Stránka 1 z 4

prosim o kontrolu logu

Napsal: 17 lis 2012 01:28
od BlackAngel
Dobrý den,
dostávám totální sadu! Můj account na blizzardu hacknut pred mesicem, resil jsem to tady. Vsechno jsme vycistili. Dneska ranov 00:04 opet snaha o zmenu meho hesla na blizzardu? Jak???? Zmenil jsem heslo na me poste (emailu) na blizzardu taktez. Prijdu domu z hospody a totez.....opet utok a snaha o likvidaci meho uctu na blizzardu!!!!!!!!!! Kurva nekdo se mi sakra a dobre hrabe v kompu!!! Sleduje kazde heslo co napisu o tom neni pochyb! Mam Strach! Prosim o pomoc...davam log :(


Logfile of random's system information tool 1.09 (written by random/random)
Run by Nasgharet at 2012-11-17 01:18:26
Microsoft Windows 7 Home Premium
System drive C: has 31 GB (31%) free of 100 GB
Total RAM: 4095 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:18:30, on 17.11.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe
C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
D:\---Download---\RSIT.exe
C:\Program Files (x86)\trend micro\Nasgharet.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Aeria Ignite] "C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe" silent
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7M\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [AppVodBurner] C:\Program Files (x86)\VodBurner\vodburner.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: PokerStars.be - {878AC5FC-BE78-4bae-896C-7F75B790A71E} - C:\Program Files (x86)\PokerStars.BE\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9269 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\Nasgharet\AppData\Roaming\Mozilla\Firefox\Profiles\1kc8j041.default-1348185830213

