...po nechténé instalaci yontoo je všechno spatně:-( HELP!
Napsal: 28 led 2013 23:46
Dobrý den
Moc tomu tady nerozumím, celkově jako PC. prosím buďte schovívaví.
Něco sem tady vyčetl o tom DDS logu tak to sem dám...
Problém je v tom že PC je enormně pomalé. Pisi nyní z nouzového režimu. Prohnal sem to Nodem, RegCure Pro, Speedupmypc...nejaká svinstva to našla ale stalé stejne pomale, nepoužitelné...
S nejakým zrejme pornem mi syn stahl yontoo a od te doby je asi problem...
PC se načíta asi pet minut a po "vítejte" je černá obrazovka s nápisem "Konfigurování Individualního nastavení uživatele" (což tam drive nebylo) a pod tím C:/Program files/Microsoft/Windows Installer.exe
DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.11.2
Run by cesko at 23:25:16 on 2013-01-28
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.2460 [GMT 1:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Windows\system32\wbem\wmiprvse.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=111304&tt=0313_4&babsrc=HP_ss&mntrId=18f252fd000000000000001d604d90ae
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://http://www.yahoo.com/?ilc=8.yahoo.com
mDefault_Page_URL = hxxp://http://www.yahoo.com/?ilc=8.yahoo.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
uURLSearchHooks: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - <orphaned>
uURLSearchHooks: {687578b9-7132-4a7a-80e4-30ee31099e03} - <orphaned>
uURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - <orphaned>
mURLSearchHooks: {855F3B16-6D32-4fe6-8A56-BBB695989046} - <orphaned>
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: IEExtension.VDownloaderBHO: {7b523e7c-f096-4e36-a0cb-7efeb5c675c1} -
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - LocalServer32 - <no file>
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [Microsoft® Windows® OS Manager] c:\program files\microsoft\Windows Installer.exe
mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe
mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe
mRun: [Microsoft® Windows® Operating System] c:\program files\microsoft\Windows Installer.exe
uExplorerRun: [Microsoft Explorer Policies] c:\program files\microsoft\Windows Installer.exe
mExplorerRun: [Microsoft Explorer Policies] c:\program files\microsoft\Windows Installer.exe
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 10.0.0.138
TCP: Interfaces\{93E4835A-8CC3-420B-91E5-48014E065A30} : DHCPNameServer = 10.0.0.138
TCP: Interfaces\{BAE6D55F-F66B-4F39-A3DD-E2F6609718A1} : DHCPNameServer = 10.0.0.138
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= c:\progra~2\browse~1\23765~1.24\{16cdf~1\browse~1.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
mASetup: {UR218G3C-0SUD-JCT2-1756-57VI7413CH5M} - c:\program files\microsoft\Windows Installer.exe
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-5-3 242240]
