Stránka 1 z 1

Poprosim vas o preventivnu kontrolu logu

Napsal: 04 črc 2013 10:26
od majjki
Jedna sa o preventivnu kontrolu. :)
Logfile of random's system information tool 1.09 (written by random/random)
Run by rodina at 2013-07-04 11:21:20
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 127 GB (82%) free of 155 GB
Total RAM: 1976 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:21:24, on 4. 7. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16618)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Users\rodina\Downloads\RSIT.exe
C:\Program Files\trend micro\rodina.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

--
End of file - 4183 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\WpsUpdateTask_rodina.job

=========Mozilla firefox=========

ProfilePath - C:\Users\rodina\AppData\Roaming\Mozilla\Firefox\Profiles\vw5hcudy.default

"url_advisor@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
"virtual_keyboard@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
"content_blocker@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
"anti_banner@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
"online_banking@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.224 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-17 537528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2013-06-18 878784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}]
Safe Money Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [2012-08-17 424888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-17 484280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [2013-03-15 356376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2011-02-11 171032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe [2011-02-11 137752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2011-02-11 172568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2013-02-28 18642024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 1791272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-07-02 12:49:30 ----AD---- C:\Windows\system32\oem
2013-07-02 12:49:26 ----D---- C:\OOBE
2013-06-30 19:42:51 ----D---- C:\ProgramData\Kingsoft
2013-06-30 19:42:29 ----D---- C:\Program Files\Kingsoft
2013-06-30 19:39:55 ----D---- C:\Users\rodina\AppData\Roaming\Kingsoft
2013-06-30 19:27:53 ----SHD---- C:\Config.Msi
2013-06-30 19:05:04 ----D---- C:\Users\rodina\AppData\Roaming\SoftGrid Client
2013-06-30 18:57:12 ----D---- C:\Users\rodina\AppData\Roaming\TP
2013-06-30 13:04:42 ----D---- C:\rsit
2013-06-30 13:04:42 ----D---- C:\Program Files\trend micro
2013-06-27 17:44:55 ----A---- C:\Windows\system32\msonpmon.dll
2013-06-27 17:25:04 ----RHD---- C:\MSOCache
2013-06-26 15:53:09 ----D---- C:\Program Files\Mozilla Firefox
2013-06-24 21:21:38 ----D---- C:\Program Files\Microsoft Silverlight
2013-06-24 20:50:57 ----D---- C:\Windows\pss
2013-06-17 11:45:43 ----A---- C:\Windows\DeleteOnReboot.bat
2013-06-17 11:32:51 ----D---- C:\Users\rodina\AppData\Roaming\uTorrent
2013-06-17 10:39:15 ----D---- C:\Windows\ELAMBKUP
2013-06-17 10:39:11 ----D---- C:\ProgramData\Kaspersky Lab
2013-06-17 10:39:11 ----D---- C:\Program Files\Kaspersky Lab
2013-06-17 10:39:03 ----A---- C:\Windows\system32\drivers\klif.sys
2013-06-17 10:39:03 ----A---- C:\Windows\system32\drivers\klflt.sys
2013-06-17 07:56:51 ----D---- C:\Program Files\Defraggler
2013-06-16 21:11:03 ----D---- C:\Users\rodina\AppData\Roaming\vlc
2013-06-16 21:10:47 ----D---- C:\Program Files\VideoLAN
2013-06-16 21:04:01 ----D---- C:\Users\rodina\AppData\Roaming\Ashampoo
2013-06-16 21:03:34 ----D---- C:\ProgramData\ashampoo
2013-06-16 21:03:13 ----D---- C:\Program Files\Ashampoo
2013-06-16 20:59:39 ----D---- C:\Program Files\VS Revo Group
