problemy s vyrusom
Napsal: 14 bře 2013 11:46
zdravim mam vazny problem v pc (pravdepodobne je to nejaka dost neprijemna haved) a nevim si dat rady ked zapne notebook tak sa nikam nedostanem len precuje a pracuje a pritom nieje nic vobec spustene??? doteraz mi to nikdy nerobilo win je nainstalovany asi 2 mesiace sedmica a aj eset6 mam a stale to robi. mwav scan ani nedorobi stale to pada a vypise modru smrt a nic len opet restartuje a zase dookola nikam sa stym neviem dostat mam disk rozdeleny na 3 particie .. prikladam scan.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Dodik at 2013-03-14 11:38:29
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 90 GB (75%) free of 120 GB
Total RAM: 766 MB (30% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:39:20, on 14. 3. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16470)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Dodik\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Dodik\Downloads\RSIT (1).exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\trend micro\Dodik.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.phpnuke.org/?lang=en&cid=1c7509ed
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Smart Driver Updater] C:\Program Files\Smart Driver Updater\SDULauncher.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Dodik\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Dodik\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NitroPDFReaderDriverCreatorReadSpool3 (NitroReaderDriverReadSpool3) - Nitro PDF Software - C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
--
End of file - 5503 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Dodik\AppData\Roaming\Mozilla\Firefox\Profiles\tak2e94z.default
prefs.js - "browser.startup.homepage" - "http://search.phpnuke.org/?lang=en&cid=1c7509ed"
prefs.js - "keyword.URL" - "http://search.phpnuke.org/?lang=en&cid=1c7509ed&q="
"{34712C68-7391-4c47-94F3-8F88D49AD632}"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nitropdf.com/NitroPDF]
"Description"=NitroPDF Web Browser Plugin
"Path"=C:\Program Files\Nitro\Reader 3\npnitromozilla.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=15.0.5.109]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=15.0.5.109]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader Peppe rFlash Video Shim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.5.109]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.5.109]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpplugin;version=15.0.5.109]
"Description"=RealPlayer Download Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@realnetworks.com/npdlplugin;version=1]
"Description"=RealDownloader Plugin
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Users\Dodik\AppData\Roaming\Mozilla\Firefox\Profiles\tak2e94z.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Dodik\AppData\Roaming\Mozilla\Firefox\Profiles\tak2e94z.default\searchplugins\
phpnuke.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2012-11-29 539888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"TkBellExe"=C:\Program Files\Real\RealPlayer\Update\realsched.exe [2013-02-14 296096]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2012-09-13 1009288]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2012-12-21 5074384]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Smart Driver Updater"=C:\Program Files\Smart Driver Updater\SDULauncher.exe [2012-09-20 338576]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-01-08 18706176]
"cz.seznam.software.autoupdate"=C:\Users\Dodik\AppData\Roaming\Seznam.cz\szninstall.exe [2012-09-13 1009288]
"cz.seznam.software.szndesktop"=C:\Users\Dodik\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-01-22 92152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=153
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=153
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Users\Dodik\6438640620394286720310355\winsvc.exe"="C:\Users\Dodik\6438640620394286720310355\winsvc.exe:*:Enabled:Microsoft Windows Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-03-14 09:48:37 ----D---- C:\9065d04c7f58c9e5ee
