
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Modrá smrt při zapnutí pc
Moderátor: Moderátoři
Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Modrá smrt při zapnutí pc
Zdravím vás,
modrá smrt se mi objeví vždycky po zapnutí pc. Někdy již po startu při nabíhání nebo pár minut či sekund po naběhnutí Windows. Pokud Windows již naběhl obrazovka zčerná a pomůže jedině restart. Po restartu běží všechno hladce a bez problémů. Také se stává že, počítač normálně běží bez problémů ale pak, bez toho, aniž bych na něm pracoval, počítač spadne.
Zde přikládám Minidump:
http://leteckaposta.cz/151100196
modrá smrt se mi objeví vždycky po zapnutí pc. Někdy již po startu při nabíhání nebo pár minut či sekund po naběhnutí Windows. Pokud Windows již naběhl obrazovka zčerná a pomůže jedině restart. Po restartu běží všechno hladce a bez problémů. Také se stává že, počítač normálně běží bez problémů ale pak, bez toho, aniž bych na něm pracoval, počítač spadne.
Zde přikládám Minidump:
http://leteckaposta.cz/151100196
- Rudy
- Site Admin
- Příspěvky: 119488
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrt při zapnutí pc
Zdravím!
Nejprve zkontrolujeme disk. Stáhněte, nainstalujte a spusťte CrystalDiskInfo: http://www.stahuj.centrum.cz/utility_a_ ... ldiskinfo/ a přes Úpravy>kopírovat sem dejte log.
Nejprve zkontrolujeme disk. Stáhněte, nainstalujte a spusťte CrystalDiskInfo: http://www.stahuj.centrum.cz/utility_a_ ... ldiskinfo/ a přes Úpravy>kopírovat sem dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Modrá smrt při zapnutí pc
----------------------------------------------------------------------------
CrystalDiskInfo 5.2.0 Shizuku Edition (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------
OS : Windows 7 Home Premium Edition SP1 [6.1 Build 7601] (x64)
Date : 2012/12/28 19:00:23
-- Controller Map ----------------------------------------------------------
+ Intel(R) 5 Series/3400 Series Chipset Family 4 port Serial ATA Storage Controller - 3B20 [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Intel(R) 5 Series/3400 Series Chipset Family 2 port Serial ATA Storage Controller - 3B26 [ATA]
- ATA Channel 0 (0)
+ ATA Channel 1 (1)
- HL-DT-ST DVDRAM GH22LS50 ATA Device
+ PCI Standardní dvoukanálový řadič IDE [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Marvell 91xx SATA 6G Controller [SCSI]
- WDC WD10 EALX-009BA0 SCSI Disk Device
- Marvell 91xx Config Device
-- Disk List ---------------------------------------------------------------
(1) WDC WD10EALX-009BA0 : 1000,2 GB [0/6/0, pd1] - wd
----------------------------------------------------------------------------
(1) WDC WD10EALX-009BA0
----------------------------------------------------------------------------
Model : WDC WD10EALX-009BA0
Firmware : 15.01H15
Serial Number : WD-WCATR4129596
Disk Size : 1000,2 GB (8,4/137,4/1000,2)
Buffer Size : 32767 KB
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : SATA/600
Power On Hours : 6019 hod.
Power On Count : 1708 krát
Temparature : 36 C (96 F)
Health Status : Dobrý
Features : S.M.A.R.T., AAM, 48bit LBA, NCQ
APM Level : ----
AAM Level : 80FEh [OFF]
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 179 175 _21 000000000FB9 Čas na roztočení ploten
04 _98 _98 __0 00000000097D Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 __0 000000000000 Počet chybných hledání
09 _92 _92 __0 000000001783 Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _99 _99 __0 0000000006AC Počet cyklů zapnutí zařízení
C0 200 200 __0 000000000246 Počet vypnutí disku
C1 200 200 __0 000000000736 Počet cyklů načítání/vymazání
C2 111 103 __0 000000000024 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 200 200 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000003 Počet chyb v kontrolním součtu UltraDMA
C8 200 200 __0 000000000000 Počet chyb při zápisu sektorů
-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5743 4154 5234 3132 3935 3936
020: 0000 FFFF 0032 3135 2E30 3148 3135 5744 4320 5744
030: 3130 4541 4C58 2D30 3039 4241 3020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 170E 0000 0044 0040
080: 01FE 0000 746B 7F61 4123 7469 BC41 4123 407F 0056
090: 0056 0000 FFFE 0000 80FE 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0000 0000 0000 5001 4EE2
110: 5A77 D16A 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0021 0000
130: 0000 0000 0000 16E2 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 3037 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 E5A5
-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 B3 AF B9 0F 00 00 00 00 00 04 32 00 62 62 7D
020: 09 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 5C 5C 83 17 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 63 63 AC 06 00 00 00 00 00 C0 32
070: 00 C8 C8 46 02 00 00 00 00 00 C1 32 00 C8 C8 36
080: 07 00 00 00 00 00 C2 22 00 6F 67 24 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 C8 C8 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 03 00 00 00 00
0C0: 00 00 C8 08 00 C8 C8 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 84 00 54 42 01 7B
170: 03 00 01 00 02 C4 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 32
-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 C8 C8 C8 C8 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5D
CrystalDiskInfo 5.2.0 Shizuku Edition (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------
OS : Windows 7 Home Premium Edition SP1 [6.1 Build 7601] (x64)
Date : 2012/12/28 19:00:23
-- Controller Map ----------------------------------------------------------
+ Intel(R) 5 Series/3400 Series Chipset Family 4 port Serial ATA Storage Controller - 3B20 [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Intel(R) 5 Series/3400 Series Chipset Family 2 port Serial ATA Storage Controller - 3B26 [ATA]
- ATA Channel 0 (0)
+ ATA Channel 1 (1)
- HL-DT-ST DVDRAM GH22LS50 ATA Device
+ PCI Standardní dvoukanálový řadič IDE [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Marvell 91xx SATA 6G Controller [SCSI]
- WDC WD10 EALX-009BA0 SCSI Disk Device
- Marvell 91xx Config Device
-- Disk List ---------------------------------------------------------------
(1) WDC WD10EALX-009BA0 : 1000,2 GB [0/6/0, pd1] - wd
----------------------------------------------------------------------------
(1) WDC WD10EALX-009BA0
----------------------------------------------------------------------------
Model : WDC WD10EALX-009BA0
Firmware : 15.01H15
Serial Number : WD-WCATR4129596
Disk Size : 1000,2 GB (8,4/137,4/1000,2)
Buffer Size : 32767 KB
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : SATA/600
Power On Hours : 6019 hod.
Power On Count : 1708 krát
Temparature : 36 C (96 F)
Health Status : Dobrý
Features : S.M.A.R.T., AAM, 48bit LBA, NCQ
APM Level : ----
AAM Level : 80FEh [OFF]
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 179 175 _21 000000000FB9 Čas na roztočení ploten
04 _98 _98 __0 00000000097D Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 __0 000000000000 Počet chybných hledání
09 _92 _92 __0 000000001783 Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _99 _99 __0 0000000006AC Počet cyklů zapnutí zařízení
C0 200 200 __0 000000000246 Počet vypnutí disku
C1 200 200 __0 000000000736 Počet cyklů načítání/vymazání
C2 111 103 __0 000000000024 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 200 200 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000003 Počet chyb v kontrolním součtu UltraDMA
C8 200 200 __0 000000000000 Počet chyb při zápisu sektorů
-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5743 4154 5234 3132 3935 3936
020: 0000 FFFF 0032 3135 2E30 3148 3135 5744 4320 5744
030: 3130 4541 4C58 2D30 3039 4241 3020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 170E 0000 0044 0040
080: 01FE 0000 746B 7F61 4123 7469 BC41 4123 407F 0056
090: 0056 0000 FFFE 0000 80FE 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0000 0000 0000 5001 4EE2
110: 5A77 D16A 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0021 0000
130: 0000 0000 0000 16E2 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 3037 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 E5A5
-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 B3 AF B9 0F 00 00 00 00 00 04 32 00 62 62 7D
020: 09 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 5C 5C 83 17 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 63 63 AC 06 00 00 00 00 00 C0 32
070: 00 C8 C8 46 02 00 00 00 00 00 C1 32 00 C8 C8 36
080: 07 00 00 00 00 00 C2 22 00 6F 67 24 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 C8 C8 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 03 00 00 00 00
0C0: 00 00 C8 08 00 C8 C8 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 84 00 54 42 01 7B
170: 03 00 01 00 02 C4 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 32
-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 C8 C8 C8 C8 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5D
- Rudy
- Site Admin
- Příspěvky: 119488
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrt při zapnutí pc
Disk je OK. Dejte log RSIT: http://www.viry.cz/forum/viewtopic.php?f=13&t=105895 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Modrá smrt při zapnutí pc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Vastl at 2012-12-28 19:38:26
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 651 GB (68%) free of 954 GB
Total RAM: 4087 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:38:30, on 28.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe
C:\Program Files (x86)\Diablo III\Diablo III.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Vastl.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: uTorrentControl_v2 - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Launcher3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 3045B
O4 - HKLM\..\Run: [DocuPrint 3045B RUN] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe"
O4 - HKLM\..\Run: [StatusAutoRun3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Vplalv] C:\Users\Vastl\AppData\Roaming\Vplalv.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3167788445-3503430199-2841087581-1004\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3167788445-3503430199-2841087581-1004\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 10873 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {3E077AE8-19EE-45F6-BD08-77AE5A59910E}
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
"C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmW.exe"
\??\C:\Windows\system32\conhost.exe "-1854526041881303874-778943778-10817394901900461846412369919-92882328058466730
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe"
\??\C:\Windows\system32\conhost.exe "8108929511843325272-8172299652113577082-355207438-2060368825-16793412542124298127
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4328.1.1569357596\1946050627" --gpu-vendor-id=0x10de --gpu-device-id=0x06cd --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.1070 --ignored=" --type=renderer " /prefetch:12
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/6/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --renderer-print-preview --channel="4328.3.1178830233\1975323507" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4328.4.1776167470\972543592" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/6/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndDynamic/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --renderer-print-preview --channel="4328.7.1722353697\2042548789" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/6/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndDynamic/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --renderer-print-preview --channel="4328.8.2033232263\1500963979" /prefetch:3
"C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe" --locale=enGB
\??\C:\Windows\system32\conhost.exe "10896739246515421751227704023-211134880-198696935513694398461075106591-219635808
"C:\Program Files (x86)\Diablo III\Diablo III.exe" -launch -uid diablo3_engb
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/6/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndDynamic/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --renderer-print-preview --channel="4328.13.1301083747\376115654" /prefetch:3
"C:\Users\Vastl\Downloads\RSITx64.exe"
taskeng.exe {553C5FD7-340D-4482-980D-3E9F60097C2C}
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\SlimDrivers Startup.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default
prefs.js - "browser.startup.homepage" - "http://eu.ask.com/?l=dis&o=14672"
prefs.js - "keyword.URL" - "http://websearch.ask.com/redirect?clien ... YYYYCZ&&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35]
"Description"=
"Path"=C:\Windows\system32\npdeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-12-21 351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2012-10-02 5748928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-12-21 53744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
uTorrentControl_v2 Toolbar - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09 176936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02 4119744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2012-08-08 1527496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7473b6bd-4691-4744-a82b-7854eb3d70b6} - uTorrentControl_v2 Toolbar - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09 176936]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2012-08-08 1527496]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2916584]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20 444904]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 12503184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"AdobeBridge"= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
"Vplalv"=C:\Users\Vastl\AppData\Roaming\Vplalv.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-06-25 1073352]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Launcher3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-04-22 2570752]
"DocuPrint 3045B RUN"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe [2011-04-22 355840]
"StatusAutoRun3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe [2011-04-22 4476928]
""= []
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2012-08-08 1644744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
======List of files/folders created in the last 1 month======
2012-12-28 19:38:26 ----D---- C:\rsit
2012-12-28 19:38:26 ----D---- C:\Program Files\trend micro
2012-12-28 19:00:10 ----D---- C:\Program Files (x86)\CrystalDiskInfo
2012-12-28 10:30:16 ----A---- C:\Windows\system32\WavesGUILib.dll
2012-12-28 10:30:15 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tosade.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tepeqapo64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSWOW64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSX64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSH64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSHP64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFSS_APO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFNHK64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtPgEx64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCfg64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkApi64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DHT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DAA64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoRes64.dat
