Pomalý PC-prosím o kontrolu
Napsal: 25 bře 2013 18:06
Zdravím,
dostal se mi do ruky kámošky pc, můžete prosím někdo kouknout na log. Zdá se mi dost pomalý.
Přikládám log z DDS, protože pomocí RSIT nešel vytvořit. Házelo to nějakou chybu.
Děkuji
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.7601.17514
Run by janička at 17:49:23 on 2013-03-25
Microsoft Windows 7 Starter 6.1.7601.1.1250.420.1029.18.1014.267 [GMT 1:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET Smart Security 4.2 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
.
============== Running Processes ================
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\System32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\System32\AsusService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe
C:\windows\Explorer.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Opera\opera.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\conhost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k SDRSVC
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://asus.msn.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
uWinlogon: Shell = c:\program files\oceanis\systemsetting\WallPaperAgent.exe
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows 7 Starter Helper: {D381FF29-7CFB-4D4E-B92A-C4EDDC696614} - c:\program files\oceanis\systemsetting\StarterHelper.dll
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [HotkeyMon] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotKeyMon.exe
mRun: [HotkeyService] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotkeyService.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ASUSPRP] c:\program files\asus\aprp\APRP.EXE
mRun: [SynAsusAcpi] c:\program files\synaptics\syntp\SynAsusAcpi.exe
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - c:\program files\icq7.2\ICQ.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.11.1
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121} : DHCPNameServer = 192.168.11.1
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121}\371627B6163484345496E6475627E65647F4462343038323031303 : DHCPNameServer = 10.0.0.138
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121}\4514C4B44514C4B4D2731413640334 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121}\653564352343 : DHCPNameServer = 208.91.112.53 208.91.112.52
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121}\E4B2B2B2 : DHCPNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-6-28 11832]
R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2010-4-7 133512]
R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2010-4-7 41312]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2010-6-28 51712]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-4-13 43944]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-2-14 54632]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2012-3-26 18432]
.
=============== Created Last 30 ================
.
2030-01-01 14:37:43 -------- d-sh--w- C:\Boot
2013-03-25 16:49:25 -------- d-----w- c:\users\janiŕka\appdata\local\Microsoft
2013-03-25 16:43:06 -------- d-----w- c:\program files\trend micro
2013-03-25 16:31:15 -------- d-----w- c:\windows\$regcmp$
2013-03-25 16:31:06 -------- d-----w- c:\program files\Registry Clean Expert
2013-03-24 22:07:04 -------- d-----w- c:\windows\system32\SPReview
2013-03-24 21:01:58 1159168 ----a-w- c:\windows\system32\sysmain.dll
2013-03-24 21:00:59 870912 ----a-w- c:\windows\system32\XpsPrint.dll
2013-03-24 20:45:39 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-03-24 16:20:40 -------- d-----w- c:\users\janička\appdata\roaming\SumatraPDF
2013-03-24 16:19:38 -------- d-----w- c:\program files\SumatraPDF
2013-03-24 14:03:24 -------- d-----w- c:\windows\pss
2013-03-14 18:55:24 981504 ----a-w- c:\windows\system32\wininet.dll
2013-03-14 18:55:03 860672 ----a-w- c:\program files\internet explorer\iedvtool.dll
2013-03-14 18:54:59 525312 ----a-w- c:\program files\internet explorer\jsdbgui.dll
2013-03-14 18:54:57 760320 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2013-03-14 18:54:49 163328 ----a-w- c:\program files\internet explorer\ieproxy.dll
2013-03-14 18:54:42 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
==================== Find3M ====================
.
2013-03-24 21:52:17 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-03-24 15:00:37 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-24 15:00:37 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-05 05:00:15 3967848 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-05 05:00:11 3913064 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 04:50:52 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-01-04 03:00:29 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-01-03 05:05:20 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-01-03 05:04:43 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
.