R3 pmkbdfltr;PenMount Keyboard Device Filter Driver;c:\windows\system32\drivers\pmkbdfltr.sys [2012-11-1 15248]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2011-11-1 27632]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2012-11-29 38608]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-1-8 161536]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2012-4-6 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2011-9-9 13224]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2008-5-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2008-5-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2008-5-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2008-5-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2008-5-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2008-5-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2008-5-16 115752]
S3 Uniblue.MaxiDiskSvc;Uniblue Maxi Disk Service;c:\program files\uniblue\maxidisk\service.exe [2013-1-28 30032]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2013-01-28 22:15:40 792 ----a-w- c:\users\cesko\appdata\roaming\ceskov3.5.0.0.vbs
2013-01-28 21:37:48 -------- d-----w- c:\program files\common files\ParetoLogic
2013-01-28 21:37:44 -------- d-----w- c:\program files\ParetoLogic
2013-01-28 21:18:21 -------- d-----w- c:\users\cesko\appdata\roaming\ParetoLogic
2013-01-28 21:18:21 -------- d-----w- c:\users\cesko\appdata\roaming\DriverCure
2013-01-28 21:18:10 -------- d-----w- c:\programdata\ParetoLogic
2013-01-28 19:28:19 -------- d-----w- c:\users\cesko\appdata\local\{4722288C-0213-4D33-9063-CFF956DEC3AF}
2013-01-28 19:17:49 -------- d-----w- c:\program files\VS Revo Group
2013-01-28 01:45:43 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2013-01-28 00:46:06 -------- d-----w- c:\users\cesko\appdata\local\{83232A03-1FD4-42FB-9EAB-982BAB386955}
2013-01-27 12:38:39 -------- d-----w- c:\users\cesko\appdata\local\{2AFB720C-D324-466E-B7A1-83BEABAE4EAC}
2013-01-27 00:04:06 -------- d-----w- c:\users\cesko\appdata\local\{20B84885-CAA7-4C65-B13F-C08914827D4B}
2013-01-26 12:03:41 -------- d-----w- c:\users\cesko\appdata\local\{8C5BF28A-81A7-4A6C-8F73-1288C9F541F3}
2013-01-26 00:03:08 -------- d-----w- c:\users\cesko\appdata\local\{3A64584D-FA5F-48A6-8F3F-C4FC980FD5A3}
2013-01-25 12:02:43 -------- d-----w- c:\users\cesko\appdata\local\{3BC836DC-8B9C-45A0-A1C0-58C84D4A8702}
2013-01-24 13:53:31 -------- d-----w- c:\users\cesko\appdata\local\{ECAB57D7-8580-453A-9E41-E37FF5957647}
2013-01-24 13:09:22 -------- d-----r- c:\program files\Skype
2013-01-23 21:28:19 -------- d-----w- c:\users\cesko\appdata\local\{5353894A-B67C-4D52-9B48-3237E468994B}
2013-01-23 09:27:33 -------- d-----w- c:\users\cesko\appdata\local\{79497AE8-2935-495F-B947-A379D36D0FA2}
2013-01-22 11:51:06 -------- d-----w- c:\users\cesko\appdata\local\{337C0669-B2D0-4323-86AB-D16749679018}
2013-01-21 13:08:27 -------- d-----w- c:\users\cesko\appdata\local\{C846D032-C137-4679-A4BD-AAB8DB996390}
2013-01-20 22:36:13 -------- d-----w- c:\users\cesko\appdata\local\{8F12A814-4113-4B2B-ADD9-D16FBB837C14}
2013-01-20 10:35:39 -------- d-----w- c:\users\cesko\appdata\local\{6ED79342-1CBA-4E7C-8071-BD95DA807EBB}
2013-01-19 13:19:22 -------- d-----w- c:\users\cesko\appdata\local\{B7C81F07-DA4A-4F09-A78C-3CD7EF3EDEB7}
2013-01-19 01:18:55 -------- d-----w- c:\users\cesko\appdata\local\{FF386866-AE8E-48A5-AEF7-FF85AEF2A14F}
2013-01-18 10:38:47 -------- d-----w- c:\users\cesko\appdata\local\{DC12CB2C-2301-449F-8894-D5444D0CD76F}
2013-01-17 22:38:23 -------- d-----w- c:\users\cesko\appdata\local\{9A0D6D4D-F5C0-46BA-ABC4-A8BDD36F1757}
2013-01-17 11:02:20 -------- d-----w- c:\program files\Zrychleni Pocitace
