Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

kontrola logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
cert75
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 12 říj 2011 08:05

kontrola logu

#1 Příspěvek od cert75 »

zdravím prosím o kontrolu Logfile of random's system information tool 1.09 (written by random/random)
Run by RT at 2012-04-20 08:14:18
Microsoft Windows 7 Home Premium
System drive C: has 24 GB (41%) free of 57 GB
Total RAM: 2046 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:14:22, on 20. 4. 2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\RT\Desktop\RSIT.exe
C:\Program Files\trend micro\RT.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Avanquest App'-Anwendungsleiste Toolbar - {1d8566bd-f06f-4029-a3be-ba80af5a09f3} - C:\Program Files\Avanquest_App'-Anwendungsleiste\tbAvan.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: RewardsArcadeSuite - {B6EF6C45-5E8D-4c3b-B580-A5073261A381} - C:\Program Files\RewardsArcadeSuite\RewardsArcadeSuite.dll
O2 - BHO: IncrediMail MediaBar 2 - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\prxtbIncr.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\prxtbIncr.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Avanquest App'-Anwendungsleiste Toolbar - {1d8566bd-f06f-4029-a3be-ba80af5a09f3} - C:\Program Files\Avanquest_App'-Anwendungsleiste\tbAvan.dll
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Spy Emergency Engine Service (SpyEmrgSrv) - NETGATE Technologies s.r.o. - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe

--
End of file - 4282 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GlaryInitialize.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d8566bd-f06f-4029-a3be-ba80af5a09f3}]
Avanquest App'-Anwendungsleiste Toolbar - C:\Program Files\Avanquest_App'-Anwendungsleiste\tbAvan.dll [2010-06-13 2734688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-02-20 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B6EF6C45-5E8D-4c3b-B580-A5073261A381}]
RewardsArcadeSuite - C:\Program Files\RewardsArcadeSuite\RewardsArcadeSuite.dll [2011-11-03 528216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
IncrediMail MediaBar 2 Toolbar - C:\Program Files\IncrediMail_MediaBar_2\prxtbIncr.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-02-20 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - IncrediMail MediaBar 2 Toolbar - C:\Program Files\IncrediMail_MediaBar_2\prxtbIncr.dll [2011-05-09 176936]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
{1d8566bd-f06f-4029-a3be-ba80af5a09f3} - Avanquest App'-Anwendungsleiste Toolbar - C:\Program Files\Avanquest_App'-Anwendungsleiste\tbAvan.dll [2010-06-13 2734688]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2010-05-19 2736128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /starttray []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\Windows\system32\NvCpl.dll [2009-10-03 13826664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-24 323640]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
[]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-04-20 08:14:18 ----D---- C:\rsit
2012-04-20 08:14:18 ----D---- C:\Program Files\trend micro
2012-04-19 11:49:42 ----SHD---- C:\Config.Msi
2012-04-11 19:11:09 ----A---- C:\Windows\system32\wmi.dll
2012-04-11 19:11:09 ----A---- C:\Windows\system32\wintrust.dll
2012-04-11 19:11:09 ----A---- C:\Windows\system32\imagehlp.dll
2012-04-11 19:11:09 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-04-11 19:10:19 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-04-11 19:10:18 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-04-07 20:27:22 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2012-04-07 20:27:22 ----A---- C:\Windows\system32\drivers\sdbus.sys
2012-04-07 16:06:06 ----D---- C:\ProgramData\EA Core
2012-04-07 16:04:38 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-04-07 16:04:37 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-04-06 22:19:08 ----D---- C:\Program Files\Origin Games
2012-04-06 22:18:42 ----D---- C:\ProgramData\Origin
2012-04-06 22:14:22 ----D---- C:\Users\RT\AppData\Roaming\Origin
2012-04-06 22:14:22 ----D---- C:\ProgramData\Electronic Arts
2012-04-06 22:14:05 ----D---- C:\Program Files\Origin
2012-03-31 20:53:55 ----D---- C:\Users\RT\AppData\Roaming\Malwarebytes
2012-03-31 20:53:43 ----D---- C:\ProgramData\Malwarebytes
2012-03-29 10:55:06 ----D---- C:\Users\RT\AppData\Roaming\Spy Emergency
2012-03-29 10:55:02 ----A---- C:\Windows\system32\drivers\spyemrg_access.sys
2012-03-29 10:55:01 ----A---- C:\Windows\system32\drivers\spyemrg_guard.sys
2012-03-29 10:55:01 ----A---- C:\Windows\system32\drivers\spyemrg.sys
2012-03-29 10:54:59 ----D---- C:\ProgramData\NETGATE
2012-03-29 10:54:58 ----D---- C:\Program Files\NETGATE

======List of files/folders modified in the last 1 month======

2012-04-20 08:14:22 ----D---- C:\Windows\Prefetch
2012-04-20 08:14:18 ----RD---- C:\Program Files
2012-04-20 07:47:00 ----D---- C:\Windows\Temp
2012-04-20 07:46:53 ----D---- C:\Windows\system32\config
2012-04-19 20:07:52 ----D---- C:\Program Files\SpeedFan
2012-04-19 11:50:29 ----SHD---- C:\Windows\Installer
2012-04-19 11:43:43 ----SHD---- C:\System Volume Information
2012-04-19 11:39:49 ----D---- C:\Windows\System32
2012-04-19 11:39:49 ----D---- C:\Windows\inf
2012-04-19 11:39:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-14 12:06:25 ----D---- C:\video_output
2012-04-12 20:45:22 ----RSD---- C:\Windows\assembly
2012-04-12 20:45:22 ----D---- C:\Windows\Microsoft.NET
2012-04-11 19:17:22 ----D---- C:\Windows\winsxs
2012-04-11 19:16:02 ----D---- C:\Windows\system32\drivers
2012-04-11 19:11:25 ----D---- C:\Windows\debug
2012-04-11 19:11:23 ----A---- C:\Windows\system32\MRT.exe
2012-04-11 19:11:14 ----D---- C:\Windows\system32\catroot
2012-04-11 19:10:28 ----D---- C:\Windows\system32\catroot2
2012-04-10 09:48:32 ----D---- C:\Windows
2012-04-09 17:56:27 ----D---- C:\Windows\SoftwareDistribution
2012-04-09 17:55:32 ----D---- C:\Windows\Minidump
2012-04-09 17:55:32 ----D---- C:\Windows\Logs
2012-04-09 16:44:27 ----D---- C:\Users\RT\AppData\Roaming\Skype
2012-04-07 20:29:20 ----D---- C:\Windows\system32\DriverStore
2012-04-07 16:06:07 ----HD---- C:\ProgramData
2012-03-30 11:16:37 ----D---- C:\Windows\system32\Tasks
2012-03-30 11:14:18 ----D---- C:\Users\RT\AppData\Roaming\Macromedia
2012-03-30 09:58:50 ----D---- C:\Program Files\Opera
2012-03-29 11:02:18 ----SD---- C:\Users\RT\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2011-03-18 25240]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS [2011-12-19 21624]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 SpyEmrg;Spy Emergency Driver; C:\Windows\System32\Drivers\spyemrg.sys [2011-04-21 14168]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 HBtnKey;HP Hotkey Device; C:\Windows\system32\DRIVERS\cpqbttn.sys [2010-02-25 15544]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 15872]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-02 139776]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2009-10-10 84992]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-14 1068032]
R3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver; C:\Windows\System32\Drivers\spyemrg_guard.sys [2011-04-21 16216]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393216]
S3 DrvAgent32;DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [2012-01-31 23456]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SpyEmrgAccess;Spy Emergency OnAccess Driver; C:\Windows\System32\Drivers\spyemrg_access.sys [2011-04-21 20056]
S3 usbser;Sony Ericsson USB Serial Port; C:\Windows\system32\DRIVERS\usbser.sys [2009-07-14 27648]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-10-03 219752]
R2 SpyEmrgSrv;Spy Emergency Engine Service; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe [2011-09-12 2338000]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-08 136176]
S3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-08 136176]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-01-08 1343400]

-----------------EOF-----------------

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: kontrola logu

#2 Příspěvek od Mc_Murphy »

Zdravím. :162:

Vydž minutku, na logu se intenzivně pracuje. Obrázek
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: kontrola logu

#3 Příspěvek od Mc_Murphy »

:!: Jako první si doinstaluj Windows 7 Service Pack 1 a všechny dostupné aktualizace!

:arrow: Z logu to nevidno, ale pokud nemáš, aktualizuj MS Internet Explorer na poslední verzi. I když používáš prohlížeč Opera, aktualizace řeší spoustu problémů i v systému samotném.
:arrow: Dále, pokud je tam najdeš, tak v nabídce Přidat nebo odebrat programy odinstaluj tyto toolbary: IncrediMail MediaBar 2 Toolbar, Conduit Engine a Avanquest App'-Anwendungsleiste Toolbar.
Obrázek Jsou to veliká "zdržovadla" systému a v případě například Ask.com Toolbar, Conduit Engine a dalších se dá hovořit už i o havěti.


:arrow: Až to všechno provedeš, tak fixni v HJT níže uvedené položky.
  • Fixnout znamená, že spustíš HJT, zvolíš možnost [Do a system scan only] a zaškrtneš čtvereček vlevo od mnou vypsaných položek.
  • Poté klikneš na [Fix checked] a odsouhlasíš [ANO].
  • Položky, které v seznamu nenajdeš, prostě přeskoč.
  • HJT najdeš zde: C:\Program Files\trend micro\RT.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =



:arrow: Dále stáhni utilitu OTM z jednoho z těchto odkazů: Ulož ji na Plochu a dvojklikem spusť.

Do levého okna Paste Instructions for Items to be Moved zkopíruj tento script (pouze zelená písmenka v bílém poli!):

Kód: Vybrat vše

:Commands
[ClearAllRestorePoints]
[ResetHosts]
[Purity]
[EmptyTemp]
[EmptyFlash]

:Services
AdobeARMservice
gupdate
gupdatem

:Files
C:\Program Files\Avanquest_App'-Anwendungsleiste
C:\Program Files\ConduitEngine
C:\Program Files\RewardsArcadeSuite
C:\Program Files\IncrediMail_MediaBar_2
C:\Windows\tasks\GlaryInitialize.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s

:Reg
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"mctadmin"=-
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Sidebar"=-
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d8566bd-f06f-4029-a3be-ba80af5a09f3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B6EF6C45-5E8D-4c3b-B580-A5073261A381}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"=-
"{30F9B915-B755-4826-820B-08FBA6BD249D}"=-
"{1d8566bd-f06f-4029-a3be-ba80af5a09f3}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
Nyní klikni na tlačítko [MoveIt!], čímž vše spustíš.
Po restartu mi sem hoď log, který najdeš v C:\_OTM\MovedFiles\
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

cert75
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 12 říj 2011 08:05

Re: kontrola logu

#4 Příspěvek od cert75 »

dakujem toolbary som odstranil Windows 7 Service Pack 1 nemam lebo toho casu ms vydal zoznam programov ktore by mohli mat problemi po nainstalovani u mna IncrediMail ale vsetky aktualizacie instalujem poctivo nedari sa mi fixnut R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = a este som sa chcel opytat na MS Internet Explorer mam ho aktualizovat aj ked ho mam vpnuty

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: kontrola logu

#5 Příspěvek od Mc_Murphy »

:arrow: Ty fixy nevadí, na ty se vybodni, pokud nejdou.

