Stránka 1 z 1

Preventivní log (prosim o kontrolu)

Napsal: 28 črc 2011 22:31
od nom
Logfile of random's system information tool 1.09 (written by random/random)
Run by HITTL ROMAN at 2011-07-28 23:15:23
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 49 GB (11%) free of 464 GB
Total RAM: 4091 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:15:29, on 28.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\WeFi\WeFi.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
C:\Program Files (x86)\Mumble\mumble.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\HITTL ROMAN.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
O3 - Toolbar: Trillian Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [NBstat] C:\Users\HITTL ROMAN\Desktop\NBSTAT.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [WinArranger] "C:\Program Files (x86)\ManageBytes\WinArranger\WinArranger.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [BitComet] "H:\Anime\BitLord\BitLord.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: BatteryBar.lnk = C:\Program Files\BatteryBar\BatteryBar.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Trillian.lnk = C:\Program Files (x86)\Trillian\trillian.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra button: Unibet - {EF0124FD-AA19-45A0-A233-705CC28AA847} - C:\Microgaming\Poker\unibetpokerMPP\MPPoker.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~2\Google\GOOGLE~2\GO36F4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Autodesk Content Service - Unknown owner - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sentinel Keys Server (SentinelKeysServer) - SafeNet, Inc. - C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WeFi Engine Service (WefiEngSvc) - WeFi - C:\Program Files (x86)\WeFi\WefiEngSvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12844 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Acer\Registration\GREGsvc.exe"
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
"C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe"
"C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2408
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-1f96f2cf-ff9f-4d64-98d8-23f9458d633c -SystemEventPortName:HostProcess-8594ccbf-90cf-444b-b6d6-b21c9e944b4f -IoCancelEventPortName:HostProcess-2c3bd693-9cfe-44e6-8a05-775a6f9fd033 -NonStateChangingEventPortName:HostProcess-58583950-d2bf-41e4-b735-c718332a12c9 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:440d8126-e1b9-471b-a3d7-4969aaedfc94
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\WeFi\WefiEngSvc.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\WeFi\WeFi.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe"
"C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
"C:\Program Files (x86)\Launch Manager\LMworker.exe"
"C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Windows\explorer.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe" /handleDdeError Excel /launchResult SFT-cea2c2fc-17be-4c94-bbd0-104d3515846a /launch "Microsoft Excel Starter 2010 9014006604050000" /dde
"C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe" /start IDLE_APP_EVENT_{90140011-0066-0405-0000-0000000FF1CE}
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Mumble\mumble.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4552.8443e80.1757610359 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 4552 plugin \\.\pipe\gecko-crash-server-pipe.4552
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe11_ Global\UsGthrCtrlFltPipeMssGthrPipe11 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
"C:\Users\HITTL ROMAN\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\BearShareNAG.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\WefiStartup.job

=========Mozilla firefox=========

ProfilePath - C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://my.daemon-search.com/|http://start.icq.com/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, jklir@volny.cz:0.3.8, {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.11.2.1, {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, toolbar@ask.com:3.12.5.17640, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.18"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.6&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GoogleDesktopMozilla.dll
GoogleDesktopMozillaStub.js
GoogleDesktopMozillaStub.xpt
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npnul32.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
googledesktop.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\
DTToolbar@toolbarnet.com
jklir@volny.cz
toolbar@ask.com
{e3f6c2cc-d8db-498c-af6c-499fb211db97}

C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\searchplugins\
daemon-search.xml
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-27 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar BHO - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll [2010-10-11 612616]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Trillian Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-07-26 1493160]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2011-01-20 1581376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2011-01-20 988480]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-06-02 1018616]
{8dcb7100-df86-4384-8842-8fa844297b3f} - @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100 - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll [2010-10-11 612616]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Trillian Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-07-26 1493160]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-06-22 10920552]
"mwlDaemon"=C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [2010-05-27 349552]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-12-10 1890088]
"PLFSetI"=C:\Windows\PLFSetI.exe [2010-11-20 206208]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2010-07-29 594080]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2010-07-29 377504]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2010-06-12 861216]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-12 2918656]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WinArranger"=C:\Program Files (x86)\ManageBytes\WinArranger\WinArranger.exe [2005-10-10 214016]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"DriverMax"= []
"DriverMax_RESTART"= []
"BitComet"=H:\Anime\BitLord\BitLord.exe []
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2011-07-03 3077528]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SuiteTray"=C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [2010-05-27 337264]
"EgisUpdate"=C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [2010-03-11 201584]
"EgisTecPMMUpdate"=C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [2010-03-11 407920]
"Norton Online Backup"=C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2010-06-02 1155928]
"BackupManagerTray"=C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2010-06-29 265984]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-04-21 98304]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2010-08-10 975952]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-10 439568]
"NBstat"=C:\Users\HITTL [2011-06-22 2214]
"Google Desktop Search"=C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2011-05-05 30192]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
""= []
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2011-07-26 397992]

C:\Users\HITTL ROMAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
BatteryBar.lnk - C:\Program Files\BatteryBar\BatteryBar.exe
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
Trillian.lnk - C:\Program Files (x86)\Trillian\trillian.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll

Re: Preventivní log (prosim o kontrolu)

Napsal: 28 črc 2011 22:33
od nom
======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 3 months======