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoInstII64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEA64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\KAAPORT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2012-12-28 10:30:14 ----D---- C:\Program Files (x86)\Realtek
2012-12-28 10:30:14 ----A---- C:\Windows\system32\FMAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAR64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAC64.dll
2012-12-28 10:30:06 ----HD---- C:\Program Files (x86)\Temp
2012-12-28 10:30:06 ----A---- C:\Windows\RtlExUpd.dll
2012-12-28 10:26:16 ----D---- C:\Program Files (x86)\SlimDrivers
2012-12-25 09:23:04 ----D---- C:\Program Files\NetBeans 7.2.1
2012-12-22 19:26:09 ----D---- C:\Users\Vastl\AppData\Roaming\TS3Client
2012-12-22 19:25:53 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2012-12-21 20:04:12 ----D---- C:\Users\Vastl\AppData\Roaming\NetBeans
2012-12-21 19:51:53 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaws.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaw.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\java.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\deployJava1.dll
2012-12-21 19:50:15 ----D---- C:\Program Files\Java
2012-12-21 17:45:23 ----D---- C:\Users\Vastl\AppData\Roaming\TeamViewer
2012-12-15 19:34:38 ----D---- C:\Users\Vastl\AppData\Roaming\mIRC
2012-12-14 23:21:05 ----D---- C:\Users\Vastl\AppData\Roaming\Malwarebytes
2012-12-14 23:20:59 ----D---- C:\ProgramData\Malwarebytes
2012-12-13 22:21:28 ----D---- C:\Program Files (x86)\Convar
2012-12-13 12:31:52 ----D---- C:\xampp
2012-12-12 18:24:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-12-12 18:24:40 ----A---- C:\Windows\system32\mshtmled.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieui.dll
2012-12-12 18:24:37 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\msfeeds.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\jscript9.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-12-12 18:24:36 ----A---- C:\Windows\system32\wininet.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\vbscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jsproxy.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jscript.dll
2012-12-12 18:24:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-12-12 18:24:34 ----A---- C:\Windows\system32\iertutil.dll
2012-12-12 18:24:33 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-12-12 18:24:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-12-12 18:24:29 ----A---- C:\Windows\system32\mshtml.dll
2012-12-12 18:24:28 ----A---- C:\Windows\system32\ieframe.dll
2012-12-12 18:24:27 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-12-12 18:22:34 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-12-12 18:22:34 ----A---- C:\Windows\system32\tzres.dll
2012-12-12 18:22:24 ----A---- C:\Windows\system32\win32k.sys
2012-12-12 18:22:12 ----A---- C:\Windows\system32\winsrv.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\KernelBase.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\kernel32.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\conhost.exe
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2012-12-12 18:22:10 ----A---- C:\Windows\SYSWOW64\setup16.exe
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\wow32.dll
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64win.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64cpu.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\ntvdm64.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----A---- C:\Windows\SYSWOW64\instnm.exe
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:03 ----A---- C:\Windows\SYSWOW64\user.exe
2012-12-12 18:20:52 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-12-12 18:20:52 ----A---- C:\Windows\system32\atmfd.dll
2012-12-12 18:20:51 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-12-12 18:20:51 ----A---- C:\Windows\system32\atmlib.dll
2012-12-12 18:20:49 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2012-12-12 18:20:49 ----A---- C:\Windows\system32\dpnet.dll
2012-12-04 23:03:38 ----D---- C:\Program Files (x86)\AGEIA Technologies
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvoglv64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvinitx.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdap64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2012-12-04 23:00:03 ----D---- C:\NVIDIA
2012-11-30 22:43:52 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2012-11-30 19:41:08 ----D---- C:\Users\Vastl\AppData\Roaming\Theta
2012-11-30 19:15:33 ----D---- C:\Program Files (x86)\Ubisoft
2012-11-30 17:02:34 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-11-30 17:02:34 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-11-30 17:02:34 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-11-30 17:02:33 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-11-30 17:02:33 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-11-30 17:02:32 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-11-30 17:02:29 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-11-30 17:02:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-11-30 17:02:29 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-11-30 17:02:29 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-11-30 17:02:26 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-11-30 17:02:26 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-11-30 17:02:24 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-11-30 17:02:15 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-11-30 17:02:15 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-11-30 17:02:12 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-11-30 17:02:12 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-11-30 17:02:11 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-11-30 17:02:11 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-11-30 17:02:11 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-11-30 17:02:11 ----A---- C:\Windows\system32\X3DAudio1_2.dll
======List of files/folders modified in the last 1 month======
2012-12-28 19:38:28 ----D---- C:\Windows\Temp
2012-12-28 19:38:26 ----RD---- C:\Program Files
2012-12-28 19:32:57 ----D---- C:\Users\Vastl\AppData\Roaming\Skype
2012-12-28 19:00:10 ----RD---- C:\Program Files (x86)
2012-12-28 17:43:29 ----D---- C:\Users\Vastl\AppData\Roaming\uTorrent
2012-12-28 17:32:18 ----D---- C:\Windows\system32\drivers
2012-12-28 17:12:29 ----D---- C:\Windows\SysWOW64
2012-12-28 17:06:09 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-28 17:01:36 ----D---- C:\ProgramData\PMB Files
2012-12-28 16:32:48 ----D---- C:\Windows\System32
2012-12-28 16:32:48 ----D---- C:\Windows\inf
2012-12-28 16:32:48 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-28 16:31:15 ----D---- C:\Windows\system32\config
2012-12-28 16:19:34 ----D---- C:\ProgramData\NVIDIA
2012-12-28 10:48:53 ----D---- C:\Windows\Minidump
2012-12-28 10:36:33 ----D---- C:\Windows
2012-12-28 10:30:38 ----D---- C:\Windows\SYSWOW64\RTCOM
2012-12-28 10:30:35 ----D---- C:\Windows\system32\catroot
2012-12-28 10:30:34 ----D---- C:\Windows\system32\DriverStore
2012-12-28 10:30:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-28 10:28:09 ----SHD---- C:\System Volume Information
2012-12-28 10:27:30 ----D---- C:\Windows\Tasks
2012-12-28 10:27:30 ----D---- C:\Windows\system32\Tasks
2012-12-28 10:26:17 ----SHD---- C:\Windows\Installer
2012-12-23 19:24:15 ----D---- C:\Windows\rescache
2012-12-23 18:58:50 ----D---- C:\Users\Vastl\AppData\Roaming\vlc
2012-12-23 07:07:53 ----D---- C:\Windows\system32\catroot2
2012-12-22 17:58:43 ----D---- C:\Program Files (x86)\Diablo III
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wfp
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wbem
2012-12-20 17:51:02 ----D---- C:\Windows\AppCompat
2012-12-20 17:51:00 ----HD---- C:\GrandeDevice
2012-12-20 17:50:58 ----D---- C:\Windows\registration
2012-12-20 17:50:50 ----RHD---- C:\MSOCache
2012-12-15 00:33:37 ----D---- C:\Windows\system32\drivers\etc
2012-12-15 00:33:37 ----D---- C:\Program Files (x86)\Internet Explorer
2012-12-15 00:33:36 ----D---- C:\Windows\system32\drivers\UMDF
2012-12-15 00:33:36 ----D---- C:\Windows\system32\CodeIntegrity
2012-12-15 00:33:34 ----D---- C:\Users\Vastl\AppData\Roaming\PSpad
2012-12-15 00:33:29 ----D---- C:\Program Files (x86)\PSPad editor
2012-12-15 00:33:29 ----D---- C:\Program Files (x86)\Ask.com
2012-12-15 00:33:02 ----D---- C:\Users\Vastl\AppData\Roaming\Mozilla
2012-12-15 00:32:58 ----D---- C:\Users\Vastl\AppData\Roaming\DAEMON Tools Lite
2012-12-15 00:32:50 ----SD---- C:\ProgramData\Microsoft
2012-12-15 00:32:50 ----HD---- C:\ProgramData
2012-12-14 23:00:28 ----D---- C:\Windows\Logs
2012-12-14 23:00:27 ----D---- C:\Windows\debug
2012-12-13 22:20:51 ----D---- C:\Program Files (x86)\Common Files
2012-12-13 07:41:48 ----D---- C:\Windows\winsxs
2012-12-12 23:02:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-12-12 23:02:50 ----D---- C:\Windows\system32\cs-CZ
2012-12-12 23:02:49 ----D---- C:\Windows\SYSWOW64\migration
2012-12-12 23:02:49 ----D---- C:\Windows\system32\migration
2012-12-12 23:02:49 ----D---- C:\Windows\AppPatch
2012-12-12 23:02:49 ----D---- C:\Program Files\Internet Explorer
2012-12-12 18:25:52 ----A---- C:\Windows\system32\MRT.exe
2012-12-12 18:24:23 ----D---- C:\ProgramData\Microsoft Help
2012-12-12 17:09:45 ----D---- C:\Program Files (x86)\uTorrent
2012-12-12 13:35:24 ----D---- C:\ProgramData\Adobe
2012-12-12 07:09:20 ----D---- C:\Windows\Prefetch
2012-12-10 15:21:51 ----SD---- C:\Users\Vastl\AppData\Roaming\Microsoft
2012-12-04 23:03:48 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-12-03 16:47:14 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvumdshimx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispgenco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvapi64.dll
2012-12-01 16:48:49 ----D---- C:\Users\Vastl\AppData\Roaming\Adobe
2012-12-01 16:29:12 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-12-01 16:28:29 ----D---- C:\Program Files (x86)\Adobe
2012-12-01 06:49:26 ----A---- C:\Windows\system32\nvsvcr.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvshext.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvmctray.dll
2012-12-01 06:49:24 ----A---- C:\Windows\system32\nvvsvc.exe
2012-12-01 06:48:41 ----A---- C:\Windows\system32\nvcpl.dll
2012-12-01 06:48:37 ----A---- C:\Windows\system32\nvsvc64.dll
2012-11-30 19:15:37 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-11-30 19:14:52 ----RSD---- C:\Windows\assembly
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2010-11-22 24880]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-11-22 303408]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 168544]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-25 283200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2000-01-01 4065296]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [2010-05-10 33592]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2010-10-22 14136]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-12-01 890216]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-12-03 1259880]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-11-30 75136]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]
R2 XRNADB;XRcnStatutsDatabase; C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe [2011-04-22 95232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 42360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-11 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-23 529744]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-29 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Vastl at 2012-12-28 19:38:26
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 651 GB (68%) free of 954 GB
Total RAM: 4087 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:38:30, on 28.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe
C:\Program Files (x86)\Diablo III\Diablo III.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Vastl.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: uTorrentControl_v2 - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Launcher3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 3045B
O4 - HKLM\..\Run: [DocuPrint 3045B RUN] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe"
O4 - HKLM\..\Run: [StatusAutoRun3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Vplalv] C:\Users\Vastl\AppData\Roaming\Vplalv.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3167788445-3503430199-2841087581-1004\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3167788445-3503430199-2841087581-1004\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 10873 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {3E077AE8-19EE-45F6-BD08-77AE5A59910E}
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
"C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmW.exe"
\??\C:\Windows\system32\conhost.exe "-1854526041881303874-778943778-10817394901900461846412369919-92882328058466730
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe"
\??\C:\Windows\system32\conhost.exe "8108929511843325272-8172299652113577082-355207438-2060368825-16793412542124298127
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4328.1.1569357596\1946050627" --gpu-vendor-id=0x10de --gpu-device-id=0x06cd --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.1070 --ignored=" --type=renderer " /prefetch:12
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/6/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --renderer-print-preview --channel="4328.3.1178830233\1975323507" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4328.4.1776167470\972543592" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/6/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndDynamic/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --renderer-print-preview --channel="4328.7.1722353697\2042548789" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/6/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndDynamic/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --renderer-print-preview --channel="4328.8.2033232263\1500963979" /prefetch:3
"C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe" --locale=enGB
\??\C:\Windows\system32\conhost.exe "10896739246515421751227704023-211134880-198696935513694398461075106591-219635808
"C:\Program Files (x86)\Diablo III\Diablo III.exe" -launch -uid diablo3_engb
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/6/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndDynamic/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --renderer-print-preview --channel="4328.13.1301083747\376115654" /prefetch:3
