Stránka 1 z 1

Prosím o kontrolu scanu

Napsal: 14 zář 2011 20:18
od sadoman
Zdravím, scanoval jsem počítač pomocí programu Spyware Terminator 2012. Vymazal jsem dva registry relevant knoweledge. Myslíte že by to mohlo mít dopad na chod počítače. Předem děkuji za odpověď.
Tady je zpráva o scanu :
Clean
Clean started at: 14.9.2011 20:41:21.

Creating System Restore Point: 14.9.2011 20:41:21.

Marketscore (Spyware):
File is set to be Removed after Restart: C:\Program Files (x86)\RelevantKnowledge\rlservice.exe

File is set to be Removed after Restart: C:\Program Files (x86)\RelevantKnowledge\rlls.dll

File is set to be Removed after Restart: C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe

File is set to be Removed after Restart: C:\Program Files (x86)\RelevantKnowledge\rlvknlg64.exe

Removed Item: HKLM\SYSTEM\CurrentControlSet\Services\RelevantKnowledge

Removed Item: HKLM\SYSTEM\CurrentControlSet\Services\RelevantKnowledge

Removed File: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Uninstall Instructions.lnk

Removed File: C:\Program Files (x86)\RelevantKnowledge\ncncf.dat

Removed File: C:\Program Files (x86)\RelevantKnowledge\nscf.dat

File is set to be Removed after Restart: C:\Program Files (x86)\RelevantKnowledge\rlls64.dll

Removed File: C:\Program Files (x86)\RelevantKnowledge\rloci.bin

Directory is set to be Removed after Restart: C:\Program Files (x86)\RelevantKnowledge\

Closing System Restore Point: 14.9.2011 20:41:43.

End of Report

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 20:28
od vyosek
Zdravim a pekny vecer preji :)

:arrow: RelevanKnowledge je smejd :boxed:

:arrow: Dejte prosim log z RSIT - viz muj podpis

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 20:32
od sadoman
vyosek píše:Zdravim a pekny vecer preji :)

:arrow: RelevanKnowledge je smejd :boxed:

:arrow: Dejte prosim log z RSIT - viz muj podpis
Tak předně děkuji. Neměl by to tedy být problém. Jinak ten RSIT uz se stahuje a instaluje.

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 20:33
od vyosek
Urcite ne, celou tu havet z PC vyzenem :wink:

Pockam na log z RSIT a uvidime co dale

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 20:41
od sadoman
Logfile of random's system information tool 1.09 (written by random/random)
Run by Pavel at 2011-09-14 21:34:30
Microsoft Windows 7 Home Premium
System drive C: has 176 GB (74%) free of 238 GB
Total RAM: 3955 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:35:34, on 14.9.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16839)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files\trend micro\Pavel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60342
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://toshiba.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110912175555.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [NBAgent] "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: @c:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15254 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\WLANExt.exe 22751184
\??\C:\Windows\system32\conhost.exe "-1647934130157543965-193110528318702875411878051968574328001425357030-1377173079
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc
"C:\Windows\system32\mfevtps.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\rundll32.exe" "c:\PROGRA~2\mcafee\SITEAD~1\saHook.dll" saHooker_Initialize_and_Wait
"C:\Windows\system32\rundll32.exe" "c:\PROGRA~2\mcafee\SITEAD~1\saHook.dll" saHooker_Initialize_and_Wait
"C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe"
"C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe"
"C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE3
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe"
C:\Windows\system32\TODDSrv.exe
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\mcafee.com\agent\mcagent.exe" /runkey
"C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" /START
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
"C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe"
WLIDSvcM.exe 3256
"C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
taskeng.exe {D0A9C85E-31A0-4991-B8D0-A3BA48363D92}
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" /ELEVATED
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Users\Pavel\Desktop\RSITX64.EXE"
C:\Windows\System32\svchost.exe -k WerSvcGroup

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2259664420-230457019-666686769-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2259664420-230457019-666686769-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
McAfee Phishing Filter - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110912175602.dll [2011-03-13 92888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll [2011-08-11 317336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
McAfee Phishing Filter - c:\progra~1\mcafee\msk\mskapbho.dll [2010-05-03 245272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110912175555.dll [2011-03-13 78456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [2011-08-11 258120]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-11-22 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2010-03-19 529784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll [2011-08-11 317336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [2011-08-11 258120]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TosNC"=C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2010-04-23 595816]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2010-07-09 38304]
"Toshiba TEMPRO"=C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2010-05-11 1050072]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-07-28 11101800]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2010-07-28 2120808]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2010-09-28 566184]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2009-08-13 570680]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-05-10 915320]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"SmartFaceVWatcher"=C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-10-19 238080]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [2010-04-19 136136]
"SpywareTerminatorShield"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2011-09-14 2775728]
"SpywareTerminatorUpdater"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-09-14 3608240]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [2010-03-03 4581280]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]
"Google Update"=C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-13 136176]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2011-07-13 1666144]
"NBAgent"=c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-09-02 1234216]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2009-11-11 288088]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-10-05 98304]
"SVPWUTIL"=C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [2010-03-03 352256]
"HWSetup"=C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [2010-03-04 423936]
"KeNotify"=C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [2010-08-15 34160]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START []
"TWebCamera"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-05-01 2454840]
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2009-10-06 1294136]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-07-05 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-08-19 421736]