2011-07-28 23:15:24 ----D---- C:\Program Files\trend micro
2011-07-28 23:15:23 ----D---- C:\rsit
2011-07-22 22:00:10 ----D---- C:\Program Files (x86)\Jolicloud USB Creator
2011-07-13 20:09:31 ----D---- C:\ProgramData\AWEM
2011-07-13 20:09:31 ----D---- C:\ProgramData\AlawarWrapper
2011-07-13 20:09:27 ----D---- C:\Program Files (x86)\Hry.cz
2011-07-13 08:43:44 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 08:43:43 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-13 08:43:42 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 08:43:42 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 08:43:39 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 08:43:38 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 08:43:37 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 08:43:33 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-07-13 08:43:33 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-07-13 08:43:29 ----A---- C:\Windows\system32\win32k.sys
2011-07-13 08:43:23 ----A---- C:\Windows\system32\wow64win.dll
2011-07-13 08:43:23 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 08:43:23 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 08:43:23 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 08:43:22 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-13 08:43:22 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-13 08:43:22 ----A---- C:\Windows\system32\wow64.dll
2011-07-13 08:43:21 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-13 08:43:21 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-13 08:43:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-13 08:43:21 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-13 08:43:21 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-13 08:43:19 ----A---- C:\Windows\SYSWOW64\user.exe
2011-07-11 13:25:59 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\Rovio
2011-07-11 13:25:23 ----D---- C:\Program Files (x86)\Rovio
2011-07-05 21:32:05 ----D---- C:\ProgramData\PopCap Games
2011-07-03 22:36:15 ----D---- C:\gPotato.com
2011-07-03 17:30:42 ----D---- C:\ProgramData\PMB Files
2011-07-03 17:30:16 ----D---- C:\Program Files (x86)\Pando Networks
2011-07-03 09:28:27 ----D---- C:\Windows\system32\SPReview
2011-07-03 09:26:38 ----D---- C:\Windows\system32\EventProviders
2011-07-02 00:57:47 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\Mount&Blade Warband
2011-07-02 00:51:30 ----D---- C:\Program Files (x86)\Mount&Blade Warband
2011-07-01 15:14:53 ----D---- C:\Program Files (x86)\Vitware
2011-07-01 15:14:44 ----D---- C:\Windows\SYSWOW64\Lessons
2011-07-01 14:37:24 ----D---- C:\Program Files (x86)\Intelore
2011-07-01 13:37:30 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\wordtester
2011-07-01 13:14:45 ----D---- C:\Program Files (x86)\Word Tester
2011-07-01 11:52:24 ----D---- C:\Program Files (x86)\Moje slovíčka
2011-06-30 11:57:50 ----D---- C:\Program Files (x86)\WebKeySoft
2011-06-29 07:39:44 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-06-29 07:39:44 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-29 07:39:44 ----A---- C:\Windows\system32\cfgmgr32.dll
2011-06-29 07:39:43 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-06-29 07:39:43 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-06-29 07:39:43 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-06-29 07:39:41 ----A---- C:\Windows\system32\tquery.dll
2011-06-29 07:39:41 ----A---- C:\Windows\system32\mssrch.dll
2011-06-29 07:39:40 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-06-29 07:39:40 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-06-29 07:39:39 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-29 07:39:39 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-29 07:39:39 ----A---- C:\Windows\system32\mssvp.dll
2011-06-29 07:39:38 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-06-29 07:39:38 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-06-29 07:39:38 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-06-29 07:39:38 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-06-29 07:39:38 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-29 07:39:38 ----A---- C:\Windows\system32\mssph.dll
2011-06-29 07:39:37 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-06-29 07:39:37 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-06-29 07:39:37 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-29 07:39:37 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-29 07:39:36 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-06-27 15:43:13 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\OpenCandy
2011-06-27 15:43:13 ----D---- C:\Program Files (x86)\Cheat Engine 6.1
2011-06-23 21:24:29 ----A---- C:\Windows\system32\netfxperf.dll
2011-06-23 21:24:29 ----A---- C:\Windows\system32\dfshim.dll
2011-06-23 21:24:21 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-06-23 21:24:17 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-06-23 21:24:17 ----A---- C:\Windows\system32\mstscax.dll
2011-06-23 21:24:17 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2011-06-23 21:24:17 ----A---- C:\Windows\system32\d3d10warp.dll
2011-06-23 21:24:12 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-06-23 21:24:09 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-06-23 21:24:09 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-06-23 21:24:08 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-06-23 21:24:08 ----A---- C:\Windows\system32\sysmain.dll
2011-06-23 21:24:08 ----A---- C:\Windows\system32\shell32.dll
2011-06-23 21:24:05 ----A---- C:\Windows\system32\MSVidCtl.dll
2011-06-23 21:24:03 ----A---- C:\Windows\system32\wmp.dll
2011-06-23 21:23:59 ----A---- C:\Windows\system32\ntdll.dll
2011-06-23 21:23:59 ----A---- C:\Windows\system32\mscoree.dll
2011-06-23 21:23:59 ----A---- C:\Windows\system32\mmcndmgr.dll
2011-06-23 21:23:57 ----A---- C:\Windows\system32\secproc_isv.dll
2011-06-23 21:23:57 ----A---- C:\Windows\system32\mf.dll
2011-06-23 21:23:56 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-06-23 21:23:55 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2011-06-23 21:23:55 ----A---- C:\Windows\system32\xpsservices.dll
2011-06-23 21:23:55 ----A---- C:\Windows\system32\secproc.dll
2011-06-23 21:23:55 ----A---- C:\Windows\system32\RMActivate.exe
2011-06-23 21:23:54 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-06-23 21:23:51 ----A---- C:\Windows\SYSWOW64\secproc.dll
2011-06-23 21:23:51 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2011-06-23 21:23:51 ----A---- C:\Windows\system32\rpcrt4.dll
2011-06-23 21:23:50 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2011-06-23 21:23:50 ----A---- C:\Windows\system32\schedsvc.dll
2011-06-23 21:23:50 ----A---- C:\Windows\system32\ole32.dll
2011-06-23 21:23:49 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-06-23 21:23:49 ----A---- C:\Windows\system32\spwizui.dll
2011-06-23 21:23:48 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-06-23 21:23:48 ----A---- C:\Windows\system32\wevtsvc.dll
2011-06-23 21:23:48 ----A---- C:\Windows\system32\taskschd.dll
2011-06-23 21:23:48 ----A---- C:\Windows\system32\RacEngn.dll
2011-06-23 21:23:48 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-06-23 21:23:48 ----A---- C:\Windows\system32\diagperf.dll
2011-06-23 21:23:47 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2011-06-23 21:23:47 ----A---- C:\Windows\system32\vssapi.dll
2011-06-23 21:23:47 ----A---- C:\Windows\system32\msxml3.dll
2011-06-23 21:23:47 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2011-06-23 21:23:46 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2011-06-23 21:23:45 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2011-06-23 21:23:44 ----A---- C:\Windows\system32\UIRibbon.dll
2011-06-23 21:23:41 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-06-23 21:23:39 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-06-23 21:23:39 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-06-23 21:23:39 ----A---- C:\Windows\system32\WsmSvc.dll
2011-06-23 21:23:39 ----A---- C:\Windows\system32\WMVCORE.DLL
2011-06-23 21:23:39 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-06-23 21:23:39 ----A---- C:\Windows\system32\PresentationHost.exe
2011-06-23 21:23:38 ----A---- C:\Windows\system32\rdpdd.dll
2011-06-23 21:23:38 ----A---- C:\Windows\system32\MPSSVC.dll
2011-06-23 21:23:37 ----A---- C:\Windows\system32\WinSAT.exe
2011-06-23 21:23:37 ----A---- C:\Windows\system32\spreview.exe
2011-06-23 21:23:37 ----A---- C:\Windows\system32\spinstall.exe
2011-06-23 21:23:37 ----A---- C:\Windows\system32\CertEnroll.dll
2011-06-23 21:23:36 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-06-23 21:23:36 ----A---- C:\Windows\system32\d3d9.dll
2011-06-23 21:23:35 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2011-06-23 21:23:35 ----A---- C:\Windows\system32\SearchFolder.dll
2011-06-23 21:23:35 ----A---- C:\Windows\system32\msxml6.dll
2011-06-23 21:23:35 ----A---- C:\Windows\system32\IKEEXT.DLL
2011-06-23 21:23:34 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2011-06-23 21:23:34 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2011-06-23 21:23:33 ----A---- C:\Windows\system32\VSSVC.exe
2011-06-23 21:23:33 ----A---- C:\Windows\system32\mstime.dll
2011-06-23 21:23:33 ----A---- C:\Windows\system32\gpsvc.dll
2011-06-23 21:23:33 ----A---- C:\Windows\system32\dwmcore.dll
2011-06-23 21:23:33 ----A---- C:\Windows\system32\drivers\http.sys
2011-06-23 21:23:33 ----A---- C:\Windows\system32\dbgeng.dll
2011-06-23 21:23:31 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-06-23 21:23:31 ----A---- C:\Windows\system32\drivers\ndis.sys
2011-06-23 21:23:31 ----A---- C:\Windows\system32\crypt32.dll
2011-06-23 21:23:30 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-06-23 21:23:30 ----A---- C:\Windows\system32\TSWorkspace.dll
2011-06-23 21:23:30 ----A---- C:\Windows\system32\schannel.dll
2011-06-23 21:23:30 ----A---- C:\Windows\system32\qmgr.dll
2011-06-23 21:23:30 ----A---- C:\Windows\system32\lsasrv.dll
2011-06-23 21:23:30 ----A---- C:\Windows\system32\audiosrv.dll
2011-06-23 21:23:30 ----A---- C:\Windows\system32\actxprxy.dll
2011-06-23 21:23:29 ----A---- C:\Windows\system32\termsrv.dll
2011-06-23 21:23:29 ----A---- C:\Windows\system32\sqmapi.dll
2011-06-23 21:23:29 ----A---- C:\Windows\system32\mstsc.exe
2011-06-23 21:23:27 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2011-06-23 21:23:27 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2011-06-23 21:23:27 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2011-06-23 21:23:27 ----A---- C:\Windows\system32\winhttp.dll
2011-06-23 21:23:27 ----A---- C:\Windows\system32\QAGENTRT.DLL
2011-06-23 21:23:27 ----A---- C:\Windows\system32\propsys.dll
2011-06-23 21:23:27 ----A---- C:\Windows\system32\netlogon.dll
2011-06-23 21:23:27 ----A---- C:\Windows\system32\msv1_0.dll
2011-06-23 21:23:27 ----A---- C:\Windows\system32\imapi2fs.dll
2011-06-23 21:23:27 ----A---- C:\Windows\system32\d3d11.dll
2011-06-23 21:23:26 ----A---- C:\Windows\system32\setupapi.dll
2011-06-23 21:23:26 ----A---- C:\Windows\system32\rpcss.dll
2011-06-23 21:23:25 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-06-23 21:23:25 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2011-06-23 21:23:25 ----A---- C:\Windows\system32\werconcpl.dll
2011-06-23 21:23:25 ----A---- C:\Windows\system32\wbengine.exe
2011-06-23 21:23:25 ----A---- C:\Windows\system32\taskeng.exe
2011-06-23 21:23:25 ----A---- C:\Windows\system32\odbc32.dll
2011-06-23 21:23:25 ----A---- C:\Windows\system32\authui.dll
2011-06-23 21:23:24 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-06-23 21:23:24 ----A---- C:\Windows\system32\WSDApi.dll
2011-06-23 21:23:24 ----A---- C:\Windows\system32\user32.dll
2011-06-23 21:23:24 ----A---- C:\Windows\system32\drivers\netio.sys
2011-06-23 21:23:23 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-06-23 21:23:23 ----A---- C:\Windows\system32\scavengeui.dll
2011-06-23 21:23:23 ----A---- C:\Windows\system32\drivers\tdx.sys
2011-06-23 21:23:23 ----A---- C:\Windows\system32\drivers\netbt.sys
2011-06-23 21:23:23 ----A---- C:\Windows\system32\dhcpcore.dll
2011-06-23 21:23:23 ----A---- C:\Windows\system32\certmgr.dll
2011-06-23 21:23:22 ----A---- C:\Windows\SYSWOW64\wer.dll
2011-06-23 21:23:22 ----A---- C:\Windows\SYSWOW64\certcli.dll
2011-06-23 21:23:22 ----A---- C:\Windows\system32\webio.dll
2011-06-23 21:23:22 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2011-06-23 21:23:22 ----A---- C:\Windows\system32\localspl.dll
2011-06-23 21:23:21 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-06-23 21:23:21 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2011-06-23 21:23:21 ----A---- C:\Windows\system32\tsmf.dll
2011-06-23 21:23:21 ----A---- C:\Windows\system32\shlwapi.dll
2011-06-23 21:23:21 ----A---- C:\Windows\system32\ncsi.dll
2011-06-23 21:23:21 ----A---- C:\Windows\system32\msdtctm.dll
2011-06-23 21:23:21 ----A---- C:\Windows\system32\msdrm.dll
2011-06-23 21:23:20 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-06-23 21:23:20 ----A---- C:\Windows\system32\netshell.dll
2011-06-23 21:23:20 ----A---- C:\Windows\system32\framedynos.dll
2011-06-23 21:23:20 ----A---- C:\Windows\system32\drivers\cng.sys
2011-06-23 21:23:19 ----A---- C:\Windows\SYSWOW64\tcpmonui.dll
2011-06-23 21:23:19 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-06-23 21:23:19 ----A---- C:\Windows\system32\winlogon.exe
2011-06-23 21:23:19 ----A---- C:\Windows\system32\netcfgx.dll
2011-06-23 21:23:18 ----A---- C:\Windows\system32\ws2_32.dll
2011-06-23 21:23:18 ----A---- C:\Windows\system32\usp10.dll
2011-06-23 21:23:17 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2011-06-23 21:23:17 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-06-23 21:23:17 ----A---- C:\Windows\system32\wmpps.dll
2011-06-23 21:23:17 ----A---- C:\Windows\system32\quartz.dll
2011-06-23 21:23:17 ----A---- C:\Windows\system32\nlasvc.dll
2011-06-23 21:23:17 ----A---- C:\Windows\system32\lsm.exe
2011-06-23 21:23:17 ----A---- C:\Windows\system32\dxgi.dll
2011-06-23 21:23:17 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2011-06-23 21:23:17 ----A---- C:\Windows\system32\comdlg32.dll
2011-06-23 21:23:17 ----A---- C:\Windows\system32\apphelp.dll
2011-06-23 21:23:16 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-06-23 21:23:16 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2011-06-23 21:23:16 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-06-23 21:23:16 ----A---- C:\Windows\SYSWOW64\dot3api.dll
2011-06-23 21:23:16 ----A---- C:\Windows\system32\wpdshext.dll
2011-06-23 21:23:16 ----A---- C:\Windows\system32\Query.dll
2011-06-23 21:23:16 ----A---- C:\Windows\system32\mswsock.dll
2011-06-23 21:23:16 ----A---- C:\Windows\system32\azroles.dll
2011-06-23 21:23:15 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2011-06-23 21:23:15 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2011-06-23 21:23:15 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2011-06-23 21:23:15 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2011-06-23 21:23:15 ----A---- C:\Windows\system32\Vault.dll
2011-06-23 21:23:15 ----A---- C:\Windows\system32\samsrv.dll
2011-06-23 21:23:15 ----A---- C:\Windows\system32\QAGENT.DLL
2011-06-23 21:23:15 ----A---- C:\Windows\system32\lpksetup.exe
2011-06-23 21:23:15 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2011-06-23 21:23:15 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-06-23 21:23:15 ----A---- C:\Windows\system32\cmd.exe
2011-06-23 21:23:15 ----A---- C:\Windows\system32\BFE.DLL
2011-06-23 21:23:14 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2011-06-23 21:23:14 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2011-06-23 21:23:14 ----A---- C:\Windows\system32\win32spl.dll
2011-06-23 21:23:13 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-06-23 21:23:13 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2011-06-23 21:23:13 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2011-06-23 21:23:13 ----A---- C:\Windows\system32\WindowsCodecs.dll
2011-06-23 21:23:13 ----A---- C:\Windows\system32\WebClnt.dll
2011-06-23 21:23:12 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2011-06-23 21:23:12 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-06-23 21:23:12 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-06-23 21:23:12 ----A---- C:\Windows\SYSWOW64\Query.dll
2011-06-23 21:23:12 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2011-06-23 21:23:12 ----A---- C:\Windows\system32\Wldap32.dll
2011-06-23 21:23:12 ----A---- C:\Windows\system32\taskcomp.dll
2011-06-23 21:23:12 ----A---- C:\Windows\system32\sxs.dll
2011-06-23 21:23:12 ----A---- C:\Windows\system32\mfds.dll
2011-06-23 21:23:12 ----A---- C:\Windows\system32\mcbuilder.exe
2011-06-23 21:23:12 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2011-06-23 21:23:11 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-06-23 21:23:11 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-06-23 21:23:11 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2011-06-23 21:23:11 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2011-06-23 21:23:11 ----A---- C:\Windows\SYSWOW64\imapi2fs.dll
2011-06-23 21:23:11 ----A---- C:\Windows\SYSWOW64\DShowRdpFilter.dll
2011-06-23 21:23:11 ----A---- C:\Windows\system32\wuaueng.dll
2011-06-23 21:23:11 ----A---- C:\Windows\system32\webservices.dll
2011-06-23 21:23:11 ----A---- C:\Windows\system32\SessEnv.dll
2011-06-23 21:23:11 ----A---- C:\Windows\system32\pnidui.dll
2011-06-23 21:23:11 ----A---- C:\Windows\system32\ipsmsnap.dll
2011-06-23 21:23:11 ----A---- C:\Windows\system32\hgprint.dll
2011-06-23 21:23:10 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2011-06-23 21:23:10 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2011-06-23 21:23:10 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2011-06-23 21:23:10 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2011-06-23 21:23:10 ----A---- C:\Windows\SYSWOW64\authui.dll
2011-06-23 21:23:10 ----A---- C:\Windows\system32\winsta.dll
2011-06-23 21:23:10 ----A---- C:\Windows\system32\sqlsrv32.dll
2011-06-23 21:23:10 ----A---- C:\Windows\system32\spoolsv.exe
2011-06-23 21:23:10 ----A---- C:\Windows\system32\iepeers.dll
2011-06-23 21:23:10 ----A---- C:\Windows\system32\fveapi.dll
2011-06-23 21:23:10 ----A---- C:\Windows\system32\dot3api.dll
2011-06-23 21:23:09 ----A---- C:\Windows\SYSWOW64\usp10.dll
2011-06-23 21:23:09 ----A---- C:\Windows\SYSWOW64\mcbuilder.exe
2011-06-23 21:23:09 ----A---- C:\Windows\system32\schtasks.exe
2011-06-23 21:23:09 ----A---- C:\Windows\system32\prncache.dll
2011-06-23 21:23:09 ----A---- C:\Windows\system32\mcmde.dll
2011-06-23 21:23:09 ----A---- C:\Windows\system32\gdi32.dll
2011-06-23 21:23:09 ----A---- C:\Windows\system32\drivers\volsnap.sys
2011-06-23 21:23:09 ----A---- C:\Windows\system32\drivers\msrpc.sys
2011-06-23 21:23:08 ----A---- C:\Windows\SYSWOW64\userenv.dll
2011-06-23 21:23:08 ----A---- C:\Windows\SYSWOW64\certmgr.dll
2011-06-23 21:23:08 ----A---- C:\Windows\system32\wuapi.dll
2011-06-23 21:23:08 ----A---- C:\Windows\system32\WMNetMgr.dll
2011-06-23 21:23:08 ----A---- C:\Windows\system32\wlanpref.dll
2011-06-23 21:23:08 ----A---- C:\Windows\system32\vpnike.dll
2011-06-23 21:23:08 ----A---- C:\Windows\system32\userenv.dll
2011-06-23 21:23:07 ----A---- C:\Windows\SYSWOW64\xpsservices.dll
2011-06-23 21:23:07 ----A---- C:\Windows\system32\wintrust.dll
2011-06-23 21:23:07 ----A---- C:\Windows\system32\drivers\rdbss.sys
2011-06-23 21:23:06 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-06-23 21:23:06 ----A---- C:\Windows\system32\photowiz.dll
2011-06-23 21:23:06 ----A---- C:\Windows\system32\evr.dll
2011-06-23 21:23:06 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2011-06-23 21:23:05 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2011-06-23 21:23:03 ----A---- C:\Windows\SYSWOW64\cmd.exe
2011-06-23 21:23:03 ----A---- C:\Windows\system32\wmpmde.dll
2011-06-23 21:23:03 ----A---- C:\Windows\system32\WMPEncEn.dll
2011-06-23 21:23:03 ----A---- C:\Windows\system32\wmpeffects.dll
2011-06-23 21:23:03 ----A---- C:\Windows\system32\SyncCenter.dll
2011-06-23 21:23:03 ----A---- C:\Windows\system32\sppobjs.dll
2011-06-23 21:23:03 ----A---- C:\Windows\system32\IPSECSVC.DLL
2011-06-23 21:23:03 ----A---- C:\Windows\system32\FXSSVC.exe
2011-06-23 21:23:03 ----A---- C:\Windows\system32\framedyn.dll
2011-06-23 21:23:03 ----A---- C:\Windows\system32\AudioSes.dll
2011-06-23 21:23:03 ----A---- C:\Windows\system32\aepdu.dll
2011-06-23 21:23:02 ----A---- C:\Windows\system32\srvsvc.dll
2011-06-23 21:23:02 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-06-23 21:23:01 ----A---- C:\Windows\system32\shsvcs.dll
2011-06-23 21:23:01 ----A---- C:\Windows\system32\aeinv.dll
2011-06-23 21:22:59 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2011-06-23 21:22:59 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2011-06-23 21:22:59 ----A---- C:\Windows\SYSWOW64\propsys.dll
2011-06-23 21:22:59 ----A---- C:\Windows\SYSWOW64\mfds.dll
2011-06-23 21:22:59 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2011-06-23 21:22:59 ----A---- C:\Windows\system32\WinSATAPI.dll
2011-06-23 21:22:59 ----A---- C:\Windows\system32\fde.dll
2011-06-23 21:22:58 ----A---- C:\Windows\system32\stobject.dll
2011-06-23 21:22:58 ----A---- C:\Windows\system32\netdiagfx.dll
2011-06-23 21:22:58 ----A---- C:\Windows\system32\localsec.dll
2011-06-23 21:22:58 ----A---- C:\Windows\system32\imapi2.dll
2011-06-23 21:22:58 ----A---- C:\Windows\system32\credui.dll
2011-06-23 21:22:58 ----A---- C:\Windows\system32\bcryptprimitives.dll
2011-06-23 21:22:57 ----A---- C:\Windows\SYSWOW64\user32.dll
2011-06-23 21:22:57 ----A---- C:\Windows\system32\tcpipcfg.dll
2011-06-23 21:22:57 ----A---- C:\Windows\system32\QSHVHOST.DLL
2011-06-23 21:22:57 ----A---- C:\Windows\system32\netid.dll
2011-06-23 21:22:57 ----A---- C:\Windows\system32\iphlpsvc.dll
2011-06-23 21:22:57 ----A---- C:\Windows\system32\inetpp.dll
2011-06-23 21:22:57 ----A---- C:\Windows\system32\drivers\udfs.sys
2011-06-23 21:22:57 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2011-06-23 21:22:57 ----A---- C:\Windows\system32\cdd.dll
2011-06-23 21:22:56 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2011-06-23 21:22:56 ----A---- C:\Windows\SYSWOW64\azroles.dll
2011-06-23 21:22:56 ----A---- C:\Windows\system32\spp.dll
2011-06-23 21:22:56 ----A---- C:\Windows\system32\profsvc.dll
2011-06-23 21:22:56 ----A---- C:\Windows\system32\msinfo32.exe
2011-06-23 21:22:56 ----A---- C:\Windows\system32\gameux.dll
2011-06-23 21:22:56 ----A---- C:\Windows\system32\davclnt.dll
2011-06-23 21:22:56 ----A---- C:\Windows\system32\biocpl.dll
2011-06-23 21:22:55 ----A---- C:\Windows\SYSWOW64\themeui.dll
2011-06-23 21:22:55 ----A---- C:\Windows\system32\scansetting.dll
2011-06-23 21:22:55 ----A---- C:\Windows\system32\printui.dll
2011-06-23 21:22:55 ----A---- C:\Windows\system32\mspbda.dll
2011-06-23 21:22:54 ----A---- C:\Windows\SYSWOW64\credui.dll
2011-06-23 21:22:54 ----A---- C:\Windows\system32\pla.dll
2011-06-23 21:22:53 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-06-23 21:22:53 ----A---- C:\Windows\SYSWOW64\spp.dll
2011-06-23 21:22:53 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll
2011-06-23 21:22:53 ----A---- C:\Windows\system32\PhotoScreensaver.scr
2011-06-23 21:22:53 ----A---- C:\Windows\splwow64.exe
2011-06-23 21:22:52 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2011-06-23 21:22:51 ----A---- C:\Windows\system32\wusa.exe
2011-06-23 21:22:51 ----A---- C:\Windows\system32\wiaservc.dll
2011-06-23 21:22:51 ----A---- C:\Windows\system32\vds.exe
2011-06-23 21:22:51 ----A---- C:\Windows\system32\msdri.dll
2011-06-23 21:22:51 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2011-06-23 21:22:51 ----A---- C:\Windows\system32\drivers\pci.sys
2011-06-23 21:22:51 ----A---- C:\Windows\system32\aitagent.exe
2011-06-23 21:22:50 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2011-06-23 21:22:50 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-06-23 21:22:50 ----A---- C:\Windows\SYSWOW64\basecsp.dll
2011-06-23 21:22:50 ----A---- C:\Windows\system32\rpchttp.dll
2011-06-23 21:22:50 ----A---- C:\Windows\system32\mscms.dll
2011-06-23 21:22:50 ----A---- C:\Windows\system32\cryptsvc.dll
2011-06-23 21:22:49 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2011-06-23 21:22:49 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-06-23 21:22:49 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2011-06-23 21:22:49 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2011-06-23 21:22:49 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2011-06-23 21:22:48 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-06-23 21:22:48 ----A---- C:\Windows\system32\wisptis.exe
2011-06-23 21:22:48 ----A---- C:\Windows\system32\msi.dll
2011-06-23 21:22:48 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2011-06-23 21:22:47 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-06-23 21:22:47 ----A---- C:\Windows\SYSWOW64\evr.dll
2011-06-23 21:22:47 ----A---- C:\Windows\system32\sppwinob.dll
2011-06-23 21:22:47 ----A---- C:\Windows\system32\ocsetup.exe
2011-06-23 21:22:47 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2011-06-23 21:22:46 ----A---- C:\Windows\SYSWOW64\WinSATAPI.dll
2011-06-23 21:22:46 ----A---- C:\Windows\SYSWOW64\calc.exe
2011-06-23 21:22:46 ----A---- C:\Windows\system32\wpdbusenum.dll
2011-06-23 21:22:46 ----A---- C:\Windows\system32\rdpcore.dll
2011-06-23 21:22:46 ----A---- C:\Windows\system32\ocsetapi.dll
2011-06-23 21:22:46 ----A---- C:\Windows\system32\DXP.dll
2011-06-23 21:22:46 ----A---- C:\Windows\system32\drivers\volmgr.sys
2011-06-23 21:22:45 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2011-06-23 21:22:45 ----A---- C:\Windows\SYSWOW64\sqlsrv32.dll
2011-06-23 21:22:45 ----A---- C:\Windows\system32\wcncsvc.dll
2011-06-23 21:22:45 ----A---- C:\Windows\system32\upnp.dll
2011-06-23 21:22:45 ----A---- C:\Windows\system32\t2embed.dll
2011-06-23 21:22:45 ----A---- C:\Windows\system32\Robocopy.exe
2011-06-23 21:22:45 ----A---- C:\Windows\system32\ntshrui.dll
2011-06-23 21:22:45 ----A---- C:\Windows\system32\mprapi.dll
2011-06-23 21:22:45 ----A---- C:\Windows\system32\eapphost.dll
2011-06-23 21:22:45 ----A---- C:\Windows\system32\eapp3hst.dll
2011-06-23 21:22:45 ----A---- C:\Windows\system32\drivers\msdsm.sys
2011-06-23 21:22:45 ----A---- C:\Windows\system32\ci.dll
2011-06-23 21:22:44 ----A---- C:\Windows\SYSWOW64\sxs.dll
2011-06-23 21:22:44 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-06-23 21:22:44 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2011-06-23 21:22:44 ----A---- C:\Windows\system32\thumbcache.dll
2011-06-23 21:22:44 ----A---- C:\Windows\system32\hal.dll
2011-06-23 21:22:44 ----A---- C:\Windows\system32\drivers\HpSAMD.sys
2011-06-23 21:22:43 ----A---- C:\Windows\SYSWOW64\ws2_32.dll
2011-06-23 21:22:43 ----A---- C:\Windows\SYSWOW64\stobject.dll
2011-06-23 21:22:43 ----A---- C:\Windows\SYSWOW64\netshell.dll
2011-06-23 21:22:43 ----A---- C:\Windows\system32\scecli.dll
2011-06-23 21:22:43 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2011-06-23 21:22:43 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2011-06-23 21:22:43 ----A---- C:\Windows\system32\DxpTaskSync.dll
2011-06-23 21:22:43 ----A---- C:\Windows\system32\dwmredir.dll
2011-06-23 21:22:43 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2011-06-23 21:22:43 ----A---- C:\Windows\system32\drivers\fvevol.sys
2011-06-23 21:22:42 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2011-06-23 21:22:42 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2011-06-23 21:22:41 ----A---- C:\Windows\system32\sspicli.dll
2011-06-23 21:22:41 ----A---- C:\Windows\system32\puiobj.dll
2011-06-23 21:22:41 ----A---- C:\Windows\system32\msasn1.dll
2011-06-23 21:22:41 ----A---- C:\Windows\system32\iasrad.dll
2011-06-23 21:22:41 ----A---- C:\Windows\system32\drivers\ipfltdrv.sys
2011-06-23 21:22:41 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2011-06-23 21:22:40 ----A---- C:\Windows\SYSWOW64\prncache.dll
2011-06-23 21:22:40 ----A---- C:\Windows\system32\themeui.dll
2011-06-23 21:22:40 ----A---- C:\Windows\system32\nlaapi.dll
2011-06-23 21:22:39 ----A---- C:\Windows\SYSWOW64\WSDApi.dll
2011-06-23 21:22:39 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2011-06-23 21:22:39 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2011-06-23 21:22:39 ----A---- C:\Windows\SYSWOW64\printui.dll
2011-06-23 21:22:39 ----A---- C:\Windows\SYSWOW64\net1.exe
2011-06-23 21:22:39 ----A---- C:\Windows\SYSWOW64\msi.dll