"C:\Users\Vastl\Downloads\RSITx64.exe"
taskeng.exe {553C5FD7-340D-4482-980D-3E9F60097C2C}
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\SlimDrivers Startup.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default
prefs.js - "browser.startup.homepage" - "http://eu.ask.com/?l=dis&o=14672"
prefs.js - "keyword.URL" - "http://websearch.ask.com/redirect?clien ... YYYYCZ&&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35]
"Description"=
"Path"=C:\Windows\system32\npdeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-12-21 351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2012-10-02 5748928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-12-21 53744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
uTorrentControl_v2 Toolbar - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09 176936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02 4119744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2012-08-08 1527496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7473b6bd-4691-4744-a82b-7854eb3d70b6} - uTorrentControl_v2 Toolbar - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll [2011-05-09 176936]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2012-08-08 1527496]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2916584]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20 444904]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 12503184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"AdobeBridge"= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
"Vplalv"=C:\Users\Vastl\AppData\Roaming\Vplalv.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-06-25 1073352]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Launcher3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-04-22 2570752]
"DocuPrint 3045B RUN"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe [2011-04-22 355840]
"StatusAutoRun3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe [2011-04-22 4476928]
""= []
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2012-08-08 1644744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
======List of files/folders created in the last 1 month======
2012-12-28 19:38:26 ----D---- C:\rsit
2012-12-28 19:38:26 ----D---- C:\Program Files\trend micro
2012-12-28 19:00:10 ----D---- C:\Program Files (x86)\CrystalDiskInfo
2012-12-28 10:30:16 ----A---- C:\Windows\system32\WavesGUILib.dll
2012-12-28 10:30:15 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tosade.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tepeqapo64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSWOW64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSX64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSH64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSHP64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFSS_APO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFNHK64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtPgEx64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCfg64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkApi64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DHT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DAA64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoRes64.dat
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoInstII64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEA64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\KAAPORT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2012-12-28 10:30:14 ----D---- C:\Program Files (x86)\Realtek
2012-12-28 10:30:14 ----A---- C:\Windows\system32\FMAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAR64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAC64.dll
2012-12-28 10:30:06 ----HD---- C:\Program Files (x86)\Temp
2012-12-28 10:30:06 ----A---- C:\Windows\RtlExUpd.dll
2012-12-28 10:26:16 ----D---- C:\Program Files (x86)\SlimDrivers
2012-12-25 09:23:04 ----D---- C:\Program Files\NetBeans 7.2.1
2012-12-22 19:26:09 ----D---- C:\Users\Vastl\AppData\Roaming\TS3Client
2012-12-22 19:25:53 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2012-12-21 20:04:12 ----D---- C:\Users\Vastl\AppData\Roaming\NetBeans
2012-12-21 19:51:53 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaws.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaw.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\java.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\deployJava1.dll
2012-12-21 19:50:15 ----D---- C:\Program Files\Java
2012-12-21 17:45:23 ----D---- C:\Users\Vastl\AppData\Roaming\TeamViewer
2012-12-15 19:34:38 ----D---- C:\Users\Vastl\AppData\Roaming\mIRC
2012-12-14 23:21:05 ----D---- C:\Users\Vastl\AppData\Roaming\Malwarebytes
2012-12-14 23:20:59 ----D---- C:\ProgramData\Malwarebytes
2012-12-13 22:21:28 ----D---- C:\Program Files (x86)\Convar
2012-12-13 12:31:52 ----D---- C:\xampp
2012-12-12 18:24:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-12-12 18:24:40 ----A---- C:\Windows\system32\mshtmled.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieui.dll
2012-12-12 18:24:37 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\msfeeds.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\jscript9.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-12-12 18:24:36 ----A---- C:\Windows\system32\wininet.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\vbscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jsproxy.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jscript.dll
2012-12-12 18:24:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-12-12 18:24:34 ----A---- C:\Windows\system32\iertutil.dll
2012-12-12 18:24:33 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-12-12 18:24:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-12-12 18:24:29 ----A---- C:\Windows\system32\mshtml.dll
2012-12-12 18:24:28 ----A---- C:\Windows\system32\ieframe.dll
2012-12-12 18:24:27 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-12-12 18:22:34 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-12-12 18:22:34 ----A---- C:\Windows\system32\tzres.dll
2012-12-12 18:22:24 ----A---- C:\Windows\system32\win32k.sys
2012-12-12 18:22:12 ----A---- C:\Windows\system32\winsrv.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\KernelBase.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\kernel32.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\conhost.exe
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2012-12-12 18:22:10 ----A---- C:\Windows\SYSWOW64\setup16.exe
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\wow32.dll
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64win.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64cpu.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\ntvdm64.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----A---- C:\Windows\SYSWOW64\instnm.exe
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:03 ----A---- C:\Windows\SYSWOW64\user.exe
2012-12-12 18:20:52 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-12-12 18:20:52 ----A---- C:\Windows\system32\atmfd.dll
2012-12-12 18:20:51 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-12-12 18:20:51 ----A---- C:\Windows\system32\atmlib.dll
2012-12-12 18:20:49 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2012-12-12 18:20:49 ----A---- C:\Windows\system32\dpnet.dll
2012-12-04 23:03:38 ----D---- C:\Program Files (x86)\AGEIA Technologies
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvoglv64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvinitx.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdap64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2012-12-04 23:00:03 ----D---- C:\NVIDIA
2012-11-30 22:43:52 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2012-11-30 19:41:08 ----D---- C:\Users\Vastl\AppData\Roaming\Theta
2012-11-30 19:15:33 ----D---- C:\Program Files (x86)\Ubisoft
2012-11-30 17:02:34 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-11-30 17:02:34 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-11-30 17:02:34 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-11-30 17:02:33 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-11-30 17:02:33 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-11-30 17:02:32 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-11-30 17:02:29 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-11-30 17:02:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-11-30 17:02:29 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-11-30 17:02:29 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-11-30 17:02:26 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-11-30 17:02:26 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-11-30 17:02:24 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-11-30 17:02:15 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-11-30 17:02:15 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-11-30 17:02:12 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-11-30 17:02:12 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-11-30 17:02:11 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-11-30 17:02:11 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-11-30 17:02:11 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-11-30 17:02:11 ----A---- C:\Windows\system32\X3DAudio1_2.dll
======List of files/folders modified in the last 1 month======
2012-12-28 19:38:28 ----D---- C:\Windows\Temp
2012-12-28 19:38:26 ----RD---- C:\Program Files
2012-12-28 19:32:57 ----D---- C:\Users\Vastl\AppData\Roaming\Skype
2012-12-28 19:00:10 ----RD---- C:\Program Files (x86)
2012-12-28 17:43:29 ----D---- C:\Users\Vastl\AppData\Roaming\uTorrent
2012-12-28 17:32:18 ----D---- C:\Windows\system32\drivers
2012-12-28 17:12:29 ----D---- C:\Windows\SysWOW64
2012-12-28 17:06:09 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-28 17:01:36 ----D---- C:\ProgramData\PMB Files
2012-12-28 16:32:48 ----D---- C:\Windows\System32
2012-12-28 16:32:48 ----D---- C:\Windows\inf
2012-12-28 16:32:48 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-28 16:31:15 ----D---- C:\Windows\system32\config
2012-12-28 16:19:34 ----D---- C:\ProgramData\NVIDIA
2012-12-28 10:48:53 ----D---- C:\Windows\Minidump
2012-12-28 10:36:33 ----D---- C:\Windows
2012-12-28 10:30:38 ----D---- C:\Windows\SYSWOW64\RTCOM
2012-12-28 10:30:35 ----D---- C:\Windows\system32\catroot
2012-12-28 10:30:34 ----D---- C:\Windows\system32\DriverStore
2012-12-28 10:30:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-28 10:28:09 ----SHD---- C:\System Volume Information
2012-12-28 10:27:30 ----D---- C:\Windows\Tasks
2012-12-28 10:27:30 ----D---- C:\Windows\system32\Tasks
2012-12-28 10:26:17 ----SHD---- C:\Windows\Installer
2012-12-23 19:24:15 ----D---- C:\Windows\rescache
2012-12-23 18:58:50 ----D---- C:\Users\Vastl\AppData\Roaming\vlc
2012-12-23 07:07:53 ----D---- C:\Windows\system32\catroot2
2012-12-22 17:58:43 ----D---- C:\Program Files (x86)\Diablo III
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wfp
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wbem
2012-12-20 17:51:02 ----D---- C:\Windows\AppCompat
2012-12-20 17:51:00 ----HD---- C:\GrandeDevice
2012-12-20 17:50:58 ----D---- C:\Windows\registration
2012-12-20 17:50:50 ----RHD---- C:\MSOCache
2012-12-15 00:33:37 ----D---- C:\Windows\system32\drivers\etc
2012-12-15 00:33:37 ----D---- C:\Program Files (x86)\Internet Explorer
2012-12-15 00:33:36 ----D---- C:\Windows\system32\drivers\UMDF
2012-12-15 00:33:36 ----D---- C:\Windows\system32\CodeIntegrity
2012-12-15 00:33:34 ----D---- C:\Users\Vastl\AppData\Roaming\PSpad
2012-12-15 00:33:29 ----D---- C:\Program Files (x86)\PSPad editor
2012-12-15 00:33:29 ----D---- C:\Program Files (x86)\Ask.com
2012-12-15 00:33:02 ----D---- C:\Users\Vastl\AppData\Roaming\Mozilla
2012-12-15 00:32:58 ----D---- C:\Users\Vastl\AppData\Roaming\DAEMON Tools Lite
2012-12-15 00:32:50 ----SD---- C:\ProgramData\Microsoft
2012-12-15 00:32:50 ----HD---- C:\ProgramData
2012-12-14 23:00:28 ----D---- C:\Windows\Logs
2012-12-14 23:00:27 ----D---- C:\Windows\debug
2012-12-13 22:20:51 ----D---- C:\Program Files (x86)\Common Files
2012-12-13 07:41:48 ----D---- C:\Windows\winsxs
2012-12-12 23:02:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-12-12 23:02:50 ----D---- C:\Windows\system32\cs-CZ
2012-12-12 23:02:49 ----D---- C:\Windows\SYSWOW64\migration
2012-12-12 23:02:49 ----D---- C:\Windows\system32\migration
2012-12-12 23:02:49 ----D---- C:\Windows\AppPatch
2012-12-12 23:02:49 ----D---- C:\Program Files\Internet Explorer
2012-12-12 18:25:52 ----A---- C:\Windows\system32\MRT.exe
2012-12-12 18:24:23 ----D---- C:\ProgramData\Microsoft Help
2012-12-12 17:09:45 ----D---- C:\Program Files (x86)\uTorrent
2012-12-12 13:35:24 ----D---- C:\ProgramData\Adobe
2012-12-12 07:09:20 ----D---- C:\Windows\Prefetch
2012-12-10 15:21:51 ----SD---- C:\Users\Vastl\AppData\Roaming\Microsoft
2012-12-04 23:03:48 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-12-03 16:47:14 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvumdshimx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispgenco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvapi64.dll
2012-12-01 16:48:49 ----D---- C:\Users\Vastl\AppData\Roaming\Adobe
2012-12-01 16:29:12 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-12-01 16:28:29 ----D---- C:\Program Files (x86)\Adobe
2012-12-01 06:49:26 ----A---- C:\Windows\system32\nvsvcr.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvshext.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvmctray.dll
2012-12-01 06:49:24 ----A---- C:\Windows\system32\nvvsvc.exe
2012-12-01 06:48:41 ----A---- C:\Windows\system32\nvcpl.dll
2012-12-01 06:48:37 ----A---- C:\Windows\system32\nvsvc64.dll
2012-11-30 19:15:37 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-11-30 19:14:52 ----RSD---- C:\Windows\assembly
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2010-11-22 24880]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-11-22 303408]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 168544]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-25 283200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2000-01-01 4065296]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [2010-05-10 33592]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2010-10-22 14136]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-12-01 890216]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-12-03 1259880]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-11-30 75136]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]
R2 XRNADB;XRcnStatutsDatabase; C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe [2011-04-22 95232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 42360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-11 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-23 529744]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-29 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119488
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrt při zapnutí pc
Zkusíme vyčistit.