C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Startup
TRDCReminder.lnk - C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefire]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfevtp]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-09-14 21:34:31 ----D---- C:\Program Files\trend micro
2011-09-14 21:34:30 ----D---- C:\rsit
2011-09-14 20:33:20 ----A---- C:\Windows\system32\drivers\stflt.sys
2011-09-14 20:33:19 ----D---- C:\Users\Pavel\AppData\Roaming\Spyware Terminator
2011-09-14 20:33:19 ----D---- C:\ProgramData\Spyware Terminator
2011-09-14 20:31:27 ----D---- C:\Program Files (x86)\Spyware Terminator
2011-09-14 20:13:38 ----D---- C:\Users\Pavel\AppData\Roaming\GHISLER
2011-09-14 20:13:38 ----D---- C:\Program Files (x86)\totalcmd
2011-09-14 20:13:38 ----A---- C:\Windows\UC.PIF
2011-09-14 20:13:38 ----A---- C:\Windows\RAR.PIF
2011-09-14 20:13:38 ----A---- C:\Windows\PKZIP.PIF
2011-09-14 20:13:38 ----A---- C:\Windows\PKUNZIP.PIF
2011-09-14 20:13:38 ----A---- C:\Windows\NOCLOSE.PIF
2011-09-14 20:13:38 ----A---- C:\Windows\LHA.PIF
2011-09-14 20:13:38 ----A---- C:\Windows\ARJ.PIF
2011-09-14 18:30:37 ----D---- C:\ProgramData\VirtualizedApplications
2011-09-14 16:40:35 ----D---- C:\Program Files (x86)\DownloadToolz
2011-09-14 06:36:29 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2011-09-14 06:36:29 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2011-09-14 06:36:29 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2011-09-14 06:36:29 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2011-09-14 06:36:29 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2011-09-14 06:36:29 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-09-14 06:36:29 ----A---- C:\Windows\system32\PresentationHost.exe
2011-09-14 06:36:29 ----A---- C:\Windows\system32\netfxperf.dll
2011-09-14 06:36:29 ----A---- C:\Windows\system32\mscoree.dll
2011-09-14 06:36:29 ----A---- C:\Windows\system32\dfshim.dll
2011-09-14 06:36:12 ----SHD---- C:\Config.Msi
2011-09-13 22:41:00 ----D---- C:\Windows\SYSWOW64\Wat
2011-09-13 22:41:00 ----D---- C:\Windows\system32\Wat
2011-09-13 22:29:43 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-09-13 22:29:43 ----A---- C:\Windows\system32\wcncsvc.dll
2011-09-13 22:23:39 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-09-13 22:22:22 ----A---- C:\Windows\system32\browserchoice.exe
2011-09-13 22:17:45 ----A---- C:\Windows\system32\MRT.exe
2011-09-13 22:13:02 ----D---- C:\Users\Pavel\AppData\Roaming\SoftGrid Client
2011-09-13 22:12:52 ----A---- C:\Windows\system32\d2d1.dll
2011-09-13 22:12:51 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-09-13 22:12:51 ----A---- C:\Windows\system32\DWrite.dll
2011-09-13 22:12:50 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-09-13 22:12:50 ----A---- C:\Windows\system32\FntCache.dll
2011-09-13 22:12:45 ----A---- C:\Windows\system32\msdri.dll
2011-09-13 22:12:38 ----A---- C:\Windows\system32\jscript.dll
2011-09-13 22:12:37 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-09-13 22:12:37 ----A---- C:\Windows\system32\vbscript.dll
2011-09-13 22:12:36 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-09-13 22:12:31 ----A---- C:\Windows\system32\EncDec.dll
2011-09-13 22:12:31 ----A---- C:\Windows\system32\CPFilters.dll
2011-09-13 22:12:30 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-09-13 22:12:28 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-09-13 22:12:28 ----A---- C:\Windows\system32\sbe.dll
2011-09-13 22:12:27 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-09-13 22:12:25 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-09-13 22:12:06 ----D---- C:\Program Files\Microsoft Office
2011-09-13 22:12:06 ----D---- C:\Program Files (x86)\Microsoft Application Virtualization Client
2011-09-13 22:11:49 ----D---- C:\Users\Pavel\AppData\Roaming\TP
2011-09-13 22:11:30 ----A---- C:\Windows\system32\upnp.dll
2011-09-13 22:11:30 ----A---- C:\Windows\system32\msxml6.dll
2011-09-13 22:11:30 ----A---- C:\Windows\system32\msxml3.dll
2011-09-13 22:11:29 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-09-13 22:11:28 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-09-13 22:11:28 ----A---- C:\Windows\system32\winhttp.dll
2011-09-13 22:11:28 ----A---- C:\Windows\system32\WebClnt.dll
2011-09-13 22:11:27 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-09-13 22:11:27 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-09-13 22:11:27 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-09-13 22:11:27 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-09-13 22:11:27 ----A---- C:\Windows\system32\wscapi.dll
2011-09-13 22:11:27 ----A---- C:\Windows\system32\davclnt.dll
2011-09-13 22:11:26 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-09-13 22:11:26 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-09-13 22:11:26 ----A---- C:\Windows\system32\wscsvc.dll
2011-09-13 22:11:26 ----A---- C:\Windows\system32\slwga.dll
2011-09-13 22:11:21 ----A---- C:\Windows\system32\taskschd.dll
2011-09-13 22:11:21 ----A---- C:\Windows\system32\schedsvc.dll
2011-09-13 22:11:20 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-09-13 22:11:20 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-09-13 22:11:20 ----A---- C:\Windows\system32\taskeng.exe
2011-09-13 22:11:20 ----A---- C:\Windows\system32\taskcomp.dll
2011-09-13 22:11:20 ----A---- C:\Windows\system32\schtasks.exe
2011-09-13 22:11:19 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-09-13 22:11:19 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-09-13 22:11:19 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-09-13 22:11:16 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-09-13 22:11:16 ----A---- C:\Windows\system32\XpsPrint.dll
2011-09-13 22:11:14 ----A---- C:\Windows\system32\mfc42u.dll
2011-09-13 22:11:14 ----A---- C:\Windows\system32\mfc42.dll
2011-09-13 22:11:13 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-09-13 22:11:12 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-09-13 22:11:05 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-09-13 22:11:05 ----A---- C:\Windows\system32\poqexec.exe
2011-09-13 22:10:50 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-09-13 22:10:50 ----A---- C:\Windows\system32\tzres.dll
2011-09-13 22:10:21 ----A---- C:\Windows\system32\drivers\afd.sys
2011-09-13 22:09:48 ----A---- C:\Windows\system32\mshtml.dll
2011-09-13 22:09:47 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-09-13 22:09:45 ----A---- C:\Windows\system32\ieframe.dll
2011-09-13 22:09:44 ----A---- C:\Windows\system32\iertutil.dll