:arrow: No nevím, co a kde jsi četl, ale Service Pack vydává přímo MS, takže problémy by být neměly. Je to opravný balíček, který mimo jiné odstraňuje spoustu bezpečnostních děr v systému. Důrazně bych Ti doporučil ho nainstalovat!

:arrow: Ano, MSIE si aktualizuj, i když ho nepoužíváš, ale to jsem Ti už psal.
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

cert75
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 12 říj 2011 08:05

Re: kontrola logu

#6 Příspěvek od cert75 »

a este tu je log z OTM All processes killed
========== COMMANDS ==========


C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56475 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: RT
->Temp folder emptied: 37335806 bytes
->Temporary Internet Files folder emptied: 16689715 bytes
->Java cache emptied: 368202 bytes
->Opera cache emptied: 1365770 bytes
->Flash cache emptied: 3119 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10055074 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 63,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: RT
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

========== SERVICES/DRIVERS ==========
Service AdobeARMservice stopped successfully!
Service AdobeARMservice deleted successfully!
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
========== FILES ==========
File/Folder C:\Program Files\Avanquest_App'-Anwendungsleiste not found.
File/Folder C:\Program Files\ConduitEngine not found.
C:\Program Files\RewardsArcadeSuite folder moved successfully.
File/Folder C:\Program Files\IncrediMail_MediaBar_2 not found.
C:\Windows\tasks\GlaryInitialize.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP279C.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5A2B.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5E64.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8545.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPBB04.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD072.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPDC69.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPF00A.tmp folder moved successfully.
C:\Windows\SoftwareDistribution\Download\495b16cc993ced580b2947f386b09002\BIT21F1.tmp moved successfully.
C:\Windows\SoftwareDistribution\Download\b4d82e26accf9aa52f84066f9b9f7ece\BIT2369.tmp moved successfully.
C:\Windows\SoftwareDistribution\Download\bd60fbfcf1ac006bf26f6afa5c1dff1a\BIT257C.tmp moved successfully.
C:\Windows\SoftwareDistribution\Download\fa16adc30e571d398c4d180bc4a555e7\BIT20F7.tmp moved successfully.
========== REGISTRY ==========
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\Sidebar deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\mctadmin not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Sidebar not found.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d8566bd-f06f-4029-a3be-ba80af5a09f3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1d8566bd-f06f-4029-a3be-ba80af5a09f3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B6EF6C45-5E8D-4c3b-B580-A5073261A381}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B6EF6C45-5E8D-4c3b-B580-A5073261A381}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{1d8566bd-f06f-4029-a3be-ba80af5a09f3} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1d8566bd-f06f-4029-a3be-ba80af5a09f3}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh\ deleted successfully.

OTM by OldTimer - Version 3.1.19.0 log created on 04202012_122708

Files moved on Reboot...
File move failed. C:\Windows\temp\ng_temp\sandbox\report.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

cert75
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 12 říj 2011 08:05

Re: kontrola logu

#7 Příspěvek od cert75 »

tak idem to skusit SP1 a potom poslem novy log

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: kontrola logu

#8 Příspěvek od Mc_Murphy »

cert75 píše:tak idem to skusit SP1 a potom poslem novy log
Dobře, vyzkoušej SP1 a pak Ti určitě vyskočí ještě nějaké další aktualizace, včetně i toho MSIE, si myslím. Tak to všechno nainstaluj a dej vědět.
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

cert75
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 12 říj 2011 08:05

Re: kontrola logu

#9 Příspěvek od cert75 »

tak nainstalovane SP1 IE9 aj aktualizovane notas celkom zrychil no nie start ale som spokojny takze dakujem za pomoc a este sem hodim novy log na kontrolu Logfile of random's system information tool 1.09 (written by random/random)
Run by RT at 2012-04-20 14:21:18
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 22 GB (39%) free of 57 GB
Total RAM: 2046 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:22:01, on 20. 4. 2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Opera\opera.exe
C:\Users\RT\Desktop\RSIT.exe
C:\Program Files\trend micro\RT.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Spy Emergency Engine Service (SpyEmrgSrv) - NETGATE Technologies s.r.o. - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe

--
End of file - 2967 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-02-20 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-02-20 42272]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-04-20 14:14:50 ----A---- C:\Windows\system32\mshtmled.dll
2012-04-20 14:14:49 ----A---- C:\Windows\system32\jscript9.dll
2012-04-20 14:14:49 ----A---- C:\Windows\system32\jscript.dll
2012-04-20 14:14:49 ----A---- C:\Windows\system32\iertutil.dll
2012-04-20 14:14:48 ----A---- C:\Windows\system32\wininet.dll
2012-04-20 14:14:48 ----A---- C:\Windows\system32\jsproxy.dll
2012-04-20 14:14:47 ----A---- C:\Windows\system32\url.dll
2012-04-20 14:14:47 ----A---- C:\Windows\system32\ieui.dll
2012-04-20 14:14:46 ----A---- C:\Windows\system32\urlmon.dll
2012-04-20 14:14:44 ----A---- C:\Windows\system32\ieframe.dll
2012-04-20 14:14:43 ----A---- C:\Windows\system32\mshtml.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\wextract.exe
2012-04-20 13:55:16 ----A---- C:\Windows\system32\webcheck.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\vbscript.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2012-04-20 13:55:16 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2012-04-20 13:55:16 ----A---- C:\Windows\system32\pngfilt.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\occache.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\msrating.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\msls31.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\mshtmler.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\mshta.exe
2012-04-20 13:55:16 ----A---- C:\Windows\system32\msfeedssync.exe
2012-04-20 13:55:16 ----A---- C:\Windows\system32\msfeedsbs.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\msfeeds.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\licmgr10.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\inseng.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\imgutil.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\iexpress.exe
2012-04-20 13:55:16 ----A---- C:\Windows\system32\ieUnatt.exe
2012-04-20 13:55:16 ----A---- C:\Windows\system32\iesysprep.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\iesetup.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\iernonce.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\iepeers.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\iedkcs32.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\ieapfltr.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\ieapfltr.dat
2012-04-20 13:55:16 ----A---- C:\Windows\system32\ieakui.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\ieaksie.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\ieakeng.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\IEAdvpack.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\ie4uinit.exe
2012-04-20 13:55:16 ----A---- C:\Windows\system32\icardie.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\dxtrans.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\dxtmsft.dll
2012-04-20 13:55:16 ----A---- C:\Windows\system32\admparse.dll
2012-04-20 13:50:51 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-04-20 13:50:50 ----A---- C:\Windows\system32\rdpwsx.dll
2012-04-20 13:08:32 ----D---- C:\Windows\system32\SPReview
2012-04-20 13:07:21 ----D---- C:\Windows\system32\EventProviders
2012-04-20 13:04:21 ----A---- C:\Windows\system32\dfshim.dll
2012-04-20 13:04:14 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2012-04-20 13:04:13 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2012-04-20 13:04:13 ----A---- C:\Windows\system32\mstscax.dll
2012-04-20 13:04:08 ----A---- C:\Windows\system32\d3d10warp.dll
2012-04-20 13:04:07 ----A---- C:\Windows\system32\mfc40u.dll
2012-04-20 13:04:07 ----A---- C:\Windows\system32\mfc40.dll
2012-04-20 13:04:05 ----A---- C:\Windows\system32\sysmain.dll
2012-04-20 13:04:03 ----A---- C:\Windows\system32\secproc_isv.dll
2012-04-20 13:04:02 ----A---- C:\Windows\system32\RMActivate_isv.exe
2012-04-20 13:04:00 ----A---- C:\Windows\system32\secproc.dll
2012-04-20 13:03:59 ----A---- C:\Windows\system32\RMActivate.exe
2012-04-20 13:03:57 ----A---- C:\Windows\system32\spwizui.dll
2012-04-20 13:03:56 ----A---- C:\Windows\system32\mscoree.dll
2012-04-20 13:03:53 ----A---- C:\Windows\system32\mf.dll
2012-04-20 13:03:52 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2012-04-20 13:03:52 ----A---- C:\Windows\system32\CertEnroll.dll
2012-04-20 13:03:50 ----A---- C:\Windows\system32\wmp.dll
2012-04-20 13:03:49 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-04-20 13:03:49 ----A---- C:\Windows\system32\PresentationHost.exe
2012-04-20 13:03:49 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2012-04-20 13:03:48 ----A---- C:\Windows\system32\drivers\hwpolicy.sys
2012-04-20 13:03:47 ----A---- C:\Windows\system32\schedsvc.dll
2012-04-20 13:03:46 ----A---- C:\Windows\system32\RacEngn.dll
2012-04-20 13:03:45 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2012-04-20 13:03:43 ----A---- C:\Windows\system32\rdpdd.dll
2012-04-20 13:03:42 ----A---- C:\Windows\system32\qmgr.dll
2012-04-20 13:03:41 ----A---- C:\Windows\system32\ExplorerFrame.dll
2012-04-20 13:03:40 ----A---- C:\Windows\system32\wevtsvc.dll
2012-04-20 13:03:40 ----A---- C:\Windows\system32\ole32.dll
2012-04-20 13:03:39 ----A---- C:\Windows\system32\vssapi.dll
2012-04-20 13:03:38 ----A---- C:\Windows\system32\SearchFolder.dll
2012-04-20 13:03:38 ----A---- C:\Windows\system32\d3d9.dll
2012-04-20 13:03:37 ----A---- C:\Windows\system32\IKEEXT.DLL
2012-04-20 13:03:36 ----A---- C:\Windows\system32\taskschd.dll
2012-04-20 13:03:36 ----A---- C:\Windows\system32\crypt32.dll
2012-04-20 13:03:35 ----A---- C:\Windows\system32\mstsc.exe
2012-04-20 13:03:34 ----A---- C:\Windows\system32\termsrv.dll
2012-04-20 13:03:34 ----A---- C:\Windows\system32\spreview.exe
2012-04-20 13:03:34 ----A---- C:\Windows\system32\spinstall.exe
2012-04-20 13:03:33 ----A---- C:\Windows\system32\wer.dll
2012-04-20 13:03:33 ----A---- C:\Windows\system32\rpcrt4.dll
2012-04-20 13:03:33 ----A---- C:\Windows\system32\certcli.dll
2012-04-20 13:03:32 ----A---- C:\Windows\system32\msxml6.dll
2012-04-20 13:03:32 ----A---- C:\Windows\system32\gpsvc.dll
2012-04-20 13:03:32 ----A---- C:\Windows\system32\dwmcore.dll
2012-04-20 13:03:31 ----A---- C:\Windows\system32\odbc32.dll
2012-04-20 13:03:31 ----A---- C:\Windows\system32\diagperf.dll
2012-04-20 13:03:30 ----A---- C:\Windows\system32\WinSAT.exe
2012-04-20 13:03:30 ----A---- C:\Windows\system32\wbengine.exe
2012-04-20 13:03:30 ----A---- C:\Windows\system32\scavengeui.dll
2012-04-20 13:03:30 ----A---- C:\Windows\system32\MPSSVC.dll
2012-04-20 13:03:28 ----A---- C:\Windows\system32\TSWorkspace.dll
2012-04-20 13:03:28 ----A---- C:\Windows\system32\tsmf.dll
2012-04-20 13:03:28 ----A---- C:\Windows\system32\localspl.dll
2012-04-20 13:03:28 ----A---- C:\Windows\system32\dot3api.dll
2012-04-20 13:03:27 ----A---- C:\Windows\system32\winhttp.dll
2012-04-20 13:03:27 ----A---- C:\Windows\system32\setupapi.dll
2012-04-20 13:03:26 ----A---- C:\Windows\system32\MSVidCtl.dll
2012-04-20 13:03:26 ----A---- C:\Windows\system32\apphelp.dll
2012-04-20 13:03:25 ----A---- C:\Windows\system32\VSSVC.exe
2012-04-20 13:03:25 ----A---- C:\Windows\system32\dbgeng.dll
2012-04-20 13:03:24 ----A---- C:\Windows\system32\WindowsCodecs.dll
2012-04-20 13:03:24 ----A---- C:\Windows\system32\netlogon.dll
2012-04-20 13:03:24 ----A---- C:\Windows\system32\netcfgx.dll
2012-04-20 13:03:24 ----A---- C:\Windows\system32\d3d11.dll
2012-04-20 13:03:23 ----A---- C:\Windows\system32\WMVDECOD.DLL
2012-04-20 13:03:23 ----A---- C:\Windows\system32\winlogon.exe
2012-04-20 13:03:23 ----A---- C:\Windows\system32\user32.dll
2012-04-20 13:03:22 ----A---- C:\Windows\system32\Query.dll
2012-04-20 13:03:21 ----A---- C:\Windows\system32\WsmSvc.dll
2012-04-20 13:03:21 ----A---- C:\Windows\system32\upnp.dll
2012-04-20 13:03:21 ----A---- C:\Windows\system32\advapi32.dll
2012-04-20 13:03:20 ----A---- C:\Windows\system32\netfxperf.dll
2012-04-20 13:03:20 ----A---- C:\Windows\system32\msv1_0.dll
2012-04-20 13:03:20 ----A---- C:\Windows\system32\mmcndmgr.dll
2012-04-20 13:03:20 ----A---- C:\Windows\system32\lsm.exe
2012-04-20 13:03:20 ----A---- C:\Windows\system32\DShowRdpFilter.dll
2012-04-20 13:03:19 ----A---- C:\Windows\system32\msdrm.dll
2012-04-20 13:03:19 ----A---- C:\Windows\system32\imapi2fs.dll
2012-04-20 13:03:18 ----A---- C:\Windows\system32\sppobjs.dll
2012-04-20 13:03:18 ----A---- C:\Windows\system32\SessEnv.dll
2012-04-20 13:03:18 ----A---- C:\Windows\system32\authui.dll
2012-04-20 13:03:17 ----A---- C:\Windows\system32\usp10.dll
2012-04-20 13:03:17 ----A---- C:\Windows\system32\shlwapi.dll
2012-04-20 13:03:17 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2012-04-20 13:03:17 ----A---- C:\Windows\system32\mcbuilder.exe
2012-04-20 13:03:16 ----A---- C:\Windows\system32\certmgr.dll
2012-04-20 13:03:15 ----A---- C:\Windows\system32\userenv.dll
2012-04-20 13:03:15 ----A---- C:\Windows\system32\drvstore.dll
2012-04-20 13:03:14 ----A---- C:\Windows\system32\xpsservices.dll
2012-04-20 13:03:14 ----A---- C:\Windows\system32\winload.exe
2012-04-20 13:03:14 ----A---- C:\Windows\system32\WebClnt.dll
2012-04-20 13:03:14 ----A---- C:\Windows\system32\comdlg32.dll
2012-04-20 13:03:14 ----A---- C:\Windows\system32\audiosrv.dll
2012-04-20 13:03:13 ----A---- C:\Windows\system32\sppwinob.dll
2012-04-20 13:03:13 ----A---- C:\Windows\system32\iphlpsvc.dll
2012-04-20 13:03:12 ----A---- C:\Windows\system32\rpcss.dll
2012-04-20 13:03:10 ----A---- C:\Windows\system32\cmd.exe
2012-04-20 13:03:09 ----A---- C:\Windows\system32\BFE.DLL
2012-04-20 13:03:08 ----A---- C:\Windows\system32\Wldap32.dll
2012-04-20 13:03:08 ----A---- C:\Windows\system32\win32spl.dll
2012-04-20 13:03:08 ----A---- C:\Windows\system32\propsys.dll
2012-04-20 13:03:08 ----A---- C:\Windows\system32\mfds.dll
2012-04-20 13:03:08 ----A---- C:\Windows\system32\framedynos.dll
2012-04-20 13:03:07 ----A---- C:\Windows\system32\nlasvc.dll
2012-04-20 13:03:07 ----A---- C:\Windows\system32\drivers\volsnap.sys