Stáhněte AdwCleaner http://stahnu.cz/tag/adw-cleaner-free-download
Uložte na plochu
Ukončete všechny programy
Klikněte na Search
Proběhne skenováni a pak se objeví log, který sem vložte.
Stáhněte AdwCleaner http://stahnu.cz/tag/adw-cleaner-free-download
Uložte na plochu
Ukončete všechny programy
Klikněte na Search
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Modrá smrt při zapnutí pc
# AdwCleaner v2.007 - Logfile created 12/29/2012 at 07:54:10
# Updated 06/11/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Vastl - VASTL-PC
# Boot Mode : Normal
# Running from : C:\Users\Vastl\Desktop\adwcleaner_2.103.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\uTorrentControl_v2
Folder Found : C:\ProgramData\Ask
Folder Found : C:\Users\Vastl\AppData\Local\Conduit
Folder Found : C:\Users\Vastl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Folder Found : C:\Users\Vastl\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Vastl\AppData\LocalLow\Conduit
Folder Found : C:\Users\Vastl\AppData\LocalLow\uTorrentControl_v2
Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
***** [Registry] *****
Key Found : HKCU\Software\APN
Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\PIP
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\Software\APN
Key Found : HKLM\Software\AskToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Found : HKLM\Software\PIP
Key Found : HKLM\Software\uTorrentControl_v2
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C16BEB5B-6AB0-4137-A580-0ED065B687B9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8D99C55-6646-4AD6-B261-B5DF3C277C2C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKU\S-1-5-21-3167788445-3503430199-2841087581-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=14672
-\\ Mozilla Firefox v16.0.1 (cs)
Profile name : default
File : C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default\prefs.js
Found : user_pref("browser.startup.homepage", "hxxp://eu.ask.com/?l=dis&o=14672");
Found : user_pref("extensions.asktb.ff-original-keyword-url", "");
Found : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ATU2&o=14670&locale=[...]
-\\ Google Chrome v [Unable to get version]
File : C:\Users\Vastl\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\\ Opera v [Unable to get version]
File : C:\Users\Vastl\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [7004 octets] - [29/12/2012 07:54:10]
########## EOF - C:\AdwCleaner[R1].txt - [7064 octets] ##########
# Updated 06/11/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Vastl - VASTL-PC
# Boot Mode : Normal
# Running from : C:\Users\Vastl\Desktop\adwcleaner_2.103.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\uTorrentControl_v2
Folder Found : C:\ProgramData\Ask
Folder Found : C:\Users\Vastl\AppData\Local\Conduit
Folder Found : C:\Users\Vastl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Folder Found : C:\Users\Vastl\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Vastl\AppData\LocalLow\Conduit
Folder Found : C:\Users\Vastl\AppData\LocalLow\uTorrentControl_v2
Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
***** [Registry] *****
Key Found : HKCU\Software\APN
Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\PIP
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\Software\APN
Key Found : HKLM\Software\AskToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Found : HKLM\Software\PIP
Key Found : HKLM\Software\uTorrentControl_v2
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C16BEB5B-6AB0-4137-A580-0ED065B687B9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8D99C55-6646-4AD6-B261-B5DF3C277C2C}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKU\S-1-5-21-3167788445-3503430199-2841087581-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=14672
-\\ Mozilla Firefox v16.0.1 (cs)
Profile name : default
File : C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default\prefs.js
Found : user_pref("browser.startup.homepage", "hxxp://eu.ask.com/?l=dis&o=14672");
Found : user_pref("extensions.asktb.ff-original-keyword-url", "");
Found : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ATU2&o=14670&locale=[...]
-\\ Google Chrome v [Unable to get version]
File : C:\Users\Vastl\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\\ Opera v [Unable to get version]
File : C:\Users\Vastl\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [7004 octets] - [29/12/2012 07:54:10]
########## EOF - C:\AdwCleaner[R1].txt - [7064 octets] ##########
- Rudy
- Site Admin
- Příspěvky: 119488
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrt při zapnutí pc
Spusťte znovu ADWCleaner a klikněte na >Delete<. Vložte nový log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Modrá smrt při zapnutí pc
# AdwCleaner v2.007 - Logfile created 12/29/2012 at 10:51:42
# Updated 06/11/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Vastl - VASTL-PC
# Boot Mode : Normal
# Running from : C:\Users\Vastl\Desktop\adwcleaner_2.103.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted : C:\Program Files (x86)\Ask.com
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\uTorrentControl_v2
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\Users\Vastl\AppData\Local\Conduit
Folder Deleted : C:\Users\Vastl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Folder Deleted : C:\Users\Vastl\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Vastl\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Vastl\AppData\LocalLow\uTorrentControl_v2
Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
***** [Registry] *****
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\uTorrentControl_v2
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C16BEB5B-6AB0-4137-A580-0ED065B687B9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8D99C55-6646-4AD6-B261-B5DF3C277C2C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=14672 --> hxxp://www.google.com
-\\ Mozilla Firefox v16.0.1 (cs)
Profile name : default
File : C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default\prefs.js
Deleted : user_pref("browser.startup.homepage", "hxxp://eu.ask.com/?l=dis&o=14672");
Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");
Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ATU2&o=14670&locale=[...]
-\\ Google Chrome v [Unable to get version]
File : C:\Users\Vastl\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\\ Opera v [Unable to get version]
File : C:\Users\Vastl\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [7123 octets] - [29/12/2012 07:54:10]
AdwCleaner[S1].txt - [6979 octets] - [29/12/2012 10:51:42]
########## EOF - C:\AdwCleaner[S1].txt - [7039 octets] ##########
# Updated 06/11/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Vastl - VASTL-PC
# Boot Mode : Normal
# Running from : C:\Users\Vastl\Desktop\adwcleaner_2.103.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted : C:\Program Files (x86)\Ask.com
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\uTorrentControl_v2
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\Users\Vastl\AppData\Local\Conduit
Folder Deleted : C:\Users\Vastl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Folder Deleted : C:\Users\Vastl\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Vastl\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Vastl\AppData\LocalLow\uTorrentControl_v2
Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
***** [Registry] *****
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\uTorrentControl_v2
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C16BEB5B-6AB0-4137-A580-0ED065B687B9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8D99C55-6646-4AD6-B261-B5DF3C277C2C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=14672 --> hxxp://www.google.com
-\\ Mozilla Firefox v16.0.1 (cs)
Profile name : default
File : C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default\prefs.js
Deleted : user_pref("browser.startup.homepage", "hxxp://eu.ask.com/?l=dis&o=14672");
Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");
Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ATU2&o=14670&locale=[...]
-\\ Google Chrome v [Unable to get version]
File : C:\Users\Vastl\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\\ Opera v [Unable to get version]
File : C:\Users\Vastl\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [7123 octets] - [29/12/2012 07:54:10]
AdwCleaner[S1].txt - [6979 octets] - [29/12/2012 10:51:42]
########## EOF - C:\AdwCleaner[S1].txt - [7039 octets] ##########
- Rudy
- Site Admin
- Příspěvky: 119488
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrt při zapnutí pc
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Modrá smrt při zapnutí pc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Vastl at 2012-12-29 11:01:02
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 650 GB (68%) free of 954 GB
Total RAM: 4087 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:01:04, on 29.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\trend micro\Vastl.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Launcher3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 3045B
O4 - HKLM\..\Run: [DocuPrint 3045B RUN] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe"
O4 - HKLM\..\Run: [StatusAutoRun3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Vplalv] C:\Users\Vastl\AppData\Roaming\Vplalv.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3167788445-3503430199-2841087581-1004\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3167788445-3503430199-2841087581-1004\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 9407 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmW.exe"
\??\C:\Windows\system32\conhost.exe "1099219945125803958853130781-1091637615701744509920964987-441965232786904375
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe"
\??\C:\Windows\system32\conhost.exe "-1431951668188417705816021013381608471585410183548-628711265-9881193021272837265
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Windows\system32\wuauclt.exe"
C:\Windows\System32\svchost.exe -k secsvcs
taskeng.exe {895321D6-1E1D-4D39-9595-961CF7FC0BA7}
taskhost.exe $(Arg0)
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
"C:\Users\Vastl\Downloads\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35]
"Description"=
"Path"=C:\Windows\system32\npdeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-12-21 351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2012-10-02 5748928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-12-21 53744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02 4119744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 155384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2916584]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20 444904]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 12503184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"AdobeBridge"= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
"Vplalv"=C:\Users\Vastl\AppData\Roaming\Vplalv.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-06-25 1073352]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Launcher3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-04-22 2570752]
"DocuPrint 3045B RUN"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe [2011-04-22 355840]
"StatusAutoRun3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe [2011-04-22 4476928]
""= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
======List of files/folders created in the last 1 month======
2012-12-29 10:51:42 ----A---- C:\AdwCleaner[S1].txt
2012-12-29 09:24:10 ----D---- C:\Program Files (x86)\Driver-Soft
2012-12-29 09:17:55 ----D---- C:\ProgramData\DriverGenius
2012-12-29 07:54:10 ----A---- C:\AdwCleaner[R1].txt
2012-12-28 19:38:26 ----D---- C:\rsit
2012-12-28 19:38:26 ----D---- C:\Program Files\trend micro
2012-12-28 10:30:16 ----A---- C:\Windows\system32\WavesGUILib.dll
2012-12-28 10:30:15 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tosade.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tepeqapo64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSWOW64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSX64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSH64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSHP64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFSS_APO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFNHK64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtPgEx64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCfg64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkApi64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DHT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DAA64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoRes64.dat
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoInstII64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEA64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\KAAPORT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2012-12-28 10:30:14 ----D---- C:\Program Files (x86)\Realtek
2012-12-28 10:30:14 ----A---- C:\Windows\system32\FMAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAR64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAC64.dll
2012-12-28 10:30:06 ----HD---- C:\Program Files (x86)\Temp
2012-12-28 10:30:06 ----A---- C:\Windows\RtlExUpd.dll
2012-12-25 09:23:04 ----D---- C:\Program Files\NetBeans 7.2.1
2012-12-22 19:26:09 ----D---- C:\Users\Vastl\AppData\Roaming\TS3Client
2012-12-22 19:25:53 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2012-12-21 20:04:12 ----D---- C:\Users\Vastl\AppData\Roaming\NetBeans
2012-12-21 19:51:53 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaws.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaw.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\java.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\deployJava1.dll
2012-12-21 19:50:15 ----D---- C:\Program Files\Java
2012-12-21 17:45:23 ----D---- C:\Users\Vastl\AppData\Roaming\TeamViewer
2012-12-15 19:34:38 ----D---- C:\Users\Vastl\AppData\Roaming\mIRC
2012-12-14 23:21:05 ----D---- C:\Users\Vastl\AppData\Roaming\Malwarebytes
2012-12-14 23:20:59 ----D---- C:\ProgramData\Malwarebytes
2012-12-13 22:21:28 ----D---- C:\Program Files (x86)\Convar
2012-12-13 12:31:52 ----D---- C:\xampp
2012-12-12 18:24:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-12-12 18:24:40 ----A---- C:\Windows\system32\mshtmled.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieui.dll