2013-03-14 09:46:59 ----A---- C:\Windows\system32\vbscript.dll
2013-03-14 09:46:59 ----A---- C:\Windows\system32\mshtmled.dll
2013-03-14 09:46:58 ----A---- C:\Windows\system32\jsproxy.dll
2013-03-14 09:46:58 ----A---- C:\Windows\system32\ieui.dll
2013-03-14 09:46:57 ----A---- C:\Windows\system32\msfeeds.dll
2013-03-14 09:46:57 ----A---- C:\Windows\system32\ieUnatt.exe
2013-03-14 09:46:56 ----A---- C:\Windows\system32\wininet.dll
2013-03-14 09:46:56 ----A---- C:\Windows\system32\jscript.dll
2013-03-14 09:46:53 ----A---- C:\Windows\system32\jscript9.dll
2013-03-14 09:46:52 ----A---- C:\Windows\system32\url.dll
2013-03-14 09:46:52 ----A---- C:\Windows\system32\iertutil.dll
2013-03-14 09:46:51 ----A---- C:\Windows\system32\urlmon.dll
2013-03-14 09:46:49 ----A---- C:\Windows\system32\mshtml.dll
2013-03-14 09:46:46 ----A---- C:\Windows\system32\ieframe.dll
2013-03-13 21:31:20 ----A---- C:\Windows\system32\drivers\trufos.sys
2013-03-13 21:31:13 ----A---- C:\Windows\system32\msvcr80.dll
2013-03-13 21:31:12 ----A---- C:\Windows\system32\msvcp80.dll
2013-03-13 21:31:10 ----A---- C:\Windows\system32\msvcp90.dll
2013-03-13 21:31:09 ----A---- C:\Windows\system32\msvcr90.dll
2013-03-13 21:31:08 ----A---- C:\Windows\system32\eEmpty.exe
2013-03-13 21:31:01 ----D---- C:\Program Files\Common Files\MicroWorld
2013-03-13 21:30:51 ----D---- C:\ProgramData\MicroWorld
2013-03-13 14:19:15 ----D---- C:\Windows\Minidump
2013-02-27 13:49:09 ----A---- C:\Windows\system32\UIAnimation.dll
2013-02-27 13:49:03 ----A---- C:\Windows\system32\WMPhoto.dll
2013-02-27 13:49:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-27 13:49:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-27 13:49:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-27 13:48:59 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\dxgi.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\d3d10warp.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\d3d10level9.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\d3d10core.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\XpsPrint.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\FntCache.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\DWrite.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\d3d11.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\d3d10_1core.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\d3d10_1.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\d3d10.dll
2013-02-27 13:48:55 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2013-02-27 13:48:55 ----A---- C:\Windows\system32\WindowsCodecs.dll
2013-02-27 13:48:55 ----A---- C:\Windows\system32\d2d1.dll
2013-02-20 19:51:38 ----D---- C:\Users\Dodik\AppData\Roaming\ESET
2013-02-20 19:43:08 ----D---- C:\ProgramData\ESET
2013-02-20 19:21:31 ----D---- C:\Program Files\CCleaner
2013-02-17 21:21:30 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2013-02-17 21:21:30 ----A---- C:\Windows\system32\drivers\ndis.sys
2013-02-17 21:20:40 ----A---- C:\Windows\system32\OxpsConverter.exe
2013-02-17 21:20:35 ----A---- C:\Windows\system32\nlasvc.dll
2013-02-17 21:20:35 ----A---- C:\Windows\system32\netcorehc.dll
2013-02-17 21:20:35 ----A---- C:\Windows\system32\ncsi.dll
2013-02-17 21:20:35 ----A---- C:\Windows\system32\iphlpsvc.dll
2013-02-17 21:20:34 ----A---- C:\Windows\system32\nlaapi.dll
2013-02-17 21:20:34 ----A---- C:\Windows\system32\netevent.dll
2013-02-17 21:20:34 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-02-17 21:19:51 ----A---- C:\Windows\system32\taskhost.exe
2013-02-17 21:19:49 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2013-02-17 21:19:49 ----A---- C:\Windows\system32\dhcpcore6.dll
2013-02-16 15:36:19 ----D---- C:\Windows\system32\SPReview
2013-02-16 15:17:56 ----A---- C:\Windows\system32\MRT.exe
2013-02-16 15:16:44 ----D---- C:\Windows\system32\EventProviders
======List of files/folders modified in the last 1 month======
2013-03-14 11:39:09 ----D---- C:\Program Files\trend micro