2013-01-17 11:00:13 -------- d-----w- c:\program files\pazera-software
2013-01-17 10:37:59 -------- d-----w- c:\users\cesko\appdata\local\{D8E41A60-C75C-496A-8FAE-873024F7986D}
2013-01-16 19:49:50 -------- d-----w- c:\users\cesko\appdata\local\{BA9EE525-8785-47D7-8CA2-3743DC7CBC38}
2013-01-16 07:27:07 -------- d-----w- c:\users\cesko\appdata\local\{9661900F-F769-496E-9DE4-25E92DE4210C}
2013-01-15 20:01:24 -------- d-----w- c:\users\cesko\appdata\roaming\TuneUp Software
2013-01-15 20:01:13 -------- d-----w- c:\programdata\TuneUp Software
2013-01-15 20:01:07 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-01-15 20:01:07 -------- d--h--w- c:\programdata\Common Files
2013-01-15 19:57:32 -------- d-----w- c:\users\cesko\appdata\roaming\Broad Intelligence
2013-01-15 19:57:30 -------- d-----w- c:\users\cesko\appdata\roaming\OpenCandy
2013-01-15 19:57:30 -------- d-----w- c:\program files\MediaCoder
2013-01-15 16:06:20 -------- d-----w- c:\users\cesko\appdata\local\{DB51A627-CED9-4B04-9A11-D364F8E12319}
2013-01-15 01:48:10 -------- d-----w- c:\users\cesko\appdata\local\{B41241F8-A478-4D70-B660-DB0FF6EABAB2}
2013-01-14 19:21:52 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-14 13:47:44 -------- d-----w- c:\users\cesko\appdata\local\{9C89DA1B-3E31-435B-B7AC-EFF2EAF2D3CC}
2013-01-14 01:47:20 -------- d-----w- c:\users\cesko\appdata\local\{BA0F75A1-2F4E-48B3-A03D-1F7EE934BFDB}
2013-01-13 13:46:54 -------- d-----w- c:\users\cesko\appdata\local\{7CEEBCC7-3D96-40D2-B86C-39983BE5BCBB}
2013-01-13 00:31:37 -------- d-----w- c:\users\cesko\appdata\local\{C40D3B18-2DA2-4E47-AA70-E1865A0931BD}
2013-01-12 12:27:48 -------- d-----w- c:\users\cesko\appdata\local\{07F6F75D-FED7-4B66-999B-B6819256E23F}
2013-01-11 23:47:00 -------- d-----w- c:\users\cesko\appdata\local\{216658C9-838A-43E0-B8AB-514FCC5715C7}
2013-01-11 11:46:23 -------- d-----w- c:\users\cesko\appdata\local\{C5EAB6A4-177E-4AF2-9D05-439B8E6A270D}
2013-01-10 22:09:29 -------- d-----w- c:\users\cesko\appdata\local\{E1BBAD65-DE93-4A2D-AF91-FA904DA01121}
2013-01-10 10:09:03 -------- d-----w- c:\users\cesko\appdata\local\{249FDFEE-E9BB-47E6-9F49-99FFB4B347F6}
2013-01-09 15:00:23 2048000 ----a-w- c:\windows\system32\win32k.sys
2013-01-09 14:59:46 204288 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-09 14:59:44 1400832 ----a-w- c:\windows\system32\msxml6.dll
2013-01-09 12:02:27 -------- d-----w- c:\users\cesko\appdata\local\{41271750-433A-48FC-A770-9D6419BD6717}
2013-01-08 23:35:05 -------- d-----w- c:\users\cesko\appdata\local\{3663BE5F-3B36-401E-8520-6148B8CC63D8}
2013-01-08 11:19:36 -------- d-----w- c:\users\cesko\appdata\local\{BEAF92EC-9FD1-46F6-9B3A-24A123B8205F}
2013-01-07 20:29:59 -------- d-----w- c:\users\cesko\appdata\local\{DA44FFDA-317D-49A3-9D5E-78369B0D9C47}
2013-01-07 08:29:33 -------- d-----w- c:\users\cesko\appdata\local\{43ECCD76-DB21-4D58-9433-25A0C6C514B2}
2013-01-06 10:20:02 -------- d-----w- c:\users\cesko\appdata\local\{6833F44B-A385-43B7-BE11-F3094B750FD3}
2013-01-05 11:41:37 -------- d-----w- c:\users\cesko\appdata\local\{6F7F0918-ED7A-450A-B7CE-ADCF4D013FFD}
2013-01-04 23:41:02 -------- d-----w- c:\users\cesko\appdata\local\{D6B0E526-BC2C-4E40-9205-AB5D4499D1DC}
2013-01-04 11:15:54 -------- d-----w- c:\program files\common files\Symantec Shared