prefs.js - "browser.startup.homepage" - "http://www.google.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-05 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-05 157672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"Aeria Ignite"=C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [2012-09-10 1411224]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2012-11-15 2254768]
"NBKeyScan"=C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-11 3672384]
"ICQ"=C:\Program Files (x86)\ICQ7M\ICQ.exe [2012-09-05 127040]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2012-10-18 1353080]
"AppVodBurner"=C:\Program Files (x86)\VodBurner\vodburner.exe [2012-10-22 4688896]
"Akamai NetSession Interface"=C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe [2012-10-09 4441920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.l3codec"=l3codecp.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-12-20 16:54:04 ----A---- C:\Windows\SysWOW64\npptNT2.sys
2012-12-20 16:41:25 ----D---- C:\Users\Nasgharet\AppData\Roaming\InstallShield
2012-11-17 01:18:26 ----D---- C:\Program Files (x86)\trend micro
2012-11-16 23:51:03 ----D---- C:\Windows\SysWOW64\directx
2012-11-16 14:59:16 ----D---- C:\Users\Nasgharet\AppData\Roaming\Nero
2012-11-16 14:51:25 ----A---- C:\Windows\Irremote.ini
2012-11-16 14:50:17 ----D---- C:\ProgramData\Nero
2012-11-16 14:50:17 ----D---- C:\Program Files (x86)\Nero
2012-11-16 14:50:17 ----D---- C:\Program Files (x86)\Common Files\Nero
2012-11-16 14:42:19 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2012-11-16 08:11:55 ----D---- C:\ProgramData\Aeria Games
2012-11-16 08:08:22 ----SHD---- C:\Windows\SysWOW64\AI_RecycleBin
2012-11-16 08:08:22 ----D---- C:\Program Files (x86)\Aeria Games
2012-11-16 01:11:14 ----D---- C:\AeriaGames
2012-11-07 10:02:36 ----D---- C:\Program Files (x86)\PokerStars.BE
2012-11-07 09:48:00 ----D---- C:\Program Files (x86)\Full Tilt Poker
2012-11-01 08:41:46 ----A---- C:\Windows\SysWOW64\XAudio2_7.dll
2012-11-01 08:41:46 ----A---- C:\Windows\SysWOW64\XAPOFX1_5.dll
2012-11-01 08:41:46 ----A---- C:\Windows\SysWOW64\xactengine3_7.dll
2012-11-01 08:41:45 ----A---- C:\Windows\SysWOW64\d3dcsx_43.dll
2012-11-01 08:41:45 ----A---- C:\Windows\SysWOW64\D3DCompiler_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SysWOW64\D3DX9_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SysWOW64\d3dx11_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SysWOW64\d3dx10_43.dll
2012-11-01 08:41:41 ----A---- C:\Windows\SysWOW64\XAudio2_5.dll
2012-11-01 08:41:40 ----A---- C:\Windows\SysWOW64\xactengine3_5.dll
2012-11-01 08:41:39 ----A---- C:\Windows\SysWOW64\D3DCompiler_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\SysWOW64\d3dx11_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\SysWOW64\d3dcsx_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\SysWOW64\D3DX9_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\SysWOW64\d3dx10_42.dll
2012-11-01 08:41:36 ----A---- C:\Windows\SysWOW64\d3dx10_41.dll
2012-11-01 08:41:36 ----A---- C:\Windows\SysWOW64\D3DCompiler_41.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SysWOW64\XAudio2_4.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SysWOW64\XAPOFX1_3.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SysWOW64\xactengine3_4.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SysWOW64\X3DAudio1_6.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SysWOW64\d3dx10_40.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SysWOW64\D3DCompiler_40.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SysWOW64\XAudio2_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SysWOW64\XAPOFX1_2.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SysWOW64\xactengine3_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SysWOW64\X3DAudio1_5.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SysWOW64\D3DX9_40.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SysWOW64\XAudio2_2.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SysWOW64\XAPOFX1_1.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SysWOW64\xactengine3_2.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SysWOW64\D3DX9_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SysWOW64\d3dx10_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SysWOW64\D3DCompiler_39.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SysWOW64\XAudio2_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SysWOW64\XAPOFX1_0.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SysWOW64\xactengine3_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SysWOW64\X3DAudio1_4.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SysWOW64\D3DX9_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SysWOW64\d3dx10_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SysWOW64\D3DCompiler_38.dll
2012-11-01 08:41:27 ----A---- C:\Windows\SysWOW64\XAudio2_0.dll
2012-11-01 08:41:27 ----A---- C:\Windows\SysWOW64\xactengine3_0.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SysWOW64\X3DAudio1_3.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SysWOW64\d3dx10_37.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SysWOW64\D3DCompiler_37.dll
2012-11-01 08:41:25 ----A---- C:\Windows\SysWOW64\xactengine2_10.dll
2012-11-01 08:41:25 ----A---- C:\Windows\SysWOW64\D3DX9_37.dll
2012-11-01 08:41:24 ----A---- C:\Windows\SysWOW64\d3dx10_36.dll
2012-11-01 08:41:24 ----A---- C:\Windows\SysWOW64\D3DCompiler_36.dll
2012-11-01 08:41:23 ----A---- C:\Windows\SysWOW64\xactengine2_9.dll
2012-11-01 08:41:23 ----A---- C:\Windows\SysWOW64\d3dx9_36.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SysWOW64\d3dx9_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SysWOW64\d3dx10_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SysWOW64\D3DCompiler_35.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SysWOW64\xactengine2_8.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SysWOW64\X3DAudio1_2.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SysWOW64\d3dx10_34.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SysWOW64\D3DCompiler_34.dll
2012-11-01 08:41:20 ----A---- C:\Windows\SysWOW64\d3dx9_34.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SysWOW64\xactengine2_7.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SysWOW64\d3dx10_33.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SysWOW64\D3DCompiler_33.dll
2012-11-01 08:41:18 ----A---- C:\Windows\SysWOW64\xactengine2_6.dll
2012-11-01 08:41:17 ----A---- C:\Windows\SysWOW64\xactengine2_5.dll
2012-11-01 08:41:17 ----A---- C:\Windows\SysWOW64\d3dx10.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SysWOW64\xactengine2_4.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SysWOW64\x3daudio1_1.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SysWOW64\d3dx9_32.dll
2012-11-01 08:41:15 ----A---- C:\Windows\SysWOW64\d3dx9_31.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SysWOW64\xinput1_2.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SysWOW64\xactengine2_3.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SysWOW64\xactengine2_2.dll
2012-11-01 08:41:08 ----A---- C:\Windows\SysWOW64\xactengine2_0.dll
2012-11-01 08:41:07 ----A---- C:\Windows\SysWOW64\d3dx9_29.dll
2012-11-01 08:41:07 ----A---- C:\Windows\SysWOW64\d3dx9_28.dll
2012-11-01 08:41:06 ----A---- C:\Windows\SysWOW64\d3dx9_27.dll
2012-11-01 08:41:06 ----A---- C:\Windows\SysWOW64\d3dx9_26.dll
2012-11-01 08:41:05 ----A---- C:\Windows\SysWOW64\d3dx9_25.dll
2012-11-01 08:41:04 ----A---- C:\Windows\SysWOW64\d3dx9_24.dll
2012-10-30 16:07:15 ----D---- C:\Users\Nasgharet\AppData\Roaming\Sun
2012-10-25 15:10:42 ----D---- C:\Program Files (x86)\VodBurner
2012-10-18 22:34:46 ----D---- C:\Program Files (x86)\Common Files\Steam
2012-10-18 22:34:45 ----D---- C:\Program Files (x86)\Steam
2012-10-18 10:01:15 ----D---- C:\Users\Nasgharet\AppData\Roaming\.minecraft
2012-10-18 09:37:10 ----D---- C:\Users\Nasgharet\AppData\Roaming\.techniclauncher