2012-04-20 13:03:06 ----A---- C:\Windows\system32\wuaueng.dll
2012-04-20 13:03:06 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-04-20 13:03:05 ----A---- C:\Windows\system32\wmicmiplugin.dll
2012-04-20 13:03:05 ----A---- C:\Windows\system32\samsrv.dll
2012-04-20 13:03:05 ----A---- C:\Windows\system32\drivers\netio.sys
2012-04-20 13:03:04 ----A---- C:\Windows\system32\wucltux.dll
2012-04-20 13:03:04 ----A---- C:\Windows\system32\winresume.exe
2012-04-20 13:03:04 ----A---- C:\Windows\system32\profsvc.dll
2012-04-20 13:03:03 ----A---- C:\Windows\system32\ncsi.dll
2012-04-20 13:03:03 ----A---- C:\Windows\system32\azroles.dll
2012-04-20 13:03:02 ----A---- C:\Windows\system32\werconcpl.dll
2012-04-20 13:03:02 ----A---- C:\Windows\system32\themeui.dll
2012-04-20 13:03:01 ----A---- C:\Windows\system32\taskeng.exe
2012-04-20 13:03:01 ----A---- C:\Windows\system32\spp.dll
2012-04-20 13:03:01 ----A---- C:\Windows\system32\dhcpcore.dll
2012-04-20 13:03:01 ----A---- C:\Windows\system32\credui.dll
2012-04-20 13:03:00 ----A---- C:\Windows\system32\mswsock.dll
2012-04-20 13:03:00 ----A---- C:\Windows\system32\mfreadwrite.dll
2012-04-20 13:03:00 ----A---- C:\Windows\system32\drivers\http.sys
2012-04-20 13:03:00 ----A---- C:\Windows\system32\basecsp.dll
2012-04-20 13:02:59 ----A---- C:\Windows\system32\taskcomp.dll
2012-04-20 13:02:59 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2012-04-20 13:02:59 ----A---- C:\Windows\system32\msxml3.dll
2012-04-20 13:02:59 ----A---- C:\Windows\system32\dxgi.dll
2012-04-20 13:02:59 ----A---- C:\Windows\system32\dbghelp.dll
2012-04-20 13:02:58 ----A---- C:\Windows\system32\WinSATAPI.dll
2012-04-20 13:02:58 ----A---- C:\Windows\system32\spoolsv.exe
2012-04-20 13:02:58 ----A---- C:\Windows\system32\gdi32.dll
2012-04-20 13:02:58 ----A---- C:\Windows\system32\evr.dll
2012-04-20 13:02:58 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2012-04-20 13:02:57 ----A---- C:\Windows\system32\drivers\1394ohci.sys
2012-04-20 13:02:57 ----A---- C:\Windows\system32\calc.exe
2012-04-20 13:02:56 ----A---- C:\Windows\system32\vpnike.dll
2012-04-20 13:02:56 ----A---- C:\Windows\system32\UIRibbon.dll
2012-04-20 13:02:56 ----A---- C:\Windows\system32\srvsvc.dll
2012-04-20 13:02:56 ----A---- C:\Windows\system32\sqlsrv32.dll
2012-04-20 13:02:56 ----A---- C:\Windows\system32\QAGENTRT.DLL
2012-04-20 13:02:55 ----A---- C:\Windows\system32\lpksetup.exe
2012-04-20 13:02:55 ----A---- C:\Windows\system32\fveapi.dll
2012-04-20 13:02:54 ----A---- C:\Windows\system32\sxs.dll
2012-04-20 13:02:54 ----A---- C:\Windows\system32\cryptsvc.dll
2012-04-20 13:02:53 ----A---- C:\Windows\system32\ws2_32.dll
2012-04-20 13:02:53 ----A---- C:\Windows\system32\stobject.dll
2012-04-20 13:02:53 ----A---- C:\Windows\system32\netshell.dll
2012-04-20 13:02:53 ----A---- C:\Windows\system32\hgprint.dll
2012-04-20 13:02:53 ----A---- C:\Windows\system32\drivers\rdbss.sys
2012-04-20 13:02:53 ----A---- C:\Windows\system32\drivers\msdsm.sys
2012-04-20 13:02:53 ----A---- C:\Windows\system32\drivers\fvevol.sys
2012-04-20 13:02:52 ----A---- C:\Windows\system32\prncache.dll
2012-04-20 13:02:52 ----A---- C:\Windows\system32\printui.dll
2012-04-20 13:02:52 ----A---- C:\Windows\system32\msi.dll
2012-04-20 13:02:52 ----A---- C:\Windows\system32\inetpp.dll
2012-04-20 13:02:52 ----A---- C:\Windows\system32\dps.dll
2012-04-20 13:02:52 ----A---- C:\Windows\system32\comctl32.dll
2012-04-20 13:02:50 ----A---- C:\Windows\system32\WSDApi.dll
2012-04-20 13:02:50 ----A---- C:\Windows\system32\wmpeffects.dll
2012-04-20 13:02:50 ----A---- C:\Windows\system32\rpchttp.dll
2012-04-20 13:02:50 ----A---- C:\Windows\system32\net1.exe
2012-04-20 13:02:50 ----A---- C:\Windows\system32\ci.dll
2012-04-20 13:02:50 ----A---- C:\Windows\system32\aitagent.exe
2012-04-20 13:02:50 ----A---- C:\Windows\system32\aepdu.dll
2012-04-20 13:02:49 ----A---- C:\Windows\system32\vds.exe
2012-04-20 13:02:49 ----A---- C:\Windows\system32\scansetting.dll
2012-04-20 13:02:49 ----A---- C:\Windows\system32\FXSSVC.exe
2012-04-20 13:02:49 ----A---- C:\Windows\system32\drivers\pci.sys
2012-04-20 13:02:48 ----A---- C:\Windows\system32\WMVCORE.DLL
2012-04-20 13:02:48 ----A---- C:\Windows\system32\wlangpui.dll
2012-04-20 13:02:48 ----A---- C:\Windows\system32\MMDevAPI.dll
2012-04-20 13:02:48 ----A---- C:\Windows\system32\davclnt.dll
2012-04-20 13:02:48 ----A---- C:\Windows\system32\aaclient.dll
2012-04-20 13:02:47 ----A---- C:\Windows\system32\t2embed.dll
2012-04-20 13:02:47 ----A---- C:\Windows\system32\QSHVHOST.DLL
2012-04-20 13:02:47 ----A---- C:\Windows\system32\pnidui.dll
2012-04-20 13:02:47 ----A---- C:\Windows\system32\IPSECSVC.DLL
2012-04-20 13:02:47 ----A---- C:\Windows\system32\consent.exe
2012-04-20 13:02:46 ----A---- C:\Windows\system32\wpdshext.dll
2012-04-20 13:02:46 ----A---- C:\Windows\system32\webservices.dll
2012-04-20 13:02:46 ----A---- C:\Windows\system32\netdiagfx.dll
2012-04-20 13:02:46 ----A---- C:\Windows\system32\fde.dll
2012-04-20 13:02:46 ----A---- C:\Windows\system32\drivers\termdd.sys
2012-04-20 13:02:45 ----A---- C:\Windows\system32\wscapi.dll
2012-04-20 13:02:45 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2012-04-20 13:02:45 ----A---- C:\Windows\system32\SyncCenter.dll
2012-04-20 13:02:45 ----A---- C:\Windows\system32\sdengin2.dll
2012-04-20 13:02:45 ----A---- C:\Windows\system32\drivers\sbp2port.sys
2012-04-20 13:02:44 ----A---- C:\Windows\system32\wuapi.dll
2012-04-20 13:02:43 ----A---- C:\Windows\system32\wisptis.exe
2012-04-20 13:02:43 ----A---- C:\Windows\system32\WinSCard.dll
2012-04-20 13:02:43 ----A---- C:\Windows\system32\pla.dll
2012-04-20 13:02:43 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2012-04-20 13:02:43 ----A---- C:\Windows\system32\msasn1.dll
2012-04-20 13:02:43 ----A---- C:\Windows\system32\mcmde.dll
2012-04-20 13:02:43 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2012-04-20 13:02:42 ----A---- C:\Windows\system32\WUDFSvc.dll
2012-04-20 13:02:42 ----A---- C:\Windows\system32\winsta.dll
2012-04-20 13:02:42 ----A---- C:\Windows\system32\wiaservc.dll
2012-04-20 13:02:42 ----A---- C:\Windows\system32\setupcl.exe
2012-04-20 13:02:42 ----A---- C:\Windows\system32\imapi2.dll
2012-04-20 13:02:42 ----A---- C:\Windows\system32\drivers\msahci.sys
2012-04-20 13:02:41 ----A---- C:\Windows\system32\gameux.dll
2012-04-20 13:02:41 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2012-04-20 13:02:41 ----A---- C:\Windows\system32\aeinv.dll
2012-04-20 13:02:40 ----A---- C:\Windows\system32\WMPEncEn.dll
2012-04-20 13:02:40 ----A---- C:\Windows\system32\onex.dll
2012-04-20 13:02:40 ----A---- C:\Windows\system32\dwmredir.dll
2012-04-20 13:02:39 ----A---- C:\Windows\system32\winmm.dll
2012-04-20 13:02:39 ----A---- C:\Windows\system32\shsvcs.dll
2012-04-20 13:02:39 ----A---- C:\Windows\system32\rasmans.dll
2012-04-20 13:02:39 ----A---- C:\Windows\system32\drivers\udfs.sys
2012-04-20 13:02:39 ----A---- C:\Windows\system32\drivers\acpi.sys
2012-04-20 13:02:38 ----A---- C:\Windows\system32\vaultsvc.dll
2012-04-20 13:02:38 ----A---- C:\Windows\system32\TabSvc.dll
2012-04-20 13:02:38 ----A---- C:\Windows\system32\netiohlp.dll
2012-04-20 13:02:38 ----A---- C:\Windows\system32\Narrator.exe
2012-04-20 13:02:38 ----A---- C:\Windows\system32\hbaapi.dll
2012-04-20 13:02:38 ----A---- C:\Windows\system32\bootres.dll
2012-04-20 13:02:38 ----A---- C:\Windows\system32\autofmt.exe
2012-04-20 13:02:37 ----A---- C:\Windows\system32\samcli.dll
2012-04-20 13:02:37 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2012-04-20 13:02:37 ----A---- C:\Windows\system32\autochk.exe
2012-04-20 13:02:37 ----A---- C:\Windows\system32\audiodg.exe
2012-04-20 13:02:36 ----A---- C:\Windows\system32\thumbcache.dll
2012-04-20 13:02:36 ----A---- C:\Windows\system32\regapi.dll
2012-04-20 13:02:36 ----A---- C:\Windows\system32\proquota.exe
2012-04-20 13:02:36 ----A---- C:\Windows\system32\msutb.dll
2012-04-20 13:02:36 ----A---- C:\Windows\system32\msinfo32.exe
2012-04-20 13:02:36 ----A---- C:\Windows\system32\mimefilt.dll
2012-04-20 13:02:36 ----A---- C:\Windows\system32\ipsmsnap.dll
2012-04-20 13:02:36 ----A---- C:\Windows\system32\halmacpi.dll
2012-04-20 13:02:36 ----A---- C:\Windows\system32\hal.dll
2012-04-20 13:02:36 ----A---- C:\Windows\system32\autoconv.exe
2012-04-20 13:02:36 ----A---- C:\Windows\system32\AudioSes.dll
2012-04-20 13:02:35 ----A---- C:\Windows\system32\srchadmin.dll
2012-04-20 13:02:35 ----A---- C:\Windows\system32\schtasks.exe
2012-04-20 13:02:34 ----A---- C:\Windows\system32\wcncsvc.dll
2012-04-20 13:02:34 ----A---- C:\Windows\system32\tcpipcfg.dll
2012-04-20 13:02:34 ----A---- C:\Windows\system32\powercpl.dll
2012-04-20 13:02:34 ----A---- C:\Windows\system32\msihnd.dll
2012-04-20 13:02:34 ----A---- C:\Windows\system32\framedyn.dll
2012-04-20 13:02:34 ----A---- C:\Windows\system32\eapphost.dll
2012-04-20 13:02:34 ----A---- C:\Windows\system32\drivers\winusb.sys
2012-04-20 13:02:34 ----A---- C:\Windows\system32\drivers\volmgr.sys
2012-04-20 13:02:33 ----A---- C:\Windows\system32\mscorier.dll
2012-04-20 13:02:33 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2012-04-20 13:02:32 ----A---- C:\Windows\system32\umpo.dll
2012-04-20 13:02:32 ----A---- C:\Windows\system32\QAGENT.DLL
2012-04-20 13:02:32 ----A---- C:\Windows\system32\netid.dll
2012-04-20 13:02:32 ----A---- C:\Windows\system32\DXP.dll
2012-04-20 13:02:32 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-04-20 13:02:32 ----A---- C:\Windows\system32\drivers\netbt.sys
2012-04-20 13:02:32 ----A---- C:\Windows\system32\actxprxy.dll
2012-04-20 13:02:31 ----A---- C:\Windows\system32\wdc.dll
2012-04-20 13:02:31 ----A---- C:\Windows\system32\StructuredQuery.dll
2012-04-20 13:02:31 ----A---- C:\Windows\system32\scesrv.dll
2012-04-20 13:02:30 ----A---- C:\Windows\system32\Vault.dll
2012-04-20 13:02:30 ----A---- C:\Windows\system32\untfs.dll
2012-04-20 13:02:30 ----A---- C:\Windows\system32\rastls.dll
2012-04-20 13:02:30 ----A---- C:\Windows\system32\nci.dll
2012-04-20 13:02:30 ----A---- C:\Windows\system32\drivers\ataport.sys
2012-04-20 13:02:29 ----A---- C:\Windows\system32\sdclt.exe