2013-01-04 10:18:22 -------- d-----w- c:\users\cesko\appdata\local\{FC804241-6DAA-4E32-9C15-21F695BF14FC}
2013-01-03 13:01:21 -------- d-----w- c:\users\cesko\appdata\local\{85512C0D-9B6D-4082-A69B-5C3138659523}
2013-01-03 01:00:56 -------- d-----w- c:\users\cesko\appdata\local\{5EDE2083-11C6-410C-9895-A6AE712BE394}
2013-01-02 11:19:36 -------- d-----w- c:\users\cesko\appdata\local\{FBC25645-9011-4E46-925C-00F36EAFB10D}
2013-01-01 22:27:05 -------- d-----w- c:\users\cesko\appdata\local\{31F8CC95-4754-4877-8856-AD2370CB52FD}
2013-01-01 10:26:19 -------- d-----w- c:\users\cesko\appdata\local\{0418435B-8595-4137-A109-08329D6ECF72}
2012-12-31 22:12:27 -------- d-----w- c:\users\cesko\appdata\local\{CAC161AE-6D2C-4072-AE4C-FF98C7B53FF7}
2012-12-31 10:11:10 -------- d-----w- c:\users\cesko\appdata\local\{510EC0B1-4F88-472E-AAF6-246084160E00}
2012-12-30 09:46:37 -------- d-----w- c:\users\cesko\appdata\local\{7C502EED-6F6F-4E33-B766-0651B17B179B}
.
==================== Find3M ====================
.
2013-01-14 13:14:53 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-01-14 13:14:52 746984 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-09 21:17:28 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-09 21:17:28 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-26 10:17:00 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-12-26 10:17:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-12-16 13:12:54 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 10:50:29 293376 ----a-w- c:\windows\system32\atmfd.dll
2012-11-20 00:45:34 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-11-14 02:09:22 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-13 01:29:51 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-02 10:18:17 376320 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26:06 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2012-11-01 12:00:19 38400 ----a-w- c:\windows\system32\drivers\rixdptsk.sys
2012-11-01 12:00:18 172032 ----a-w- c:\windows\system32\rixdicon.dll
2012-11-01 11:11:36 48128 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2012-11-01 11:04:02 46592 ----a-w- c:\windows\system32\drivers\risdptsk.sys
2012-11-01 08:04:39 44544 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2012-11-01 08:02:17 80488 ----a-w- c:\windows\system32\RtNicProp32.dll
2012-11-01 08:02:17 363112 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2012-11-01 08:02:17 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2012-11-01 07:57:51 10632 ----a-w- c:\windows\system32\drivers\amdide.sys
2012-11-01 07:55:59 53328 ----a-w- c:\windows\system32\LMouFiltCoInst.dll
2012-11-01 07:55:59 38864 ----a-w- c:\windows\system32\drivers\LHidFilt.Sys
2012-11-01 07:55:59 37328 ----a-w- c:\windows\system32\drivers\LMouFilt.Sys
2012-11-01 07:55:59 1581136 ----a-w- c:\windows\system32\LkmdfCoInst.dll
2012-11-01 07:48:58 516096 ----a-w- c:\windows\system32\sm56co85.txt
2012-11-01 07:48:57 1095936 ----a-w- c:\windows\system32\drivers\smserial.sys
2012-11-01 07:42:44 15248 ----a-w- c:\windows\system32\drivers\pmkbdfltr.sys
2011-12-19 00:38:03 63 ----a-w- c:\program files\dialogysclip.bat
2011-09-16 13:12:04 143240 ----a-w- c:\program files\common files\ApnStub.exe
.