2013-06-16 20:56:29 ----D---- C:\Program Files\7-Zip
2013-06-16 19:37:31 ----D---- C:\Program Files\CCleaner
2013-06-16 19:30:46 ----D---- C:\Users\rodina\AppData\Roaming\Skype
2013-06-16 19:30:39 ----RD---- C:\Program Files\Skype
2013-06-16 19:30:39 ----D---- C:\Program Files\Common Files\Skype
2013-06-16 19:30:32 ----D---- C:\ProgramData\Skype
2013-06-16 19:11:13 ----D---- C:\Program Files\Google
2013-06-16 18:55:15 ----A---- C:\Windows\system32\esent.dll
2013-06-16 18:55:14 ----A---- C:\Windows\system32\fsutil.exe
2013-06-16 18:55:14 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2013-06-16 18:55:14 ----A---- C:\Windows\system32\drivers\storport.sys
2013-06-16 18:55:14 ----A---- C:\Windows\system32\drivers\nvstor.sys
2013-06-16 18:55:14 ----A---- C:\Windows\system32\drivers\nvraid.sys
2013-06-16 18:55:14 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2013-06-16 18:55:14 ----A---- C:\Windows\system32\drivers\amdxata.sys
2013-06-16 18:55:14 ----A---- C:\Windows\system32\drivers\amdsata.sys
2013-06-16 18:55:09 ----A---- C:\Windows\system32\WindowsCodecs.dll
2013-06-16 18:55:09 ----A---- C:\Windows\system32\drivers\usbport.sys
2013-06-16 18:55:09 ----A---- C:\Windows\system32\drivers\usbehci.sys
2013-06-16 18:55:09 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2013-06-16 18:55:09 ----A---- C:\Windows\system32\drivers\bthport.sys
2013-06-16 18:55:08 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2013-06-16 18:55:08 ----A---- C:\Windows\system32\drivers\usbohci.sys
2013-06-16 18:55:08 ----A---- C:\Windows\system32\drivers\usbhub.sys
2013-06-16 18:55:08 ----A---- C:\Windows\system32\drivers\usbd.sys
2013-06-16 18:55:08 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2013-06-16 18:55:07 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-06-16 18:55:07 ----A---- C:\Windows\system32\ntkrnlpa.exe
2013-06-16 18:32:40 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-06-16 18:32:39 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-06-16 18:32:39 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-06-16 18:32:39 ----A---- C:\Windows\system32\drivers\TsUsbGD.sys
2013-06-16 18:32:39 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-06-16 18:32:39 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2013-06-16 18:32:38 ----A---- C:\Windows\system32\wksprtPS.dll
2013-06-16 18:32:38 ----A---- C:\Windows\system32\wksprt.exe
2013-06-16 18:32:38 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-06-16 18:32:38 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-06-16 18:32:38 ----A---- C:\Windows\system32\tsgqec.dll
2013-06-16 18:32:38 ----A---- C:\Windows\system32\rdpudd.dll
2013-06-16 18:32:38 ----A---- C:\Windows\system32\rdpendp_winip.dll
2013-06-16 18:32:38 ----A---- C:\Windows\system32\rdpcorets.dll
2013-06-16 18:32:38 ----A---- C:\Windows\system32\mstsc.exe
2013-06-16 18:32:38 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-06-16 18:32:38 ----A---- C:\Windows\system32\aaclient.dll
2013-06-16 18:32:37 ----A---- C:\Windows\system32\mstscax.dll
2013-06-16 18:32:11 ----D---- C:\Program Files\Synaptics
2013-06-16 18:31:48 ----D---- C:\Program Files\LSI SoftModem
2013-06-16 18:31:33 ----D---- C:\Program Files\Intel
2013-06-16 18:31:32 ----D---- C:\Intel
2013-06-16 18:29:42 ----A---- C:\Windows\system32\schannel.dll
2013-06-16 18:29:42 ----A---- C:\Windows\system32\lsasrv.dll
2013-06-16 18:29:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-06-16 18:29:42 ----A---- C:\Windows\system32\drivers\cng.sys
2013-06-16 18:29:39 ----A---- C:\Windows\system32\qdvd.dll
2013-06-16 18:28:11 ----D---- C:\Users\rodina\AppData\Roaming\Macromedia