2011-06-23 21:22:39 ----A---- C:\Windows\system32\onex.dll
2011-06-23 21:22:39 ----A---- C:\Windows\system32\iedkcs32.dll
2011-06-23 21:22:39 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2011-06-23 21:22:39 ----A---- C:\Windows\system32\aaclient.dll
2011-06-23 21:22:38 ----A---- C:\Windows\SYSWOW64\scansetting.dll
2011-06-23 21:22:38 ----A---- C:\Windows\system32\wlangpui.dll
2011-06-23 21:22:38 ----A---- C:\Windows\system32\wdc.dll
2011-06-23 21:22:38 ----A---- C:\Windows\system32\scesrv.dll
2011-06-23 21:22:38 ----A---- C:\Windows\system32\rasmans.dll
2011-06-23 21:22:37 ----A---- C:\Windows\SYSWOW64\MMDevAPI.dll
2011-06-23 21:22:37 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-06-23 21:22:37 ----A---- C:\Windows\system32\wiadefui.dll
2011-06-23 21:22:37 ----A---- C:\Windows\system32\VAN.dll
2011-06-23 21:22:37 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-06-23 21:22:37 ----A---- C:\Windows\system32\sdengin2.dll
2011-06-23 21:22:37 ----A---- C:\Windows\system32\netcenter.dll
2011-06-23 21:22:37 ----A---- C:\Windows\system32\msftedit.dll
2011-06-23 21:22:37 ----A---- C:\Windows\system32\dskquoui.dll
2011-06-23 21:22:36 ----A---- C:\Windows\system32\wscapi.dll
2011-06-23 21:22:36 ----A---- C:\Windows\system32\SndVol.exe
2011-06-23 21:22:36 ----A---- C:\Windows\system32\samcli.dll
2011-06-23 21:22:36 ----A---- C:\Windows\system32\iasacct.dll
2011-06-23 21:22:36 ----A---- C:\Windows\system32\drivers\partmgr.sys
2011-06-23 21:22:36 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2011-06-23 21:22:35 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2011-06-23 21:22:35 ----A---- C:\Windows\SYSWOW64\WMVCORE.DLL
2011-06-23 21:22:35 ----A---- C:\Windows\SYSWOW64\wlangpui.dll
2011-06-23 21:22:35 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2011-06-23 21:22:35 ----A---- C:\Windows\SYSWOW64\QSHVHOST.DLL
2011-06-23 21:22:35 ----A---- C:\Windows\SYSWOW64\pnidui.dll
2011-06-23 21:22:35 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2011-06-23 21:22:35 ----A---- C:\Windows\system32\wucltux.dll
2011-06-23 21:22:35 ----A---- C:\Windows\system32\TabSvc.dll
2011-06-23 21:22:35 ----A---- C:\Windows\system32\srchadmin.dll
2011-06-23 21:22:35 ----A---- C:\Windows\system32\regapi.dll
2011-06-23 21:22:35 ----A---- C:\Windows\system32\QUTIL.DLL
2011-06-23 21:22:35 ----A---- C:\Windows\system32\drivers\termdd.sys
2011-06-23 21:22:35 ----A---- C:\Windows\system32\consent.exe
2011-06-23 21:22:34 ----A---- C:\Windows\SYSWOW64\webservices.dll
2011-06-23 21:22:34 ----A---- C:\Windows\SYSWOW64\netdiagfx.dll
2011-06-23 21:22:34 ----A---- C:\Windows\SYSWOW64\fde.dll
2011-06-23 21:22:34 ----A---- C:\Windows\system32\WUDFSvc.dll
2011-06-23 21:22:34 ----A---- C:\Windows\system32\wksprt.exe
2011-06-23 21:22:34 ----A---- C:\Windows\system32\taskhost.exe
2011-06-23 21:22:34 ----A---- C:\Windows\system32\setupcl.exe
2011-06-23 21:22:34 ----A---- C:\Windows\system32\rastls.dll
2011-06-23 21:22:34 ----A---- C:\Windows\system32\drivers\msahci.sys
2011-06-23 21:22:33 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2011-06-23 21:22:33 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-06-23 21:22:33 ----A---- C:\Windows\SYSWOW64\SyncCenter.dll
2011-06-23 21:22:33 ----A---- C:\Windows\system32\tapisrv.dll
2011-06-23 21:22:33 ----A---- C:\Windows\system32\drivers\acpi.sys
2011-06-23 21:22:32 ----A---- C:\Windows\SYSWOW64\WinSCard.dll
2011-06-23 21:22:32 ----A---- C:\Windows\SYSWOW64\pla.dll
2011-06-23 21:22:32 ----A---- C:\Windows\SYSWOW64\msasn1.dll
2011-06-23 21:22:32 ----A---- C:\Windows\system32\netiohlp.dll
2011-06-23 21:22:32 ----A---- C:\Windows\system32\msconfig.exe
2011-06-23 21:22:32 ----A---- C:\Windows\system32\mimefilt.dll
2011-06-23 21:22:32 ----A---- C:\Windows\system32\ListSvc.dll
2011-06-23 21:22:32 ----A---- C:\Windows\system32\hgcpl.dll
2011-06-23 21:22:32 ----A---- C:\Windows\system32\drivers\raspptp.sys
2011-06-23 21:22:31 ----A---- C:\Windows\SYSWOW64\winsta.dll
2011-06-23 21:22:31 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2011-06-23 21:22:31 ----A---- C:\Windows\SYSWOW64\MSMPEG2ENC.DLL
2011-06-23 21:22:31 ----A---- C:\Windows\system32\lsmproxy.dll
2011-06-23 21:22:31 ----A---- C:\Windows\system32\fdeploy.dll
2011-06-23 21:22:31 ----A---- C:\Windows\system32\drivers\sbp2port.sys
2011-06-23 21:22:31 ----A---- C:\Windows\system32\drivers\ks.sys
2011-06-23 21:22:31 ----A---- C:\Windows\system32\clusapi.dll
2011-06-23 21:22:31 ----A---- C:\Windows\system32\basecsp.dll
2011-06-23 21:22:31 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2011-06-23 21:22:30 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2011-06-23 21:22:30 ----A---- C:\Windows\SYSWOW64\imapi2.dll
2011-06-23 21:22:30 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-06-23 21:22:30 ----A---- C:\Windows\SYSWOW64\gameux.dll
2011-06-23 21:22:30 ----A---- C:\Windows\SYSWOW64\DXPTaskRingtone.dll
2011-06-23 21:22:30 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2011-06-23 21:22:30 ----A---- C:\Windows\system32\riched20.dll
2011-06-23 21:22:30 ----A---- C:\Windows\system32\mtxclu.dll
2011-06-23 21:22:30 ----A---- C:\Windows\system32\dnscmmc.dll
2011-06-23 21:22:29 ----A---- C:\Windows\SYSWOW64\WMPEncEn.dll
2011-06-23 21:22:29 ----A---- C:\Windows\SYSWOW64\onex.dll
2011-06-23 21:22:29 ----A---- C:\Windows\system32\sharemediacpl.dll
2011-06-23 21:22:29 ----A---- C:\Windows\system32\RpcRtRemote.dll
2011-06-23 21:22:29 ----A---- C:\Windows\system32\powercpl.dll
2011-06-23 21:22:29 ----A---- C:\Windows\system32\logoncli.dll
2011-06-23 21:22:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-06-23 21:22:28 ----A---- C:\Windows\SYSWOW64\winmm.dll
2011-06-23 21:22:28 ----A---- C:\Windows\SYSWOW64\shsvcs.dll
2011-06-23 21:22:28 ----A---- C:\Windows\SYSWOW64\samcli.dll
2011-06-23 21:22:28 ----A---- C:\Windows\SYSWOW64\netiohlp.dll
2011-06-23 21:22:28 ----A---- C:\Windows\SYSWOW64\hbaapi.dll
2011-06-23 21:22:28 ----A---- C:\Windows\SYSWOW64\autochk.exe
2011-06-23 21:22:28 ----A---- C:\Windows\SYSWOW64\autofmt.exe
2011-06-23 21:22:28 ----A---- C:\Windows\system32\wkssvc.dll
2011-06-23 21:22:28 ----A---- C:\Windows\system32\vpnikeapi.dll
2011-06-23 21:22:28 ----A---- C:\Windows\system32\themecpl.dll
2011-06-23 21:22:28 ----A---- C:\Windows\system32\SensorsCpl.dll
2011-06-23 21:22:28 ----A---- C:\Windows\system32\netjoin.dll
2011-06-23 21:22:28 ----A---- C:\Windows\system32\nci.dll
2011-06-23 21:22:28 ----A---- C:\Windows\system32\Narrator.exe
2011-06-23 21:22:28 ----A---- C:\Windows\system32\licmgr10.dll
2011-06-23 21:22:28 ----A---- C:\Windows\system32\Faultrep.dll
2011-06-23 21:22:28 ----A---- C:\Windows\system32\eudcedit.exe
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\thumbcache.dll
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\regapi.dll
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\proquota.exe
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\msutb.dll
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\msinfo32.exe
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\mimefilt.dll
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\ipsmsnap.dll
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\IPHLPAPI.DLL
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\autoconv.exe
2011-06-23 21:22:27 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2011-06-23 21:22:27 ----A---- C:\Windows\system32\sppcomapi.dll
2011-06-23 21:22:27 ----A---- C:\Windows\system32\comctl32.dll
2011-06-23 21:22:27 ----A---- C:\Windows\system32\cabview.dll
2011-06-23 21:22:27 ----A---- C:\Windows\system32\autochk.exe
2011-06-23 21:22:27 ----A---- C:\Windows\system32\autofmt.exe
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\tcpipcfg.dll
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\srchadmin.dll
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\powercpl.dll
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\framedyn.dll
2011-06-23 21:22:26 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\wwanconn.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\wpd_ci.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\wlanui.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\shsetup.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\sdclt.exe
2011-06-23 21:22:26 ----A---- C:\Windows\system32\prntvpt.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\nshipsec.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\mscorier.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\fms.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\drivers\wanarp.sys
2011-06-23 21:22:26 ----A---- C:\Windows\system32\drivers\scsiport.sys
2011-06-23 21:22:26 ----A---- C:\Windows\system32\bcdsrv.dll
2011-06-23 21:22:26 ----A---- C:\Windows\system32\autoconv.exe
2011-06-23 21:22:26 ----A---- C:\Windows\system32\audiodg.exe
2011-06-23 21:22:25 ----A---- C:\Windows\SYSWOW64\QAGENT.DLL
2011-06-23 21:22:25 ----A---- C:\Windows\SYSWOW64\netid.dll
2011-06-23 21:22:25 ----A---- C:\Windows\SYSWOW64\AuxiliaryDisplayCpl.dll
2011-06-23 21:22:25 ----A---- C:\Windows\system32\qedit.dll
2011-06-23 21:22:25 ----A---- C:\Windows\system32\mprddm.dll
2011-06-23 21:22:25 ----A---- C:\Windows\system32\fontext.dll
2011-06-23 21:22:25 ----A---- C:\Windows\system32\drivers\volmgrx.sys
2011-06-23 21:22:25 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2011-06-23 21:22:25 ----A---- C:\Windows\system32\dps.dll
2011-06-23 21:22:25 ----A---- C:\Windows\system32\Display.dll
2011-06-23 21:22:25 ----A---- C:\Windows\system32\AxInstSv.dll
2011-06-23 21:22:24 ----A---- C:\Windows\SYSWOW64\wdc.dll
2011-06-23 21:22:24 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2011-06-23 21:22:24 ----A---- C:\Windows\system32\mblctr.exe
2011-06-23 21:22:24 ----A---- C:\Windows\system32\drivers\hidclass.sys
2011-06-23 21:22:24 ----A---- C:\Windows\system32\credssp.dll
2011-06-23 21:22:24 ----A---- C:\Windows\system32\batmeter.dll
2011-06-23 21:22:23 ----A---- C:\Windows\SYSWOW64\Vault.dll
2011-06-23 21:22:23 ----A---- C:\Windows\SYSWOW64\untfs.dll
2011-06-23 21:22:23 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2011-06-23 21:22:23 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2011-06-23 21:22:23 ----A---- C:\Windows\SYSWOW64\rastls.dll
2011-06-23 21:22:23 ----A---- C:\Windows\SYSWOW64\nci.dll
2011-06-23 21:22:23 ----A---- C:\Windows\system32\wmpsrcwp.dll
2011-06-23 21:22:22 ----A---- C:\Windows\SYSWOW64\wlanpref.dll
2011-06-23 21:22:22 ----A---- C:\Windows\system32\DiagCpl.dll
2011-06-23 21:22:21 ----A---- C:\Windows\SYSWOW64\RpcRtRemote.dll
2011-06-23 21:22:21 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-06-23 21:22:20 ----A---- C:\Windows\SYSWOW64\WMNetMgr.dll
2011-06-23 21:22:20 ----A---- C:\Windows\SYSWOW64\Robocopy.exe
2011-06-23 21:22:20 ----A---- C:\Windows\system32\usercpl.dll
2011-06-23 21:22:20 ----A---- C:\Windows\system32\rtutils.dll
2011-06-23 21:22:20 ----A---- C:\Windows\system32\provsvc.dll
2011-06-23 21:22:20 ----A---- C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2011-06-23 21:22:20 ----A---- C:\Windows\system32\bootres.dll
2011-06-23 21:22:19 ----A---- C:\Windows\SYSWOW64\taskmgr.exe
2011-06-23 21:22:19 ----A---- C:\Windows\SYSWOW64\mtxclu.dll
2011-06-23 21:22:19 ----A---- C:\Windows\SYSWOW64\DxpTaskSync.dll
2011-06-23 21:22:19 ----A---- C:\Windows\SYSWOW64\Display.dll
2011-06-23 21:22:19 ----A---- C:\Windows\system32\wpccpl.dll
2011-06-23 21:22:19 ----A---- C:\Windows\system32\sppsvc.exe
2011-06-23 21:22:19 ----A---- C:\Windows\system32\SndVolSSO.dll
2011-06-23 21:22:19 ----A---- C:\Windows\system32\rasppp.dll
2011-06-23 21:22:19 ----A---- C:\Windows\system32\dxdiagn.dll
2011-06-23 21:22:19 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2011-06-23 21:22:19 ----A---- C:\Windows\system32\dot3cfg.dll
2011-06-23 21:22:18 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-06-23 21:22:18 ----A---- C:\Windows\SYSWOW64\userinit.exe
2011-06-23 21:22:18 ----A---- C:\Windows\SYSWOW64\termmgr.dll
2011-06-23 21:22:18 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2011-06-23 21:22:18 ----A---- C:\Windows\system32\taskmgr.exe
2011-06-23 21:22:18 ----A---- C:\Windows\system32\shdocvw.dll
2011-06-23 21:22:18 ----A---- C:\Windows\system32\prnfldr.dll
2011-06-23 21:22:18 ----A---- C:\Windows\system32\hbaapi.dll
2011-06-23 21:22:18 ----A---- C:\Windows\system32\drivers\hwpolicy.sys
2011-06-23 21:22:17 ----A---- C:\Windows\SYSWOW64\wiadefui.dll
2011-06-23 21:22:17 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
2011-06-23 21:22:17 ----A---- C:\Windows\SYSWOW64\shsetup.dll
2011-06-23 21:22:17 ----A---- C:\Windows\SYSWOW64\rasppp.dll
2011-06-23 21:22:17 ----A---- C:\Windows\SYSWOW64\logoncli.dll
2011-06-23 21:22:17 ----A---- C:\Windows\SYSWOW64\eudcedit.exe
2011-06-23 21:22:17 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2011-06-23 21:22:17 ----A---- C:\Windows\system32\untfs.dll
2011-06-23 21:22:17 ----A---- C:\Windows\system32\proquota.exe
2011-06-23 21:22:17 ----A---- C:\Windows\system32\pdh.dll
2011-06-23 21:22:17 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2011-06-23 21:22:17 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2011-06-23 21:22:17 ----A---- C:\Windows\system32\drivers\ataport.sys
2011-06-23 21:22:16 ----A---- C:\Windows\SYSWOW64\SensorsCpl.dll
2011-06-23 21:22:16 ----A---- C:\Windows\SYSWOW64\FirewallControlPanel.dll
2011-06-23 21:22:16 ----A---- C:\Windows\SYSWOW64\cabview.dll
2011-06-23 21:22:16 ----A---- C:\Windows\system32\userinit.exe
2011-06-23 21:22:16 ----A---- C:\Windows\system32\rdpcorekmts.dll
2011-06-23 21:22:16 ----A---- C:\Windows\system32\accessibilitycpl.dll
2011-06-23 21:22:15 ----A---- C:\Windows\SYSWOW64\themecpl.dll
2011-06-23 21:22:15 ----A---- C:\Windows\SYSWOW64\PhotoScreensaver.scr
2011-06-23 21:22:15 ----A---- C:\Windows\SYSWOW64\hgcpl.dll
2011-06-23 21:22:15 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2011-06-23 21:22:15 ----A---- C:\Windows\SYSWOW64\dnscmmc.dll
2011-06-23 21:22:15 ----A---- C:\Windows\system32\zipfldr.dll
2011-06-23 21:22:15 ----A---- C:\Windows\system32\webcheck.dll
2011-06-23 21:22:15 ----A---- C:\Windows\system32\slui.exe
2011-06-23 21:22:15 ----A---- C:\Windows\system32\msieftp.dll
2011-06-23 21:22:15 ----A---- C:\Windows\system32\defaultlocationcpl.dll
2011-06-23 21:22:14 ----A---- C:\Windows\SYSWOW64\tapisrv.dll
2011-06-23 21:22:14 ----A---- C:\Windows\SYSWOW64\scecli.dll
2011-06-23 21:22:14 ----A---- C:\Windows\SYSWOW64\mscories.dll
2011-06-23 21:22:14 ----A---- C:\Windows\SYSWOW64\fontext.dll
2011-06-23 21:22:14 ----A---- C:\Windows\system32\sud.dll
2011-06-23 21:22:14 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2011-06-23 21:22:13 ----A---- C:\Windows\SYSWOW64\mscms.dll
2011-06-23 21:22:13 ----A---- C:\Windows\SYSWOW64\mprddm.dll
2011-06-23 21:22:13 ----A---- C:\Windows\SYSWOW64\localsec.dll
2011-06-23 21:22:13 ----A---- C:\Windows\SYSWOW64\iasacct.dll
2011-06-23 21:22:13 ----A---- C:\Windows\system32\OnLineIDCpl.dll
2011-06-23 21:22:13 ----A---- C:\Windows\system32\networkmap.dll
2011-06-23 21:22:13 ----A---- C:\Windows\system32\dot3svc.dll
2011-06-23 21:22:13 ----A---- C:\Windows\system32\DeviceCenter.dll
2011-06-23 21:22:13 ----A---- C:\Windows\system32\cryptui.dll
2011-06-23 21:22:12 ----A---- C:\Windows\SYSWOW64\SndVolSSO.dll
2011-06-23 21:22:12 ----A---- C:\Windows\system32\taskbarcpl.dll
2011-06-23 21:22:12 ----A---- C:\Windows\system32\qdvd.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\wlanui.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\VAN.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\usercpl.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\SndVol.exe
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\qedit.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\prntvpt.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\PerfCenterCPL.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\netcenter.dll
2011-06-23 21:22:11 ----A---- C:\Windows\SYSWOW64\batmeter.dll
2011-06-23 21:22:11 ----A---- C:\Windows\system32\twext.dll
2011-06-23 21:22:11 ----A---- C:\Windows\system32\srcore.dll
2011-06-23 21:22:11 ----A---- C:\Windows\system32\rdpwsx.dll
2011-06-23 21:22:11 ----A---- C:\Windows\system32\OobeFldr.dll
2011-06-23 21:22:11 ----A---- C:\Windows\system32\bcdedit.exe
2011-06-23 21:22:11 ----A---- C:\Windows\system32\ActionCenter.dll
2011-06-23 21:22:10 ----A---- C:\Windows\SYSWOW64\w32tm.exe
2011-06-23 21:22:10 ----A---- C:\Windows\SYSWOW64\spwizeng.dll
2011-06-23 21:22:10 ----A---- C:\Windows\SYSWOW64\azroleui.dll
2011-06-23 21:22:10 ----A---- C:\Windows\SYSWOW64\accessibilitycpl.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\uxlib.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\tzutil.exe
2011-06-23 21:22:10 ----A---- C:\Windows\system32\sisbkup.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\recovery.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\isoburn.exe
2011-06-23 21:22:10 ----A---- C:\Windows\system32\efscore.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\dsuiext.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\cca.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\azroleui.dll
2011-06-23 21:22:10 ----A---- C:\Windows\system32\asycfilt.dll
2011-06-23 21:22:09 ----A---- C:\Windows\SYSWOW64\zipfldr.dll
2011-06-23 21:22:09 ----A---- C:\Windows\SYSWOW64\netjoin.dll
2011-06-23 21:22:09 ----A---- C:\Windows\SYSWOW64\MSAC3ENC.DLL
2011-06-23 21:22:09 ----A---- C:\Windows\SYSWOW64\fdeploy.dll
2011-06-23 21:22:09 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2011-06-23 21:22:09 ----A---- C:\Windows\SYSWOW64\adsldp.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\systemcpl.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\syncui.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\sspisrv.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\shwebsvc.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\sdcpl.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\recdisc.exe
2011-06-23 21:22:09 ----A---- C:\Windows\system32\netplwiz.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\httpapi.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\drivers\mpio.sys
2011-06-23 21:22:09 ----A---- C:\Windows\system32\certcli.dll
2011-06-23 21:22:09 ----A---- C:\Windows\system32\autoplay.dll
2011-06-23 21:22:08 ----A---- C:\Windows\SYSWOW64\wusa.exe
2011-06-23 21:22:08 ----A---- C:\Windows\SYSWOW64\prnfldr.dll
2011-06-23 21:22:08 ----A---- C:\Windows\SYSWOW64\networkmap.dll
2011-06-23 21:22:08 ----A---- C:\Windows\SYSWOW64\MCEWMDRMNDBootstrap.dll
2011-06-23 21:22:08 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2011-06-23 21:22:08 ----A---- C:\Windows\system32\wlanmsm.dll
2011-06-23 21:22:08 ----A---- C:\Windows\system32\sysclass.dll
2011-06-23 21:22:08 ----A---- C:\Windows\system32\sdrsvc.dll
2011-06-23 21:22:08 ----A---- C:\Windows\system32\ncryptui.dll
2011-06-23 21:22:08 ----A---- C:\Windows\system32\msvidc32.dll
2011-06-23 21:22:08 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2011-06-23 21:22:08 ----A---- C:\Windows\system32\appinfo.dll
2011-06-23 21:22:08 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2011-06-23 21:22:07 ----A---- C:\Windows\SYSWOW64\sud.dll
2011-06-23 21:22:07 ----A---- C:\Windows\SYSWOW64\photowiz.dll
2011-06-23 21:22:07 ----A---- C:\Windows\SYSWOW64\OnLineIDCpl.dll
2011-06-23 21:22:07 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2011-06-23 21:22:07 ----A---- C:\Windows\SYSWOW64\MediaMetadataHandler.dll
2011-06-23 21:22:07 ----A---- C:\Windows\SYSWOW64\credssp.dll
2011-06-23 21:22:07 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2011-06-23 21:22:07 ----A---- C:\Windows\system32\vdsutil.dll
2011-06-23 21:22:07 ----A---- C:\Windows\system32\termmgr.dll
2011-06-23 21:22:07 ----A---- C:\Windows\system32\spwizeng.dll
2011-06-23 21:22:07 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-23 21:22:07 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-06-23 21:22:07 ----A---- C:\Windows\system32\MFPlay.dll
2011-06-23 21:22:06 ----A---- C:\Windows\SYSWOW64\iprtrmgr.dll
2011-06-23 21:22:06 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-06-23 21:22:06 ----A---- C:\Windows\SYSWOW64\iasrad.dll
2011-06-23 21:22:06 ----A---- C:\Windows\SYSWOW64\ftp.exe
2011-06-23 21:22:06 ----A---- C:\Windows\SYSWOW64\dot3cfg.dll
2011-06-23 21:22:06 ----A---- C:\Windows\SYSWOW64\defaultlocationcpl.dll
2011-06-23 21:22:06 ----A---- C:\Windows\system32\tsgqec.dll
2011-06-23 21:22:06 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2011-06-23 21:22:06 ----A---- C:\Windows\system32\sethc.exe
2011-06-23 21:22:06 ----A---- C:\Windows\system32\rstrui.exe
2011-06-23 21:22:06 ----A---- C:\Windows\system32\ReAgent.dll
2011-06-23 21:22:06 ----A---- C:\Windows\system32\odbccp32.dll
2011-06-23 21:22:06 ----A---- C:\Windows\system32\ntlanman.dll
2011-06-23 21:22:06 ----A---- C:\Windows\system32\msscp.dll
2011-06-23 21:22:05 ----A---- C:\Windows\SYSWOW64\sisbkup.dll
2011-06-23 21:22:05 ----A---- C:\Windows\SYSWOW64\shwebsvc.dll
2011-06-23 21:22:05 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-06-23 21:22:05 ----A---- C:\Windows\SYSWOW64\ifsutil.dll
2011-06-23 21:22:05 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-06-23 21:22:05 ----A---- C:\Windows\SYSWOW64\efscore.dll
2011-06-23 21:22:05 ----A---- C:\Windows\SYSWOW64\ActionCenterCPL.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\wwanprotdim.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\UserAccountControlSettings.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\ssText3d.scr
2011-06-23 21:22:05 ----A---- C:\Windows\system32\sqlcese30.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\secur32.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\rdpd3d.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\odbctrac.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\iTVData.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\iprtrmgr.dll
2011-06-23 21:22:05 ----A---- C:\Windows\system32\drivers\ndproxy.sys
2011-06-23 21:22:04 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2011-06-23 21:22:04 ----A---- C:\Windows\SYSWOW64\syncui.dll
2011-06-23 21:22:04 ----A---- C:\Windows\SYSWOW64\ntlanman.dll
2011-06-23 21:22:04 ----A---- C:\Windows\SYSWOW64\dskquoui.dll
2011-06-23 21:22:04 ----A---- C:\Windows\SYSWOW64\DeviceCenter.dll
2011-06-23 21:22:04 ----A---- C:\Windows\SYSWOW64\autoplay.dll
2011-06-23 21:22:04 ----A---- C:\Windows\system32\wmdrmsdk.dll
2011-06-23 21:22:04 ----A---- C:\Windows\system32\srvcli.dll
2011-06-23 21:22:04 ----A---- C:\Windows\system32\slwga.dll
2011-06-23 21:22:04 ----A---- C:\Windows\system32\iyuv_32.dll
2011-06-23 21:22:04 ----A---- C:\Windows\system32\drmmgrtn.dll
2011-06-23 21:22:03 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2011-06-23 21:22:03 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2011-06-23 21:22:03 ----A---- C:\Windows\SYSWOW64\sethc.exe
2011-06-23 21:22:03 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2011-06-23 21:22:03 ----A---- C:\Windows\SYSWOW64\riched20.dll
2011-06-23 21:22:03 ----A---- C:\Windows\SYSWOW64\OobeFldr.dll
2011-06-23 21:22:03 ----A---- C:\Windows\SYSWOW64\ntprint.dll
2011-06-23 21:22:03 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2011-06-23 21:22:03 ----A---- C:\Windows\system32\wavemsp.dll
2011-06-23 21:22:03 ----A---- C:\Windows\system32\srrstr.dll
2011-06-23 21:22:03 ----A---- C:\Windows\system32\ntprint.dll
2011-06-23 21:22:03 ----A---- C:\Windows\system32\nslookup.exe
2011-06-23 21:22:03 ----A---- C:\Windows\system32\NAPHLPR.DLL
2011-06-23 21:22:03 ----A---- C:\Windows\system32\msiexec.exe
2011-06-23 21:22:03 ----A---- C:\Windows\system32\DevicePairingFolder.dll
2011-06-23 21:22:03 ----A---- C:\Windows\system32\bcdboot.exe
2011-06-23 21:22:03 ----A---- C:\Windows\system32\acppage.dll
2011-06-23 21:22:02 ----A---- C:\Windows\SYSWOW64\netplwiz.dll
2011-06-23 21:22:02 ----A---- C:\Windows\SYSWOW64\NAPHLPR.DLL
2011-06-23 21:22:02 ----A---- C:\Windows\SYSWOW64\fms.dll
2011-06-23 21:22:02 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2011-06-23 21:22:02 ----A---- C:\Windows\SYSWOW64\activeds.dll
2011-06-23 21:22:02 ----A---- C:\Windows\system32\TSpkg.dll
2011-06-23 21:22:02 ----A---- C:\Windows\system32\sppnp.dll
2011-06-23 21:22:02 ----A---- C:\Windows\system32\fsquirt.exe
2011-06-23 21:22:02 ----A---- C:\Windows\system32\certprop.dll
2011-06-23 21:22:01 ----A---- C:\Windows\SYSWOW64\wmpsrcwp.dll
2011-06-23 21:22:01 ----A---- C:\Windows\SYSWOW64\nshipsec.dll
2011-06-23 21:22:01 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2011-06-23 21:22:01 ----A---- C:\Windows\SYSWOW64\migisol.dll
2011-06-23 21:22:01 ----A---- C:\Windows\SYSWOW64\httpapi.dll
2011-06-23 21:22:01 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2011-06-23 21:22:01 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2011-06-23 21:22:01 ----A---- C:\Windows\system32\wkscli.dll
2011-06-23 21:22:01 ----A---- C:\Windows\system32\remotepg.dll
2011-06-23 21:22:01 ----A---- C:\Windows\system32\networkexplorer.dll
2011-06-23 21:22:01 ----A---- C:\Windows\system32\dfrgui.exe
2011-06-23 21:22:01 ----A---- C:\Windows\system32\cdosys.dll
2011-06-23 21:22:01 ----A---- C:\Windows\system32\cabinet.dll
2011-06-23 21:22:00 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2011-06-23 21:22:00 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll
2011-06-23 21:22:00 ----A---- C:\Windows\SYSWOW64\wavemsp.dll
2011-06-23 21:22:00 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2011-06-23 21:22:00 ----A---- C:\Windows\SYSWOW64\provsvc.dll
2011-06-23 21:22:00 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2011-06-23 21:22:00 ----A---- C:\Windows\SYSWOW64\isoburn.exe
2011-06-23 21:22:00 ----A---- C:\Windows\system32\wmpdxm.dll
2011-06-23 21:22:00 ----A---- C:\Windows\system32\WinSCard.dll
2011-06-23 21:22:00 ----A---- C:\Windows\system32\ftp.exe
2011-06-23 21:21:59 ----A---- C:\Windows\SYSWOW64\wvc.dll
2011-06-23 21:21:59 ----A---- C:\Windows\SYSWOW64\wtsapi32.dll
2011-06-23 21:21:59 ----A---- C:\Windows\SYSWOW64\tzutil.exe
2011-06-23 21:21:59 ----A---- C:\Windows\SYSWOW64\ocsetup.exe
2011-06-23 21:21:59 ----A---- C:\Windows\SYSWOW64\dsuiext.dll
2011-06-23 21:21:59 ----A---- C:\Windows\SYSWOW64\dot3ui.dll
2011-06-23 21:21:59 ----A---- C:\Windows\SYSWOW64\dfrgui.exe
2011-06-23 21:21:59 ----A---- C:\Windows\system32\wvc.dll
2011-06-23 21:21:59 ----A---- C:\Windows\system32\wuwebv.dll
2011-06-23 21:21:59 ----A---- C:\Windows\system32\wsqmcons.exe
2011-06-23 21:21:59 ----A---- C:\Windows\system32\wsnmp32.dll
2011-06-23 21:21:59 ----A---- C:\Windows\system32\wmdrmdev.dll
2011-06-23 21:21:59 ----A---- C:\Windows\system32\WerFaultSecure.exe
2011-06-23 21:21:59 ----A---- C:\Windows\system32\net1.exe
2011-06-23 21:21:59 ----A---- C:\Windows\system32\blackbox.dll
2011-06-23 21:21:58 ----A---- C:\Windows\twain_32.dll
2011-06-23 21:21:58 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2011-06-23 21:21:58 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-06-23 21:21:58 ----A---- C:\Windows\SYSWOW64\twext.dll
2011-06-23 21:21:58 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2011-06-23 21:21:58 ----A---- C:\Windows\SYSWOW64\setupugc.exe
2011-06-23 21:21:58 ----A---- C:\Windows\SYSWOW64\qcap.dll
2011-06-23 21:21:58 ----A---- C:\Windows\SYSWOW64\mstask.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\WUDFPlatform.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\unimdmat.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2011-06-23 21:21:58 ----A---- C:\Windows\system32\OpcServices.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\msyuv.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\msrle32.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\mfps.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\mapistub.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\mapi32.dll
2011-06-23 21:21:58 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-06-23 21:21:58 ----A---- C:\Windows\system32\Bubbles.scr
2011-06-23 21:21:57 ----A---- C:\Windows\SYSWOW64\uxlib.dll
2011-06-23 21:21:57 ----A---- C:\Windows\SYSWOW64\ssText3d.scr
2011-06-23 21:21:57 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-06-23 21:21:57 ----A---- C:\Windows\SYSWOW64\qasf.dll
2011-06-23 21:21:57 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-06-23 21:21:57 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-06-23 21:21:57 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-06-23 21:21:57 ----A---- C:\Windows\system32\tsbyuv.dll
2011-06-23 21:21:57 ----A---- C:\Windows\system32\seclogon.dll