2013-03-14 11:39:07 ----D---- C:\Windows\Temp
2013-03-14 11:38:54 ----D---- C:\Windows\system32\Tasks
2013-03-14 11:33:49 ----D---- C:\Users\Dodik\AppData\Roaming\Seznam.cz
2013-03-14 11:29:00 ----D---- C:\Users\Dodik\AppData\Roaming\Skype
2013-03-14 11:27:31 ----D---- C:\Windows
2013-03-14 11:10:36 ----D---- C:\Windows\system32\drivers
2013-03-14 09:56:54 ----D---- C:\Windows\winsxs
2013-03-14 09:56:41 ----D---- C:\Windows\system32\config
2013-03-14 09:56:08 ----D---- C:\Windows\system32\migration
2013-03-14 09:56:08 ----D---- C:\Windows\System32
2013-03-14 09:56:07 ----D---- C:\Program Files\Internet Explorer
2013-03-14 09:48:51 ----D---- C:\Windows\debug
2013-03-14 09:47:54 ----D---- C:\Windows\system32\catroot
2013-03-14 09:47:51 ----D---- C:\Windows\system32\catroot2
2013-03-14 09:46:27 ----D---- C:\Windows\AppPatch
2013-03-14 09:45:49 ----SHD---- C:\System Volume Information
2013-03-14 09:39:35 ----D---- C:\Windows\Prefetch
2013-03-13 22:25:16 ----A---- C:\Windows\win.ini
2013-03-13 21:37:27 ----D---- C:\Users\Dodik\AppData\Roaming\vlc
2013-03-13 21:36:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-03-13 21:36:10 ----D---- C:\Windows\inf
2013-03-13 21:31:01 ----D---- C:\Program Files\Common Files
2013-03-13 21:30:51 ----HD---- C:\ProgramData
2013-03-13 20:29:14 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-03-13 12:19:18 ----D---- C:\Program Files\Mozilla Firefox
2013-03-06 00:03:26 ----D---- C:\Users\Dodik\AppData\Roaming\codeblocks
2013-02-27 16:54:44 ----D---- C:\Windows\system32\zh-TW
2013-02-27 16:54:44 ----D---- C:\Windows\system32\zh-HK
2013-02-27 16:54:44 ----D---- C:\Windows\system32\tr-TR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\sv-SE
2013-02-27 16:54:44 ----D---- C:\Windows\system32\pt-PT
2013-02-27 16:54:44 ----D---- C:\Windows\system32\pt-BR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\pl-PL
2013-02-27 16:54:44 ----D---- C:\Windows\system32\nl-NL
2013-02-27 16:54:44 ----D---- C:\Windows\system32\ko-KR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\it-IT
2013-02-27 16:54:44 ----D---- C:\Windows\system32\hu-HU
2013-02-27 16:54:44 ----D---- C:\Windows\system32\fr-FR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\fi-FI
2013-02-27 16:54:44 ----D---- C:\Windows\system32\es-ES
2013-02-27 16:54:44 ----D---- C:\Windows\system32\el-GR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\de-DE
2013-02-27 16:54:44 ----D---- C:\Windows\system32\cs-CZ
2013-02-27 16:54:43 ----D---- C:\Windows\system32\zh-CN
2013-02-27 16:54:43 ----D---- C:\Windows\system32\ru-RU
2013-02-27 16:54:43 ----D---- C:\Windows\system32\nb-NO
2013-02-27 16:54:43 ----D---- C:\Windows\system32\ja-JP
2013-02-27 16:54:43 ----D---- C:\Windows\system32\en-US
2013-02-27 16:54:43 ----D---- C:\Windows\system32\da-DK
2013-02-22 09:29:19 ----SHD---- C:\Windows\Installer
2013-02-21 21:21:21 ----D---- C:\Windows\Panther
2013-02-21 21:20:57 ----D---- C:\Windows\Logs
2013-02-21 20:26:04 ----D---- C:\Windows\Registration
2013-02-20 20:07:46 ----D---- C:\Windows\system32\drivers\UMDF
2013-02-20 19:47:49 ----D---- C:\Windows\system32\DriverStore
2013-02-20 19:43:08 ----D---- C:\Program Files\ESET
2013-02-20 19:21:31 ----D---- C:\Program Files
2013-02-18 19:13:02 ----D---- C:\Windows\Microsoft.NET
2013-02-18 19:12:17 ----RSD---- C:\Windows\assembly
2013-02-18 13:21:23 ----D---- C:\Windows\PolicyDefinitions
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Sidebar
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Portable Devices
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Photo Viewer
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Media Player
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Mail
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Journal
2013-02-16 20:21:23 ----D---- C:\Program Files\DVD Maker
2013-02-16 20:21:22 ----D---- C:\Windows\servicing
2013-02-16 20:21:22 ----D---- C:\Program Files\Windows Defender
2013-02-16 20:21:22 ----D---- C:\Program Files\Common Files\System
