ----D---- C:\WINDOWS\AppPatch
2010-08-28 19:44:13 ----D---- C:\Program Files\Common Files
2010-08-28 14:01:03 ----D---- C:\Program Files\Debugging Tools for Windows (x86)
2010-08-27 18:34:29 ----HD---- C:\WINDOWS\inf
2010-08-27 16:40:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-08-27 16:40:27 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Real
2010-08-27 15:02:10 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-08-26 19:01:57 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\dvdcss
2010-08-26 18:38:38 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\vlc
2010-08-26 18:13:31 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-26 18:13:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-08-26 18:12:58 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-08-26 17:58:54 ----ASH---- C:\boot.ini
2010-08-26 17:58:54 ----A---- C:\WINDOWS\win.ini
2010-08-26 16:02:32 ----D---- C:\Program Files\AIMP2
2010-08-26 11:19:25 ----D---- C:\Program Files\CCleaner
2010-08-26 10:23:48 ----D---- C:\Program Files\Mozilla Firefox 4.0 Beta 1
2010-08-25 22:28:56 ----D---- C:\Program Files\WhoCrashed
2010-08-25 13:46:54 ----D---- C:\Program Files\SystemRequirementsLab
2010-08-25 12:55:51 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\gtk-2.0
2010-08-24 00:53:33 ----D---- C:\WINDOWS\system32\config
2010-08-23 21:26:18 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Mozilla
2010-08-23 13:10:45 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-08-23 12:25:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2010-08-23 12:24:32 ----D---- C:\Program Files\DivX
2010-08-23 11:59:17 ----SHD---- C:\WINDOWS\CSC
2010-08-23 11:15:56 ----A---- C:\WINDOWS\UPGRADE.TXT
2010-08-23 10:39:43 ----D---- C:\WINDOWS\system32\wbem
2010-08-23 10:39:42 ----D---- C:\WINDOWS\Registration
2010-08-23 00:57:36 ----D---- C:\Program Files\Adobe
2010-08-22 17:03:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-08-22 12:33:45 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-22 11:22:43 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\KeePass
2010-08-21 10:27:00 ----D---- C:\WINDOWS\Help
2010-08-20 22:10:35 ----A---- C:\WINDOWS\system32\resetlog.txt
2010-08-20 21:59:27 ----D---- C:\WINDOWS\network diagnostic
2010-08-19 21:47:27 ----D---- C:\Program Files\Google
2010-08-19 21:35:26 ----D---- C:\Program Files\QuickTime
2010-08-19 19:49:57 ----D---- C:\WINDOWS\WinSxS
2010-08-19 19:49:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-08-19 11:01:16 ----D---- C:\Program Files\Defraggler
2010-08-19 10:58:11 ----D---- C:\Program Files\FileHippo.com
2010-08-18 23:12:41 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\HLSW
2010-08-18 23:09:40 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Samsung
2010-08-18 23:09:33 ----D---- C:\Program Files\Samsung
2010-08-18 22:31:21 ----D---- C:\Program Files\Opera
2010-08-18 14:09:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2010-08-13 21:06:45 ----D---- C:\WINDOWS\Debug
2010-08-13 14:19:26 ----RSD---- C:\WINDOWS\assembly
2010-08-13 14:15:00 ----HD---- C:\WINDOWS\$hf_mig$
2010-08-13 14:13:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-08-13 14:11:33 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-13 14:10:49 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-13 14:07:12 ----D---- C:\Program Files\Internet Explorer
2010-08-13 14:07:00 ----D---- C:\WINDOWS\ie8updates
2010-08-13 14:04:26 ----D---- C:\Program Files\Movie Maker
2010-08-07 17:13:55 ----D---- C:\Program Files\Trillian
2010-08-07 17:13:13 ----D---- C:\Documents and Settings\Butterfly\Data aplikací\Trillian
2010-08-07 09:30:03 ----D---- C:\WINDOWS\Cursors
2010-08-07 09:30:02 ----RSD---- C:\WINDOWS\Fonts
2010-08-07 09:30:02 ----D---- C:\WINDOWS\Media
2010-08-07 09:30:02 ----D---- C:\Program Files\Outlook Express
2010-08-07 09:30:01 ----D---- C:\WINDOWS\system32\usmt
2010-08-07 00:00:08 ----A---- C:\WINDOWS\BricoPackUninst.txt
2010-08-07 00:00:08 ----A---- C:\WINDOWS\BricoPackUninst.cmd
2010-08-06 23:54:35 ----D---- C:\WINDOWS\BricoPacks
2010-08-04 03:46:04 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2010-08-04 03:41:40 ----A---- C:\WINDOWS\system32\ati3duag.dll
2010-08-04 03:28:06 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2010-08-04 03:16:50 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2010-08-03 20:09:31 ----A---- C:\WINDOWS\system32\MRT.exe
2010-08-02 11:54:48 ----D---- C:\Program Files\Safari
2010-08-02 11:34:58 ----D---- C:\WINDOWS\twain_32

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-06-28 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-06-28 165456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-06-28 46672]
R1 BIOS;BIOS; \??\C:\WINDOWS\system32\drivers\BIOS.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-06-28 17744]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-06-28 100176]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-06-28 23376]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-08-04 5243392]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2010-05-17 101904]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2009-06-16 46592]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-07-28 6108776]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-25 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2005-01-05 6912]
R3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2005-06-06 11264]
S1 Winhpfile;Winhpfile; C:\WINDOWS\system32\drivers\Winhpfile.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 DrvAgent32;DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2010-04-03 223128]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-01-09 42496]
S3 gHidPnp;USB Device Enhanced Function Driver; C:\WINDOWS\System32\Drivers\gHidPnp.Sys [2009-03-06 18944]
S3 gMouUsb;USB Mouse Device Drv; C:\WINDOWS\system32\DRIVERS\gMouUsb.sys [2009-03-04 11520]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 msloop;Microsoft Loopback Adapter Driver; C:\WINDOWS\system32\DRIVERS\loop.sys [2001-08-17 4992]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 NTSIM;NTSIM; \??\C:\WINDOWS\system32\ntsim.sys []
S3 P1131VID;Creative WebCam NX Pro (WDM); C:\WINDOWS\system32\DRIVERS\P1131Vid.sys [2004-03-26 91241]
S3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2010-03-19 19072]
S3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2008-02-25 105088]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2008-02-22 87936]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2008-02-22 14976]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2008-02-22 114304]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 tap0901_2gm;VPN Anonymizer Adapter; C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 30720]
S3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2010-06-23 32768]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2009-05-23 29696]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2009-01-30 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-08-04 606208]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-08-23 153376]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-08-27 1051968]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 HideMyIpSRV;HideMyIpSRV; C:\Program Files\Hide My IP\HideMyIpSrv.exe [2010-04-10 2752816]
S2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-21 136176]
S2 HDDlife HDD Access service;HDDlife HDD Access service; C:\Program Files\Common Files\BinarySense\hldasvc.exe [2009-08-19 822936]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-05-31 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MatSvc;Microsoft Automated Troubleshooting Service; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-08-29 435008]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-01-30 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosim o kontrolu - Blue screen hpfile.sys

#14 Příspěvek od motji »

Tento program jste si instaloval sám?
- C:\Program Files\SpyMyPC

Hlídacího psa by jste měl správně v nouzovém režimu odinstalovat, protože jinak v pc zůstává, i kdžy si myslíte, že je smazaný :o
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BOnioo1775
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 24 dub 2010 09:52

Re: Prosim o kontrolu - Blue screen hpfile.sys

#15 Příspěvek od BOnioo1775 »

jo sam ,

Hlidaci pes nesel odinstalovat standardnim postupem..musel jsem zmacknout klavesou zkratku a zvolit odinstalovat ,jenze to neslo.Tak jsem zvolil nestandardni postup.

Pokud uz není ,co ke smazaní,tak je to asi vse ))

diky za Váš čas.

BOnioo*

Odpovědět