Re: Preventivní log (prosim o kontrolu)

Napsal: 28 črc 2011 22:33
od nom
2011-06-23 21:21:57 ----A---- C:\Windows\system32\Ribbons.scr
2011-06-23 21:21:57 ----A---- C:\Windows\system32\Mystify.scr
2011-06-23 21:21:57 ----A---- C:\Windows\system32\iscsium.dll
2011-06-23 21:21:57 ----A---- C:\Windows\system32\ifsutil.dll
2011-06-23 21:21:57 ----A---- C:\Windows\system32\diskraid.exe
2011-06-23 21:21:56 ----A---- C:\Windows\SYSWOW64\msvfw32.dll
2011-06-23 21:21:56 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-06-23 21:21:56 ----A---- C:\Windows\system32\drivers\umbus.sys
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\WPDShServiceObj.dll
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\nslookup.exe
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\msscp.dll
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\DevicePairingFolder.dll
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\clusapi.dll
2011-06-23 21:21:55 ----A---- C:\Windows\SYSWOW64\audiodev.dll
2011-06-23 21:21:55 ----A---- C:\Windows\system32\wmpshell.dll
2011-06-23 21:21:55 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2011-06-23 21:21:55 ----A---- C:\Windows\system32\rdpencom.dll
2011-06-23 21:21:55 ----A---- C:\Windows\system32\perfmon.exe
2011-06-23 21:21:55 ----A---- C:\Windows\system32\muifontsetup.dll
2011-06-23 21:21:55 ----A---- C:\Windows\system32\d3d10level9.dll
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\wimserv.exe
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\remotepg.dll
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\rdpencom.dll
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\raschap.dll
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\perfmon.exe
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\diskraid.exe
2011-06-23 21:21:54 ----A---- C:\Windows\SYSWOW64\acppage.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\umb.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\tlscsp.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\runonce.exe
2011-06-23 21:21:54 ----A---- C:\Windows\system32\raschap.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\qasf.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\netutils.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\NAPCRYPT.DLL
2011-06-23 21:21:54 ----A---- C:\Windows\system32\inseng.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\FXSAPI.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\dbghelp.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\browser.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\AzSqlExt.dll
2011-06-23 21:21:54 ----A---- C:\Windows\system32\ActionQueue.dll
2011-06-23 21:21:54 ----A---- C:\Windows\bfsvc.exe
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\vpnikeapi.dll
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\UserAccountControlSettings.dll
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\QUTIL.DLL
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\onexui.dll
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\ocsetapi.dll
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\networkexplorer.dll
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\NAPCRYPT.DLL
2011-06-23 21:21:53 ----A---- C:\Windows\SYSWOW64\input.dll
2011-06-23 21:21:53 ----A---- C:\Windows\system32\wpdwcn.dll
2011-06-23 21:21:53 ----A---- C:\Windows\system32\WMVSDECD.DLL
2011-06-23 21:21:53 ----A---- C:\Windows\system32\WMADMOD.DLL
2011-06-23 21:21:53 ----A---- C:\Windows\system32\wiavideo.dll
2011-06-23 21:21:53 ----A---- C:\Windows\system32\vdsbas.dll
2011-06-23 21:21:53 ----A---- C:\Windows\system32\syssetup.dll
2011-06-23 21:21:53 ----A---- C:\Windows\system32\PrintIsolationProxy.dll
2011-06-23 21:21:53 ----A---- C:\Windows\system32\MdSched.exe
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\wpdwcn.dll
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\vdsbas.dll
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\runonce.exe
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\logagent.exe
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\iTVData.dll
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2011-06-23 21:21:52 ----A---- C:\Windows\SYSWOW64\dxdiagn.dll
2011-06-23 21:21:52 ----A---- C:\Windows\system32\nltest.exe
2011-06-23 21:21:52 ----A---- C:\Windows\system32\mstask.dll
2011-06-23 21:21:52 ----A---- C:\Windows\system32\Mcx2Svc.dll
2011-06-23 21:21:52 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2011-06-23 21:21:52 ----A---- C:\Windows\system32\drivers\rmcast.sys
2011-06-23 21:21:52 ----A---- C:\Windows\system32\bitsadmin.exe
2011-06-23 21:21:51 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2011-06-23 21:21:51 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2011-06-23 21:21:51 ----A---- C:\Windows\SYSWOW64\wmdrmdev.dll
2011-06-23 21:21:51 ----A---- C:\Windows\SYSWOW64\shacct.dll
2011-06-23 21:21:51 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2011-06-23 21:21:51 ----A---- C:\Windows\SYSWOW64\lsmproxy.dll
2011-06-23 21:21:51 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2011-06-23 21:21:51 ----A---- C:\Windows\SYSWOW64\bitsadmin.exe
2011-06-23 21:21:51 ----A---- C:\Windows\system32\wudriver.dll
2011-06-23 21:21:51 ----A---- C:\Windows\system32\WPDSp.dll
2011-06-23 21:21:51 ----A---- C:\Windows\system32\wmdrmnet.dll
2011-06-23 21:21:51 ----A---- C:\Windows\system32\vss_ps.dll
2011-06-23 21:21:51 ----A---- C:\Windows\system32\tabcal.exe
2011-06-23 21:21:51 ----A---- C:\Windows\system32\shacct.dll
2011-06-23 21:21:51 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2011-06-23 21:21:51 ----A---- C:\Windows\system32\QSVRMGMT.DLL
2011-06-23 21:21:51 ----A---- C:\Windows\system32\qcap.dll
2011-06-23 21:21:51 ----A---- C:\Windows\system32\msnetobj.dll
2011-06-23 21:21:51 ----A---- C:\Windows\system32\logman.exe
2011-06-23 21:21:51 ----A---- C:\Windows\system32\cscapi.dll
2011-06-23 21:21:50 ----A---- C:\Windows\SYSWOW64\unimdmat.dll
2011-06-23 21:21:50 ----A---- C:\Windows\SYSWOW64\sqlcese30.dll
2011-06-23 21:21:50 ----A---- C:\Windows\SYSWOW64\rdpd3d.dll
2011-06-23 21:21:50 ----A---- C:\Windows\SYSWOW64\iscsium.dll
2011-06-23 21:21:50 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2011-06-23 21:21:50 ----A---- C:\Windows\system32\PortableDeviceSyncProvider.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\WPDSp.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\srvcli.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\PortableDeviceSyncProvider.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\pdh.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\OpcServices.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\olethk32.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\ncryptui.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\mprapi.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\logman.exe
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\cscapi.dll
2011-06-23 21:21:49 ----A---- C:\Windows\SYSWOW64\Bubbles.scr
2011-06-23 21:21:49 ----A---- C:\Windows\system32\spbcd.dll
2011-06-23 21:21:49 ----A---- C:\Windows\system32\secproc_ssp.dll
2011-06-23 21:21:49 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-06-23 21:21:49 ----A---- C:\Windows\system32\qdv.dll
2011-06-23 21:21:49 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2011-06-23 21:21:49 ----A---- C:\Windows\system32\fphc.dll
2011-06-23 21:21:49 ----A---- C:\Windows\system32\drivers\ndisuio.sys
2011-06-23 21:21:49 ----A---- C:\Windows\system32\dot3ui.dll
2011-06-23 21:21:48 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2011-06-23 21:21:48 ----A---- C:\Windows\SYSWOW64\Ribbons.scr
2011-06-23 21:21:48 ----A---- C:\Windows\SYSWOW64\QSVRMGMT.DLL
2011-06-23 21:21:48 ----A---- C:\Windows\SYSWOW64\PortableDeviceStatus.dll
2011-06-23 21:21:48 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-06-23 21:21:48 ----A---- C:\Windows\system32\takeown.exe
2011-06-23 21:21:47 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2011-06-23 21:21:47 ----A---- C:\Windows\SYSWOW64\WMADMOD.DLL
2011-06-23 21:21:47 ----A---- C:\Windows\SYSWOW64\utildll.dll
2011-06-23 21:21:47 ----A---- C:\Windows\SYSWOW64\Mystify.scr
2011-06-23 21:21:47 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-23 21:21:47 ----A---- C:\Windows\SYSWOW64\mapistub.dll
2011-06-23 21:21:47 ----A---- C:\Windows\SYSWOW64\mapi32.dll
2011-06-23 21:21:47 ----A---- C:\Windows\system32\WMPhoto.dll
2011-06-23 21:21:47 ----A---- C:\Windows\system32\PnPUnattend.exe
2011-06-23 21:21:47 ----A---- C:\Windows\system32\amstream.dll
2011-06-23 21:21:46 ----A---- C:\Windows\SYSWOW64\fphc.dll
2011-06-23 21:21:46 ----A---- C:\Windows\SYSWOW64\dot3msm.dll
2011-06-23 21:21:46 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2011-06-23 21:21:45 ----A---- C:\Windows\SYSWOW64\WMVSDECD.DLL
2011-06-23 21:21:45 ----A---- C:\Windows\SYSWOW64\wmdrmnet.dll
2011-06-23 21:21:45 ----A---- C:\Windows\SYSWOW64\wiavideo.dll
2011-06-23 21:21:45 ----A---- C:\Windows\SYSWOW64\takeown.exe
2011-06-23 21:21:45 ----A---- C:\Windows\SYSWOW64\sqmapi.dll
2011-06-23 21:21:45 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2011-06-23 21:21:45 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2011-06-23 21:21:45 ----A---- C:\Windows\system32\vfwwdm32.dll
2011-06-23 21:21:45 ----A---- C:\Windows\system32\shimgvw.dll
2011-06-23 21:21:45 ----A---- C:\Windows\system32\QCLIPROV.DLL
2011-06-23 21:21:45 ----A---- C:\Windows\system32\netapi32.dll
2011-06-23 21:21:45 ----A---- C:\Windows\system32\HotStartUserAgent.dll
2011-06-23 21:21:45 ----A---- C:\Windows\system32\EhStorAPI.dll
2011-06-23 21:21:45 ----A---- C:\Windows\system32\djoin.exe
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\vfwwdm32.dll
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\sppinst.dll
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\qdv.dll
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\QCLIPROV.DLL
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\MuiUnattend.exe
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\EhStorAPI.dll
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\cmstp.exe
2011-06-23 21:21:44 ----A---- C:\Windows\SYSWOW64\cca.dll
2011-06-23 21:21:44 ----A---- C:\Windows\system32\WUDFx.dll
2011-06-23 21:21:44 ----A---- C:\Windows\system32\WUDFHost.exe
2011-06-23 21:21:44 ----A---- C:\Windows\system32\WavDest.dll
2011-06-23 21:21:44 ----A---- C:\Windows\system32\nrpsrv.dll
2011-06-23 21:21:44 ----A---- C:\Windows\system32\MultiDigiMon.exe
2011-06-23 21:21:44 ----A---- C:\Windows\system32\KMSVC.DLL
2011-06-23 21:21:44 ----A---- C:\Windows\system32\iasrecst.dll
2011-06-23 21:21:44 ----A---- C:\Windows\system32\fdProxy.dll
2011-06-23 21:21:44 ----A---- C:\Windows\system32\drivers\usbser.sys
2011-06-23 21:21:44 ----A---- C:\Windows\system32\drivers\pacer.sys
2011-06-23 21:21:44 ----A---- C:\Windows\system32\cmstp.exe
2011-06-23 21:21:44 ----A---- C:\Windows\system32\CertPolEng.dll
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\wsnmp32.dll
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\WMSPDMOD.DLL
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\setupcln.dll
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\relog.exe
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\pdhui.dll
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\netiougc.exe
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\msorcl32.dll
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\iscsicli.exe
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\iasrecst.dll
2011-06-23 21:21:43 ----A---- C:\Windows\SYSWOW64\AzSqlExt.dll
2011-06-23 21:21:43 ----A---- C:\Windows\system32\wuauclt.exe
2011-06-23 21:21:43 ----A---- C:\Windows\system32\sscore.dll
2011-06-23 21:21:43 ----A---- C:\Windows\system32\relog.exe
2011-06-23 21:21:43 ----A---- C:\Windows\system32\mydocs.dll
2011-06-23 21:21:43 ----A---- C:\Windows\system32\mobsync.exe
2011-06-23 21:21:43 ----A---- C:\Windows\system32\iscsicli.exe
2011-06-23 21:21:43 ----A---- C:\Windows\system32\diskpart.exe
2011-06-23 21:21:43 ----A---- C:\Windows\system32\BWUnpairElevated.dll
2011-06-23 21:21:42 ----A---- C:\Windows\SYSWOW64\wkscli.dll
2011-06-23 21:21:42 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2011-06-23 21:21:42 ----A---- C:\Windows\SYSWOW64\rastapi.dll
2011-06-23 21:21:42 ----A---- C:\Windows\SYSWOW64\netbtugc.exe
2011-06-23 21:21:42 ----A---- C:\Windows\SYSWOW64\mydocs.dll
2011-06-23 21:21:42 ----A---- C:\Windows\SYSWOW64\diskpart.exe
2011-06-23 21:21:42 ----A---- C:\Windows\SYSWOW64\amstream.dll
2011-06-23 21:21:42 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2011-06-23 21:21:42 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2011-06-23 21:21:42 ----A---- C:\Windows\system32\msdmo.dll
2011-06-23 21:21:42 ----A---- C:\Windows\system32\itircl.dll
2011-06-23 21:21:42 ----A---- C:\Windows\system32\dot3msm.dll
2011-06-23 21:21:42 ----A---- C:\Windows\system32\browcli.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\wmpps.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\WerFaultSecure.exe
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\tlscsp.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\syssetup.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\secur32.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\resutils.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\ReAgentc.exe
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\itircl.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\findstr.exe
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2011-06-23 21:21:41 ----A---- C:\Windows\SYSWOW64\CertPolEng.dll
2011-06-23 21:21:41 ----A---- C:\Windows\system32\wuapp.exe
2011-06-23 21:21:41 ----A---- C:\Windows\system32\mciqtz32.dll
2011-06-23 21:21:41 ----A---- C:\Windows\system32\imagehlp.dll
2011-06-23 21:21:41 ----A---- C:\Windows\system32\choice.exe
2011-06-23 21:21:41 ----A---- C:\Windows\system32\FXSTIFF.dll
2011-06-23 21:21:41 ----A---- C:\Windows\system32\findstr.exe
2011-06-23 21:21:41 ----A---- C:\Windows\system32\eappgnui.dll
2011-06-23 21:21:40 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2011-06-23 21:21:40 ----A---- C:\Windows\SYSWOW64\netutils.dll
2011-06-23 21:21:40 ----A---- C:\Windows\SYSWOW64\mobsync.exe
2011-06-23 21:21:40 ----A---- C:\Windows\SYSWOW64\mciqtz32.dll
2011-06-23 21:21:40 ----A---- C:\Windows\system32\sppc.dll
2011-06-23 21:21:40 ----A---- C:\Windows\system32\onexui.dll
2011-06-23 21:21:40 ----A---- C:\Windows\system32\luainstall.dll
2011-06-23 21:21:40 ----A---- C:\Windows\system32\drivers\tunnel.sys
2011-06-23 21:21:40 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\unlodctr.exe
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\sppc.dll
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\spopk.dll
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\shimgvw.dll
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\muifontsetup.dll
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\msdmo.dll
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\luainstall.dll
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2011-06-23 21:21:39 ----A---- C:\Windows\SYSWOW64\cabinet.dll
2011-06-23 21:21:39 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2011-06-23 21:21:39 ----A---- C:\Windows\system32\wdiasqmmodule.dll
2011-06-23 21:21:39 ----A---- C:\Windows\system32\spopk.dll
2011-06-23 21:21:39 ----A---- C:\Windows\system32\schedcli.dll
2011-06-23 21:21:39 ----A---- C:\Windows\system32\repair-bde.exe
2011-06-23 21:21:39 ----A---- C:\Windows\system32\RDPENCDD.dll
2011-06-23 21:21:39 ----A---- C:\Windows\system32\profprov.dll
2011-06-23 21:21:39 ----A---- C:\Windows\system32\odbcconf.dll
2011-06-23 21:21:39 ----A---- C:\Windows\system32\manage-bde.exe
2011-06-23 21:21:39 ----A---- C:\Windows\system32\inetmib1.dll
2011-06-23 21:21:38 ----A---- C:\Windows\SYSWOW64\wups.dll
2011-06-23 21:21:38 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2011-06-23 21:21:38 ----A---- C:\Windows\SYSWOW64\rdprefdrvapi.dll
2011-06-23 21:21:38 ----A---- C:\Windows\SYSWOW64\odbcconf.dll
2011-06-23 21:21:38 ----A---- C:\Windows\SYSWOW64\inetmib1.dll
2011-06-23 21:21:38 ----A---- C:\Windows\SYSWOW64\browcli.dll
2011-06-23 21:21:38 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-06-23 21:21:38 ----A---- C:\Windows\system32\TRAPI.dll
2011-06-23 21:21:38 ----A---- C:\Windows\system32\msfeedssync.exe
2011-06-23 21:21:38 ----A---- C:\Windows\system32\FXSMON.dll
2011-06-23 21:21:38 ----A---- C:\Windows\system32\fixmapi.exe
2011-06-23 21:21:38 ----A---- C:\Windows\system32\elsTrans.dll
2011-06-23 21:21:38 ----A---- C:\Windows\system32\drivers\tdi.sys
2011-06-23 21:21:37 ----A---- C:\Windows\SYSWOW64\perfts.dll
2011-06-23 21:21:37 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-06-23 21:21:37 ----A---- C:\Windows\SYSWOW64\imm32.dll
2011-06-23 21:21:37 ----A---- C:\Windows\SYSWOW64\elsTrans.dll
2011-06-23 21:21:37 ----A---- C:\Windows\system32\wshbth.dll
2011-06-23 21:21:37 ----A---- C:\Windows\system32\rdprefdrvapi.dll
2011-06-23 21:21:37 ----A---- C:\Windows\system32\napdsnap.dll
2011-06-23 21:21:37 ----A---- C:\Windows\system32\LogonUI.exe
2011-06-23 21:21:37 ----A---- C:\Windows\system32\FXSUNATD.exe
2011-06-23 21:21:37 ----A---- C:\Windows\system32\dsauth.dll
2011-06-23 21:21:36 ----A---- C:\Windows\SYSWOW64\TRAPI.dll
2011-06-23 21:21:36 ----A---- C:\Windows\SYSWOW64\bitsperf.dll
2011-06-23 21:21:36 ----A---- C:\Windows\system32\cscdll.dll
2011-06-23 21:21:36 ----A---- C:\Windows\system32\bitsperf.dll
2011-06-23 21:21:35 ----A---- C:\Windows\system32\drivers\usbrpm.sys
2011-06-23 21:21:34 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2011-06-23 21:21:34 ----A---- C:\Windows\SYSWOW64\schedcli.dll
2011-06-23 21:21:34 ----A---- C:\Windows\SYSWOW64\napdsnap.dll
2011-06-23 21:21:34 ----A---- C:\Windows\SYSWOW64\dsauth.dll
2011-06-23 21:21:34 ----A---- C:\Windows\SYSWOW64\cscdll.dll
2011-06-23 21:21:33 ----A---- C:\Windows\system32\wups2.dll
2011-06-23 21:21:33 ----A---- C:\Windows\system32\drivers\acpipmi.sys
2011-06-23 21:21:32 ----A---- C:\Windows\SYSWOW64\wsdchngr.dll
2011-06-23 21:21:32 ----A---- C:\Windows\SYSWOW64\sscore.dll
2011-06-23 21:21:32 ----A---- C:\Windows\system32\wups.dll
2011-06-23 21:21:32 ----A---- C:\Windows\system32\wsdchngr.dll
2011-06-23 21:21:32 ----A---- C:\Windows\system32\shgina.dll
2011-06-23 21:21:31 ----A---- C:\Windows\SYSWOW64\shgina.dll
2011-06-23 21:21:31 ----A---- C:\Windows\SYSWOW64\riched32.dll
2011-06-23 21:21:31 ----A---- C:\Windows\system32\wshirda.dll
2011-06-23 21:21:31 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2011-06-23 21:21:31 ----A---- C:\Windows\system32\drivers\CompositeBus.sys
2011-06-23 21:21:30 ----A---- C:\Windows\SYSWOW64\wshirda.dll
2011-06-23 21:21:30 ----A---- C:\Windows\system32\rdpcfgex.dll
2011-06-23 21:21:30 ----A---- C:\Windows\system32\drivers\hidusb.sys
2011-06-23 21:21:30 ----A---- C:\Windows\system32\drivers\appid.sys
2011-06-23 21:21:29 ----A---- C:\Windows\system32\riched32.dll
2011-06-23 21:21:29 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2011-06-23 21:21:29 ----A---- C:\Windows\system32\browseui.dll
2011-06-23 21:21:28 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2011-06-23 21:21:28 ----A---- C:\Windows\SYSWOW64\C_ISCII.DLL
2011-06-23 21:21:28 ----A---- C:\Windows\SYSWOW64\browseui.dll
2011-06-23 21:21:28 ----A---- C:\Windows\system32\spwmp.dll
2011-06-23 21:21:28 ----A---- C:\Windows\system32\dxmasf.dll
2011-06-23 21:21:28 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2011-06-23 21:21:28 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2011-06-23 21:21:28 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2011-06-23 21:21:28 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2011-06-23 21:21:28 ----A---- C:\Windows\system32\drivers\cdrom.sys
2011-06-23 21:21:28 ----A---- C:\Windows\system32\C_ISCII.DLL
2011-06-23 21:21:27 ----AH---- C:\Windows\system32\api-ms-win-core-ums-l1-1-0.dll
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\shunimpl.dll
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\KBDTUQ.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\KBDTUF.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\KBDSG.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\kbdlk41a.dll
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\KBDGR1.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\KBDGKL.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2011-06-23 21:21:27 ----A---- C:\Windows\system32\shunimpl.dll
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDTUQ.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDTUF.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDSG.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDSF.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDPO.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDNEPR.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\kbdlk41a.dll
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDINTAM.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDINBEN.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDGR1.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\KBDGKL.DLL
2011-06-23 21:21:27 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2011-06-23 21:21:27 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-06-23 21:21:27 ----A---- C:\Windows\system32\drivers\scfilter.sys
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\spwizres.dll
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\pifmgr.dll
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\nlsbres.dll
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDUS.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDUGHR1.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDTURME.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDTAJIK.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDSF.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDPO.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDNEPR.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDMON.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDMAORI.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDLT1.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDINTEL.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDINTAM.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDINORI.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDINMAR.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDINKAN.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDINHIN.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDINBEN.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDGEO.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDCZ1.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDBULG.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDBLR.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\SYSWOW64\dpnaddr.dll
2011-06-23 21:21:26 ----A---- C:\Windows\system32\wmploc.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\tzres.dll
2011-06-23 21:21:26 ----A---- C:\Windows\system32\spwizres.dll
2011-06-23 21:21:26 ----A---- C:\Windows\system32\pifmgr.dll
2011-06-23 21:21:26 ----A---- C:\Windows\system32\nlsbres.dll
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDUS.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDUGHR1.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDTURME.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDTAJIK.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDMON.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDMAORI.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDLT1.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDINTEL.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDINORI.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDINMAR.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDINKAN.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDINHIN.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDGEO.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDCZ1.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDBULG.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDBLR.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\KBDBASH.DLL
2011-06-23 21:21:26 ----A---- C:\Windows\system32\dpnaddr.dll
2011-06-23 21:21:26 ----A---- C:\Windows\system32\BlbEvents.dll
2011-06-23 21:21:04 ----A---- C:\Windows\SYSWOW64\wdscore.dll
2011-06-23 21:21:04 ----A---- C:\Windows\SYSWOW64\PkgMgr.exe
2011-06-23 21:20:56 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2011-06-23 21:20:56 ----A---- C:\Windows\SYSWOW64\dpx.dll
2011-06-23 21:20:54 ----A---- C:\Windows\SYSWOW64\wbemcomn.dll
2011-06-23 21:18:19 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-06-23 21:18:19 ----A---- C:\Windows\system32\wbemcomn.dll
2011-06-23 21:18:12 ----A---- C:\Windows\system32\SmiEngine.dll
2011-06-23 21:18:08 ----A---- C:\Windows\system32\PkgMgr.exe
2011-06-23 21:17:43 ----A---- C:\Windows\system32\drvstore.dll
2011-06-23 21:17:43 ----A---- C:\Windows\system32\dpx.dll
2011-06-18 10:25:35 ----D---- C:\Program Files (x86)\XTB-Trader
2011-06-17 10:09:22 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-06-17 10:09:22 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-06-17 10:09:22 ----A---- C:\Windows\SYSWOW64\java.exe
2011-06-16 14:37:37 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-16 14:37:36 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2011-06-16 14:37:36 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-16 14:37:30 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-16 14:37:30 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-16 14:37:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-16 14:37:19 ----A---- C:\Windows\system32\mshtml.dll
2011-06-16 14:37:18 ----A---- C:\Windows\system32\iertutil.dll
2011-06-16 14:37:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-16 14:37:15 ----A---- C:\Windows\system32\ieframe.dll
2011-06-16 14:37:13 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-16 14:37:12 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-16 14:37:11 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-06-16 14:37:11 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-16 14:37:09 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-16 14:37:09 ----A---- C:\Windows\system32\urlmon.dll
2011-06-16 14:37:08 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-06-16 14:37:08 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-16 14:37:08 ----A---- C:\Windows\system32\wininet.dll
2011-06-16 14:37:07 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-06-16 14:37:07 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-16 14:37:07 ----A---- C:\Windows\system32\ieui.dll
2011-06-16 14:37:01 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-06-16 14:37:01 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-06-16 14:37:01 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-06-16 14:37:01 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-16 14:36:59 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-16 14:36:59 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-16 14:36:59 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-16 14:36:58 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-16 14:36:58 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-16 14:36:56 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-16 14:36:56 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-14 18:50:37 ----D---- C:\Program Files\Common Files\Macrovision Shared
2011-06-14 18:46:31 ----D---- C:\Program Files\Common Files\Autodesk Shared
2011-06-14 18:46:31 ----D---- C:\Program Files\Autodesk
2011-06-14 18:37:54 ----D---- C:\Program Files (x86)\Autodesk
2011-06-14 16:56:48 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\Autodesk
2011-06-14 16:56:48 ----D---- C:\ProgramData\Autodesk
2011-06-14 16:53:57 ----D---- C:\Autodesk
2011-06-09 13:27:08 ----D---- C:\Program Files (x86)\Poker Heaven
2011-06-06 20:59:36 ----D---- C:\Program Files (x86)\Full Tilt Poker
2011-05-31 10:05:03 ----A---- C:\Users\HITTL ROMAN\AppData\Roaming\room_v3.dat
2011-05-31 10:03:56 ----D---- C:\Program Files (x86)\Garena Messenger
2011-05-31 10:03:54 ----D---- C:\ProgramData\GarenaMessenger
2011-05-25 13:25:57 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-05-25 13:25:52 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-05-25 13:25:52 ----A---- C:\Windows\system32\poqexec.exe
2011-05-11 21:38:48 ----D---- C:\9645e8e20a094e065deb5d2eed5dae
2011-05-11 20:46:15 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-05-11 20:46:13 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-05-11 20:46:13 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-05-11 20:46:10 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-05-11 20:46:10 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-05-11 20:46:09 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-05-11 20:46:09 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-05-11 20:46:09 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-05-11 20:46:09 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-05-11 20:46:09 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2011-05-07 09:05:15 ----A---- C:\Windows\War3Unin.pif
2011-05-07 09:05:15 ----A---- C:\Windows\War3Unin.dat
2011-05-07 09:05:14 ----A---- C:\Windows\War3Unin.exe
2011-05-07 09:00:09 ----D---- C:\Program Files (x86)\Warcraft III
2011-04-30 17:46:17 ----A---- C:\Windows\AviSplitter.INI
2011-04-29 20:09:58 ----D---- C:\Program Files (x86)\Veetle
2011-04-29 15:19:17 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\Microgaming
2011-04-29 15:15:39 ----D---- C:\Microgaming
2011-04-29 14:56:01 ----D---- C:\bwinPoker
2011-04-29 14:46:00 ----D---- C:\ProgramData\Boss Media
2011-04-29 14:45:46 ----D---- C:\Program Files (x86)\ParadisePoker
======List of files/folders modified in the last 3 months======

2011-07-28 23:15:26 ----D---- C:\Windows\Temp
2011-07-28 23:15:24 ----RD---- C:\Program Files
2011-07-28 23:13:22 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\Mumble
2011-07-28 22:52:47 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\Skype
2011-07-28 22:42:00 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\SoftGrid Client
2011-07-28 21:14:33 ----D---- C:\Windows\system32\NDF
2011-07-28 21:14:30 ----D---- C:\Windows\Prefetch
2011-07-28 21:08:56 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\DAEMON Tools Lite
2011-07-28 21:08:45 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\TS3Client
2011-07-28 21:08:40 ----D---- C:\Windows\Minidump
2011-07-28 21:08:40 ----D---- C:\Windows\Logs
2011-07-28 21:08:40 ----D---- C:\Windows\debug
2011-07-28 21:08:40 ----D---- C:\Windows
2011-07-28 21:06:04 ----D---- C:\Program Files\CCleaner
2011-07-28 15:17:31 ----D---- C:\ProgramData\WeFi
2011-07-28 14:27:31 ----D---- C:\Windows\system32\config
2011-07-28 14:25:39 ----A---- C:\wowrm.ini
2011-07-28 14:17:14 ----D---- C:\Program Files (x86)\Trillian
2011-07-28 09:43:40 ----SHD---- C:\Windows\Installer
2011-07-28 09:43:40 ----D---- C:\Program Files (x86)\Ask.com
2011-07-28 09:43:39 ----D---- C:\Windows\system32\Tasks
2011-07-28 09:43:35 ----SHD---- C:\Config.Msi
2011-07-27 17:59:50 ----D---- C:\World of Warcraft
2011-07-27 14:55:38 ----D---- C:\ProgramData\boost_interprocess
2011-07-26 13:09:35 ----SHD---- C:\System Volume Information
2011-07-22 22:00:10 ----RD---- C:\Program Files (x86)
2011-07-21 14:31:10 ----D---- C:\Windows\System32
2011-07-21 14:31:10 ----D---- C:\Windows\inf
2011-07-21 14:31:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-15 07:56:29 ----D---- C:\Windows\winsxs
2011-07-15 07:54:19 ----D---- C:\Windows\SysWOW64
2011-07-15 07:54:13 ----D---- C:\Windows\AppPatch
2011-07-15 07:54:11 ----D---- C:\Windows\system32\DriverStore
2011-07-15 07:54:10 ----D---- C:\Windows\system32\drivers
2011-07-14 23:42:19 ----A---- C:\Windows\system32\MRT.exe
2011-07-13 20:09:35 ----HD---- C:\ProgramData
2011-07-13 08:43:08 ----D---- C:\Windows\system32\catroot
2011-07-13 08:43:07 ----D---- C:\Windows\system32\catroot2
2011-07-12 18:50:18 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\vlc
2011-07-06 18:49:38 ----D---- C:\Windows\Microsoft.NET
2011-07-06 18:48:39 ----RSD---- C:\Windows\assembly
2011-07-05 17:37:41 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\ICQ
2011-07-04 19:05:49 ----D---- C:\Program Files\TeamSpeak 3 Client
2011-07-04 15:54:04 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-07-04 13:44:50 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-07-04 12:35:00 ----D---- C:\Windows\rescache
2011-07-04 11:52:46 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-07-04 11:52:46 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-07-04 11:52:46 ----D---- C:\Program Files (x86)\Windows Media Player
2011-07-04 11:52:46 ----D---- C:\Program Files (x86)\Windows Mail
2011-07-04 11:52:46 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-04 11:52:45 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-07-04 11:52:43 ----D---- C:\Program Files\Windows Sidebar
2011-07-04 11:52:43 ----D---- C:\Program Files\Windows Mail
2011-07-04 11:52:43 ----D---- C:\Program Files\DVD Maker
2011-07-04 11:52:42 ----D---- C:\Program Files\Windows Portable Devices
2011-07-04 11:52:42 ----D---- C:\Program Files\Windows Photo Viewer
2011-07-04 11:52:42 ----D---- C:\Program Files\Windows Media Player
2011-07-04 11:52:42 ----D---- C:\Program Files\Internet Explorer
2011-07-04 11:52:41 ----D---- C:\Program Files\Windows Journal
2011-07-04 11:52:37 ----D---- C:\Windows\servicing
2011-07-04 11:52:37 ----D---- C:\Program Files\Windows Defender
2011-07-04 11:52:36 ----D---- C:\Windows\ehome
2011-07-04 11:52:23 ----D---- C:\Windows\SYSWOW64\oobe
2011-07-04 11:52:23 ----D---- C:\Windows\SYSWOW64\migration
2011-07-04 11:52:23 ----D---- C:\Windows\SYSWOW64\da-DK
2011-07-04 11:52:22 ----D---- C:\Windows\SYSWOW64\Setup
2011-07-04 11:52:22 ----D---- C:\Windows\SYSWOW64\cs
2011-07-04 11:52:22 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-07-04 11:52:21 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-07-04 11:52:19 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-07-04 11:52:18 ----D---- C:\Windows\SYSWOW64\wbem
2011-07-04 11:52:18 ----D---- C:\Windows\SYSWOW64\sppui
2011-07-04 11:52:18 ----D---- C:\Windows\SYSWOW64\es-ES
2011-07-04 11:52:17 ----D---- C:\Windows\SYSWOW64\migwiz
2011-07-04 11:52:16 ----D---- C:\Windows\SYSWOW64\Dism
2011-07-04 11:51:25 ----D---- C:\Windows\system32\da-DK
2011-07-04 11:51:25 ----D---- C:\Windows\PolicyDefinitions
2011-07-04 11:51:24 ----D---- C:\Windows\system32\oobe
2011-07-04 11:51:24 ----D---- C:\Windows\system32\migration
2011-07-04 11:51:24 ----D---- C:\Windows\system32\en-US
2011-07-04 11:51:23 ----D---- C:\Windows\system32\Setup
2011-07-04 11:51:23 ----D---- C:\Windows\system32\cs
2011-07-04 11:51:23 ----D---- C:\Windows\system32\AdvancedInstallers
2011-07-04 11:51:21 ----D---- C:\Windows\system32\cs-CZ
2011-07-04 11:51:18 ----D---- C:\Windows\system32\sppui
2011-07-04 11:51:18 ----D---- C:\Windows\system32\manifeststore
2011-07-04 11:51:18 ----D---- C:\Windows\system32\es-ES
2011-07-04 11:51:16 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-07-04 11:51:15 ----D---- C:\Windows\system32\wbem
2011-07-04 11:51:14 ----D---- C:\Windows\system32\migwiz
2011-07-04 11:51:14 ----D---- C:\Windows\system32\Dism
2011-07-04 11:50:16 ----RSD---- C:\Windows\Fonts
2011-07-04 11:49:47 ----D---- C:\Windows\system32\Boot
2011-07-03 09:44:34 ----A---- C:\Windows\SYSWOW64\msclmd.dll
2011-07-03 09:44:33 ----A---- C:\Windows\system32\msclmd.dll
2011-07-02 15:46:25 ----D---- C:\Program Files (x86)\Scorpions WinCheater
2011-07-01 13:41:16 ----SD---- C:\Users\HITTL ROMAN\AppData\Roaming\Microsoft
2011-06-27 15:43:52 ----D---- C:\Program Files\Zrychleni Pocitace
2011-06-17 10:10:25 ----D---- C:\Program Files (x86)\Common Files
2011-06-17 10:09:17 ----D---- C:\Program Files (x86)\Java
2011-06-17 00:11:02 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-06-17 00:09:25 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-17 00:07:47 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-06-16 19:25:42 ----D---- C:\ProgramData\Adobe
2011-06-16 19:25:41 ----D---- C:\Program Files (x86)\Adobe
2011-06-14 18:57:55 ----D---- C:\ProgramData\FLEXnet
2011-06-14 18:53:12 ----D---- C:\Windows\Downloaded Program Files
2011-06-14 18:50:37 ----D---- C:\Program Files\Common Files
2011-06-11 22:42:35 ----D---- C:\Windows\system32\wdi
2011-06-06 20:24:46 ----D---- C:\Program Files (x86)\ICQ7.2
2011-06-01 18:50:06 ----D---- C:\Program Files (x86)\Google
2011-05-31 18:33:05 ----D---- C:\Program Files (x86)\The KMPlayer
2011-05-27 07:54:26 ----D---- C:\Program Files (x86)\LJ-Widget
2011-05-24 19:14:10 ----N---- C:\Windows\system32\MpSigStub.exe
2011-05-06 16:01:56 ----D---- C:\Users\HITTL ROMAN\AppData\Roaming\SolidWorks
2011-05-05 17:51:00 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-05-04 04:52:22 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-05-03 20:14:15 ----D---- C:\Windows\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-08-23 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-01-13 513080]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 141264]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 170640]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 125296]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-04-21 6406144]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-04-21 188928]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-05-11 2229608]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2010-07-29 28832]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-06-22 2399848]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2010-05-14 384040]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2010-04-20 18432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-06-17 246376]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2010-01-27 231328]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-12-10 301104]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2010-07-09 17408]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S2 SentinelFilter;SentinelFilter; \??\C:\Windows\syswow64 []
S3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2010-07-29 36000]
S3 ATHDFU;Atheros Valkyrie USB BootROM; C:\Windows\System32\Drivers\AthDfu.sys [2010-07-29 51872]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2010-07-29 295072]
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2010-07-29 201376]
S3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2010-07-29 51872]
S3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2010-07-29 154272]
S3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2010-07-29 270496]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena Messenger\Room\safedrv.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-12-02 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-12-02 27136]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-12-02 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2010-12-02 9216]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2010-12-22 154256]
S3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM); C:\Windows\system32\DRIVERS\vcsvad.sys [2008-12-26 21504]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-04-21 202752]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2010-07-29 52896]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2011-02-02 18656]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-08-10 321104]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-12 868896]
R2 GREGService;GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-06-02 246520]
R2 NOBU;Norton Online Backup; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-06-02 2804568]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-06-29 255744]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-01-15 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2011-01-15 107832]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-07-27 249136]
R2 SentinelKeysServer;Sentinel Keys Server; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [2006-08-22 316992]
R2 SentinelProtectionServer;Sentinel Protection Server; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [2006-12-21 206400]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-29 243232]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 WefiEngSvc;WeFi Engine Service; C:\Program Files (x86)\WeFi\WefiEngSvc.exe [2010-11-03 120152]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-31 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-12 42360]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-06-14 1431888]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-11-20 655624]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2011-05-05 30192]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-31 136176]
S3 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-13 1255736]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Preventivní log (prosim o kontrolu)