2013-02-16 20:21:21 ----D---- C:\Windows\ehome
2013-02-16 20:21:16 ----D---- C:\Windows\system32\sysprep
2013-02-16 20:21:16 ----D---- C:\Windows\system32\sppui
2013-02-16 20:21:16 ----D---- C:\Windows\system32\Setup
2013-02-16 20:21:16 ----D---- C:\Windows\system32\oobe
2013-02-16 20:21:16 ----D---- C:\Windows\system32\manifeststore
2013-02-16 20:21:16 ----D---- C:\Windows\system32\en
2013-02-16 20:21:16 ----D---- C:\Windows\system32\AdvancedInstallers
2013-02-16 20:21:12 ----D---- C:\Windows\system32\drivers\en-US
2013-02-16 20:21:11 ----D---- C:\Windows\system32\wbem
2013-02-16 20:21:10 ----D---- C:\Windows\system32\migwiz
2013-02-16 20:21:10 ----D---- C:\Windows\system32\Dism
2013-02-16 20:20:52 ----RSD---- C:\Windows\Fonts
2013-02-16 20:20:42 ----D---- C:\Windows\system32\Boot
2013-02-16 15:47:05 ----A---- C:\Windows\system32\msclmd.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2013-01-10 47568]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-01-10 171680]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-01-10 122240]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2013-01-10 46056]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2013-01-10 150080]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-12-01 4179968]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\Windows\system32\DRIVERS\ss_bus.sys [2009-09-21 98560]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\Windows\system32\DRIVERS\ss_mdfl.sys [2009-09-21 14848]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\Windows\system32\DRIVERS\ss_mdm.sys [2009-09-21 123776]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 trufos;trufos; C:\Windows\system32\drivers\trufos.sys [2013-03-13 343456]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-12-01 720896]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2012-12-21 1333424]
R2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [2012-10-30 196624]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-29 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-13 253656]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-29 116648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-02-07 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-29 1343400]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Dodik at 2013-03-14 11:38:29
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 90 GB (75%) free of 120 GB
Total RAM: 766 MB (30% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:39:20, on 14. 3. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16470)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Dodik\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Dodik\Downloads\RSIT (1).exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\trend micro\Dodik.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.phpnuke.org/?lang=en&cid=1c7509ed
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Smart Driver Updater] C:\Program Files\Smart Driver Updater\SDULauncher.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Dodik\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Dodik\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NitroPDFReaderDriverCreatorReadSpool3 (NitroReaderDriverReadSpool3) - Nitro PDF Software - C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
--
End of file - 5503 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Dodik\AppData\Roaming\Mozilla\Firefox\Profiles\tak2e94z.default
prefs.js - "browser.startup.homepage" - "http://search.phpnuke.org/?lang=en&cid=1c7509ed"
prefs.js - "keyword.URL" - "http://search.phpnuke.org/?lang=en&cid=1c7509ed&q="
"{34712C68-7391-4c47-94F3-8F88D49AD632}"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nitropdf.com/NitroPDF]
"Description"=NitroPDF Web Browser Plugin
"Path"=C:\Program Files\Nitro\Reader 3\npnitromozilla.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=15.0.5.109]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=15.0.5.109]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader Peppe rFlash Video Shim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.5.109]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.5.109]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpplugin;version=15.0.5.109]
