Stránka 1 z 1

Notebook

Napsal: 26 říj 2012 23:53
od IbareduS
Logfile of random's system information tool 1.09 (written by random/random)
Run by Wosatko at 2012-10-27 00:52:21
Microsoft Windows 7 Home Premium
System drive C: has 20 GB (26%) free of 76 GB
Total RAM: 2039 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:52:34, on 27.10.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Steam\Steam.exe
C:\Users\Wosatko\Desktop\Wosátko\Metin2 Server\PortMap.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Wosatko\Desktop\RSIT.exe
C:\Program Files\trend micro\Wosatko.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll
O2 - BHO: uTorrentControl_v2 - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe

--
End of file - 5640 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
uTorrentControl_v2 Toolbar - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-16 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02 4119744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-16 157672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7473b6bd-4691-4744-a82b-7854eb3d70b6} - uTorrentControl_v2 Toolbar - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2012-10-14 735608]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-07-13 17418928]
"Pando Media Booster"=C:\Program Files\Pando Networks\Media Booster\PMB.exe [2012-10-24 3093624]
"Steam"=C:\Program Files\Steam\Steam.exe [2012-10-26 1353080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-10-27 00:52:22 ----D---- C:\Program Files\trend micro
2012-10-27 00:52:21 ----D---- C:\rsit
2012-10-27 00:44:29 ----D---- C:\Program Files\CCleaner
2012-10-26 22:07:48 ----D---- C:\Program Files\DsNET Corp
2012-10-26 22:07:21 ----D---- C:\ProgramData\Ask
2012-10-26 22:04:28 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2012-10-26 22:04:27 ----D---- C:\Program Files\DVDVideoSoft
2012-10-26 22:04:27 ----A---- C:\Windows\system32\msvcr70.dll
2012-10-26 02:14:01 ----D---- C:\Program Files\Gameforge4D
2012-10-26 01:06:33 ----D---- C:\Program Files\Common Files\Steam
2012-10-26 01:06:28 ----D---- C:\Program Files\Steam
2012-10-25 22:07:04 ----D---- C:\Program Files\FireArc Arcade
2012-10-24 23:24:50 ----D---- C:\CFLog
2012-10-24 23:15:39 ----D---- C:\SG Interactive
2012-10-24 20:08:12 ----A---- C:\Windows\system32\npptNT2.sys
2012-10-24 20:07:56 ----D---- C:\Program Files\Common Files\INCA Shared
2012-10-24 19:44:51 ----D---- C:\Program Files\eFusion
2012-10-24 18:40:24 ----D---- C:\ProgramData\PMB Files
2012-10-24 18:39:50 ----D---- C:\Program Files\Pando Networks
2012-10-24 18:15:09 ----D---- C:\Program Files\Garena Plus
2012-10-24 18:14:55 ----D---- C:\ProgramData\GarenaMessenger
2012-10-23 15:00:44 ----A---- C:\Windows\system32\FntCache.dll
2012-10-22 17:06:04 ----D---- C:\Program Files\EA Sports
2012-10-21 17:33:06 ----RHD---- C:\Users\Wosatko\AppData\Roaming\SecuROM
2012-10-20 18:52:57 ----D---- C:\Users\Wosatko\AppData\Roaming\TeamViewer
2012-10-20 18:52:18 ----D---- C:\Program Files\TeamViewer
2012-10-20 16:48:29 ----D---- C:\Users\Wosatko\AppData\Roaming\FastStone
2012-10-20 16:48:18 ----D---- C:\Program Files\FastStone Capture
2012-10-20 16:35:46 ----A---- C:\Windows\system32\libmysql_d.dll
2012-10-20 16:20:21 ----D---- C:\FR
2012-10-20 15:52:37 ----A---- C:\Windows\system32\drivers\VBoxDrv.sys
2012-10-20 15:52:21 ----A---- C:\Windows\system32\drivers\VBoxUSBMon.sys
2012-10-20 15:52:20 ----DC---- C:\Windows\system32\DRVSTORE