2012-04-20 13:02:28 ----A---- C:\Windows\system32\WMNetMgr.dll
2012-04-20 13:02:28 ----A---- C:\Windows\system32\wlanpref.dll
2012-04-20 13:02:28 ----A---- C:\Windows\system32\sppsvc.exe
2012-04-20 13:02:28 ----A---- C:\Windows\system32\RpcRtRemote.dll
2012-04-20 13:02:28 ----A---- C:\Windows\system32\ListSvc.dll
2012-04-20 13:02:27 ----A---- C:\Windows\system32\Robocopy.exe
2012-04-20 13:02:26 ----A---- C:\Windows\system32\taskmgr.exe
2012-04-20 13:02:26 ----A---- C:\Windows\system32\mtxclu.dll
2012-04-20 13:02:26 ----A---- C:\Windows\system32\msdri.dll
2012-04-20 13:02:26 ----A---- C:\Windows\system32\DxpTaskSync.dll
2012-04-20 13:02:26 ----A---- C:\Windows\system32\drivers\mpio.sys
2012-04-20 13:02:26 ----A---- C:\Windows\system32\Display.dll
2012-04-20 13:02:25 ----A---- C:\Windows\system32\XpsRasterService.dll
2012-04-20 13:02:25 ----A---- C:\Windows\system32\userinit.exe
2012-04-20 13:02:25 ----A---- C:\Windows\system32\termmgr.dll
2012-04-20 13:02:25 ----A---- C:\Windows\system32\sharemediacpl.dll
2012-04-20 13:02:25 ----A---- C:\Windows\system32\puiobj.dll
2012-04-20 13:02:25 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2012-04-20 13:02:25 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2012-04-20 13:02:24 ----A---- C:\Windows\system32\eudcedit.exe
2012-04-20 13:02:24 ----A---- C:\Windows\system32\drivers\scsiport.sys
2012-04-20 13:02:24 ----A---- C:\Windows\system32\DiagCpl.dll
2012-04-20 13:02:23 ----A---- C:\Windows\system32\wiadefui.dll
2012-04-20 13:02:23 ----A---- C:\Windows\system32\shsetup.dll
2012-04-20 13:02:23 ----A---- C:\Windows\system32\rasppp.dll
2012-04-20 13:02:23 ----A---- C:\Windows\system32\msdtctm.dll
2012-04-20 13:02:23 ----A---- C:\Windows\system32\logoncli.dll
2012-04-20 13:02:23 ----A---- C:\Windows\system32\biocpl.dll
2012-04-20 13:02:22 ----A---- C:\Windows\system32\sppcomapi.dll
2012-04-20 13:02:22 ----A---- C:\Windows\system32\msconfig.exe
2012-04-20 13:02:22 ----A---- C:\Windows\system32\FirewallControlPanel.dll
2012-04-20 13:02:22 ----A---- C:\Windows\system32\cabview.dll
2012-04-20 13:02:21 ----A---- C:\Windows\system32\wpccpl.dll
2012-04-20 13:02:21 ----A---- C:\Windows\system32\themecpl.dll
2012-04-20 13:02:21 ----A---- C:\Windows\system32\SensorsCpl.dll
2012-04-20 13:02:21 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2012-04-20 13:02:21 ----A---- C:\Windows\system32\dnscmmc.dll
2012-04-20 13:02:20 ----A---- C:\Windows\system32\PhotoScreensaver.scr
2012-04-20 13:02:20 ----A---- C:\Windows\system32\hgcpl.dll
2012-04-20 13:02:20 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2012-04-20 13:02:19 ----A---- C:\Windows\system32\tapisrv.dll
2012-04-20 13:02:19 ----A---- C:\Windows\system32\scecli.dll
2012-04-20 13:02:19 ----A---- C:\Windows\system32\mscories.dll
2012-04-20 13:02:19 ----A---- C:\Windows\system32\mscms.dll
2012-04-20 13:02:19 ----A---- C:\Windows\system32\fontext.dll
2012-04-20 13:02:18 ----A---- C:\Windows\system32\wkssvc.dll
2012-04-20 13:02:18 ----A---- C:\Windows\system32\usercpl.dll
2012-04-20 13:02:18 ----A---- C:\Windows\system32\srcore.dll
2012-04-20 13:02:18 ----A---- C:\Windows\system32\SndVolSSO.dll
2012-04-20 13:02:18 ----A---- C:\Windows\system32\mprddm.dll
2012-04-20 13:02:18 ----A---- C:\Windows\system32\localsec.dll
2012-04-20 13:02:18 ----A---- C:\Windows\system32\KMSVC.DLL
2012-04-20 13:02:18 ----A---- C:\Windows\system32\iasacct.dll
2012-04-20 13:02:18 ----A---- C:\Windows\system32\bcdsrv.dll
2012-04-20 13:02:17 ----A---- C:\Windows\system32\wlanui.dll
2012-04-20 13:02:17 ----A---- C:\Windows\system32\VAN.dll
2012-04-20 13:02:17 ----A---- C:\Windows\system32\qedit.dll
2012-04-20 13:02:17 ----A---- C:\Windows\system32\prntvpt.dll
2012-04-20 13:02:17 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2012-04-20 13:02:17 ----A---- C:\Windows\system32\netcenter.dll
2012-04-20 13:02:17 ----A---- C:\Windows\system32\mblctr.exe
2012-04-20 13:02:17 ----A---- C:\Windows\system32\batmeter.dll
2012-04-20 13:02:16 ----A---- C:\Windows\system32\wpdbusenum.dll
2012-04-20 13:02:16 ----A---- C:\Windows\system32\wksprt.exe
2012-04-20 13:02:16 ----A---- C:\Windows\system32\w32tm.exe
2012-04-20 13:02:16 ----A---- C:\Windows\system32\spwizeng.dll
2012-04-20 13:02:16 ----A---- C:\Windows\system32\SndVol.exe
2012-04-20 13:02:16 ----A---- C:\Windows\system32\azroleui.dll
2012-04-20 13:02:15 ----A---- C:\Windows\system32\zipfldr.dll
2012-04-20 13:02:15 ----A---- C:\Windows\system32\fdeploy.dll
2012-04-20 13:02:15 ----A---- C:\Windows\system32\drivers\ks.sys
2012-04-20 13:02:15 ----A---- C:\Windows\system32\accessibilitycpl.dll
2012-04-20 13:02:14 ----A---- C:\Windows\system32\netjoin.dll
2012-04-20 13:02:14 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2012-04-20 13:02:14 ----A---- C:\Windows\system32\cryptui.dll
2012-04-20 13:02:14 ----A---- C:\Windows\system32\adsldp.dll
2012-04-20 13:02:13 ----A---- C:\Windows\system32\wusa.exe
2012-04-20 13:02:13 ----A---- C:\Windows\system32\prnfldr.dll
2012-04-20 13:02:13 ----A---- C:\Windows\system32\networkmap.dll
2012-04-20 13:02:13 ----A---- C:\Windows\system32\mspbda.dll
2012-04-20 13:02:13 ----A---- C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2012-04-20 13:02:13 ----A---- C:\Windows\system32\Faultrep.dll
2012-04-20 13:02:12 ----A---- C:\Windows\system32\taskbarcpl.dll
2012-04-20 13:02:12 ----A---- C:\Windows\system32\sud.dll
2012-04-20 13:02:12 ----A---- C:\Windows\system32\photowiz.dll
2012-04-20 13:02:12 ----A---- C:\Windows\system32\OnLineIDCpl.dll
2012-04-20 13:02:12 ----A---- C:\Windows\system32\msieftp.dll
2012-04-20 13:02:12 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2012-04-20 13:02:12 ----A---- C:\Windows\system32\ActionCenter.dll
2012-04-20 13:02:11 ----A---- C:\Windows\system32\taskhost.exe
2012-04-20 13:02:11 ----A---- C:\Windows\system32\slui.exe
2012-04-20 13:02:11 ----A---- C:\Windows\system32\iprtrmgr.dll
2012-04-20 13:02:11 ----A---- C:\Windows\system32\iasrad.dll
2012-04-20 13:02:11 ----A---- C:\Windows\system32\drivers\hidclass.sys
2012-04-20 13:02:11 ----A---- C:\Windows\system32\defaultlocationcpl.dll
2012-04-20 13:02:11 ----A---- C:\Windows\system32\credssp.dll
2012-04-20 13:02:10 ----A---- C:\Windows\system32\sisbkup.dll
2012-04-20 13:02:10 ----A---- C:\Windows\system32\halacpi.dll
2012-04-20 13:02:10 ----A---- C:\Windows\system32\ftp.exe
2012-04-20 13:02:10 ----A---- C:\Windows\system32\dot3cfg.dll
2012-04-20 13:02:09 ----A---- C:\Windows\system32\wpd_ci.dll
2012-04-20 13:02:09 ----A---- C:\Windows\system32\shwebsvc.dll
2012-04-20 13:02:09 ----A---- C:\Windows\system32\recovery.dll
2012-04-20 13:02:09 ----A---- C:\Windows\system32\ifsutil.dll
2012-04-20 13:02:09 ----A---- C:\Windows\system32\efscore.dll
2012-04-20 13:02:09 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2012-04-20 13:02:08 ----A---- C:\Windows\system32\syncui.dll
2012-04-20 13:02:08 ----A---- C:\Windows\system32\sdcpl.dll
2012-04-20 13:02:08 ----A---- C:\Windows\system32\DeviceCenter.dll
2012-04-20 13:02:08 ----A---- C:\Windows\system32\bcdedit.exe
2012-04-20 13:02:08 ----A---- C:\Windows\system32\autoplay.dll
2012-04-20 13:02:07 ----A---- C:\Windows\system32\wmpmde.dll
2012-04-20 13:02:07 ----A---- C:\Windows\system32\sppnp.dll
2012-04-20 13:02:07 ----A---- C:\Windows\system32\rtutils.dll
2012-04-20 13:02:07 ----A---- C:\Windows\system32\OobeFldr.dll
2012-04-20 13:02:07 ----A---- C:\Windows\system32\ntlanman.dll
2012-04-20 13:02:07 ----A---- C:\Windows\system32\dskquoui.dll
2012-04-20 13:02:06 ----A---- C:\Windows\system32\vdsutil.dll
2012-04-20 13:02:06 ----A---- C:\Windows\system32\systemcpl.dll
2012-04-20 13:02:06 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2012-04-20 13:02:06 ----A---- C:\Windows\system32\sethc.exe
2012-04-20 13:02:06 ----A---- C:\Windows\system32\rstrui.exe
2012-04-20 13:02:06 ----A---- C:\Windows\system32\riched20.dll
2012-04-20 13:02:06 ----A---- C:\Windows\system32\recdisc.exe
2012-04-20 13:02:06 ----A---- C:\Windows\system32\ntprint.dll
2012-04-20 13:02:06 ----A---- C:\Windows\system32\nshwfp.dll
2012-04-20 13:02:06 ----A---- C:\Windows\system32\bcdboot.exe
2012-04-20 13:02:05 ----A---- C:\Windows\system32\drivers\tdx.sys
2012-04-20 13:02:05 ----A---- C:\Windows\system32\blackbox.dll
2012-04-20 13:02:04 ----A---- C:\Windows\system32\wmpsrcwp.dll
2012-04-20 13:02:04 ----A---- C:\Windows\system32\netplwiz.dll
2012-04-20 13:02:04 ----A---- C:\Windows\system32\NAPHLPR.DLL
2012-04-20 13:02:04 ----A---- C:\Windows\system32\migisol.dll
2012-04-20 13:02:04 ----A---- C:\Windows\system32\fms.dll
2012-04-20 13:02:04 ----A---- C:\Windows\system32\dpx.dll
2012-04-20 13:02:04 ----A---- C:\Windows\system32\AxInstSv.dll
2012-04-20 13:02:04 ----A---- C:\Windows\system32\activeds.dll
2012-04-20 13:02:03 ----A---- C:\Windows\system32\nshipsec.dll
2012-04-20 13:02:03 ----A---- C:\Windows\system32\nlaapi.dll
2012-04-20 13:02:03 ----A---- C:\Windows\system32\httpapi.dll
2012-04-20 13:02:03 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2012-04-20 13:02:03 ----A---- C:\Windows\system32\dot3svc.dll
2012-04-20 13:02:03 ----A---- C:\Windows\system32\cdosys.dll
2012-04-20 13:02:03 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2012-04-20 13:02:03 ----A---- C:\Windows\system32\asycfilt.dll
2012-04-20 13:02:02 ----A---- C:\Windows\system32\wuwebv.dll
2012-04-20 13:02:02 ----A---- C:\Windows\system32\wsqmcons.exe
2012-04-20 13:02:02 ----A---- C:\Windows\system32\wlanmsm.dll
2012-04-20 13:02:02 ----A---- C:\Windows\system32\wavemsp.dll
2012-04-20 13:02:02 ----A---- C:\Windows\system32\ReAgent.dll
2012-04-20 13:02:02 ----A---- C:\Windows\system32\provsvc.dll
2012-04-20 13:02:02 ----A---- C:\Windows\system32\msftedit.dll
2012-04-20 13:02:02 ----A---- C:\Windows\system32\isoburn.exe
2012-04-20 13:02:02 ----A---- C:\Windows\system32\dot3ui.dll
2012-04-20 13:02:01 ----A---- C:\Windows\system32\wvc.dll
2012-04-20 13:02:01 ----A---- C:\Windows\system32\wtsapi32.dll
2012-04-20 13:02:01 ----A---- C:\Windows\system32\tzutil.exe
2012-04-20 13:02:01 ----A---- C:\Windows\system32\sysclass.dll