======List of files/folders modified in the last 1 month======

2012-12-20 16:42:22 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-20 16:02:29 ----SD---- C:\Users\Nasgharet\AppData\Roaming\Microsoft
2012-11-17 01:18:30 ----D---- C:\Windows\Prefetch
2012-11-17 01:18:29 ----D---- C:\Windows\Temp
2012-11-17 01:18:26 ----RD---- C:\Program Files (x86)
2012-11-16 23:51:03 ----D---- C:\Windows\SysWOW64
2012-11-16 23:51:01 ----SHD---- C:\Windows\Installer
2012-11-16 23:51:01 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2012-11-16 15:20:25 ----D---- C:\Users\Nasgharet\AppData\Roaming\vlc
2012-11-16 15:01:46 ----D---- C:\Windows\System32
2012-11-16 15:01:46 ----D---- C:\Windows\inf
2012-11-16 14:56:23 ----D---- C:\Users\Nasgharet\AppData\Roaming\ICQ
2012-11-16 14:53:29 ----D---- C:\Windows\winsxs
2012-11-16 14:51:25 ----D---- C:\Windows
2012-11-16 14:51:02 ----RSD---- C:\Windows\assembly
2012-11-16 14:50:17 ----HD---- C:\ProgramData
2012-11-16 14:50:17 ----D---- C:\Program Files (x86)\Common Files
2012-11-16 14:50:16 ----D---- C:\Windows\Cursors
2012-11-16 14:49:34 ----SHD---- C:\System Volume Information
2012-11-16 14:20:00 ----D---- C:\Users\Nasgharet\AppData\Roaming\Azureus
2012-11-15 09:12:00 ----D---- C:\Users\Nasgharet\AppData\Roaming\Skype
2012-11-01 08:41:11 ----D---- C:\Windows\Microsoft.NET

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys []
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys []
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-11-15 2461104]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-07 114144]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-02 529744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 08:49
od Márty84
Zdravim :)

To slovo na K se nerika Bohušu :evil:

:arrow: Odinstalujte Akamai
:arrow: Dejte sem log z RSIT pro 64bit system http://images.malwareremoval.com/random/RSITx64.exe

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 10:14
od BlackAngel
Promiňte, měl jsem včera už opravdu hodně popito. Prostě mě jen zaráží, jak drze se mnou teď někdo zametá. A začínám se bát o internetové bankovnictví
a další účty. Včera v noci pokus o změnu mého accountu u blizzardu.....po změně všech hesel na emailu atd.....večer další pokus. To je vážně hrozné tohle. :(
Dávám log.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Nasgharet at 2012-11-17 10:09:17
Microsoft Windows 7 Home Premium
System drive C: has 29 GB (29%) free of 100 GB
Total RAM: 4095 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:09:24, on 17.11.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Program Files\trend micro\Nasgharet.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Aeria Ignite] "C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe" silent
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7M\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [AppVodBurner] C:\Program Files (x86)\VodBurner\vodburner.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: PokerStars.be - {878AC5FC-BE78-4bae-896C-7F75B790A71E} - C:\Program Files (x86)\PokerStars.BE\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9116 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe"
"C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe" -Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "http://www.aeriagames.com/playnow/dkus/ ... ium=DKO_CB"
"C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "D:\---Serials---\Joey\2.serie\Joey 02x04.avi"
"taskhost.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3212.c1fcb60.581632748 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll" E7CF176E110C211B -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" 3212 "\\.\pipe\gecko-crash-server-pipe.3212" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe" --proxy-stub-channel=Flash1972.613FF168.41 --host-broker-channel=Flash1972.613FF168.18467 --host-pid=1972 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe" --channel=884.0017F82C.138059378 --proxy-stub-channel=Flash1972.613FF168.41 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll" --host-npapi-version=27 --type=renderer
"C:\totalcmd\TOTALCMD64.EXE"
"C:\Users\Nasgharet\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe"
"D:\---Download---\RSITx64(2).exe"
C:\Windows\system32\wbem\wmiprvse.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Nasgharet\AppData\Roaming\Mozilla\Firefox\Profiles\1kc8j041.default-1348185830213