2013-06-16 18:27:14 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-06-16 18:27:13 ----D---- C:\Windows\system32\Macromed
2013-06-16 18:24:50 ----D---- C:\Program Files\Microsoft.NET
2013-06-16 18:24:22 ----SHD---- C:\Windows\Installer
2013-06-16 18:22:52 ----D---- C:\Users\rodina\AppData\Roaming\Mozilla
2013-06-16 18:22:43 ----D---- C:\ProgramData\Mozilla
2013-06-16 18:22:42 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-06-16 18:20:34 ----D---- C:\Users\rodina\AppData\Roaming\Adobe
2013-06-16 18:16:59 ----D---- C:\Windows\system32\Wat
2013-06-16 18:15:09 ----A---- C:\Windows\system32\fontsub.dll
2013-06-16 18:15:09 ----A---- C:\Windows\system32\atmlib.dll
2013-06-16 18:15:09 ----A---- C:\Windows\system32\atmfd.dll
2013-06-16 18:03:50 ----N---- C:\Windows\system32\MpSigStub.exe
2013-06-16 17:53:09 ----D---- C:\Windows\Panther
2013-06-16 17:52:57 ----RASH---- C:\BOOTSECT.BAK
2013-06-16 17:52:55 ----SHD---- C:\Boot
2013-06-16 17:45:06 ----A---- C:\Windows\system32\MRT.exe
2013-06-16 17:44:31 ----A---- C:\Windows\system32\Wdfres.dll
2013-06-16 17:44:31 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2013-06-16 17:44:31 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2013-06-16 17:43:34 ----A---- C:\Windows\system32\WUDFx.dll
2013-06-16 17:43:34 ----A---- C:\Windows\system32\WUDFSvc.dll
2013-06-16 17:43:34 ----A---- C:\Windows\system32\WUDFPlatform.dll
2013-06-16 17:43:34 ----A---- C:\Windows\system32\WUDFHost.exe
2013-06-16 17:43:34 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2013-06-16 17:43:34 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2013-06-16 17:43:34 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2013-06-16 17:43:04 ----A---- C:\Windows\system32\wmi.dll
2013-06-16 17:43:04 ----A---- C:\Windows\system32\imagehlp.dll
2013-06-16 17:43:04 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2013-06-16 17:40:11 ----A---- C:\Windows\system32\browserchoice.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\wininet.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\wextract.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\webcheck.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\vbscript.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\urlmon.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\url.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\pngfilt.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\occache.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\msrating.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\msls31.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\mshtmler.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\mshtmled.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\mshtml.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\mshta.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\msfeedssync.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\msfeeds.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\jsproxy.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\jscript9.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\jscript.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\inseng.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\imgutil.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\iexpress.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\ieUnatt.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\ieui.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\iesysprep.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\iesetup.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\iertutil.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\iernonce.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\iepeers.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\ieframe.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\iedkcs32.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\ieapfltr.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\ieapfltr.dat