2012-04-20 13:02:01 ----A---- C:\Windows\system32\ocsetup.exe
2012-04-20 13:02:01 ----A---- C:\Windows\system32\dsuiext.dll
2012-04-20 13:02:01 ----A---- C:\Windows\system32\drivers\ndproxy.sys
2012-04-20 13:02:01 ----A---- C:\Windows\system32\dfrgui.exe
2012-04-20 13:02:01 ----A---- C:\Windows\system32\appinfo.dll
2012-04-20 13:02:00 ----A---- C:\Windows\system32\wimgapi.dll
2012-04-20 13:02:00 ----A---- C:\Windows\system32\twext.dll
2012-04-20 13:02:00 ----A---- C:\Windows\system32\PkgMgr.exe
2012-04-20 13:02:00 ----A---- C:\Windows\system32\mstask.dll
2012-04-20 13:02:00 ----A---- C:\Windows\system32\certprop.dll
2012-04-20 13:01:59 ----A---- C:\Windows\twain_32.dll
2012-04-20 13:01:59 ----A---- C:\Windows\system32\SmiEngine.dll
2012-04-20 13:01:59 ----A---- C:\Windows\system32\shdocvw.dll
2012-04-20 13:01:59 ----A---- C:\Windows\system32\setupugc.exe
2012-04-20 13:01:59 ----A---- C:\Windows\system32\qcap.dll
2012-04-20 13:01:59 ----A---- C:\Windows\system32\qasf.dll
2012-04-20 13:01:58 ----A---- C:\Windows\system32\wwanconn.dll
2012-04-20 13:01:58 ----A---- C:\Windows\system32\uxlib.dll
2012-04-20 13:01:58 ----A---- C:\Windows\system32\ssText3d.scr
2012-04-20 13:01:58 ----A---- C:\Windows\system32\srrstr.dll
2012-04-20 13:01:58 ----A---- C:\Windows\system32\slwga.dll
2012-04-20 13:01:58 ----A---- C:\Windows\system32\imm32.dll
2012-04-20 13:01:57 ----A---- C:\Windows\system32\wmdrmsdk.dll
2012-04-20 13:01:57 ----A---- C:\Windows\system32\nslookup.exe
2012-04-20 13:01:57 ----A---- C:\Windows\system32\msvfw32.dll
2012-04-20 13:01:57 ----A---- C:\Windows\system32\mciavi32.dll
2012-04-20 13:01:57 ----A---- C:\Windows\system32\clusapi.dll
2012-04-20 13:01:57 ----A---- C:\Windows\system32\audiodev.dll
2012-04-20 13:01:56 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2012-04-20 13:01:56 ----A---- C:\Windows\system32\msscp.dll
2012-04-20 13:01:56 ----A---- C:\Windows\system32\diskraid.exe
2012-04-20 13:01:56 ----A---- C:\Windows\system32\DevicePairingFolder.dll
2012-04-20 13:01:55 ----A---- C:\Windows\system32\wimserv.exe
2012-04-20 13:01:55 ----A---- C:\Windows\system32\TSpkg.dll
2012-04-20 13:01:55 ----A---- C:\Windows\system32\remotepg.dll
2012-04-20 13:01:55 ----A---- C:\Windows\system32\rdpencom.dll
2012-04-20 13:01:55 ----A---- C:\Windows\system32\raschap.dll
2012-04-20 13:01:55 ----A---- C:\Windows\system32\perfmon.exe
2012-04-20 13:01:55 ----A---- C:\Windows\system32\acppage.dll
2012-04-20 13:01:54 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2012-04-20 13:01:54 ----A---- C:\Windows\system32\UserAccountControlSettings.dll
2012-04-20 13:01:54 ----A---- C:\Windows\system32\sdrsvc.dll
2012-04-20 13:01:54 ----A---- C:\Windows\system32\QUTIL.DLL
2012-04-20 13:01:54 ----A---- C:\Windows\system32\ocsetapi.dll
2012-04-20 13:01:54 ----A---- C:\Windows\system32\networkexplorer.dll
2012-04-20 13:01:54 ----A---- C:\Windows\system32\NAPCRYPT.DLL
2012-04-20 13:01:54 ----A---- C:\Windows\system32\input.dll
2012-04-20 13:01:54 ----A---- C:\Windows\system32\drmmgrtn.dll
2012-04-20 13:01:54 ----A---- C:\Windows\system32\browser.dll
2012-04-20 13:01:53 ----A---- C:\Windows\system32\wmpdxm.dll
2012-04-20 13:01:53 ----A---- C:\Windows\system32\vpnikeapi.dll
2012-04-20 13:01:53 ----A---- C:\Windows\system32\olepro32.dll
2012-04-20 13:01:53 ----A---- C:\Windows\system32\nltest.exe
2012-04-20 13:01:52 ----A---- C:\Windows\system32\wpdwcn.dll
2012-04-20 13:01:52 ----A---- C:\Windows\system32\vdsbas.dll
2012-04-20 13:01:52 ----A---- C:\Windows\system32\runonce.exe
2012-04-20 13:01:52 ----A---- C:\Windows\system32\onexui.dll
2012-04-20 13:01:52 ----A---- C:\Windows\system32\iTVData.dll
2012-04-20 13:01:52 ----A---- C:\Windows\system32\dxdiagn.dll
2012-04-20 13:01:52 ----A---- C:\Windows\bfsvc.exe
2012-04-20 13:01:51 ----A---- C:\Windows\system32\Mcx2Svc.dll
2012-04-20 13:01:51 ----A---- C:\Windows\system32\logagent.exe
2012-04-20 13:01:51 ----A---- C:\Windows\system32\drivers\sdbus.sys
2012-04-20 13:01:50 ----A---- C:\Windows\system32\msvidc32.dll
2012-04-20 13:01:50 ----A---- C:\Windows\system32\msiexec.exe
2012-04-20 13:01:50 ----A---- C:\Windows\system32\MFPlay.dll
2012-04-20 13:01:50 ----A---- C:\Windows\system32\eapp3hst.dll
2012-04-20 13:01:50 ----A---- C:\Windows\system32\drivers\rmcast.sys
2012-04-20 13:01:50 ----A---- C:\Windows\system32\d3d10level9.dll
2012-04-20 13:01:49 ----A---- C:\Windows\system32\wmpshell.dll
2012-04-20 13:01:49 ----A---- C:\Windows\system32\wmdrmdev.dll
2012-04-20 13:01:49 ----A---- C:\Windows\system32\shacct.dll
2012-04-20 13:01:49 ----A---- C:\Windows\system32\PnPUnattend.exe
2012-04-20 13:01:48 ----A---- C:\Windows\system32\wudriver.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\unimdmat.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\tabcal.exe
2012-04-20 13:01:48 ----A---- C:\Windows\system32\sqlcese30.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\rdpd3d.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\pdh.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\mprapi.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\lsmproxy.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\iscsium.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\cscapi.dll
2012-04-20 13:01:48 ----A---- C:\Windows\system32\Bubbles.scr
2012-04-20 13:01:48 ----A---- C:\Windows\system32\bitsadmin.exe
2012-04-20 13:01:47 ----A---- C:\Windows\system32\WUDFPlatform.dll
2012-04-20 13:01:47 ----A---- C:\Windows\system32\WPDSp.dll
2012-04-20 13:01:47 ----A---- C:\Windows\system32\srvcli.dll
2012-04-20 13:01:47 ----A---- C:\Windows\system32\PortableDeviceSyncProvider.dll
2012-04-20 13:01:47 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2012-04-20 13:01:47 ----A---- C:\Windows\system32\OpcServices.dll
2012-04-20 13:01:47 ----A---- C:\Windows\system32\olethk32.dll
2012-04-20 13:01:47 ----A---- C:\Windows\system32\ncryptui.dll
2012-04-20 13:01:47 ----A---- C:\Windows\system32\MdSched.exe
2012-04-20 13:01:47 ----A---- C:\Windows\system32\logman.exe
2012-04-20 13:01:47 ----A---- C:\Windows\system32\djoin.exe
2012-04-20 13:01:46 ----A---- C:\Windows\system32\wwanprotdim.dll
2012-04-20 13:01:46 ----A---- C:\Windows\system32\WMPhoto.dll
2012-04-20 13:01:46 ----A---- C:\Windows\system32\tsgqec.dll
2012-04-20 13:01:46 ----A---- C:\Windows\system32\Ribbons.scr
2012-04-20 13:01:46 ----A---- C:\Windows\system32\QSVRMGMT.DLL
2012-04-20 13:01:46 ----A---- C:\Windows\system32\Mystify.scr
2012-04-20 13:01:46 ----A---- C:\Windows\system32\mapistub.dll
2012-04-20 13:01:46 ----A---- C:\Windows\system32\mapi32.dll
2012-04-20 13:01:46 ----A---- C:\Windows\system32\lpremove.exe
2012-04-20 13:01:46 ----A---- C:\Windows\system32\ActionQueue.dll
2012-04-20 13:01:45 ----A---- C:\Windows\system32\WMADMOD.DLL
2012-04-20 13:01:45 ----A---- C:\Windows\system32\wiavideo.dll
2012-04-20 13:01:45 ----A---- C:\Windows\system32\utildll.dll
2012-04-20 13:01:45 ----A---- C:\Windows\system32\takeown.exe
2012-04-20 13:01:45 ----A---- C:\Windows\system32\fphc.dll
2012-04-20 13:01:45 ----A---- C:\Windows\system32\dot3msm.dll
2012-04-20 13:01:45 ----A---- C:\Windows\system32\avifil32.dll
2012-04-20 13:01:44 ----A---- C:\Windows\system32\WMVSDECD.DLL
2012-04-20 13:01:44 ----A---- C:\Windows\system32\wmdrmnet.dll
2012-04-20 13:01:44 ----A---- C:\Windows\system32\WindowsAnytimeUpgrade.exe
2012-04-20 13:01:44 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2012-04-20 13:01:44 ----A---- C:\Windows\system32\sqmapi.dll
2012-04-20 13:01:44 ----A---- C:\Windows\system32\qdv.dll
2012-04-20 13:01:44 ----A---- C:\Windows\system32\iyuv_32.dll
2012-04-20 13:01:44 ----A---- C:\Windows\system32\EhStorAPI.dll
2012-04-20 13:01:43 ----A---- C:\Windows\system32\unattend.dll
2012-04-20 13:01:43 ----A---- C:\Windows\system32\sppinst.dll
2012-04-20 13:01:43 ----A---- C:\Windows\system32\QCLIPROV.DLL
2012-04-20 13:01:43 ----A---- C:\Windows\system32\msyuv.dll
2012-04-20 13:01:43 ----A---- C:\Windows\system32\msrle32.dll
2012-04-20 13:01:43 ----A---- C:\Windows\system32\msnetobj.dll
2012-04-20 13:01:43 ----A---- C:\Windows\system32\cmstp.exe
2012-04-20 13:01:43 ----A---- C:\Windows\system32\cca.dll
2012-04-20 13:01:42 ----A---- C:\Windows\system32\WUDFx.dll
2012-04-20 13:01:42 ----A---- C:\Windows\system32\WUDFHost.exe
2012-04-20 13:01:42 ----A---- C:\Windows\system32\wsnmp32.dll
2012-04-20 13:01:42 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2012-04-20 13:01:42 ----A---- C:\Windows\system32\vfwwdm32.dll
2012-04-20 13:01:42 ----A---- C:\Windows\system32\RelPost.exe
2012-04-20 13:01:42 ----A---- C:\Windows\system32\pdhui.dll
2012-04-20 13:01:42 ----A---- C:\Windows\system32\MuiUnattend.exe
2012-04-20 13:01:42 ----A---- C:\Windows\system32\basesrv.dll
2012-04-20 13:01:41 ----A---- C:\Windows\system32\wuauclt.exe
2012-04-20 13:01:41 ----A---- C:\Windows\system32\umb.dll
2012-04-20 13:01:41 ----A---- C:\Windows\system32\tsbyuv.dll
2012-04-20 13:01:41 ----A---- C:\Windows\system32\setupcln.dll
2012-04-20 13:01:41 ----A---- C:\Windows\system32\msorcl32.dll
2012-04-20 13:01:41 ----A---- C:\Windows\system32\iasrecst.dll
2012-04-20 13:01:41 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2012-04-20 13:01:41 ----A---- C:\Windows\system32\AzSqlExt.dll
2012-04-20 13:01:40 ----A---- C:\Windows\system32\wkscli.dll
2012-04-20 13:01:40 ----A---- C:\Windows\system32\WavDest.dll
2012-04-20 13:01:40 ----A---- C:\Windows\system32\relog.exe
2012-04-20 13:01:40 ----A---- C:\Windows\system32\PrintIsolationProxy.dll
2012-04-20 13:01:40 ----A---- C:\Windows\system32\netiougc.exe
2012-04-20 13:01:40 ----A---- C:\Windows\system32\iscsicli.exe
2012-04-20 13:01:40 ----A---- C:\Windows\system32\drivers\ndisuio.sys
2012-04-20 13:01:39 ----A---- C:\Windows\system32\sppuinotify.dll
2012-04-20 13:01:39 ----A---- C:\Windows\system32\spbcd.dll
2012-04-20 13:01:39 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2012-04-20 13:01:39 ----A---- C:\Windows\system32\resutils.dll
2012-04-20 13:01:39 ----A---- C:\Windows\system32\rastapi.dll
2012-04-20 13:01:39 ----A---- C:\Windows\system32\netbtugc.exe
2012-04-20 13:01:39 ----A---- C:\Windows\system32\mydocs.dll