============= FINISH: 17:52:17,71 ===============
dostal se mi do ruky kámošky pc, můžete prosím někdo kouknout na log. Zdá se mi dost pomalý.
Přikládám log z DDS, protože pomocí RSIT nešel vytvořit. Házelo to nějakou chybu.
Děkuji
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.7601.17514
Run by janička at 17:49:23 on 2013-03-25
Microsoft Windows 7 Starter 6.1.7601.1.1250.420.1029.18.1014.267 [GMT 1:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET Smart Security 4.2 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
.
============== Running Processes ================
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\System32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\System32\AsusService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe
C:\windows\Explorer.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Opera\opera.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\conhost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k SDRSVC
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://asus.msn.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
uWinlogon: Shell = c:\program files\oceanis\systemsetting\WallPaperAgent.exe
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows 7 Starter Helper: {D381FF29-7CFB-4D4E-B92A-C4EDDC696614} - c:\program files\oceanis\systemsetting\StarterHelper.dll
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [HotkeyMon] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotKeyMon.exe
mRun: [HotkeyService] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotkeyService.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ASUSPRP] c:\program files\asus\aprp\APRP.EXE
mRun: [SynAsusAcpi] c:\program files\synaptics\syntp\SynAsusAcpi.exe
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - c:\program files\icq7.2\ICQ.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.11.1
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121} : DHCPNameServer = 192.168.11.1
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121}\371627B6163484345496E6475627E65647F4462343038323031303 : DHCPNameServer = 10.0.0.138
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121}\4514C4B44514C4B4D2731413640334 : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121}\653564352343 : DHCPNameServer = 208.91.112.53 208.91.112.52
TCP: Interfaces\{E34CEC1C-222A-4EAF-A95A-27E1AA7D8121}\E4B2B2B2 : DHCPNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-6-28 11832]
R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2010-4-7 133512]
R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2010-4-7 41312]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2010-6-28 51712]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-4-13 43944]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-2-14 54632]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2012-3-26 18432]
.
=============== Created Last 30 ================
.
2030-01-01 14:37:43 -------- d-sh--w- C:\Boot
2013-03-25 16:49:25 -------- d-----w- c:\users\janiŕka\appdata\local\Microsoft
2013-03-25 16:43:06 -------- d-----w- c:\program files\trend micro
2013-03-25 16:31:15 -------- d-----w- c:\windows\$regcmp$
2013-03-25 16:31:06 -------- d-----w- c:\program files\Registry Clean Expert
2013-03-24 22:07:04 -------- d-----w- c:\windows\system32\SPReview
2013-03-24 21:01:58 1159168 ----a-w- c:\windows\system32\sysmain.dll
2013-03-24 21:00:59 870912 ----a-w- c:\windows\system32\XpsPrint.dll
2013-03-24 20:45:39 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-03-24 16:20:40 -------- d-----w- c:\users\janička\appdata\roaming\SumatraPDF
2013-03-24 16:19:38 -------- d-----w- c:\program files\SumatraPDF
2013-03-24 14:03:24 -------- d-----w- c:\windows\pss
2013-03-14 18:55:24 981504 ----a-w- c:\windows\system32\wininet.dll
2013-03-14 18:55:03 860672 ----a-w- c:\program files\internet explorer\iedvtool.dll
2013-03-14 18:54:59 525312 ----a-w- c:\program files\internet explorer\jsdbgui.dll
2013-03-14 18:54:57 760320 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2013-03-14 18:54:49 163328 ----a-w- c:\program files\internet explorer\ieproxy.dll
2013-03-14 18:54:42 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
==================== Find3M ====================
.
2013-03-24 21:52:17 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-03-24 15:00:37 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-24 15:00:37 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-05 05:00:15 3967848 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-05 05:00:11 3913064 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 04:50:52 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-01-04 03:00:29 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-01-03 05:05:20 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-01-03 05:04:43 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
.
============= FINISH: 17:52:17,71 ===============