2013-06-16 17:30:18 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\ie4uinit.exe
2013-06-16 17:30:18 ----A---- C:\Windows\system32\icardie.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\elshyph.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\dxtrans.dll
2013-06-16 17:30:18 ----A---- C:\Windows\system32\dxtmsft.dll
2013-06-16 17:30:17 ----A---- C:\Windows\system32\licmgr10.dll
2013-06-16 17:29:49 ----A---- C:\Windows\system32\taskhost.exe
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-16 17:28:20 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\XpsPrint.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\WMPhoto.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\UIAnimation.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\FntCache.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\dxgi.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\DWrite.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\d3d10warp.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\d3d10level9.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\d3d10core.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\d3d10_1core.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\d3d10_1.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\d3d10.dll
2013-06-16 17:28:20 ----A---- C:\Windows\system32\d2d1.dll
2013-06-16 17:24:33 ----A---- C:\Windows\system32\Wpc.dll
2013-06-16 17:24:33 ----A---- C:\Windows\system32\gameux.dll
2013-06-16 17:24:05 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2013-06-16 17:24:05 ----A---- C:\Windows\system32\dhcpcore6.dll
2013-06-16 17:24:01 ----A---- C:\Windows\system32\cryptsvc.dll
2013-06-16 17:24:01 ----A---- C:\Windows\system32\cryptnet.dll
2013-06-16 17:24:01 ----A---- C:\Windows\system32\crypt32.dll
2013-06-16 17:24:01 ----A---- C:\Windows\system32\certutil.exe
2013-06-16 17:24:01 ----A---- C:\Windows\system32\certenc.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-06-16 17:23:55 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-06-16 17:23:55 ----A---- C:\Windows\system32\KernelBase.dll
2013-06-16 17:23:55 ----A---- C:\Windows\system32\kernel32.dll
2013-06-16 17:23:55 ----A---- C:\Windows\system32\conhost.exe
2013-06-16 17:23:54 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-06-16 17:23:54 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-06-16 17:23:54 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-06-16 17:23:54 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-06-16 17:23:54 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-06-16 17:23:54 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-06-16 17:23:54 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-06-16 17:23:30 ----A---- C:\Windows\system32\nlasvc.dll
2013-06-16 17:23:30 ----A---- C:\Windows\system32\nlaapi.dll
2013-06-16 17:23:30 ----A---- C:\Windows\system32\netevent.dll
2013-06-16 17:23:30 ----A---- C:\Windows\system32\netcorehc.dll
2013-06-16 17:23:30 ----A---- C:\Windows\system32\ncsi.dll
2013-06-16 17:23:30 ----A---- C:\Windows\system32\iphlpsvc.dll
2013-06-16 17:23:30 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-06-16 17:23:07 ----A---- C:\Windows\system32\EncDec.dll
2013-06-16 17:23:05 ----A---- C:\Windows\system32\prevhost.exe
2013-06-16 17:23:05 ----A---- C:\Windows\system32\ntshrui.dll
2013-06-16 17:23:02 ----A---- C:\Windows\system32\OxpsConverter.exe
2013-06-16 17:23:00 ----A---- C:\Windows\system32\cryptdlg.dll
2013-06-16 17:22:53 ----A---- C:\Windows\system32\ntdll.dll
2013-06-16 17:22:52 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-06-16 17:22:50 ----A---- C:\Windows\system32\CPFilters.dll
2013-06-16 17:22:49 ----A---- C:\Windows\system32\sbe.dll
2013-06-16 17:22:46 ----A---- C:\Windows\system32\cdosys.dll
2013-06-16 17:22:44 ----A---- C:\Windows\system32\ncrypt.dll
2013-06-16 17:22:44 ----A---- C:\Windows\system32\d3d11.dll
2013-06-16 17:22:42 ----A---- C:\Windows\system32\tquery.dll
2013-06-16 17:22:42 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2013-06-16 17:22:42 ----A---- C:\Windows\system32\SearchIndexer.exe
2013-06-16 17:22:42 ----A---- C:\Windows\system32\SearchFilterHost.exe
2013-06-16 17:22:42 ----A---- C:\Windows\system32\mssvp.dll
2013-06-16 17:22:42 ----A---- C:\Windows\system32\mssrch.dll
2013-06-16 17:22:42 ----A---- C:\Windows\system32\mssphtb.dll
2013-06-16 17:22:42 ----A---- C:\Windows\system32\mssph.dll
2013-06-16 17:22:42 ----A---- C:\Windows\system32\msscntrs.dll
2013-06-16 17:22:40 ----A---- C:\Windows\system32\smss.exe
2013-06-16 17:22:40 ----A---- C:\Windows\system32\csrsrv.dll
2013-06-16 17:22:33 ----A---- C:\Windows\system32\drivers\bowser.sys
2013-06-16 17:22:32 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-06-16 17:22:31 ----A---- C:\Windows\system32\mfc42u.dll
2013-06-16 17:22:31 ----A---- C:\Windows\system32\mfc42.dll
2013-06-16 17:22:30 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2013-06-16 17:22:30 ----A---- C:\Windows\system32\drivers\ndis.sys
2013-06-16 17:22:30 ----A---- C:\Windows\system32\drivers\afd.sys
2013-06-16 17:22:29 ----A---- C:\Windows\system32\odbcjt32.dll
2013-06-16 17:22:28 ----A---- C:\Windows\system32\spoolsv.exe
2013-06-16 17:22:28 ----A---- C:\Windows\system32\odbctrac.dll
2013-06-16 17:22:28 ----A---- C:\Windows\system32\odbccu32.dll
2013-06-16 17:22:28 ----A---- C:\Windows\system32\odbccr32.dll
2013-06-16 17:22:28 ----A---- C:\Windows\system32\odbccp32.dll
2013-06-16 17:22:27 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-06-16 17:22:27 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2013-06-16 17:22:27 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2013-06-16 17:22:27 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2013-06-16 17:22:26 ----A---- C:\Windows\system32\kerberos.dll
2013-06-16 17:22:24 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-06-16 17:22:24 ----A---- C:\Windows\system32\drivers\netio.sys
2013-06-16 17:22:24 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-06-16 17:22:23 ----A---- C:\Windows\system32\msi.dll
2013-06-16 17:22:23 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-06-16 17:22:23 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-06-16 17:22:22 ----A---- C:\Windows\system32\netapi32.dll
2013-06-16 17:22:22 ----A---- C:\Windows\system32\browser.dll
2013-06-16 17:22:22 ----A---- C:\Windows\system32\browcli.dll
2013-06-16 17:22:21 ----A---- C:\Windows\system32\xmllite.dll
2013-06-16 17:22:21 ----A---- C:\Windows\system32\usp10.dll
2013-06-16 17:22:20 ----A---- C:\Windows\system32\webio.dll
2013-06-16 17:22:20 ----A---- C:\Windows\system32\sspisrv.dll
2013-06-16 17:22:20 ----A---- C:\Windows\system32\sspicli.dll
2013-06-16 17:22:20 ----A---- C:\Windows\system32\secur32.dll
2013-06-16 17:22:20 ----A---- C:\Windows\system32\lsass.exe
2013-06-16 17:22:19 ----A---- C:\Windows\system32\srcore.dll
2013-06-16 17:22:19 ----A---- C:\Windows\system32\dpnet.dll
2013-06-16 17:22:18 ----A---- C:\Windows\system32\drivers\srvnet.sys
2013-06-16 17:22:18 ----A---- C:\Windows\system32\drivers\srv2.sys
2013-06-16 17:22:18 ----A---- C:\Windows\system32\drivers\srv.sys