2012-04-20 13:01:39 ----A---- C:\Windows\system32\MultiDigiMon.exe
2012-04-20 13:01:39 ----A---- C:\Windows\system32\diskpart.exe
2012-04-20 13:01:39 ----A---- C:\Windows\system32\amstream.dll
2012-04-20 13:01:38 ----A---- C:\Windows\system32\wmpps.dll
2012-04-20 13:01:38 ----A---- C:\Windows\system32\syssetup.dll
2012-04-20 13:01:38 ----A---- C:\Windows\system32\setbcdlocale.dll
2012-04-20 13:01:38 ----A---- C:\Windows\system32\secproc_ssp.dll
2012-04-20 13:01:38 ----A---- C:\Windows\system32\nrpsrv.dll
2012-04-20 13:01:38 ----A---- C:\Windows\system32\itircl.dll
2012-04-20 13:01:38 ----A---- C:\Windows\system32\FXSTIFF.dll
2012-04-20 13:01:38 ----A---- C:\Windows\system32\CertPolEng.dll
2012-04-20 13:01:37 ----A---- C:\Windows\system32\wuapp.exe
2012-04-20 13:01:37 ----A---- C:\Windows\system32\WerFaultSecure.exe
2012-04-20 13:01:37 ----A---- C:\Windows\system32\tlscsp.dll
2012-04-20 13:01:37 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2012-04-20 13:01:37 ----A---- C:\Windows\system32\ReAgentc.exe
2012-04-20 13:01:37 ----A---- C:\Windows\system32\findstr.exe
2012-04-20 13:01:37 ----A---- C:\Windows\system32\eappgnui.dll
2012-04-20 13:01:36 ----A---- C:\Windows\system32\wiarpc.dll
2012-04-20 13:01:36 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2012-04-20 13:01:36 ----A---- C:\Windows\system32\netutils.dll
2012-04-20 13:01:36 ----A---- C:\Windows\system32\mciqtz32.dll
2012-04-20 13:01:35 ----A---- C:\Windows\system32\sppc.dll
2012-04-20 13:01:35 ----A---- C:\Windows\system32\spopk.dll
2012-04-20 13:01:35 ----A---- C:\Windows\system32\netapi32.dll
2012-04-20 13:01:35 ----A---- C:\Windows\system32\muifontsetup.dll
2012-04-20 13:01:35 ----A---- C:\Windows\system32\mobsync.exe
2012-04-20 13:01:35 ----A---- C:\Windows\system32\iccvid.dll
2012-04-20 13:01:35 ----A---- C:\Windows\system32\drivers\tdi.sys
2012-04-20 13:01:35 ----A---- C:\Windows\system32\dosx.exe
2012-04-20 13:01:35 ----A---- C:\Windows\system32\cabinet.dll
2012-04-20 13:01:34 ----A---- C:\Windows\system32\wdiasqmmodule.dll
2012-04-20 13:01:34 ----A---- C:\Windows\system32\unlodctr.exe
2012-04-20 13:01:34 ----A---- C:\Windows\system32\shimgvw.dll
2012-04-20 13:01:34 ----A---- C:\Windows\system32\repair-bde.exe
2012-04-20 13:01:34 ----A---- C:\Windows\system32\netcfg.exe
2012-04-20 13:01:34 ----A---- C:\Windows\system32\msdmo.dll
2012-04-20 13:01:34 ----A---- C:\Windows\system32\manage-bde.exe
2012-04-20 13:01:34 ----A---- C:\Windows\system32\luainstall.dll
2012-04-20 13:01:34 ----A---- C:\Windows\system32\HotStartUserAgent.dll
2012-04-20 13:01:34 ----A---- C:\Windows\system32\drivers\usbrpm.sys
2012-04-20 13:01:34 ----A---- C:\Windows\system32\drivers\CompositeBus.sys
2012-04-20 13:01:33 ----A---- C:\Windows\system32\rdprefdrvapi.dll
2012-04-20 13:01:33 ----A---- C:\Windows\system32\inetmib1.dll
2012-04-20 13:01:32 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2012-04-20 13:01:32 ----A---- C:\Windows\system32\profprov.dll
2012-04-20 13:01:32 ----A---- C:\Windows\system32\odbcconf.dll
2012-04-20 13:01:32 ----A---- C:\Windows\system32\drivers\cdrom.sys
2012-04-20 13:01:31 ----A---- C:\Windows\system32\wups.dll
2012-04-20 13:01:31 ----A---- C:\Windows\system32\UIRibbonRes.dll
2012-04-20 13:01:31 ----A---- C:\Windows\system32\browcli.dll
2012-04-20 13:01:30 ----A---- C:\Windows\system32\perfts.dll
2012-04-20 13:01:30 ----A---- C:\Windows\system32\icaapi.dll
2012-04-20 13:01:30 ----A---- C:\Windows\system32\FXSMON.dll
2012-04-20 13:01:30 ----A---- C:\Windows\system32\drivers\tunnel.sys
2012-04-20 13:01:30 ----A---- C:\Windows\system32\drivers\dfsc.sys
2012-04-20 13:01:29 ----A---- C:\Windows\system32\TRAPI.dll
2012-04-20 13:01:29 ----A---- C:\Windows\system32\RDPENCDD.dll
2012-04-20 13:01:29 ----A---- C:\Windows\system32\elsTrans.dll
2012-04-20 13:01:29 ----A---- C:\Windows\system32\bitsperf.dll
2012-04-20 13:01:28 ----A---- C:\Windows\system32\wshbth.dll
2012-04-20 13:01:28 ----A---- C:\Windows\system32\schedcli.dll
2012-04-20 13:01:28 ----A---- C:\Windows\system32\napdsnap.dll
2012-04-20 13:01:28 ----A---- C:\Windows\system32\LogonUI.exe
2012-04-20 13:01:28 ----A---- C:\Windows\system32\dsauth.dll
2012-04-20 13:01:28 ----A---- C:\Windows\system32\cscdll.dll
2012-04-20 13:01:27 ----A---- C:\Windows\system32\sscore.dll
2012-04-20 13:01:27 ----A---- C:\Windows\system32\drivers\acpipmi.sys
2012-04-20 13:01:26 ----A---- C:\Windows\system32\wups2.dll
2012-04-20 13:01:26 ----A---- C:\Windows\system32\wsdchngr.dll
2012-04-20 13:01:26 ----A---- C:\Windows\system32\shgina.dll
2012-04-20 13:01:26 ----A---- C:\Windows\system32\riched32.dll
2012-04-20 13:01:26 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2012-04-20 13:01:25 ----A---- C:\Windows\system32\rdpcfgex.dll
2012-04-20 13:01:25 ----A---- C:\Windows\system32\drivers\hidusb.sys
2012-04-20 13:01:24 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2012-04-20 13:01:24 ----A---- C:\Windows\system32\drivers\appid.sys
2012-04-20 13:01:23 ----A---- C:\Windows\system32\wshirda.dll
2012-04-20 13:01:23 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2012-04-20 13:01:22 ----A---- C:\Windows\system32\drivers\usbser.sys
2012-04-20 13:01:22 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys
2012-04-20 13:01:22 ----A---- C:\Windows\system32\drivers\USBCAMD.sys
2012-04-20 13:01:22 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2012-04-20 13:01:22 ----A---- C:\Windows\system32\browseui.dll
2012-04-20 13:01:21 ----A---- C:\Windows\system32\spwmp.dll
2012-04-20 13:01:21 ----A---- C:\Windows\system32\drivers\wanarp.sys
2012-04-20 13:01:21 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2012-04-20 13:01:20 ----A---- C:\Windows\system32\shunimpl.dll
2012-04-20 13:01:20 ----A---- C:\Windows\system32\RDPREFDD.dll
2012-04-20 13:01:20 ----A---- C:\Windows\system32\dxmasf.dll
2012-04-20 13:01:20 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2012-04-20 13:01:20 ----A---- C:\Windows\system32\drivers\umbus.sys
2012-04-20 13:01:20 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2012-04-20 13:01:20 ----A---- C:\Windows\system32\drivers\scfilter.sys
2012-04-20 13:01:20 ----A---- C:\Windows\system32\drivers\RDPCDD.sys
2012-04-20 13:01:20 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2012-04-20 13:01:20 ----A---- C:\Windows\system32\C_ISCII.DLL
2012-04-20 13:01:19 ----A---- C:\Windows\system32\wmploc.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDUS.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDUGHR1.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDTURME.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDTAJIK.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDSF.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDNEPR.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDMON.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDMAORI.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDLT1.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\kbdlk41a.dll
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDINTEL.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDINTAM.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDINORI.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDINMAR.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDINKAN.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDINHIN.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDINBEN.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDGEO.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDBULG.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDBLR.DLL
2012-04-20 13:01:18 ----A---- C:\Windows\system32\KBDBASH.DLL
2012-04-20 13:01:17 ----A---- C:\Windows\system32\spwizres.dll
2012-04-20 13:01:17 ----A---- C:\Windows\system32\pifmgr.dll
2012-04-20 13:01:17 ----A---- C:\Windows\system32\nlsbres.dll
2012-04-20 13:01:17 ----A---- C:\Windows\system32\KBDTUQ.DLL
2012-04-20 13:01:17 ----A---- C:\Windows\system32\KBDTUF.DLL
2012-04-20 13:01:17 ----A---- C:\Windows\system32\KBDSG.DLL
2012-04-20 13:01:17 ----A---- C:\Windows\system32\KBDPO.DLL
2012-04-20 13:01:17 ----A---- C:\Windows\system32\KBDGR1.DLL
2012-04-20 13:01:17 ----A---- C:\Windows\system32\KBDGKL.DLL
2012-04-20 13:01:17 ----A---- C:\Windows\system32\KBDCZ1.DLL
2012-04-20 13:01:17 ----A---- C:\Windows\system32\dpnaddr.dll
2012-04-20 13:01:17 ----A---- C:\Windows\system32\BlbEvents.dll
2012-04-20 13:01:06 ----A---- C:\Windows\system32\wdscore.dll
2012-04-20 13:00:44 ----A---- C:\Windows\system32\wbemcomn.dll
2012-04-20 12:27:08 ----D---- C:\_OTM
2012-04-20 08:14:18 ----D---- C:\rsit
2012-04-20 08:14:18 ----D---- C:\Program Files\trend micro
2012-04-19 11:49:42 ----SHD---- C:\Config.Msi
2012-04-11 19:11:09 ----A---- C:\Windows\system32\wmi.dll
2012-04-11 19:11:09 ----A---- C:\Windows\system32\wintrust.dll
2012-04-11 19:11:09 ----A---- C:\Windows\system32\imagehlp.dll
2012-04-11 19:11:09 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-04-11 19:10:19 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-04-11 19:10:18 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-04-07 16:06:06 ----D---- C:\ProgramData\EA Core
2012-04-07 16:04:38 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-04-07 16:04:37 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-04-06 22:19:08 ----D---- C:\Program Files\Origin Games
2012-04-06 22:18:42 ----D---- C:\ProgramData\Origin
2012-04-06 22:14:22 ----D---- C:\Users\RT\AppData\Roaming\Origin
2012-04-06 22:14:22 ----D---- C:\ProgramData\Electronic Arts
2012-04-06 22:14:05 ----D---- C:\Program Files\Origin
2012-03-31 20:53:55 ----D---- C:\Users\RT\AppData\Roaming\Malwarebytes
2012-03-31 20:53:43 ----D---- C:\ProgramData\Malwarebytes
2012-03-29 10:55:06 ----D---- C:\Users\RT\AppData\Roaming\Spy Emergency
2012-03-29 10:55:02 ----A---- C:\Windows\system32\drivers\spyemrg_access.sys
2012-03-29 10:55:01 ----A---- C:\Windows\system32\drivers\spyemrg_guard.sys
2012-03-29 10:55:01 ----A---- C:\Windows\system32\drivers\spyemrg.sys
2012-03-29 10:54:59 ----D---- C:\ProgramData\NETGATE
2012-03-29 10:54:58 ----D---- C:\Program Files\NETGATE