2012-12-12 18:24:37 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\msfeeds.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\jscript9.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-12-12 18:24:36 ----A---- C:\Windows\system32\wininet.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\vbscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jsproxy.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jscript.dll
2012-12-12 18:24:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-12-12 18:24:34 ----A---- C:\Windows\system32\iertutil.dll
2012-12-12 18:24:33 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-12-12 18:24:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-12-12 18:24:29 ----A---- C:\Windows\system32\mshtml.dll
2012-12-12 18:24:28 ----A---- C:\Windows\system32\ieframe.dll
2012-12-12 18:24:27 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-12-12 18:22:34 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-12-12 18:22:34 ----A---- C:\Windows\system32\tzres.dll
2012-12-12 18:22:24 ----A---- C:\Windows\system32\win32k.sys
2012-12-12 18:22:12 ----A---- C:\Windows\system32\winsrv.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\KernelBase.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\kernel32.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\conhost.exe
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2012-12-12 18:22:10 ----A---- C:\Windows\SYSWOW64\setup16.exe
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\wow32.dll
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64win.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64cpu.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\ntvdm64.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----A---- C:\Windows\SYSWOW64\instnm.exe
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:03 ----A---- C:\Windows\SYSWOW64\user.exe
2012-12-12 18:20:52 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-12-12 18:20:52 ----A---- C:\Windows\system32\atmfd.dll
2012-12-12 18:20:51 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-12-12 18:20:51 ----A---- C:\Windows\system32\atmlib.dll
2012-12-12 18:20:49 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2012-12-12 18:20:49 ----A---- C:\Windows\system32\dpnet.dll
2012-12-04 23:03:38 ----D---- C:\Program Files (x86)\AGEIA Technologies
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvoglv64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvinitx.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdap64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2012-12-04 23:00:03 ----D---- C:\NVIDIA
2012-11-30 22:43:52 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2012-11-30 19:41:08 ----D---- C:\Users\Vastl\AppData\Roaming\Theta
2012-11-30 19:15:33 ----D---- C:\Program Files (x86)\Ubisoft
2012-11-30 17:02:34 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-11-30 17:02:34 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-11-30 17:02:34 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-11-30 17:02:33 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-11-30 17:02:33 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-11-30 17:02:32 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-11-30 17:02:29 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-11-30 17:02:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-11-30 17:02:29 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-11-30 17:02:29 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-11-30 17:02:26 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-11-30 17:02:26 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-11-30 17:02:24 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-11-30 17:02:15 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-11-30 17:02:15 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-11-30 17:02:12 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-11-30 17:02:12 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-11-30 17:02:11 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-11-30 17:02:11 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-11-30 17:02:11 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-11-30 17:02:11 ----A---- C:\Windows\system32\X3DAudio1_2.dll
======List of files/folders modified in the last 1 month======
2012-12-29 11:01:03 ----D---- C:\Windows\Temp
2012-12-29 10:57:27 ----D---- C:\Windows\System32
2012-12-29 10:57:27 ----D---- C:\Windows\inf
2012-12-29 10:57:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-29 10:54:48 ----D---- C:\Windows\system32\config
2012-12-29 10:53:13 ----D---- C:\ProgramData\NVIDIA
2012-12-29 10:51:44 ----SHD---- C:\Windows\Installer
2012-12-29 10:51:44 ----RD---- C:\Program Files (x86)
2012-12-29 10:51:44 ----HD---- C:\ProgramData
2012-12-29 10:51:18 ----D---- C:\Users\Vastl\AppData\Roaming\Skype
2012-12-29 10:06:06 ----D---- C:\Program Files (x86)\Adobe
2012-12-29 09:23:51 ----D---- C:\Windows\system32\Tasks
2012-12-29 09:23:46 ----D---- C:\Windows\Tasks
2012-12-29 09:23:18 ----SHD---- C:\System Volume Information
2012-12-29 09:20:04 ----D---- C:\Users\Vastl\AppData\Roaming\uTorrent
2012-12-29 07:53:09 ----D---- C:\Windows\system32\drivers
2012-12-28 23:59:09 ----D---- C:\ProgramData\PMB Files
2012-12-28 21:06:16 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-12-28 21:06:12 ----D---- C:\Windows\SysWOW64
2012-12-28 21:06:00 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-28 20:11:24 ----D---- C:\Windows\Minidump
2012-12-28 20:11:19 ----D---- C:\Windows
2012-12-28 19:38:26 ----RD---- C:\Program Files
2012-12-28 10:30:38 ----D---- C:\Windows\SYSWOW64\RTCOM
2012-12-28 10:30:35 ----D---- C:\Windows\system32\catroot
2012-12-28 10:30:34 ----D---- C:\Windows\system32\DriverStore
2012-12-28 10:30:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-23 19:24:15 ----D---- C:\Windows\rescache
2012-12-23 18:58:50 ----D---- C:\Users\Vastl\AppData\Roaming\vlc
2012-12-23 07:07:53 ----D---- C:\Windows\system32\catroot2
2012-12-22 17:58:43 ----D---- C:\Program Files (x86)\Diablo III
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wfp
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wbem
2012-12-20 17:51:02 ----D---- C:\Windows\AppCompat
2012-12-20 17:51:00 ----HD---- C:\GrandeDevice
2012-12-20 17:50:58 ----D---- C:\Windows\registration
2012-12-20 17:50:50 ----RHD---- C:\MSOCache
2012-12-15 00:33:37 ----D---- C:\Windows\system32\drivers\etc
2012-12-15 00:33:37 ----D---- C:\Program Files (x86)\Internet Explorer
2012-12-15 00:33:36 ----D---- C:\Windows\system32\drivers\UMDF
2012-12-15 00:33:36 ----D---- C:\Windows\system32\CodeIntegrity
2012-12-15 00:33:34 ----D---- C:\Users\Vastl\AppData\Roaming\PSpad
2012-12-15 00:33:29 ----D---- C:\Program Files (x86)\PSPad editor
2012-12-15 00:33:02 ----D---- C:\Users\Vastl\AppData\Roaming\Mozilla
2012-12-15 00:32:58 ----D---- C:\Users\Vastl\AppData\Roaming\DAEMON Tools Lite
2012-12-15 00:32:50 ----SD---- C:\ProgramData\Microsoft
2012-12-14 23:00:28 ----D---- C:\Windows\Logs
2012-12-14 23:00:27 ----D---- C:\Windows\debug
2012-12-13 22:20:51 ----D---- C:\Program Files (x86)\Common Files
2012-12-13 07:41:48 ----D---- C:\Windows\winsxs
2012-12-12 23:02:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-12-12 23:02:50 ----D---- C:\Windows\system32\cs-CZ
2012-12-12 23:02:49 ----D---- C:\Windows\SYSWOW64\migration
2012-12-12 23:02:49 ----D---- C:\Windows\system32\migration
2012-12-12 23:02:49 ----D---- C:\Windows\AppPatch
2012-12-12 23:02:49 ----D---- C:\Program Files\Internet Explorer
2012-12-12 18:25:52 ----A---- C:\Windows\system32\MRT.exe
2012-12-12 18:24:23 ----D---- C:\ProgramData\Microsoft Help
2012-12-12 17:09:45 ----D---- C:\Program Files (x86)\uTorrent
2012-12-12 13:35:24 ----D---- C:\ProgramData\Adobe
2012-12-12 07:09:20 ----D---- C:\Windows\Prefetch
2012-12-10 15:21:51 ----SD---- C:\Users\Vastl\AppData\Roaming\Microsoft
2012-12-04 23:03:48 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-12-03 16:47:14 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvumdshimx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispgenco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvapi64.dll
2012-12-01 16:48:49 ----D---- C:\Users\Vastl\AppData\Roaming\Adobe
2012-12-01 16:29:12 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-12-01 06:49:26 ----A---- C:\Windows\system32\nvsvcr.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvshext.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvmctray.dll
2012-12-01 06:49:24 ----A---- C:\Windows\system32\nvvsvc.exe
2012-12-01 06:48:41 ----A---- C:\Windows\system32\nvcpl.dll
2012-12-01 06:48:37 ----A---- C:\Windows\system32\nvsvc64.dll
2012-11-30 19:14:52 ----RSD---- C:\Windows\assembly
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2010-11-22 24880]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-11-22 303408]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 168544]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-25 283200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2000-01-01 4065296]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [2010-05-10 33592]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2010-10-22 14136]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-12-01 890216]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-12-03 1259880]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-28 76888]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]
R2 XRNADB;XRcnStatutsDatabase; C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe [2011-04-22 95232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 42360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-11 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-23 529744]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-29 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Vastl at 2012-12-29 11:01:02
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 650 GB (68%) free of 954 GB
Total RAM: 4087 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:01:04, on 29.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\trend micro\Vastl.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Launcher3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 3045B
O4 - HKLM\..\Run: [DocuPrint 3045B RUN] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe"
O4 - HKLM\..\Run: [StatusAutoRun3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Vplalv] C:\Users\Vastl\AppData\Roaming\Vplalv.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3167788445-3503430199-2841087581-1004\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3167788445-3503430199-2841087581-1004\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 9407 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmW.exe"
\??\C:\Windows\system32\conhost.exe "1099219945125803958853130781-1091637615701744509920964987-441965232786904375
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe"
\??\C:\Windows\system32\conhost.exe "-1431951668188417705816021013381608471585410183548-628711265-9881193021272837265
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Windows\system32\wuauclt.exe"
C:\Windows\System32\svchost.exe -k secsvcs
taskeng.exe {895321D6-1E1D-4D39-9595-961CF7FC0BA7}
taskhost.exe $(Arg0)
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
"C:\Users\Vastl\Downloads\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35]
"Description"=
"Path"=C:\Windows\system32\npdeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-12-21 351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2012-10-02 5748928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-12-21 53744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02 4119744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 155384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2916584]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20 444904]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 12503184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"AdobeBridge"= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
"Vplalv"=C:\Users\Vastl\AppData\Roaming\Vplalv.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-06-25 1073352]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Launcher3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-04-22 2570752]
"DocuPrint 3045B RUN"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe [2011-04-22 355840]
"StatusAutoRun3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe [2011-04-22 4476928]
""= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
======List of files/folders created in the last 1 month======
2012-12-29 10:51:42 ----A---- C:\AdwCleaner[S1].txt
2012-12-29 09:24:10 ----D---- C:\Program Files (x86)\Driver-Soft
2012-12-29 09:17:55 ----D---- C:\ProgramData\DriverGenius
2012-12-29 07:54:10 ----A---- C:\AdwCleaner[R1].txt
2012-12-28 19:38:26 ----D---- C:\rsit
2012-12-28 19:38:26 ----D---- C:\Program Files\trend micro
2012-12-28 10:30:16 ----A---- C:\Windows\system32\WavesGUILib.dll
2012-12-28 10:30:15 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tosade.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tepeqapo64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSWOW64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSX64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSH64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSHP64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFSS_APO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFNHK64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtPgEx64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCfg64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkApi64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DHT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DAA64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoRes64.dat
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoInstII64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEA64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\KAAPORT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2012-12-28 10:30:14 ----D---- C:\Program Files (x86)\Realtek
2012-12-28 10:30:14 ----A---- C:\Windows\system32\FMAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAR64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAC64.dll
2012-12-28 10:30:06 ----HD---- C:\Program Files (x86)\Temp
2012-12-28 10:30:06 ----A---- C:\Windows\RtlExUpd.dll
2012-12-25 09:23:04 ----D---- C:\Program Files\NetBeans 7.2.1
2012-12-22 19:26:09 ----D---- C:\Users\Vastl\AppData\Roaming\TS3Client
2012-12-22 19:25:53 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2012-12-21 20:04:12 ----D---- C:\Users\Vastl\AppData\Roaming\NetBeans
2012-12-21 19:51:53 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaws.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaw.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\java.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\deployJava1.dll
2012-12-21 19:50:15 ----D---- C:\Program Files\Java
2012-12-21 17:45:23 ----D---- C:\Users\Vastl\AppData\Roaming\TeamViewer
2012-12-15 19:34:38 ----D---- C:\Users\Vastl\AppData\Roaming\mIRC
2012-12-14 23:21:05 ----D---- C:\Users\Vastl\AppData\Roaming\Malwarebytes
2012-12-14 23:20:59 ----D---- C:\ProgramData\Malwarebytes
2012-12-13 22:21:28 ----D---- C:\Program Files (x86)\Convar
2012-12-13 12:31:52 ----D---- C:\xampp
2012-12-12 18:24:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-12-12 18:24:40 ----A---- C:\Windows\system32\mshtmled.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieui.dll
2012-12-12 18:24:37 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\msfeeds.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\jscript9.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-12-12 18:24:36 ----A---- C:\Windows\system32\wininet.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\vbscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jsproxy.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jscript.dll
2012-12-12 18:24:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-12-12 18:24:34 ----A---- C:\Windows\system32\iertutil.dll
2012-12-12 18:24:33 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-12-12 18:24:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-12-12 18:24:29 ----A---- C:\Windows\system32\mshtml.dll
2012-12-12 18:24:28 ----A---- C:\Windows\system32\ieframe.dll
2012-12-12 18:24:27 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-12-12 18:22:34 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-12-12 18:22:34 ----A---- C:\Windows\system32\tzres.dll
2012-12-12 18:22:24 ----A---- C:\Windows\system32\win32k.sys
2012-12-12 18:22:12 ----A---- C:\Windows\system32\winsrv.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\KernelBase.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\kernel32.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\conhost.exe
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2012-12-12 18:22:10 ----A---- C:\Windows\SYSWOW64\setup16.exe
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\wow32.dll
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64win.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64cpu.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\ntvdm64.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----A---- C:\Windows\SYSWOW64\instnm.exe
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:03 ----A---- C:\Windows\SYSWOW64\user.exe
2012-12-12 18:20:52 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-12-12 18:20:52 ----A---- C:\Windows\system32\atmfd.dll
2012-12-12 18:20:51 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-12-12 18:20:51 ----A---- C:\Windows\system32\atmlib.dll
2012-12-12 18:20:49 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2012-12-12 18:20:49 ----A---- C:\Windows\system32\dpnet.dll
2012-12-04 23:03:38 ----D---- C:\Program Files (x86)\AGEIA Technologies
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvoglv64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvinitx.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdap64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2012-12-04 23:00:03 ----D---- C:\NVIDIA
2012-11-30 22:43:52 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2012-11-30 19:41:08 ----D---- C:\Users\Vastl\AppData\Roaming\Theta
2012-11-30 19:15:33 ----D---- C:\Program Files (x86)\Ubisoft
2012-11-30 17:02:34 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2012-11-30 17:02:34 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2012-11-30 17:02:34 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-11-30 17:02:33 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2012-11-30 17:02:33 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-11-30 17:02:32 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-11-30 17:02:32 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-11-30 17:02:31 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-11-30 17:02:30 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-11-30 17:02:29 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2012-11-30 17:02:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2012-11-30 17:02:29 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-11-30 17:02:29 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-11-30 17:02:28 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-11-30 17:02:27 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-11-30 17:02:26 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2012-11-30 17:02:26 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-11-30 17:02:25 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-11-30 17:02:24 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-11-30 17:02:24 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-11-30 17:02:23 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-11-30 17:02:22 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-11-30 17:02:20 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2012-11-30 17:02:19 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-11-30 17:02:19 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-11-30 17:02:18 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-11-30 17:02:17 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-11-30 17:02:16 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-11-30 17:02:15 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2012-11-30 17:02:15 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-11-30 17:02:14 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-11-30 17:02:13 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-11-30 17:02:12 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2012-11-30 17:02:12 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-11-30 17:02:11 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2012-11-30 17:02:11 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2012-11-30 17:02:11 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-11-30 17:02:11 ----A---- C:\Windows\system32\X3DAudio1_2.dll
======List of files/folders modified in the last 1 month======
2012-12-29 11:01:03 ----D---- C:\Windows\Temp
2012-12-29 10:57:27 ----D---- C:\Windows\System32
2012-12-29 10:57:27 ----D---- C:\Windows\inf
2012-12-29 10:57:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-29 10:54:48 ----D---- C:\Windows\system32\config
2012-12-29 10:53:13 ----D---- C:\ProgramData\NVIDIA
2012-12-29 10:51:44 ----SHD---- C:\Windows\Installer
2012-12-29 10:51:44 ----RD---- C:\Program Files (x86)
2012-12-29 10:51:44 ----HD---- C:\ProgramData
2012-12-29 10:51:18 ----D---- C:\Users\Vastl\AppData\Roaming\Skype
2012-12-29 10:06:06 ----D---- C:\Program Files (x86)\Adobe
2012-12-29 09:23:51 ----D---- C:\Windows\system32\Tasks
2012-12-29 09:23:46 ----D---- C:\Windows\Tasks
2012-12-29 09:23:18 ----SHD---- C:\System Volume Information
2012-12-29 09:20:04 ----D---- C:\Users\Vastl\AppData\Roaming\uTorrent
2012-12-29 07:53:09 ----D---- C:\Windows\system32\drivers
2012-12-28 23:59:09 ----D---- C:\ProgramData\PMB Files
2012-12-28 21:06:16 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-12-28 21:06:12 ----D---- C:\Windows\SysWOW64
2012-12-28 21:06:00 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-28 20:11:24 ----D---- C:\Windows\Minidump
2012-12-28 20:11:19 ----D---- C:\Windows
2012-12-28 19:38:26 ----RD---- C:\Program Files
2012-12-28 10:30:38 ----D---- C:\Windows\SYSWOW64\RTCOM
2012-12-28 10:30:35 ----D---- C:\Windows\system32\catroot
2012-12-28 10:30:34 ----D---- C:\Windows\system32\DriverStore
2012-12-28 10:30:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-23 19:24:15 ----D---- C:\Windows\rescache
2012-12-23 18:58:50 ----D---- C:\Users\Vastl\AppData\Roaming\vlc
2012-12-23 07:07:53 ----D---- C:\Windows\system32\catroot2
2012-12-22 17:58:43 ----D---- C:\Program Files (x86)\Diablo III
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wfp
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wbem
2012-12-20 17:51:02 ----D---- C:\Windows\AppCompat
2012-12-20 17:51:00 ----HD---- C:\GrandeDevice
2012-12-20 17:50:58 ----D---- C:\Windows\registration
2012-12-20 17:50:50 ----RHD---- C:\MSOCache
2012-12-15 00:33:37 ----D---- C:\Windows\system32\drivers\etc
2012-12-15 00:33:37 ----D---- C:\Program Files (x86)\Internet Explorer
2012-12-15 00:33:36 ----D---- C:\Windows\system32\drivers\UMDF
2012-12-15 00:33:36 ----D---- C:\Windows\system32\CodeIntegrity
2012-12-15 00:33:34 ----D---- C:\Users\Vastl\AppData\Roaming\PSpad
2012-12-15 00:33:29 ----D---- C:\Program Files (x86)\PSPad editor
2012-12-15 00:33:02 ----D---- C:\Users\Vastl\AppData\Roaming\Mozilla
2012-12-15 00:32:58 ----D---- C:\Users\Vastl\AppData\Roaming\DAEMON Tools Lite
2012-12-15 00:32:50 ----SD---- C:\ProgramData\Microsoft
2012-12-14 23:00:28 ----D---- C:\Windows\Logs
2012-12-14 23:00:27 ----D---- C:\Windows\debug
2012-12-13 22:20:51 ----D---- C:\Program Files (x86)\Common Files
2012-12-13 07:41:48 ----D---- C:\Windows\winsxs
2012-12-12 23:02:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-12-12 23:02:50 ----D---- C:\Windows\system32\cs-CZ
2012-12-12 23:02:49 ----D---- C:\Windows\SYSWOW64\migration
2012-12-12 23:02:49 ----D---- C:\Windows\system32\migration
2012-12-12 23:02:49 ----D---- C:\Windows\AppPatch
2012-12-12 23:02:49 ----D---- C:\Program Files\Internet Explorer
2012-12-12 18:25:52 ----A---- C:\Windows\system32\MRT.exe
2012-12-12 18:24:23 ----D---- C:\ProgramData\Microsoft Help
2012-12-12 17:09:45 ----D---- C:\Program Files (x86)\uTorrent
2012-12-12 13:35:24 ----D---- C:\ProgramData\Adobe
2012-12-12 07:09:20 ----D---- C:\Windows\Prefetch
2012-12-10 15:21:51 ----SD---- C:\Users\Vastl\AppData\Roaming\Microsoft
2012-12-04 23:03:48 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-12-03 16:47:14 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvumdshimx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispgenco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvapi64.dll
2012-12-01 16:48:49 ----D---- C:\Users\Vastl\AppData\Roaming\Adobe
2012-12-01 16:29:12 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-12-01 06:49:26 ----A---- C:\Windows\system32\nvsvcr.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvshext.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvmctray.dll
2012-12-01 06:49:24 ----A---- C:\Windows\system32\nvvsvc.exe
2012-12-01 06:48:41 ----A---- C:\Windows\system32\nvcpl.dll
2012-12-01 06:48:37 ----A---- C:\Windows\system32\nvsvc64.dll
2012-11-30 19:14:52 ----RSD---- C:\Windows\assembly
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2010-11-22 24880]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-11-22 303408]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 168544]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-25 283200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2000-01-01 4065296]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [2010-05-10 33592]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2010-10-22 14136]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-12-01 890216]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-12-03 1259880]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-28 76888]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]
R2 XRNADB;XRcnStatutsDatabase; C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe [2011-04-22 95232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 42360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-11 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-23 529744]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-29 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119488
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrt při zapnutí pc
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.:files
C:\Program Files (x86)\Skype\Toolbars
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Users\Vastl\AppData\Roaming\Vplalv.exe
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Vplalv"=-
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Modrá smrt při zapnutí pc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Vastl at 2012-12-30 16:08:59
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 649 GB (68%) free of 954 GB
Total RAM: 4087 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:09:01, on 30.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\trend micro\Vastl.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Launcher3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 3045B
O4 - HKLM\..\Run: [DocuPrint 3045B RUN] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe"
O4 - HKLM\..\Run: [StatusAutoRun3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 9111 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
taskeng.exe {186D218D-0A8E-43A4-9EA2-6D35C1D69C75}
"C:\Windows\system32\Dwm.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe"
C:\Windows\Explorer.EXE
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmW.exe"
\??\C:\Windows\system32\conhost.exe "1946509733-1021712856-74645384815374202951906477140-702162365-4396821372136301304
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe"
\??\C:\Windows\system32\conhost.exe "1164953115-2837458893380345582404634208436957-2830164131911049479-253100950
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3167788445-3503430199-2841087581-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3167788445-3503430199-2841087581-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
taskeng.exe {63723E83-A8A2-4902-B0CC-65901FADD7C2}
"C:\Users\Vastl\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35]
"Description"=
"Path"=C:\Windows\system32\npdeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-12-21 351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-12-21 53744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 155384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2916584]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20 444904]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 12503184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"AdobeBridge"= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-06-25 1073352]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Launcher3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-04-22 2570752]
"DocuPrint 3045B RUN"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe [2011-04-22 355840]
"StatusAutoRun3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe [2011-04-22 4476928]
""= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
======List of files/folders created in the last 1 month======
2012-12-30 16:02:06 ----D---- C:\_OTM
2012-12-29 10:51:42 ----A---- C:\AdwCleaner[S1].txt
2012-12-29 09:24:10 ----D---- C:\Program Files (x86)\Driver-Soft
2012-12-29 09:17:55 ----D---- C:\ProgramData\DriverGenius
2012-12-29 07:54:10 ----A---- C:\AdwCleaner[R1].txt
2012-12-28 19:38:26 ----D---- C:\rsit
2012-12-28 19:38:26 ----D---- C:\Program Files\trend micro
2012-12-28 10:30:16 ----A---- C:\Windows\system32\WavesGUILib.dll
2012-12-28 10:30:15 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tosade.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tepeqapo64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSWOW64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSX64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSH64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSHP64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFSS_APO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFNHK64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtPgEx64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCfg64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkApi64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DHT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DAA64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoRes64.dat
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoInstII64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEA64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\KAAPORT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2012-12-28 10:30:14 ----D---- C:\Program Files (x86)\Realtek
2012-12-28 10:30:14 ----A---- C:\Windows\system32\FMAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAR64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAC64.dll
2012-12-28 10:30:06 ----HD---- C:\Program Files (x86)\Temp
2012-12-28 10:30:06 ----A---- C:\Windows\RtlExUpd.dll
2012-12-25 09:23:04 ----D---- C:\Program Files\NetBeans 7.2.1
2012-12-22 19:26:09 ----D---- C:\Users\Vastl\AppData\Roaming\TS3Client
2012-12-22 19:25:53 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2012-12-21 20:04:12 ----D---- C:\Users\Vastl\AppData\Roaming\NetBeans
2012-12-21 19:51:53 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaws.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaw.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\java.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\deployJava1.dll
2012-12-21 19:50:15 ----D---- C:\Program Files\Java
2012-12-21 17:45:23 ----D---- C:\Users\Vastl\AppData\Roaming\TeamViewer
2012-12-15 19:34:38 ----D---- C:\Users\Vastl\AppData\Roaming\mIRC
2012-12-14 23:21:05 ----D---- C:\Users\Vastl\AppData\Roaming\Malwarebytes
2012-12-14 23:20:59 ----D---- C:\ProgramData\Malwarebytes
2012-12-13 22:21:28 ----D---- C:\Program Files (x86)\Convar
2012-12-13 12:31:52 ----D---- C:\xampp
2012-12-12 18:24:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-12-12 18:24:40 ----A---- C:\Windows\system32\mshtmled.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieui.dll
2012-12-12 18:24:37 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\msfeeds.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\jscript9.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-12-12 18:24:36 ----A---- C:\Windows\system32\wininet.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\vbscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jsproxy.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jscript.dll
2012-12-12 18:24:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-12-12 18:24:34 ----A---- C:\Windows\system32\iertutil.dll
2012-12-12 18:24:33 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-12-12 18:24:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-12-12 18:24:29 ----A---- C:\Windows\system32\mshtml.dll
2012-12-12 18:24:28 ----A---- C:\Windows\system32\ieframe.dll
2012-12-12 18:24:27 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-12-12 18:22:34 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-12-12 18:22:34 ----A---- C:\Windows\system32\tzres.dll
2012-12-12 18:22:24 ----A---- C:\Windows\system32\win32k.sys
2012-12-12 18:22:12 ----A---- C:\Windows\system32\winsrv.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\KernelBase.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\kernel32.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\conhost.exe
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2012-12-12 18:22:10 ----A---- C:\Windows\SYSWOW64\setup16.exe
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\wow32.dll
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64win.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64cpu.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\ntvdm64.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----A---- C:\Windows\SYSWOW64\instnm.exe
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:03 ----A---- C:\Windows\SYSWOW64\user.exe
2012-12-12 18:20:52 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-12-12 18:20:52 ----A---- C:\Windows\system32\atmfd.dll
2012-12-12 18:20:51 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-12-12 18:20:51 ----A---- C:\Windows\system32\atmlib.dll
2012-12-12 18:20:49 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2012-12-12 18:20:49 ----A---- C:\Windows\system32\dpnet.dll
2012-12-04 23:03:38 ----D---- C:\Program Files (x86)\AGEIA Technologies
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvoglv64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvinitx.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdap64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2012-12-04 23:00:03 ----D---- C:\NVIDIA
======List of files/folders modified in the last 1 month======
2012-12-30 16:09:01 ----D---- C:\Windows\Prefetch
2012-12-30 16:08:59 ----D---- C:\Windows\Temp
2012-12-30 16:07:06 ----D---- C:\ProgramData\NVIDIA
2012-12-30 16:04:40 ----D---- C:\Windows\system32\catroot2
2012-12-30 16:04:11 ----D---- C:\Windows\Minidump
2012-12-30 16:04:05 ----D---- C:\Windows
2012-12-30 16:02:07 ----RD---- C:\Program Files (x86)\Skype
2012-12-30 16:02:07 ----D---- C:\Windows\Tasks
2012-12-30 16:00:51 ----D---- C:\Windows\system32\config
2012-12-30 16:00:43 ----D---- C:\Windows\system32\Tasks
2012-12-30 16:00:41 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-12-29 21:39:33 ----D---- C:\Users\Vastl\AppData\Roaming\vlc
2012-12-29 21:01:36 ----D---- C:\Windows\System32
2012-12-29 21:01:35 ----D---- C:\Windows\inf
2012-12-29 21:01:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-29 17:26:28 ----D---- C:\Users\Vastl\AppData\Roaming\Skype
2012-12-29 17:26:23 ----D---- C:\ProgramData\PMB Files
2012-12-29 10:51:44 ----SHD---- C:\Windows\Installer
2012-12-29 10:51:44 ----RD---- C:\Program Files (x86)
2012-12-29 10:51:44 ----HD---- C:\ProgramData
2012-12-29 10:06:06 ----D---- C:\Program Files (x86)\Adobe
2012-12-29 09:23:18 ----SHD---- C:\System Volume Information
2012-12-29 09:20:04 ----D---- C:\Users\Vastl\AppData\Roaming\uTorrent
2012-12-29 07:53:09 ----D---- C:\Windows\system32\drivers
2012-12-28 21:06:16 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-12-28 21:06:12 ----D---- C:\Windows\SysWOW64
2012-12-28 21:06:00 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-28 19:38:26 ----RD---- C:\Program Files
2012-12-28 10:30:38 ----D---- C:\Windows\SYSWOW64\RTCOM
2012-12-28 10:30:35 ----D---- C:\Windows\system32\catroot
2012-12-28 10:30:34 ----D---- C:\Windows\system32\DriverStore
2012-12-28 10:30:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-23 19:24:15 ----D---- C:\Windows\rescache
2012-12-22 17:58:43 ----D---- C:\Program Files (x86)\Diablo III
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wfp
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wbem
2012-12-20 17:51:02 ----D---- C:\Windows\AppCompat
2012-12-20 17:51:00 ----HD---- C:\GrandeDevice
2012-12-20 17:50:58 ----D---- C:\Windows\registration
2012-12-20 17:50:50 ----RHD---- C:\MSOCache
2012-12-15 00:33:37 ----D---- C:\Windows\system32\drivers\etc
2012-12-15 00:33:37 ----D---- C:\Program Files (x86)\Internet Explorer
2012-12-15 00:33:36 ----D---- C:\Windows\system32\drivers\UMDF
2012-12-15 00:33:36 ----D---- C:\Windows\system32\CodeIntegrity
2012-12-15 00:33:34 ----D---- C:\Users\Vastl\AppData\Roaming\PSpad
2012-12-15 00:33:29 ----D---- C:\Program Files (x86)\PSPad editor
2012-12-15 00:33:02 ----D---- C:\Users\Vastl\AppData\Roaming\Mozilla
2012-12-15 00:32:58 ----D---- C:\Users\Vastl\AppData\Roaming\DAEMON Tools Lite
2012-12-15 00:32:50 ----SD---- C:\ProgramData\Microsoft
2012-12-14 23:00:28 ----D---- C:\Windows\Logs
2012-12-14 23:00:27 ----D---- C:\Windows\debug
2012-12-13 22:20:51 ----D---- C:\Program Files (x86)\Common Files
2012-12-13 07:41:48 ----D---- C:\Windows\winsxs
2012-12-12 23:02:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-12-12 23:02:50 ----D---- C:\Windows\system32\cs-CZ
2012-12-12 23:02:49 ----D---- C:\Windows\SYSWOW64\migration
2012-12-12 23:02:49 ----D---- C:\Windows\system32\migration
2012-12-12 23:02:49 ----D---- C:\Windows\AppPatch
2012-12-12 23:02:49 ----D---- C:\Program Files\Internet Explorer
2012-12-12 18:25:52 ----A---- C:\Windows\system32\MRT.exe
2012-12-12 18:24:23 ----D---- C:\ProgramData\Microsoft Help
2012-12-12 17:09:45 ----D---- C:\Program Files (x86)\uTorrent
2012-12-12 13:35:24 ----D---- C:\ProgramData\Adobe
2012-12-10 15:21:51 ----SD---- C:\Users\Vastl\AppData\Roaming\Microsoft
2012-12-04 23:03:48 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-12-03 16:47:14 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvumdshimx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispgenco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvapi64.dll
2012-12-01 16:48:49 ----D---- C:\Users\Vastl\AppData\Roaming\Adobe
2012-12-01 16:29:12 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-12-01 06:49:26 ----A---- C:\Windows\system32\nvsvcr.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvshext.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvmctray.dll
2012-12-01 06:49:24 ----A---- C:\Windows\system32\nvvsvc.exe
2012-12-01 06:48:41 ----A---- C:\Windows\system32\nvcpl.dll
2012-12-01 06:48:37 ----A---- C:\Windows\system32\nvsvc64.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2010-11-22 24880]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-11-22 303408]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 168544]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-25 283200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2000-01-01 4065296]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [2010-05-10 33592]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2010-10-22 14136]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-12-01 890216]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-28 76888]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]
R2 XRNADB;XRcnStatutsDatabase; C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe [2011-04-22 95232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-12-03 1259880]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-30 250808]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 42360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-11 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-23 529744]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-29 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Vastl at 2012-12-30 16:08:59
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 649 GB (68%) free of 954 GB
Total RAM: 4087 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:09:01, on 30.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\trend micro\Vastl.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Launcher3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 3045B
O4 - HKLM\..\Run: [DocuPrint 3045B RUN] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe"
O4 - HKLM\..\Run: [StatusAutoRun3045B] "C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe" Xerox WorkCentre 3045B,hide,\S
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 9111 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
taskeng.exe {186D218D-0A8E-43A4-9EA2-6D35C1D69C75}
"C:\Windows\system32\Dwm.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe"
C:\Windows\Explorer.EXE
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmW.exe"
\??\C:\Windows\system32\conhost.exe "1946509733-1021712856-74645384815374202951906477140-702162365-4396821372136301304
"C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmwj.exe"
\??\C:\Windows\system32\conhost.exe "1164953115-2837458893380345582404634208436957-2830164131911049479-253100950
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3167788445-3503430199-2841087581-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3167788445-3503430199-2841087581-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
taskeng.exe {63723E83-A8A2-4902-B0CC-65901FADD7C2}
"C:\Users\Vastl\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Vastl\AppData\Roaming\Mozilla\Firefox\Profiles\c0yqr4y1.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35]
"Description"=
"Path"=C:\Windows\system32\npdeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-12-21 351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-12-21 53744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 155384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2916584]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20 444904]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 12503184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"AdobeBridge"= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-06-25 1073352]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"Launcher3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-04-22 2570752]