2011-09-13 22:09:43 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-09-13 22:09:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-09-13 22:09:42 ----A---- C:\Windows\system32\urlmon.dll
2011-09-13 22:09:41 ----A---- C:\Windows\system32\mstime.dll
2011-09-13 22:09:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-09-13 22:09:40 ----A---- C:\Windows\system32\msfeeds.dll
2011-09-13 22:09:39 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-09-13 22:09:39 ----A---- C:\Windows\system32\wininet.dll
2011-09-13 22:09:38 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-09-13 22:09:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-09-13 22:09:37 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-09-13 22:09:37 ----A---- C:\Windows\system32\licmgr10.dll
2011-09-13 22:09:37 ----A---- C:\Windows\system32\iepeers.dll
2011-09-13 22:09:37 ----A---- C:\Windows\system32\iedkcs32.dll
2011-09-13 22:09:36 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-09-13 22:09:35 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-09-13 22:09:35 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-09-13 22:09:35 ----A---- C:\Windows\system32\mshtmled.dll
2011-09-13 22:09:35 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-09-13 22:09:34 ----A---- C:\Windows\system32\url.dll
2011-09-13 22:09:33 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-09-13 22:09:33 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-09-13 22:09:33 ----A---- C:\Windows\system32\ieui.dll
2011-09-13 22:09:32 ----A---- C:\Windows\SYSWOW64\url.dll
2011-09-13 22:09:30 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-09-13 22:09:30 ----A---- C:\Windows\system32\jsproxy.dll
2011-09-13 22:09:29 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-09-13 22:09:29 ----A---- C:\Windows\system32\msfeedssync.exe
2011-09-13 22:09:14 ----A---- C:\Windows\system32\odbccu32.dll
2011-09-13 22:09:14 ----A---- C:\Windows\system32\odbccr32.dll
2011-09-13 22:09:14 ----A---- C:\Windows\system32\odbccp32.dll
2011-09-13 22:09:13 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-09-13 22:09:13 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-09-13 22:09:13 ----A---- C:\Windows\system32\odbctrac.dll
2011-09-13 22:09:12 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-09-13 22:09:11 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-09-13 22:09:10 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-09-13 22:09:07 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-09-13 22:09:07 ----A---- C:\Windows\system32\kerberos.dll
2011-09-13 22:09:05 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-09-13 22:09:04 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-09-13 22:09:04 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-09-13 22:09:02 ----A---- C:\Windows\system32\atmfd.dll
2011-09-13 22:09:01 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-09-13 22:09:01 ----A---- C:\Windows\system32\atmlib.dll
2011-09-13 22:09:00 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-09-13 22:08:57 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-09-13 22:08:55 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-09-13 22:08:55 ----A---- C:\Windows\system32\xmllite.dll
2011-09-13 22:08:47 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-09-13 22:08:47 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-09-13 22:08:46 ----A---- C:\Windows\system32\d3d10_1.dll
2011-09-13 22:08:45 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-09-13 22:08:29 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-09-13 22:08:28 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-09-13 22:08:27 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-09-13 22:08:27 ----A---- C:\Windows\system32\drivers\srv.sys
2011-09-13 22:08:26 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-09-13 22:08:23 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-09-13 22:08:23 ----A---- C:\Windows\system32\webio.dll
2011-09-13 22:08:12 ----A---- C:\Windows\system32\drivers\fvevol.sys
2011-09-13 22:08:09 ----A---- C:\Windows\system32\d3d10warp.dll
2011-09-13 22:08:08 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-09-13 22:08:05 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-09-13 22:08:05 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-09-13 22:08:04 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-09-13 22:08:04 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-09-13 22:08:03 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-09-13 22:08:03 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-09-13 22:08:03 ----A---- C:\Windows\system32\cdd.dll
2011-09-13 22:07:57 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-09-13 22:07:57 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-09-13 22:07:57 ----A---- C:\Windows\system32\dnsapi.dll
2011-09-13 22:07:56 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-09-13 22:07:55 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-09-13 22:07:47 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-09-13 20:49:42 ----RHD---- C:\Users\Pavel\AppData\Roaming\SecuROM
2011-09-13 20:48:03 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-09-13 20:43:57 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-09-13 20:43:57 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-09-13 20:43:56 ----A---- C:\Windows\SYSWOW64\pbsvc.exe
2011-09-13 20:36:52 ----D---- C:\Program Files (x86)\Ubisoft
2011-09-13 16:24:03 ----A---- C:\Windows\explorer.exe
2011-09-13 16:24:02 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-09-13 16:23:58 ----A---- C:\Windows\system32\mssrch.dll
2011-09-13 16:23:56 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-09-13 16:23:56 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-09-13 16:23:56 ----A---- C:\Windows\system32\tquery.dll
2011-09-13 16:23:54 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-09-13 16:23:54 ----A---- C:\Windows\system32\mssph.dll
2011-09-13 16:23:53 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-09-13 16:23:52 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-09-13 16:23:52 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-09-13 16:23:52 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-09-13 16:23:51 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-09-13 16:23:51 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-09-13 16:23:51 ----A---- C:\Windows\system32\mssvp.dll
2011-09-13 16:23:51 ----A---- C:\Windows\system32\msscntrs.dll
2011-09-13 16:23:50 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-09-13 16:23:50 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-09-13 16:23:50 ----A---- C:\Windows\system32\mssphtb.dll
2011-09-13 16:23:49 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-09-13 16:18:10 ----A---- C:\Windows\system32\ntdll.dll
2011-09-13 16:18:09 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-09-13 16:17:57 ----A---- C:\Windows\system32\winresume.exe
2011-09-13 16:17:57 ----A---- C:\Windows\system32\winload.exe
2011-09-13 16:17:57 ----A---- C:\Windows\system32\kd1394.dll
2011-09-13 16:17:56 ----A---- C:\Windows\system32\kdusb.dll
2011-09-13 16:17:56 ----A---- C:\Windows\system32\kdcom.dll
2011-09-13 16:17:51 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-09-13 16:17:51 ----A---- C:\Windows\system32\oleaut32.dll
2011-09-13 16:17:40 ----A---- C:\Windows\system32\KernelBase.dll
2011-09-13 16:17:40 ----A---- C:\Windows\system32\kernel32.dll
2011-09-13 16:17:39 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-09-13 16:17:39 ----A---- C:\Windows\system32\wow64win.dll
2011-09-13 16:17:39 ----A---- C:\Windows\system32\winsrv.dll
2011-09-13 16:17:39 ----A---- C:\Windows\system32\conhost.exe
2011-09-13 16:17:38 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-09-13 16:17:38 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-09-13 16:17:38 ----A---- C:\Windows\system32\wow64.dll
2011-09-13 16:17:37 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-09-13 16:17:37 ----A---- C:\Windows\system32\ntvdm64.dll
2011-09-13 16:17:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-09-13 16:17:36 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-09-13 16:17:36 ----A---- C:\Windows\system32\wow64cpu.dll
2011-09-13 16:17:35 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-09-13 16:17:34 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-09-13 16:17:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-09-13 16:17:24 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-09-13 16:17:23 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-09-13 16:17:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-09-13 16:17:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-09-13 16:17:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-09-13 16:17:22 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-09-13 16:17:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-09-13 16:17:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-09-13 16:17:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-09-13 16:17:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-09-13 16:17:21 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-09-13 16:17:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-09-13 16:17:21 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-09-13 16:17:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-09-13 16:17:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-09-13 16:17:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-09-13 16:17:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-09-13 16:17:20 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-09-13 16:17:20 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-09-13 16:17:20 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-09-13 16:17:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-09-13 16:17:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-09-13 16:17:19 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-09-13 16:17:19 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-09-13 16:17:19 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-09-13 16:17:19 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-09-13 16:17:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-09-13 16:17:17 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-09-13 16:17:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-09-13 16:17:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-09-13 16:17:16 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-09-13 16:17:16 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-09-13 16:17:16 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-09-13 16:17:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-09-13 16:17:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-09-13 16:17:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-09-13 16:17:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-09-13 16:17:15 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-09-13 16:17:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-09-13 16:17:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-09-13 16:17:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-09-13 16:17:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-09-13 16:17:14 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-09-13 16:17:13 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-09-13 16:17:13 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-09-13 16:17:12 ----A---- C:\Windows\SYSWOW64\user.exe
2011-09-13 16:17:09 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-09-13 16:17:08 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-09-13 16:17:08 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-09-13 16:17:07 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-09-13 16:17:07 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-09-13 16:17:05 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-09-13 16:17:05 ----A---- C:\Windows\system32\mstscax.dll
2011-09-13 16:17:03 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-09-13 16:17:02 ----A---- C:\Windows\system32\mstsc.exe
2011-09-13 16:16:58 ----A---- C:\Windows\system32\win32k.sys
2011-09-13 16:16:56 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-09-13 16:16:52 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2011-09-13 16:16:52 ----A---- C:\Windows\system32\prevhost.exe
2011-09-13 16:16:50 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-09-13 16:16:48 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-09-13 16:16:48 ----A---- C:\Windows\system32\inetcomm.dll
2011-09-13 16:16:45 ----A---- C:\Windows\system32\consent.exe
2011-09-13 16:16:42 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-09-13 16:16:38 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-09-13 16:16:38 ----A---- C:\Windows\system32\odbc32.dll
2011-09-13 06:50:15 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-09-13 06:50:14 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-09-13 06:50:14 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-09-12 20:21:56 ----D---- C:\Program Files (x86)\Counter-Strike Source
2011-09-12 19:41:22 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-09-12 19:41:22 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-09-12 19:41:22 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-09-12 19:41:21 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-09-12 19:41:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-09-12 19:41:21 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-09-12 19:41:21 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-09-12 19:41:20 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-09-12 19:41:20 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-09-12 19:41:19 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-09-12 19:41:19 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-09-12 19:41:18 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-09-12 19:41:18 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-09-12 19:41:18 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-09-12 19:41:18 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-09-12 19:41:17 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-09-12 19:41:17 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-09-12 19:41:17 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-09-12 19:41:16 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-09-12 19:41:16 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-09-12 19:41:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-09-12 19:41:16 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-09-12 19:41:16 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-09-12 19:41:16 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-09-12 19:41:15 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-09-12 19:41:15 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-09-12 19:41:14 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-09-12 19:41:14 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-09-12 19:41:14 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-09-12 19:41:13 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-09-12 19:41:13 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-09-12 19:41:13 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-09-12 19:41:13 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-09-12 19:41:13 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-09-12 19:41:13 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-09-12 19:41:12 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-09-12 19:41:12 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-09-12 19:41:12 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-09-12 19:41:12 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-09-12 19:41:12 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-09-12 19:41:12 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-09-12 19:41:11 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-09-12 19:41:11 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-09-12 19:41:11 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-09-12 19:41:11 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-09-12 19:41:11 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-09-12 19:41:11 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-09-12 19:41:10 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-09-12 19:41:10 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-09-12 19:41:10 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-09-12 19:41:10 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-09-12 19:41:10 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-09-12 19:41:10 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-09-12 19:41:09 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-09-12 19:41:09 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-09-12 19:41:09 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-09-12 19:41:09 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-09-12 19:41:09 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-09-12 19:41:09 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-09-12 19:41:08 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-09-12 19:41:08 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-09-12 19:41:08 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-09-12 19:41:08 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-09-12 19:41:07 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-09-12 19:41:07 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-09-12 19:41:07 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-09-12 19:41:07 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-09-12 19:41:07 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-09-12 19:41:07 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-09-12 19:41:07 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-09-12 19:41:07 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-09-12 19:41:06 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-09-12 19:41:06 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-09-12 19:41:06 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-09-12 19:41:06 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-09-12 19:41:05 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-09-12 19:41:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-09-12 19:41:05 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-09-12 19:41:05 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-09-12 19:41:04 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-09-12 19:41:04 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-09-12 19:41:03 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-09-12 19:41:03 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-09-12 19:41:02 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-09-12 19:41:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-09-12 19:41:02 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-09-12 19:41:02 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-09-12 19:41:01 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-09-12 19:41:00 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-09-12 19:41:00 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-09-12 19:41:00 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-09-12 19:41:00 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-09-12 19:41:00 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-09-12 19:41:00 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-09-12 19:40:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-09-12 19:40:59 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-09-12 19:40:58 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-09-12 19:40:58 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-09-12 19:40:58 ----A---- C:\Windows\system32\xinput1_3.dll
2011-09-12 19:40:58 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-09-12 19:40:58 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-09-12 19:40:57 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-09-12 19:40:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-09-12 19:40:57 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-09-12 19:40:57 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-09-12 19:40:56 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-09-12 19:40:56 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-09-12 19:40:56 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-09-12 19:40:56 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-09-12 19:40:55 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-09-12 19:40:55 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-09-12 19:40:55 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-09-12 19:40:55 ----A---- C:\Windows\system32\d3dx10.dll
2011-09-12 19:40:54 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-09-12 19:40:54 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-09-12 19:40:54 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-09-12 19:40:54 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-09-12 19:40:53 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-09-12 19:40:53 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-09-12 19:40:52 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-09-12 19:40:52 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-09-12 19:40:52 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-09-12 19:40:52 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-09-12 19:40:52 ----A---- C:\Windows\system32\xinput1_2.dll
2011-09-12 19:40:52 ----A---- C:\Windows\system32\xinput1_1.dll
2011-09-12 19:40:52 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-09-12 19:40:52 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-09-12 19:40:51 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-09-12 19:40:51 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-09-12 19:40:45 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-09-12 19:40:44 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-09-12 19:40:44 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-09-12 19:40:44 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-09-12 19:40:44 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-09-12 19:40:44 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-09-12 19:40:44 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-09-12 19:40:43 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-09-12 19:40:43 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-09-12 19:40:43 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-09-12 19:40:43 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-09-12 19:40:42 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-09-12 19:40:42 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-09-12 19:40:42 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-09-12 19:40:42 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-09-12 19:40:41 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-09-12 19:40:41 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-09-12 19:28:29 ----D---- C:\Program Files (x86)\GTA San Andreas
2011-09-12 19:21:00 ----D---- C:\Program Files (x86)\Eidos
2011-09-12 19:13:18 ----D---- C:\Users\Pavel\AppData\Roaming\WinRAR
2011-09-12 19:13:11 ----D---- C:\Program Files (x86)\WinRAR
2011-09-12 18:57:38 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-09-12 18:57:26 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-09-12 18:56:51 ----D---- C:\Users\Pavel\AppData\Roaming\DAEMON Tools Lite
2011-09-12 18:56:47 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-09-12 18:30:15 ----D---- C:\Users\Pavel\AppData\Roaming\vlc
2011-09-12 18:29:53 ----D---- C:\Program Files (x86)\VideoLAN
2011-09-12 18:19:14 ----D---- C:\Users\Pavel\AppData\Roaming\Apple Computer
2011-09-12 18:19:05 ----DC---- C:\Windows\system32\DRVSTORE
2011-09-12 18:19:05 ----A---- C:\Windows\SYSWOW64\GEARAspi.dll
2011-09-12 18:19:05 ----A---- C:\Windows\system32\GEARAspi64.dll
2011-09-12 18:19:05 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2011-09-12 18:18:32 ----D---- C:\Program Files\iPod
2011-09-12 18:18:31 ----D---- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-09-12 18:18:31 ----D---- C:\Program Files\iTunes
2011-09-12 18:18:31 ----D---- C:\Program Files (x86)\iTunes
2011-09-12 18:17:27 ----D---- C:\ProgramData\Apple Computer
2011-09-12 18:17:27 ----D---- C:\Program Files (x86)\QuickTime
2011-09-12 18:17:15 ----D---- C:\Program Files (x86)\Apple Software Update
2011-09-12 18:17:08 ----D---- C:\Program Files\Common Files\Apple
2011-09-12 18:17:01 ----D---- C:\Program Files\Bonjour
2011-09-12 18:17:01 ----D---- C:\Program Files (x86)\Bonjour
2011-09-12 18:16:58 ----D---- C:\ProgramData\Apple
2011-09-12 18:09:31 ----D---- C:\Program Files (x86)\KigoVideoConverter
2011-09-12 18:09:02 ----D---- C:\Users\Pavel\AppData\Roaming\Leawo
2011-09-12 18:07:38 ----A---- C:\Windows\SYSWOW64\unrar.dll
2011-09-12 18:07:35 ----D---- C:\Program Files (x86)\K-Lite Codec Pack
2011-09-12 18:07:24 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-09-12 18:07:24 ----A---- C:\Windows\SYSWOW64\msvcr71.dll
2011-09-12 18:07:23 ----A---- C:\Windows\SYSWOW64\msvcp71.dll
2011-09-12 18:07:16 ----D---- C:\Program Files (x86)\Leawo
2011-09-12 17:52:46 ----D---- C:\Users\Pavel\AppData\Roaming\skypePM
2011-09-12 17:52:46 ----AH---- C:\ProgramData\ezsidmv.dat
2011-09-12 17:51:48 ----D---- C:\Users\Pavel\AppData\Roaming\Skype
2011-09-12 17:12:05 ----D---- C:\Users\Pavel\AppData\Roaming\Opera
2011-09-12 17:11:58 ----D---- C:\Program Files (x86)\Opera
2011-09-12 17:10:26 ----D---- C:\Users\Pavel\AppData\Roaming\Toshiba
2011-09-12 17:10:02 ----D---- C:\Users\Pavel\AppData\Roaming\Adobe
2011-09-12 17:09:02 ----D---- C:\Users\Pavel\AppData\Roaming\Nero
2011-09-12 17:08:58 ----D---- C:\Users\Pavel\AppData\Roaming\ATI
2011-09-12 17:08:24 ----D---- C:\Users\Pavel\AppData\Roaming\Identities
2011-09-12 16:59:36 ----D---- C:\ProgramData\ToshibaEurope
2011-09-12 16:59:09 ----SD---- C:\Users\Pavel\AppData\Roaming\Microsoft
2011-09-12 16:59:09 ----D---- C:\Users\Pavel\AppData\Roaming\Media Center Programs
2011-09-12 16:59:09 ----D---- C:\Users\Pavel\AppData\Roaming\Macromedia
2011-09-12 16:58:52 ----SHD---- C:\ProgramData\Šablony
2011-09-12 16:58:51 ----SHD---- C:\ProgramData\Plocha
2011-09-12 16:58:51 ----SHD---- C:\ProgramData\Oblíbené položky
2011-09-12 16:58:51 ----SHD---- C:\ProgramData\Nabídka Start
2011-09-12 16:58:51 ----SHD---- C:\ProgramData\Dokumenty
2011-09-12 16:58:51 ----SHD---- C:\ProgramData\Data aplikací

======List of files/folders modified in the last 1 month======

2011-09-14 21:35:04 ----D---- C:\Windows\Temp
2011-09-14 21:34:31 ----RD---- C:\Program Files
2011-09-14 21:13:24 ----D---- C:\Windows\System32
2011-09-14 21:13:24 ----D---- C:\Windows\inf
2011-09-14 21:13:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-09-14 20:57:09 ----D---- C:\Windows\system32\config
2011-09-14 20:43:24 ----A---- C:\Windows\SYSWOW64\log.txt
2011-09-14 20:43:19 ----RD---- C:\Program Files (x86)
2011-09-14 20:41:36 ----SHD---- C:\System Volume Information
2011-09-14 20:33:20 ----D---- C:\Windows\system32\drivers
2011-09-14 20:33:19 ----HD---- C:\ProgramData
2011-09-14 20:13:38 ----D---- C:\Windows
2011-09-14 19:42:35 ----D---- C:\Windows\Microsoft.NET
2011-09-14 19:42:26 ----RSD---- C:\Windows\assembly
2011-09-14 16:34:00 ----D---- C:\Windows\winsxs
2011-09-14 16:19:43 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-09-14 06:49:28 ----D---- C:\Windows\SysWOW64
2011-09-14 06:38:32 ----SHD---- C:\Windows\Installer
2011-09-14 06:37:31 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-09-14 06:36:32 ----D---- C:\Windows\system32\catroot
2011-09-13 22:44:24 ----D---- C:\Windows\Prefetch
2011-09-13 22:41:17 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-09-13 22:41:17 ----D---- C:\Windows\system32\cs-CZ
2011-09-13 22:41:14 ----D---- C:\Program Files\Internet Explorer
2011-09-13 22:41:14 ----D---- C:\Program Files (x86)\Internet Explorer
2011-09-13 22:41:12 ----D---- C:\Windows\ehome
2011-09-13 22:41:11 ----RSD---- C:\Windows\Fonts
2011-09-13 22:40:58 ----D---- C:\Windows\AppPatch
2011-09-13 22:40:55 ----D---- C:\Windows\system32\Boot
2011-09-13 22:40:55 ----D---- C:\Program Files\Windows Mail
2011-09-13 22:40:55 ----D---- C:\Program Files (x86)\Windows Mail
2011-09-13 22:40:44 ----D---- C:\Windows\SYSWOW64\migration
2011-09-13 22:40:44 ----D---- C:\Windows\system32\migration
2011-09-13 22:39:17 ----D---- C:\Windows\system32\catroot2
2011-09-13 22:28:02 ----D---- C:\Windows\Logs
2011-09-13 22:17:46 ----D---- C:\Windows\debug
2011-09-13 22:14:15 ----D---- C:\Windows\SoftwareDistribution
2011-09-13 22:12:52 ----SD---- C:\ProgramData\Microsoft
2011-09-13 22:12:28 ----D---- C:\Windows\system32\Tasks
2011-09-13 22:12:07 ----D---- C:\Program Files (x86)\Microsoft Office
2011-09-13 22:12:07 ----D---- C:\Program Files (x86)\Common Files
2011-09-13 21:34:28 ----D---- C:\Program Files (x86)\McAfee
2011-09-13 21:26:44 ----D---- C:\Windows\Tasks
2011-09-13 21:11:15 ----D---- C:\Windows\system32\NDF
2011-09-13 20:43:56 ----D---- C:\Windows\system32\LogFiles
2011-09-13 20:36:47 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-09-13 20:21:32 ----D---- C:\Windows\system32\wdi
2011-09-13 06:37:34 ----D---- C:\ProgramData\McAfee
2011-09-12 18:58:26 ----D---- C:\Windows\system32\DriverStore
2011-09-12 18:18:02 ----D---- C:\Windows\system32\restore
2011-09-12 18:17:08 ----D---- C:\Program Files\Common Files
2011-09-12 17:48:12 ----D---- C:\ProgramData\Adobe
2011-09-12 17:08:21 ----SHD---- C:\$RECYCLE.BIN
2011-09-12 17:08:18 ----D---- C:\Toshiba
2011-09-12 16:59:04 ----RD---- C:\Users
2011-09-12 16:58:52 ----D---- C:\Program Files\Windows NT
2011-09-12 16:56:56 ----D---- C:\Windows\rescache
2011-09-12 16:54:40 ----D---- C:\Windows\SYSWOW64\drivers

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-01-15 538136]
R0 LPCFilter;LPC Lower Filter Driver; C:\Windows\system32\DRIVERS\LPCFilter.sys [2010-03-22 46192]
R0 mfehidk;McAfee Inc. mfehidk; C:\Windows\system32\drivers\mfehidk.sys [2011-03-13 639216]
R0 mfewfpk;McAfee Inc. mfewfpk; C:\Windows\system32\drivers\mfewfpk.sys [2011-03-13 281928]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-06-19 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 mfenlfk;McAfee NDIS Light Filter; C:\Windows\system32\DRIVERS\mfenlfk.sys [2011-03-13 75672]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2011-09-14 51496]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-10-05 7884288]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-10-05 285696]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-11-05 2637824]
R3 CeKbFilter;CeKbFilter; C:\Windows\system32\DRIVERS\CeKbFilter.sys [2011-03-04 20592]
R3 cfwids;McAfee Inc. cfwids; C:\Windows\system32\drivers\cfwids.sys [2011-03-13 65128]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-09-12 270912]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-07-28 2445672]
R3 mfeapfk;McAfee Inc. mfeapfk; C:\Windows\system32\drivers\mfeapfk.sys [2011-03-13 156792]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys [2011-03-13 227856]
R3 mfefirek;McAfee Inc. mfefirek; C:\Windows\system32\drivers\mfefirek.sys [2011-03-13 481376]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2010-09-14 760168]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2010-09-14 268648]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2010-09-14 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2010-09-14 22376]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2010-06-18 18872]
S3 BtFilter;Bluetooth LowerFilter Class Filter Driver; C:\Windows\system32\DRIVERS\btfilter.sys [2010-10-18 42096]
S3 mfeavfk01;McAfee Inc.; C:\Windows\system32\drivers\mfeavfk01.sys []
S3 mferkdet;McAfee Inc. mferkdet; C:\Windows\system32\drivers\mferkdet.sys [2011-03-13 98728]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-01-07 232992]
S3 Tosrfcom;Tosrfcom; C:\Windows\system32\drivers\Tosrfcom.sys []
S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2010-05-13 59704]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-10-05 203264]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-05-25 37664]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2011-07-12 387944]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2010-08-27 1811456]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-03-03 268824]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McMPFSvc;McAfee Personal Firewall Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 mcmscsvc;McAfee Services; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McNaiAnn;McAfee VirusScan Announcer; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McNASvc;McAfee Network Agent; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McProxy;McAfee Proxy Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 McShield;McAfee McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [2011-03-13 197960]
R2 mfefire;McAfee Firewall Core Service; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-03-13 208272]
R2 mfevtp;McAfee Validation Trust Protection Service; C:\Windows\system32\mfevtps.exe [2011-03-13 158832]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 NAUpdate;@c:\Program Files (x86)\Nero\Update\NASvc.exe,-200; c:\Program Files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-09-13 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2011-09-13 107832]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2011-09-14 1139928]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2010-09-28 489384]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-08-19 934760]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S3 McODS;McAfee Scanner; C:\Program Files\mcafee\VirusScan\mcods.exe [2011-06-23 501768]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-05-11 124368]
S3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2010-04-12 196976]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-09-13 1255736]
S4 McOobeSv;McAfee OOBE Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 20:44
od sadoman
Tak log je zde. Jak to teda vypadá?

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 20:47
od vyosek
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 20:52
od sadoman
Chtěl bych se jenom zeptat, je toto nutné nebo by se to bez toho obešlo. Nejsem v těchto věcech moc technicky zdatný.

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 21:05
od vyosek
Ok, zvolime tedy mene agresivnejsi cestu :wink:

:arrow: Stahnete OTL (viz muj podpis) a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    adp3132.sys
    AGP440.sys
    ahcix86.sys
    ahcix86s.sys
    atapi.sys
    autochk.exe
    cdrom.sys
    cngaudit.dll
    cryptsvc.dll
    eNetHook.dll
    eventlog.dll
    explorer.exe
    hal.dll
    Changer.sys
    iaStor.sys
    iastorv.sys
    IdeChnDr.sys
    isapnp.sys
    JakNDis.sys
    KR10N.sys
    logevent.dll
    lsass.exe
    mv61xx.sys
    ndis.sys
    netlogon.dll
    ntelogon.dll
    nvata.sys
    nvatabus.sys
    nvgts.sys
    nvraid.sys
    nvrd32.sys
    nvstor.sys
    nvstor32.sys
    scecli.dll
    sceclt.dll
    smss.exe
    svchost.exe
    symmpi.sys
    tcpip.sys
    userinit.exe
    vaxscsi.sys
    viamraid.sys
    viasraid.sys
    ViPrt.sys
    winlogon.exe
    ws2_32.dll
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    type c:\boot.ini >> test.txt /c
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte

Re: Prosím o kontrolu scanu

Napsal: 14 zář 2011 21:50
od sadoman
Ten scan už mi to scanuje vice jak pul hodiny. Je to v poradku?

Re: Prosím o kontrolu scanu

Napsal: 15 zář 2011 06:45
od vyosek
Pokud sken bezi, tak jej nechte - ono hodne zalezi i na mnozstvi souboru, kterymi se musi OTLko prodirat