Napsal: 29 črc 2011 07:22
od vyosek
Zdravim a pekny den preji :)

:arrow: Poprosim i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit

:arrow: Predpokladam, ze ten NOD32 mate legalni = zakoupena licence? Ne jen jednou za mesic jeho preinstalovani na trial licenci

Re: Preventivní log (prosim o kontrolu)

Napsal: 29 črc 2011 08:11
od nom
Ano nod je legální ale není to zakoupená licence je to licence zdarma na rok z jejich prezentace

info.txt logfile of random's system information tool 1.09 2011-07-28 23:15:38

======Uninstall list======

-->"C:\Program Files (x86)\InstallShield Installation Information\{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}\setup.exe" -runfromtemp -l0x0405 -removeonly
-->"C:\Program Files (x86)\InstallShield Installation Information\{C2695E83-CF1D-43D1-84FE-B3BEC561012A}\setup.exe" -runfromtemp -l0x0409 -removeonly
Acer Backup Manager-->C:\Program Files (x86)\InstallShield Installation Information\{72B776E5-4530-4C4B-9453-751DF87D9D93}\setup.exe -runfromtemp -l0x0409
Acer Crystal Eye webcam Ver:1.1.192.810-->"C:\Program Files (x86)\InstallShield Installation Information\{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}\setup.exe" -runfromtemp -l0x0409 -removeonly
Acer ePower Management-->"C:\Program Files (x86)\InstallShield Installation Information\{3DB0448D-AD82-4923-B305-D001E521A964}\setup.exe" -runfromtemp -l0x405 -removeonly
Acer eRecovery Management-->"C:\Program Files (x86)\InstallShield Installation Information\{7F811A54-5A09-4579-90E1-C93498E230D9}\setup.exe" -runfromtemp -l0x405 -removeonly
Acer GameZone Console-->"C:\Program Files (x86)\Acer GameZone\GameConsole\unins000.exe"
Acer Registration-->C:\Program Files (x86)\Acer\Registration\Uninstall.exe
Acer ScreenSaver-->C:\Program Files (x86)\Acer\Screensaver\Uninstall.exe
Acer Updater-->"C:\Program Files (x86)\InstallShield Installation Information\{EE171732-BEB4-4576-887D-CB62727F01CA}\setup.exe" -runfromtemp -l0x405 -removeonly
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Adobe AIR-->c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10i_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10t_Plugin.exe -maintain plugin
Adobe Reader X (10.1.0) - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-AA1000000001}
Aegisub 2.1.8-->"C:\Program Files (x86)\Aegisub\unins000.exe"
Airport Mania First Flight-->"C:\Program Files (x86)\Acer GameZone\Airport Mania First Flight\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Airport Mania First Flight\install.log"
Alchemy Mahjong-->C:\Program Files (x86)\Hry.cz\Alchemy Mahjong\Uninstall.exe
Allods Online 2.0.02.89-->C:\gPotato.com\Allods Online\uninst.exe
Amazonia-->"C:\Program Files (x86)\Acer GameZone\Amazonia\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Amazonia\install.log"
Angry Birds-->MsiExec.exe /I{80843623-6460-4A3E-BFE6-6C66BDAE5178}
Ask Toolbar-->MsiExec.exe /X{86D4B82A-ABED-442A-BE86-96357B70F4FE}
ATI Catalyst Install Manager-->msiexec /q/x{21958FA9-A346-4745-E831-98013FA0C203} REBOOT=ReallySuppress
Audacity 1.3.12 (Unicode)-->"C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)\unins000.exe"
AutoCAD LT 2012 - Czech-->C:\Program Files\Autodesk\AutoCAD LT 2012 - Czech\Setup\Setup.exe /P {5783F2D7-A009-0405-0102-0060B0CE6BBA} /M ACADLT /language cs-CZ
AutoCAD LT 2012 - Czech-->C:\Program Files\Autodesk\AutoCAD LT 2012 - Czech\Setup\Setup.exe /P {5783F2D7-A009-0405-0102-0060B0CE6BBA} /M ACADLT /language cs-CZ
Autodesk Content Service-->MsiExec.exe /X{086F9A69-CD39-4893-A9FB-D3A0634CE3F7}
Autodesk Design Review 2012-->C:\Program Files (x86)\Autodesk\Autodesk Design Review 2012\Setup\Setup.exe /P {A49BDCBE-590E-43A6-AB77-7C40E499B7C1} /M ADR /language en-US
Autodesk Material Library 2012-->MsiExec.exe /I{8F0837C2-EE09-4903-88F3-1976FE7FFF4E}
Autodesk Material Library Base Resolution Image Library 2012-->MsiExec.exe /I{65420DC9-306E-4371-905F-F4DC3B418E52}
AutoHotkey 1.0.48.05-->C:\Program Files\AutoHotkey\uninst.exe
AV Voice Changer Software 7.0-->C:\PROGRA~2\AVVCS7~1.0\UNWISE.EXE C:\PROGRA~2\AVVCS7~1.0\INSTALL.LOG
Backup Manager Basic-->C:\Program Files (x86)\InstallShield Installation Information\{72B776E5-4530-4C4B-9453-751DF87D9D93}\setup.exe -runfromtemp -l0x0409
Bing Bar Platform-->MsiExec.exe /I{02EE107B-8D95-4949-8935-4DEBE8F08BE3}
Bluetooth Win7 Suite (64)-->MsiExec.exe /X{230D1595-57DA-4933-8C4E-375797EBB7E1}
bwin Poker-->"C:\bwinPoker\unins000.exe"
Cake Mania-->"C:\Program Files (x86)\Acer GameZone\Cake Mania\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Cake Mania\install.log"
Catalyst Control Center - Branding-->MsiExec.exe /I{FC635D8E-FFBA-4B2C-BE68-A37D56BDFB74}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
CyberLink PowerDVD 9-->"C:\Program Files (x86)\InstallShield Installation Information\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\setup.exe" /z-uninstall
CyberLink PowerDVD 9-->"C:\Program Files (x86)\InstallShield Installation Information\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\setup.exe" /z-uninstall
D3DX10-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
DAEMON Tools Lite-->C:\Program Files (x86)\DAEMON Tools Lite\uninst.exe
DAEMON Tools Toolbar-->C:\Program Files (x86)\DAEMON Tools Toolbar\uninst.exe
Dostihy 3000 deluxe 1.1-->"C:\Program Files\Dostihy 3000 Deluxe\uninstall.exe"
Dream Day First Home-->"C:\Program Files (x86)\Acer GameZone\Dream Day First Home\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Dream Day First Home\install.log"
DriverMax 5-->"C:\Program Files (x86)\Innovative Solutions\DriverMax\unins000.exe"
eSobi v2-->C:\Program Files (x86)\InstallShield Installation Information\{15D967B5-A4BE-42AE-9E84-64CD062B25AA}\setup.exe -runfromtemp -l0x0409
EVEREST Ultimate Edition v5.50-->"C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\unins000.exe"
Far Cry 2-->"C:\Program Files (x86)\InstallShield Installation Information\{F2835483-37F2-4123-B4FE-0E77D58447F2}\setup.exe" -runfromtemp -l0x0005 -removeonly
Farm Frenzy 2-->"C:\Program Files (x86)\Acer GameZone\Farm Frenzy 2\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Farm Frenzy 2\install.log"
Fraps-->"C:\Fraps\uninstall.exe"
Full Tilt Poker-->C:\Program Files (x86)\Full Tilt Poker\uninstall.exe
Galapago-->"C:\Program Files (x86)\Acer GameZone\Galapago\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Galapago\install.log"
Garena Messenger-->C:\Program Files (x86)\Garena Messenger\uninst.exe
Google Desktop-->C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Earth Plug-in-->MsiExec.exe /X{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\12.0.742.122\Installer\setup.exe" --uninstall --system-level
Google SketchUp 6-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x5 -removeonly
Google SketchUp 6-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x5 -removeonly
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Gothic III-->C:\Program Files (x86)\InstallShield Installation Information\{02B244A2-7F6A-42E8-A36F-8C385D7A1625}\setup.exe -runfromtemp -l0x0005 -removeonly
Harry Potter(TM) a vězeň z Azkabanu-->C:\Program Files (x86)\EA GAMES\Harry Potter(TM) a vězeň z Azkabanu\EAUninstall.exe
Heroes of Hellas-->"C:\Program Files (x86)\Acer GameZone\Heroes of Hellas\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Heroes of Hellas\install.log"
Hot Potatoes-->MsiExec.exe /X{58EAED3C-1704-4F9A-BB7B-B8D31F5762C5}
Cheat Engine 6.1-->"C:\Program Files (x86)\Cheat Engine 6.1\unins000.exe"
ICQ Toolbar-->C:\Program Files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
ICQ7.2-->"C:\Program Files (x86)\InstallShield Installation Information\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
Identity Card-->C:\Program Files (x86)\Acer\Identity Card\Uninstall.exe
Java(TM) 6 Update 26-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216023FF}
Jolicloud USB Creator 1.2.1-->"C:\Program Files (x86)\Jolicloud USB Creator\unins000.exe"
Junk Mail filter update-->MsiExec.exe /I{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
Keyword Crawler-->MsiExec.exe /I{54DC1593-E881-4EEB-BAE0-6638D78CE4F6}
Launch Manager-->C:\Windows\UNINSTLMv4.EXE LMv4.UNI
LJ-Widget-->msiexec /qb /x {8CF431C9-B78C-9225-EDF7-7F5135C1B8EF}
LJ-Widget-->MsiExec.exe /I{8CF431C9-B78C-9225-EDF7-7F5135C1B8EF}
Merriam Websters Spell Jam-->"C:\Program Files (x86)\Acer GameZone\Merriam Websters Spell Jam\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Merriam Websters Spell Jam\install.log"
MHD Simulator 2009 - SCORE edice-->C:\Program Files (x86)\MHD Simulator 2009\Uninstal.exe
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /x64 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{790E02A1-145A-3843-8C13-A4F41C9B48B7}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft .NET Framework 4 Extended CSY Language Pack-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\ExtendedLP\Setup.exe /repair /x86 /x64 /lcid 1029 /parameterfolder ExtendedLP
Microsoft .NET Framework 4 Extended CSY Language Pack-->MsiExec.exe /X{A324DC11-FF02-3CE8-9D6F-67EBC006D970}
Microsoft .NET Framework 4 Extended-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /x64 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{8E34682C-8118-31F1-BC4C-98CD9675E1C2}
Microsoft Default Manager-->MsiExec.exe /X{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}
Microsoft Office 2010-->MsiExec.exe /X{95140000-0070-0000-0000-0000000FF1CE}
Microsoft Office Klikni a spusť 2010-->"C:\PROGRA~2\COMMON~1\MICROS~1\VIRTUA~1\CVHBS.EXE" /removeall
Microsoft Office Klikni a spusť 2010-->MsiExec.exe /I{90140000-006D-0405-1000-0000000FF1CE}
Microsoft Office Starter 2010 - čeština-->C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvhbs.exe /uninstall {90140011-0066-0405-0000-0000000FF1CE}
Microsoft PowerPoint Viewer-->MsiExec.exe /X{95140000-00AF-0405-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{928B06E4-DDAA-476A-926A-641620326327}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053-->MsiExec.exe /X{B6E3757B-5E77-3915-866A-CCFC4B8D194C}
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175-->MsiExec.exe /X{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148-->MsiExec.exe /X{EE936C7A-EA40-31D5-9B65-8E3E089C3828}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570-->MsiExec.exe /X{8338783A-0968-3B85-AFC7-BAAE0A63DC50}
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570-->MsiExec.exe /X{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319-->MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}
Moje slovíčka 1.3-->"C:\Program Files (x86)\Moje slovíčka\unins000.exe"
Mount&Blade Warband-->C:\Program Files (x86)\Mount&Blade Warband\uninstall.exe
Mozilla Firefox (3.6.18)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSVCRT_amd64-->MsiExec.exe /I{D0B44725-3666-492D-BEF6-587A14BD9BD9}
MSVCRT-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Mumble and Murmur-->C:\Program Files (x86)\Mumble\Uninstall.exe
MyWinLocker Suite-->"C:\Program Files (x86)\InstallShield Installation Information\{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}\setup.exe" -runfromtemp -l0x0405 -removeonly
MyWinLocker Suite-->MsiExec.exe /X{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}
MyWinLocker-->MsiExec.exe /X{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}
Nokia Connectivity Cable Driver-->RUNDLL32.EXE ccdcmbwux64.dll,WuUninstall
Norton Online Backup-->MsiExec.exe /X{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}
NTI Media Maker 9-->C:\Program Files (x86)\InstallShield Installation Information\{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}\setup.exe -runfromtemp -l0x0409
OpenOffice.org 3.2-->MsiExec.exe /I{FAB43061-FEFB-46E8-A159-96710395DB5E}
Pando Media Booster-->C:\Program Files (x86)\Pando Networks\Media Booster\uninst.exe
Panel nástrojů Bing-->C:\Program Files (x86)\Bing Bar Installer\InstallManager.exe /UNINSTALL
ParadisePoker-->C:\PROGRA~2\PARADI~1\UNWISE.EXE C:\PROGRA~2\PARADI~1\INSTALL.LOG
Plus500-->C:\Program Files (x86)\Plus500\Plus500.exe /uninstall
Poker Heaven-->C:\PROGRA~2\POKERH~1\UNWISE.EXE C:\PROGRA~2\POKERH~1\INSTALL.LOG
Poker Pop-->"C:\Program Files (x86)\Acer GameZone\Poker Pop\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Poker Pop\install.log"
Polda III-->"C:\Windows\UNISTB32.EXE" /U "C:\Program Files (x86)\Polda 3\UNINST0.000" "C:\Program Files (x86)\Polda 3\UNINST1.000"
Port Royale 2-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\Ascaron\Port Royale 2\Uninstall\setup.exe" -l0x5
Port Royale-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\Ascaron\Port Royale\Uninstall\setup.exe" -l0x5
Pro Evolution Soccer 2009-->MsiExec.exe /X{A8DB611A-D80E-450D-85F6-3ACDD164BE31}
PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
RAR Password Recovery v1.1 RC17 (remove only)-->C:\Program Files (x86)\Intelore\RAR Password Recovery\uninstall.exe
Realtek HDMI Audio Driver for ATI-->C:\Program Files\Realtek\Audio\HDA\RtkUpd64.exe -k -m -nrg2709
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Realtek USB 2.0 Card Reader-->"C:\Program Files (x86)\InstallShield Installation Information\{96AE7E41-E34E-47D0-AC07-1091A8127911}\setup.exe" -runfromtemp -removeonly
Scorpions WinCheater-->"C:\Program Files (x86)\Scorpions WinCheater\unins000.exe"
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD8D7C9A-E56A-3E7B-BA6D-FE68F13296E3} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {F66C3466-1FDB-347C-B3AE-FB6C50627B10} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {B5BD3CA1-11AB-35A6-B22A-6A219DC0668E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E720AD01-93D5-3E8E-BB8D-E4EF5AF4E5DD} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {B5BD3CA1-11AB-35A6-B22A-6A219DC0668E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {E720AD01-93D5-3E8E-BB8D-E4EF5AF4E5DD} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {3162617C-537F-3BB6-8D0C-C6021F442391} /parameterfolder Extended
Sentinel Protection Installer 7.1.0-->MsiExec.exe /I{4C1A3B65-E284-4F04-822F-3774E0CEEF67}
Sentinel Protection Installer 7.3.2-->MsiExec.exe /I{EDFE2142-CFB3-44AB-A961-DE85F6408A28}
Shockwave Player-->MsiExec.exe /X{930439A1-B49E-4A54-A499-31BDC1A91DE5}
Shredder-->MsiExec.exe /I{C2695E83-CF1D-43D1-84FE-B3BEC561012A}
Singles-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{5628829F-3318-4DDA-988D-D301832F1611}\setup.exe"
Sizer 3.32-->MsiExec.exe /X{DE43AA92-E8C0-4620-AFE2-FBD623C71643}
Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
SolidWorks 2005 SP0-->MsiExec.exe /I{58CAF800-851B-48E8-AFDE-3FAF1981D714}
Spin & Win-->"C:\Program Files (x86)\Acer GameZone\Spin & Win\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Spin & Win\install.log"
SURFCAM DNC-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{72EB4A51-9F4B-4C1E-9467-5448D40C57C5}\setup.exe" -l0x9
SURFCAM Network SIM 8.0-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{62CFE7BF-0BA7-40F5-9CB3-6F5DA10784B3}\setup.exe" -l0x9
SURFCAM SolidsOneStep-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{662BE674-A963-4F49-BC8A-3B97F8196136}\setup.exe" -l0x9
SURFCAM VELOCITY 3.0-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{FFB332F6-8FEE-4CEE-BC9E-56EBEA89431E}\setup.exe" -l0x9
Synaptics Pointing Device Driver-->rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
The KMPlayer (remove only)-->"C:\Program Files (x86)\The KMPlayer\uninstall.exe"
TheGuild2-->MsiExec.exe /I{54EA04A0-E1E5-47FB-9B1E-268D3C3BE199}
TmNationsForever-->"C:\Program Files (x86)\TmNationsForever\unins000.exe"
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
Trillian-->C:\Program Files (x86)\Trillian\trillian.exe /uninstall
Ubuntu-->C:\ubuntu\uninstall-wubi.exe
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {A45DD0BE-3CD9-3F1E-B233-B90C6983AE77} /parameterfolder Client
Veetle TV 0.9.18-->C:\Program Files (x86)\Veetle\UninstallVeetleTV.exe
Vegas Pro 9.0 (64-bit)-->MsiExec.exe /X{DD57342D-62B2-4D22-90FB-0BE732962410}
VertrigoServ (remove only)-->C:\Program Files (x86)\VertrigoServ\Uninstall.exe
VLC media player 1.1.7-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
Warcraft III-->C:\Windows\War3Unin.exe C:\Windows\War3Unin.dat
WebDwarf V2-->MsiExec.exe /I{0D92D5D0-624F-4ED3-98C2-CEE6A3285544}
Websurf verze 1.0.0.2-->"C:\Program Files (x86)\navstevnost\Websurf\unins000.exe"
WeFi 4.0.1.0-->C:\Program Files (x86)\WeFi\uninst.exe
Welcome Center-->C:\Program Files (x86)\Acer\Welcome Center\Uninstall.exe
Windows Live Communications Platform-->MsiExec.exe /I{D45240D3-B6B3-4FF9-B243-54ECE3E10066}
Windows Live Essentials-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}
Windows Live Fotogalerie-->MsiExec.exe /X{FB79FDB7-4DE1-453D-99FE-9A880F57380E}
Windows Live ID Sign-in Assistant-->MsiExec.exe /I{1B8ABA62-74F0-47ED-B18C-A43128E591B8}
Windows Live Installer-->MsiExec.exe /I{0B0F231F-CE6A-483D-AA23-77B364F75917}
Windows Live Language Selector-->MsiExec.exe /I{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}
Windows Live Mail-->MsiExec.exe /I{9D56775A-93F3-44A3-8092-840E3826DE30}
Windows Live Mail-->MsiExec.exe /I{C454280F-3C3E-4929-B60E-9E6CED5717E7}
Windows Live Messenger-->MsiExec.exe /X{50300123-F8FC-4B50-B449-E847D04F1BA2}
Windows Live Messenger-->MsiExec.exe /X{EB4DF488-AAEF-406F-A341-CB2AAA315B90}
Windows Live MIME IFilter-->MsiExec.exe /I{DA54F80E-261C-41A2-A855-549A144F2F59}
Windows Live Movie Maker-->MsiExec.exe /X{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}
Windows Live Movie Maker-->MsiExec.exe /X{92EA4134-10D1-418A-91E1-5A0453131A38}
Windows Live Photo Common-->MsiExec.exe /X{78906B56-0E81-42A7-AC25-F54C946E1538}
Windows Live Photo Common-->MsiExec.exe /X{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}
Windows Live Photo Gallery-->MsiExec.exe /X{3336F667-9049-4D46-98B6-4C743EEBC5B1}
Windows Live PIMT Platform-->MsiExec.exe /I{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}
Windows Live SOXE Definitions-->MsiExec.exe /I{200FEC62-3C34-4D60-9CE8-EC372E01C08F}
Windows Live SOXE-->MsiExec.exe /I{682B3E4F-696A-42DE-A41C-4C07EA1678B4}
Windows Live Sync-->MsiExec.exe /X{1407B87C-36E3-4FC1-9051-D08B21E1096F}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{463F67F4-58D0-4C0D-BBC9-D0CC4E56D1B8}
Windows Live UX Platform-->MsiExec.exe /I{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}
Windows Live Writer Resources-->MsiExec.exe /X{AB78C965-5C67-409B-8433-D7B5BDB12073}
Windows Live Writer-->MsiExec.exe /X{4264C020-850B-4F08-ACBE-98205D9C336C}
Windows Live Writer-->MsiExec.exe /X{A726AE06-AAA3-43D1-87E3-70F510314F04}
Windows Live Writer-->MsiExec.exe /X{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Wireshark 1.2.5-->"C:\Program Files\Wireshark\uninstall.exe"
Word Manager DEMO-->C:\Program Files (x86)\Vitware\Word Manager DEMO\uninstall.exe
Word Tester-->MsiExec.exe /I{299BEFFF-9F48-494F-8D1A-9BFB21CB9440}
World of Tanks closed Beta v.0.6.2.8-->"C:\Games\World_of_Tanks_closed_Beta\unins000.exe"
XTB-Trader 4.00-->"C:\Program Files (x86)\XTB-Trader\Uninstall.exe" "C:\Program Files (x86)\XTB-Trader\install.log"
Zrychleni Pocitace-->"C:\Program Files\Zrychleni Pocitace\unins000.exe"

======System event log======

Computer Name: NOMOVO-NOTEBOOK
Event Code: 62464
Message: UVD Information
Record Number: 63672
Source Name: amdkmdag
Time Written: 20110429192457.789435-000
Event Type: Informace
User:

Computer Name: NOMOVO-NOTEBOOK
Event Code: 62464
Message: UVD Information
Record Number: 63671
Source Name: amdkmdag
Time Written: 20110429192457.789435-000
Event Type: Informace
User:

Computer Name: NOMOVO-NOTEBOOK
Event Code: 62464
Message: UVD Information
Record Number: 63670
Source Name: amdkmdag
Time Written: 20110429192457.789435-000
Event Type: Informace
User:

Computer Name: NOMOVO-NOTEBOOK
Event Code: 62464
Message: UVD Information
Record Number: 63669
Source Name: amdkmdag
Time Written: 20110429192457.789435-000
Event Type: Informace
User:

Computer Name: NOMOVO-NOTEBOOK
Event Code: 62464
Message: UVD Information
Record Number: 63668
Source Name: amdkmdag
Time Written: 20110429192456.297350-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: NOMOVO-PC
Event Code: 1001
Message: Čítače výkonu pro službu WmiApRpl (WmiApRpl) byly úspěšně odstraněny. Data záznamu obsahují nové hodnoty položek Last Counter a Last Help systémového registru.
Record Number: 856
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20101120174951.979282-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: NOMOVO-PC
Event Code: 1532
Message: Služba Profil uživatele byla zastavena.


Record Number: 855
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20101120174450.315463-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: WIN-NO9QRQDAFVN
Event Code: 1003
Message: Služba Windows Search byla spuštěna.

Record Number: 854
Source Name: Microsoft-Windows-Search
Time Written: 20101120174346.000000-000
Event Type: Informace
User:

Computer Name: WIN-NO9QRQDAFVN
Event Code: 1013
Message: Služba Windows Search byla řádně zastavena.

Record Number: 853
Source Name: Microsoft-Windows-Search
Time Written: 20101120174346.000000-000
Event Type: Informace
User:

Computer Name: WIN-NO9QRQDAFVN
Event Code: 103
Message: Windows (2996) Windows: Databázový stroj zastavil instanci (0).
Record Number: 852
Source Name: ESENT
Time Written: 20101120174345.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: WIN-NO9QRQDAFVN
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: WIN-NO9QRQDAFVN$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x278
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 604
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101120174348.024154-000
Event Type: Úspěšný audit
User:

Computer Name: WIN-NO9QRQDAFVN
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 603
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101120174346.417351-000
Event Type: Úspěšný audit
User:

Computer Name: WIN-NO9QRQDAFVN
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: WIN-NO9QRQDAFVN$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x278
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 602
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101120174346.417351-000
Event Type: Úspěšný audit
User:

Computer Name: WIN-NO9QRQDAFVN
Event Code: 4738
Message: Byl změněn uživatelský účet.

Předmět:
ID zabezpečení: S-1-5-21-1498072532-3510031312-3464764778-500
Název účtu: Administrator
Doména účtu: WIN-NO9QRQDAFVN
ID přihlášení: 0x28458

Cílový účet:
ID zabezpečení: S-1-5-21-1498072532-3510031312-3464764778-500
Název účtu: Administrator
Doména účtu: WIN-NO9QRQDAFVN

Změněné atributy:
Název účtu SAM: -
Zobrazovaný název: -
Zaregistrovaný název uživatele: -
Domovský adresář: -
Domovská jednotka: -
Cesta skriptu: -
Cesta profilu: -
Pracovní stanice uživatele: -
Poslední nastavení hesla: -
Vypršení platnosti účtu: -
ID primární skupiny: -
Povolené delegování: -
Původní hodnota UAC: 0x211
Nová hodnota UAC: 0x211
Řízení účtu uživatele: -
Parametry uživatele: -
Historie identifikátoru zabezpečení: -
Přihlašovací hodiny: -

Další informace:
Oprávnění: -
Record Number: 601
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101120174344.233347-000
Event Type: Úspěšný audit
User:

Computer Name: WIN-NO9QRQDAFVN
Event Code: 1102
Message: Protokol auditu byl vymazán.
Předmět:
ID zabezpečení: S-1-5-21-1498072532-3510031312-3464764778-500
Název účtu: Administrator
Název domény: WIN-NO9QRQDAFVN
ID přihlášení: 0x28458
Record Number: 600
Source Name: Microsoft-Windows-Eventlog
Time Written: 20101120174339.350539-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\EgisTec MyWinLocker\x86;C:\Program Files (x86)\EgisTec MyWinLocker\x64;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\WeFi;C:\Program Files (x86)\Windows Live\Shared;C:\SURFCAM\Velocity3\Trans\PrsdDll\Dll
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=16
"PROCESSOR_IDENTIFIER"=AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=0503
"ARCH"=NT_DLL
"PSDIR"=C:\SURFCAM\Velocity3\Trans\PrsdDll
"P_SCHEMA"=C:\SURFCAM\Velocity3\Trans\PrsdDll\PSchema
"P_LISP"=C:\SURFCAM\Velocity3\Trans\PrsdDll\Lispdata
"CM2012DIR"=C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\
"ILBDIR"=C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\

-----------------EOF-----------------

Re: Preventivní log (prosim o kontrolu)

Napsal: 29 črc 2011 09:08
od vyosek
:arrow: Stahnete OTL (viz muj podpis) a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    netsvcs
    drivers32
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    c:\windows\*.* /U
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    /md5start
    adp3132.sys
    AGP440.sys
    ahcix86.sys
    ahcix86s.sys
    atapi.sys
    autochk.exe
    cdrom.sys
    cngaudit.dll
    cryptsvc.dll
    eNetHook.dll
    eventlog.dll
    explorer.exe
    hal.dll
    Changer.sys
    iaStor.sys
    iastorv.sys
    IdeChnDr.sys
    isapnp.sys
    JakNDis.sys
    KR10N.sys
    logevent.dll
    lsass.exe
    mv61xx.sys
    ndis.sys
    netlogon.dll
    ntelogon.dll
    nvata.sys
    nvatabus.sys
    nvgts.sys
    nvraid.sys
    nvrd32.sys
    nvstor.sys
    nvstor32.sys
    scecli.dll
    sceclt.dll
    smss.exe
    svchost.exe
    symmpi.sys
    tcpip.sys
    userinit.exe
    vaxscsi.sys
    viamraid.sys
    viasraid.sys
    ViPrt.sys
    winlogon.exe
    ws2_32.dll
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    CREATERESTOREPOINT
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte

Re: Preventivní log (prosim o kontrolu)

Napsal: 29 črc 2011 15:43
od nom
Vyhodí to chybu: Cannot create file c:\Users\HITTL ROMAN\Desktop\cmd.bat.

//edit : a ano spustil sem to jako spravce zkoušel sem to znovu

Re: Preventivní log (prosim o kontrolu)

Napsal: 29 črc 2011 15:50
od vyosek
OK, pouzijte tento (upraveny) skript

Kód: Vybrat vše

netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT

Re: Preventivní log (prosim o kontrolu)

Napsal: 01 srp 2011 16:57
od nom
OTL logfile created on: 8/1/2011 5:18:03 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\HITTL ROMAN\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4.00 Gb Total Physical Memory | 2.15 Gb Available Physical Memory | 53.90% Memory free
4.24 Gb Paging File | 2.29 Gb Available in Paging File | 53.86% Paging File free
Paging file location(s): c:\pagefile.sys 256 8180 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.66 Gb Total Space | 125.93 Gb Free Space | 27.82% Space Free | Partition Type: NTFS
Drive G: | 1.83 Gb Total Space | 1.83 Gb Free Space | 100.00% Space Free | Partition Type: FAT

Computer Name: NOMOVO-NOTEBOOK | User Name: HITTL ROMAN | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2011/07/29 15:42:03 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\HITTL ROMAN\Desktop\OTL.exe
PRC - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/02/02 14:08:16 | 000,018,656 | ---- | M] () -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
PRC - [2011/01/20 11:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2011/01/15 22:10:06 | 000,107,832 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe
PRC - [2011/01/15 22:09:57 | 000,066,872 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011/01/12 17:41:42 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2010/11/20 19:14:35 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2010/11/03 11:21:46 | 000,120,152 | ---- | M] (WeFi) -- C:\Program Files (x86)\WeFi\WefiEngSvc.exe
PRC - [2010/11/03 11:21:44 | 001,645,912 | ---- | M] (WeFi) -- C:\Program Files (x86)\WeFi\WeFi.exe
PRC - [2010/08/29 09:20:06 | 007,704,216 | ---- | M] (Blizzard Entertainment) -- C:\World of Warcraft\Wow.exe
PRC - [2010/08/10 11:06:16 | 000,975,952 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010/08/10 11:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010/08/10 11:06:16 | 000,305,744 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010/06/29 00:23:12 | 000,265,984 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2010/06/29 00:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2010/05/27 04:41:24 | 000,349,552 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
PRC - [2010/03/11 07:11:56 | 000,407,920 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
PRC - [2010/03/11 07:11:42 | 000,201,584 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
PRC - [2010/02/09 18:38:56 | 003,465,384 | ---- | M] (Thorvald Natvig) -- C:\Program Files (x86)\Mumble\mumble.exe
PRC - [2010/01/29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2010/01/08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009/12/02 23:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2009/12/02 23:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2006/12/21 08:30:02 | 000,206,400 | ---- | M] (SafeNet, Inc) -- C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
PRC - [2006/08/22 02:00:20 | 000,316,992 | ---- | M] (SafeNet, Inc.) -- C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
PRC - [2005/10/10 21:25:50 | 000,214,016 | ---- | M] (ManageBytes Software, Inc.) -- C:\Program Files (x86)\ManageBytes\WinArranger\WinArranger.exe


========== Modules (SafeList) ==========

MOD - [2011/07/29 15:42:03 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\HITTL ROMAN\Desktop\OTL.exe
MOD - [2010/11/20 13:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
MOD - [2010/02/09 18:38:56 | 000,133,800 | ---- | M] () -- C:\Program Files (x86)\Mumble\mumble_ol.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/06/14 18:50:37 | 001,431,888 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2011/01/12 17:44:02 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV:64bit: - [2011/01/12 17:41:42 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV:64bit: - [2010/06/12 00:27:26 | 000,868,896 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2010/04/21 01:34:40 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/01/29 01:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/02/02 14:08:16 | 000,018,656 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
SRV - [2011/01/15 22:10:06 | 000,107,832 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB)
SRV - [2011/01/15 22:09:57 | 000,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010/11/20 19:25:25 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/11/03 11:21:46 | 000,120,152 | ---- | M] (WeFi) [On_Demand | Running] -- C:\Program Files (x86)\WeFi\WefiEngSvc.exe -- (WefiEngSvc)
SRV - [2010/08/10 11:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010/07/29 23:16:12 | 000,052,896 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2010/06/29 00:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010/06/02 00:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/05/27 04:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/12/02 23:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2009/12/02 23:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2006/12/21 08:30:02 | 000,206,400 | ---- | M] (SafeNet, Inc) [Auto | Running] -- C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe -- (SentinelProtectionServer)
SRV - [2006/08/22 02:00:20 | 000,316,992 | ---- | M] (SafeNet, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe -- (SentinelKeysServer)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | Auto | Stopped] -- C:\Windows\SysNative -- (SentinelFilter)
DRV:64bit: - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/01/13 19:33:41 | 000,513,080 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010/12/22 16:08:50 | 000,154,256 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2010/12/21 16:04:06 | 000,170,640 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2010/12/21 16:04:06 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2010/12/21 14:47:38 | 000,125,296 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:64bit: - [2010/12/02 12:14:26 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:64bit: - [2010/12/02 12:14:24 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2010/12/02 12:14:22 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:64bit: - [2010/12/02 12:14:18 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2010/11/20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 12:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010/07/29 23:16:30 | 000,270,496 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2010/07/29 23:16:28 | 000,295,072 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2010/07/29 23:16:28 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2010/07/29 23:16:28 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2010/07/29 23:16:28 | 000,051,872 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2010/07/29 23:16:28 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2010/07/29 23:16:28 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2010/07/29 23:16:26 | 000,051,872 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AthDfu.sys -- (ATHDFU)
DRV:64bit: - [2010/07/09 05:51:50 | 000,017,408 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2010/06/17 11:18:28 | 000,246,376 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/05/14 23:48:28 | 000,384,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2010/05/11 12:11:38 | 002,229,608 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010/04/21 03:15:04 | 006,406,144 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/04/21 00:39:36 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/04/20 04:35:14 | 000,018,432 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2010/01/27 05:05:00 | 000,231,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2009/12/10 13:25:10 | 000,301,104 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009/12/02 23:23:38 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2009/12/02 23:23:34 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2009/12/02 23:23:32 | 000,269,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2009/12/02 23:23:26 | 000,721,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2009/08/23 11:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/03 04:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009/06/03 04:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009/06/03 04:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2008/12/26 12:56:04 | 000,021,504 | ---- | M] (Avnex) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vcsvad.sys -- (VCSVADHWSer) Avnex Virtual Audio Device (WDM)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.cz/ [binary data]
IE - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://my.daemon-search.com/|http://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: jklir@volny.cz:0.3.8
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.11.2.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.12.5.100006
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... r=1.1.6&q="
FF - prefs.js..network.proxy.autoconfig_url: "http://herkules.knihovna.utb.cz/proxy.pac"
FF - prefs.js..network.proxy.type: 0

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\MOZILLA THUNDERBIRD [2011/02/15 10:43:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/01/18 13:19:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/01/18 13:19:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/07/04 15:54:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/07/04 15:54:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/02/15 10:43:40 | 000,000,000 | ---D | M]

[2011/01/11 00:48:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Extensions
[2011/07/31 19:26:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions
[2011/06/14 16:15:20 | 000,000,000 | ---D | M] (Page Speed) -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2011/05/06 11:50:32 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\DTToolbar@toolbarnet.com
[2011/01/27 22:56:02 | 000,000,000 | ---D | M] (Rank Checker) -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\jklir@volny.cz
[2011/07/29 13:00:03 | 000,000,000 | ---D | M] ("Trillian Toolbar") -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com
[2011/01/29 09:14:53 | 000,002,059 | ---- | M] () -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\searchplugins\daemon-search.xml
[2011/07/28 11:52:53 | 000,001,056 | ---- | M] () -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\searchplugins\icqplugin.xml
[2011/07/31 19:26:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/12 15:50:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/06/17 10:09:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/04 15:53:54 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
[2011/07/04 15:53:54 | 000,001,687 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mall-cz.xml
[2011/07/04 15:53:54 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
[2011/07/04 15:53:54 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011/07/04 15:53:54 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..\Toolbar\WebBrowser: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [NBstat] C:\Users\HITTL ROMAN\Desktop\NBSTAT.EXE ()
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000..\Run: [BitComet] File not found
O4 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000..\Run: [DriverMax] File not found
O4 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000..\Run: [DriverMax_RESTART] File not found
O4 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000..\Run: [WinArranger] C:\Program Files (x86)\ManageBytes\WinArranger\WinArranger.exe (ManageBytes Software, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O4 - Startup: C:\Users\HITTL ROMAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BatteryBar.lnk = File not found
O4 - Startup: C:\Users\HITTL ROMAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\HITTL ROMAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~2\GO36F4~1.DLL) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/06/14 18:21:44 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O33 - MountPoints2\{14962d40-1f3c-11e0-8d0a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{14962d40-1f3c-11e0-8d0a-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Setup.exe
O33 - MountPoints2\{a9b33640-20a2-11e0-a984-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a9b33640-20a2-11e0-a984-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup\i386\msetup.exe
O33 - MountPoints2\{a9b33640-20a2-11e0-a984-806e6f6e6963}\Shell\langenglish\command - "" = E:\setup\i386\msetup.exe lang:english
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 7 Days ==========

[2011/07/30 01:16:16 | 000,000,000 | ---D | C] -- C:\Users\HITTL ROMAN\AppData\Roaming\gtk-2.0
[2011/07/30 01:07:59 | 000,000,000 | ---D | C] -- C:\Users\HITTL ROMAN\AppData\Roaming\Python-Eggs
[2011/07/30 01:07:53 | 000,000,000 | ---D | C] -- C:\Users\HITTL ROMAN\AppData\Roaming\BitLord
[2011/07/30 01:06:59 | 000,000,000 | ---D | C] -- C:\Users\HITTL ROMAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitLord
[2011/07/30 01:05:39 | 000,000,000 | ---D | C] -- C:\Users\HITTL ROMAN\Documents\BitLord
[2011/07/30 01:05:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BitLord 1.2
[2011/07/29 15:41:56 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\HITTL ROMAN\Desktop\OTL.exe
[2011/07/28 23:15:24 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011/07/28 23:15:23 | 000,000,000 | ---D | C] -- C:\rsit
[2011/02/12 10:36:25 | 003,200,960 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\vcredist_x64.exe
[2011/02/12 10:36:24 | 002,723,264 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\vcredist_x86.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\HITTL ROMAN\Desktop\*.tmp files -> C:\Users\HITTL ROMAN\Desktop\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2011/08/01 16:44:00 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/01 12:44:00 | 000,000,958 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/01 11:11:18 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/01 11:11:18 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/01 11:09:03 | 000,000,628 | ---- | M] () -- C:\wowrm.ini
[2011/08/01 11:05:39 | 000,002,084 | ---- | M] () -- C:\Users\HITTL ROMAN\Desktop\Trillian.lnk
[2011/08/01 11:05:37 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\WefiStartup.job
[2011/08/01 11:05:22 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2011/08/01 11:04:59 | 000,000,318 | ---- | M] () -- C:\Windows\tasks\BearShareNAG.job
[2011/08/01 11:04:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/08/01 11:04:51 | 3217,211,392 | -HS- | M] () -- C:\hiberfil.sys
[2011/07/30 01:06:59 | 000,002,051 | ---- | M] () -- C:\Users\HITTL ROMAN\Desktop\BitLord.lnk
[2011/07/29 15:42:03 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\HITTL ROMAN\Desktop\OTL.exe
[2011/07/29 08:50:07 | 000,004,444 | ---- | M] () -- C:\Users\HITTL ROMAN\Desktop\bateriedata.sav
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\HITTL ROMAN\Desktop\*.tmp files -> C:\Users\HITTL ROMAN\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/30 01:06:59 | 000,002,051 | ---- | C] () -- C:\Users\HITTL ROMAN\Desktop\BitLord.lnk
[2011/06/30 11:58:31 | 000,000,099 | ---- | C] () -- C:\Users\HITTL ROMAN\AppData\Local\fusioncache.dat
[2011/06/14 18:52:13 | 000,000,153 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/05/31 10:05:03 | 000,045,286 | ---- | C] () -- C:\Users\HITTL ROMAN\AppData\Roaming\room_v3.dat
[2011/05/20 17:35:42 | 000,000,920 | ---- | C] () -- C:\Users\HITTL ROMAN\AppData\Local\SRDownloader.nast
[2011/05/07 09:05:15 | 000,085,748 | ---- | C] () -- C:\Windows\War3Unin.dat
[2011/04/30 17:46:17 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2011/03/12 17:08:48 | 000,000,113 | ---- | C] () -- C:\Windows\(null)toolkit.ini
[2011/02/12 11:09:04 | 000,000,024 | ---- | C] () -- C:\Windows\SCAux.INI
[2011/02/12 11:06:03 | 000,000,530 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/02/12 11:02:33 | 001,532,928 | ---- | C] () -- C:\Windows\SysWow64\Emulator Utility.exe
[2011/02/12 11:02:33 | 000,256,256 | ---- | C] () -- C:\Windows\SysWow64\SentinelFilter.sys
[2011/02/12 10:51:14 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2011/02/12 10:51:14 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2011/02/12 10:51:03 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\serauth2.dll
[2011/02/12 10:51:03 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\serauth1.dll
[2011/02/12 10:51:03 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\rvkauth2.dll
[2011/02/12 10:51:03 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\rvkauth1.dll
[2011/02/12 10:51:03 | 000,000,095 | ---- | C] () -- C:\Windows\SysWow64\prsrvk.dll
[2011/02/12 10:51:03 | 000,000,073 | ---- | C] () -- C:\Windows\SysWow64\nsprs.dll
[2011/02/12 10:39:47 | 000,000,353 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/02/12 10:36:41 | 000,024,576 | ---- | C] () -- C:\Windows\SCRemove.exe
[2011/02/12 10:30:07 | 000,009,552 | ---- | C] () -- C:\Windows\SysWow64\INETWH16.DLL
[2011/02/12 10:27:47 | 000,080,384 | ---- | C] () -- C:\Windows\SysWow64\UTILS.DLL
[2011/02/12 10:27:47 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\_FSTDIO.DLL
[2011/02/12 10:27:47 | 000,015,360 | ---- | C] () -- C:\Windows\SysWow64\WIN_CHNG.DLL
[2011/02/12 10:27:42 | 000,120,832 | ---- | C] () -- C:\Windows\SysWow64\CLASSES.DLL
[2011/02/12 10:27:42 | 000,021,504 | ---- | C] () -- C:\Windows\SysWow64\LISTBOX.DLL
[2011/02/05 10:52:47 | 000,017,412 | ---- | C] () -- C:\Users\HITTL ROMAN\AppData\Roaming\UserTile.png
[2011/01/28 16:14:09 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Nadeo.ini
[2011/01/15 22:09:58 | 000,107,832 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/01/15 22:09:57 | 002,250,024 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2011/01/15 22:09:57 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/01/14 21:59:00 | 000,103,936 | ---- | C] () -- C:\Windows\Lavish.dll
[2011/01/13 16:06:37 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011/01/12 19:57:08 | 000,007,599 | ---- | C] () -- C:\Users\HITTL ROMAN\AppData\Local\Resmon.ResmonCfg
[2011/01/11 23:12:43 | 001,597,030 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/11 00:48:36 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/11/20 19:14:43 | 000,206,208 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2010/11/20 19:14:43 | 000,113,264 | ---- | C] () -- C:\Windows\FixUVC.exe
[2010/11/20 19:14:43 | 000,000,302 | ---- | C] () -- C:\Windows\PidList_C.ini
[2010/11/20 19:08:25 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/08/30 05:35:11 | 000,002,093 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/08/30 05:01:45 | 000,131,984 | ---- | C] () -- C:\ProgramData\FullRemove.exe
[2009/07/14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2003/12/09 01:08:20 | 002,539,520 | ---- | C] () -- C:\Windows\SysWow64\Bbgspdf.dll
[2003/12/02 14:39:08 | 000,094,208 | ---- | C] () -- C:\Windows\SysWow64\InstallPrinter.dll
[2003/01/30 07:04:00 | 000,618,496 | ---- | C] () -- C:\Windows\SysWow64\stlpmt45.dll