"DocuPrint 3045B RUN"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmRun.exe [2011-04-22 355840]
"StatusAutoRun3045B"=C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmpl.exe [2011-04-22 4476928]
""= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
======List of files/folders created in the last 1 month======
2012-12-30 16:02:06 ----D---- C:\_OTM
2012-12-29 10:51:42 ----A---- C:\AdwCleaner[S1].txt
2012-12-29 09:24:10 ----D---- C:\Program Files (x86)\Driver-Soft
2012-12-29 09:17:55 ----D---- C:\ProgramData\DriverGenius
2012-12-29 07:54:10 ----A---- C:\AdwCleaner[R1].txt
2012-12-28 19:38:26 ----D---- C:\rsit
2012-12-28 19:38:26 ----D---- C:\Program Files\trend micro
2012-12-28 10:30:16 ----A---- C:\Windows\system32\WavesGUILib.dll
2012-12-28 10:30:15 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tosade.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tepeqapo64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\tadefxapo.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSWOW64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSX64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSTSH64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SRSHP64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFSS_APO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFNHK64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\SFAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtPgEx64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkCfg64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkAPO64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RtkApi64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTEED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RTCOM64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DHT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RP3DAA64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoRes64.dat
2012-12-28 10:30:15 ----A---- C:\Windows\system32\RCoInstII64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEP64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEL64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEG64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EED64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\R4EEA64A.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\KAAPORT64.dll
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2012-12-28 10:30:15 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2012-12-28 10:30:14 ----D---- C:\Program Files (x86)\Realtek
2012-12-28 10:30:14 ----A---- C:\Windows\system32\FMAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAR64.dll
2012-12-28 10:30:14 ----A---- C:\Windows\system32\AERTAC64.dll
2012-12-28 10:30:06 ----HD---- C:\Program Files (x86)\Temp
2012-12-28 10:30:06 ----A---- C:\Windows\RtlExUpd.dll
2012-12-25 09:23:04 ----D---- C:\Program Files\NetBeans 7.2.1
2012-12-22 19:26:09 ----D---- C:\Users\Vastl\AppData\Roaming\TS3Client
2012-12-22 19:25:53 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2012-12-21 20:04:12 ----D---- C:\Users\Vastl\AppData\Roaming\NetBeans
2012-12-21 19:51:53 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaws.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\javaw.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\java.exe
2012-12-21 19:51:53 ----A---- C:\Windows\system32\deployJava1.dll
2012-12-21 19:50:15 ----D---- C:\Program Files\Java
2012-12-21 17:45:23 ----D---- C:\Users\Vastl\AppData\Roaming\TeamViewer
2012-12-15 19:34:38 ----D---- C:\Users\Vastl\AppData\Roaming\mIRC
2012-12-14 23:21:05 ----D---- C:\Users\Vastl\AppData\Roaming\Malwarebytes
2012-12-14 23:20:59 ----D---- C:\ProgramData\Malwarebytes
2012-12-13 22:21:28 ----D---- C:\Program Files (x86)\Convar
2012-12-13 12:31:52 ----D---- C:\xampp
2012-12-12 18:24:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-12-12 18:24:40 ----A---- C:\Windows\system32\mshtmled.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2012-12-12 18:24:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\url.dll
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieUnatt.exe
2012-12-12 18:24:38 ----A---- C:\Windows\system32\ieui.dll
2012-12-12 18:24:37 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\urlmon.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\msfeeds.dll
2012-12-12 18:24:37 ----A---- C:\Windows\system32\jscript9.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-12-12 18:24:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-12-12 18:24:36 ----A---- C:\Windows\system32\wininet.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-12-12 18:24:35 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\vbscript.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jsproxy.dll
2012-12-12 18:24:35 ----A---- C:\Windows\system32\jscript.dll
2012-12-12 18:24:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-12-12 18:24:34 ----A---- C:\Windows\system32\iertutil.dll
2012-12-12 18:24:33 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-12-12 18:24:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-12-12 18:24:29 ----A---- C:\Windows\system32\mshtml.dll
2012-12-12 18:24:28 ----A---- C:\Windows\system32\ieframe.dll
2012-12-12 18:24:27 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-12-12 18:22:34 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-12-12 18:22:34 ----A---- C:\Windows\system32\tzres.dll
2012-12-12 18:22:24 ----A---- C:\Windows\system32\win32k.sys
2012-12-12 18:22:12 ----A---- C:\Windows\system32\winsrv.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\KernelBase.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\kernel32.dll
2012-12-12 18:22:12 ----A---- C:\Windows\system32\conhost.exe
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2012-12-12 18:22:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2012-12-12 18:22:10 ----A---- C:\Windows\SYSWOW64\setup16.exe
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\wow32.dll
2012-12-12 18:22:09 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64win.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64cpu.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\wow64.dll
2012-12-12 18:22:09 ----A---- C:\Windows\system32\ntvdm64.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:07 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-12-12 18:22:07 ----A---- C:\Windows\SYSWOW64\instnm.exe
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-12-12 18:22:06 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2012-12-12 18:22:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-12-12 18:22:04 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-12-12 18:22:03 ----A---- C:\Windows\SYSWOW64\user.exe
2012-12-12 18:20:52 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2012-12-12 18:20:52 ----A---- C:\Windows\system32\atmfd.dll
2012-12-12 18:20:51 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2012-12-12 18:20:51 ----A---- C:\Windows\system32\atmlib.dll
2012-12-12 18:20:49 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2012-12-12 18:20:49 ----A---- C:\Windows\system32\dpnet.dll
2012-12-04 23:03:38 ----D---- C:\Program Files (x86)\AGEIA Technologies
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvopencl.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvoglv64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvinitx.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdap64.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvid.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcuda.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\nvcompiler.dll
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-12-04 23:00:41 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2012-12-04 23:00:03 ----D---- C:\NVIDIA
======List of files/folders modified in the last 1 month======
2012-12-30 16:09:01 ----D---- C:\Windows\Prefetch
2012-12-30 16:08:59 ----D---- C:\Windows\Temp
2012-12-30 16:07:06 ----D---- C:\ProgramData\NVIDIA
2012-12-30 16:04:40 ----D---- C:\Windows\system32\catroot2
2012-12-30 16:04:11 ----D---- C:\Windows\Minidump
2012-12-30 16:04:05 ----D---- C:\Windows
2012-12-30 16:02:07 ----RD---- C:\Program Files (x86)\Skype
2012-12-30 16:02:07 ----D---- C:\Windows\Tasks
2012-12-30 16:00:51 ----D---- C:\Windows\system32\config
2012-12-30 16:00:43 ----D---- C:\Windows\system32\Tasks
2012-12-30 16:00:41 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-12-29 21:39:33 ----D---- C:\Users\Vastl\AppData\Roaming\vlc
2012-12-29 21:01:36 ----D---- C:\Windows\System32
2012-12-29 21:01:35 ----D---- C:\Windows\inf
2012-12-29 21:01:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-29 17:26:28 ----D---- C:\Users\Vastl\AppData\Roaming\Skype
2012-12-29 17:26:23 ----D---- C:\ProgramData\PMB Files
2012-12-29 10:51:44 ----SHD---- C:\Windows\Installer
2012-12-29 10:51:44 ----RD---- C:\Program Files (x86)
2012-12-29 10:51:44 ----HD---- C:\ProgramData
2012-12-29 10:06:06 ----D---- C:\Program Files (x86)\Adobe
2012-12-29 09:23:18 ----SHD---- C:\System Volume Information
2012-12-29 09:20:04 ----D---- C:\Users\Vastl\AppData\Roaming\uTorrent
2012-12-29 07:53:09 ----D---- C:\Windows\system32\drivers
2012-12-28 21:06:16 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-12-28 21:06:12 ----D---- C:\Windows\SysWOW64
2012-12-28 21:06:00 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-28 19:38:26 ----RD---- C:\Program Files
2012-12-28 10:30:38 ----D---- C:\Windows\SYSWOW64\RTCOM
2012-12-28 10:30:35 ----D---- C:\Windows\system32\catroot
2012-12-28 10:30:34 ----D---- C:\Windows\system32\DriverStore
2012-12-28 10:30:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-23 19:24:15 ----D---- C:\Windows\rescache
2012-12-22 17:58:43 ----D---- C:\Program Files (x86)\Diablo III
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wfp
2012-12-20 17:51:04 ----D---- C:\Windows\system32\wbem
2012-12-20 17:51:02 ----D---- C:\Windows\AppCompat
2012-12-20 17:51:00 ----HD---- C:\GrandeDevice
2012-12-20 17:50:58 ----D---- C:\Windows\registration
2012-12-20 17:50:50 ----RHD---- C:\MSOCache
2012-12-15 00:33:37 ----D---- C:\Windows\system32\drivers\etc
2012-12-15 00:33:37 ----D---- C:\Program Files (x86)\Internet Explorer
2012-12-15 00:33:36 ----D---- C:\Windows\system32\drivers\UMDF
2012-12-15 00:33:36 ----D---- C:\Windows\system32\CodeIntegrity
2012-12-15 00:33:34 ----D---- C:\Users\Vastl\AppData\Roaming\PSpad
2012-12-15 00:33:29 ----D---- C:\Program Files (x86)\PSPad editor
2012-12-15 00:33:02 ----D---- C:\Users\Vastl\AppData\Roaming\Mozilla
2012-12-15 00:32:58 ----D---- C:\Users\Vastl\AppData\Roaming\DAEMON Tools Lite
2012-12-15 00:32:50 ----SD---- C:\ProgramData\Microsoft
2012-12-14 23:00:28 ----D---- C:\Windows\Logs
2012-12-14 23:00:27 ----D---- C:\Windows\debug
2012-12-13 22:20:51 ----D---- C:\Program Files (x86)\Common Files
2012-12-13 07:41:48 ----D---- C:\Windows\winsxs
2012-12-12 23:02:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-12-12 23:02:50 ----D---- C:\Windows\system32\cs-CZ
2012-12-12 23:02:49 ----D---- C:\Windows\SYSWOW64\migration
2012-12-12 23:02:49 ----D---- C:\Windows\system32\migration
2012-12-12 23:02:49 ----D---- C:\Windows\AppPatch
2012-12-12 23:02:49 ----D---- C:\Program Files\Internet Explorer
2012-12-12 18:25:52 ----A---- C:\Windows\system32\MRT.exe
2012-12-12 18:24:23 ----D---- C:\ProgramData\Microsoft Help
2012-12-12 17:09:45 ----D---- C:\Program Files (x86)\uTorrent
2012-12-12 13:35:24 ----D---- C:\ProgramData\Adobe
2012-12-10 15:21:51 ----SD---- C:\Users\Vastl\AppData\Roaming\Microsoft
2012-12-04 23:03:48 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-12-03 16:47:14 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvumdshimx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispgenco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvdispco64.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvd3dumx.dll
2012-12-03 16:47:14 ----A---- C:\Windows\system32\nvapi64.dll
2012-12-01 16:48:49 ----D---- C:\Users\Vastl\AppData\Roaming\Adobe
2012-12-01 16:29:12 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-12-01 06:49:26 ----A---- C:\Windows\system32\nvsvcr.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvshext.dll
2012-12-01 06:49:25 ----A---- C:\Windows\system32\nvmctray.dll
2012-12-01 06:49:24 ----A---- C:\Windows\system32\nvvsvc.exe
2012-12-01 06:48:41 ----A---- C:\Windows\system32\nvcpl.dll
2012-12-01 06:48:37 ----A---- C:\Windows\system32\nvsvc64.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2010-11-22 24880]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-11-22 303408]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 168544]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 126320]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-25 283200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2000-01-01 4065296]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [2010-05-10 33592]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2010-10-22 14136]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2010-08-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-12-01 890216]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-28 76888]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]
R2 XRNADB;XRcnStatutsDatabase; C:\Program Files (x86)\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe [2011-04-22 95232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-12-03 1259880]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-30 250808]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 42360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-11 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-23 529744]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-29 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119488
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Modrá smrt při zapnutí pc
Smazáno. Ještě poprosím o prověření souboru C:\Windows\system32\R4EEG64A.dll online na www.virustotal.com . Výsledek oznamte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Modrá smrt při zapnutí pc
Jinak při spuštění OTM a následném Move It počítač hodil BSOD poté co jsem pc restartoval, šel OTM správně.
https://www.virustotal.com/file/7578fcb ... 356882019/
https://www.virustotal.com/file/7578fcb ... 356882019/