prefs.js - "browser.startup.homepage" - "http://www.google.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-05 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-05 157672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-06-11 12503184]
"AutoKMS"=C:\Windows\AutoKMS.exe [2012-09-05 615936]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-11 3672384]
"ICQ"=C:\Program Files (x86)\ICQ7M\ICQ.exe [2012-09-05 127040]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2012-10-18 1353080]
"AppVodBurner"=C:\Program Files (x86)\VodBurner\vodburner.exe [2012-10-22 4688896]
"Akamai NetSession Interface"=C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"Aeria Ignite"=C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [2012-09-10 1411224]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2012-11-15 2254768]
"NBKeyScan"=C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-12-20 16:54:04 ----A---- C:\Windows\SYSWOW64\npptNT2.sys
2012-12-20 16:41:25 ----D---- C:\Users\Nasgharet\AppData\Roaming\InstallShield
2012-11-17 01:18:26 ----D---- C:\Program Files (x86)\trend micro
2012-11-16 23:51:03 ----D---- C:\Windows\SYSWOW64\directx
2012-11-16 14:59:16 ----D---- C:\Users\Nasgharet\AppData\Roaming\Nero
2012-11-16 14:51:25 ----A---- C:\Windows\Irremote.ini
2012-11-16 14:50:17 ----D---- C:\ProgramData\Nero
2012-11-16 14:50:17 ----D---- C:\Program Files (x86)\Nero
2012-11-16 14:42:23 ----AH---- C:\Windows\system32\hamachi.sys
2012-11-16 14:42:19 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2012-11-16 08:11:55 ----D---- C:\ProgramData\Aeria Games
2012-11-16 08:08:22 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2012-11-16 08:08:22 ----D---- C:\Program Files (x86)\Aeria Games
2012-11-16 01:11:14 ----D---- C:\AeriaGames
2012-11-07 10:02:36 ----D---- C:\Program Files (x86)\PokerStars.BE
2012-11-07 09:48:00 ----D---- C:\Program Files (x86)\Full Tilt Poker
2012-11-01 08:41:46 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-11-01 08:41:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-11-01 08:41:46 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-11-01 08:41:46 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-11-01 08:41:46 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-11-01 08:41:46 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-11-01 08:41:45 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-11-01 08:41:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-11-01 08:41:45 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-11-01 08:41:45 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-11-01 08:41:43 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-11-01 08:41:43 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-11-01 08:41:42 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-11-01 08:41:42 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-11-01 08:41:41 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-11-01 08:41:41 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-11-01 08:41:40 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-11-01 08:41:40 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-11-01 08:41:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-11-01 08:41:39 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-11-01 08:41:36 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-11-01 08:41:36 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-11-01 08:41:36 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-11-01 08:41:36 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-11-01 08:41:35 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-11-01 08:41:34 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-11-01 08:41:34 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-11-01 08:41:34 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-11-01 08:41:33 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-11-01 08:41:33 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-11-01 08:41:33 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-11-01 08:41:31 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-11-01 08:41:31 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-11-01 08:41:31 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-11-01 08:41:29 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-11-01 08:41:29 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-11-01 08:41:27 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-11-01 08:41:27 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-11-01 08:41:27 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-11-01 08:41:27 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-11-01 08:41:26 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-11-01 08:41:26 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-11-01 08:41:26 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-11-01 08:41:25 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-11-01 08:41:25 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-11-01 08:41:25 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-11-01 08:41:25 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-11-01 08:41:24 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-11-01 08:41:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-11-01 08:41:24 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-11-01 08:41:24 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-11-01 08:41:23 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-11-01 08:41:23 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-11-01 08:41:23 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-11-01 08:41:23 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-11-01 08:41:21 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-11-01 08:41:21 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-11-01 08:41:21 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-11-01 08:41:21 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-11-01 08:41:20 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-11-01 08:41:20 ----A---- C:\Windows\system32\xinput1_3.dll
2012-11-01 08:41:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-11-01 08:41:19 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-11-01 08:41:19 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-11-01 08:41:19 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-11-01 08:41:18 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-11-01 08:41:18 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-11-01 08:41:18 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-11-01 08:41:17 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-11-01 08:41:17 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-11-01 08:41:17 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-11-01 08:41:17 ----A---- C:\Windows\system32\d3dx10.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-11-01 08:41:16 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-11-01 08:41:16 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-11-01 08:41:16 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-11-01 08:41:15 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-11-01 08:41:15 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-11-01 08:41:14 ----A---- C:\Windows\system32\xinput1_2.dll
2012-11-01 08:41:14 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-11-01 08:41:14 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-11-01 08:41:08 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-11-01 08:41:08 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-11-01 08:41:07 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-11-01 08:41:07 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-11-01 08:41:07 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-11-01 08:41:07 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-11-01 08:41:06 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-11-01 08:41:06 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-11-01 08:41:06 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-11-01 08:41:06 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-11-01 08:41:05 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2012-11-01 08:41:05 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-11-01 08:41:04 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-11-01 08:41:04 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-10-30 16:07:15 ----D---- C:\Users\Nasgharet\AppData\Roaming\Sun
2012-10-25 15:10:42 ----D---- C:\Program Files (x86)\VodBurner
2012-10-18 22:34:45 ----D---- C:\Program Files (x86)\Steam
2012-10-18 10:01:15 ----D---- C:\Users\Nasgharet\AppData\Roaming\.minecraft
2012-10-18 09:37:10 ----D---- C:\Users\Nasgharet\AppData\Roaming\.techniclauncher

======List of files/folders modified in the last 1 month======

2012-12-20 16:42:22 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-20 16:02:29 ----SD---- C:\Users\Nasgharet\AppData\Roaming\Microsoft
2012-11-17 10:09:24 ----D---- C:\Windows\Prefetch
2012-11-17 10:09:23 ----D---- C:\Program Files\trend micro
2012-11-17 10:09:22 ----D---- C:\Windows\Temp
2012-11-17 01:18:26 ----RD---- C:\Program Files (x86)
2012-11-17 01:15:30 ----D---- C:\Users\Nasgharet\AppData\Roaming\ICQ
2012-11-16 23:51:03 ----D---- C:\Windows\SysWOW64
2012-11-16 23:51:02 ----SHD---- C:\Windows\Installer
2012-11-16 18:46:30 ----D---- C:\Windows\system32\config
2012-11-16 15:20:25 ----D---- C:\Users\Nasgharet\AppData\Roaming\vlc
2012-11-16 15:01:46 ----D---- C:\Windows\System32
2012-11-16 15:01:46 ----D---- C:\Windows\inf
2012-11-16 15:01:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-11-16 14:53:29 ----D---- C:\Windows\winsxs
2012-11-16 14:51:25 ----D---- C:\Windows
2012-11-16 14:51:02 ----RSD---- C:\Windows\assembly
2012-11-16 14:50:17 ----HD---- C:\ProgramData
2012-11-16 14:50:17 ----D---- C:\Program Files (x86)\Common Files
2012-11-16 14:50:16 ----D---- C:\Windows\Cursors
2012-11-16 14:49:34 ----SHD---- C:\System Volume Information
2012-11-16 14:20:00 ----D---- C:\Users\Nasgharet\AppData\Roaming\Azureus
2012-11-15 09:12:00 ----D---- C:\Users\Nasgharet\AppData\Roaming\Skype
2012-11-01 08:41:11 ----D---- C:\Windows\Microsoft.NET

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-13 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-13 214096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-05 283200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-13 59904]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-27 10278912]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-27 368640]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-19 1394688]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-05-13 96896]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-12 4060560]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys []
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys []
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-13 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-27 239616]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-11-15 2461104]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-07 114144]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-02 529744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 10:38
od cernohous13
Márty84 píše: To slovo na K se nerika Bohušu :evil:
:?: Já zatím nic neříkal.
Nerušeně pokračujte :D

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 12:02
od Márty84
cernohous13 píše: :?: Já zatím nic neříkal.
Nerušeně pokračujte :D
:lol: To jsem si nejak v te chvili neuvedomil :arcisit:

-------------------------------------------------------------------------------------------------------------------
BlackAngel píše:To je vážně hrozné tohle. :(
A cemu se divite? Stahujete cracky (nelegalni office) a nemate ani antivir. To je potom jen otazka casu, nez se neco stane.

:!: :arrow: Pokud chcete pomoct, office odinstalujte. Je mi jasne, ze ho tam pak narvete zpatky, ale pravidla fora hovori jasne.

:arrow: Pak sem dejte novy log z RSIT

:arrow: Udelejte !!!uplnou!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 16:00
od BlackAngel
Office mam legalne, ale mam je doma v CR.....ted jsem uz rok v belgii kde studuju a nejak pracovat musim.
Ale odinstaloval jsem je. Antivir je tomto pocitaci NEPOUZITELNY. Jsem si vedom, ze je to ma chyba. Tady je log.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Nasgharet at 2012-11-17 15:55:15
Microsoft Windows 7 Home Premium
System drive C: has 34 GB (34%) free of 100 GB
Total RAM: 4095 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:55:22, on 17.11.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Program Files\trend micro\Nasgharet.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Aeria Ignite] "C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe" silent
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7M\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [AppVodBurner] C:\Program Files (x86)\VodBurner\vodburner.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra button: PokerStars.be - {878AC5FC-BE78-4bae-896C-7F75B790A71E} - C:\Program Files (x86)\PokerStars.BE\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8320 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe"
"C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe"
"C:/Users/Nasgharet/AppData/Local/Akamai/netsession_win.exe" --client
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe" silent
"C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 504 508 516 65536 512
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=308.5931980.136348956 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll" E7CF176E110C211B -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" 308 "\\.\pipe\gecko-crash-server-pipe.308" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe" --proxy-stub-channel=Flash2436.6725F168.41 --host-broker-channel=Flash2436.6725F168.18467 --host-pid=2436 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe" --channel=1920.0040F16C.405665643 --proxy-stub-channel=Flash2436.6725F168.41 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll" --host-npapi-version=27 --type=renderer
"D:\---Download---\RSITx64(3).exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\Nasgharet\AppData\Roaming\Mozilla\Firefox\Profiles\1kc8j041.default-1348185830213

prefs.js - "browser.startup.homepage" - "http://www.google.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-05 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-05 157672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-06-11 12503184]
"AutoKMS"=C:\Windows\AutoKMS.exe [2012-09-05 615936]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-11 3672384]
"ICQ"=C:\Program Files (x86)\ICQ7M\ICQ.exe [2012-09-05 127040]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2012-10-18 1353080]
"AppVodBurner"=C:\Program Files (x86)\VodBurner\vodburner.exe [2012-10-22 4688896]
"Akamai NetSession Interface"=C:\Users\Nasgharet\AppData\Local\Akamai\netsession_win.exe [2012-10-09 4441920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"Aeria Ignite"=C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [2012-09-10 1411224]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2012-11-15 2254768]
"NBKeyScan"=C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-12-20 16:54:04 ----A---- C:\Windows\SYSWOW64\npptNT2.sys
2012-12-20 16:41:25 ----D---- C:\Users\Nasgharet\AppData\Roaming\InstallShield
2012-11-17 15:45:47 ----SHD---- C:\Config.Msi
2012-11-17 01:18:26 ----D---- C:\Program Files (x86)\trend micro
2012-11-16 23:51:03 ----D---- C:\Windows\SYSWOW64\directx
2012-11-16 14:59:16 ----D---- C:\Users\Nasgharet\AppData\Roaming\Nero
2012-11-16 14:51:25 ----A---- C:\Windows\Irremote.ini
2012-11-16 14:50:17 ----D---- C:\ProgramData\Nero
2012-11-16 14:50:17 ----D---- C:\Program Files (x86)\Nero
2012-11-16 14:42:23 ----AH---- C:\Windows\system32\hamachi.sys
2012-11-16 14:42:19 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2012-11-16 08:11:55 ----D---- C:\ProgramData\Aeria Games
2012-11-16 08:08:22 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2012-11-16 08:08:22 ----D---- C:\Program Files (x86)\Aeria Games
2012-11-16 01:11:14 ----D---- C:\AeriaGames
2012-11-07 10:02:36 ----D---- C:\Program Files (x86)\PokerStars.BE
2012-11-07 09:48:00 ----D---- C:\Program Files (x86)\Full Tilt Poker
2012-11-01 08:41:46 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-11-01 08:41:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-11-01 08:41:46 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-11-01 08:41:46 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-11-01 08:41:46 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-11-01 08:41:46 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-11-01 08:41:45 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-11-01 08:41:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-11-01 08:41:45 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-11-01 08:41:45 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-11-01 08:41:44 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-11-01 08:41:43 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-11-01 08:41:43 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-11-01 08:41:42 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-11-01 08:41:42 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-11-01 08:41:41 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-11-01 08:41:41 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-11-01 08:41:40 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-11-01 08:41:40 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-11-01 08:41:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-11-01 08:41:39 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-11-01 08:41:38 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-11-01 08:41:37 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-11-01 08:41:36 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-11-01 08:41:36 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-11-01 08:41:36 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-11-01 08:41:36 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-11-01 08:41:35 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-11-01 08:41:34 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-11-01 08:41:34 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-11-01 08:41:34 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-11-01 08:41:34 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-11-01 08:41:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-11-01 08:41:33 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-11-01 08:41:33 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-11-01 08:41:33 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-11-01 08:41:32 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-11-01 08:41:32 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-11-01 08:41:31 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-11-01 08:41:31 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-11-01 08:41:31 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-11-01 08:41:31 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-11-01 08:41:30 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-11-01 08:41:29 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-11-01 08:41:29 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-11-01 08:41:29 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-11-01 08:41:28 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-11-01 08:41:27 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-11-01 08:41:27 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-11-01 08:41:27 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-11-01 08:41:27 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-11-01 08:41:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-11-01 08:41:26 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-11-01 08:41:26 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-11-01 08:41:26 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-11-01 08:41:25 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-11-01 08:41:25 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-11-01 08:41:25 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-11-01 08:41:25 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-11-01 08:41:24 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-11-01 08:41:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-11-01 08:41:24 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-11-01 08:41:24 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-11-01 08:41:23 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-11-01 08:41:23 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-11-01 08:41:23 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-11-01 08:41:23 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-11-01 08:41:22 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2012-11-01 08:41:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2012-11-01 08:41:21 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-11-01 08:41:21 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-11-01 08:41:21 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-11-01 08:41:21 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-11-01 08:41:20 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2012-11-01 08:41:20 ----A---- C:\Windows\system32\xinput1_3.dll
2012-11-01 08:41:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2012-11-01 08:41:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2012-11-01 08:41:19 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-11-01 08:41:19 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-11-01 08:41:19 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-11-01 08:41:18 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2012-11-01 08:41:18 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-11-01 08:41:18 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-11-01 08:41:17 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2012-11-01 08:41:17 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2012-11-01 08:41:17 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-11-01 08:41:17 ----A---- C:\Windows\system32\d3dx10.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2012-11-01 08:41:16 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2012-11-01 08:41:16 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-11-01 08:41:16 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-11-01 08:41:16 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-11-01 08:41:15 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2012-11-01 08:41:15 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2012-11-01 08:41:14 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2012-11-01 08:41:14 ----A---- C:\Windows\system32\xinput1_2.dll
2012-11-01 08:41:14 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-11-01 08:41:14 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-11-01 08:41:08 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2012-11-01 08:41:08 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-11-01 08:41:07 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2012-11-01 08:41:07 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2012-11-01 08:41:07 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-11-01 08:41:07 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-11-01 08:41:06 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2012-11-01 08:41:06 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2012-11-01 08:41:06 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-11-01 08:41:06 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-11-01 08:41:05 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2012-11-01 08:41:05 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-11-01 08:41:04 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2012-11-01 08:41:04 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-10-30 16:07:15 ----D---- C:\Users\Nasgharet\AppData\Roaming\Sun
2012-10-25 15:10:42 ----D---- C:\Program Files (x86)\VodBurner
2012-10-18 22:34:45 ----D---- C:\Program Files (x86)\Steam
2012-10-18 10:01:15 ----D---- C:\Users\Nasgharet\AppData\Roaming\.minecraft
2012-10-18 09:37:10 ----D---- C:\Users\Nasgharet\AppData\Roaming\.techniclauncher

======List of files/folders modified in the last 1 month======

2012-12-20 16:42:22 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-20 16:02:29 ----SD---- C:\Users\Nasgharet\AppData\Roaming\Microsoft
2012-11-17 15:55:21 ----D---- C:\Windows\Temp
2012-11-17 15:55:21 ----D---- C:\Program Files\trend micro
2012-11-17 15:55:14 ----D---- C:\Windows\Prefetch
2012-11-17 15:53:31 ----D---- C:\Users\Nasgharet\AppData\Roaming\ICQ
2012-11-17 15:49:47 ----D---- C:\Windows\Microsoft.NET
2012-11-17 15:49:44 ----SHD---- C:\Windows\Installer
2012-11-17 15:49:28 ----D---- C:\ProgramData\Microsoft Help
2012-11-17 15:49:27 ----RSD---- C:\Windows\assembly
2012-11-17 15:48:38 ----SD---- C:\ProgramData\Microsoft
2012-11-17 15:48:38 ----RD---- C:\Program Files (x86)
2012-11-17 15:48:38 ----RD---- C:\Program Files
2012-11-17 15:48:38 ----D---- C:\Windows
2012-11-17 15:48:38 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-11-17 15:48:38 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-11-17 15:48:23 ----RSD---- C:\Windows\Fonts
2012-11-17 15:48:18 ----D---- C:\Program Files (x86)\MSBuild
2012-11-17 15:48:16 ----D---- C:\Windows\System32
2012-11-17 15:48:16 ----D---- C:\Program Files\Common Files
2012-11-17 15:47:04 ----D---- C:\Windows\ShellNew
2012-11-17 15:46:52 ----D---- C:\Program Files\Common Files\System
2012-11-17 15:46:52 ----A---- C:\Windows\win.ini
2012-11-17 15:45:57 ----D---- C:\Windows\system32\config
2012-11-17 15:45:38 ----SHD---- C:\System Volume Information
2012-11-16 23:51:03 ----D---- C:\Windows\SysWOW64
2012-11-16 15:20:25 ----D---- C:\Users\Nasgharet\AppData\Roaming\vlc
2012-11-16 15:01:46 ----D---- C:\Windows\inf
2012-11-16 15:01:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-11-16 14:53:29 ----D---- C:\Windows\winsxs
2012-11-16 14:50:17 ----HD---- C:\ProgramData
2012-11-16 14:50:17 ----D---- C:\Program Files (x86)\Common Files
2012-11-16 14:50:16 ----D---- C:\Windows\Cursors
2012-11-16 14:20:00 ----D---- C:\Users\Nasgharet\AppData\Roaming\Azureus
2012-11-15 09:12:00 ----D---- C:\Users\Nasgharet\AppData\Roaming\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-13 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-13 214096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-05 283200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-13 59904]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-27 10278912]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-27 368640]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-19 1394688]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-05-13 96896]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-12 4060560]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys []
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys []
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-13 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-27 239616]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-11-15 2461104]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-07 114144]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-02 529744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 16:54
od tuvok07
Promiň za vstup Márty ale nedalo mi to :D
To jste si nemohl vzít do Belgie ty legální Office s sebou? Případně si můžete nechat originálku poslat poštou. Nebo vám pošlou SMSkou klíč.
Nechápu, proč by měl být antivir na tom PC nepoužitelný, zase taková plečka to nebude když utáhne WOW či jinou hru :?: Takový Avast by tam jít měl.

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 17:33
od Márty84
Office komentovat nebudu, kolega to uz napsal :)

Pocitac je dost vykonny na antivir. Pokud je to s nim pomale, bude problem nekde jinde. Cistit pc, ktere stejne nebude zabezpecene, je ztrata casu. Sam jste zjistil, ze je to otazka nekolika dnu, nez si vas zase nekdo najde a slohne vam hesla.

Uvidime, co najde MBAM, podle toho budeme pokracovat.

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 17:49
od BlackAngel
Jednoduchá odpoveď..... cca pred trema mesici jsem prisel o disk. Winy jsem si stahl, i kdyz anglicke, kod je ze spodni strany notebooku. CD s Officama je ale jaksi fyzicky doma a navic ve skrini, ve ktere urcite nechci aby se mi hrabala matka :) Posilat to rohodne nebudu....zbytecnych 240 kc za postu. Navic myslim ze muzu mit klidne cracknute offici, protoze v pripade kontroly jsem schopen dolozit licenci a to dokonce hned dvakrat. Mam skolni licenci z VSB a vlastni. Za druhe, pocitac cistim kompresorem tak jednou za 2 mesice a jednou za pul roku menim pastu. Proste fyzicky je v tom pocitaci neco v neporadku. Wowko je to jedine co na tomto jeste spustim a to rikam ze v minimalni grafice....vubec nejhorsi moznosti a to se to jeste obcas krpe. Pokud si naistaluju napriklad avasta a chci hrat, krpe se to uz uplne. Pri hre dokonce shazuji proces explorer. Pocitac uz bohuzel neni v zaruce a ja tady nehodlam platit za jeho opravu. A to abzvlaste kdyz je uz utrzeny pravy roh od dispeleje (spojnice display a klavesnice) a jen cekam kdy zhasne uplne. Proste tohle pujde casem na odpis. Doma mam jeste stolni se kterym budu muset vystacit. Uz ja vam to jasnejsi panové? :)

Re: prosim o kontrolu logu

Napsal: 17 lis 2012 18:23
od Márty84
Jak jsem rekl, office neresim, to je mi jedno.

Ovsem budete se muset rozhodnout, jestli investujete do opravy pc (pokud je to HW problem), nebo se rozloucite s heslama.

Odvirovat ho muzem, ale proste je to zase jen na par dnu :?:

Re: prosim o kontrolu logu

Napsal: 18 lis 2012 09:32
od BlackAngel
No já to chci urcite resit....jsem ochoten i radeji prestat hrat a naistalovat si antivir. Cekam co poradite. :)

Re: prosim o kontrolu logu

Napsal: 18 lis 2012 09:40
od Márty84
BlackAngel píše:Cekam co poradite. :)
No, ja stale cekam na ten log z MBAM :James008:

Re: prosim o kontrolu logu

Napsal: 18 lis 2012 18:04
od BlackAngel
Jo, aha....tak musite dat nejaky odkaz nebo vysvetleni co to vubec MBAM je :D Ja jsem to dal vyhledat pres google a naslo mi to neco u vas ve foru,
tak jsem klikl na link...stahlo to nejake ARO 2012. Skenovalo to a napsalo 413 cbyb....100 jich to opravilo, zbytek bych musel pry zaplatit. Nemohl jsem ale najit nejaky vystup ve forme logu.

Re: prosim o kontrolu logu

Napsal: 18 lis 2012 18:20
od tuvok07
Vyhledávání na fóru funguje dobře - a nehápu proč jste tahal takovou blbost když i z google vede první odkaz sem
http://forum.viry.cz/viewtopic.php?f=29&t=115222

Re: prosim o kontrolu logu

Napsal: 18 lis 2012 18:58
od BlackAngel
No ja teda nevim, kam vede odkaz vas....ale me veda takto: http://forum.viry.cz/viewtopic.php?t=115222 -->> http://www.malwarebytes.org/ a tlacitko download now jaksi nevidim, ale vidim free download. Tak si ho zkuste a uvidite sam, co si nasitalujete. V kaydem pripade ja jsem na tom pracoval hned po vloyeni prispevku znovu, akorat kontrola trvala 45 minut.

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Verze databáze: v2012.11.18.02

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Nasgharet :: BLACKANGEL [administrátor]

18.11.2012 18:08:09
mbam-log-2012-11-18 (18-50-48).txt

Typ: Úplná kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 339597
Uplynulý čas: 42 minut, 23 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 6
C:\Windows\AutoKMS.exe (Riskware.Keygen) -> Žádná instrukce nebyla provedena.
D:\---Download---\---Vuze Download---\Nero 8 FULL CZ\nero-8.x-keygen\Nero 8.x KeyGen.exe (RiskWare.Tool.CK) -> Žádná instrukce nebyla provedena.
D:\---Games--\---ISO---\TERA_EURO\Client\Binaries\TERA.exe (VirTool.Vbcrypt) -> Žádná instrukce nebyla provedena.
D:\---Games--\L2 - Gracia final\system\msxml4b.dll (Spyware.Agent) -> Žádná instrukce nebyla provedena.
D:\---Games--\L2 - Gracia final\system\msxml4c.dll (Trojan.Spy.Agent) -> Žádná instrukce nebyla provedena.
D:\---Games--\Super Meat Boy\Uninstall.exe (Malware.Packer.Krunchy) -> Žádná instrukce nebyla provedena.

(konec)