======List of files/folders modified in the last 1 month======

2012-04-20 14:21:25 ----RSD---- C:\Windows\assembly
2012-04-20 14:20:11 ----D---- C:\Windows\Temp
2012-04-20 14:17:57 ----D---- C:\Windows\Microsoft.NET
2012-04-20 14:17:40 ----D---- C:\Windows\winsxs
2012-04-20 14:17:26 ----D---- C:\Windows\system32\config
2012-04-20 14:16:09 ----D---- C:\Windows\system32\migration
2012-04-20 14:16:09 ----D---- C:\Windows\System32
2012-04-20 14:16:09 ----D---- C:\Program Files\Internet Explorer
2012-04-20 14:15:01 ----D---- C:\Windows\system32\catroot
2012-04-20 14:15:00 ----D---- C:\Windows\system32\catroot2
2012-04-20 14:13:20 ----SHD---- C:\System Volume Information
2012-04-20 14:11:02 ----D---- C:\Windows\inf
2012-04-20 14:11:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-20 13:57:17 ----D---- C:\Windows\Logs
2012-04-20 13:57:10 ----D---- C:\Windows\servicing
2012-04-20 13:56:41 ----D---- C:\Windows\system32\sk-SK
2012-04-20 13:55:30 ----D---- C:\Windows\system32\en-US
2012-04-20 13:55:30 ----D---- C:\Windows\PolicyDefinitions
2012-04-20 13:52:56 ----D---- C:\Windows
2012-04-20 13:37:00 ----D---- C:\Windows\Prefetch
2012-04-20 13:36:30 ----SHD---- C:\Boot
2012-04-20 13:35:01 ----D---- C:\Windows\system32\DriverStore
2012-04-20 13:30:28 ----D---- C:\Program Files\Windows Sidebar
2012-04-20 13:30:28 ----D---- C:\Program Files\Windows Mail
2012-04-20 13:30:28 ----D---- C:\Program Files\DVD Maker
2012-04-20 13:30:27 ----D---- C:\Program Files\Windows Portable Devices
2012-04-20 13:30:27 ----D---- C:\Program Files\Windows Photo Viewer
2012-04-20 13:30:27 ----D---- C:\Program Files\Windows Media Player
2012-04-20 13:30:27 ----D---- C:\Program Files\Windows Journal
2012-04-20 13:30:26 ----D---- C:\Windows\ehome
2012-04-20 13:30:26 ----D---- C:\Program Files\Windows Defender
2012-04-20 13:30:26 ----D---- C:\Program Files\Common Files\System
2012-04-20 13:30:19 ----D---- C:\Windows\system32\da-DK
2012-04-20 13:30:18 ----D---- C:\Windows\system32\sysprep
2012-04-20 13:30:18 ----D---- C:\Windows\system32\oobe
2012-04-20 13:30:17 ----D---- C:\Windows\system32\wbem
2012-04-20 13:30:17 ----D---- C:\Windows\system32\sppui
2012-04-20 13:30:17 ----D---- C:\Windows\system32\Setup
2012-04-20 13:30:17 ----D---- C:\Windows\system32\manifeststore
2012-04-20 13:30:17 ----D---- C:\Windows\system32\es-ES
2012-04-20 13:30:17 ----D---- C:\Windows\system32\en
2012-04-20 13:30:17 ----D---- C:\Windows\system32\drivers\en-US
2012-04-20 13:30:17 ----D---- C:\Windows\system32\drivers
2012-04-20 13:30:17 ----D---- C:\Windows\system32\cs-CZ
2012-04-20 13:30:17 ----D---- C:\Windows\system32\AdvancedInstallers
2012-04-20 13:30:16 ----D---- C:\Windows\system32\migwiz
2012-04-20 13:30:16 ----D---- C:\Windows\system32\Dism
2012-04-20 13:30:02 ----RSD---- C:\Windows\Fonts
2012-04-20 13:30:01 ----D---- C:\Windows\AppPatch
2012-04-20 13:29:53 ----D---- C:\Windows\system32\Boot
2012-04-20 13:27:38 ----D---- C:\Windows\system32\wdi
2012-04-20 13:22:21 ----A---- C:\Windows\system32\msclmd.dll
2012-04-20 13:15:58 ----D---- C:\Windows\Panther
2012-04-20 12:27:26 ----RD---- C:\Program Files
2012-04-20 12:27:26 ----D---- C:\Windows\Tasks
2012-04-20 12:27:09 ----D---- C:\Windows\system32\drivers\etc
2012-04-19 20:07:52 ----D---- C:\Program Files\SpeedFan
2012-04-19 11:50:29 ----SHD---- C:\Windows\Installer
2012-04-14 12:06:25 ----D---- C:\video_output
2012-04-11 19:11:25 ----D---- C:\Windows\debug
2012-04-11 19:11:23 ----A---- C:\Windows\system32\MRT.exe
2012-04-09 17:56:27 ----D---- C:\Windows\SoftwareDistribution
2012-04-09 17:55:32 ----D---- C:\Windows\Minidump
2012-04-09 16:44:27 ----D---- C:\Users\RT\AppData\Roaming\Skype
2012-04-07 16:06:07 ----HD---- C:\ProgramData
2012-03-30 11:16:37 ----D---- C:\Windows\system32\Tasks
2012-03-30 11:14:18 ----D---- C:\Users\RT\AppData\Roaming\Macromedia
2012-03-30 09:58:50 ----D---- C:\Program Files\Opera
2012-03-29 11:02:18 ----SD---- C:\Users\RT\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2011-03-18 25240]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS [2011-12-19 21624]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 SpyEmrg;Spy Emergency Driver; C:\Windows\System32\Drivers\spyemrg.sys [2011-04-21 14168]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 HBtnKey;HP Hotkey Device; C:\Windows\system32\DRIVERS\cpqbttn.sys [2010-02-25 15544]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 15872]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-02 139776]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 84992]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-14 1068032]
R3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver; C:\Windows\System32\Drivers\spyemrg_guard.sys [2011-04-21 16216]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393728]
S3 DrvAgent32;DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [2012-01-31 23456]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SpyEmrgAccess;Spy Emergency OnAccess Driver; C:\Windows\System32\Drivers\spyemrg_access.sys [2011-04-21 20056]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 usbser;Sony Ericsson USB Serial Port; C:\Windows\system32\DRIVERS\usbser.sys [2010-11-20 27648]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-10-03 219752]
R2 SpyEmrgSrv;Spy Emergency Engine Service; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe [2011-09-12 2338000]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
S3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-01-08 1343400]

-----------------EOF-----------------

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: kontrola logu

#10 Příspěvek od Mc_Murphy »

No vidíš, že když chceš, že to jde. :|
Ještě dočistíme a po těchto instalacích Ti doporučím provést defragmentaci, chod PC by se měl ještě trošku zrychlit. ;)


:arrow: Spusť tedy OTM znovu a klikni na tlačítko [CleanUp!], čímž po sobě program uklidí.

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stáhni a spusť.
  • Klikni na Start a potvrď OK.
  • Program uklidí a může (nemusí) restartovat PC.
  • Po použití utilitu smaž.
:arrow: Pokud nemáš, stáhni CCleaner z tohoto odkazu.
  • Panel čistič
  • Vše nech jak je, jen dej Analyzovat a poté Spustit CCleaner.
  • Panel registry
  • Klikni na Hledej problémy.
  • Následně na Opravit problémy - zálohu registrů doporučuji udělat, oprav všechny problémy.
  • Postup opakuj, dokud nebude bez problémů - většinou cca 3x.
  • Panel nástroje
  • Zde můžeš odinstalovat nepotřebné programy.
Obrázek CCleaner doporučuji používat cca jednou za týden.

:arrow: Po všech krocích, postupně provedených, se vrhni na tu defragmentaci. Může trvat déle - záleží na velikosti a obsazení jednotlivých disků. Nepoužívej standardní windowsovskou defragmentaci, ale doporučím Ti raději tento šikovný prográmek Defraggler. Je od stejné firmy, jako populární CCleaner, sám ho používám a jsem s ním maximálně spokojen.

... a pokud nejsou žádné dotazy, bylo by to z mé strany vše. :worship:
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

Odpovědět