"Description"=RealPlayer Download Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@realnetworks.com/npdlplugin;version=1]
"Description"=RealDownloader Plugin
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Users\Dodik\AppData\Roaming\Mozilla\Firefox\Profiles\tak2e94z.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Dodik\AppData\Roaming\Mozilla\Firefox\Profiles\tak2e94z.default\searchplugins\
phpnuke.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2012-11-29 539888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"TkBellExe"=C:\Program Files\Real\RealPlayer\Update\realsched.exe [2013-02-14 296096]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2012-09-13 1009288]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2012-12-21 5074384]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Smart Driver Updater"=C:\Program Files\Smart Driver Updater\SDULauncher.exe [2012-09-20 338576]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-01-08 18706176]
"cz.seznam.software.autoupdate"=C:\Users\Dodik\AppData\Roaming\Seznam.cz\szninstall.exe [2012-09-13 1009288]
"cz.seznam.software.szndesktop"=C:\Users\Dodik\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-01-22 92152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=153
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=153
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Users\Dodik\6438640620394286720310355\winsvc.exe"="C:\Users\Dodik\6438640620394286720310355\winsvc.exe:*:Enabled:Microsoft Windows Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-03-14 09:48:37 ----D---- C:\9065d04c7f58c9e5ee
2013-03-14 09:46:59 ----A---- C:\Windows\system32\vbscript.dll
2013-03-14 09:46:59 ----A---- C:\Windows\system32\mshtmled.dll
2013-03-14 09:46:58 ----A---- C:\Windows\system32\jsproxy.dll
2013-03-14 09:46:58 ----A---- C:\Windows\system32\ieui.dll
2013-03-14 09:46:57 ----A---- C:\Windows\system32\msfeeds.dll
2013-03-14 09:46:57 ----A---- C:\Windows\system32\ieUnatt.exe
2013-03-14 09:46:56 ----A---- C:\Windows\system32\wininet.dll
2013-03-14 09:46:56 ----A---- C:\Windows\system32\jscript.dll
2013-03-14 09:46:53 ----A---- C:\Windows\system32\jscript9.dll
2013-03-14 09:46:52 ----A---- C:\Windows\system32\url.dll
2013-03-14 09:46:52 ----A---- C:\Windows\system32\iertutil.dll
2013-03-14 09:46:51 ----A---- C:\Windows\system32\urlmon.dll
2013-03-14 09:46:49 ----A---- C:\Windows\system32\mshtml.dll
2013-03-14 09:46:46 ----A---- C:\Windows\system32\ieframe.dll
2013-03-13 21:31:20 ----A---- C:\Windows\system32\drivers\trufos.sys
2013-03-13 21:31:13 ----A---- C:\Windows\system32\msvcr80.dll
2013-03-13 21:31:12 ----A---- C:\Windows\system32\msvcp80.dll
2013-03-13 21:31:10 ----A---- C:\Windows\system32\msvcp90.dll
2013-03-13 21:31:09 ----A---- C:\Windows\system32\msvcr90.dll
2013-03-13 21:31:08 ----A---- C:\Windows\system32\eEmpty.exe
2013-03-13 21:31:01 ----D---- C:\Program Files\Common Files\MicroWorld
2013-03-13 21:30:51 ----D---- C:\ProgramData\MicroWorld
2013-03-13 14:19:15 ----D---- C:\Windows\Minidump
2013-02-27 13:49:09 ----A---- C:\Windows\system32\UIAnimation.dll
2013-02-27 13:49:03 ----A---- C:\Windows\system32\WMPhoto.dll
2013-02-27 13:49:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-27 13:49:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-27 13:49:01 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-27 13:48:59 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-27 13:48:58 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\dxgi.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\d3d10warp.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\d3d10level9.dll
2013-02-27 13:48:58 ----A---- C:\Windows\system32\d3d10core.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\XpsPrint.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\FntCache.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\DWrite.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\d3d11.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\d3d10_1core.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\d3d10_1.dll