============= FINISH: 23:27:15,71 ===============
Moc tomu tady nerozumím, celkově jako PC. prosím buďte schovívaví.
Něco sem tady vyčetl o tom DDS logu tak to sem dám...
Problém je v tom že PC je enormně pomalé. Pisi nyní z nouzového režimu. Prohnal sem to Nodem, RegCure Pro, Speedupmypc...nejaká svinstva to našla ale stalé stejne pomale, nepoužitelné...
S nejakým zrejme pornem mi syn stahl yontoo a od te doby je asi problem...
PC se načíta asi pet minut a po "vítejte" je černá obrazovka s nápisem "Konfigurování Individualního nastavení uživatele" (což tam drive nebylo) a pod tím C:/Program files/Microsoft/Windows Installer.exe
DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.11.2
Run by cesko at 23:25:16 on 2013-01-28
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.2460 [GMT 1:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Windows\system32\wbem\wmiprvse.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=111304&tt=0313_4&babsrc=HP_ss&mntrId=18f252fd000000000000001d604d90ae
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://http://www.yahoo.com/?ilc=8.yahoo.com
mDefault_Page_URL = hxxp://http://www.yahoo.com/?ilc=8.yahoo.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
uURLSearchHooks: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - <orphaned>
uURLSearchHooks: {687578b9-7132-4a7a-80e4-30ee31099e03} - <orphaned>
uURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - <orphaned>
mURLSearchHooks: {855F3B16-6D32-4fe6-8A56-BBB695989046} - <orphaned>
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: IEExtension.VDownloaderBHO: {7b523e7c-f096-4e36-a0cb-7efeb5c675c1} -
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - LocalServer32 - <no file>
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [Microsoft® Windows® OS Manager] c:\program files\microsoft\Windows Installer.exe
mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe
mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe
mRun: [Microsoft® Windows® Operating System] c:\program files\microsoft\Windows Installer.exe
uExplorerRun: [Microsoft Explorer Policies] c:\program files\microsoft\Windows Installer.exe
mExplorerRun: [Microsoft Explorer Policies] c:\program files\microsoft\Windows Installer.exe
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 10.0.0.138
TCP: Interfaces\{93E4835A-8CC3-420B-91E5-48014E065A30} : DHCPNameServer = 10.0.0.138
TCP: Interfaces\{BAE6D55F-F66B-4F39-A3DD-E2F6609718A1} : DHCPNameServer = 10.0.0.138
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= c:\progra~2\browse~1\23765~1.24\{16cdf~1\browse~1.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
mASetup: {UR218G3C-0SUD-JCT2-1756-57VI7413CH5M} - c:\program files\microsoft\Windows Installer.exe
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-5-3 242240]
R3 pmkbdfltr;PenMount Keyboard Device Filter Driver;c:\windows\system32\drivers\pmkbdfltr.sys [2012-11-1 15248]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2011-11-1 27632]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2012-11-29 38608]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-1-8 161536]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2012-4-6 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2011-9-9 13224]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2008-5-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2008-5-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2008-5-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2008-5-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2008-5-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2008-5-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2008-5-16 115752]
S3 Uniblue.MaxiDiskSvc;Uniblue Maxi Disk Service;c:\program files\uniblue\maxidisk\service.exe [2013-1-28 30032]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2013-01-28 22:15:40 792 ----a-w- c:\users\cesko\appdata\roaming\ceskov3.5.0.0.vbs
2013-01-28 21:37:48 -------- d-----w- c:\program files\common files\ParetoLogic
2013-01-28 21:37:44 -------- d-----w- c:\program files\ParetoLogic
2013-01-28 21:18:21 -------- d-----w- c:\users\cesko\appdata\roaming\ParetoLogic
2013-01-28 21:18:21 -------- d-----w- c:\users\cesko\appdata\roaming\DriverCure
2013-01-28 21:18:10 -------- d-----w- c:\programdata\ParetoLogic
2013-01-28 19:28:19 -------- d-----w- c:\users\cesko\appdata\local\{4722288C-0213-4D33-9063-CFF956DEC3AF}
2013-01-28 19:17:49 -------- d-----w- c:\program files\VS Revo Group
2013-01-28 01:45:43 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2013-01-28 00:46:06 -------- d-----w- c:\users\cesko\appdata\local\{83232A03-1FD4-42FB-9EAB-982BAB386955}
2013-01-27 12:38:39 -------- d-----w- c:\users\cesko\appdata\local\{2AFB720C-D324-466E-B7A1-83BEABAE4EAC}
2013-01-27 00:04:06 -------- d-----w- c:\users\cesko\appdata\local\{20B84885-CAA7-4C65-B13F-C08914827D4B}
2013-01-26 12:03:41 -------- d-----w- c:\users\cesko\appdata\local\{8C5BF28A-81A7-4A6C-8F73-1288C9F541F3}
2013-01-26 00:03:08 -------- d-----w- c:\users\cesko\appdata\local\{3A64584D-FA5F-48A6-8F3F-C4FC980FD5A3}
2013-01-25 12:02:43 -------- d-----w- c:\users\cesko\appdata\local\{3BC836DC-8B9C-45A0-A1C0-58C84D4A8702}
2013-01-24 13:53:31 -------- d-----w- c:\users\cesko\appdata\local\{ECAB57D7-8580-453A-9E41-E37FF5957647}
2013-01-24 13:09:22 -------- d-----r- c:\program files\Skype
2013-01-23 21:28:19 -------- d-----w- c:\users\cesko\appdata\local\{5353894A-B67C-4D52-9B48-3237E468994B}
2013-01-23 09:27:33 -------- d-----w- c:\users\cesko\appdata\local\{79497AE8-2935-495F-B947-A379D36D0FA2}
2013-01-22 11:51:06 -------- d-----w- c:\users\cesko\appdata\local\{337C0669-B2D0-4323-86AB-D16749679018}
2013-01-21 13:08:27 -------- d-----w- c:\users\cesko\appdata\local\{C846D032-C137-4679-A4BD-AAB8DB996390}
2013-01-20 22:36:13 -------- d-----w- c:\users\cesko\appdata\local\{8F12A814-4113-4B2B-ADD9-D16FBB837C14}
2013-01-20 10:35:39 -------- d-----w- c:\users\cesko\appdata\local\{6ED79342-1CBA-4E7C-8071-BD95DA807EBB}
2013-01-19 13:19:22 -------- d-----w- c:\users\cesko\appdata\local\{B7C81F07-DA4A-4F09-A78C-3CD7EF3EDEB7}
2013-01-19 01:18:55 -------- d-----w- c:\users\cesko\appdata\local\{FF386866-AE8E-48A5-AEF7-FF85AEF2A14F}
2013-01-18 10:38:47 -------- d-----w- c:\users\cesko\appdata\local\{DC12CB2C-2301-449F-8894-D5444D0CD76F}
2013-01-17 22:38:23 -------- d-----w- c:\users\cesko\appdata\local\{9A0D6D4D-F5C0-46BA-ABC4-A8BDD36F1757}
2013-01-17 11:02:20 -------- d-----w- c:\program files\Zrychleni Pocitace
2013-01-17 11:00:13 -------- d-----w- c:\program files\pazera-software
2013-01-17 10:37:59 -------- d-----w- c:\users\cesko\appdata\local\{D8E41A60-C75C-496A-8FAE-873024F7986D}
2013-01-16 19:49:50 -------- d-----w- c:\users\cesko\appdata\local\{BA9EE525-8785-47D7-8CA2-3743DC7CBC38}
2013-01-16 07:27:07 -------- d-----w- c:\users\cesko\appdata\local\{9661900F-F769-496E-9DE4-25E92DE4210C}
2013-01-15 20:01:24 -------- d-----w- c:\users\cesko\appdata\roaming\TuneUp Software
2013-01-15 20:01:13 -------- d-----w- c:\programdata\TuneUp Software
2013-01-15 20:01:07 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-01-15 20:01:07 -------- d--h--w- c:\programdata\Common Files
2013-01-15 19:57:32 -------- d-----w- c:\users\cesko\appdata\roaming\Broad Intelligence
2013-01-15 19:57:30 -------- d-----w- c:\users\cesko\appdata\roaming\OpenCandy
2013-01-15 19:57:30 -------- d-----w- c:\program files\MediaCoder
2013-01-15 16:06:20 -------- d-----w- c:\users\cesko\appdata\local\{DB51A627-CED9-4B04-9A11-D364F8E12319}
2013-01-15 01:48:10 -------- d-----w- c:\users\cesko\appdata\local\{B41241F8-A478-4D70-B660-DB0FF6EABAB2}
2013-01-14 19:21:52 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-14 13:47:44 -------- d-----w- c:\users\cesko\appdata\local\{9C89DA1B-3E31-435B-B7AC-EFF2EAF2D3CC}
2013-01-14 01:47:20 -------- d-----w- c:\users\cesko\appdata\local\{BA0F75A1-2F4E-48B3-A03D-1F7EE934BFDB}
2013-01-13 13:46:54 -------- d-----w- c:\users\cesko\appdata\local\{7CEEBCC7-3D96-40D2-B86C-39983BE5BCBB}
2013-01-13 00:31:37 -------- d-----w- c:\users\cesko\appdata\local\{C40D3B18-2DA2-4E47-AA70-E1865A0931BD}
2013-01-12 12:27:48 -------- d-----w- c:\users\cesko\appdata\local\{07F6F75D-FED7-4B66-999B-B6819256E23F}
2013-01-11 23:47:00 -------- d-----w- c:\users\cesko\appdata\local\{216658C9-838A-43E0-B8AB-514FCC5715C7}
2013-01-11 11:46:23 -------- d-----w- c:\users\cesko\appdata\local\{C5EAB6A4-177E-4AF2-9D05-439B8E6A270D}
2013-01-10 22:09:29 -------- d-----w- c:\users\cesko\appdata\local\{E1BBAD65-DE93-4A2D-AF91-FA904DA01121}
2013-01-10 10:09:03 -------- d-----w- c:\users\cesko\appdata\local\{249FDFEE-E9BB-47E6-9F49-99FFB4B347F6}
2013-01-09 15:00:23 2048000 ----a-w- c:\windows\system32\win32k.sys
2013-01-09 14:59:46 204288 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-09 14:59:44 1400832 ----a-w- c:\windows\system32\msxml6.dll
2013-01-09 12:02:27 -------- d-----w- c:\users\cesko\appdata\local\{41271750-433A-48FC-A770-9D6419BD6717}
2013-01-08 23:35:05 -------- d-----w- c:\users\cesko\appdata\local\{3663BE5F-3B36-401E-8520-6148B8CC63D8}
2013-01-08 11:19:36 -------- d-----w- c:\users\cesko\appdata\local\{BEAF92EC-9FD1-46F6-9B3A-24A123B8205F}
2013-01-07 20:29:59 -------- d-----w- c:\users\cesko\appdata\local\{DA44FFDA-317D-49A3-9D5E-78369B0D9C47}
2013-01-07 08:29:33 -------- d-----w- c:\users\cesko\appdata\local\{43ECCD76-DB21-4D58-9433-25A0C6C514B2}
2013-01-06 10:20:02 -------- d-----w- c:\users\cesko\appdata\local\{6833F44B-A385-43B7-BE11-F3094B750FD3}
2013-01-05 11:41:37 -------- d-----w- c:\users\cesko\appdata\local\{6F7F0918-ED7A-450A-B7CE-ADCF4D013FFD}
2013-01-04 23:41:02 -------- d-----w- c:\users\cesko\appdata\local\{D6B0E526-BC2C-4E40-9205-AB5D4499D1DC}
2013-01-04 11:15:54 -------- d-----w- c:\program files\common files\Symantec Shared
2013-01-04 10:18:22 -------- d-----w- c:\users\cesko\appdata\local\{FC804241-6DAA-4E32-9C15-21F695BF14FC}
2013-01-03 13:01:21 -------- d-----w- c:\users\cesko\appdata\local\{85512C0D-9B6D-4082-A69B-5C3138659523}
2013-01-03 01:00:56 -------- d-----w- c:\users\cesko\appdata\local\{5EDE2083-11C6-410C-9895-A6AE712BE394}
2013-01-02 11:19:36 -------- d-----w- c:\users\cesko\appdata\local\{FBC25645-9011-4E46-925C-00F36EAFB10D}
2013-01-01 22:27:05 -------- d-----w- c:\users\cesko\appdata\local\{31F8CC95-4754-4877-8856-AD2370CB52FD}
2013-01-01 10:26:19 -------- d-----w- c:\users\cesko\appdata\local\{0418435B-8595-4137-A109-08329D6ECF72}
2012-12-31 22:12:27 -------- d-----w- c:\users\cesko\appdata\local\{CAC161AE-6D2C-4072-AE4C-FF98C7B53FF7}
2012-12-31 10:11:10 -------- d-----w- c:\users\cesko\appdata\local\{510EC0B1-4F88-472E-AAF6-246084160E00}
2012-12-30 09:46:37 -------- d-----w- c:\users\cesko\appdata\local\{7C502EED-6F6F-4E33-B766-0651B17B179B}
.
==================== Find3M ====================
.
2013-01-14 13:14:53 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-01-14 13:14:52 746984 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-09 21:17:28 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-09 21:17:28 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-26 10:17:00 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-12-26 10:17:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-12-16 13:12:54 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 10:50:29 293376 ----a-w- c:\windows\system32\atmfd.dll
2012-11-20 00:45:34 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-11-14 02:09:22 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-13 01:29:51 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-02 10:18:17 376320 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26:06 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2012-11-01 12:00:19 38400 ----a-w- c:\windows\system32\drivers\rixdptsk.sys
2012-11-01 12:00:18 172032 ----a-w- c:\windows\system32\rixdicon.dll
2012-11-01 11:11:36 48128 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2012-11-01 11:04:02 46592 ----a-w- c:\windows\system32\drivers\risdptsk.sys
2012-11-01 08:04:39 44544 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2012-11-01 08:02:17 80488 ----a-w- c:\windows\system32\RtNicProp32.dll
2012-11-01 08:02:17 363112 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2012-11-01 08:02:17 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2012-11-01 07:57:51 10632 ----a-w- c:\windows\system32\drivers\amdide.sys
2012-11-01 07:55:59 53328 ----a-w- c:\windows\system32\LMouFiltCoInst.dll
2012-11-01 07:55:59 38864 ----a-w- c:\windows\system32\drivers\LHidFilt.Sys
2012-11-01 07:55:59 37328 ----a-w- c:\windows\system32\drivers\LMouFilt.Sys
2012-11-01 07:55:59 1581136 ----a-w- c:\windows\system32\LkmdfCoInst.dll
2012-11-01 07:48:58 516096 ----a-w- c:\windows\system32\sm56co85.txt
2012-11-01 07:48:57 1095936 ----a-w- c:\windows\system32\drivers\smserial.sys
2012-11-01 07:42:44 15248 ----a-w- c:\windows\system32\drivers\pmkbdfltr.sys
2011-12-19 00:38:03 63 ----a-w- c:\program files\dialogysclip.bat
2011-09-16 13:12:04 143240 ----a-w- c:\program files\common files\ApnStub.exe
.
============= FINISH: 23:27:15,71 ===============