========== LOP Check ==========

[2011/03/20 01:04:44 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Aegisub
[2011/03/31 13:21:27 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Ascaron Entertainment
[2011/03/22 15:24:39 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Audacity
[2011/06/17 16:38:47 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Autodesk
[2011/02/01 22:03:04 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Avnex
[2011/01/19 13:39:19 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\BatteryBar
[2011/07/30 01:30:59 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\BitLord
[2011/02/02 00:28:26 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\com.livejasmin.jasmin
[2011/07/28 21:08:56 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\DAEMON Tools Lite
[2011/03/16 15:23:26 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\DWGEditor
[2011/01/12 23:03:34 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\GHISLER
[2011/07/30 01:20:43 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\gtk-2.0
[2011/07/05 17:37:41 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\ICQ
[2011/07/19 08:54:00 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Microgaming
[2011/07/02 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Mount&Blade Warband
[2011/08/01 17:22:20 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Mumble
[2011/01/15 00:34:56 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Notebook Hardware Control
[2011/06/27 15:43:13 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\OpenCandy
[2011/01/29 12:18:37 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\OpenOffice.org
[2011/01/29 00:04:52 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Publish Providers
[2011/07/30 01:07:59 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Python-Eggs
[2011/07/11 13:25:59 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Rovio
[2011/07/28 22:42:00 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\SoftGrid Client
[2011/01/29 00:04:50 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Sony
[2011/01/11 23:14:12 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\TP
[2011/03/12 17:04:31 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Trillian
[2011/07/28 21:08:45 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\TS3Client
[2011/02/01 22:00:33 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Virtual Mechanics
[2011/04/23 13:19:15 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\wargaming.net
[2011/04/08 14:52:35 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Windows Live Writer
[2011/01/12 01:02:34 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Wireshark
[2011/07/01 13:37:30 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\wordtester
[2011/08/01 11:04:59 | 000,000,318 | ---- | M] () -- C:\Windows\Tasks\BearShareNAG.job
[2011/04/28 14:02:43 | 000,032,584 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/08/01 11:05:37 | 000,000,332 | ---- | M] () -- C:\Windows\Tasks\WefiStartup.job

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"WinArranger" = "C:\Program Files (x86)\ManageBytes\WinArranger\WinArranger.exe" -- [2005/10/10 21:25:50 | 000,214,016 | ---- | M] (ManageBytes Software, Inc.)
"DAEMON Tools Lite" = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun -- [2011/01/20 11:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd)
"DriverMax" =
"DriverMax_RESTART" =
"BitComet" = "H:\Anime\BitLord\BitLord.exe"
"Pando Media Booster" = C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe -- [2011/07/03 17:30:30 | 003,077,528 | ---- | M] ()

< c:\windows\*.* /U >
[1 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2009/02/09 09:05:42 | 000,520,704 | ---- | M] (Apocalypse Softworks) -- C:\wowrm2.exe

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2011/03/30 15:51:08 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Adobe
[2011/03/20 01:04:44 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Aegisub
[2011/03/31 13:21:27 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Ascaron Entertainment
[2011/01/11 00:17:59 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\ATI
[2011/03/22 15:24:39 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Audacity
[2011/06/17 16:38:47 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Autodesk
[2011/02/01 22:03:04 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Avnex
[2011/01/19 13:39:19 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\BatteryBar
[2011/07/30 01:30:59 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\BitLord
[2011/02/02 00:28:26 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\com.livejasmin.jasmin
[2011/07/28 21:08:56 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\DAEMON Tools Lite
[2011/03/16 15:23:26 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\DWGEditor
[2011/01/12 23:03:34 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\GHISLER
[2011/07/30 01:20:43 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\gtk-2.0
[2011/07/05 17:37:41 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\ICQ
[2011/01/11 00:16:06 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Identities
[2011/01/11 21:25:15 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\InstallShield
[2011/01/11 00:16:43 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Macromedia
[2009/07/14 09:44:38 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Media Center Programs
[2011/07/19 08:54:00 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Microgaming
[2011/07/01 13:41:16 | 000,000,000 | --SD | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Microsoft
[2011/07/02 01:00:21 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Mount&Blade Warband
[2011/04/16 17:35:48 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla
[2011/08/01 17:22:20 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Mumble
[2011/01/15 00:34:56 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Notebook Hardware Control
[2011/06/27 15:43:13 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\OpenCandy
[2011/01/29 12:18:37 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\OpenOffice.org
[2011/01/29 00:04:52 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Publish Providers
[2011/07/30 01:07:59 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Python-Eggs
[2011/07/11 13:25:59 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Rovio
[2011/01/15 23:26:00 | 000,000,000 | RH-D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\SecuROM
[2011/07/31 20:47:48 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Skype
[2011/07/28 22:42:00 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\SoftGrid Client
[2011/05/06 16:01:56 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\SolidWorks
[2011/01/29 00:04:50 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Sony
[2011/01/11 23:14:12 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\TP
[2011/03/12 17:04:31 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Trillian
[2011/07/28 21:08:45 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\TS3Client
[2011/01/11 01:26:13 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Ventrilo
[2011/02/01 22:00:33 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Virtual Mechanics
[2011/07/12 18:50:18 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\vlc
[2011/04/23 13:19:15 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\wargaming.net
[2011/04/08 14:52:35 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Windows Live Writer
[2011/01/11 22:58:28 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\WinRAR
[2011/01/12 01:02:34 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\Wireshark
[2011/07/01 13:37:30 | 000,000,000 | ---D | M] -- C:\Users\HITTL ROMAN\AppData\Roaming\wordtester

< %APPDATA%\*.exe /s >
[2011/03/30 15:23:00 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\HITTL ROMAN\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2011/02/12 10:50:54 | 000,025,214 | R--- | M] () -- C:\Users\HITTL ROMAN\AppData\Roaming\Microsoft\Installer\{4C1A3B65-E284-4F04-822F-3774E0CEEF67}\ARPPRODUCTICON.exe
[2011/07/28 00:13:13 | 003,500,712 | ---- | M] (Ask) -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe
[2011/06/27 15:43:14 | 000,416,160 | ---- | M] () -- C:\Users\HITTL ROMAN\AppData\Roaming\OpenCandy\OpenCandy_5690DA49A7A64041BFF768D07D4AC3DA\LatestDLMgr.exe
[2010/12/18 00:07:06 | 000,043,440 | ---- | M] () -- C:\Users\HITTL ROMAN\AppData\Roaming\OpenCandy\OpenCandy_5690DA49A7A64041BFF768D07D4AC3DA\SpeedstarterCZ.exe
[2010/12/17 19:48:22 | 001,720,472 | ---- | M] (Speedchecker Limited ) -- C:\Users\HITTL ROMAN\AppData\Roaming\OpenCandy\OpenCandy_5690DA49A7A64041BFF768D07D4AC3DA\ZrychleniPocitace.exe
[2011/06/27 15:43:22 | 001,842,096 | ---- | M] () -- C:\Users\HITTL ROMAN\AppData\Roaming\OpenCandy\OpenCandy_5690DA49A7A64041BFF768D07D4AC3DA\ZrychleniPocitace_p2v1.exe


< MD5 for: AGP440.SYS >
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2010/11/20 15:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010/11/20 15:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2009/07/14 03:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009/07/14 03:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
[2010/11/20 14:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010/11/20 14:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe

< MD5 for: CDROM.SYS >
[2009/07/14 01:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
[2010/11/20 11:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010/11/20 11:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010/11/20 11:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys

Re: Preventivní log (prosim o kontrolu)

Napsal: 01 srp 2011 16:58
od nom
< MD5 for: CNGAUDIT.DLL >
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: CRYPTSVC.DLL >
[2010/11/20 15:25:59 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=15597883FBE9B056F276ADA3AD87D9AF -- C:\Windows\SysNative\cryptsvc.dll
[2010/11/20 15:25:59 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=15597883FBE9B056F276ADA3AD87D9AF -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_d4259ed3b16ed82a\cryptsvc.dll
[2009/07/14 03:40:24 | 000,175,104 | ---- | M] (Microsoft Corporation) MD5=8C57411B66282C01533CB776F98AD384 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_d1f48b0bb4805490\cryptsvc.dll
[2009/07/14 03:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_75d5ef87fc22e35a\cryptsvc.dll
[2010/11/20 14:18:24 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\SysWOW64\cryptsvc.dll
[2010/11/20 14:18:24 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll

< MD5 for: EXPLORER.EXE >
[2011/02/26 08:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 07:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/07/17 21:26:04 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/02/04 12:49:48 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/07/17 21:26:04 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/02/04 12:49:48 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 15:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/07/17 21:26:04 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/02/04 12:49:48 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 03:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/07/17 21:26:04 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 08:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/02/04 12:49:48 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: HAL.DLL >
[2009/07/14 03:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
[2010/11/20 15:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010/11/20 15:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll

< MD5 for: IASTORV.SYS >
[2010/11/20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011/03/11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011/03/11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009/07/14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: ISAPNP.SYS >
[2009/07/14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\drivers\isapnp.sys
[2009/07/14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\isapnp.sys
[2009/07/14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\isapnp.sys
[2009/07/14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\isapnp.sys

< MD5 for: LSASS.EXE >
[2009/07/14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\SysNative\lsass.exe
[2009/07/14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_023f7c69767c3edd\lsass.exe
[2009/07/14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16484_none_023e7e05767d22ad\lsass.exe
[2009/07/14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.20594_none_02bd4ae48fa2de68\lsass.exe
[2009/07/14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe

< MD5 for: NDIS.SYS >
[2010/11/20 15:33:45 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\SysNative\drivers\ndis.sys
[2010/11/20 15:33:45 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys
[2009/07/14 03:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys

< MD5 for: NETLOGON.DLL >
[2009/07/14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010/11/20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010/11/20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010/11/20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009/07/14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVRAID.SYS >
[2011/03/11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\drivers\nvraid.sys
[2011/03/11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvraid.sys
[2011/03/11 08:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvraid.sys
[2009/07/14 03:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys
[2010/11/20 15:33:48 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvraid.sys
[2010/11/20 15:33:48 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvraid.sys
[2011/03/11 08:19:21 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=666CA16F17914C1CD3616CF16DE0A6EA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvraid.sys
[2011/03/11 08:23:06 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=A4D9C9A608A97F59307C2F2600EDC6A4 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvraid.sys
[2011/03/11 08:25:53 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=A5C82EB2F72AA004887F90B84A771F73 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2009/07/14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011/03/11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011/03/11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011/03/11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010/11/20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010/11/20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010/11/20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll

< MD5 for: SMSS.EXE >
[2009/07/14 03:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\SysNative\smss.exe
[2009/07/14 03:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe

< MD5 for: SVCHOST.EXE >
[2009/07/14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: TCPIP.SYS >
[2011/04/25 07:28:24 | 001,893,248 | ---- | M] (Microsoft Corporation) MD5=1F748D5439B65E0BEBD92F65048F030D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_0fb918de99201ffb\tcpip.sys
[2010/11/20 15:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2010/06/14 08:39:16 | 001,889,152 | ---- | M] (Microsoft Corporation) MD5=542C6767C68C9D6AAACA59436B0D15C2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_0fd0b57e990e2079\tcpip.sys
[2011/04/25 07:32:22 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=61DC720BB065D607D5823F13D2A64321 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_0f668bf97fd90dd3\tcpip.sys
[2010/06/14 08:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_0f59b7ad7fe2fcc8\tcpip.sys
[2009/07/14 03:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2011/04/25 07:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\SysNative\drivers\tcpip.sys
[2011/04/25 07:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2011/04/25 08:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010/11/20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010/07/17 21:26:04 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010/07/17 21:26:04 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WS2_32.DLL >
[2010/11/20 15:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\SysNative\ws2_32.dll
[2010/11/20 15:27:29 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll
[2009/07/14 03:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_4eaca269e8070c6b\ws2_32.dll
[2010/11/20 14:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\SysWOW64\ws2_32.dll
[2010/11/20 14:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll
[2009/07/14 03:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >

========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:CDFF58FE
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:4D066AD2
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:E1F04E8D

< End of report >

Re: Preventivní log (prosim o kontrolu)

Napsal: 01 srp 2011 17:53
od vyosek
:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    IE - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..\URLSearchHook: - Reg Error: Key error. File not found
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.12.5.100006
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.6&q="
    [2011/05/06 11:50:32 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\DTToolbar@toolbarnet.com
    [2011/07/29 13:00:03 | 000,000,000 | ---D | M] ("Trillian Toolbar") -- C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com
    O2 - BHO: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
    O3 - HKLM\..\Toolbar: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3:64bit: - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
    O3 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
    O3 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..\Toolbar\WebBrowser: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O13 - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..Trusted Domains: localhost ([]http in Local intranet)
    O15 - HKU\S-1-5-21-1498072532-3510031312-3464764778-1000\..Trusted Ranges: GD ([http] in Local intranet)
    O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O33 - MountPoints2\{14962d40-1f3c-11e0-8d0a-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{a9b33640-20a2-11e0-a984-806e6f6e6963}\Shell - "" = AutoRun
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [1 C:\Users\HITTL ROMAN\Desktop\*.tmp files -> C:\Users\HITTL ROMAN\Desktop\*.tmp -> ]
    @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:CDFF58FE
    @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:4D066AD2
    @Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:E1F04E8D
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    "DriverMax"=-
    "DriverMax_RESTART"=-
    "BitComet"=-
    "Pando Media Booster"=-
    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "NBstat"=-
    "Adobe ARM"=-
    "SunJavaUpdateSched"=-
    ""=-
    
    :service
    gupdate
    gupdatem
     
    :files
    C:\Program Files (x86)\Ask.com
    C:\Program Files (x86)\DAEMON Tools Toolbar
    C:\Windows\tasks\BearShareNAG.job
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\WefiStartup.job
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Preventivní log (prosim o kontrolu)

Napsal: 03 srp 2011 00:10
od nom
All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-1498072532-3510031312-3464764778-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: toolbar@ask.com:3.12.5.100006 removed from extensions.enabledItems
Prefs.js: "http://search.icq.com/search/afe_result ... r=1.1.6&q=" removed from keyword.URL
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\DTToolbar@toolbarnet.com\components\Resources folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\DTToolbar@toolbarnet.com\components folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\DTToolbar@toolbarnet.com\chrome\content folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\DTToolbar@toolbarnet.com\chrome folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\DTToolbar@toolbarnet.com folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\searchplugins folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\logs folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\defaults\preferences folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\defaults folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\datastore folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Thu-28-Jul-2011-09-42-47-GMT folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Sat-02-Jul-2011-07-32-59-GMT folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\chrome\temp folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\chrome\skin folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\chrome\content folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com\chrome folder moved successfully.
C:\Users\HITTL ROMAN\AppData\Roaming\Mozilla\Firefox\Profiles\e1a9hhyo.default\extensions\toolbar@ask.com folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
64bit-Registry value HKEY_USERS\S-1-5-21-1498072532-3510031312-3464764778-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
File C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll not found.
Registry value HKEY_USERS\S-1-5-21-1498072532-3510031312-3464764778-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
File C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll not found.
Registry value HKEY_USERS\S-1-5-21-1498072532-3510031312-3464764778-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully.
C:\Program Files (x86)\Ask.com\Updater\Updater.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1498072532-3510031312-3464764778-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1498072532-3510031312-3464764778-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\GD\\http deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C514A3-1EFB-4856-9F99-10D7BE1653C0}\ not found.
File {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324}\ not found.
File {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{14962d40-1f3c-11e0-8d0a-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14962d40-1f3c-11e0-8d0a-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a9b33640-20a2-11e0-a984-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a9b33640-20a2-11e0-a984-806e6f6e6963}\ not found.
C:\Windows\msdownld.tmp folder deleted successfully.
C:\Users\HITTL ROMAN\Desktop\~WRL3115.tmp deleted successfully.
ADS C:\ProgramData\Temp:CDFF58FE deleted successfully.
ADS C:\ProgramData\Temp:4D066AD2 deleted successfully.
ADS C:\ProgramData\Temp:E1F04E8D deleted successfully.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DriverMax deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DriverMax_RESTART deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BitComet deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Pando Media Booster deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\NBstat deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\ not found.
Error: Unable to interpret <:service> in the current context!
Error: Unable to interpret <gupdate> in the current context!
Error: Unable to interpret <gupdatem> in the current context!
========== FILES ==========
C:\Program Files (x86)\Ask.com\Updater folder moved successfully.
C:\Program Files (x86)\Ask.com\assets\oobe folder moved successfully.
C:\Program Files (x86)\Ask.com\assets folder moved successfully.
C:\Program Files (x86)\Ask.com folder moved successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\Resources folder moved successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar folder moved successfully.
C:\Windows\tasks\BearShareNAG.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\tasks\WefiStartup.job moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 338160001 bytes
->Temporary Internet Files folder emptied: 33234 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 56729378 bytes
->Google Chrome cache emptied: 36857232 bytes
->Flash cache emptied: 72251 bytes

User: HITTL ROMAN
->Temp folder emptied: 17311947 bytes
->Temporary Internet Files folder emptied: 3926248 bytes
->Java cache emptied: 12600878 bytes
->FireFox cache emptied: 76760037 bytes
->Google Chrome cache emptied: 135721245 bytes
->Flash cache emptied: 59569 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 40936861 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 120458 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 686.00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Guest
->Flash cache emptied: 0 bytes

User: HITTL ROMAN
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.26.1 log created on 08032011_010504

Files\Folders moved on Reboot...
C:\Users\HITTL ROMAN\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot.
File move failed. C:\Windows\temp\gnserv.dat scheduled to be moved on reboot.
File move failed. C:\Windows\temp\spserv.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Preventivní log (prosim o kontrolu)

Napsal: 03 srp 2011 06:51
od vyosek
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Napiste jak se chova PC

Re: Preventivní log (prosim o kontrolu)

Napsal: 06 srp 2011 07:53
od nom
Děkuji za rady defragmentace sem použival windousácký byli nic moc tahle urychlila nabíhání programu a jde to znat

Re: Preventivní log (prosim o kontrolu)

Napsal: 06 srp 2011 08:40
od vyosek
Mate pravdu ze ta windows defragmentace stoji opravdz za p*d...

Pokud tedy nejsou problemy ci dotazy, je to z me strany vse :turned: