
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Vir sa dostal do PC aj po preinstalacii
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 107
- Registrován: 13 led 2012 16:53
Vir sa dostal do PC aj po preinstalacii
Dobry den,
minuly tyden mi admin Rudy psal, ze asi mam v pc rootkit, ale nic so nenaslo... Nemal som cas na odinstalovanie kasperskym, tak som si racej preinstaloval PC(Mam 1 disk, ktory je rozdeleni na 2 casti, C a D.. C bolo sformatovane, ale na Dcku mam surne informacie). Virus zrejme sa do PC dostal z druheho diska(D) alebo to urobil LightShot.... Ak si dobre pametam , ComboFix vymazaval nieco z LightShotu(ja som si ho znova nainstaloval, ten program pouzivam furt)... Virus sa momentalne prejavuje u driverov... Vsetky USB Kluce(myska, usb debugging u androidech jde) nezobrazi, resp. pocujem zvucku pridania, ael nic neukaze, ani to ze je pripojeni dole(pre odstranenie hardweru), ani u diskov... Dalej sa pohrava este zo OpenGL drivermi... RSIT logy:
log.txt:
Logfile of random's system information tool 1.09 (written by random/random)
Run by GAMELASTER at 2012-09-26 21:08:06
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 20 GB (48%) free of 41 GB
Total RAM: 1789 MB (56% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2c4
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
"C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\3.0.0.0\LightShot.exe" Flags: uninsdeletevalue
"C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe"
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1324871451-212935027-3657544241-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1324871451-212935027-3657544241-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\GAMELASTER\Desktop\RSITx64.exe"
"C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\update-S-1-5-21-1324871451-212935027-3657544241-1000.job
C:\Windows\tasks\update-sys.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-23 537576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-23 193512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{876d9f09-c6d6-4324-a2cc-04dd9a4de12f}]
Microsoft Web Test Recorder 10.0 Helper - D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26 74888]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-09-10 17984688]
"DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [2012-04-26 3111744]
"Sidebar"=C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21 1174016]
"Sony PC Companion"=C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2012-05-31 445624]
"LightShot"=C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe [2012-02-02 220160]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-08-04 98304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-09-26 21:08:06 ----D---- C:\rsit
2012-09-26 21:08:06 ----D---- C:\Program Files\trend micro
2012-09-26 21:02:40 ----D---- C:\Windows\SYSWOW64\Wat
2012-09-26 21:02:40 ----D---- C:\Windows\system32\Wat
2012-09-24 18:08:36 ----D---- C:\Program Files (x86)\Skillbrains
2012-09-24 17:57:59 ----D---- C:\Users\GAMELASTER\AppData\Roaming\ATI
2012-09-24 17:57:59 ----D---- C:\ProgramData\ATI
2012-09-24 17:55:54 ----D---- C:\Windows\Minidump
2012-09-24 17:21:50 ----D---- C:\Program Files (x86)\ATI Technologies
2012-09-24 17:21:30 ----D---- C:\Program Files\ATI Technologies
2012-09-24 17:21:28 ----D---- C:\Program Files\ATI
2012-09-24 17:20:58 ----D---- C:\SwSetup
2012-09-23 23:42:09 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-09-23 23:39:04 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2012-09-23 23:38:58 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-09-23 23:37:04 ----D---- C:\Program Files\Application Verifier
2012-09-23 23:37:04 ----D---- C:\Program Files (x86)\Application Verifier
2012-09-23 23:36:57 ----D---- C:\ProgramData\Windows App Certification Kit
2012-09-23 23:35:12 ----D---- C:\ProgramData\PreEmptive Solutions
2012-09-23 23:30:32 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2012-09-23 23:30:06 ----D---- C:\Program Files (x86)\Microsoft Web Tools
2012-09-23 23:29:41 ----D---- C:\Program Files\Microsoft
2012-09-23 23:29:07 ----D---- C:\Program Files\IIS Express
2012-09-23 23:29:07 ----D---- C:\Program Files (x86)\IIS Express
2012-09-23 23:28:02 ----D---- C:\Program Files (x86)\NuGet
2012-09-23 23:27:37 ----D---- C:\Program Files (x86)\Microsoft WCF Data Services
2012-09-23 23:27:27 ----D---- C:\Program Files\IIS
2012-09-23 23:27:27 ----D---- C:\Program Files (x86)\IIS
2012-09-23 23:25:06 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-09-23 23:23:56 ----D---- C:\Program Files (x86)\Windows Kits
2012-09-23 23:14:35 ----D---- C:\Program Files (x86)\HTML Help Workshop
2012-09-23 23:14:21 ----D---- C:\Program Files (x86)\Microsoft Help Viewer
2012-09-23 23:12:56 ----D---- C:\Windows\SYSWOW64\1033
2012-09-23 23:12:37 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2012-09-23 23:12:36 ----D---- C:\Program Files\Microsoft SQL Server
2012-09-23 23:06:52 ----D---- C:\Windows\system32\1033
2012-09-23 23:06:42 ----D---- C:\Windows\symbols
2012-09-23 23:06:41 ----D---- C:\Program Files\Microsoft Visual Studio 11.0
2012-09-23 23:06:41 ----D---- C:\Program Files (x86)\Microsoft SDKs
2012-09-23 22:54:26 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2012-09-23 22:51:52 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-09-23 22:45:37 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2012-09-23 22:43:27 ----D---- C:\ProgramData\Package Cache
2012-09-23 21:52:36 ----A---- C:\Windows\system32\npDeployJava1.dll
2012-09-23 21:52:36 ----A---- C:\Windows\system32\javaws.exe
2012-09-23 21:52:36 ----A---- C:\Windows\system32\deployJava1.dll
2012-09-23 21:52:04 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2012-09-23 21:52:04 ----A---- C:\Windows\system32\javaw.exe
2012-09-23 21:52:04 ----A---- C:\Windows\system32\java.exe
2012-09-23 21:48:54 ----D---- C:\Program Files\Java
2012-09-23 21:32:33 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-09-23 21:32:33 ----D---- C:\ProgramData\Sony
2012-09-23 21:32:33 ----D---- C:\Program Files (x86)\Sony
2012-09-23 21:27:13 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2012-09-23 21:26:58 ----D---- C:\Users\GAMELASTER\AppData\Roaming\DAEMON Tools Pro
2012-09-23 21:26:51 ----D---- C:\Program Files (x86)\DAEMON Tools Pro
2012-09-23 21:25:04 ----D---- C:\ProgramData\DAEMON Tools Pro
2012-09-23 21:19:13 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Macromedia
2012-09-23 21:19:12 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Adobe
2012-09-23 21:18:33 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-09-23 21:18:32 ----D---- C:\Windows\SYSWOW64\Macromed
2012-09-23 21:18:31 ----D---- C:\Windows\system32\Macromed
2012-09-23 21:15:34 ----D---- C:\Android
2012-09-23 21:14:39 ----D---- C:\Windows\Panther
2012-09-23 21:14:27 ----RASH---- C:\BOOTSECT.BAK
2012-09-23 21:14:24 ----SHD---- C:\Boot
2012-09-23 21:02:13 ----D---- C:\Users\GAMELASTER\AppData\Roaming\GameMaker-Studio
2012-09-23 20:55:14 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-09-23 20:55:13 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-09-23 20:54:14 ----D---- C:\Program Files (x86)\Winamp Detect
2012-09-23 20:54:02 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Winamp
2012-09-23 20:54:02 ----D---- C:\Program Files (x86)\Winamp
2012-09-23 20:52:41 ----D---- C:\Program Files (x86)\Notepad++
2012-09-23 20:52:15 ----D---- C:\Program Files (x86)\PuTTY
2012-09-23 20:50:54 ----D---- C:\Program Files (x86)\Altap Salamander
2012-09-23 20:46:00 ----D---- C:\Program Files (x86)\WinSCP
2012-09-23 20:41:38 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Skype
2012-09-23 20:41:31 ----RD---- C:\Program Files (x86)\Skype
2012-09-23 20:41:26 ----SHD---- C:\Windows\Installer
2012-09-23 20:41:22 ----D---- C:\ProgramData\Skype
2012-09-23 20:36:10 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Opera
2012-09-23 20:36:06 ----D---- C:\Program Files (x86)\Opera
2012-09-23 20:24:32 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Identities
2012-09-23 20:24:10 ----SD---- C:\Users\GAMELASTER\AppData\Roaming\Microsoft
2012-09-23 20:24:10 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Media Center Programs
2012-09-23 20:23:59 ----SHD---- C:\Recovery
2012-09-23 20:18:44 ----D---- C:\Windows\SoftwareDistribution
2012-09-23 20:16:29 ----D---- C:\Windows\Prefetch
2012-09-23 20:15:32 ----ASH---- C:\pagefile.sys
2012-09-23 20:15:30 ----SHD---- C:\System Volume Information
2012-09-23 20:15:30 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 month======
2012-09-26 21:08:07 ----D---- C:\Windows\Temp
2012-09-26 21:08:06 ----RD---- C:\Program Files
2012-09-26 21:05:48 ----D---- C:\Windows\System32
2012-09-26 21:05:48 ----D---- C:\Windows\inf
2012-09-26 21:05:48 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-09-26 21:02:53 ----D---- C:\Windows\SysWOW64
2012-09-26 21:02:53 ----A---- C:\Windows\SYSWOW64\slwga.dll
2012-09-26 21:02:53 ----A---- C:\Windows\system32\systemcpl.dll
2012-09-26 21:02:53 ----A---- C:\Windows\system32\slwga.dll
2012-09-26 21:02:51 ----A---- C:\Windows\SYSWOW64\user32.dll
2012-09-26 21:02:51 ----A---- C:\Windows\system32\user32.dll
2012-09-26 21:02:49 ----D---- C:\Windows
2012-09-26 21:02:48 ----D---- C:\Windows\winsxs
2012-09-26 21:02:38 ----D---- C:\Windows\system32\catroot
2012-09-26 21:01:57 ----SD---- C:\ProgramData\Microsoft
2012-09-26 21:01:56 ----D---- C:\Windows\system32\drivers
2012-09-26 21:01:54 ----D---- C:\Windows\system32\drivers\UMDF
2012-09-26 20:58:55 ----D---- C:\Windows\system32\config
2012-09-26 17:25:47 ----D---- C:\Windows\Logs
2012-09-25 21:16:12 ----D---- C:\Windows\Microsoft.NET
2012-09-25 21:16:07 ----RSD---- C:\Windows\assembly
2012-09-24 18:08:37 ----D---- C:\Windows\Tasks
2012-09-24 18:08:37 ----D---- C:\Windows\system32\Tasks
2012-09-24 18:08:36 ----RD---- C:\Program Files (x86)
2012-09-24 17:57:59 ----HD---- C:\ProgramData
2012-09-24 17:23:01 ----D---- C:\Windows\system32\DriverStore
2012-09-24 17:22:56 ----D---- C:\Windows\system32\catroot2
2012-09-24 15:55:50 ----D---- C:\Windows\system32\wdi
2012-09-23 23:38:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-09-23 23:35:45 ----D---- C:\Program Files (x86)\Common Files
2012-09-23 23:34:37 ----D---- C:\Program Files\MSBuild
2012-09-23 23:24:01 ----RSD---- C:\Windows\Fonts
2012-09-23 23:14:23 ----D---- C:\Program Files (x86)\MSBuild
2012-09-23 22:52:07 ----D---- C:\Windows\SYSWOW64\en-US
2012-09-23 22:52:06 ----D---- C:\Windows\system32\en-US
2012-09-23 20:54:49 ----D---- C:\Windows\system32\restore
2012-09-23 20:31:07 ----D---- C:\Windows\system32\CodeIntegrity
2012-09-23 20:24:28 ----SHD---- C:\$Recycle.Bin
2012-09-23 20:24:09 ----RD---- C:\Users
2012-09-23 20:23:59 ----D---- C:\Windows\system32\Recovery
2012-09-23 20:23:34 ----D---- C:\Windows\rescache
2012-09-23 20:23:18 ----D---- C:\Windows\debug
2012-09-23 20:19:24 ----D---- C:\Windows\system32\sysprep
2012-09-23 20:16:23 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-04 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-23 283200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-04 6037504]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-06-10 1311232]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 VSPerfDrv110;Performance Tools Driver 11.0; \??\D:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [2012-07-13 70264]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-04 203264]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-02-11 129624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-09-10 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-23 250288]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-09-26 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
-----------------EOF-----------------
info.txt(Myslim, ze aj toto pomoze):
info.txt logfile of random's system information tool 1.09 2012-09-26 21:08:10
======Uninstall list======
Tools for .Net 3.5-->MsiExec.exe /X{1690CE56-2231-4E59-9006-A0876D949EA8}
Adobe Flash Player 11 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_278_Plugin.exe -maintain plugin
Altap Salamander 2.54-->C:\Program Files (x86)\Altap Salamander\remove\remove.exe
Blend for Visual Studio 2012 ENU resources-->MsiExec.exe /I{532DBCC8-9468-435C-AEF6-30B7F50735A2}
Blend for Visual Studio 2012-->MsiExec.exe /I{57F20F04-014D-453F-B6A3-AE9485C4DFAB}
Catalyst Control Center - Branding-->MsiExec.exe /I{31D9C74D-CD7A-4215-B1E4-DF8099AEA997}
DAEMON Tools Pro-->C:\Program Files (x86)\DAEMON Tools Pro\uninst.exe
Dotfuscator and Analytics Community Edition-->MsiExec.exe /X{372D17F6-A54E-4A01-B264-1314890FFE61}
Entity Framework Designer for Visual Studio 2012 - enu-->MsiExec.exe /X{0A1A1D48-DB23-443A-BC7B-49255D138020}
IIS 8.0 Express-->MsiExec.exe /X{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}
IIS Express Application Compatibility Database for x64-->%windir%\system32\sdbinst.exe -u "C:\Windows\AppPatch\Custom\Custom64\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb"
IIS Express Application Compatibility Database for x86-->%windir%\system32\sdbinst.exe -u "C:\Windows\AppPatch\Custom\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb"
Java 7 Update 7 (64-bit)-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F86417007FF}
Java SE Development Kit 7 Update 7 (64-bit)-->MsiExec.exe /I{64A3A4F4-B792-11D6-A78A-00B0D0170070}
lightshot-3.0.0.0-->"C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\unins000.exe"
LocalESPC-->MsiExec.exe /I{BDBE5D2A-AAB7-77BD-7A0E-5006665CE7C6}
LocalESPCui for en-us-->MsiExec.exe /I{B5DA9D49-9BD8-0F2F-52FC-C7E66BC8D944}
Microsoft .NET Framework 4 Multi-Targeting Pack-->MsiExec.exe /I{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}
Microsoft .NET Framework 4.5 Multi-Targeting Pack-->MsiExec.exe /X{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}
Microsoft .NET Framework 4.5 SDK-->MsiExec.exe /X{1948E039-EC79-4591-951D-9867A8C14C90}
Microsoft .NET Framework 4.5-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\\Setup.exe /repair /x86 /x64
Microsoft .NET Framework 4.5-->MsiExec.exe /X{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}
Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update-->MsiExec.exe /X{2F6CE32A-018D-4656-895B-9E5E20D7740A}
Microsoft ASP.NET MVC 3-->MsiExec.exe /X{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}
Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools-->MsiExec.exe /X{59D87F40-6C4B-4F80-A42B-FAA0E6EAFAB6}
Microsoft ASP.NET MVC 4 Runtime-->MsiExec.exe /X{942CC691-5B98-42A3-8BC5-A246BA69D983}
Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools-->MsiExec.exe /X{6F066545-40A2-4C38-A8F7-78581CC5C442}
Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools-->MsiExec.exe /X{57D782D7-49FD-48DE-AB47-A690A1519A2D}
Microsoft ASP.NET Web Pages 2 Runtime-->MsiExec.exe /X{FBBC8076-BB21-4E06-9FA0-309AEF6E35EE}
Microsoft ASP.NET Web Pages-->MsiExec.exe /X{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}
Microsoft Help Viewer 2.0-->msiexec.exe /X{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}
Microsoft Help Viewer 2.0-->MsiExec.exe /X{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}
Microsoft LightSwitch for Visual Studio 2012 Core-->MsiExec.exe /I{7437A4B9-314F-3B8F-827B-22909146E471}
Microsoft LightSwitch for Visual Studio 2012 CoreRes - ENU-->MsiExec.exe /I{E4ADE757-7FE9-322D-9CAE-C77D77A2D2BF}
Microsoft NuGet - Visual Studio 2012-->MsiExec.exe /I{00EC8ABC-3C5A-40F8-A8CB-E7DCD5ABFA05}
Microsoft Portable Library Multi-Targeting Pack Language Pack - enu-->MsiExec.exe /X{BAD0254F-9BDB-3D14-A5AC-9C0EF51F3D09}
Microsoft Portable Library Multi-Targeting Pack-->MsiExec.exe /X{C4CAD994-6EA2-3121-8352-DA593150B322}
Microsoft Report Viewer Add-On for Visual Studio 2012-->MsiExec.exe /I{1DB43E5A-2F24-4F51-92B0-A2C0EBF5C742}
Microsoft Silverlight 4 SDK-->MsiExec.exe /X{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}
Microsoft Silverlight 5 SDK-->MsiExec.exe /X{E1FBB3D4-ADB0-4949-B101-855DA061C735}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2012 Command Line Utilities -->MsiExec.exe /I{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}
Microsoft SQL Server 2012 Data-Tier App Framework -->MsiExec.exe /I{36E619BC-A234-4EC3-849B-779A7C865A45}
Microsoft SQL Server 2012 Data-Tier App Framework -->MsiExec.exe /I{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}
Microsoft SQL Server 2012 Express LocalDB -->MsiExec.exe /I{13D558FE-A863-402C-B115-160007277033}
Microsoft SQL Server 2012 Management Objects (x64)-->MsiExec.exe /I{FA0A244E-F3C2-4589-B42A-3D522DE79A42}
Microsoft SQL Server 2012 Management Objects -->MsiExec.exe /I{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}
Microsoft SQL Server 2012 Native Client -->MsiExec.exe /I{49D665A2-4C2A-476E-9AB8-FCC425F526FC}
Microsoft SQL Server 2012 Transact-SQL Compiler Service -->MsiExec.exe /I{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}
Microsoft SQL Server 2012 Transact-SQL ScriptDom -->MsiExec.exe /I{0E8670B8-3965-4930-ADA6-570348B67153}
Microsoft SQL Server 2012 T-SQL Language Service -->MsiExec.exe /I{6D6D43E5-218C-4B05-92D3-2240810F4760}
Microsoft SQL Server Compact 4.0 SP1 x64 ENU-->MsiExec.exe /X{78909610-D229-459C-A936-25D92283D3FD}
Microsoft SQL Server Data Tools - enu (11.1.20627.00)-->MsiExec.exe /X{FA804794-2CCB-4301-954F-2C2894698876}
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00)-->MsiExec.exe /X{790E9425-8570-493F-9AE7-81AFC9E46930}
Microsoft SQL Server System CLR Types (x64)-->MsiExec.exe /I{4701DEDE-1888-49E0-BAE5-857875924CA2}
Microsoft SQL Server System CLR Types-->MsiExec.exe /I{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}
Microsoft System CLR Types for SQL Server 2012 (x64)-->MsiExec.exe /I{F1949145-EB64-4DE7-9D81-E6D27937146C}
Microsoft System CLR Types for SQL Server 2012-->MsiExec.exe /I{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2012 x64 Designtime - 11.0.50727-->MsiExec.exe /X{D9F3D00D-E946-3B3D-A4A6-93D5020DB9F7}
Microsoft Visual C++ 2012 Compilers - ENU Resources-->MsiExec.exe /X{A4366F69-CE22-4DB7-9C8C-46A5845AF997}
Microsoft Visual C++ 2012 Compilers-->MsiExec.exe /X{1F8E06E2-BA93-40DC-B183-E024CBD853A8}
Microsoft Visual C++ 2012 Core Libraries-->MsiExec.exe /X{AD1AEE2A-D9C0-3FAC-8D6B-B5E07B47257B}
Microsoft Visual C++ 2012 Extended Libraries-->MsiExec.exe /X{731C183B-86A0-3442-BE55-68A7C92581E9}
Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries-->MsiExec.exe /X{29F259D7-C517-3EED-84B4-237573CFD39C}
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727-->MsiExec.exe /X{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}
Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727-->MsiExec.exe /X{2B997E80-3BEC-3222-9114-98DBE1182B2E}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727-->MsiExec.exe /X{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}
Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727-->MsiExec.exe /X{1C163D33-33B3-33EB-A617-0D4D852BE8E1}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}
Microsoft Visual Studio 2010 Office Developer Tools (x64)-->MsiExec.exe /X{572E796D-C52B-3797-A685-2FB6F895D4BE}
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)-->C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)\install.exe
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)-->MsiExec.exe /X{24C3AEE0-4BCE-3190-8EE0-BBA0BF72CAC1}
Microsoft Visual Studio 2012 Devenv Resources-->MsiExec.exe /I{B1465D1D-6427-4CA1-AE29-8B699209E663}
Microsoft Visual Studio 2012 Devenv-->MsiExec.exe /I{330E5D98-20D2-4CA4-AE51-FCB8AA80F634}
Microsoft Visual Studio 2012 IntelliTrace Core amd64-->MsiExec.exe /I{6AAF4427-3039-4C8A-BE53-D6F01C21AD46}
Microsoft Visual Studio 2012 IntelliTrace Core x86-->MsiExec.exe /I{B3533B84-A8DF-4A7A-8E95-B15F08B26E96}
Microsoft Visual Studio 2012 IntelliTrace Front End x86-->MsiExec.exe /I{D971780F-A609-4F78-92AA-B56FBC3955B9}
Microsoft Visual Studio 2012 Performance Collection Tools - ENU-->MsiExec.exe /I{FE74AC04-F248-4641-B3A9-89C6AA4339CD}
Microsoft Visual Studio 2012 Performance Collection Tools-->MsiExec.exe /I{633AB014-DDE6-403E-A302-8920CC32C543}
Microsoft Visual Studio 2012 Preparation-->MsiExec.exe /I{246B0F46-F84E-4857-8C47-F2A86B598BC5}
Microsoft Visual Studio 2012 SharePoint Developer Tools ENU Language Pack-->MsiExec.exe /X{B9F35D86-242E-3FA4-B9F8-A982E0DF918D}
Microsoft Visual Studio 2012 SharePoint Developer Tools-->MsiExec.exe /X{A3A6D5EA-B6B5-3C05-BDA8-EAB99C09CDDC}
Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies-->MsiExec.exe /I{820C677A-41B2-48C3-8136-FEE35A052E73}
Microsoft Visual Studio 2012 Shell (Minimum) Resources-->MsiExec.exe /I{38FC6E9A-F719-431A-A83D-4C86D5FD6555}
Microsoft Visual Studio 2012 Shell (Minimum)-->MsiExec.exe /I{800F484E-9D69-492D-B656-7BAA32586142}
Microsoft Visual Studio 2012 Tools for SQL Server Compact 4.0 SP1 ENU-->MsiExec.exe /I{E818AE7C-244B-4A50-9C86-C0E4A8B69159}
Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU-->MsiExec.exe /I{68A48EF1-DF03-394F-AF40-1E4FE42BB8DD}
Microsoft Visual Studio Team Foundation Server 2012 Object Model-->MsiExec.exe /I{6F07A6C2-9068-3673-A120-DC10012468C6}
Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - ENU-->MsiExec.exe /I{55EFD1A6-ED8E-3A4C-9581-5E1A1FF244CD}
Microsoft Visual Studio Team Foundation Server 2012 Storyboarding-->MsiExec.exe /I{28D85F24-B685-3364-BB7C-284C88C2FFE5}
Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - ENU-->MsiExec.exe /I{1B9BBB23-65CB-3AEE-BFC6-633E7CA299FD}
Microsoft Visual Studio Team Foundation Server 2012 Team Explorer-->MsiExec.exe /I{6DAB46E3-D017-3E2B-85D8-F57A230384C0}
Microsoft Visual Studio Ultimate 2012-->"C:\ProgramData\Package Cache\{e238e1a0-7fbd-4146-a4ac-d48badcdf3ae}\vs_ultimate.exe" /uninstall
Microsoft Web Deploy 3.0-->MsiExec.exe /I{AA72C306-30BE-4BB1-9E42-59552BAD2CDF}
Microsoft Web Deploy dbSqlPackage Provider - enu-->MsiExec.exe /X{E4C33F5B-1B2F-466E-957E-B274F08151A0}
Microsoft Web Developer Tools - Visual Studio 2012-->MsiExec.exe /I{B96FCD4F-6EDD-4258-8A6D-0FCEA8445E3E}
Microsoft Web Platform Installer 4.0-->MsiExec.exe /X{E2B8249D-895C-4685-8C83-00F3B1A13028}
Notepad++-->C:\Program Files (x86)\Notepad++\uninstall.exe
Opera 12.02-->"C:\Program Files (x86)\Opera\Opera.exe" /uninstall
PreEmptive Analytics Visual Studio Components-->MsiExec.exe /X{2C76E3DA-BA76-4FAD-B1B1-72B46D639028}
Prerequisites for SSDT -->MsiExec.exe /I{9169C939-ED01-446A-BD0C-29873BAF4E48}
PuTTY version 0.62-->"C:\Program Files (x86)\PuTTY\unins000.exe"
Skype™ 5.11-->MsiExec.exe /X{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}
Sony PC Companion 2.10.094-->"C:\Program Files (x86)\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0409 -removeonly
Update for (KB2504637)-->C:\Windows\SysWOW64\msiexec.exe /package {CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE} /uninstall {815F0BC1-7E54-300C-9ACA-C9460FDF6F78} /qb+ REBOOTPROMPT=""
Visual Studio 2012 Prerequisites - ENU Language Pack-->MsiExec.exe /X{13417784-A359-3CDD-8DE1-B7108707D647}
Visual Studio 2012 Prerequisites-->MsiExec.exe /X{61862D7C-CDBC-48D5-8AE1-3B8BD1E23BC5}
Visual Studio Extensions for Windows Library for JavaScript-->MsiExec.exe /I{89B4532E-19CE-4FA9-9692-10BFD5A38532}
WCF Data Services 5.0 (for OData v3) Primary Components-->MsiExec.exe /I{0BCC836F-0B28-4090-B58A-64883BAA3B2F}
WCF Data Services Tools for Microsoft Visual Studio 2012-->MsiExec.exe /I{148878BD-A2A5-4CF1-A103-2BA632F41953}
WCF RIA Services V1.0 SP2-->MsiExec.exe /X{3A523AF9-D32F-4C85-8388-0335731F3405}
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows App Certification Kit Native Components-->MsiExec.exe /I{3FA063D7-EDC1-AFA8-54AF-0563C7DEE070}
Windows App Certification Kit x64-->MsiExec.exe /I{02213A81-CB13-7262-5ABE-1FFA2C75559F}
Windows Runtime Intellisense Content - en-us-->MsiExec.exe /I{C81452EB-CBCF-B8EB-3124-48C5B3D506B0}
Windows Software Development Kit DirectX x64 Remote-->MsiExec.exe /I{5FB4C443-6BD6-1514-2717-3827D65AE6FB}
Windows Software Development Kit DirectX x86 Remote-->MsiExec.exe /I{23176E97-26CB-C72A-19EB-BFB21AC1D15A}
Windows Software Development Kit for Windows Store Apps DirectX x64 Remote-->MsiExec.exe /I{27EF252D-800C-ED42-9904-459FE0046225}
Windows Software Development Kit for Windows Store Apps DirectX x86 Remote-->MsiExec.exe /I{42F61556-29ED-8122-F39E-6F04EA5FF279}
Windows Software Development Kit for Windows Store Apps-->MsiExec.exe /I{D11F66FF-82B3-DDB8-1146-525370552BE1}
Windows Software Development Kit-->MsiExec.exe /I{60D5EF2A-4E0C-2C30-38F6-59C26E134F4A}
WinSCP 5.0.9 RC-->"C:\Program Files (x86)\WinSCP\unins000.exe"
======System event log======
Computer Name: GAMELASTER-PC
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 548
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20120923204328.352892-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: GAMELASTER-PC
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 545
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20120923204325.603715-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: GAMELASTER-PC
Event Code: 19
Message: A corrected hardware error has occurred.
Reported by component: Processor Core
Error Source: Corrected Machine Check
Error Type: Unknown Error
Processor ID: 1
The details view of this entry contains further information.
Record Number: 541
Source Name: Microsoft-Windows-WHEA-Logger
Time Written: 20120923204318.723271-000
Event Type: Warning
User: NT AUTHORITY\LOCAL SERVICE
Computer Name: GAMELASTER-PC
Event Code: 19
Message: A corrected hardware error has occurred.
Reported by component: Processor Core
Error Source: Corrected Machine Check
Error Type: Cache Hierarchy Error
Processor ID: 1
The details view of this entry contains further information.
Record Number: 540
Source Name: Microsoft-Windows-WHEA-Logger
Time Written: 20120923204318.565261-000
Event Type: Warning
User: NT AUTHORITY\LOCAL SERVICE
Computer Name: GAMELASTER-PC
Event Code: 7011
Message: Počas čakania na odpoveď transakcie od služby ShellHWDetection bol dosiahnutý časový limit (30000 ms).
Record Number: 538
Source Name: Service Control Manager
Time Written: 20120923204316.990160-000
Event Type: Error
User:
=====Application event log=====
Computer Name: GAMELASTER-PC
Event Code: 4107
Message: Zlyhala extrakcia zoznamu koreňových certifikátov nezávislých vydavateľov z kabinetu automatickej aktualizácie v: <http://www.download.windowsupdate.com/m ... ootstl.cab> s chybou: Pri overovaní s aktuálnymi systémovými hodinami alebo časovou pečiatkou podpísaného súboru sa zistilo, že požadovaný certifikát je mimo dobu platnosti.
.
Record Number: 251
Source Name: Microsoft-Windows-CAPI2
Time Written: 20120923192719.916938-000
Event Type: Error
User:
Computer Name: GAMELASTER-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 224
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20120923182833.806523-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: GAMELASTER-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 222
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20120923182833.712923-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: GAMELASTER-PC
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 126
Source Name: Microsoft-Windows-Search
Time Written: 20120923182400.000000-000
Event Type: Warning
User:
Computer Name: GAMELASTER-PC
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 123
Source Name: Microsoft-Windows-WMI
Time Written: 20120923182326.000000-000
Event Type: Error
User:
=====Security event log=====
Computer Name: 37L4247F27-25
Event Code: 4735
Message: A security-enabled local group was changed.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247F27-25$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Changed Attributes:
SAM Account Name: -
SID History: -
Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181557.587306-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4731
Message: A security-enabled local group was created.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247F27-25$
Account Domain: WORKGROUP
Logon ID: 0x3e7
New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Attributes:
SAM Account Name: Backup Operators
SID History: -
Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181557.571706-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4902
Message: The Per-user audit policy table was created.
Number of Elements: 0
Policy ID: 0x3cbd5
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181557.025704-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 0
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x4
Process Name:
Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181553.827697-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4608
Message: Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181553.656096-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files (x86)\Windows Kits\8.0\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=17
"PROCESSOR_IDENTIFIER"=AMD64 Family 17 Model 3 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=0301
"windows_tracing_logfile"=C:\BVTBin\Tests\installpackage\csilogfile.log
"windows_tracing_flags"=3
"VS110COMNTOOLS"=D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\Tools\
-----------------EOF-----------------
minuly tyden mi admin Rudy psal, ze asi mam v pc rootkit, ale nic so nenaslo... Nemal som cas na odinstalovanie kasperskym, tak som si racej preinstaloval PC(Mam 1 disk, ktory je rozdeleni na 2 casti, C a D.. C bolo sformatovane, ale na Dcku mam surne informacie). Virus zrejme sa do PC dostal z druheho diska(D) alebo to urobil LightShot.... Ak si dobre pametam , ComboFix vymazaval nieco z LightShotu(ja som si ho znova nainstaloval, ten program pouzivam furt)... Virus sa momentalne prejavuje u driverov... Vsetky USB Kluce(myska, usb debugging u androidech jde) nezobrazi, resp. pocujem zvucku pridania, ael nic neukaze, ani to ze je pripojeni dole(pre odstranenie hardweru), ani u diskov... Dalej sa pohrava este zo OpenGL drivermi... RSIT logy:
log.txt:
Logfile of random's system information tool 1.09 (written by random/random)
Run by GAMELASTER at 2012-09-26 21:08:06
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 20 GB (48%) free of 41 GB
Total RAM: 1789 MB (56% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2c4
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
"C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\3.0.0.0\LightShot.exe" Flags: uninsdeletevalue
"C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe"
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1324871451-212935027-3657544241-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1324871451-212935027-3657544241-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\GAMELASTER\Desktop\RSITx64.exe"
"C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\update-S-1-5-21-1324871451-212935027-3657544241-1000.job
C:\Windows\tasks\update-sys.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-23 537576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-23 193512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{876d9f09-c6d6-4324-a2cc-04dd9a4de12f}]
Microsoft Web Test Recorder 10.0 Helper - D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26 74888]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-09-10 17984688]
"DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [2012-04-26 3111744]
"Sidebar"=C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21 1174016]
"Sony PC Companion"=C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2012-05-31 445624]
"LightShot"=C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe [2012-02-02 220160]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-08-04 98304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-09-26 21:08:06 ----D---- C:\rsit
2012-09-26 21:08:06 ----D---- C:\Program Files\trend micro
2012-09-26 21:02:40 ----D---- C:\Windows\SYSWOW64\Wat
2012-09-26 21:02:40 ----D---- C:\Windows\system32\Wat
2012-09-24 18:08:36 ----D---- C:\Program Files (x86)\Skillbrains
2012-09-24 17:57:59 ----D---- C:\Users\GAMELASTER\AppData\Roaming\ATI
2012-09-24 17:57:59 ----D---- C:\ProgramData\ATI
2012-09-24 17:55:54 ----D---- C:\Windows\Minidump
2012-09-24 17:21:50 ----D---- C:\Program Files (x86)\ATI Technologies
2012-09-24 17:21:30 ----D---- C:\Program Files\ATI Technologies
2012-09-24 17:21:28 ----D---- C:\Program Files\ATI
2012-09-24 17:20:58 ----D---- C:\SwSetup
2012-09-23 23:42:09 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-09-23 23:39:04 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2012-09-23 23:38:58 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-09-23 23:37:04 ----D---- C:\Program Files\Application Verifier
2012-09-23 23:37:04 ----D---- C:\Program Files (x86)\Application Verifier
2012-09-23 23:36:57 ----D---- C:\ProgramData\Windows App Certification Kit
2012-09-23 23:35:12 ----D---- C:\ProgramData\PreEmptive Solutions
2012-09-23 23:30:32 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2012-09-23 23:30:06 ----D---- C:\Program Files (x86)\Microsoft Web Tools
2012-09-23 23:29:41 ----D---- C:\Program Files\Microsoft
2012-09-23 23:29:07 ----D---- C:\Program Files\IIS Express
2012-09-23 23:29:07 ----D---- C:\Program Files (x86)\IIS Express
2012-09-23 23:28:02 ----D---- C:\Program Files (x86)\NuGet
2012-09-23 23:27:37 ----D---- C:\Program Files (x86)\Microsoft WCF Data Services
2012-09-23 23:27:27 ----D---- C:\Program Files\IIS
2012-09-23 23:27:27 ----D---- C:\Program Files (x86)\IIS
2012-09-23 23:25:06 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-09-23 23:23:56 ----D---- C:\Program Files (x86)\Windows Kits
2012-09-23 23:14:35 ----D---- C:\Program Files (x86)\HTML Help Workshop
2012-09-23 23:14:21 ----D---- C:\Program Files (x86)\Microsoft Help Viewer
2012-09-23 23:12:56 ----D---- C:\Windows\SYSWOW64\1033
2012-09-23 23:12:37 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2012-09-23 23:12:36 ----D---- C:\Program Files\Microsoft SQL Server
2012-09-23 23:06:52 ----D---- C:\Windows\system32\1033
2012-09-23 23:06:42 ----D---- C:\Windows\symbols
2012-09-23 23:06:41 ----D---- C:\Program Files\Microsoft Visual Studio 11.0
2012-09-23 23:06:41 ----D---- C:\Program Files (x86)\Microsoft SDKs
2012-09-23 22:54:26 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2012-09-23 22:51:52 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-09-23 22:45:37 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2012-09-23 22:43:27 ----D---- C:\ProgramData\Package Cache
2012-09-23 21:52:36 ----A---- C:\Windows\system32\npDeployJava1.dll
2012-09-23 21:52:36 ----A---- C:\Windows\system32\javaws.exe
2012-09-23 21:52:36 ----A---- C:\Windows\system32\deployJava1.dll
2012-09-23 21:52:04 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2012-09-23 21:52:04 ----A---- C:\Windows\system32\javaw.exe
2012-09-23 21:52:04 ----A---- C:\Windows\system32\java.exe
2012-09-23 21:48:54 ----D---- C:\Program Files\Java
2012-09-23 21:32:33 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-09-23 21:32:33 ----D---- C:\ProgramData\Sony
2012-09-23 21:32:33 ----D---- C:\Program Files (x86)\Sony
2012-09-23 21:27:13 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2012-09-23 21:26:58 ----D---- C:\Users\GAMELASTER\AppData\Roaming\DAEMON Tools Pro
2012-09-23 21:26:51 ----D---- C:\Program Files (x86)\DAEMON Tools Pro
2012-09-23 21:25:04 ----D---- C:\ProgramData\DAEMON Tools Pro
2012-09-23 21:19:13 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Macromedia
2012-09-23 21:19:12 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Adobe
2012-09-23 21:18:33 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-09-23 21:18:32 ----D---- C:\Windows\SYSWOW64\Macromed
2012-09-23 21:18:31 ----D---- C:\Windows\system32\Macromed
2012-09-23 21:15:34 ----D---- C:\Android
2012-09-23 21:14:39 ----D---- C:\Windows\Panther
2012-09-23 21:14:27 ----RASH---- C:\BOOTSECT.BAK
2012-09-23 21:14:24 ----SHD---- C:\Boot
2012-09-23 21:02:13 ----D---- C:\Users\GAMELASTER\AppData\Roaming\GameMaker-Studio
2012-09-23 20:55:14 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-09-23 20:55:13 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-09-23 20:54:14 ----D---- C:\Program Files (x86)\Winamp Detect
2012-09-23 20:54:02 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Winamp
2012-09-23 20:54:02 ----D---- C:\Program Files (x86)\Winamp
2012-09-23 20:52:41 ----D---- C:\Program Files (x86)\Notepad++
2012-09-23 20:52:15 ----D---- C:\Program Files (x86)\PuTTY
2012-09-23 20:50:54 ----D---- C:\Program Files (x86)\Altap Salamander
2012-09-23 20:46:00 ----D---- C:\Program Files (x86)\WinSCP
2012-09-23 20:41:38 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Skype
2012-09-23 20:41:31 ----RD---- C:\Program Files (x86)\Skype
2012-09-23 20:41:26 ----SHD---- C:\Windows\Installer
2012-09-23 20:41:22 ----D---- C:\ProgramData\Skype
2012-09-23 20:36:10 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Opera
2012-09-23 20:36:06 ----D---- C:\Program Files (x86)\Opera
2012-09-23 20:24:32 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Identities
2012-09-23 20:24:10 ----SD---- C:\Users\GAMELASTER\AppData\Roaming\Microsoft
2012-09-23 20:24:10 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Media Center Programs
2012-09-23 20:23:59 ----SHD---- C:\Recovery
2012-09-23 20:18:44 ----D---- C:\Windows\SoftwareDistribution
2012-09-23 20:16:29 ----D---- C:\Windows\Prefetch
2012-09-23 20:15:32 ----ASH---- C:\pagefile.sys
2012-09-23 20:15:30 ----SHD---- C:\System Volume Information
2012-09-23 20:15:30 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 month======
2012-09-26 21:08:07 ----D---- C:\Windows\Temp
2012-09-26 21:08:06 ----RD---- C:\Program Files
2012-09-26 21:05:48 ----D---- C:\Windows\System32
2012-09-26 21:05:48 ----D---- C:\Windows\inf
2012-09-26 21:05:48 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-09-26 21:02:53 ----D---- C:\Windows\SysWOW64
2012-09-26 21:02:53 ----A---- C:\Windows\SYSWOW64\slwga.dll
2012-09-26 21:02:53 ----A---- C:\Windows\system32\systemcpl.dll
2012-09-26 21:02:53 ----A---- C:\Windows\system32\slwga.dll
2012-09-26 21:02:51 ----A---- C:\Windows\SYSWOW64\user32.dll
2012-09-26 21:02:51 ----A---- C:\Windows\system32\user32.dll
2012-09-26 21:02:49 ----D---- C:\Windows
2012-09-26 21:02:48 ----D---- C:\Windows\winsxs
2012-09-26 21:02:38 ----D---- C:\Windows\system32\catroot
2012-09-26 21:01:57 ----SD---- C:\ProgramData\Microsoft
2012-09-26 21:01:56 ----D---- C:\Windows\system32\drivers
2012-09-26 21:01:54 ----D---- C:\Windows\system32\drivers\UMDF
2012-09-26 20:58:55 ----D---- C:\Windows\system32\config
2012-09-26 17:25:47 ----D---- C:\Windows\Logs
2012-09-25 21:16:12 ----D---- C:\Windows\Microsoft.NET
2012-09-25 21:16:07 ----RSD---- C:\Windows\assembly
2012-09-24 18:08:37 ----D---- C:\Windows\Tasks
2012-09-24 18:08:37 ----D---- C:\Windows\system32\Tasks
2012-09-24 18:08:36 ----RD---- C:\Program Files (x86)
2012-09-24 17:57:59 ----HD---- C:\ProgramData
2012-09-24 17:23:01 ----D---- C:\Windows\system32\DriverStore
2012-09-24 17:22:56 ----D---- C:\Windows\system32\catroot2
2012-09-24 15:55:50 ----D---- C:\Windows\system32\wdi
2012-09-23 23:38:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-09-23 23:35:45 ----D---- C:\Program Files (x86)\Common Files
2012-09-23 23:34:37 ----D---- C:\Program Files\MSBuild
2012-09-23 23:24:01 ----RSD---- C:\Windows\Fonts
2012-09-23 23:14:23 ----D---- C:\Program Files (x86)\MSBuild
2012-09-23 22:52:07 ----D---- C:\Windows\SYSWOW64\en-US
2012-09-23 22:52:06 ----D---- C:\Windows\system32\en-US
2012-09-23 20:54:49 ----D---- C:\Windows\system32\restore
2012-09-23 20:31:07 ----D---- C:\Windows\system32\CodeIntegrity
2012-09-23 20:24:28 ----SHD---- C:\$Recycle.Bin
2012-09-23 20:24:09 ----RD---- C:\Users
2012-09-23 20:23:59 ----D---- C:\Windows\system32\Recovery
2012-09-23 20:23:34 ----D---- C:\Windows\rescache
2012-09-23 20:23:18 ----D---- C:\Windows\debug
2012-09-23 20:19:24 ----D---- C:\Windows\system32\sysprep
2012-09-23 20:16:23 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-04 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-23 283200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-04 6037504]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-06-10 1311232]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 VSPerfDrv110;Performance Tools Driver 11.0; \??\D:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [2012-07-13 70264]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-04 203264]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-02-11 129624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-09-10 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-23 250288]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-09-26 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
-----------------EOF-----------------
info.txt(Myslim, ze aj toto pomoze):
info.txt logfile of random's system information tool 1.09 2012-09-26 21:08:10
======Uninstall list======
Tools for .Net 3.5-->MsiExec.exe /X{1690CE56-2231-4E59-9006-A0876D949EA8}
Adobe Flash Player 11 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_278_Plugin.exe -maintain plugin
Altap Salamander 2.54-->C:\Program Files (x86)\Altap Salamander\remove\remove.exe
Blend for Visual Studio 2012 ENU resources-->MsiExec.exe /I{532DBCC8-9468-435C-AEF6-30B7F50735A2}
Blend for Visual Studio 2012-->MsiExec.exe /I{57F20F04-014D-453F-B6A3-AE9485C4DFAB}
Catalyst Control Center - Branding-->MsiExec.exe /I{31D9C74D-CD7A-4215-B1E4-DF8099AEA997}
DAEMON Tools Pro-->C:\Program Files (x86)\DAEMON Tools Pro\uninst.exe
Dotfuscator and Analytics Community Edition-->MsiExec.exe /X{372D17F6-A54E-4A01-B264-1314890FFE61}
Entity Framework Designer for Visual Studio 2012 - enu-->MsiExec.exe /X{0A1A1D48-DB23-443A-BC7B-49255D138020}
IIS 8.0 Express-->MsiExec.exe /X{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}
IIS Express Application Compatibility Database for x64-->%windir%\system32\sdbinst.exe -u "C:\Windows\AppPatch\Custom\Custom64\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb"
IIS Express Application Compatibility Database for x86-->%windir%\system32\sdbinst.exe -u "C:\Windows\AppPatch\Custom\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb"
Java 7 Update 7 (64-bit)-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F86417007FF}
Java SE Development Kit 7 Update 7 (64-bit)-->MsiExec.exe /I{64A3A4F4-B792-11D6-A78A-00B0D0170070}
lightshot-3.0.0.0-->"C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\unins000.exe"
LocalESPC-->MsiExec.exe /I{BDBE5D2A-AAB7-77BD-7A0E-5006665CE7C6}
LocalESPCui for en-us-->MsiExec.exe /I{B5DA9D49-9BD8-0F2F-52FC-C7E66BC8D944}
Microsoft .NET Framework 4 Multi-Targeting Pack-->MsiExec.exe /I{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}
Microsoft .NET Framework 4.5 Multi-Targeting Pack-->MsiExec.exe /X{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}
Microsoft .NET Framework 4.5 SDK-->MsiExec.exe /X{1948E039-EC79-4591-951D-9867A8C14C90}
Microsoft .NET Framework 4.5-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\\Setup.exe /repair /x86 /x64
Microsoft .NET Framework 4.5-->MsiExec.exe /X{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}
Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update-->MsiExec.exe /X{2F6CE32A-018D-4656-895B-9E5E20D7740A}
Microsoft ASP.NET MVC 3-->MsiExec.exe /X{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}
Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools-->MsiExec.exe /X{59D87F40-6C4B-4F80-A42B-FAA0E6EAFAB6}
Microsoft ASP.NET MVC 4 Runtime-->MsiExec.exe /X{942CC691-5B98-42A3-8BC5-A246BA69D983}
Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools-->MsiExec.exe /X{6F066545-40A2-4C38-A8F7-78581CC5C442}
Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools-->MsiExec.exe /X{57D782D7-49FD-48DE-AB47-A690A1519A2D}
Microsoft ASP.NET Web Pages 2 Runtime-->MsiExec.exe /X{FBBC8076-BB21-4E06-9FA0-309AEF6E35EE}
Microsoft ASP.NET Web Pages-->MsiExec.exe /X{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}
Microsoft Help Viewer 2.0-->msiexec.exe /X{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}
Microsoft Help Viewer 2.0-->MsiExec.exe /X{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}
Microsoft LightSwitch for Visual Studio 2012 Core-->MsiExec.exe /I{7437A4B9-314F-3B8F-827B-22909146E471}
Microsoft LightSwitch for Visual Studio 2012 CoreRes - ENU-->MsiExec.exe /I{E4ADE757-7FE9-322D-9CAE-C77D77A2D2BF}
Microsoft NuGet - Visual Studio 2012-->MsiExec.exe /I{00EC8ABC-3C5A-40F8-A8CB-E7DCD5ABFA05}
Microsoft Portable Library Multi-Targeting Pack Language Pack - enu-->MsiExec.exe /X{BAD0254F-9BDB-3D14-A5AC-9C0EF51F3D09}
Microsoft Portable Library Multi-Targeting Pack-->MsiExec.exe /X{C4CAD994-6EA2-3121-8352-DA593150B322}
Microsoft Report Viewer Add-On for Visual Studio 2012-->MsiExec.exe /I{1DB43E5A-2F24-4F51-92B0-A2C0EBF5C742}
Microsoft Silverlight 4 SDK-->MsiExec.exe /X{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}
Microsoft Silverlight 5 SDK-->MsiExec.exe /X{E1FBB3D4-ADB0-4949-B101-855DA061C735}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2012 Command Line Utilities -->MsiExec.exe /I{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}
Microsoft SQL Server 2012 Data-Tier App Framework -->MsiExec.exe /I{36E619BC-A234-4EC3-849B-779A7C865A45}
Microsoft SQL Server 2012 Data-Tier App Framework -->MsiExec.exe /I{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}
Microsoft SQL Server 2012 Express LocalDB -->MsiExec.exe /I{13D558FE-A863-402C-B115-160007277033}
Microsoft SQL Server 2012 Management Objects (x64)-->MsiExec.exe /I{FA0A244E-F3C2-4589-B42A-3D522DE79A42}
Microsoft SQL Server 2012 Management Objects -->MsiExec.exe /I{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}
Microsoft SQL Server 2012 Native Client -->MsiExec.exe /I{49D665A2-4C2A-476E-9AB8-FCC425F526FC}
Microsoft SQL Server 2012 Transact-SQL Compiler Service -->MsiExec.exe /I{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}
Microsoft SQL Server 2012 Transact-SQL ScriptDom -->MsiExec.exe /I{0E8670B8-3965-4930-ADA6-570348B67153}
Microsoft SQL Server 2012 T-SQL Language Service -->MsiExec.exe /I{6D6D43E5-218C-4B05-92D3-2240810F4760}
Microsoft SQL Server Compact 4.0 SP1 x64 ENU-->MsiExec.exe /X{78909610-D229-459C-A936-25D92283D3FD}
Microsoft SQL Server Data Tools - enu (11.1.20627.00)-->MsiExec.exe /X{FA804794-2CCB-4301-954F-2C2894698876}
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00)-->MsiExec.exe /X{790E9425-8570-493F-9AE7-81AFC9E46930}
Microsoft SQL Server System CLR Types (x64)-->MsiExec.exe /I{4701DEDE-1888-49E0-BAE5-857875924CA2}
Microsoft SQL Server System CLR Types-->MsiExec.exe /I{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}
Microsoft System CLR Types for SQL Server 2012 (x64)-->MsiExec.exe /I{F1949145-EB64-4DE7-9D81-E6D27937146C}
Microsoft System CLR Types for SQL Server 2012-->MsiExec.exe /I{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2012 x64 Designtime - 11.0.50727-->MsiExec.exe /X{D9F3D00D-E946-3B3D-A4A6-93D5020DB9F7}
Microsoft Visual C++ 2012 Compilers - ENU Resources-->MsiExec.exe /X{A4366F69-CE22-4DB7-9C8C-46A5845AF997}
Microsoft Visual C++ 2012 Compilers-->MsiExec.exe /X{1F8E06E2-BA93-40DC-B183-E024CBD853A8}
Microsoft Visual C++ 2012 Core Libraries-->MsiExec.exe /X{AD1AEE2A-D9C0-3FAC-8D6B-B5E07B47257B}
Microsoft Visual C++ 2012 Extended Libraries-->MsiExec.exe /X{731C183B-86A0-3442-BE55-68A7C92581E9}
Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries-->MsiExec.exe /X{29F259D7-C517-3EED-84B4-237573CFD39C}
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727-->MsiExec.exe /X{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}
Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727-->MsiExec.exe /X{2B997E80-3BEC-3222-9114-98DBE1182B2E}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727-->MsiExec.exe /X{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}
Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727-->MsiExec.exe /X{1C163D33-33B3-33EB-A617-0D4D852BE8E1}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}
Microsoft Visual Studio 2010 Office Developer Tools (x64)-->MsiExec.exe /X{572E796D-C52B-3797-A685-2FB6F895D4BE}
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)-->C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)\install.exe
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)-->MsiExec.exe /X{24C3AEE0-4BCE-3190-8EE0-BBA0BF72CAC1}
Microsoft Visual Studio 2012 Devenv Resources-->MsiExec.exe /I{B1465D1D-6427-4CA1-AE29-8B699209E663}
Microsoft Visual Studio 2012 Devenv-->MsiExec.exe /I{330E5D98-20D2-4CA4-AE51-FCB8AA80F634}
Microsoft Visual Studio 2012 IntelliTrace Core amd64-->MsiExec.exe /I{6AAF4427-3039-4C8A-BE53-D6F01C21AD46}
Microsoft Visual Studio 2012 IntelliTrace Core x86-->MsiExec.exe /I{B3533B84-A8DF-4A7A-8E95-B15F08B26E96}
Microsoft Visual Studio 2012 IntelliTrace Front End x86-->MsiExec.exe /I{D971780F-A609-4F78-92AA-B56FBC3955B9}
Microsoft Visual Studio 2012 Performance Collection Tools - ENU-->MsiExec.exe /I{FE74AC04-F248-4641-B3A9-89C6AA4339CD}
Microsoft Visual Studio 2012 Performance Collection Tools-->MsiExec.exe /I{633AB014-DDE6-403E-A302-8920CC32C543}
Microsoft Visual Studio 2012 Preparation-->MsiExec.exe /I{246B0F46-F84E-4857-8C47-F2A86B598BC5}
Microsoft Visual Studio 2012 SharePoint Developer Tools ENU Language Pack-->MsiExec.exe /X{B9F35D86-242E-3FA4-B9F8-A982E0DF918D}
Microsoft Visual Studio 2012 SharePoint Developer Tools-->MsiExec.exe /X{A3A6D5EA-B6B5-3C05-BDA8-EAB99C09CDDC}
Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies-->MsiExec.exe /I{820C677A-41B2-48C3-8136-FEE35A052E73}
Microsoft Visual Studio 2012 Shell (Minimum) Resources-->MsiExec.exe /I{38FC6E9A-F719-431A-A83D-4C86D5FD6555}
Microsoft Visual Studio 2012 Shell (Minimum)-->MsiExec.exe /I{800F484E-9D69-492D-B656-7BAA32586142}
Microsoft Visual Studio 2012 Tools for SQL Server Compact 4.0 SP1 ENU-->MsiExec.exe /I{E818AE7C-244B-4A50-9C86-C0E4A8B69159}
Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU-->MsiExec.exe /I{68A48EF1-DF03-394F-AF40-1E4FE42BB8DD}
Microsoft Visual Studio Team Foundation Server 2012 Object Model-->MsiExec.exe /I{6F07A6C2-9068-3673-A120-DC10012468C6}
Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - ENU-->MsiExec.exe /I{55EFD1A6-ED8E-3A4C-9581-5E1A1FF244CD}
Microsoft Visual Studio Team Foundation Server 2012 Storyboarding-->MsiExec.exe /I{28D85F24-B685-3364-BB7C-284C88C2FFE5}
Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - ENU-->MsiExec.exe /I{1B9BBB23-65CB-3AEE-BFC6-633E7CA299FD}
Microsoft Visual Studio Team Foundation Server 2012 Team Explorer-->MsiExec.exe /I{6DAB46E3-D017-3E2B-85D8-F57A230384C0}
Microsoft Visual Studio Ultimate 2012-->"C:\ProgramData\Package Cache\{e238e1a0-7fbd-4146-a4ac-d48badcdf3ae}\vs_ultimate.exe" /uninstall
Microsoft Web Deploy 3.0-->MsiExec.exe /I{AA72C306-30BE-4BB1-9E42-59552BAD2CDF}
Microsoft Web Deploy dbSqlPackage Provider - enu-->MsiExec.exe /X{E4C33F5B-1B2F-466E-957E-B274F08151A0}
Microsoft Web Developer Tools - Visual Studio 2012-->MsiExec.exe /I{B96FCD4F-6EDD-4258-8A6D-0FCEA8445E3E}
Microsoft Web Platform Installer 4.0-->MsiExec.exe /X{E2B8249D-895C-4685-8C83-00F3B1A13028}
Notepad++-->C:\Program Files (x86)\Notepad++\uninstall.exe
Opera 12.02-->"C:\Program Files (x86)\Opera\Opera.exe" /uninstall
PreEmptive Analytics Visual Studio Components-->MsiExec.exe /X{2C76E3DA-BA76-4FAD-B1B1-72B46D639028}
Prerequisites for SSDT -->MsiExec.exe /I{9169C939-ED01-446A-BD0C-29873BAF4E48}
PuTTY version 0.62-->"C:\Program Files (x86)\PuTTY\unins000.exe"
Skype™ 5.11-->MsiExec.exe /X{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}
Sony PC Companion 2.10.094-->"C:\Program Files (x86)\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0409 -removeonly
Update for (KB2504637)-->C:\Windows\SysWOW64\msiexec.exe /package {CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE} /uninstall {815F0BC1-7E54-300C-9ACA-C9460FDF6F78} /qb+ REBOOTPROMPT=""
Visual Studio 2012 Prerequisites - ENU Language Pack-->MsiExec.exe /X{13417784-A359-3CDD-8DE1-B7108707D647}
Visual Studio 2012 Prerequisites-->MsiExec.exe /X{61862D7C-CDBC-48D5-8AE1-3B8BD1E23BC5}
Visual Studio Extensions for Windows Library for JavaScript-->MsiExec.exe /I{89B4532E-19CE-4FA9-9692-10BFD5A38532}
WCF Data Services 5.0 (for OData v3) Primary Components-->MsiExec.exe /I{0BCC836F-0B28-4090-B58A-64883BAA3B2F}
WCF Data Services Tools for Microsoft Visual Studio 2012-->MsiExec.exe /I{148878BD-A2A5-4CF1-A103-2BA632F41953}
WCF RIA Services V1.0 SP2-->MsiExec.exe /X{3A523AF9-D32F-4C85-8388-0335731F3405}
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows App Certification Kit Native Components-->MsiExec.exe /I{3FA063D7-EDC1-AFA8-54AF-0563C7DEE070}
Windows App Certification Kit x64-->MsiExec.exe /I{02213A81-CB13-7262-5ABE-1FFA2C75559F}
Windows Runtime Intellisense Content - en-us-->MsiExec.exe /I{C81452EB-CBCF-B8EB-3124-48C5B3D506B0}
Windows Software Development Kit DirectX x64 Remote-->MsiExec.exe /I{5FB4C443-6BD6-1514-2717-3827D65AE6FB}
Windows Software Development Kit DirectX x86 Remote-->MsiExec.exe /I{23176E97-26CB-C72A-19EB-BFB21AC1D15A}
Windows Software Development Kit for Windows Store Apps DirectX x64 Remote-->MsiExec.exe /I{27EF252D-800C-ED42-9904-459FE0046225}
Windows Software Development Kit for Windows Store Apps DirectX x86 Remote-->MsiExec.exe /I{42F61556-29ED-8122-F39E-6F04EA5FF279}
Windows Software Development Kit for Windows Store Apps-->MsiExec.exe /I{D11F66FF-82B3-DDB8-1146-525370552BE1}
Windows Software Development Kit-->MsiExec.exe /I{60D5EF2A-4E0C-2C30-38F6-59C26E134F4A}
WinSCP 5.0.9 RC-->"C:\Program Files (x86)\WinSCP\unins000.exe"
======System event log======
Computer Name: GAMELASTER-PC
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 548
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20120923204328.352892-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: GAMELASTER-PC
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 545
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20120923204325.603715-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: GAMELASTER-PC
Event Code: 19
Message: A corrected hardware error has occurred.
Reported by component: Processor Core
Error Source: Corrected Machine Check
Error Type: Unknown Error
Processor ID: 1
The details view of this entry contains further information.
Record Number: 541
Source Name: Microsoft-Windows-WHEA-Logger
Time Written: 20120923204318.723271-000
Event Type: Warning
User: NT AUTHORITY\LOCAL SERVICE
Computer Name: GAMELASTER-PC
Event Code: 19
Message: A corrected hardware error has occurred.
Reported by component: Processor Core
Error Source: Corrected Machine Check
Error Type: Cache Hierarchy Error
Processor ID: 1
The details view of this entry contains further information.
Record Number: 540
Source Name: Microsoft-Windows-WHEA-Logger
Time Written: 20120923204318.565261-000
Event Type: Warning
User: NT AUTHORITY\LOCAL SERVICE
Computer Name: GAMELASTER-PC
Event Code: 7011
Message: Počas čakania na odpoveď transakcie od služby ShellHWDetection bol dosiahnutý časový limit (30000 ms).
Record Number: 538
Source Name: Service Control Manager
Time Written: 20120923204316.990160-000
Event Type: Error
User:
=====Application event log=====
Computer Name: GAMELASTER-PC
Event Code: 4107
Message: Zlyhala extrakcia zoznamu koreňových certifikátov nezávislých vydavateľov z kabinetu automatickej aktualizácie v: <http://www.download.windowsupdate.com/m ... ootstl.cab> s chybou: Pri overovaní s aktuálnymi systémovými hodinami alebo časovou pečiatkou podpísaného súboru sa zistilo, že požadovaný certifikát je mimo dobu platnosti.
.
Record Number: 251
Source Name: Microsoft-Windows-CAPI2
Time Written: 20120923192719.916938-000
Event Type: Error
User:
Computer Name: GAMELASTER-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 224
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20120923182833.806523-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: GAMELASTER-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 222
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20120923182833.712923-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: GAMELASTER-PC
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 126
Source Name: Microsoft-Windows-Search
Time Written: 20120923182400.000000-000
Event Type: Warning
User:
Computer Name: GAMELASTER-PC
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 123
Source Name: Microsoft-Windows-WMI
Time Written: 20120923182326.000000-000
Event Type: Error
User:
=====Security event log=====
Computer Name: 37L4247F27-25
Event Code: 4735
Message: A security-enabled local group was changed.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247F27-25$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Changed Attributes:
SAM Account Name: -
SID History: -
Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181557.587306-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4731
Message: A security-enabled local group was created.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247F27-25$
Account Domain: WORKGROUP
Logon ID: 0x3e7
New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Attributes:
SAM Account Name: Backup Operators
SID History: -
Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181557.571706-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4902
Message: The Per-user audit policy table was created.
Number of Elements: 0
Policy ID: 0x3cbd5
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181557.025704-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 0
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x4
Process Name:
Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181553.827697-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4608
Message: Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120923181553.656096-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files (x86)\Windows Kits\8.0\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=17
"PROCESSOR_IDENTIFIER"=AMD64 Family 17 Model 3 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=0301
"windows_tracing_logfile"=C:\BVTBin\Tests\installpackage\csilogfile.log
"windows_tracing_flags"=3
"VS110COMNTOOLS"=D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\Tools\
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir sa dostal do PC aj po preinstalacii
Měl jste úplně smazat partition, pak ji znovu vytvořit a až potom formátovat. Dejte nový ComboFix.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 107
- Registrován: 13 led 2012 16:53
Re: Vir sa dostal do PC aj po preinstalacii
virus zas dela to iste(zas mi to zmazalo vsetky kolaciky)...
ComboFix:
ComboFix 12-09-26.04 - GAMELASTER . 09. 2012 21:50:16.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.421.1051.18.1789.578 [GMT 2:00]
Running from: c:\users\GAMELASTER\Documents\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue
c:\windows\SysWow64\d2d1debug1.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-08-26 to 2012-09-26 )))))))))))))))))))))))))))))))
.
.
2012-09-26 19:08 . 2012-09-26 19:08 -------- d-----w- C:\rsit
2012-09-26 19:08 . 2012-09-26 19:08 -------- d-----w- c:\program files\trend micro
2012-09-26 19:02 . 2012-09-26 19:02 -------- d-----w- c:\windows\SysWow64\Wat
2012-09-26 19:02 . 2012-09-26 19:02 -------- d-----w- c:\windows\system32\Wat
2012-09-24 16:08 . 2012-09-24 16:08 -------- d-----w- c:\program files (x86)\Skillbrains
2012-09-24 15:57 . 2012-09-24 15:57 -------- d-----w- c:\programdata\ATI
2012-09-24 15:21 . 2012-09-24 15:21 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-09-24 15:21 . 2012-09-24 15:23 -------- d-----w- c:\program files\ATI Technologies
2012-09-24 15:21 . 2012-09-24 15:21 -------- d-----w- c:\program files\ATI
2012-09-24 15:20 . 2012-09-24 15:20 -------- d-----w- C:\SwSetup
2012-09-23 21:52 . 2012-09-23 21:52 2549120 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2012-09-23 21:42 . 2012-09-23 21:43 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-09-23 21:39 . 2012-09-23 21:39 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-09-23 21:38 . 2012-09-23 21:39 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2012-09-23 21:37 . 2012-09-23 21:37 -------- d-----w- c:\program files\Application Verifier
2012-09-23 21:37 . 2012-09-23 21:37 -------- d-----w- c:\program files (x86)\Application Verifier
2012-09-23 21:36 . 2012-09-23 21:36 -------- d-----w- c:\programdata\Windows App Certification Kit
2012-09-23 21:35 . 2012-09-23 21:35 -------- d-----w- c:\program files (x86)\Common Files\Microsoft
2012-09-23 21:35 . 2012-09-23 21:35 -------- d-----w- c:\programdata\PreEmptive Solutions
2012-09-23 21:30 . 2012-09-23 21:32 -------- d-----w- c:\program files (x86)\Microsoft ASP.NET
2012-09-23 21:30 . 2012-09-23 21:30 -------- d-----w- c:\program files (x86)\Microsoft Web Tools
2012-09-23 21:29 . 2012-09-23 21:29 -------- d-----w- c:\program files\Microsoft
2012-09-23 21:29 . 2012-09-23 21:29 -------- d-----w- c:\program files\IIS Express
2012-09-23 21:29 . 2012-09-23 21:29 -------- d-----w- c:\program files (x86)\IIS Express
2012-09-23 21:28 . 2012-09-23 21:28 -------- d-----w- c:\program files (x86)\NuGet
2012-09-23 21:27 . 2012-09-23 21:27 -------- d-----w- c:\program files (x86)\Microsoft WCF Data Services
2012-09-23 21:27 . 2012-09-23 21:27 -------- d-----w- c:\program files\IIS
2012-09-23 21:27 . 2012-09-23 21:27 -------- d-----w- c:\program files (x86)\IIS
2012-09-23 21:25 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-09-23 21:23 . 2012-09-23 21:23 -------- d-----w- c:\program files (x86)\Windows Kits
2012-09-23 21:14 . 2012-09-23 21:14 -------- d-----w- c:\program files (x86)\HTML Help Workshop
2012-09-23 21:14 . 2012-09-23 21:14 -------- d-----w- c:\program files (x86)\Microsoft Help Viewer
2012-09-23 21:12 . 2012-09-23 21:19 -------- d-----w- c:\windows\SysWow64\1033
2012-09-23 21:12 . 2012-09-23 21:39 -------- d-----w- c:\program files (x86)\Microsoft SQL Server
2012-09-23 21:12 . 2012-09-23 21:39 -------- d-----w- c:\program files\Microsoft SQL Server
2012-09-23 21:07 . 2012-09-23 21:10 -------- d-----w- c:\program files (x86)\Common Files\Merge Modules
2012-09-23 21:06 . 2012-09-23 21:12 -------- d-----w- c:\windows\system32\1033
2012-09-23 21:06 . 2012-09-23 21:06 -------- d-----w- c:\windows\symbols
2012-09-23 21:06 . 2012-09-23 21:44 -------- d-----w- c:\program files (x86)\Microsoft SDKs
2012-09-23 21:06 . 2012-09-23 21:06 -------- d-----w- c:\program files\Microsoft Visual Studio 11.0
2012-09-23 20:51 . 2012-09-23 21:11 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-09-23 20:45 . 2012-09-23 20:45 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2012-09-23 20:43 . 2012-09-23 20:50 -------- d-----w- c:\programdata\Package Cache
2012-09-23 19:52 . 2012-09-23 19:51 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-23 19:52 . 2012-09-23 19:51 289768 ----a-w- c:\windows\system32\javaws.exe
2012-09-23 19:52 . 2012-09-23 19:51 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-23 19:52 . 2012-09-23 19:51 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-23 19:52 . 2012-09-23 19:51 189416 ----a-w- c:\windows\system32\javaw.exe
2012-09-23 19:52 . 2012-09-23 19:51 188904 ----a-w- c:\windows\system32\java.exe
2012-09-23 19:48 . 2012-09-23 19:51 -------- d-----w- c:\program files\Java
2012-09-23 19:32 . 2012-09-23 19:32 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2012-09-23 19:32 . 2012-09-23 19:32 -------- d-----w- c:\programdata\Sony
2012-09-23 19:32 . 2012-09-23 19:32 -------- d-----w- c:\program files (x86)\Sony
2012-09-23 19:27 . 2012-09-23 19:27 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-09-23 19:26 . 2012-09-23 19:27 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-09-23 19:25 . 2012-09-23 19:32 -------- d-----w- c:\programdata\DAEMON Tools Pro
2012-09-23 19:18 . 2012-09-23 19:18 73136 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-23 19:18 . 2012-09-23 19:18 696240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-23 19:18 . 2012-09-23 19:18 -------- d-----w- c:\windows\SysWow64\Macromed
2012-09-23 19:18 . 2012-09-23 19:18 -------- d-----w- c:\windows\system32\Macromed
2012-09-23 19:15 . 2012-09-23 19:15 -------- d-----w- C:\Android
2012-09-23 19:14 . 2012-09-23 18:24 -------- d-----w- c:\windows\Panther
2012-09-23 19:14 . 2012-09-23 19:14 -------- d-----w- C:\Boot
2012-09-23 18:55 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2012-09-23 18:55 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\SysWow64\d3dx9_31.dll
2012-09-23 18:54 . 2012-09-23 18:54 -------- d-----w- c:\program files (x86)\Winamp Detect
2012-09-23 18:54 . 2012-09-23 18:54 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2012-09-23 18:54 . 2012-09-23 18:55 -------- d-----w- c:\program files (x86)\Winamp
2012-09-23 18:52 . 2012-09-23 18:52 -------- d-----w- c:\program files (x86)\Notepad++
2012-09-23 18:52 . 2012-09-23 18:52 -------- d-----w- c:\program files (x86)\PuTTY
2012-09-23 18:50 . 2012-09-23 18:51 -------- d-----w- c:\program files (x86)\Altap Salamander
2012-09-23 18:46 . 2012-09-23 18:46 -------- d-----w- c:\program files (x86)\WinSCP
2012-09-23 18:41 . 2012-09-23 18:41 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-09-23 18:41 . 2012-09-23 18:41 -------- d-----r- c:\program files (x86)\Skype
2012-09-23 18:41 . 2012-09-24 15:24 -------- d-sh--w- c:\windows\Installer
2012-09-23 18:41 . 2012-09-23 18:41 -------- d-----w- c:\programdata\Skype
2012-09-23 18:36 . 2012-09-23 18:36 -------- d-----w- c:\program files (x86)\Opera
2012-09-23 18:24 . 2012-09-23 18:24 -------- d-----w- c:\users\GAMELASTER
2012-09-23 18:23 . 2012-09-23 18:23 -------- d-----w- C:\Recovery
2012-09-23 18:18 . 2012-09-23 18:18 0 ----a-w- c:\windows\ativpsrm.bin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-26 19:02 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2012-09-26 19:02 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2012-09-26 19:02 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2012-09-26 19:02 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2012-09-26 19:02 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2012-07-26 17:08 . 2012-07-26 17:08 862664 ----a-w- c:\windows\SysWow64\msvcr110.dll
2012-07-26 17:08 . 2012-07-26 17:08 837072 ----a-w- c:\windows\SysWow64\vcamp110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 82888 ----a-w- c:\windows\SysWow64\mfcm110u.dll
2012-07-26 17:08 . 2012-07-26 17:08 82888 ----a-w- c:\windows\SysWow64\mfcm110.dll
2012-07-26 17:08 . 2012-07-26 17:08 8234952 ----a-w- c:\windows\SysWow64\mfc110ud.dll
2012-07-26 17:08 . 2012-07-26 17:08 821200 ----a-w- c:\windows\SysWow64\msvcp110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 8164296 ----a-w- c:\windows\SysWow64\mfc110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 74704 ----a-w- c:\windows\SysWow64\mfc110fra.dll
2012-07-26 17:08 . 2012-07-26 17:08 74704 ----a-w- c:\windows\SysWow64\mfc110deu.dll
2012-07-26 17:08 . 2012-07-26 17:08 73680 ----a-w- c:\windows\SysWow64\mfc110esn.dll
2012-07-26 17:08 . 2012-07-26 17:08 729560 ----a-w- c:\windows\SysWow64\vccorlib110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 72656 ----a-w- c:\windows\SysWow64\mfc110ita.dll
2012-07-26 17:08 . 2012-07-26 17:08 70608 ----a-w- c:\windows\SysWow64\mfc110rus.dll
2012-07-26 17:08 . 2012-07-26 17:08 64976 ----a-w- c:\windows\SysWow64\mfc110enu.dll
2012-07-26 17:08 . 2012-07-26 17:08 53712 ----a-w- c:\windows\SysWow64\mfc110jpn.dll
2012-07-26 17:08 . 2012-07-26 17:08 534480 ----a-w- c:\windows\SysWow64\msvcp110.dll
2012-07-26 17:08 . 2012-07-26 17:08 53200 ----a-w- c:\windows\SysWow64\mfc110kor.dll
2012-07-26 17:08 . 2012-07-26 17:08 46032 ----a-w- c:\windows\SysWow64\mfc110cht.dll
2012-07-26 17:08 . 2012-07-26 17:08 46032 ----a-w- c:\windows\SysWow64\mfc110chs.dll
2012-07-26 17:08 . 2012-07-26 17:08 4446152 ----a-w- c:\windows\SysWow64\mfc110u.dll
2012-07-26 17:08 . 2012-07-26 17:08 4411848 ----a-w- c:\windows\SysWow64\mfc110.dll
2012-07-26 17:08 . 2012-07-26 17:08 320976 ----a-w- c:\windows\SysWow64\vcamp110.dll
2012-07-26 17:08 . 2012-07-26 17:08 263112 ----a-w- c:\windows\SysWow64\vsjitdebugger.exe
2012-07-26 17:08 . 2012-07-26 17:08 251864 ----a-w- c:\windows\SysWow64\vccorlib110.dll
2012-07-26 17:08 . 2012-07-26 17:08 2203632 ----a-w- c:\windows\SysWow64\VsGraphicsHelper.dll
2012-07-26 17:08 . 2012-07-26 17:08 216016 ----a-w- c:\windows\SysWow64\VSPerf110.dll
2012-07-26 17:08 . 2012-07-26 17:08 173016 ----a-w- c:\windows\SysWow64\VSCover110.dll
2012-07-26 17:08 . 2012-07-26 17:08 1678792 ----a-w- c:\windows\SysWow64\msvcr110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 153536 ----a-w- c:\windows\SysWow64\atl110.dll
2012-07-26 17:08 . 2012-07-26 17:08 144848 ----a-w- c:\windows\SysWow64\vcomp110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 115656 ----a-w- c:\windows\SysWow64\vcomp110.dll
2012-07-26 17:08 . 2012-07-26 17:08 111560 ----a-w- c:\windows\SysWow64\mfcm110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 110544 ----a-w- c:\windows\SysWow64\mfcm110ud.dll
2012-07-26 13:22 . 2012-07-26 13:22 997336 ----a-w- c:\windows\system32\vccorlib110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 90056 ----a-w- c:\windows\system32\mfcm110u.dll
2012-07-26 13:22 . 2012-07-26 13:22 90056 ----a-w- c:\windows\system32\mfcm110.dll
2012-07-26 13:22 . 2012-07-26 13:22 828872 ----a-w- c:\windows\system32\msvcr110.dll
2012-07-26 13:22 . 2012-07-26 13:22 74704 ----a-w- c:\windows\system32\mfc110fra.dll
2012-07-26 13:22 . 2012-07-26 13:22 74704 ----a-w- c:\windows\system32\mfc110deu.dll
2012-07-26 13:22 . 2012-07-26 13:22 73680 ----a-w- c:\windows\system32\mfc110esn.dll
2012-07-26 13:22 . 2012-07-26 13:22 72656 ----a-w- c:\windows\system32\mfc110ita.dll
2012-07-26 13:22 . 2012-07-26 13:22 70608 ----a-w- c:\windows\system32\mfc110rus.dll
2012-07-26 13:22 . 2012-07-26 13:22 661448 ----a-w- c:\windows\system32\msvcp110.dll
2012-07-26 13:22 . 2012-07-26 13:22 64976 ----a-w- c:\windows\system32\mfc110enu.dll
2012-07-26 13:22 . 2012-07-26 13:22 5606856 ----a-w- c:\windows\system32\mfc110u.dll
2012-07-26 13:22 . 2012-07-26 13:22 5579208 ----a-w- c:\windows\system32\mfc110.dll
2012-07-26 13:22 . 2012-07-26 13:22 53712 ----a-w- c:\windows\system32\mfc110jpn.dll
2012-07-26 13:22 . 2012-07-26 13:22 53200 ----a-w- c:\windows\system32\mfc110kor.dll
2012-07-26 13:22 . 2012-07-26 13:22 46032 ----a-w- c:\windows\system32\mfc110cht.dll
2012-07-26 13:22 . 2012-07-26 13:22 46032 ----a-w- c:\windows\system32\mfc110chs.dll
2012-07-26 13:22 . 2012-07-26 13:22 385480 ----a-w- c:\windows\system32\vcamp110.dll
2012-07-26 13:22 . 2012-07-26 13:22 354264 ----a-w- c:\windows\system32\vccorlib110.dll
2012-07-26 13:22 . 2012-07-26 13:22 292320 ----a-w- c:\windows\system32\vsjitdebugger.exe
2012-07-26 13:22 . 2012-07-26 13:22 248272 ----a-w- c:\windows\system32\VSPerf110.dll
2012-07-26 13:22 . 2012-07-26 13:22 1957328 ----a-w- c:\windows\system32\msvcr110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 187864 ----a-w- c:\windows\system32\VSCover110.dll
2012-07-26 13:22 . 2012-07-26 13:22 177096 ----a-w- c:\windows\system32\atl110.dll
2012-07-26 13:22 . 2012-07-26 13:22 153040 ----a-w- c:\windows\system32\vcomp110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 124360 ----a-w- c:\windows\system32\vcomp110.dll
2012-07-26 13:22 . 2012-07-26 13:22 120776 ----a-w- c:\windows\system32\mfcm110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 119760 ----a-w- c:\windows\system32\mfcm110ud.dll
2012-07-26 13:22 . 2012-07-26 13:22 1106384 ----a-w- c:\windows\system32\msvcp110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 10915784 ----a-w- c:\windows\system32\mfc110ud.dll
2012-07-26 13:22 . 2012-07-26 13:22 10843080 ----a-w- c:\windows\system32\mfc110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 1077688 ----a-w- c:\windows\system32\vcamp110d.dll
2012-07-25 18:32 . 2012-07-25 18:32 98792 ----a-w- c:\windows\SysWow64\vfrdvcompat.dll
2012-07-25 18:32 . 2012-07-25 18:32 164200 ----a-w- c:\windows\SysWow64\vrfcore.dll
2012-07-25 18:31 . 2012-07-25 18:31 87328 ----a-w- c:\windows\SysWow64\vfcompat.dll
2012-07-25 18:31 . 2012-07-25 18:31 81592 ----a-w- c:\windows\SysWow64\vfnet.dll
2012-07-25 18:31 . 2012-07-25 18:31 61384 ----a-w- c:\windows\SysWow64\vfnws.dll
2012-07-25 18:31 . 2012-07-25 18:31 52032 ----a-w- c:\windows\SysWow64\vfcuzz.dll
2012-07-25 18:31 . 2012-07-25 18:31 40136 ----a-w- c:\windows\SysWow64\vfntlmless.dll
2012-07-25 18:31 . 2012-07-25 18:31 367392 ----a-w- c:\windows\SysWow64\vfprintpthelper.dll
2012-07-25 18:31 . 2012-07-25 18:31 353328 ----a-w- c:\windows\SysWow64\vfbasics.dll
2012-07-25 18:31 . 2012-07-25 18:31 306592 ----a-w- c:\windows\SysWow64\vfprint.dll
2012-07-25 18:31 . 2012-07-25 18:31 242776 ----a-w- c:\windows\SysWow64\vfluapriv.dll
2012-07-25 18:31 . 2012-07-25 18:31 21448 ----a-w- c:\windows\SysWow64\cuzzapi.dll
2012-07-25 18:31 . 2012-07-25 18:31 173520 ----a-w- c:\windows\SysWow64\appverif.exe
2012-07-25 18:25 . 2012-07-25 18:25 59848 ----a-w- c:\windows\SysWow64\VSD3DRefDebug.dll
2012-07-25 18:25 . 2012-07-25 18:25 713672 ----a-w- c:\windows\SysWow64\d3d11_1sdklayers.dll
2012-07-25 18:25 . 2012-07-25 18:25 609224 ----a-w- c:\windows\SysWow64\d3d11ref.dll
2012-07-25 18:25 . 2012-07-25 18:25 590792 ----a-w- c:\windows\SysWow64\d3d11sdklayers.dll
2012-07-25 18:25 . 2012-07-25 18:25 461256 ----a-w- c:\windows\SysWow64\d3d10sdklayers.dll
2012-07-25 18:25 . 2012-07-25 18:25 383944 ----a-w- c:\windows\SysWow64\d3dref9.dll
2012-07-25 18:25 . 2012-07-25 18:25 365512 ----a-w- c:\windows\SysWow64\d3d10ref.dll
2012-07-25 18:25 . 2012-07-25 18:25 232904 ----a-w- c:\windows\SysWow64\dxcpl.exe
2012-07-25 18:25 . 2012-07-25 18:25 102344 ----a-w- c:\windows\SysWow64\dxgidebug.dll
2012-07-25 18:16 . 2012-07-25 18:16 90480 ----a-w- c:\windows\system32\vfcompat.dll
2012-07-25 18:16 . 2012-07-25 18:16 83248 ----a-w- c:\windows\system32\vfnws.dll
2012-07-25 18:16 . 2012-07-25 18:16 711320 ----a-w- c:\windows\system32\vfprintpthelper.dll
2012-07-25 18:16 . 2012-07-25 18:16 48976 ----a-w- c:\windows\system32\vfcuzz.dll
2012-07-25 18:16 . 2012-07-25 18:16 45336 ----a-w- c:\windows\system32\vfntlmless.dll
2012-07-25 18:16 . 2012-07-25 18:16 433376 ----a-w- c:\windows\system32\vfprint.dll
2012-07-25 18:16 . 2012-07-25 18:16 406848 ----a-w- c:\windows\system32\vfbasics.dll
2012-07-25 18:16 . 2012-07-25 18:16 281656 ----a-w- c:\windows\system32\vfluapriv.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-09-26 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2012-09-26 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-09-10 17984688]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-04-26 3111744]
"Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2010-11-21 1174016]
"Sony PC Companion"="c:\program files (x86)\Sony\Sony PC Companion\PCCompanion.exe" [2012-05-31 445624]
"LightShot"="c:\users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe" [2012-02-02 220160]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-04 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-09-10 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-23 250288]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 fussvc;Windows App Certification Kit Fast User Switching Utility Service;c:\program files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 VSPerfDrv110;Performance Tools Driver 11.0;d:\program files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [2012-07-13 70264]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-26 1255736]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-23 283200]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-04 203264]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-23 19:18]
.
2012-09-26 c:\windows\Tasks\update-S-1-5-21-1324871451-212935027-3657544241-1000.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2012-09-24 20:09]
.
2012-09-26 c:\windows\Tasks\update-sys.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2012-09-24 20:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe
c:\users\GAMELASTER\AppData\Local\Skillbrains\lightshot\3.0.0.0\LightShot.exe
c:\program files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
.
**************************************************************************
.
Completion time: 2012-09-26 22:03:03 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-26 20:03
.
Pre-Run: 20 537 643 008 bytes free
Post-Run: 20 469 673 984 bytes free
.
- - End Of File - - 0A3418A52B0D2598B1DF9FD624EE4D3D
P.S. Lightshot furt funguje
ComboFix:
ComboFix 12-09-26.04 - GAMELASTER . 09. 2012 21:50:16.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.421.1051.18.1789.578 [GMT 2:00]
Running from: c:\users\GAMELASTER\Documents\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue
c:\windows\SysWow64\d2d1debug1.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-08-26 to 2012-09-26 )))))))))))))))))))))))))))))))
.
.
2012-09-26 19:08 . 2012-09-26 19:08 -------- d-----w- C:\rsit
2012-09-26 19:08 . 2012-09-26 19:08 -------- d-----w- c:\program files\trend micro
2012-09-26 19:02 . 2012-09-26 19:02 -------- d-----w- c:\windows\SysWow64\Wat
2012-09-26 19:02 . 2012-09-26 19:02 -------- d-----w- c:\windows\system32\Wat
2012-09-24 16:08 . 2012-09-24 16:08 -------- d-----w- c:\program files (x86)\Skillbrains
2012-09-24 15:57 . 2012-09-24 15:57 -------- d-----w- c:\programdata\ATI
2012-09-24 15:21 . 2012-09-24 15:21 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-09-24 15:21 . 2012-09-24 15:23 -------- d-----w- c:\program files\ATI Technologies
2012-09-24 15:21 . 2012-09-24 15:21 -------- d-----w- c:\program files\ATI
2012-09-24 15:20 . 2012-09-24 15:20 -------- d-----w- C:\SwSetup
2012-09-23 21:52 . 2012-09-23 21:52 2549120 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2012-09-23 21:42 . 2012-09-23 21:43 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-09-23 21:39 . 2012-09-23 21:39 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-09-23 21:38 . 2012-09-23 21:39 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2012-09-23 21:37 . 2012-09-23 21:37 -------- d-----w- c:\program files\Application Verifier
2012-09-23 21:37 . 2012-09-23 21:37 -------- d-----w- c:\program files (x86)\Application Verifier
2012-09-23 21:36 . 2012-09-23 21:36 -------- d-----w- c:\programdata\Windows App Certification Kit
2012-09-23 21:35 . 2012-09-23 21:35 -------- d-----w- c:\program files (x86)\Common Files\Microsoft
2012-09-23 21:35 . 2012-09-23 21:35 -------- d-----w- c:\programdata\PreEmptive Solutions
2012-09-23 21:30 . 2012-09-23 21:32 -------- d-----w- c:\program files (x86)\Microsoft ASP.NET
2012-09-23 21:30 . 2012-09-23 21:30 -------- d-----w- c:\program files (x86)\Microsoft Web Tools
2012-09-23 21:29 . 2012-09-23 21:29 -------- d-----w- c:\program files\Microsoft
2012-09-23 21:29 . 2012-09-23 21:29 -------- d-----w- c:\program files\IIS Express
2012-09-23 21:29 . 2012-09-23 21:29 -------- d-----w- c:\program files (x86)\IIS Express
2012-09-23 21:28 . 2012-09-23 21:28 -------- d-----w- c:\program files (x86)\NuGet
2012-09-23 21:27 . 2012-09-23 21:27 -------- d-----w- c:\program files (x86)\Microsoft WCF Data Services
2012-09-23 21:27 . 2012-09-23 21:27 -------- d-----w- c:\program files\IIS
2012-09-23 21:27 . 2012-09-23 21:27 -------- d-----w- c:\program files (x86)\IIS
2012-09-23 21:25 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-09-23 21:23 . 2012-09-23 21:23 -------- d-----w- c:\program files (x86)\Windows Kits
2012-09-23 21:14 . 2012-09-23 21:14 -------- d-----w- c:\program files (x86)\HTML Help Workshop
2012-09-23 21:14 . 2012-09-23 21:14 -------- d-----w- c:\program files (x86)\Microsoft Help Viewer
2012-09-23 21:12 . 2012-09-23 21:19 -------- d-----w- c:\windows\SysWow64\1033
2012-09-23 21:12 . 2012-09-23 21:39 -------- d-----w- c:\program files (x86)\Microsoft SQL Server
2012-09-23 21:12 . 2012-09-23 21:39 -------- d-----w- c:\program files\Microsoft SQL Server
2012-09-23 21:07 . 2012-09-23 21:10 -------- d-----w- c:\program files (x86)\Common Files\Merge Modules
2012-09-23 21:06 . 2012-09-23 21:12 -------- d-----w- c:\windows\system32\1033
2012-09-23 21:06 . 2012-09-23 21:06 -------- d-----w- c:\windows\symbols
2012-09-23 21:06 . 2012-09-23 21:44 -------- d-----w- c:\program files (x86)\Microsoft SDKs
2012-09-23 21:06 . 2012-09-23 21:06 -------- d-----w- c:\program files\Microsoft Visual Studio 11.0
2012-09-23 20:51 . 2012-09-23 21:11 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-09-23 20:45 . 2012-09-23 20:45 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2012-09-23 20:43 . 2012-09-23 20:50 -------- d-----w- c:\programdata\Package Cache
2012-09-23 19:52 . 2012-09-23 19:51 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-23 19:52 . 2012-09-23 19:51 289768 ----a-w- c:\windows\system32\javaws.exe
2012-09-23 19:52 . 2012-09-23 19:51 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-23 19:52 . 2012-09-23 19:51 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-23 19:52 . 2012-09-23 19:51 189416 ----a-w- c:\windows\system32\javaw.exe
2012-09-23 19:52 . 2012-09-23 19:51 188904 ----a-w- c:\windows\system32\java.exe
2012-09-23 19:48 . 2012-09-23 19:51 -------- d-----w- c:\program files\Java
2012-09-23 19:32 . 2012-09-23 19:32 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2012-09-23 19:32 . 2012-09-23 19:32 -------- d-----w- c:\programdata\Sony
2012-09-23 19:32 . 2012-09-23 19:32 -------- d-----w- c:\program files (x86)\Sony
2012-09-23 19:27 . 2012-09-23 19:27 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-09-23 19:26 . 2012-09-23 19:27 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-09-23 19:25 . 2012-09-23 19:32 -------- d-----w- c:\programdata\DAEMON Tools Pro
2012-09-23 19:18 . 2012-09-23 19:18 73136 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-23 19:18 . 2012-09-23 19:18 696240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-23 19:18 . 2012-09-23 19:18 -------- d-----w- c:\windows\SysWow64\Macromed
2012-09-23 19:18 . 2012-09-23 19:18 -------- d-----w- c:\windows\system32\Macromed
2012-09-23 19:15 . 2012-09-23 19:15 -------- d-----w- C:\Android
2012-09-23 19:14 . 2012-09-23 18:24 -------- d-----w- c:\windows\Panther
2012-09-23 19:14 . 2012-09-23 19:14 -------- d-----w- C:\Boot
2012-09-23 18:55 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2012-09-23 18:55 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\SysWow64\d3dx9_31.dll
2012-09-23 18:54 . 2012-09-23 18:54 -------- d-----w- c:\program files (x86)\Winamp Detect
2012-09-23 18:54 . 2012-09-23 18:54 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2012-09-23 18:54 . 2012-09-23 18:55 -------- d-----w- c:\program files (x86)\Winamp
2012-09-23 18:52 . 2012-09-23 18:52 -------- d-----w- c:\program files (x86)\Notepad++
2012-09-23 18:52 . 2012-09-23 18:52 -------- d-----w- c:\program files (x86)\PuTTY
2012-09-23 18:50 . 2012-09-23 18:51 -------- d-----w- c:\program files (x86)\Altap Salamander
2012-09-23 18:46 . 2012-09-23 18:46 -------- d-----w- c:\program files (x86)\WinSCP
2012-09-23 18:41 . 2012-09-23 18:41 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-09-23 18:41 . 2012-09-23 18:41 -------- d-----r- c:\program files (x86)\Skype
2012-09-23 18:41 . 2012-09-24 15:24 -------- d-sh--w- c:\windows\Installer
2012-09-23 18:41 . 2012-09-23 18:41 -------- d-----w- c:\programdata\Skype
2012-09-23 18:36 . 2012-09-23 18:36 -------- d-----w- c:\program files (x86)\Opera
2012-09-23 18:24 . 2012-09-23 18:24 -------- d-----w- c:\users\GAMELASTER
2012-09-23 18:23 . 2012-09-23 18:23 -------- d-----w- C:\Recovery
2012-09-23 18:18 . 2012-09-23 18:18 0 ----a-w- c:\windows\ativpsrm.bin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-26 19:02 . 2010-11-21 03:24 14848 ----a-w- c:\windows\system32\slwga.dll
2012-09-26 19:02 . 2010-11-21 03:24 419840 ----a-w- c:\windows\system32\systemcpl.dll
2012-09-26 19:02 . 2010-11-21 03:23 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2012-09-26 19:02 . 2010-11-21 03:24 833024 ----a-w- c:\windows\SysWow64\user32.dll
2012-09-26 19:02 . 2010-11-21 03:24 1008640 ----a-w- c:\windows\system32\user32.dll
2012-07-26 17:08 . 2012-07-26 17:08 862664 ----a-w- c:\windows\SysWow64\msvcr110.dll
2012-07-26 17:08 . 2012-07-26 17:08 837072 ----a-w- c:\windows\SysWow64\vcamp110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 82888 ----a-w- c:\windows\SysWow64\mfcm110u.dll
2012-07-26 17:08 . 2012-07-26 17:08 82888 ----a-w- c:\windows\SysWow64\mfcm110.dll
2012-07-26 17:08 . 2012-07-26 17:08 8234952 ----a-w- c:\windows\SysWow64\mfc110ud.dll
2012-07-26 17:08 . 2012-07-26 17:08 821200 ----a-w- c:\windows\SysWow64\msvcp110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 8164296 ----a-w- c:\windows\SysWow64\mfc110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 74704 ----a-w- c:\windows\SysWow64\mfc110fra.dll
2012-07-26 17:08 . 2012-07-26 17:08 74704 ----a-w- c:\windows\SysWow64\mfc110deu.dll
2012-07-26 17:08 . 2012-07-26 17:08 73680 ----a-w- c:\windows\SysWow64\mfc110esn.dll
2012-07-26 17:08 . 2012-07-26 17:08 729560 ----a-w- c:\windows\SysWow64\vccorlib110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 72656 ----a-w- c:\windows\SysWow64\mfc110ita.dll
2012-07-26 17:08 . 2012-07-26 17:08 70608 ----a-w- c:\windows\SysWow64\mfc110rus.dll
2012-07-26 17:08 . 2012-07-26 17:08 64976 ----a-w- c:\windows\SysWow64\mfc110enu.dll
2012-07-26 17:08 . 2012-07-26 17:08 53712 ----a-w- c:\windows\SysWow64\mfc110jpn.dll
2012-07-26 17:08 . 2012-07-26 17:08 534480 ----a-w- c:\windows\SysWow64\msvcp110.dll
2012-07-26 17:08 . 2012-07-26 17:08 53200 ----a-w- c:\windows\SysWow64\mfc110kor.dll
2012-07-26 17:08 . 2012-07-26 17:08 46032 ----a-w- c:\windows\SysWow64\mfc110cht.dll
2012-07-26 17:08 . 2012-07-26 17:08 46032 ----a-w- c:\windows\SysWow64\mfc110chs.dll
2012-07-26 17:08 . 2012-07-26 17:08 4446152 ----a-w- c:\windows\SysWow64\mfc110u.dll
2012-07-26 17:08 . 2012-07-26 17:08 4411848 ----a-w- c:\windows\SysWow64\mfc110.dll
2012-07-26 17:08 . 2012-07-26 17:08 320976 ----a-w- c:\windows\SysWow64\vcamp110.dll
2012-07-26 17:08 . 2012-07-26 17:08 263112 ----a-w- c:\windows\SysWow64\vsjitdebugger.exe
2012-07-26 17:08 . 2012-07-26 17:08 251864 ----a-w- c:\windows\SysWow64\vccorlib110.dll
2012-07-26 17:08 . 2012-07-26 17:08 2203632 ----a-w- c:\windows\SysWow64\VsGraphicsHelper.dll
2012-07-26 17:08 . 2012-07-26 17:08 216016 ----a-w- c:\windows\SysWow64\VSPerf110.dll
2012-07-26 17:08 . 2012-07-26 17:08 173016 ----a-w- c:\windows\SysWow64\VSCover110.dll
2012-07-26 17:08 . 2012-07-26 17:08 1678792 ----a-w- c:\windows\SysWow64\msvcr110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 153536 ----a-w- c:\windows\SysWow64\atl110.dll
2012-07-26 17:08 . 2012-07-26 17:08 144848 ----a-w- c:\windows\SysWow64\vcomp110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 115656 ----a-w- c:\windows\SysWow64\vcomp110.dll
2012-07-26 17:08 . 2012-07-26 17:08 111560 ----a-w- c:\windows\SysWow64\mfcm110d.dll
2012-07-26 17:08 . 2012-07-26 17:08 110544 ----a-w- c:\windows\SysWow64\mfcm110ud.dll
2012-07-26 13:22 . 2012-07-26 13:22 997336 ----a-w- c:\windows\system32\vccorlib110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 90056 ----a-w- c:\windows\system32\mfcm110u.dll
2012-07-26 13:22 . 2012-07-26 13:22 90056 ----a-w- c:\windows\system32\mfcm110.dll
2012-07-26 13:22 . 2012-07-26 13:22 828872 ----a-w- c:\windows\system32\msvcr110.dll
2012-07-26 13:22 . 2012-07-26 13:22 74704 ----a-w- c:\windows\system32\mfc110fra.dll
2012-07-26 13:22 . 2012-07-26 13:22 74704 ----a-w- c:\windows\system32\mfc110deu.dll
2012-07-26 13:22 . 2012-07-26 13:22 73680 ----a-w- c:\windows\system32\mfc110esn.dll
2012-07-26 13:22 . 2012-07-26 13:22 72656 ----a-w- c:\windows\system32\mfc110ita.dll
2012-07-26 13:22 . 2012-07-26 13:22 70608 ----a-w- c:\windows\system32\mfc110rus.dll
2012-07-26 13:22 . 2012-07-26 13:22 661448 ----a-w- c:\windows\system32\msvcp110.dll
2012-07-26 13:22 . 2012-07-26 13:22 64976 ----a-w- c:\windows\system32\mfc110enu.dll
2012-07-26 13:22 . 2012-07-26 13:22 5606856 ----a-w- c:\windows\system32\mfc110u.dll
2012-07-26 13:22 . 2012-07-26 13:22 5579208 ----a-w- c:\windows\system32\mfc110.dll
2012-07-26 13:22 . 2012-07-26 13:22 53712 ----a-w- c:\windows\system32\mfc110jpn.dll
2012-07-26 13:22 . 2012-07-26 13:22 53200 ----a-w- c:\windows\system32\mfc110kor.dll
2012-07-26 13:22 . 2012-07-26 13:22 46032 ----a-w- c:\windows\system32\mfc110cht.dll
2012-07-26 13:22 . 2012-07-26 13:22 46032 ----a-w- c:\windows\system32\mfc110chs.dll
2012-07-26 13:22 . 2012-07-26 13:22 385480 ----a-w- c:\windows\system32\vcamp110.dll
2012-07-26 13:22 . 2012-07-26 13:22 354264 ----a-w- c:\windows\system32\vccorlib110.dll
2012-07-26 13:22 . 2012-07-26 13:22 292320 ----a-w- c:\windows\system32\vsjitdebugger.exe
2012-07-26 13:22 . 2012-07-26 13:22 248272 ----a-w- c:\windows\system32\VSPerf110.dll
2012-07-26 13:22 . 2012-07-26 13:22 1957328 ----a-w- c:\windows\system32\msvcr110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 187864 ----a-w- c:\windows\system32\VSCover110.dll
2012-07-26 13:22 . 2012-07-26 13:22 177096 ----a-w- c:\windows\system32\atl110.dll
2012-07-26 13:22 . 2012-07-26 13:22 153040 ----a-w- c:\windows\system32\vcomp110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 124360 ----a-w- c:\windows\system32\vcomp110.dll
2012-07-26 13:22 . 2012-07-26 13:22 120776 ----a-w- c:\windows\system32\mfcm110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 119760 ----a-w- c:\windows\system32\mfcm110ud.dll
2012-07-26 13:22 . 2012-07-26 13:22 1106384 ----a-w- c:\windows\system32\msvcp110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 10915784 ----a-w- c:\windows\system32\mfc110ud.dll
2012-07-26 13:22 . 2012-07-26 13:22 10843080 ----a-w- c:\windows\system32\mfc110d.dll
2012-07-26 13:22 . 2012-07-26 13:22 1077688 ----a-w- c:\windows\system32\vcamp110d.dll
2012-07-25 18:32 . 2012-07-25 18:32 98792 ----a-w- c:\windows\SysWow64\vfrdvcompat.dll
2012-07-25 18:32 . 2012-07-25 18:32 164200 ----a-w- c:\windows\SysWow64\vrfcore.dll
2012-07-25 18:31 . 2012-07-25 18:31 87328 ----a-w- c:\windows\SysWow64\vfcompat.dll
2012-07-25 18:31 . 2012-07-25 18:31 81592 ----a-w- c:\windows\SysWow64\vfnet.dll
2012-07-25 18:31 . 2012-07-25 18:31 61384 ----a-w- c:\windows\SysWow64\vfnws.dll
2012-07-25 18:31 . 2012-07-25 18:31 52032 ----a-w- c:\windows\SysWow64\vfcuzz.dll
2012-07-25 18:31 . 2012-07-25 18:31 40136 ----a-w- c:\windows\SysWow64\vfntlmless.dll
2012-07-25 18:31 . 2012-07-25 18:31 367392 ----a-w- c:\windows\SysWow64\vfprintpthelper.dll
2012-07-25 18:31 . 2012-07-25 18:31 353328 ----a-w- c:\windows\SysWow64\vfbasics.dll
2012-07-25 18:31 . 2012-07-25 18:31 306592 ----a-w- c:\windows\SysWow64\vfprint.dll
2012-07-25 18:31 . 2012-07-25 18:31 242776 ----a-w- c:\windows\SysWow64\vfluapriv.dll
2012-07-25 18:31 . 2012-07-25 18:31 21448 ----a-w- c:\windows\SysWow64\cuzzapi.dll
2012-07-25 18:31 . 2012-07-25 18:31 173520 ----a-w- c:\windows\SysWow64\appverif.exe
2012-07-25 18:25 . 2012-07-25 18:25 59848 ----a-w- c:\windows\SysWow64\VSD3DRefDebug.dll
2012-07-25 18:25 . 2012-07-25 18:25 713672 ----a-w- c:\windows\SysWow64\d3d11_1sdklayers.dll
2012-07-25 18:25 . 2012-07-25 18:25 609224 ----a-w- c:\windows\SysWow64\d3d11ref.dll
2012-07-25 18:25 . 2012-07-25 18:25 590792 ----a-w- c:\windows\SysWow64\d3d11sdklayers.dll
2012-07-25 18:25 . 2012-07-25 18:25 461256 ----a-w- c:\windows\SysWow64\d3d10sdklayers.dll
2012-07-25 18:25 . 2012-07-25 18:25 383944 ----a-w- c:\windows\SysWow64\d3dref9.dll
2012-07-25 18:25 . 2012-07-25 18:25 365512 ----a-w- c:\windows\SysWow64\d3d10ref.dll
2012-07-25 18:25 . 2012-07-25 18:25 232904 ----a-w- c:\windows\SysWow64\dxcpl.exe
2012-07-25 18:25 . 2012-07-25 18:25 102344 ----a-w- c:\windows\SysWow64\dxgidebug.dll
2012-07-25 18:16 . 2012-07-25 18:16 90480 ----a-w- c:\windows\system32\vfcompat.dll
2012-07-25 18:16 . 2012-07-25 18:16 83248 ----a-w- c:\windows\system32\vfnws.dll
2012-07-25 18:16 . 2012-07-25 18:16 711320 ----a-w- c:\windows\system32\vfprintpthelper.dll
2012-07-25 18:16 . 2012-07-25 18:16 48976 ----a-w- c:\windows\system32\vfcuzz.dll
2012-07-25 18:16 . 2012-07-25 18:16 45336 ----a-w- c:\windows\system32\vfntlmless.dll
2012-07-25 18:16 . 2012-07-25 18:16 433376 ----a-w- c:\windows\system32\vfprint.dll
2012-07-25 18:16 . 2012-07-25 18:16 406848 ----a-w- c:\windows\system32\vfbasics.dll
2012-07-25 18:16 . 2012-07-25 18:16 281656 ----a-w- c:\windows\system32\vfluapriv.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-09-26 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2012-09-26 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-09-10 17984688]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-04-26 3111744]
"Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2010-11-21 1174016]
"Sony PC Companion"="c:\program files (x86)\Sony\Sony PC Companion\PCCompanion.exe" [2012-05-31 445624]
"LightShot"="c:\users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe" [2012-02-02 220160]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-04 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-09-10 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-23 250288]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 fussvc;Windows App Certification Kit Fast User Switching Utility Service;c:\program files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 VSPerfDrv110;Performance Tools Driver 11.0;d:\program files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [2012-07-13 70264]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-26 1255736]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-23 283200]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-04 203264]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-23 19:18]
.
2012-09-26 c:\windows\Tasks\update-S-1-5-21-1324871451-212935027-3657544241-1000.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2012-09-24 20:09]
.
2012-09-26 c:\windows\Tasks\update-sys.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2012-09-24 20:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe
c:\users\GAMELASTER\AppData\Local\Skillbrains\lightshot\3.0.0.0\LightShot.exe
c:\program files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
.
**************************************************************************
.
Completion time: 2012-09-26 22:03:03 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-26 20:03
.
Pre-Run: 20 537 643 008 bytes free
Post-Run: 20 469 673 984 bytes free
.
- - End Of File - - 0A3418A52B0D2598B1DF9FD624EE4D3D
P.S. Lightshot furt funguje
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir sa dostal do PC aj po preinstalacii
Zkuste sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 a dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 107
- Registrován: 13 led 2012 16:53
Re: Vir sa dostal do PC aj po preinstalacii
naslo zopar virusov , a vsetky v Dcku :DStatus: Detected (events: 7)
27. 9. 2012 0:12:25 Detected malware HackTool.Win32.Hoic.a D:\DWN\DDoS.rar//DDoS/Hoic/hoic2.1.exe Medium
27. 9. 2012 0:12:26 Detected malware HackTool.MSIL.Loic.av D:\DWN\DDoS.rar//DDoS/Loic/debug/LOIC.exe Medium
27. 9. 2012 0:12:26 Detected malware Flooder.MSIL.Agent.e D:\DWN\DDoS.rar//DDoS/Loic/LOIC.exe Medium
27. 9. 2012 0:16:19 Detected Trojan program Trojan.Win32.Jorik.Shakblades.fed D:\DWN\game_maker.zip.part//setup.exe High
27. 9. 2012 0:28:43 Detected Trojan program Trojan.Win32.Vilsel.bkvq D:\DWN\The Eclipse V4.8.rar//plugins/audio.dll High
27. 9. 2012 0:28:45 Detected Trojan program Trojan.Win32.Vilsel.bkvq D:\DWN\The_Eclipse_V4.8.rar//plugins/audio.dll High
27. 9. 2012 1:07:15 Detected malware HackTool.Win32.PassDic.i D:\OldDWN\Rcon_Cracker.rar//Rcon Hack/NaWaR-Rcon-Pass.exe//UPX Medium
Status: Deleted (events: 4)
27. 9. 2012 1:13:38 Deleted malware HackTool.Win32.PassDic.i D:\OldDWN\Rcon_Cracker\Rcon Hack\NaWaR-Rcon-Pass.exe Medium
27. 9. 2012 1:13:38 Deleted malware HackTool.Win32.PassDic.i D:\OldDWN\Rcon_Cracker\Rcon Hack\NaWaR-Rcon-Pass.exe//UPX Medium
27. 9. 2012 1:37:17 Deleted malware Hoax.Win32.ArchSMS.obun D:\RockStarGames\GTA San Andreas\d3d9c.dll Medium
27. 9. 2012 2:30:45 Deleted Trojan program Trojan.Win32.Vilsel.bkvu D:\Zaloha!!!\Marek\Zabavky\SA-MP\samp03csvr_win32\plugins\sscanf.dll High
je cudni, ze som ani jeden z tichto programov po reinstalacii ani reaz nepustil...
hmm, nevedel som ze v Eclipse ktory je volen stiahnutelni zo eclipse.org je virus...
Jinak, k tym souborum, tihle soubori som pouzil 1 ked som mal povodny PC, takze nwm... :/
27. 9. 2012 0:12:25 Detected malware HackTool.Win32.Hoic.a D:\DWN\DDoS.rar//DDoS/Hoic/hoic2.1.exe Medium
27. 9. 2012 0:12:26 Detected malware HackTool.MSIL.Loic.av D:\DWN\DDoS.rar//DDoS/Loic/debug/LOIC.exe Medium
27. 9. 2012 0:12:26 Detected malware Flooder.MSIL.Agent.e D:\DWN\DDoS.rar//DDoS/Loic/LOIC.exe Medium
27. 9. 2012 0:16:19 Detected Trojan program Trojan.Win32.Jorik.Shakblades.fed D:\DWN\game_maker.zip.part//setup.exe High
27. 9. 2012 0:28:43 Detected Trojan program Trojan.Win32.Vilsel.bkvq D:\DWN\The Eclipse V4.8.rar//plugins/audio.dll High
27. 9. 2012 0:28:45 Detected Trojan program Trojan.Win32.Vilsel.bkvq D:\DWN\The_Eclipse_V4.8.rar//plugins/audio.dll High
27. 9. 2012 1:07:15 Detected malware HackTool.Win32.PassDic.i D:\OldDWN\Rcon_Cracker.rar//Rcon Hack/NaWaR-Rcon-Pass.exe//UPX Medium
Status: Deleted (events: 4)
27. 9. 2012 1:13:38 Deleted malware HackTool.Win32.PassDic.i D:\OldDWN\Rcon_Cracker\Rcon Hack\NaWaR-Rcon-Pass.exe Medium
27. 9. 2012 1:13:38 Deleted malware HackTool.Win32.PassDic.i D:\OldDWN\Rcon_Cracker\Rcon Hack\NaWaR-Rcon-Pass.exe//UPX Medium
27. 9. 2012 1:37:17 Deleted malware Hoax.Win32.ArchSMS.obun D:\RockStarGames\GTA San Andreas\d3d9c.dll Medium
27. 9. 2012 2:30:45 Deleted Trojan program Trojan.Win32.Vilsel.bkvu D:\Zaloha!!!\Marek\Zabavky\SA-MP\samp03csvr_win32\plugins\sscanf.dll High
je cudni, ze som ani jeden z tichto programov po reinstalacii ani reaz nepustil...
hmm, nevedel som ze v Eclipse ktory je volen stiahnutelni zo eclipse.org je virus...
Jinak, k tym souborum, tihle soubori som pouzil 1 ked som mal povodny PC, takze nwm... :/
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir sa dostal do PC aj po preinstalacii
Pokud taháte cracky, potom se nedivte. Vše smažte. Jak se nyní PC chová?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 107
- Registrován: 13 led 2012 16:53
Re: Vir sa dostal do PC aj po preinstalacii
hmm, furt mi nebere ziadne usb..... Ale myska atd funguje, dokonca aj citacka kariet, len vsetky usb kluce nefunguju...
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir sa dostal do PC aj po preinstalacii
Jakou chybu vyhodí? Máte nainstalovány všechny ovladače hardwaru?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 107
- Registrován: 13 led 2012 16:53
Re: Vir sa dostal do PC aj po preinstalacii
zadnou chybu nevyhodi.. Slysim zvuk pripojeni a dalej nic.. Neukazuje ani v dolnych ikonkach ze je nieco pripojene, jedine vo "Zazireni a tlaciarne".Rudy píše:Jakou chybu vyhodí? Máte nainstalovány všechny ovladače hardwaru?
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir sa dostal do PC aj po preinstalacii
Rudy píše:Máte nainstalovány všechny ovladače hardwaru?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 107
- Registrován: 13 led 2012 16:53
Re: Vir sa dostal do PC aj po preinstalacii
ano, sem si jisty! Do odoslani topicu mi to slo!
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir sa dostal do PC aj po preinstalacii
Zkuste ty USB ve správci zařízení odebrat. Pak PC restartujte a nechte znovu načíst.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.