2012-10-19 17:08:06 ----A---- C:\Users\Wosatko\AppData\Roaming\technic-launcher.jar
2012-10-19 17:08:03 ----D---- C:\Users\Wosatko\AppData\Roaming\logs
2012-10-19 17:08:03 ----D---- C:\Users\Wosatko\AppData\Roaming\.techniclauncher
2012-10-18 18:09:15 ----D---- C:\Program Files\Google
2012-10-18 18:09:12 ----D---- C:\Program Files\WinSCP
2012-10-18 17:50:24 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2012-10-18 17:50:24 ----A---- C:\Windows\system32\drivers\usbport.sys
2012-10-18 17:50:24 ----A---- C:\Windows\system32\drivers\usbohci.sys
2012-10-18 17:50:24 ----A---- C:\Windows\system32\drivers\usbhub.sys
2012-10-18 17:50:24 ----A---- C:\Windows\system32\drivers\usbehci.sys
2012-10-18 17:50:24 ----A---- C:\Windows\system32\drivers\usbd.sys
2012-10-18 17:50:24 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2012-10-18 17:50:08 ----A---- C:\Windows\system32\drivers\nvstor.sys
2012-10-18 17:50:07 ----A---- C:\Windows\system32\esent.dll
2012-10-18 17:50:07 ----A---- C:\Windows\system32\drivers\storport.sys
2012-10-18 17:50:07 ----A---- C:\Windows\system32\drivers\nvraid.sys
2012-10-18 17:50:07 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2012-10-18 17:50:07 ----A---- C:\Windows\system32\drivers\amdsata.sys
2012-10-18 17:50:06 ----A---- C:\Windows\system32\fsutil.exe
2012-10-18 17:50:06 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2012-10-18 17:50:06 ----A---- C:\Windows\system32\drivers\amdxata.sys
2012-10-18 17:49:58 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2012-10-18 17:49:58 ----A---- C:\Windows\system32\drivers\bthport.sys
2012-10-18 17:18:56 ----A---- C:\Windows\system32\drivers\VBoxNetAdp.sys
2012-10-18 15:13:51 ----D---- C:\Program Files\Microsoft.NET
2012-10-17 15:52:06 ----A---- C:\Windows\system32\msv1_0.dll
2012-10-17 15:43:21 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-10-17 15:43:21 ----A---- C:\Windows\system32\PresentationHost.exe
2012-10-17 15:43:21 ----A---- C:\Windows\system32\netfxperf.dll
2012-10-17 15:43:21 ----A---- C:\Windows\system32\mscoree.dll
2012-10-17 15:43:21 ----A---- C:\Windows\system32\dfshim.dll
2012-10-17 15:33:06 ----D---- C:\Users\Wosatko\AppData\Roaming\.minecraft
2012-10-17 14:04:38 ----A---- C:\Windows\system32\wmi.dll
2012-10-17 14:04:38 ----A---- C:\Windows\system32\imagehlp.dll
2012-10-17 14:04:38 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-10-17 14:02:28 ----A---- C:\Windows\system32\wininet.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\urlmon.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2012-10-17 14:02:28 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2012-10-17 14:02:28 ----A---- C:\Windows\system32\msrating.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\msls31.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\mshtmler.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\msfeedssync.exe
2012-10-17 14:02:28 ----A---- C:\Windows\system32\msfeedsbs.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\jsproxy.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\ieui.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\iesysprep.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\iertutil.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\ieframe.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\ieakeng.dll
2012-10-17 14:02:28 ----A---- C:\Windows\system32\IEAdvpack.dll
2012-10-17 14:02:27 ----A---- C:\Windows\system32\dxtrans.dll
2012-10-17 14:02:27 ----A---- C:\Windows\system32\dxtmsft.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\wextract.exe
2012-10-17 14:02:26 ----A---- C:\Windows\system32\webcheck.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\vbscript.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\url.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\mshtmled.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\msfeeds.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\licmgr10.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\inseng.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\iexpress.exe
2012-10-17 14:02:26 ----A---- C:\Windows\system32\iesetup.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\iernonce.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\iedkcs32.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\ieapfltr.dll
2012-10-17 14:02:26 ----A---- C:\Windows\system32\ieapfltr.dat
2012-10-17 14:02:26 ----A---- C:\Windows\system32\ie4uinit.exe
2012-10-17 14:02:26 ----A---- C:\Windows\system32\icardie.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\pngfilt.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\occache.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\mshtml.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\mshta.exe
2012-10-17 14:02:25 ----A---- C:\Windows\system32\jscript9.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\jscript.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\imgutil.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\ieUnatt.exe
2012-10-17 14:02:25 ----A---- C:\Windows\system32\iepeers.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\ieakui.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\ieaksie.dll
2012-10-17 14:02:25 ----A---- C:\Windows\system32\admparse.dll
2012-10-17 13:52:03 ----A---- C:\Windows\system32\browserchoice.exe
2012-10-17 13:47:03 ----A---- C:\Windows\system32\drivers\ks.sys
2012-10-17 13:46:48 ----D---- C:\Windows\system32\Wat
2012-10-16 23:27:10 ----A---- C:\Windows\system32\wcncsvc.dll
2012-10-16 18:11:31 ----D---- C:\ProgramData\Sun
2012-10-16 18:11:30 ----D---- C:\Program Files\Common Files\Java
2012-10-16 18:11:15 ----A---- C:\Windows\system32\npDeployJava1.dll
2012-10-16 18:11:15 ----A---- C:\Windows\system32\javaws.exe
2012-10-16 18:11:15 ----A---- C:\Windows\system32\deployJava1.dll
2012-10-16 18:10:57 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2012-10-16 18:10:57 ----A---- C:\Windows\system32\javaw.exe
2012-10-16 18:10:57 ----A---- C:\Windows\system32\java.exe
2012-10-16 18:10:38 ----D---- C:\Program Files\Java
2012-10-16 17:49:58 ----D---- C:\Users\Wosatko\AppData\Roaming\Hamachi
2012-10-16 17:49:33 ----A---- C:\Windows\system32\drivers\hamachi.sys
2012-10-16 16:42:37 ----A---- C:\Windows\system32\msdri.dll
2012-10-16 16:42:34 ----A---- C:\Windows\system32\win32spl.dll
2012-10-16 16:42:34 ----A---- C:\Windows\system32\spoolsv.exe
2012-10-16 16:42:32 ----A---- C:\Windows\system32\ole32.dll
2012-10-16 16:42:30 ----A---- C:\Windows\system32\drivers\fvevol.sys
2012-10-16 16:42:25 ----A---- C:\Windows\system32\drivers\srv.sys
2012-10-16 16:42:24 ----A---- C:\Windows\system32\drivers\srvnet.sys
2012-10-16 16:42:24 ----A---- C:\Windows\system32\drivers\srv2.sys
2012-10-16 16:42:23 ----A---- C:\Windows\system32\drivers\afd.sys
2012-10-16 16:42:20 ----A---- C:\Windows\system32\ntdll.dll
2012-10-16 16:42:03 ----A---- C:\Windows\system32\wintrust.dll
2012-10-16 16:42:01 ----A---- C:\Windows\system32\xmllite.dll
2012-10-16 16:42:00 ----A---- C:\Windows\system32\prevhost.exe
2012-10-16 16:41:53 ----A---- C:\Windows\system32\tzres.dll
2012-10-16 16:41:43 ----A---- C:\Windows\system32\atmlib.dll
2012-10-16 16:41:43 ----A---- C:\Windows\system32\atmfd.dll
2012-10-16 16:41:41 ----A---- C:\Windows\system32\dnsrslvr.dll
2012-10-16 16:41:41 ----A---- C:\Windows\system32\dnsapi.dll
2012-10-16 16:41:40 ----A---- C:\Windows\system32\dnscacheugc.exe
2012-10-16 16:41:35 ----A---- C:\Windows\system32\winsrv.dll
2012-10-16 16:41:35 ----A---- C:\Windows\system32\KernelBase.dll
2012-10-16 16:41:35 ----A---- C:\Windows\system32\kernel32.dll
2012-10-16 16:41:35 ----A---- C:\Windows\system32\conhost.exe
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-10-16 16:41:34 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-10-16 16:41:15 ----A---- C:\Windows\system32\ir32_32.dll
2012-10-16 16:41:15 ----A---- C:\Windows\system32\iccvid.dll
2012-10-16 16:41:11 ----A---- C:\Windows\system32\winlogon.exe
2012-10-16 16:41:10 ----A---- C:\Windows\system32\t2embed.dll
2012-10-16 16:40:59 ----A---- C:\Windows\system32\cryptsvc.dll
2012-10-16 16:40:59 ----A---- C:\Windows\system32\cryptnet.dll
2012-10-16 16:40:59 ----A---- C:\Windows\system32\crypt32.dll
2012-10-16 16:40:07 ----A---- C:\Windows\system32\psisdecd.dll
2012-10-16 16:40:04 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-10-16 16:39:38 ----A---- C:\Windows\system32\umpnpmgr.dll
2012-10-16 16:39:33 ----A---- C:\Windows\system32\wmicmiplugin.dll
2012-10-16 16:39:33 ----A---- C:\Windows\system32\taskschd.dll
2012-10-16 16:39:33 ----A---- C:\Windows\system32\taskeng.exe
2012-10-16 16:39:33 ----A---- C:\Windows\system32\taskcomp.dll
2012-10-16 16:39:33 ----A---- C:\Windows\system32\schtasks.exe
2012-10-16 16:39:33 ----A---- C:\Windows\system32\schedsvc.dll
2012-10-16 16:39:31 ----A---- C:\Windows\system32\msasn1.dll
2012-10-16 16:39:27 ----A---- C:\Windows\system32\rtutils.dll
2012-10-16 16:39:22 ----A---- C:\Windows\system32\schannel.dll
2012-10-16 16:39:22 ----A---- C:\Windows\system32\ncrypt.dll
2012-10-16 16:39:22 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-10-16 16:39:22 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-10-16 16:39:22 ----A---- C:\Windows\system32\drivers\cng.sys
2012-10-16 16:39:20 ----A---- C:\Windows\system32\oleaut32.dll
2012-10-16 16:39:20 ----A---- C:\Windows\system32\oleacc.dll
2012-10-16 16:39:18 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2012-10-16 16:39:17 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2012-10-16 16:39:17 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2012-10-16 16:39:15 ----A---- C:\Windows\system32\msxml6.dll
2012-10-16 16:39:15 ----A---- C:\Windows\system32\msxml3.dll
2012-10-16 16:39:11 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-10-16 16:39:09 ----A---- C:\Windows\system32\odbc32.dll
2012-10-16 16:39:02 ----A---- C:\Windows\system32\drivers\dfsc.sys
2012-10-16 16:39:00 ----A---- C:\Windows\system32\drivers\ntfs.sys
2012-10-16 16:38:57 ----A---- C:\Windows\system32\inetcomm.dll
2012-10-16 16:38:51 ----A---- C:\Windows\system32\CertEnroll.dll
2012-10-16 16:38:50 ----A---- C:\Windows\system32\winresume.exe
2012-10-16 16:38:50 ----A---- C:\Windows\system32\winload.exe
2012-10-16 16:38:09 ----A---- C:\Windows\system32\asycfilt.dll
2012-10-16 16:36:32 ----A---- C:\Windows\system32\comctl32.dll
2012-10-16 16:36:28 ----A---- C:\Windows\system32\mfc40.dll
2012-10-16 16:36:27 ----A---- C:\Windows\system32\mfc40u.dll
2012-10-16 16:36:25 ----A---- C:\Windows\system32\wmp.dll
2012-10-16 16:36:23 ----A---- C:\Windows\system32\wmploc.DLL
2012-10-16 16:36:21 ----A---- C:\Windows\system32\packager.dll
2012-10-16 16:36:16 ----A---- C:\Windows\system32\tquery.dll
2012-10-16 16:36:16 ----A---- C:\Windows\system32\SearchIndexer.exe
2012-10-16 16:36:16 ----A---- C:\Windows\system32\mssrch.dll
2012-10-16 16:36:15 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2012-10-16 16:36:15 ----A---- C:\Windows\system32\SearchFilterHost.exe
2012-10-16 16:36:15 ----A---- C:\Windows\system32\mssvp.dll
2012-10-16 16:36:15 ----A---- C:\Windows\system32\mssphtb.dll
2012-10-16 16:36:15 ----A---- C:\Windows\system32\mssph.dll
2012-10-16 16:36:15 ----A---- C:\Windows\system32\msscntrs.dll
2012-10-16 16:35:48 ----A---- C:\Windows\system32\FXSCOVER.exe
2012-10-16 16:35:47 ----A---- C:\Windows\system32\fontsub.dll
2012-10-16 16:35:46 ----A---- C:\Windows\system32\srcore.dll
2012-10-16 16:35:42 ----A---- C:\Windows\system32\EncDec.dll
2012-10-16 16:35:36 ----A---- C:\Windows\system32\apphelp.dll
2012-10-16 16:35:33 ----A---- C:\Windows\system32\netapi32.dll
2012-10-16 16:35:33 ----A---- C:\Windows\system32\browser.dll
2012-10-16 16:35:33 ----A---- C:\Windows\system32\browcli.dll
2012-10-16 16:35:31 ----A---- C:\Windows\system32\XpsPrint.dll
2012-10-16 16:35:29 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2012-10-16 16:35:28 ----A---- C:\Windows\system32\csrsrv.dll
2012-10-16 16:35:24 ----A---- C:\Windows\system32\tsbyuv.dll
2012-10-16 16:35:24 ----A---- C:\Windows\system32\msyuv.dll
2012-10-16 16:35:24 ----A---- C:\Windows\system32\msvidc32.dll
2012-10-16 16:35:24 ----A---- C:\Windows\system32\msrle32.dll
2012-10-16 16:35:24 ----A---- C:\Windows\system32\mciavi32.dll
2012-10-16 16:35:24 ----A---- C:\Windows\system32\iyuv_32.dll
2012-10-16 16:35:24 ----A---- C:\Windows\system32\avifil32.dll
2012-10-16 16:35:23 ----A---- C:\Windows\system32\CPFilters.dll
2012-10-16 16:35:22 ----A---- C:\Windows\system32\sbe.dll
2012-10-16 16:35:20 ----A---- C:\Windows\system32\quartz.dll
2012-10-16 16:35:19 ----A---- C:\Windows\system32\qdvd.dll
2012-10-16 16:35:17 ----A---- C:\Windows\system32\kerberos.dll
2012-10-16 16:35:13 ----A---- C:\Windows\explorer.exe
2012-10-16 16:35:09 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-10-16 16:35:09 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-10-16 16:35:06 ----A---- C:\Windows\system32\msi.dll
2012-10-16 16:34:59 ----A---- C:\Windows\system32\d3d10level9.dll
2012-10-16 16:34:58 ----A---- C:\Windows\system32\mstscax.dll
2012-10-16 16:34:57 ----A---- C:\Windows\system32\mstsc.exe
2012-10-16 16:33:20 ----A---- C:\Windows\system32\webio.dll
2012-10-16 16:33:20 ----A---- C:\Windows\system32\lsasrv.dll
2012-10-16 16:33:19 ----A---- C:\Windows\system32\sspisrv.dll
2012-10-16 16:33:19 ----A---- C:\Windows\system32\sspicli.dll
2012-10-16 16:33:19 ----A---- C:\Windows\system32\secur32.dll
2012-10-16 16:33:19 ----A---- C:\Windows\system32\lsass.exe
2012-10-16 16:33:17 ----A---- C:\Windows\system32\odbcjt32.dll
2012-10-16 16:33:17 ----A---- C:\Windows\system32\odbccp32.dll
2012-10-16 16:33:16 ----A---- C:\Windows\system32\odbctrac.dll
2012-10-16 16:33:16 ----A---- C:\Windows\system32\odbccu32.dll
2012-10-16 16:33:16 ----A---- C:\Windows\system32\odbccr32.dll
2012-10-16 16:33:13 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-10-16 16:33:13 ----A---- C:\Windows\system32\rdpwsx.dll
2012-10-16 16:33:13 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-10-16 16:33:10 ----A---- C:\Windows\system32\msvcrt.dll
2012-10-16 16:33:08 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-10-16 16:33:06 ----A---- C:\Windows\system32\srvsvc.dll
2012-10-16 16:33:04 ----A---- C:\Windows\system32\profsvc.dll
2012-10-16 16:32:58 ----A---- C:\Windows\system32\mf.dll
2012-10-16 16:32:56 ----A---- C:\Windows\system32\XpsRasterService.dll
2012-10-16 16:32:56 ----A---- C:\Windows\system32\WMVDECOD.DLL
2012-10-16 16:32:56 ----A---- C:\Windows\system32\mfreadwrite.dll
2012-10-16 16:32:56 ----A---- C:\Windows\system32\ExplorerFrame.dll
2012-10-16 16:32:48 ----A---- C:\Windows\system32\upnp.dll
2012-10-16 16:32:47 ----A---- C:\Windows\system32\wscsvc.dll
2012-10-16 16:32:47 ----A---- C:\Windows\system32\wscapi.dll
2012-10-16 16:32:47 ----A---- C:\Windows\system32\winhttp.dll
2012-10-16 16:32:47 ----A---- C:\Windows\system32\WebClnt.dll
2012-10-16 16:32:47 ----A---- C:\Windows\system32\slwga.dll
2012-10-16 16:32:47 ----A---- C:\Windows\system32\davclnt.dll
2012-10-16 16:32:19 ----A---- C:\Windows\system32\localspl.dll
2012-10-16 16:32:15 ----A---- C:\Windows\system32\win32k.sys
2012-10-16 16:32:09 ----A---- C:\Windows\system32\wmpmde.dll
2012-10-16 16:32:07 ----A---- C:\Windows\system32\consent.exe
2012-10-16 16:32:03 ----A---- C:\Windows\system32\ntshrui.dll
2012-10-16 16:32:01 ----A---- C:\Windows\system32\secproc_isv.dll
2012-10-16 16:32:00 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2012-10-16 16:32:00 ----A---- C:\Windows\system32\secproc_ssp.dll
2012-10-16 16:32:00 ----A---- C:\Windows\system32\secproc.dll
2012-10-16 16:32:00 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2012-10-16 16:32:00 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2012-10-16 16:32:00 ----A---- C:\Windows\system32\RMActivate_isv.exe
2012-10-16 16:32:00 ----A---- C:\Windows\system32\RMActivate.exe
2012-10-16 16:31:58 ----A---- C:\Windows\system32\d3d10warp.dll
2012-10-16 16:31:58 ----A---- C:\Windows\system32\d2d1.dll
2012-10-16 16:31:57 ----A---- C:\Windows\system32\DWrite.dll
2012-10-16 16:31:57 ----A---- C:\Windows\system32\d3d10_1core.dll
2012-10-16 16:31:57 ----A---- C:\Windows\system32\d3d10_1.dll
2012-10-16 16:31:52 ----A---- C:\Windows\system32\mfc42u.dll
2012-10-16 16:31:52 ----A---- C:\Windows\system32\mfc42.dll
2012-10-16 16:31:49 ----A---- C:\Windows\system32\StructuredQuery.dll
2012-10-16 16:31:49 ----A---- C:\Windows\system32\drivers\bowser.sys
2012-10-16 16:31:45 ----A---- C:\Windows\system32\shell32.dll
2012-10-16 16:31:42 ----A---- C:\Windows\system32\poqexec.exe
2012-10-16 16:31:41 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2012-10-16 16:30:16 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2012-10-16 16:30:16 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2012-10-16 16:30:16 ----A---- C:\Windows\system32\cdd.dll
2012-10-16 16:12:22 ----D---- C:\Users\Wosatko\AppData\Roaming\Skype
2012-10-16 16:12:16 ----RD---- C:\Program Files\Skype
2012-10-16 16:12:16 ----D---- C:\Program Files\Common Files\Skype
2012-10-16 16:12:11 ----D---- C:\ProgramData\Skype
2012-10-14 21:02:30 ----D---- C:\ProgramData\FLEXnet
2012-10-14 20:55:47 ----D---- C:\Program Files\Adobe
2012-10-14 20:54:40 ----D---- C:\Program Files\Common Files\Macrovision Shared
2012-10-14 20:42:29 ----D---- C:\Program Files\Adobe Media Player
2012-10-14 20:40:11 ----D---- C:\Program Files\Common Files\Adobe AIR
2012-10-14 20:37:55 ----D---- C:\ProgramData\Adobe
2012-10-14 20:32:13 ----SHD---- C:\Windows\Installer
2012-10-14 20:32:02 ----D---- C:\Program Files\Common Files\Adobe
2012-10-14 16:42:25 ----D---- C:\Users\Wosatko\AppData\Roaming\WinRAR
2012-10-14 16:42:17 ----D---- C:\Program Files\WinRAR
2012-10-14 16:35:50 ----D---- C:\Program Files\EA GAMES
2012-10-14 16:25:39 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2012-10-14 16:25:32 ----D---- C:\Users\Wosatko\AppData\Roaming\DAEMON Tools Lite
2012-10-14 16:25:30 ----D---- C:\Program Files\DAEMON Tools Lite
2012-10-14 16:23:01 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-10-14 16:19:18 ----D---- C:\Users\Wosatko\AppData\Roaming\Mozilla
2012-10-14 16:19:16 ----D---- C:\Program Files\Conduit
2012-10-14 16:19:13 ----D---- C:\Program Files\uTorrentControl_v2
2012-10-14 16:19:11 ----D---- C:\Program Files\uTorrent
2012-10-14 16:18:44 ----D---- C:\Users\Wosatko\AppData\Roaming\uTorrent
2012-10-14 16:12:20 ----D---- C:\Users\Wosatko\AppData\Roaming\Macromedia
2012-10-14 16:12:20 ----D---- C:\Users\Wosatko\AppData\Roaming\Adobe
2012-10-14 16:12:05 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-10-14 16:11:37 ----D---- C:\Windows\system32\Macromed
2012-10-14 15:56:38 ----D---- C:\Windows\system32\x64
2012-10-14 15:56:38 ----A---- C:\Windows\system32\igxpun.exe
2012-10-14 15:54:57 ----A---- C:\Windows\system32\rdpcore.dll
2012-10-14 15:54:57 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2012-10-14 15:54:48 ----N---- C:\Windows\system32\MpSigStub.exe
2012-10-14 15:54:26 ----A---- C:\Windows\system32\cabview.dll
2012-10-14 15:51:47 ----D---- C:\Users\Wosatko\AppData\Roaming\Opera
2012-10-14 15:51:40 ----D---- C:\Program Files\Opera
2012-10-14 15:50:51 ----A---- C:\Windows\system32\wups2.dll
2012-10-14 15:50:51 ----A---- C:\Windows\system32\wuauclt.exe
2012-10-14 15:50:50 ----A---- C:\Windows\system32\wucltux.dll
2012-10-14 15:50:50 ----A---- C:\Windows\system32\wuaueng.dll
2012-10-14 15:50:30 ----A---- C:\Windows\system32\wups.dll
2012-10-14 15:50:30 ----A---- C:\Windows\system32\wudriver.dll
2012-10-14 15:50:30 ----A---- C:\Windows\system32\wuapi.dll
2012-10-14 15:50:15 ----A---- C:\Windows\system32\wuwebv.dll
2012-10-14 15:50:15 ----A---- C:\Windows\system32\wuapp.exe
2012-10-14 15:30:18 ----D---- C:\Windows\Panther
2012-10-14 15:20:58 ----D---- C:\Windows.old
2012-10-14 15:00:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-10-14 14:55:20 ----D---- C:\Users\Wosatko\AppData\Roaming\Identities
2012-10-14 14:53:39 ----SD---- C:\Users\Wosatko\AppData\Roaming\Microsoft
2012-10-14 14:53:39 ----D---- C:\Users\Wosatko\AppData\Roaming\Media Center Programs
2012-10-14 14:52:39 ----SHD---- C:\ProgramData\Šablony
2012-10-14 14:52:39 ----SHD---- C:\ProgramData\Plocha
2012-10-14 14:52:39 ----SHD---- C:\ProgramData\Oblíbené položky
2012-10-14 14:52:39 ----SHD---- C:\ProgramData\Nabídka Start
2012-10-14 14:52:39 ----SHD---- C:\ProgramData\Dokumenty
2012-10-14 14:52:39 ----SHD---- C:\ProgramData\Data aplikací
2012-10-14 14:34:49 ----D---- C:\Windows\SoftwareDistribution
2012-10-14 14:31:30 ----D---- C:\Windows\Prefetch
2012-10-14 14:30:57 ----ASH---- C:\hiberfil.sys
2012-10-06 17:05:44 ----D---- C:\Temp
2012-10-02 15:42:30 ----SHD---- C:\found.001
2012-09-28 19:02:28 ----A---- C:\dsetup32.dll
2012-09-28 19:02:28 ----A---- C:\DSETUP.dll

======List of files/folders modified in the last 1 month======

2012-10-27 00:52:27 ----D---- C:\Windows\Temp
2012-10-27 00:52:22 ----RD---- C:\Program Files
2012-10-27 00:45:24 ----D---- C:\Windows\Logs
2012-10-27 00:45:24 ----D---- C:\Windows\inf
2012-10-27 00:45:24 ----D---- C:\Windows\debug
2012-10-27 00:45:24 ----D---- C:\Windows
2012-10-27 00:44:30 ----D---- C:\Windows\system32\Tasks
2012-10-27 00:40:11 ----D---- C:\Windows\System32
2012-10-27 00:39:24 ----SHD---- C:\Config.Msi
2012-10-27 00:39:21 ----D---- C:\Windows\system32\DriverStore
2012-10-27 00:39:21 ----D---- C:\Windows\system32\catroot
2012-10-27 00:38:18 ----D---- C:\Windows\system32\drivers
2012-10-27 00:37:32 ----SHD---- C:\System Volume Information
2012-10-26 22:07:21 ----HD---- C:\ProgramData
2012-10-26 22:04:28 ----D---- C:\Program Files\Common Files
2012-10-26 20:50:58 ----D---- C:\Windows\system32\config
2012-10-26 19:27:40 ----D---- C:\Windows\system32\wdi
2012-10-24 18:16:12 ----D---- C:\Program Files\Common Files\microsoft shared
2012-10-24 18:15:48 ----D---- C:\Windows\winsxs
2012-10-24 14:49:56 ----D---- C:\Windows\system32\NDF
2012-10-21 04:10:50 ----D---- C:\Windows\rescache
2012-10-20 08:29:37 ----RSD---- C:\Windows\assembly
2012-10-20 08:29:37 ----D---- C:\Windows\Microsoft.NET
2012-10-19 16:20:18 ----D---- C:\Windows\system32\catroot2
2012-10-19 13:39:24 ----D---- C:\Windows\system32\cs-CZ
2012-10-18 18:09:22 ----D---- C:\Windows\Tasks
2012-10-18 15:13:52 ----D---- C:\Windows\system32\en-US
2012-10-17 16:25:16 ----D---- C:\Windows\AppPatch
2012-10-17 16:25:15 ----RSD---- C:\Windows\Fonts
2012-10-17 16:25:15 ----D---- C:\Program Files\Windows Mail
2012-10-17 16:25:15 ----D---- C:\Program Files\Common Files\System
2012-10-17 16:25:14 ----D---- C:\Windows\ehome
2012-10-17 16:25:03 ----D---- C:\Windows\system32\Boot
2012-10-17 16:25:03 ----D---- C:\Program Files\Windows Journal
2012-10-17 16:25:02 ----D---- C:\Program Files\Windows Media Player
2012-10-17 16:24:58 ----D---- C:\Program Files\Internet Explorer
2012-10-17 16:24:57 ----D---- C:\Windows\system32\migration
2012-10-17 16:24:57 ----D---- C:\Windows\PolicyDefinitions
2012-10-16 16:00:27 ----SD---- C:\ProgramData\Microsoft
2012-10-16 15:08:59 ----D---- C:\Windows\system32\LogFiles
2012-10-14 15:49:26 ----D---- C:\Windows\system32\restore
2012-10-14 15:29:46 ----D---- C:\Windows\Setup
2012-10-14 14:59:37 ----D---- C:\Windows\system32\wbem
2012-10-14 14:55:16 ----SHD---- C:\$Recycle.Bin
2012-10-14 14:53:39 ----RD---- C:\Users
2012-10-14 14:52:40 ----SHD---- C:\Recovery
2012-10-14 14:52:39 ----D---- C:\Program Files\Windows NT
2012-10-14 14:40:46 ----D---- C:\Windows\system32\CodeIntegrity
2012-10-14 14:35:39 ----D---- C:\Windows\system32\sysprep
2012-10-14 14:34:12 ----D---- C:\Windows\system32\drivers\UMDF
2012-09-29 12:04:32 ----D---- C:\Download

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 25656]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-10-14 242240]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-08-14 74720]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 35896]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-14 1035776]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
R3 SMSCIRDA;SMSC Infrared Device Driver; C:\Windows\system32\DRIVERS\SMSCirda.sys [2007-04-25 31232]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 30720]
R3 XDva401;XDva401; \??\C:\Windows\system32\XDva401.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393216]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2012-10-16 25280]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2012-10-18 104280]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 XDva400;XDva400; \??\C:\Windows\system32\XDva400.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 26168]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R2 TeamViewer7;TeamViewer 7; C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe [2012-08-31 2754984]
R3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2012-10-26 529744]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-10-18 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-14 250808]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-10-14 655624]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-10-18 136176]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2012-09-26 4521720]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-10-17 1343400]

-----------------EOF-----------------

Re: Notebook

Napsal: 27 říj 2012 09:06
od Márty84
Zdravim :)

:???: Nejak tam nevidim antivir :?:

:arrow: Odinstalujte Pando Networks (Pando Media Booster)

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Notebook

Napsal: 27 říj 2012 10:26
od IbareduS
Bohužel :( 2 jsem to spustil a ani jednou nedojelo vždy mi to zabere celou operační pamět,furt píše,že už to dělá ten soubor .txt ale nic to nedělá jen počítač je zpomalenej ... a Antivirus už je ;)

Re: Notebook

Napsal: 27 říj 2012 14:29
od Márty84
:arrow: Zkuste to znovu, ale tentokrat v nouzovem rezimu a s timto upravenym skriptem

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
atapi.sys
autochk.exe
cdrom.sys
explorer.exe
hal.dll
scecli.dll
svchost.exe
tcpip.sys
userinit.exe
winlogon.exe
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

*crack* /s
*keygen* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s

Re: Notebook

Napsal: 27 říj 2012 15:25
od IbareduS
Dobře jdu na to

Re: Notebook

Napsal: 27 říj 2012 15:42
od IbareduS
Stále to nejde,tak já nevím :(

Re: Notebook

Napsal: 27 říj 2012 15:54
od Márty84
Zkuste to tedy bez skriptu. Nejdrive v normlanim, pokud nepujde, tak i v nouzovem rezimu.