2013-02-27 13:48:57 ----A---- C:\Windows\system32\d3d10.dll
2013-02-27 13:48:55 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2013-02-27 13:48:55 ----A---- C:\Windows\system32\WindowsCodecs.dll
2013-02-27 13:48:55 ----A---- C:\Windows\system32\d2d1.dll
2013-02-20 19:51:38 ----D---- C:\Users\Dodik\AppData\Roaming\ESET
2013-02-20 19:43:08 ----D---- C:\ProgramData\ESET
2013-02-20 19:21:31 ----D---- C:\Program Files\CCleaner
2013-02-17 21:21:30 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2013-02-17 21:21:30 ----A---- C:\Windows\system32\drivers\ndis.sys
2013-02-17 21:20:40 ----A---- C:\Windows\system32\OxpsConverter.exe
2013-02-17 21:20:35 ----A---- C:\Windows\system32\nlasvc.dll
2013-02-17 21:20:35 ----A---- C:\Windows\system32\netcorehc.dll
2013-02-17 21:20:35 ----A---- C:\Windows\system32\ncsi.dll
2013-02-17 21:20:35 ----A---- C:\Windows\system32\iphlpsvc.dll
2013-02-17 21:20:34 ----A---- C:\Windows\system32\nlaapi.dll
2013-02-17 21:20:34 ----A---- C:\Windows\system32\netevent.dll
2013-02-17 21:20:34 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-02-17 21:19:51 ----A---- C:\Windows\system32\taskhost.exe
2013-02-17 21:19:49 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2013-02-17 21:19:49 ----A---- C:\Windows\system32\dhcpcore6.dll
2013-02-16 15:36:19 ----D---- C:\Windows\system32\SPReview
2013-02-16 15:17:56 ----A---- C:\Windows\system32\MRT.exe
2013-02-16 15:16:44 ----D---- C:\Windows\system32\EventProviders
======List of files/folders modified in the last 1 month======
2013-03-14 11:39:09 ----D---- C:\Program Files\trend micro
2013-03-14 11:39:07 ----D---- C:\Windows\Temp
2013-03-14 11:38:54 ----D---- C:\Windows\system32\Tasks
2013-03-14 11:33:49 ----D---- C:\Users\Dodik\AppData\Roaming\Seznam.cz
2013-03-14 11:29:00 ----D---- C:\Users\Dodik\AppData\Roaming\Skype
2013-03-14 11:27:31 ----D---- C:\Windows
2013-03-14 11:10:36 ----D---- C:\Windows\system32\drivers
2013-03-14 09:56:54 ----D---- C:\Windows\winsxs
2013-03-14 09:56:41 ----D---- C:\Windows\system32\config
2013-03-14 09:56:08 ----D---- C:\Windows\system32\migration
2013-03-14 09:56:08 ----D---- C:\Windows\System32
2013-03-14 09:56:07 ----D---- C:\Program Files\Internet Explorer
2013-03-14 09:48:51 ----D---- C:\Windows\debug
2013-03-14 09:47:54 ----D---- C:\Windows\system32\catroot
2013-03-14 09:47:51 ----D---- C:\Windows\system32\catroot2
2013-03-14 09:46:27 ----D---- C:\Windows\AppPatch
2013-03-14 09:45:49 ----SHD---- C:\System Volume Information
2013-03-14 09:39:35 ----D---- C:\Windows\Prefetch
2013-03-13 22:25:16 ----A---- C:\Windows\win.ini
2013-03-13 21:37:27 ----D---- C:\Users\Dodik\AppData\Roaming\vlc
2013-03-13 21:36:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-03-13 21:36:10 ----D---- C:\Windows\inf
2013-03-13 21:31:01 ----D---- C:\Program Files\Common Files
2013-03-13 21:30:51 ----HD---- C:\ProgramData
2013-03-13 20:29:14 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-03-13 12:19:18 ----D---- C:\Program Files\Mozilla Firefox
2013-03-06 00:03:26 ----D---- C:\Users\Dodik\AppData\Roaming\codeblocks
2013-02-27 16:54:44 ----D---- C:\Windows\system32\zh-TW
2013-02-27 16:54:44 ----D---- C:\Windows\system32\zh-HK
2013-02-27 16:54:44 ----D---- C:\Windows\system32\tr-TR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\sv-SE
2013-02-27 16:54:44 ----D---- C:\Windows\system32\pt-PT
2013-02-27 16:54:44 ----D---- C:\Windows\system32\pt-BR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\pl-PL
2013-02-27 16:54:44 ----D---- C:\Windows\system32\nl-NL
2013-02-27 16:54:44 ----D---- C:\Windows\system32\ko-KR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\it-IT
2013-02-27 16:54:44 ----D---- C:\Windows\system32\hu-HU
2013-02-27 16:54:44 ----D---- C:\Windows\system32\fr-FR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\fi-FI
2013-02-27 16:54:44 ----D---- C:\Windows\system32\es-ES
2013-02-27 16:54:44 ----D---- C:\Windows\system32\el-GR
2013-02-27 16:54:44 ----D---- C:\Windows\system32\de-DE
2013-02-27 16:54:44 ----D---- C:\Windows\system32\cs-CZ
2013-02-27 16:54:43 ----D---- C:\Windows\system32\zh-CN
2013-02-27 16:54:43 ----D---- C:\Windows\system32\ru-RU
2013-02-27 16:54:43 ----D---- C:\Windows\system32\nb-NO
2013-02-27 16:54:43 ----D---- C:\Windows\system32\ja-JP
2013-02-27 16:54:43 ----D---- C:\Windows\system32\en-US
2013-02-27 16:54:43 ----D---- C:\Windows\system32\da-DK
2013-02-22 09:29:19 ----SHD---- C:\Windows\Installer
2013-02-21 21:21:21 ----D---- C:\Windows\Panther
2013-02-21 21:20:57 ----D---- C:\Windows\Logs
2013-02-21 20:26:04 ----D---- C:\Windows\Registration
2013-02-20 20:07:46 ----D---- C:\Windows\system32\drivers\UMDF
2013-02-20 19:47:49 ----D---- C:\Windows\system32\DriverStore
2013-02-20 19:43:08 ----D---- C:\Program Files\ESET
2013-02-20 19:21:31 ----D---- C:\Program Files
2013-02-18 19:13:02 ----D---- C:\Windows\Microsoft.NET
2013-02-18 19:12:17 ----RSD---- C:\Windows\assembly
2013-02-18 13:21:23 ----D---- C:\Windows\PolicyDefinitions
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Sidebar
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Portable Devices
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Photo Viewer
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Media Player
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Mail
2013-02-16 20:21:23 ----D---- C:\Program Files\Windows Journal
2013-02-16 20:21:23 ----D---- C:\Program Files\DVD Maker
2013-02-16 20:21:22 ----D---- C:\Windows\servicing
2013-02-16 20:21:22 ----D---- C:\Program Files\Windows Defender
2013-02-16 20:21:22 ----D---- C:\Program Files\Common Files\System
2013-02-16 20:21:21 ----D---- C:\Windows\ehome
2013-02-16 20:21:16 ----D---- C:\Windows\system32\sysprep
2013-02-16 20:21:16 ----D---- C:\Windows\system32\sppui
2013-02-16 20:21:16 ----D---- C:\Windows\system32\Setup
2013-02-16 20:21:16 ----D---- C:\Windows\system32\oobe
2013-02-16 20:21:16 ----D---- C:\Windows\system32\manifeststore
2013-02-16 20:21:16 ----D---- C:\Windows\system32\en
2013-02-16 20:21:16 ----D---- C:\Windows\system32\AdvancedInstallers
2013-02-16 20:21:12 ----D---- C:\Windows\system32\drivers\en-US
2013-02-16 20:21:11 ----D---- C:\Windows\system32\wbem
2013-02-16 20:21:10 ----D---- C:\Windows\system32\migwiz
2013-02-16 20:21:10 ----D---- C:\Windows\system32\Dism
2013-02-16 20:20:52 ----RSD---- C:\Windows\Fonts
2013-02-16 20:20:42 ----D---- C:\Windows\system32\Boot
2013-02-16 15:47:05 ----A---- C:\Windows\system32\msclmd.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2013-01-10 47568]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-01-10 171680]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-01-10 122240]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2013-01-10 46056]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2013-01-10 150080]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-12-01 4179968]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\Windows\system32\DRIVERS\ss_bus.sys [2009-09-21 98560]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\Windows\system32\DRIVERS\ss_mdfl.sys [2009-09-21 14848]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\Windows\system32\DRIVERS\ss_mdm.sys [2009-09-21 123776]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 trufos;trufos; C:\Windows\system32\drivers\trufos.sys [2013-03-13 343456]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-12-01 720896]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2012-12-21 1333424]
R2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [2012-10-30 196624]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-29 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-13 253656]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-29 116648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-02-07 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-29 1343400]
-----------------EOF-----------------