2013-06-16 17:22:18 ----A---- C:\Windows\system32\dnsrslvr.dll
2013-06-16 17:22:18 ----A---- C:\Windows\system32\dnscacheugc.exe
2013-06-16 17:22:18 ----A---- C:\Windows\system32\dnsapi.dll
2013-06-16 17:22:14 ----A---- C:\Windows\system32\rdrmemptylst.exe
2013-06-16 17:22:14 ----A---- C:\Windows\system32\rdpwsx.dll
2013-06-16 17:22:14 ----A---- C:\Windows\system32\rdpcorekmts.dll
2013-06-16 17:22:14 ----A---- C:\Windows\system32\packager.dll
2013-06-16 17:22:12 ----A---- C:\Windows\system32\synceng.dll
2013-06-16 17:22:12 ----A---- C:\Windows\system32\msxml3r.dll
2013-06-16 17:22:12 ----A---- C:\Windows\system32\msxml3.dll
2013-06-16 17:22:11 ----A---- C:\Windows\system32\drivers\fvevol.sys
2013-06-16 17:22:10 ----A---- C:\Windows\system32\inetcomm.dll
2013-06-16 17:22:10 ----A---- C:\Windows\system32\FXSCOVER.exe
2013-06-16 17:22:09 ----A---- C:\Windows\system32\win32k.sys
2013-06-16 17:22:08 ----A---- C:\Windows\system32\umpnpmgr.dll
2013-06-16 17:22:07 ----A---- C:\Windows\system32\msxml6.dll
2013-06-16 17:22:07 ----A---- C:\Windows\explorer.exe
2013-06-16 17:22:05 ----A---- C:\Windows\system32\msvcrt.dll
2013-06-16 17:22:04 ----A---- C:\Windows\system32\win32spl.dll
2013-06-16 17:22:04 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2013-06-16 17:22:04 ----A---- C:\Windows\system32\drivers\partmgr.sys
2013-06-16 17:22:03 ----A---- C:\Windows\system32\wwansvc.dll
2013-06-16 17:22:03 ----A---- C:\Windows\system32\wwanprotdim.dll
2013-06-16 17:22:01 ----A---- C:\Windows\system32\localspl.dll
2013-06-16 17:22:00 ----A---- C:\Windows\system32\psisdecd.dll
2013-06-16 17:22:00 ----A---- C:\Windows\system32\oleaut32.dll
2013-06-16 17:22:00 ----A---- C:\Windows\system32\oleacc.dll
2013-06-16 17:21:59 ----A---- C:\Windows\system32\wintrust.dll
2013-06-16 17:21:58 ----A---- C:\Windows\system32\poqexec.exe
2013-06-16 17:21:56 ----A---- C:\Windows\system32\quartz.dll
2013-06-16 17:21:56 ----A---- C:\Windows\system32\profsvc.dll
2013-06-16 17:21:45 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2013-06-16 17:13:11 ----A---- C:\Windows\system32\winsrv.dll
2013-06-16 17:13:01 ----A---- C:\Windows\system32\tzres.dll
2013-06-16 17:12:52 ----A---- C:\Windows\system32\shell32.dll
2013-06-16 17:12:51 ----A---- C:\Windows\system32\shdocvw.dll
2013-06-16 17:12:51 ----A---- C:\Windows\system32\consent.exe
2013-06-16 17:12:51 ----A---- C:\Windows\system32\authui.dll
2013-06-16 17:12:51 ----A---- C:\Windows\system32\appinfo.dll
2013-06-16 17:05:58 ----A---- C:\Windows\system32\rdpcore.dll
2013-06-16 17:05:58 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2013-06-16 17:02:05 ----A---- C:\Windows\system32\wups2.dll
2013-06-16 17:02:05 ----A---- C:\Windows\system32\wucltux.dll
2013-06-16 17:02:05 ----A---- C:\Windows\system32\wuauclt.exe
2013-06-16 17:02:04 ----A---- C:\Windows\system32\wuaueng.dll
2013-06-16 17:01:55 ----A---- C:\Windows\system32\wups.dll
2013-06-16 17:01:55 ----A---- C:\Windows\system32\wudriver.dll
2013-06-16 17:01:55 ----A---- C:\Windows\system32\wuapi.dll
2013-06-16 17:01:45 ----A---- C:\Windows\system32\wuwebv.dll
2013-06-16 17:01:45 ----A---- C:\Windows\system32\wuapp.exe
2013-06-16 17:01:32 ----D---- C:\Users\rodina\AppData\Roaming\Identities
2013-06-16 17:01:22 ----SD---- C:\Users\rodina\AppData\Roaming\Microsoft
2013-06-16 17:01:22 ----D---- C:\Users\rodina\AppData\Roaming\Media Center Programs
2013-06-16 17:01:10 ----SHD---- C:\Recovery
2013-06-16 16:57:04 ----D---- C:\Windows\SoftwareDistribution
2013-06-16 16:54:58 ----D---- C:\Windows\Prefetch
2013-06-16 16:54:14 ----ASH---- C:\pagefile.sys
2013-06-16 16:54:06 ----SHD---- C:\System Volume Information
2013-06-16 16:54:06 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 month======

2013-07-04 11:18:27 ----D---- C:\Windows\Temp
2013-07-04 11:01:28 ----D---- C:\Windows\system32\config
2013-07-04 10:53:34 ----D---- C:\Windows\System32
2013-07-04 10:53:34 ----D---- C:\Windows\inf
2013-07-04 10:53:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-07-04 10:47:44 ----D---- C:\Windows
2013-07-03 10:52:22 ----D---- C:\Windows\system32\catroot2
2013-07-02 12:49:30 ----AD---- C:\Windows\system32\oobe
2013-06-30 19:44:26 ----D---- C:\Windows\winsxs
2013-06-30 19:43:59 ----D---- C:\Windows\Tasks
2013-06-30 19:43:59 ----D---- C:\Windows\system32\Tasks
2013-06-30 19:43:58 ----D---- C:\Windows\ShellNew
2013-06-30 19:42:51 ----HD---- C:\ProgramData
2013-06-30 19:42:29 ----RD---- C:\Program Files
2013-06-30 19:28:02 ----SD---- C:\ProgramData\Microsoft
2013-06-30 19:28:02 ----D---- C:\Program Files\Common Files\microsoft shared
2013-06-30 19:28:01 ----D---- C:\Program Files\Common Files
2013-06-30 19:19:40 ----D---- C:\Windows\system32\drivers
2013-06-30 19:13:14 ----RSD---- C:\Windows\assembly
2013-06-30 19:12:32 ----RSD---- C:\Windows\Fonts
2013-06-30 19:10:44 ----D---- C:\Program Files\Common Files\System
2013-06-30 19:10:42 ----A---- C:\Windows\win.ini
2013-06-28 20:17:39 ----D---- C:\Windows\system32\drivers\UMDF
2013-06-27 18:49:11 ----D---- C:\Windows\Microsoft.NET
2013-06-23 21:19:48 ----D---- C:\Windows\system32\wdi
2013-06-22 19:41:56 ----SHD---- C:\$Recycle.Bin
2013-06-22 11:18:21 ----D---- C:\Windows\system32\LogFiles
2013-06-17 11:00:30 ----D---- C:\Windows\Logs
2013-06-17 10:39:51 ----D---- C:\Windows\system32\catroot
2013-06-17 10:39:41 ----D---- C:\Windows\system32\DriverStore
2013-06-17 09:14:30 ----D---- C:\Windows\rescache
2013-06-16 19:38:10 ----D---- C:\Windows\debug
2013-06-16 19:19:22 ----D---- C:\Windows\system32\en-US
2013-06-16 18:48:47 ----D---- C:\Windows\system32\wbem
2013-06-16 18:48:47 ----D---- C:\Windows\system32\sk-SK
2013-06-16 18:48:47 ----D---- C:\Windows\system32\drivers\en-US
2013-06-16 18:48:47 ----D---- C:\Windows\PolicyDefinitions
2013-06-16 18:17:08 ----D---- C:\Windows\ehome
2013-06-16 18:17:08 ----D---- C:\Program Files\Windows Journal
2013-06-16 18:17:07 ----D---- C:\Windows\system32\migration
2013-06-16 18:17:07 ----D---- C:\Windows\AppPatch
2013-06-16 18:16:59 ----D---- C:\Program Files\Internet Explorer
2013-06-16 18:16:56 ----D---- C:\Windows\system32\zh-TW
2013-06-16 18:16:56 ----D---- C:\Windows\system32\zh-HK
2013-06-16 18:16:56 ----D---- C:\Windows\system32\zh-CN
2013-06-16 18:16:56 ----D---- C:\Windows\system32\tr-TR
2013-06-16 18:16:56 ----D---- C:\Windows\system32\sv-SE
2013-06-16 18:16:56 ----D---- C:\Windows\system32\ru-RU
2013-06-16 18:16:56 ----D---- C:\Windows\system32\pt-PT
2013-06-16 18:16:56 ----D---- C:\Windows\system32\pt-BR
2013-06-16 18:16:56 ----D---- C:\Windows\system32\pl-PL
2013-06-16 18:16:56 ----D---- C:\Windows\system32\nl-NL
2013-06-16 18:16:56 ----D---- C:\Windows\system32\nb-NO
2013-06-16 18:16:56 ----D---- C:\Windows\system32\ko-KR
2013-06-16 18:16:56 ----D---- C:\Windows\system32\ja-JP
2013-06-16 18:16:56 ----D---- C:\Windows\system32\it-IT
2013-06-16 18:16:56 ----D---- C:\Windows\system32\hu-HU
2013-06-16 18:16:56 ----D---- C:\Windows\system32\fr-FR
2013-06-16 18:16:56 ----D---- C:\Windows\system32\fi-FI
2013-06-16 18:16:56 ----D---- C:\Windows\system32\es-ES
2013-06-16 18:16:56 ----D---- C:\Windows\system32\el-GR
2013-06-16 18:16:56 ----D---- C:\Windows\system32\de-DE
2013-06-16 18:16:56 ----D---- C:\Windows\system32\da-DK
2013-06-16 18:16:56 ----D---- C:\Windows\system32\cs-CZ
2013-06-16 17:17:36 ----D---- C:\Windows\system32\CodeIntegrity
2013-06-16 17:01:27 ----D---- C:\Windows\system32\restore
2013-06-16 17:01:18 ----RD---- C:\Users
2013-06-16 16:57:33 ----D---- C:\Windows\system32\sysprep

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2012-06-19 136024]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2013-06-18 594528]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2012-08-02 24408]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2013-06-18 44000]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2013-06-18 145040]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2010-01-26 1163328]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2013-03-15 25944]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2013-03-15 25944]
R3 netr28;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28.sys [2012-12-06 2046560]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-04 1303728]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-12-03 26112]
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [2013-03-15 356376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-19 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-16 256904]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-19 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-06-26 117144]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-06-16 1343400]

-----------------EOF-----------------

Re: Poprosim vas o preventivnu kontrolu logu

Napsal: 04 črc 2013 13:30
od Márty84
Zdravim :)

Nic nebezpecneho nevidim. Jen nejake zbytecnosti. Chcete to procistit?

Re: Poprosim vas o preventivnu kontrolu logu

Napsal: 04 črc 2013 20:47
od majjki
Márty84 píše:Zdravim :)

Nic nebezpecneho nevidim. Jen nejake zbytecnosti. Chcete to procistit?
Zdravim.Bol by som rad,keby sme dali zbytočnosti preč.

Re: Poprosim vas o preventivnu kontrolu logu

Napsal: 04 črc 2013 21:01
od Márty84
OK :)


:arrow: Najdete tento soubor C:\Program Files\trend micro\rodina.exe , kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Kliknete na Main menu a na Do a system scan only
U techto radku dejte vlevo zatrzitko

Kód: Vybrat vše

O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
Kliknete na nápis Fix checked a potvrdte



:!: Vypnete antivir, at nebrani programu v praci!
:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe a ulozte nejlepe na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Do leveho okna zkopirujte tento skript (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[RESETHOSTS]
[Purity]

:services
gupdate
AdobeFlashPlayerUpdateSvc
gupdatem

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\WpsUpdateTask_rodina.job

:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery na vas vyskoci, nebo bude zde C:\_OTM\MovedFiles\xxxxxxxx_xxxxxx (misto tech x budou cisla, predstavujici datum a cas spusteni)

Re: Poprosim vas o preventivnu kontrolu logu

Napsal: 04 črc 2013 21:15
od majjki
Položky fixnute,pridavam log OTM
All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: rodina
->Temp folder emptied: 813 bytes
->Temporary Internet Files folder emptied: 128 bytes
->FireFox cache emptied: 20301569 bytes
->Google Chrome cache emptied: 48543412 bytes
->Flash cache emptied: 506 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2432 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33298 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 66.00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: rodina
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
========== SERVICES/DRIVERS ==========
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service AdobeFlashPlayerUpdateSvc stopped successfully!
Service AdobeFlashPlayerUpdateSvc deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
C:\Windows\tasks\Adobe Flash Player Updater.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\tasks\WpsUpdateTask_rodina.job moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype\ deleted successfully.

OTM by OldTimer - Version 3.1.21.0 log created on 07042013_221142

Re: Poprosim vas o preventivnu kontrolu logu

Napsal: 04 črc 2013 21:20
od Márty84
Program udelal co mel. Jinak vypada log OK a pokud neni zadny problem, nestoural bych se v tom :D

Znovu spustte OTM a kliknete na CleanUp! Program po sobe uklidi.

CCleaner a Defraggler vidim v logu, takze predpokladam, ze to obcas i pouzivate. Cili podle mne jsme hotovi, jestli tedy jde vse jak ma :)

Re: Poprosim vas o preventivnu kontrolu logu

Napsal: 04 črc 2013 21:24
od majjki
Všetko ide ako má.Vdaka :) Sem tam to dam prekontrolovať či je všetko OK.Ach ta moja paranoia. :idea:

Re: Poprosim vas o preventivnu kontrolu logu

Napsal: 04 črc 2013 21:29
od Márty84
Nemate zac! To je v poradku, prevence je dulezita. I pro nas to je pak pohodova pracicka. Lepsi nez to nechat zaliskat a ozvat se az uz nejde pc ani spustit :D

Mejte se a treba zase nekdy :bye:

:closed: