Stránka 1 z 2

Zamrzne počítač

Napsal: 10 črc 2013 07:49
od ras099
Logfile of random's system information tool 1.09 (written by random/random)
Run by Martin at 2013-07-10 08:46:04
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 33 GB (70%) free of 46 GB
Total RAM: 3519 MB (84% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:46:10, on 10.7.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PDF Architect\HelperService.exe
C:\Program Files\PDF Architect\ConversionService.exe
C:\Program Files\Skype\Updater\Updater.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE
C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
E:\Programy\Antiviry\RSIT.exe
C:\Program Files\trend micro\Martin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE
O4 - Global Startup: REALTEK 11n USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7765927656
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PDF Architect Helper Service - pdfforge GmbH - C:\Program Files\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GmbH - C:\Program Files\PDF Architect\ConversionService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 5375 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\avast! Emergency Update.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\2ryyvvu5.default-1368371723227

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"FFPDFArchitectConverter@pdfarchitect.com"=C:\Program Files\PDF Architect\FFPDFArchitectExt


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.224 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.21.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Program Files\Mozilla Firefox\searchplugins\
yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711}]
PDF Architect Helper - C:\Program Files\PDF Architect\PDFIEHelper.dll [2013-04-08 92208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-05-12 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-05-12 171424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2013-03-22 15517984]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2013-03-23 1982312]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-11-10 15473664]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09 4858968]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Zoner Photo Studio Autoupdate"=C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [2013-02-18 774168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection]
C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe [2011-10-21 198032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [2013-02-18 774168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=2
"AdobeFlashPlayerUpdateSvc"=3

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
REALTEK 11n USB Wireless LAN Utility.lnk - C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe"="C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan"
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Java\jre7\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre7\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe"="C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe:*:Enabled:Visual Basic Command Line Compiler"
"C:\Program Files\REALTEK\USB Wireless LAN Utility\RtWLan.exe"="C:\Program Files\REALTEK\USB Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan"
"C:\Program Files\REALTEK\USB Wireless LAN Utility\RTLDHCP.exe"="C:\Program Files\REALTEK\USB Wireless LAN Utility\RTLDHCP.exe:*:Enabled:RTLDHCP"
"C:\Program Files\QIP 2012\qip.exe"="C:\Program Files\QIP 2012\qip.exe:*:Enabled:QIP 2012"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.voxacm160"=vct3216.acm
"msacm.scg726"=scg726.acm
"msacm.alf2cd"=alf2cd.acm
"msacm.ac3acm"=AC3ACM.acm
"vidc.dvsd"=mcdvd_32.dll
"vidc.xvid"=xvidvfw.dll
"vidc.DIVX"=DivX.dll
"vidc.mpg4"=mpg4c32.dll
"vidc.mp42"=mpg4c32.dll
"vidc.mp43"=mpg4c32.dll

======List of files/folders created in the last 1 month======

2013-07-10 08:46:04 ----D---- C:\rsit
2013-07-04 10:18:33 ----D---- C:\Documents and Settings\Martin\Data aplikací\BSplayer
2013-07-04 00:12:24 ----D---- C:\Program Files\Mozilla Firefox
2013-07-04 00:09:03 ----D---- C:\Program Files\CDex_170b2
2013-07-02 10:54:20 ----A---- C:\TDSSKiller.2.8.18.0_02.07.2013_10.54.20_log.txt
2013-07-02 10:47:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\GFI Software
2013-07-02 10:39:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection
2013-07-02 10:39:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2013-07-02 10:39:43 ----D---- C:\Program Files\Ad-Aware Antivirus
2013-07-02 10:38:35 ----D---- C:\Documents and Settings\Martin\Data aplikací\Ad-Aware Antivirus
2013-06-30 23:09:36 ----A---- C:\WINDOWS\system32\nvUnsupRes.dat
2013-06-27 11:17:29 ----R---- C:\WINDOWS\system32\drivers\rtwlanu.sys
2013-06-27 11:17:29 ----D---- C:\WINDOWS\OPTIONS
2013-06-27 00:09:31 ----D---- C:\Program Files\Mozilla Thunderbird
2013-06-23 23:25:24 ----D---- C:\Program Files\Ashampoo
2013-06-20 21:41:46 ----D---- C:\Program Files\Microsoft Bootvis
2013-06-18 00:25:40 ----A---- C:\AdwCleaner[S2].txt
2013-06-16 23:37:13 ----A---- C:\AdwCleaner[R2].txt

======List of files/folders modified in the last 1 month======

2013-07-10 08:46:06 ----D---- C:\Program Files\trend micro
2013-07-10 08:45:40 ----D---- C:\WINDOWS\system32\CatRoot2
2013-07-10 08:45:39 ----D---- C:\WINDOWS\system32\Lang
2013-07-10 08:45:39 ----D---- C:\WINDOWS
2013-07-10 08:45:39 ----A---- C:\WINDOWS\RTacDbg.txt
2013-07-10 08:44:32 ----D---- C:\WINDOWS\Temp
2013-07-10 00:24:55 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-07-09 11:00:54 ----D---- C:\Temp
2013-07-09 10:57:18 ----A---- C:\WINDOWS\win.ini
2013-07-09 10:57:18 ----A---- C:\WINDOWS\system.ini
2013-07-05 00:11:20 ----D---- C:\Documents and Settings\Martin\Data aplikací\vlc
2013-07-04 23:21:42 ----D---- C:\WINDOWS\Prefetch
2013-07-04 12:33:16 ----D---- C:\Documents and Settings\Martin\Data aplikací\Canon
2013-07-04 09:06:54 ----RD---- C:\Program Files
2013-07-04 09:06:54 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-07-02 10:54:21 ----D---- C:\WINDOWS\system32\drivers
2013-07-02 10:53:22 ----D---- C:\WINDOWS\system32
2013-07-02 10:47:59 ----SHD---- C:\WINDOWS\Installer
2013-07-02 10:45:35 ----SD---- C:\WINDOWS\Tasks
2013-07-01 11:27:02 ----D---- C:\Documents and Settings\Martin\Data aplikací\dvdcss
2013-06-30 19:39:41 ----D---- C:\Documents and Settings\Martin\Data aplikací\Mp3tag
2013-06-30 14:00:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Freemake
2013-06-30 11:36:02 ----D---- C:\Documents and Settings\Martin\Data aplikací\Audacity
2013-06-28 23:10:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-06-27 12:04:00 ----D---- C:\Documents and Settings\Martin\Data aplikací\Winamp
2013-06-27 11:23:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\DriverGenius
2013-06-27 11:21:06 ----HD---- C:\WINDOWS\inf
2013-06-27 11:17:45 ----D---- C:\WINDOWS\system32\CatRoot
2013-06-27 11:17:02 ----D---- C:\WINDOWS\system32\RtlGina
2013-06-27 11:17:01 ----D---- C:\Program Files\REALTEK
2013-06-27 11:16:58 ----HD---- C:\Program Files\InstallShield Installation Information
2013-06-23 23:25:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ashampoo
2013-06-23 15:38:05 ----D---- C:\Documents and Settings\Martin\Data aplikací\Skype
2013-06-20 23:57:21 ----SH---- C:\boot.ini
2013-06-20 21:41:46 ----SD---- C:\Documents and Settings\Martin\Data aplikací\Microsoft
2013-06-19 16:17:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2013-06-19 16:17:41 ----RD---- C:\Program Files\Skype
2013-06-17 17:21:13 ----D---- C:\WINDOWS\assembly
2013-06-17 17:20:34 ----D---- C:\WINDOWS\Microsoft.NET
2013-06-16 13:57:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-06-16 13:56:55 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2013-06-16 13:56:54 ----D---- C:\WINDOWS\pchealth
2013-06-16 13:56:54 ----D---- C:\Program Files\Microsoft.NET
2013-06-16 13:56:54 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-06-16 13:55:50 ----RSD---- C:\WINDOWS\Fonts
2013-06-16 13:54:45 ----D---- C:\Program Files\Common Files
2013-06-16 13:50:17 ----D---- C:\Program Files\Common Files\System
2013-06-12 16:25:26 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2013-05-09 49376]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2013-06-27 175176]
R0 nvgts;nvgts; C:\WINDOWS\system32\DRIVERS\nvgts.sys [2010-04-09 168040]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 AswRdr;aswRdr; C:\WINDOWS\system32\drivers\AswRdr.sys [2013-05-09 49760]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2013-06-27 770344]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2013-06-27 369584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2013-05-09 56080]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2013-05-05 21361]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2013-05-09 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-11-10 4064256]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-03-23 12653120]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2010-03-04 13824]
R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\WINDOWS\system32\DRIVERS\rtwlanu.sys [2011-05-09 904680]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S1 SBRE;SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NPF;WinPcap Packet Driver (NPF); C:\WINDOWS\system32\drivers\NPF.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2010-03-04 70912]
S3 RtlWlanu;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter; C:\WINDOWS\system32\DRIVERS\rtwlanu.sys [2011-05-09 904680]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-05-09 46808]
R2 FreemakeVideoCapture;FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [2013-04-01 9216]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-05-12 181664]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2013-03-22 156448]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-23 1259296]
R2 PDF Architect Helper Service;PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [2013-04-08 1320496]
R2 PDF Architect Service;PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [2013-04-08 799280]
R2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-06-03 162408]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-07-04 117144]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12 256904]

-----------------EOF-----------------

Re: Zamrzne počítač

Napsal: 10 črc 2013 10:17
od Márty84
Zdravim :)

:???: Proc jste nedokoncil minulou prohlidku?

:???: Co jste provadel s TDSSKillerem?

:arrow: Odinstalujte Ad-Aware

:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Zamrzne počítač

Napsal: 10 črc 2013 11:18
od ras099
Ale já jsem minule všechno dokončil.

Re: Zamrzne počítač

Napsal: 10 črc 2013 11:27
od Márty84
ras099 píše:Ale já jsem minule všechno dokončil.
Fakt? Mi to nepripada jako dokoncene, kdyz posledni veta radce je zakoncena otaznikem :?: http://forum.viry.cz/viewtopic.php?f=30 ... 3#p1230658

Re: Zamrzne počítač

Napsal: 10 črc 2013 11:32
od ras099
Stav pc byl ok. Ale od té doby uběhlo už skoro měsíc.

Re: Zamrzne počítač

Napsal: 10 črc 2013 19:35
od Márty84
No to jste mel napsat jemu, ne ted mi :arcisit:

A co s tim zbytkem, co jsem psal v prvnim prispevku? Dockam se logu? Nebo uz je to zase OK?

Re: Zamrzne počítač

Napsal: 10 črc 2013 22:46
od ras099
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
http://www.malwarebytes.org

Verze: v2013.07.10.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Martin :: MARTINRASZKA-PC [administrátor]

Ochrana: Povolena

10.7.2013 22:59:22
MBAM-log-2013-07-10 (23-45-23).txt

Typ: Kompletní kontrola (C:\|D:\|E:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 321832
Uplynulý čas: 35 minut, 11 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 1
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 2
C:\WINDOWS\AutoKMS\AutoKMS.exe (Trojan.AutoKMS) -> Nebyla provedena žádná instrukce.
C:\WINDOWS\inf\MSASGui.exe (PUP.BitCoinMiner) -> Nebyla provedena žádná instrukce.

(konec)

Re: Zamrzne počítač

Napsal: 11 črc 2013 02:18
od Márty84
:arrow: Nalezy nechte odstranit, pak MBAM odinstalujte.

:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe , ulozte na plochu a spustte.
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Zamrzne počítač

Napsal: 11 črc 2013 11:13
od ras099
OTL logfile created on: 11.7.2013 11:29:16 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Martin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,44 Gb Total Physical Memory | 2,63 Gb Available Physical Memory | 76,51% Memory free
5,28 Gb Paging File | 4,59 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 45,30 Gb Total Space | 31,31 Gb Free Space | 69,12% Space Free | Partition Type: NTFS
Drive D: | 13,30 Gb Total Space | 7,01 Gb Free Space | 52,73% Space Free | Partition Type: NTFS
Drive E: | 174,29 Gb Total Space | 11,20 Gb Free Space | 6,43% Space Free | Partition Type: NTFS

Computer Name: MARTINRASZKA-PC | User Name: Martin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013.07.11 11:28:11 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Martin\Plocha\OTL.exe
PRC - [2013.07.04 00:12:36 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013.05.12 03:48:14 | 000,181,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013.04.08 18:44:12 | 001,320,496 | ---- | M] (pdfforge GmbH) -- C:\Program Files\PDF Architect\HelperService.exe
PRC - [2013.04.08 18:43:36 | 000,799,280 | ---- | M] (pdfforge GmbH) -- C:\Program Files\PDF Architect\ConversionService.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013.04.01 13:07:24 | 000,009,216 | ---- | M] (Ellora Assets Corp.) -- C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
PRC - [2013.03.23 01:22:24 | 001,259,296 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013.02.18 12:50:18 | 000,774,168 | ---- | M] (ZONER software) -- C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
PRC - [2011.04.11 10:41:00 | 001,044,480 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2013.07.10 21:23:35 | 002,090,496 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\13071002\algo.dll
MOD - [2013.07.04 00:12:35 | 003,285,912 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2013.06.12 16:25:26 | 016,033,160 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll
MOD - [2013.03.23 01:22:26 | 001,564,008 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nview\nView.dll
MOD - [2013.03.23 01:22:22 | 000,357,224 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nview\nvShell.dll
MOD - [2009.12.09 21:20:06 | 000,126,976 | ---- | M] () -- C:\Program Files\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll
MOD - [2007.07.12 11:11:54 | 001,163,264 | ---- | M] () -- C:\Program Files\REALTEK\11n USB Wireless LAN Utility\acAuth.dll


========== Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013.07.04 00:12:35 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.06.12 16:25:27 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.06.03 16:21:54 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.05.12 03:48:14 | 000,181,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013.04.08 18:44:12 | 001,320,496 | ---- | M] (pdfforge GmbH) [Auto | Running] -- C:\Program Files\PDF Architect\HelperService.exe -- (PDF Architect Helper Service)
SRV - [2013.04.08 18:43:36 | 000,799,280 | ---- | M] (pdfforge GmbH) [Auto | Running] -- C:\Program Files\PDF Architect\ConversionService.exe -- (PDF Architect Service)
SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013.04.01 13:07:24 | 000,009,216 | ---- | M] (Ellora Assets Corp.) [Auto | Running] -- C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe -- (FreemakeVideoCapture)
SRV - [2013.03.23 01:22:24 | 001,259,296 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\SBREdrv.sys -- (SBRE)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\NPF.sys -- (NPF)
DRV - [2013.06.27 23:03:59 | 000,770,344 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013.06.27 23:03:59 | 000,369,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013.06.27 23:03:59 | 000,175,176 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013.05.09 10:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013.05.09 10:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013.05.09 10:59:09 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013.05.09 10:59:09 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2013.05.09 10:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.05.09 17:54:02 | 000,904,680 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rtwlanu.sys -- (RtlWlanu)
DRV - [2011.05.09 17:54:02 | 000,904,680 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtwlanu.sys -- (RTL8192cu)
DRV - [2010.04.09 02:30:10 | 000,168,040 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts)
DRV - [2010.03.04 18:02:10 | 000,013,824 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2010.03.04 18:02:08 | 000,070,912 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006.07.24 16:05:00 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2006.07.01 22:42:58 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.11.10 16:44:12 | 004,064,256 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService)
DRV - [2005.08.30 17:59:00 | 000,094,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2005.08.30 17:58:56 | 000,008,304 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2005.08.30 17:57:18 | 000,058,320 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus)
DRV - [2005.01.07 17:07:16 | 000,145,920 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-507921405-117609710-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
IE - HKU\S-1-5-21-507921405-117609710-839522115-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-507921405-117609710-839522115-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-507921405-117609710-839522115-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-507921405-117609710-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-507921405-117609710-839522115-1005\..\SearchScopes,DefaultScope =

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: translator%40zoli.bod:2.1.0.3
FF - prefs.js..extensions.enabledAddons: %7BBD4B37E6-7AE7-48d7-A2D7-6FF5775924AB%7D:1.5.1.18
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.05.18 18:36:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\FFPDFArchitectConverter@pdfarchitect.com: C:\Program Files\PDF Architect\FFPDFArchitectExt [2013.06.07 01:57:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.07.04 00:12:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.06.27 00:09:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2013.05.05 16:51:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Martin\Data aplikací\Mozilla\Extensions
[2013.06.30 23:03:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\2ryyvvu5.default-1368371723227\extensions
[2013.05.14 23:21:11 | 000,060,290 | ---- | M] () (No name found) -- C:\Documents and Settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\2ryyvvu5.default-1368371723227\extensions\translator@zoli.bod.xpi
[2013.05.14 23:24:18 | 000,252,158 | ---- | M] () (No name found) -- C:\Documents and Settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\2ryyvvu5.default-1368371723227\extensions\{BD4B37E6-7AE7-48d7-A2D7-6FF5775924AB}.xpi
[2013.06.30 23:03:14 | 000,870,680 | ---- | M] () (No name found) -- C:\Documents and Settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\2ryyvvu5.default-1368371723227\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.07.04 00:12:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013.07.04 00:12:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MARTIN\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\2RYYVVU5.DEFAULT-1368371723227\EXTENSIONS\{BD4B37E6-7AE7-48D7-A2D7-6FF5775924AB}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MARTIN\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\2RYYVVU5.DEFAULT-1368371723227\EXTENSIONS\TRANSLATOR@ZOLI.BOD.XPI

O1 HOSTS File: ([2013.05.14 00:10:15 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKU\S-1-5-21-507921405-117609710-839522115-1004..\Run: [Zoner Photo Studio Autoupdate] C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe (ZONER software)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\REALTEK 11n USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.)
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-507921405-117609710-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-507921405-117609710-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 7764883328 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 7765927656 (MUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{368261C2-6B0A-4726-AF44-A232E2A97158}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Martin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Martin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{390c09c0-b6f1-11e2-b9a1-00e04c0a2fc9}\Shell\AutoRun\command - "" = G:\installer.exe
O33 - MountPoints2\{390c09c0-b6f1-11e2-b9a1-00e04c0a2fc9}\Shell\verb\command - "" = G:\installer.exe
O33 - MountPoints2\{8b30b58a-bb18-11e2-b9c6-00e04c0a2fc9}\Shell\AutoRun\command - "" = G:\installer.exe
O33 - MountPoints2\{8b30b58a-bb18-11e2-b9c6-00e04c0a2fc9}\Shell\verb\command - "" = G:\installer.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2013.07.11 11:28:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Martin\Plocha\OTL.exe
[2013.07.10 12:23:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Data aplikací\Malwarebytes
[2013.07.10 12:22:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2013.07.10 12:22:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2013.07.10 12:22:32 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013.07.10 12:22:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.07.10 08:46:04 | 000,000,000 | ---D | C] -- C:\rsit
[2013.07.04 10:22:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Nabídka Start\Programy\BS.Player
[2013.07.04 10:18:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Data aplikací\BSplayer
[2013.07.04 00:12:24 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.07.04 00:09:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Dokumenty\My Music
[2013.07.04 00:09:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Nabídka Start\Programy\CDex
[2013.07.04 00:09:03 | 000,000,000 | ---D | C] -- C:\Program Files\CDex_170b2
[2013.07.02 10:47:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\GFI Software
[2013.07.02 10:40:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Data aplikací\Ad-Aware Antivirus
[2013.07.02 10:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
[2013.07.02 10:39:43 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Aware Antivirus
[2013.07.02 10:39:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Local Settings\Data aplikací\Downloaded Installations
[2013.07.02 10:38:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Data aplikací\Ad-Aware Antivirus
[2013.06.27 11:17:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\REALTEK 11n USB Wireless LAN Utility
[2013.06.27 11:17:29 | 000,904,680 | R--- | C] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\drivers\rtwlanu.sys
[2013.06.27 11:17:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\OPTIONS
[2013.06.27 00:39:29 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Martin\Recent
[2013.06.27 00:09:31 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2013.06.23 23:25:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Ashampoo
[2013.06.23 23:25:24 | 000,000,000 | ---D | C] -- C:\Program Files\Ashampoo
[2013.06.20 21:41:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Bootvis
[2013.06.20 21:41:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Nabídka Start\Programy\Microsoft Bootvis
[2013.06.20 15:58:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Local Settings\Data aplikací\Temp
[2013.06.20 15:58:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martin\Local Settings\Data aplikací\Facebook

========== Files - Modified Within 30 Days ==========

[2013.07.11 11:35:31 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.07.11 11:28:11 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Martin\Plocha\OTL.exe
[2013.07.11 11:26:13 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.07.11 11:25:51 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2013.07.11 11:25:02 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.07.11 11:24:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.07.10 12:22:36 | 000,000,790 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
[2013.07.08 22:28:25 | 000,013,676 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.07.04 10:22:24 | 000,000,781 | ---- | M] () -- C:\Documents and Settings\Martin\Plocha\BS.Player FREE.lnk
[2013.07.04 10:07:54 | 000,018,432 | ---- | M] () -- C:\Documents and Settings\Martin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.07.04 00:09:04 | 000,000,678 | ---- | M] () -- C:\Documents and Settings\Martin\Plocha\CDex.lnk
[2013.07.02 10:45:36 | 000,000,946 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2013.06.30 23:11:02 | 001,072,544 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2013.06.30 23:11:02 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2013.06.30 23:10:04 | 001,072,544 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2013.06.30 23:09:36 | 000,000,075 | ---- | M] () -- C:\WINDOWS\System32\nvUnsupRes.dat
[2013.06.30 23:06:08 | 000,001,674 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Mozilla Thunderbird.lnk
[2013.06.30 23:02:16 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Mozilla Firefox.lnk
[2013.06.30 22:41:38 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013.06.30 13:59:56 | 000,000,991 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Freemake Video Downloader.lnk
[2013.06.29 21:17:07 | 000,234,972 | ---- | M] () -- C:\WINDOWS\img-0299.jpg
[2013.06.29 21:13:16 | 000,000,110 | -H-- | M] () -- C:\WINDOWS\img-0299.jpg.uid-zps
[2013.06.28 23:10:26 | 000,405,148 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013.06.28 23:10:26 | 000,403,732 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2013.06.28 23:10:26 | 000,063,314 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2013.06.28 23:10:26 | 000,054,492 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013.06.27 23:03:59 | 000,770,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.06.27 23:03:59 | 000,369,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.06.27 23:03:59 | 000,175,176 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.06.27 23:03:59 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.06.27 23:03:59 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.06.27 23:03:59 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.06.27 11:17:37 | 000,001,814 | ---- | M] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\REALTEK 11n USB Wireless LAN Utility.lnk
[2013.06.23 14:26:42 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\LauncherAccess.dt
[2013.06.18 01:05:20 | 000,293,272 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.06.17 16:45:06 | 000,000,565 | ---- | M] () -- C:\Documents and Settings\Martin\Plocha\vydaje.lnk
[2013.06.17 16:45:06 | 000,000,557 | ---- | M] () -- C:\Documents and Settings\Martin\Plocha\mzda.lnk
[2013.06.12 16:25:26 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013.06.12 16:25:26 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

========== Files Created - No Company Name ==========

[2013.07.11 11:35:31 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.07.10 12:22:36 | 000,000,790 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
[2013.07.04 10:22:24 | 000,000,781 | ---- | C] () -- C:\Documents and Settings\Martin\Plocha\BS.Player FREE.lnk
[2013.07.04 00:09:04 | 000,000,678 | ---- | C] () -- C:\Documents and Settings\Martin\Plocha\CDex.lnk
[2013.07.02 10:45:35 | 000,000,946 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2013.06.30 23:09:36 | 000,000,075 | ---- | C] () -- C:\WINDOWS\System32\nvUnsupRes.dat
[2013.06.29 21:16:11 | 000,234,972 | ---- | C] () -- C:\WINDOWS\img-0299.jpg
[2013.06.29 21:16:11 | 000,000,110 | -H-- | C] () -- C:\WINDOWS\img-0299.jpg.uid-zps
[2013.06.27 23:03:59 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.06.27 11:17:37 | 000,001,814 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\REALTEK 11n USB Wireless LAN Utility.lnk
[2013.06.26 23:16:12 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.06.26 23:16:12 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.06.17 16:45:06 | 000,000,565 | ---- | C] () -- C:\Documents and Settings\Martin\Plocha\vydaje.lnk
[2013.06.17 16:45:06 | 000,000,557 | ---- | C] () -- C:\Documents and Settings\Martin\Plocha\mzda.lnk
[2013.05.17 23:33:18 | 001,653,706 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-18-0.dat
[2013.05.17 16:04:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Martin\Data aplikací\AVSMediaPlayer.m3u
[2013.05.17 15:58:43 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2013.05.17 15:58:43 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2013.05.12 14:17:30 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013.05.11 00:58:14 | 002,022,954 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-507921405-117609710-839522115-1004-0.dat
[2013.05.11 00:58:14 | 000,329,514 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
[2013.05.08 23:22:22 | 000,018,432 | ---- | C] () -- C:\Documents and Settings\Martin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.05.07 02:05:46 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\LauncherAccess.dt
[2013.05.07 02:04:38 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2013.05.05 17:51:21 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2013.05.05 17:50:21 | 000,293,272 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.05.05 17:19:56 | 000,175,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.05.05 17:19:56 | 000,049,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2013.05.05 16:38:39 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2013.05.05 16:38:39 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2013.05.05 16:31:35 | 000,010,084 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2013.05.05 16:28:58 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2013.05.05 16:28:58 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2013.05.05 16:28:58 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2013.05.05 16:28:42 | 002,817,904 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2013.05.05 16:06:34 | 000,451,072 | ---- | C] () -- C:\WINDOWS\System32\ISSRemoveSP.exe
[2013.05.05 16:01:55 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013.05.05 15:57:56 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 08:51:56 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2008.04.14 08:51:42 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 08:52:06 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013.06.23 23:25:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ashampoo
[2013.05.05 17:19:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2013.06.27 11:23:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DriverGenius
[2013.06.30 14:00:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Freemake
[2013.07.02 10:47:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\GFI Software
[2013.05.05 17:39:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Zoner
[2013.05.10 14:52:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\Search Settings
[2013.05.10 23:55:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\Thunderbird
[2013.07.02 10:40:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Ad-Aware Antivirus
[2013.07.02 10:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Ad-Aware Antivirus
[2013.05.05 17:31:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Ashampoo
[2013.06.30 11:36:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Audacity
[2013.07.04 10:22:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\BSplayer
[2013.05.17 16:07:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\BSplayer Pro
[2013.07.11 00:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Canon
[2013.05.11 00:48:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\FreemakeVideoDownloader
[2013.06.10 11:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\ID3 renamer
[2013.06.30 19:39:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Mp3tag
[2013.05.07 01:13:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\OpenOffice.org
[2013.06.07 01:57:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\PDF Architect
[2013.06.09 12:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\QIP
[2013.05.11 10:50:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Samsung
[2013.05.07 00:40:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Thunderbird
[2013.05.12 03:49:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\VitySoft
[2013.05.11 00:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\YTD

========== Purity Check ==========



========== Custom Scans ==========

< >
[2013.05.05 15:58:26 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2013.05.05 16:03:04 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2013.05.05 17:19:55 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
[2013.05.12 17:09:56 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2013.07.02 10:45:35 | 000,000,946 | ---- | C] () -- C:\WINDOWS\Tasks\Ad-Aware Antivirus Scheduled Scan.job

< >

< MD5 for: AGP440.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2006.03.02 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

< MD5 for: CDROM.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2006.03.02 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2006.03.02 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2006.03.02 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006.03.02 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: HAL.DLL >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.14 00:01:30 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2006.03.02 14:00:00 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: CHANGER.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys

< MD5 for: ISAPNP.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2006.03.02 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2006.03.02 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2006.03.02 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

< MD5 for: NETLOGON.DLL >
[2006.03.02 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: NVGTS.SYS >
[2010.04.09 02:30:10 | 000,168,040 | -H-- | M] (NVIDIA Corporation) MD5=52DCE3B30C9D61C8E20FE3C6DA4BDFB7 -- C:\NVIDIA\nForceWinXPInt\15.57\IDE\WinXP\sata_ide\nvgts.sys
[2010.04.09 02:30:10 | 000,168,040 | ---- | M] (NVIDIA Corporation) MD5=52DCE3B30C9D61C8E20FE3C6DA4BDFB7 -- C:\WINDOWS\system32\drivers\nvgts.sys
[2010.04.09 02:30:28 | 000,168,040 | -H-- | M] (NVIDIA Corporation) MD5=87096913DFB9129144E1038AADFF17EE -- C:\NVIDIA\nForceWinXPInt\15.57\IDE\WinXP\sataraid\nvgts.sys

< MD5 for: NVRD32.SYS >
[2010.04.09 02:30:28 | 000,139,368 | -H-- | M] (NVIDIA Corporation) MD5=587E8634A13B682FA39E0DA48CA88ED5 -- C:\NVIDIA\nForceWinXPInt\15.57\IDE\WinXP\sataraid\nvrd32.sys

< MD5 for: SCECLI.DLL >
[2006.03.02 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2006.03.02 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SVCHOST.EXE >
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\system32\drivers\tcpip.sys
[2006.03.02 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2006.03.02 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2006.03.02 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2006.03.02 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

< >

< %systemroot%*.* /U /s >

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2013.07.02 10:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Ad-Aware Antivirus
[2013.05.06 23:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Adobe
[2013.05.05 17:31:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Ashampoo
[2013.06.30 11:36:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Audacity
[2013.07.11 11:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\BSplayer
[2013.05.17 16:07:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\BSplayer Pro
[2013.07.11 00:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Canon
[2013.07.01 11:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\dvdcss
[2013.05.11 00:48:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\FreemakeVideoDownloader
[2013.06.10 11:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\ID3 renamer
[2013.05.05 16:03:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Identities
[2013.05.05 16:25:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\InstallShield
[2013.05.05 17:16:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Macromedia
[2013.07.10 12:23:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Malwarebytes
[2013.06.20 21:41:46 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Martin\Data aplikací\Microsoft
[2013.05.05 16:51:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Mozilla
[2013.06.30 19:39:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Mp3tag
[2013.05.07 01:13:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\OpenOffice.org
[2013.06.07 01:57:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\PDF Architect
[2013.06.09 12:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\QIP
[2013.05.11 10:50:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Samsung
[2013.06.23 15:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Skype
[2013.05.12 03:47:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Sun
[2013.05.07 00:40:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Thunderbird
[2013.05.12 03:49:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\VitySoft
[2013.07.11 11:38:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\vlc
[2013.06.27 12:04:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Winamp
[2013.05.11 00:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\YTD

< %APPDATA%\*.exe /s >
[2013.06.20 21:41:46 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Martin\Data aplikací\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_18be6784.exe
[2013.06.20 21:41:46 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Martin\Data aplikací\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_294823.exe
[2013.06.20 21:41:46 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Martin\Data aplikací\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_2cd672ae.exe
[2013.06.20 21:41:46 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Martin\Data aplikací\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_4ae13d6c.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2013.05.05 17:48:36 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2013.05.05 17:48:36 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2013.05.05 17:48:35 | 000,487,424 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2013.07.08 22:28:25 | 000,013,676 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"Zoner Photo Studio Autoupdate" = C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE -- [2013.02.18 12:50:18 | 000,774,168 | ---- | M] (ZONER software)

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.07.11 11:35:31 | 000,000,512 | ---- | M] () MD5=E14FE54B553E6BAEA87388B4553A8C3F -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2013.05.12 03:49:44 | 000,005,369 | ---- | M] () -- \Documents and Settings\Martin\Data aplikací\VitySoft\FRD\plugins\crackle.frp

< *keygen* /s >

< *AntiWPA* /s >

< *loader* /s >
[2013.02.20 16:28:38 | 000,072,638 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.gif
[2013.02.20 16:28:38 | 000,003,032 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.png
[2013.02.20 16:28:38 | 000,009,772 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\retina\loader@2x.png
[2013.06.30 13:59:56 | 000,001,003 | ---- | M] () -- \Documents and Settings\All Users\Nabídka Start\Programy\Freemake\Freemake Video Downloader.lnk
[2013.06.30 13:59:56 | 000,000,991 | ---- | M] () -- \Documents and Settings\All Users\Plocha\Freemake Video Downloader.lnk
[2013.07.05 00:04:21 | 000,000,145 | ---- | M] () -- \Documents and Settings\Martin\Dokumenty\Freemake\FreemakeVideoDownloader\Persistent\DownloaderPersistentList.xml
[2013.05.17 20:45:28 | 001,272,128 | ---- | M] () -- \Documents and Settings\Martin\Dokumenty\Stažené soubory\FreemakeVideoDownloaderSetup.exe
[2013.06.30 13:58:49 | 014,224,000 | ---- | M] () -- \Documents and Settings\Martin\Local Settings\Temp\FreemakeVideoDownloader_3.5.2.4.exe
[137 \Documents and Settings\Martin\Local Settings\Temp\*.tmp files -> \Documents and Settings\Martin\Local Settings\Temp\*.tmp -> ]
[2013.06.30 13:59:56 | 000,001,050 | ---- | M] () -- \Documents and Settings\Martin\Nabídka Start\Programy\Freemake\Uninstall\Uninstall Freemake Video Downloader.lnk
[2013.06.28 04:39:10 | 002,089,536 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader.exe
[2013.02.05 03:05:50 | 000,007,379 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\downloader.js
[2012.09.13 09:17:00 | 000,000,402 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\downloader.xul
[2013.02.11 05:56:44 | 000,015,511 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMCommon\FreemakeCommon\Profiles\FmDownloaderProfiles.xml
[2012.09.13 10:52:54 | 000,064,651 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMCommon\FreemakeCommon\Resources\VideoDownloader.png
[2012.09.13 10:52:54 | 000,064,719 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMCommon\FreemakeCommon\Resources\VideoDownloaderOn.png
[2013.06.28 04:34:42 | 000,020,992 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.Detector.dll
[2013.06.28 04:28:22 | 000,008,192 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.GlobalSettings.dll
[2013.06.28 04:34:44 | 000,014,336 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.HtmlParser.dll
[2013.06.28 04:34:34 | 000,041,984 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.Interface.dll
[2013.06.28 04:28:24 | 000,019,968 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.Miscellaneous.dll
[2013.06.28 04:34:38 | 000,066,048 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.SmartDownloader.Core.dll
[2013.06.28 04:34:40 | 000,158,720 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.SmartDownloader.Extensions.dll
[2013.06.28 04:34:44 | 000,139,776 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.SupportedSite.dll
[2013.06.28 04:34:36 | 000,019,456 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FMWeb\Downloader\FMDownloader.TrackDownloaderLib.dll
[2013.06.28 04:36:46 | 000,253,952 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\VideoDownloader.Model.dll
[2013.06.28 04:34:44 | 000,019,968 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\VideoDownloader.Tools.dll
[2013.06.28 04:37:00 | 000,010,752 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\cs\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:00 | 000,010,752 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\da\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:02 | 000,016,384 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\de-DE\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:02 | 000,013,312 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\el-GR\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:02 | 000,015,872 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\es-ES\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:02 | 000,016,384 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\fr-FR\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:02 | 000,011,264 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\hu\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:02 | 000,015,872 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\it\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:02 | 000,017,920 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\ja-JP\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:04 | 000,011,264 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\nl\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:04 | 000,011,264 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\pl\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:04 | 000,015,872 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\pt-BR\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:06 | 000,018,944 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\ru-RU\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:04 | 000,011,264 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\sk\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:04 | 000,012,800 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\uk\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:04 | 000,011,776 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\vi\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:04 | 000,010,240 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\zh-CN\FreemakeVideoDownloader.resources.dll
[2013.06.28 04:37:06 | 000,010,240 | ---- | M] () -- \Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader\Languages\zh-TW\FreemakeVideoDownloader.resources.dll
[2013.01.24 14:01:30 | 000,008,661 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\downloader.js
[2012.09.13 20:17:00 | 000,000,402 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\downloader.xul
[2012.09.11 13:45:40 | 000,015,511 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMCommon\FreemakeCommon\Profiles\FmDownloaderProfiles.xml
[2012.09.13 21:52:54 | 000,064,651 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMCommon\FreemakeCommon\Resources\VideoDownloader.png
[2012.09.13 21:52:54 | 000,064,719 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMCommon\FreemakeCommon\Resources\VideoDownloaderOn.png
[2013.04.01 13:12:18 | 000,020,992 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.Detector.dll
[2013.04.01 13:12:12 | 000,008,192 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.GlobalSettings.dll
[2013.04.01 13:12:18 | 000,014,336 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.HtmlParser.dll
[2013.04.01 13:12:12 | 000,041,984 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.Interface.dll
[2013.04.01 13:12:14 | 000,019,968 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.Miscellaneous.dll
[2013.04.01 13:12:14 | 000,066,048 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.SmartDownloader.Core.dll
[2013.04.01 13:12:16 | 000,158,720 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.SmartDownloader.Extensions.dll
[2013.04.01 13:12:18 | 000,126,976 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.SupportedSite.dll
[2013.04.01 13:12:14 | 000,019,456 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FMWeb\Downloader\FMDownloader.TrackDownloaderLib.dll
[2013.04.01 13:12:22 | 000,257,536 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\VideoDownloader.Model.dll
[2013.04.01 13:12:20 | 000,037,376 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\VideoDownloader.Tools.dll
[2013.04.01 13:12:32 | 000,010,752 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\cs\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:32 | 000,010,752 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\da\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:32 | 000,015,872 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\de-DE\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:32 | 000,013,312 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\el-GR\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:32 | 000,015,872 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\es-ES\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:32 | 000,015,872 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\fr-FR\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:32 | 000,011,264 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\hu\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,015,872 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\it\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,017,408 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\ja-JP\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,011,264 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\nl\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,011,264 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\pl\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,015,872 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\pt-BR\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,018,944 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\ru-RU\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,011,264 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\sk\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,012,800 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\uk\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,011,776 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\vi\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,010,240 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\zh-CN\FreemakeVideoDownloader.resources.dll
[2013.04.01 13:12:34 | 000,010,240 | ---- | M] () -- \Program Files\Freemake\Freemake Youtube Mp3 Converter\FreemakeVideoDownloader\Languages\zh-TW\FreemakeVideoDownloader.resources.dll
[2012.08.13 10:52:58 | 000,006,081 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.py
[2013.05.07 01:12:46 | 000,020,992 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.dll
[2012.08.13 11:04:18 | 000,000,171 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.ini
[2013.05.07 01:12:50 | 000,029,696 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\bin\javaloader.uno.dll
[2012.08.13 10:12:36 | 000,003,868 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\java\unoloader.jar
[2007.04.03 11:05:20 | 000,018,944 | ---- | M] () -- \Program Files\Samsung\Samsung PC Studio 3\CMLoader.dll
[2013.02.06 16:42:00 | 000,432,128 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Facebook\ZPSFacebookUploader.exe
[2010.04.29 14:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Facebook\ZPSPluginLoader.exe
[2012.10.18 16:47:30 | 000,442,368 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Flickr\ZPSFlickrUploader.exe
[2010.04.29 14:12:42 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Flickr\ZPSPluginLoader.exe
[2013.02.06 16:20:12 | 000,192,512 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Picasa\ZPSPicasaUploader.exe
[2010.04.29 14:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Picasa\ZPSPluginLoader.exe
[2013.02.18 12:50:00 | 000,103,960 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Program32\8bfLoader.exe
[2013.02.18 12:50:08 | 000,017,944 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Program32\WICLoader.exe
[2006.03.02 14:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.14 00:01:48 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.14 00:01:50 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll

< *minodlogin* /s >

< *tnod* /s >

< *AutoKMS* /s >
[2013.05.12 13:40:55 | 000,000,715 | ---- | M] () -- \WINDOWS\AutoKMS\AutoKMS.ini
[2013.06.16 21:23:18 | 000,063,049 | ---- | M] () -- \WINDOWS\AutoKMS\AutoKMS.log

< *activator* /s >

< *serial* /s >
[2006.03.02 14:00:00 | 000,064,640 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\serial.sys
[2013.05.11 10:11:06 | 000,310,272 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d0ff3383438d688a0118d0fa19ed1dc4\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2013.05.11 10:10:59 | 002,625,024 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1\System.Runtime.Serialization.ni.dll
[2013.05.11 00:44:14 | 000,017,840 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\v4.0_4.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013.05.11 00:37:31 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013.05.11 00:44:13 | 000,099,208 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.RunTime.Serialization.resources\v4.0_4.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.resources.dll
[2013.05.11 00:37:28 | 001,026,936 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2010.03.18 13:16:28 | 001,026,936 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 13:16:28 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2010.06.15 02:33:16 | 000,017,840 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2010.06.15 02:33:16 | 000,099,208 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2008.04.14 07:47:26 | 000,028,416 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\grserial.sys
[2008.04.14 07:51:10 | 000,064,256 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\serial.sys
[2006.03.02 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[2006.03.02 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2008.04.14 07:51:10 | 000,064,256 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys

< *w7lxe* /s >

< End of report >

Re: Zamrzne počítač

Napsal: 11 črc 2013 11:13
od ras099
OTL Extras logfile created on: 11.7.2013 11:29:16 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Martin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,44 Gb Total Physical Memory | 2,63 Gb Available Physical Memory | 76,51% Memory free
5,28 Gb Paging File | 4,59 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 45,30 Gb Total Space | 31,31 Gb Free Space | 69,12% Space Free | Partition Type: NTFS
Drive D: | 13,30 Gb Total Space | 7,01 Gb Free Space | 52,73% Space Free | Partition Type: NTFS
Drive E: | 174,29 Gb Total Space | 11,20 Gb Free Space | 6,43% Space Free | Partition Type: NTFS

Computer Name: MARTINRASZKA-PC | User Name: Martin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-507921405-117609710-839522115-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1542:TCP" = 1542:TCP:*:Enabled:Realtek WPS TCP Prot
"1542:UDP" = 1542:UDP:*:Enabled:Realtek WPS UDP Prot
"53:UDP" = 53:UDP:*:Enabled:Realtek AP UDP Prot
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe" = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan -- (Realtek Semiconductor Corp.)
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe -- (NVIDIA Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Java\jre7\launch4j-tmp\frd.exe" = C:\Program Files\Java\jre7\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary -- (Oracle Corporation)
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe" = C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe:*:Enabled:Visual Basic Command Line Compiler -- (Microsoft Corporation)
"C:\Program Files\REALTEK\USB Wireless LAN Utility\RtWLan.exe" = C:\Program Files\REALTEK\USB Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan
"C:\Program Files\REALTEK\USB Wireless LAN Utility\RTLDHCP.exe" = C:\Program Files\REALTEK\USB Wireless LAN Utility\RTLDHCP.exe:*:Enabled:RTLDHCP
"C:\Program Files\QIP 2012\qip.exe" = C:\Program Files\QIP 2012\qip.exe:*:Enabled:QIP 2012
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{064A929A-4DE8-40CF-A901-BD40C14E4D25}" = PDF Architect
"{0C1B3A6B-B467-474D-97E4-D8BAC3E839CD}" = YTD Toolbar v7.0
"{0F9196C6-58B4-445B-B56E-B1200FECC151}" = Microsoft Bootvis
"{1E0AF527-0B8E-4F8A-BA27-CB3C359998C6}" = OpenOffice.org 3.4.1
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.5
"{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C049499-055C-4a0c-A916-1D12314F45EB}" = REALTEK Wireless LAN Driver and Utility
"{AC76BA86-7AD7-1029-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) - Czech
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 307.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 307.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.53
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{CA8A885F-E95B-3FC6-BB91-F4D9377C7686}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{D642ACC5-F7E9-48F3-A7EE-B49C5447A10E}" = Samsung PC Studio 3
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE v.6.82
"Audacity_is1" = Audacity 2.0.3
"avast" = avast! Free Antivirus
"BSPlayerf" = BS.Player FREE
"CCleaner" = CCleaner
"CDex" = CDex extraction audio
"Cool Edit Pro 2.1" = Cool Edit Pro 2.1
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"Freemake Video Downloader_is1" = Freemake Video Downloader
"Freemake Youtube Mp3 Converter_is1" = Freemake Youtube Mp3 Converter
"ie8" = Windows Internet Explorer 8
"LAME_is1" = LAME v3.99.3 (for Windows)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.75.0.1300
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Mozilla Firefox 22.0 (x86 cs)" = Mozilla Firefox 22.0 (x86 cs)
"Mozilla Thunderbird 17.0.7 (x86 cs)" = Mozilla Thunderbird 17.0.7 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Mp3tag" = Mp3tag v2.54
"NVIDIA Drivers" = NVIDIA Drivers
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"VLC media player" = VLC media player 2.0.6
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"ZonerPhotoStudio15_CZ_is1" = Zoner Photo Studio 15

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 20.6.2013 10:02:27 | Computer Name = MARTINRASZKA-PC | Source = MsiInstaller | ID = 10005
Description = Product: Facebook Messenger 2.1.4814.0 -- This application requires
.NET Framework 2.0 or higher. Please install the .NET Framework then run this installer
again. You can download .NET Framework 4 from http://go.microsoft.com/fwlink/?LinkId=181011

Error - 20.6.2013 15:39:46 | Computer Name = MARTINRASZKA-PC | Source = MsiInstaller | ID = 11335
Description = Product: Microsoft Bootvis -- Error 1335. The cabinet file '_F5C7E0E1C2B04F1A46B4EC7EF43DE9A5'
required for this installation is corrupt and cannot be used. This could indicate
a network error, an error reading from the CD-ROM, or a problem with this package.

Error - 20.6.2013 15:39:47 | Computer Name = MARTINRASZKA-PC | Source = MsiInstaller | ID = 11335
Description = Product: Microsoft Bootvis -- Error 1335. The cabinet file '_F5C7E0E1C2B04F1A46B4EC7EF43DE9A5'
required for this installation is corrupt and cannot be used. This could indicate
a network error, an error reading from the CD-ROM, or a problem with this package.

Error - 20.6.2013 15:39:53 | Computer Name = MARTINRASZKA-PC | Source = MsiInstaller | ID = 11335
Description = Product: Microsoft Bootvis -- Error 1335. The cabinet file '_F5C7E0E1C2B04F1A46B4EC7EF43DE9A5'
required for this installation is corrupt and cannot be used. This could indicate
a network error, an error reading from the CD-ROM, or a problem with this package.

Error - 20.6.2013 15:39:54 | Computer Name = MARTINRASZKA-PC | Source = MsiInstaller | ID = 11335
Description = Product: Microsoft Bootvis -- Error 1335. The cabinet file '_F5C7E0E1C2B04F1A46B4EC7EF43DE9A5'
required for this installation is corrupt and cannot be used. This could indicate
a network error, an error reading from the CD-ROM, or a problem with this package.

Error - 26.6.2013 6:53:07 | Computer Name = MARTINRASZKA-PC | Source = WmiAdapter | ID = 4099
Description = Otevření služby se nezdařil

Error - 26.6.2013 6:53:38 | Computer Name = MARTINRASZKA-PC | Source = WmiAdapter | ID = 4099
Description = Otevření služby se nezdařil

Error - 26.6.2013 6:54:09 | Computer Name = MARTINRASZKA-PC | Source = WmiAdapter | ID = 4099
Description = Otevření služby se nezdařil

Error - 26.6.2013 6:54:39 | Computer Name = MARTINRASZKA-PC | Source = WmiAdapter | ID = 4099
Description = Otevření služby se nezdařil

Error - 30.6.2013 7:59:03 | Computer Name = MARTINRASZKA-PC | Source = Service1 | ID = 0
Description = Zastavení služby se nezdařilo. System.NullReferenceException: Odkaz
na objekt není nastaven na instanci objektu. v CaptureLibService.CaptureLibService.OnStop()

v System.ServiceProcess.ServiceBase.DeferredStop()

[ System Events ]
Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 11.7.2013 5:24:55 | Computer Name = MARTINRASZKA-PC | Source = Service Control Manager | ID = 7000
Description = Služba WinPcap Packet Driver (NPF) neuspěla při spuštění v důsledku
následující chyby: %%2


< End of report >

Re: Zamrzne počítač

Napsal: 11 črc 2013 14:30
od Márty84
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Spustte ho.
Kliknete na Prohledat a program zacne pracovat.
Az skonci, vyplivne na vas log (pokud ne, najdete ho zde C:\AdwCleaner[R?].txt ), ten mi sem zkopirujte.

Re: Zamrzne počítač

Napsal: 11 črc 2013 22:26
od ras099
# AdwCleaner v2.305 - Log vytvooen 11/07/2013 v 23:25:43
# Aktualizováno 11/07/2013 Xplode
# Operaení systém : Microsoft Windows XP Service Pack 3 (32 bits)
# Uživatel : Martin - MARTINRASZKA-PC
# Spuštin systém : Normální
# Spuštino z : C:\Documents and Settings\Martin\Plocha\adwcleaner.exe
# Volba [Prohledat]


***** [Služby] *****


***** [Soubory / Složky] *****


***** [Registry] *****

Klíe Nalezeno : HKCU\Software\AppDataLow\Software\SmartBar
Klíe Nalezeno : HKCU\Software\Conduit
Klíe Nalezeno : HKLM\Software\Conduit

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry jsou eisté.

-\\ Mozilla Firefox v22.0 (cs)

Soubor : C:\Documents and Settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\2ryyvvu5.default-1368371723227\prefs.js

[OK] Soubor je eistý.

*************************

AdwCleaner[R2].txt - [1467 octets] - [16/06/2013 23:37:13]
AdwCleaner[R3].txt - [934 octets] - [11/07/2013 23:25:43]
AdwCleaner[S2].txt - [1525 octets] - [18/06/2013 00:25:40]

########## EOF - C:\AdwCleaner[R3].txt - [1053 octets] ##########

Re: Zamrzne počítač

Napsal: 11 črc 2013 22:55
od Márty84
:arrow: Znovu ukoncete vsechny programy a spustte AdwCleaner.
Tentokrat kliknete na Smazat
Program zacne pracovat (muze dojit k restartu pc) a vyplivne dalsi log (pripadne bude zde C:\AdwCleaner [S1].txt ). Ten mi sem zase zkopirujte.


Jeste bych chtel vedet, kdo a proc spoustel TDSSKiller. Dejte mi sem jeho log. Je zde
C:\TDSSKiller.2.8.18.0_02.07.2013_10.54.20_log.txt

Re: Zamrzne počítač

Napsal: 12 črc 2013 08:50
od ras099
# AdwCleaner v2.305 - Log vytvooen 12/07/2013 v 09:41:54
# Aktualizováno 11/07/2013 Xplode
# Operaení systém : Microsoft Windows XP Service Pack 3 (32 bits)
# Uživatel : Martin - MARTINRASZKA-PC
# Spuštin systém : Normální
# Spuštino z : C:\Documents and Settings\Martin\Plocha\adwcleaner.exe
# Volba [Vymazat]


***** [Služby] *****


***** [Soubory / Složky] *****


***** [Registry] *****

Klíe Vymazáno : HKCU\Software\AppDataLow\Software\SmartBar
Klíe Vymazáno : HKCU\Software\Conduit
Klíe Vymazáno : HKLM\Software\Conduit

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry jsou eisté.

-\\ Mozilla Firefox v22.0 (cs)

Soubor : C:\Documents and Settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\2ryyvvu5.default-1368371723227\prefs.js

[OK] Soubor je eistý.

*************************

AdwCleaner[R2].txt - [1467 octets] - [16/06/2013 23:37:13]
AdwCleaner[R3].txt - [1122 octets] - [11/07/2013 23:25:43]
AdwCleaner[R4].txt - [1182 octets] - [11/07/2013 23:33:28]
AdwCleaner[S2].txt - [1525 octets] - [18/06/2013 00:25:40]
AdwCleaner[S3].txt - [1112 octets] - [12/07/2013 09:41:54]

########## EOF - C:\AdwCleaner[S3].txt - [1172 octets] ##########

Re: Zamrzne počítač

Napsal: 12 črc 2013 08:50
od ras099
10:54:20.0921 3536 TDSS rootkit removing tool 2.8.18.0 Jun 10 2013 21:44:19
10:54:21.0171 3536 ============================================================
10:54:21.0171 3536 Current date / time: 2013/07/02 10:54:21.0171
10:54:21.0171 3536 SystemInfo:
10:54:21.0171 3536
10:54:21.0171 3536 OS Version: 5.1.2600 ServicePack: 3.0
10:54:21.0171 3536 Product type: Workstation
10:54:21.0171 3536 ComputerName: MARTINRASZKA-PC
10:54:21.0171 3536 UserName: Martin
10:54:21.0171 3536 Windows directory: C:\WINDOWS
10:54:21.0171 3536 System windows directory: C:\WINDOWS
10:54:21.0171 3536 Processor architecture: Intel x86
10:54:21.0171 3536 Number of processors: 1
10:54:21.0171 3536 Page size: 0x1000
10:54:21.0171 3536 Boot type: Normal boot
10:54:21.0171 3536 ============================================================
10:54:22.0234 3536 Drive \Device\Harddisk0\DR0 - Size: 0x3A38A25E00 (232.88 Gb), SectorSize: 0x200, Cylinders: 0x7E2D, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000058
10:54:22.0250 3536 Drive \Device\Harddisk1\DR4 - Size: 0xF4400000 (3.82 Gb), SectorSize: 0x200, Cylinders: 0x1F2, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
10:54:22.0250 3536 ============================================================
10:54:22.0250 3536 \Device\Harddisk0\DR0:
10:54:22.0250 3536 MBR partitions:
10:54:22.0250 3536 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x5A9768A
10:54:22.0265 3536 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x5A97818, BlocksNum 0x1A98C89
10:54:22.0265 3536 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x75304E0, BlocksNum 0x15C940A1
10:54:22.0265 3536 \Device\Harddisk1\DR4:
10:54:22.0265 3536 MBR partitions:
10:54:22.0265 3536 ============================================================
10:54:22.0281 3536 C: <-> \Device\Harddisk0\DR0\Partition1
10:54:22.0328 3536 D: <-> \Device\Harddisk0\DR0\Partition2
10:54:22.0359 3536 E: <-> \Device\Harddisk0\DR0\Partition3
10:54:22.0359 3536 ============================================================
10:54:22.0359 3536 Initialize success
10:54:22.0359 3536 ============================================================
10:54:23.0953 0712 ============================================================
10:54:23.0953 0712 Scan started
10:54:23.0953 0712 Mode: Manual;
10:54:23.0953 0712 ============================================================
10:54:24.0671 0712 ================ Scan system memory ========================
10:54:24.0687 0712 System memory - ok
10:54:24.0687 0712 ================ Scan services =============================
10:54:24.0812 0712 Abiosdsk - ok
10:54:24.0812 0712 abp480n5 - ok
10:54:24.0859 0712 [ 4FE34F1F3126B61FCC6B2043AA8112C9 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:54:24.0859 0712 ACPI - ok
10:54:24.0890 0712 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
10:54:24.0890 0712 ACPIEC - ok
10:54:24.0953 0712 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
10:54:24.0953 0712 AdobeFlashPlayerUpdateSvc - ok
10:54:24.0968 0712 adpu160m - ok
10:54:24.0984 0712 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
10:54:24.0984 0712 aec - ok
10:54:25.0031 0712 [ 023867B6606FBABCDD52E089C4A507DA ] AegisP C:\WINDOWS\system32\DRIVERS\AegisP.sys
10:54:25.0031 0712 AegisP - ok
10:54:25.0062 0712 [ 322D0E36693D6E24A2398BEE62A268CD ] AFD C:\WINDOWS\System32\drivers\afd.sys
10:54:25.0062 0712 AFD - ok
10:54:25.0078 0712 Aha154x - ok
10:54:25.0078 0712 aic78u2 - ok
10:54:25.0093 0712 aic78xx - ok
10:54:25.0125 0712 [ E0A6FA244B8624D78FE5FF6F56A33BAE ] Alerter C:\WINDOWS\system32\alrsvc.dll
10:54:25.0125 0712 Alerter - ok
10:54:25.0140 0712 [ 88842DE939A827577BF24243699AC80A ] ALG C:\WINDOWS\System32\alg.exe
10:54:25.0156 0712 ALG - ok
10:54:25.0156 0712 AliIde - ok
10:54:25.0187 0712 [ FCFFA85CFD4BF7A4711012847048DCA3 ] AmdK8 C:\WINDOWS\system32\DRIVERS\AmdK8.sys
10:54:25.0187 0712 AmdK8 - ok
10:54:25.0203 0712 amsint - ok
10:54:25.0203 0712 AppMgmt - ok
10:54:25.0218 0712 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
10:54:25.0218 0712 Arp1394 - ok
10:54:25.0234 0712 asc - ok
10:54:25.0250 0712 asc3350p - ok
10:54:25.0250 0712 asc3550 - ok
10:54:25.0281 0712 [ 4AF5F360BA1E8794D32B366E45A64A0A ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
10:54:25.0281 0712 aswFsBlk - ok
10:54:25.0296 0712 [ 1F7094D4268D46F718C51286DC189791 ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys
10:54:25.0296 0712 aswMonFlt - ok
10:54:25.0328 0712 [ 7B43265F92257A21CBFD88E7A651044C ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys
10:54:25.0328 0712 AswRdr - ok
10:54:25.0328 0712 [ B680134BA1813B78B47FDD1DFF223CA5 ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys
10:54:25.0343 0712 aswRvrt - ok
10:54:25.0375 0712 [ CCD565A8A72AF7D45F9A242013870926 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
10:54:25.0375 0712 aswSnx - ok
10:54:25.0406 0712 [ 937300BC7C4CDF7576BCCE44E19BBB9D ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
10:54:25.0406 0712 aswSP - ok
10:54:25.0421 0712 [ 1F71F170D90E42EFDE9633D81D5E12DC ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
10:54:25.0421 0712 aswTdi - ok
10:54:25.0437 0712 [ 8CFAA2B965773A653F48F1207A9CB9C4 ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys
10:54:25.0437 0712 aswVmm - ok
10:54:25.0468 0712 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:54:25.0468 0712 AsyncMac - ok
10:54:25.0500 0712 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
10:54:25.0515 0712 atapi - ok
10:54:25.0515 0712 Atdisk - ok
10:54:25.0531 0712 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:54:25.0531 0712 Atmarpc - ok
10:54:25.0562 0712 [ DE31B88962A8645DBA5A37B993E7B0F1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
10:54:25.0562 0712 AudioSrv - ok
10:54:25.0593 0712 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
10:54:25.0593 0712 audstub - ok
10:54:25.0640 0712 [ 28D6701C710AD7BA3CB95E75F8F1A9AA ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
10:54:25.0656 0712 avast! Antivirus - ok
10:54:25.0687 0712 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
10:54:25.0687 0712 Beep - ok
10:54:25.0734 0712 [ 19395D092FD85DDC2D9C7729CF5A2AC8 ] BITS C:\WINDOWS\system32\qmgr.dll
10:54:25.0765 0712 BITS - ok
10:54:25.0812 0712 [ 249276D3EF1E74B992299CB96099E4D7 ] Browser C:\WINDOWS\System32\browser.dll
10:54:25.0812 0712 Browser - ok
10:54:25.0843 0712 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
10:54:25.0843 0712 cbidf2k - ok
10:54:25.0875 0712 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:54:25.0875 0712 CCDECODE - ok
10:54:25.0890 0712 cd20xrnt - ok
10:54:25.0906 0712 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
10:54:25.0906 0712 Cdaudio - ok
10:54:25.0937 0712 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
10:54:25.0937 0712 Cdfs - ok
10:54:25.0968 0712 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:54:25.0968 0712 Cdrom - ok
10:54:25.0984 0712 [ E390DC1D7C461D7D56EC53402F329928 ] CiSvc C:\WINDOWS\system32\cisvc.exe
10:54:25.0984 0712 CiSvc - ok
10:54:26.0000 0712 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
10:54:26.0000 0712 ClipSrv - ok
10:54:26.0078 0712 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:54:26.0078 0712 clr_optimization_v4.0.30319_32 - ok
10:54:26.0093 0712 CmdIde - ok
10:54:26.0093 0712 COMSysApp - ok
10:54:26.0125 0712 Cpqarray - ok
10:54:26.0140 0712 [ F3AB0933CBD166D271992F411C27CCAF ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
10:54:26.0156 0712 CryptSvc - ok
10:54:26.0156 0712 dac2w2k - ok
10:54:26.0171 0712 dac960nt - ok
10:54:26.0218 0712 [ C868F3AE15CF71A93F2AA3A32856D839 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
10:54:26.0234 0712 DcomLaunch - ok
10:54:26.0250 0712 [ 8C9A53E285AC5E6704844D0459EC85BE ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
10:54:26.0250 0712 Dhcp - ok
10:54:26.0265 0712 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
10:54:26.0265 0712 Disk - ok
10:54:26.0281 0712 dmadmin - ok
10:54:26.0312 0712 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
10:54:26.0328 0712 dmboot - ok
10:54:26.0343 0712 [ FFF1720AF51171F32F1EAD5CF71F2810 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
10:54:26.0343 0712 dmio - ok
10:54:26.0359 0712 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
10:54:26.0375 0712 dmload - ok
10:54:26.0406 0712 [ 2BFEFE9E865655A76982F050450B9591 ] dmserver C:\WINDOWS\System32\dmserver.dll
10:54:26.0406 0712 dmserver - ok
10:54:26.0421 0712 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
10:54:26.0421 0712 DMusic - ok
10:54:26.0437 0712 [ 0634B791684B84F4A331F3D3536FEEF8 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
10:54:26.0437 0712 Dnscache - ok
10:54:26.0484 0712 [ 4A3E2BD20157A0946751229E92EB8621 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
10:54:26.0484 0712 Dot3svc - ok
10:54:26.0500 0712 dpti2o - ok
10:54:26.0515 0712 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
10:54:26.0515 0712 drmkaud - ok
10:54:26.0546 0712 [ 0887D9C2BE8D940778CAD1E3B85F2A41 ] EapHost C:\WINDOWS\System32\eapsvc.dll
10:54:26.0546 0712 EapHost - ok
10:54:26.0562 0712 [ A2A4912798F2BE706ABADD3D30800D16 ] ERSvc C:\WINDOWS\System32\ersvc.dll
10:54:26.0562 0712 ERSvc - ok
10:54:26.0593 0712 [ F0D2AE69035092BF22DAD6B50FAB85C2 ] Eventlog C:\WINDOWS\system32\services.exe
10:54:26.0609 0712 Eventlog - ok
10:54:26.0625 0712 [ 260C69FD67687B0DC062FC3D31655857 ] EventSystem C:\WINDOWS\system32\es.dll
10:54:26.0640 0712 EventSystem - ok
10:54:26.0687 0712 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
10:54:26.0687 0712 Fastfat - ok
10:54:26.0703 0712 [ B927443008910B412BEC72FC41C1BAD0 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
10:54:26.0734 0712 FastUserSwitchingCompatibility - ok
10:54:26.0765 0712 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
10:54:26.0765 0712 Fdc - ok
10:54:26.0781 0712 [ AC366695A0796560AA37215AD5762AAF ] Fips C:\WINDOWS\system32\drivers\Fips.sys
10:54:26.0781 0712 Fips - ok
10:54:26.0796 0712 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:54:26.0796 0712 Flpydisk - ok
10:54:26.0812 0712 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
10:54:26.0828 0712 FltMgr - ok
10:54:26.0859 0712 [ 25E8ED6FC3820B59CE602BA4D4C1D01E ] FreemakeVideoCapture C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
10:54:26.0859 0712 FreemakeVideoCapture - ok
10:54:26.0875 0712 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:54:26.0875 0712 Fs_Rec - ok
10:54:26.0890 0712 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:54:26.0890 0712 Ftdisk - ok
10:54:26.0906 0712 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:54:26.0906 0712 Gpc - ok
10:54:26.0937 0712 [ 2A013E7530BEAB6E569FAA83F517E836 ] HdAudAddService C:\WINDOWS\system32\drivers\HdAudio.sys
10:54:26.0937 0712 HdAudAddService - ok
10:54:26.0984 0712 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
10:54:27.0000 0712 HDAudBus - ok
10:54:27.0187 0712 [ FCFE31FB75F8A6295B6B0AF87A626282 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
10:54:27.0203 0712 helpsvc - ok
10:54:27.0281 0712 [ 00E25EE90166B3E1BE6E74AEBF858306 ] HidServ C:\WINDOWS\System32\hidserv.dll
10:54:27.0281 0712 HidServ - ok
10:54:27.0312 0712 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:54:27.0312 0712 hidusb - ok
10:54:27.0343 0712 [ 7A6B320928F86BC851530D63C82965D9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
10:54:27.0343 0712 hkmsvc - ok
10:54:27.0359 0712 hpn - ok
10:54:27.0390 0712 [ F6AACF5BCE2893E0C1754AFEB672E5C9 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
10:54:27.0390 0712 HTTP - ok
10:54:27.0421 0712 [ 58FE2F2DA3BC5573F4A35B3760D3125F ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
10:54:27.0437 0712 HTTPFilter - ok
10:54:27.0437 0712 i2omp - ok
10:54:27.0453 0712 [ C528E27945367191E7BAE364930B6932 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:54:27.0468 0712 i8042prt - ok
10:54:27.0468 0712 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
10:54:27.0468 0712 Imapi - ok
10:54:27.0515 0712 [ F7B93AAFAD33B2320954C17E26C8D361 ] ImapiService C:\WINDOWS\system32\imapi.exe
10:54:27.0515 0712 ImapiService - ok
10:54:27.0531 0712 ini910u - ok
10:54:27.0656 0712 [ 1A5B97B5BFFDE5742F4209F734C4FAF0 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
10:54:27.0703 0712 IntcAzAudAddService - ok
10:54:27.0703 0712 IntelIde - ok
10:54:27.0734 0712 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
10:54:27.0734 0712 Ip6Fw - ok
10:54:27.0765 0712 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:54:27.0765 0712 IpFilterDriver - ok
10:54:27.0765 0712 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:54:27.0765 0712 IpInIp - ok
10:54:27.0781 0712 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:54:27.0781 0712 IpNat - ok
10:54:27.0812 0712 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:54:27.0812 0712 IPSec - ok
10:54:27.0812 0712 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
10:54:27.0828 0712 IRENUM - ok
10:54:27.0843 0712 [ CC9F8A2D60AED1A51A3AC34C59B987AE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:54:27.0843 0712 isapnp - ok
10:54:27.0906 0712 [ 5739F2821D49975CEDE6BF0153D0CF01 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
10:54:27.0906 0712 JavaQuickStarterService - ok
10:54:27.0921 0712 [ 1B6162FE7F66B1A71A4B70F941C4AA9B ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:54:27.0921 0712 Kbdclass - ok
10:54:27.0937 0712 [ 86C8F23616C6C6E5B2776901C17B945B ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
10:54:27.0937 0712 kbdhid - ok
10:54:27.0968 0712 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
10:54:27.0968 0712 kmixer - ok
10:54:27.0984 0712 [ 1705745D900DABF2D89F90EBADDC7517 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
10:54:27.0984 0712 KSecDD - ok
10:54:28.0015 0712 [ 21920AC69594AB021237054FA728FE46 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
10:54:28.0031 0712 lanmanserver - ok
10:54:28.0046 0712 [ 5190783F51A2D7A8495202C664D7C963 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
10:54:28.0062 0712 lanmanworkstation - ok
10:54:28.0093 0712 [ 0AB159F536E3E8F7F07113702A07CCA5 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
10:54:28.0093 0712 LmHosts - ok
10:54:28.0125 0712 [ 221CD1C815B8A6B79389C3F5D1018DE8 ] Messenger C:\WINDOWS\System32\msgsvc.dll
10:54:28.0125 0712 Messenger - ok
10:54:28.0156 0712 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
10:54:28.0156 0712 mnmdd - ok
10:54:28.0187 0712 [ 9A57D046F88F4B69751B11FD40088A61 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
10:54:28.0187 0712 mnmsrvc - ok
10:54:28.0218 0712 [ 44032B0C6D9954D3FD26438330B99EE7 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
10:54:28.0218 0712 Modem - ok
10:54:28.0234 0712 [ 4CB582831DBDE63CE43B45D771218374 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:54:28.0234 0712 Mouclass - ok
10:54:28.0265 0712 [ BB269EBA740737AB749B214D568B6812 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:54:28.0265 0712 mouhid - ok
10:54:28.0265 0712 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
10:54:28.0281 0712 MountMgr - ok
10:54:28.0312 0712 [ 825BF0E46B4470A463AEB641480C5FCA ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
10:54:28.0312 0712 MozillaMaintenance - ok
10:54:28.0328 0712 mraid35x - ok
10:54:28.0343 0712 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:54:28.0343 0712 MRxDAV - ok
10:54:28.0375 0712 [ 68755F0FF16070178B54674FE5B847B0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:54:28.0375 0712 MRxSmb - ok
10:54:28.0390 0712 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D ] MSDTC C:\WINDOWS\system32\msdtc.exe
10:54:28.0390 0712 MSDTC - ok
10:54:28.0421 0712 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
10:54:28.0421 0712 Msfs - ok
10:54:28.0437 0712 MSIServer - ok
10:54:28.0453 0712 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:54:28.0453 0712 MSKSSRV - ok
10:54:28.0468 0712 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:54:28.0468 0712 MSPCLOCK - ok
10:54:28.0484 0712 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
10:54:28.0500 0712 MSPQM - ok
10:54:28.0515 0712 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:54:28.0515 0712 mssmbios - ok
10:54:28.0546 0712 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
10:54:28.0546 0712 MSTEE - ok
10:54:28.0546 0712 [ 2F625D11385B1A94360BFC70AAEFDEE1 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
10:54:28.0562 0712 Mup - ok
10:54:28.0578 0712 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:54:28.0578 0712 NABTSFEC - ok
10:54:28.0609 0712 [ 6EA362E9DB03D44F6B996F4D8BE237E9 ] napagent C:\WINDOWS\System32\qagentrt.dll
10:54:28.0625 0712 napagent - ok
10:54:28.0656 0712 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
10:54:28.0656 0712 NDIS - ok
10:54:28.0671 0712 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:54:28.0671 0712 NdisIP - ok
10:54:28.0687 0712 [ 1AB3D00C991AB086E69DB84B6C0ED78F ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:54:28.0687 0712 NdisTapi - ok
10:54:28.0718 0712 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:54:28.0718 0712 Ndisuio - ok
10:54:28.0734 0712 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:54:28.0734 0712 NdisWan - ok
10:54:28.0734 0712 [ 6215023940CFD3702B46ABC304E1D45A ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
10:54:28.0750 0712 NDProxy - ok
10:54:28.0765 0712 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
10:54:28.0765 0712 NetBIOS - ok
10:54:28.0796 0712 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
10:54:28.0796 0712 NetBT - ok
10:54:28.0828 0712 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDE C:\WINDOWS\system32\netdde.exe
10:54:28.0843 0712 NetDDE - ok
10:54:28.0843 0712 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
10:54:28.0859 0712 NetDDEdsdm - ok
10:54:28.0890 0712 [ ED0A176354487CEED65B80A7148AB739 ] Netlogon C:\WINDOWS\system32\lsass.exe
10:54:28.0890 0712 Netlogon - ok
10:54:28.0921 0712 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40 ] Netman C:\WINDOWS\System32\netman.dll
10:54:28.0937 0712 Netman - ok
10:54:28.0968 0712 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
10:54:28.0968 0712 NIC1394 - ok
10:54:29.0015 0712 [ AAC97DAB5F8A0573CF10E0EAC42A7724 ] Nla C:\WINDOWS\System32\mswsock.dll
10:54:29.0031 0712 Nla - ok
10:54:29.0031 0712 NPF - ok
10:54:29.0046 0712 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
10:54:29.0046 0712 Npfs - ok
10:54:29.0078 0712 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
10:54:29.0078 0712 Ntfs - ok
10:54:29.0093 0712 [ ED0A176354487CEED65B80A7148AB739 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
10:54:29.0093 0712 NtLmSsp - ok
10:54:29.0171 0712 [ 023DD70573D644F3D9C8B1258A7BFD08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
10:54:29.0187 0712 NtmsSvc - ok
10:54:29.0203 0712 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
10:54:29.0203 0712 Null - ok
10:54:29.0562 0712 [ 785500CE8693C06EAAF29FAA64DB17C5 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:54:29.0671 0712 nv - ok
10:54:29.0687 0712 [ C61927D27B75ED56723F2508F1A6B1BE ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
10:54:29.0703 0712 NVENETFD - ok
10:54:29.0734 0712 [ 52DCE3B30C9D61C8E20FE3C6DA4BDFB7 ] nvgts C:\WINDOWS\system32\DRIVERS\nvgts.sys
10:54:29.0734 0712 nvgts - ok
10:54:29.0765 0712 [ C529B614EF88BE0F62B886C67B516550 ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
10:54:29.0765 0712 nvnetbus - ok
10:54:29.0796 0712 [ 3A990B8FA88E1B9F2D99C1B9B8D76F4B ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
10:54:29.0812 0712 NVSvc - ok
10:54:29.0875 0712 [ 14314A33845ABD19CADA062A037CC2F6 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
10:54:29.0890 0712 nvUpdatusService - ok
10:54:29.0906 0712 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:54:29.0906 0712 NwlnkFlt - ok
10:54:29.0921 0712 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:54:29.0921 0712 NwlnkFwd - ok
10:54:29.0937 0712 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
10:54:29.0937 0712 ohci1394 - ok
10:54:29.0953 0712 [ 46F8DB73B4A53E543F8E371DC7C75BAE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
10:54:29.0953 0712 Parport - ok
10:54:29.0968 0712 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
10:54:29.0968 0712 PartMgr - ok
10:54:29.0984 0712 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
10:54:30.0000 0712 ParVdm - ok
10:54:30.0000 0712 [ 6CE351D149CB4BEFC702951E471E1730 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
10:54:30.0015 0712 PCI - ok
10:54:30.0015 0712 [ 2DA4EC85E0EA7A45C6B2A05820492D5A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
10:54:30.0031 0712 PCIIde - ok
10:54:30.0046 0712 [ 4FC31E6C19A5CE5198B1ABFF94CAE758 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
10:54:30.0046 0712 Pcmcia - ok
10:54:30.0109 0712 [ 20372BE109FEE1C37E2D5216680DB9EB ] PDF Architect Helper Service C:\Program Files\PDF Architect\HelperService.exe
10:54:30.0125 0712 PDF Architect Helper Service - ok
10:54:30.0171 0712 [ B90A279073A815A4AA2C45A09EE004FA ] PDF Architect Service C:\Program Files\PDF Architect\ConversionService.exe
10:54:30.0171 0712 PDF Architect Service - ok
10:54:30.0187 0712 perc2 - ok
10:54:30.0203 0712 perc2hib - ok
10:54:30.0234 0712 [ F0D2AE69035092BF22DAD6B50FAB85C2 ] PlugPlay C:\WINDOWS\system32\services.exe
10:54:30.0250 0712 PlugPlay - ok
10:54:30.0265 0712 [ ED0A176354487CEED65B80A7148AB739 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
10:54:30.0265 0712 PolicyAgent - ok
10:54:30.0281 0712 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:54:30.0296 0712 PptpMiniport - ok
10:54:30.0296 0712 [ 7EB15DCE4EC3A0220BD796A15C18186E ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
10:54:30.0296 0712 Processor - ok
10:54:30.0312 0712 [ ED0A176354487CEED65B80A7148AB739 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
10:54:30.0312 0712 ProtectedStorage - ok
10:54:30.0328 0712 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
10:54:30.0328 0712 PSched - ok
10:54:30.0343 0712 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:54:30.0343 0712 Ptilink - ok
10:54:30.0375 0712 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:54:30.0375 0712 PxHelp20 - ok
10:54:30.0375 0712 ql1080 - ok
10:54:30.0390 0712 Ql10wnt - ok
10:54:30.0406 0712 ql12160 - ok
10:54:30.0421 0712 ql1240 - ok
10:54:30.0421 0712 ql1280 - ok
10:54:30.0453 0712 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:54:30.0453 0712 RasAcd - ok
10:54:30.0484 0712 [ 2B5E44EA009F2F374B980E1E9A70635D ] RasAuto C:\WINDOWS\System32\rasauto.dll
10:54:30.0500 0712 RasAuto - ok
10:54:30.0515 0712 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:54:30.0531 0712 Rasl2tp - ok
10:54:30.0578 0712 [ D57554C664B64604BD1EE13EA2C07E77 ] RasMan C:\WINDOWS\System32\rasmans.dll
10:54:30.0593 0712 RasMan - ok
10:54:30.0593 0712 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:54:30.0609 0712 RasPppoe - ok
10:54:30.0609 0712 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
10:54:30.0609 0712 Raspti - ok
10:54:30.0640 0712 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:54:30.0640 0712 Rdbss - ok
10:54:30.0671 0712 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:54:30.0671 0712 RDPCDD - ok
10:54:30.0718 0712 [ 6728E45B66F93C08F11DE2E316FC70DD ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
10:54:30.0718 0712 RDPWD - ok
10:54:30.0765 0712 [ C0D9D9711CB74EE9BC66353D8CBDAB0E ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
10:54:30.0781 0712 RDSessMgr - ok
10:54:30.0781 0712 [ 611BFD220305BE3A85AE876EA47D4AA5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
10:54:30.0796 0712 redbook - ok
10:54:30.0828 0712 [ 127C26B5371651043450E52542099ABA ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
10:54:30.0828 0712 RemoteAccess - ok
10:54:30.0843 0712 [ 718B3BDC0BC3C2F7D065A53D26202AF9 ] RpcLocator C:\WINDOWS\system32\locator.exe
10:54:30.0843 0712 RpcLocator - ok
10:54:30.0875 0712 [ C868F3AE15CF71A93F2AA3A32856D839 ] RpcSs C:\WINDOWS\system32\rpcss.dll
10:54:30.0890 0712 RpcSs - ok
10:54:30.0906 0712 [ 09AB2E71E58B078038E3BFDBA7FFC984 ] RSVP C:\WINDOWS\system32\rsvp.exe
10:54:30.0906 0712 RSVP - ok
10:54:30.0953 0712 [ CE7BF0FBA412F5C339A2212567DFECBA ] RTL8192cu C:\WINDOWS\system32\DRIVERS\rtwlanu.sys
10:54:30.0968 0712 RTL8192cu - ok
10:54:31.0015 0712 [ CE7BF0FBA412F5C339A2212567DFECBA ] RtlWlanu C:\WINDOWS\system32\DRIVERS\rtwlanu.sys
10:54:31.0031 0712 RtlWlanu - ok
10:54:31.0046 0712 [ ED0A176354487CEED65B80A7148AB739 ] SamSs C:\WINDOWS\system32\lsass.exe
10:54:31.0046 0712 SamSs - ok
10:54:31.0062 0712 sbaphd - ok
10:54:31.0062 0712 SBRE - ok
10:54:31.0078 0712 [ 410046E401EB11E1E6749E9DEEA41D4A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
10:54:31.0093 0712 SCardSvr - ok
10:54:31.0125 0712 [ 3FF232A7731621B8902D81D42418C93C ] Schedule C:\WINDOWS\system32\schedsvc.dll
10:54:31.0140 0712 Schedule - ok
10:54:31.0171 0712 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:54:31.0171 0712 Secdrv - ok
10:54:31.0187 0712 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6 ] seclogon C:\WINDOWS\System32\seclogon.dll
10:54:31.0203 0712 seclogon - ok
10:54:31.0218 0712 [ A530B75C10C23C9AB28FDB6CE719E21F ] SENS C:\WINDOWS\system32\sens.dll
10:54:31.0234 0712 SENS - ok
10:54:31.0250 0712 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
10:54:31.0250 0712 serenum - ok
10:54:31.0250 0712 [ B842729337C9B921615C40D3C1A1AF96 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
10:54:31.0265 0712 Serial - ok
10:54:31.0296 0712 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
10:54:31.0296 0712 Sfloppy - ok
10:54:31.0343 0712 [ F58FACA9621D2DB01BD0927D9A0A208E ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
10:54:31.0359 0712 SharedAccess - ok
10:54:31.0375 0712 [ B927443008910B412BEC72FC41C1BAD0 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
10:54:31.0390 0712 ShellHWDetection - ok
10:54:31.0406 0712 Simbad - ok
10:54:31.0437 0712 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
10:54:31.0437 0712 SkypeUpdate - ok
10:54:31.0468 0712 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:54:31.0468 0712 SLIP - ok
10:54:31.0484 0712 Sparrow - ok
10:54:31.0500 0712 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
10:54:31.0500 0712 splitter - ok
10:54:31.0515 0712 [ CB1090BCA0E7B40D0B5B4E4D66531809 ] Spooler C:\WINDOWS\system32\spoolsv.exe
10:54:31.0515 0712 Spooler - ok
10:54:31.0531 0712 [ 94610C8653635E4459316A0050D55CE7 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
10:54:31.0546 0712 sr - ok
10:54:31.0562 0712 [ 35B91147124F64AC8081A2EDB9EA4DEE ] srservice C:\WINDOWS\system32\srsvc.dll
10:54:31.0578 0712 srservice - ok
10:54:31.0609 0712 [ 5252605079810904E31C332E241CD59B ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
10:54:31.0609 0712 Srv - ok
10:54:31.0640 0712 [ BECD5271DC4E3B7C3D035F790FCBC1E5 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
10:54:31.0656 0712 SSDPSRV - ok
10:54:31.0687 0712 [ BD15182E9D2D3FABC1D1313BADBD2415 ] ss_bus C:\WINDOWS\system32\DRIVERS\ss_bus.sys
10:54:31.0687 0712 ss_bus - ok
10:54:31.0703 0712 [ 67D1144F249A3C5E03EBD7A2304DEE11 ] ss_mdfl C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
10:54:31.0718 0712 ss_mdfl - ok
10:54:31.0750 0712 [ 954B7CE2D54C703D6A8471D6B05A5E13 ] ss_mdm C:\WINDOWS\system32\DRIVERS\ss_mdm.sys
10:54:31.0750 0712 ss_mdm - ok
10:54:31.0781 0712 [ 306521935042FC0A6988D528643619B3 ] StarOpen C:\WINDOWS\system32\drivers\StarOpen.sys
10:54:31.0781 0712 StarOpen - ok
10:54:31.0828 0712 [ C1CDD9275F6A115BB0AE1D55D8D27BA6 ] stisvc C:\WINDOWS\system32\wiaservc.dll
10:54:31.0843 0712 stisvc - ok
10:54:31.0875 0712 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:54:31.0875 0712 streamip - ok
10:54:31.0890 0712 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
10:54:31.0890 0712 swenum - ok
10:54:31.0906 0712 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
10:54:31.0906 0712 swmidi - ok
10:54:31.0921 0712 SwPrv - ok
10:54:31.0937 0712 symc810 - ok
10:54:31.0937 0712 symc8xx - ok
10:54:31.0953 0712 sym_hi - ok
10:54:31.0968 0712 sym_u3 - ok
10:54:31.0984 0712 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
10:54:31.0984 0712 sysaudio - ok
10:54:32.0015 0712 [ CE06F01B88ACE199A1BF460CAC29C110 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
10:54:32.0031 0712 SysmonLog - ok
10:54:32.0078 0712 [ C2546CD7A398476F9DF5614B2AE160E8 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
10:54:32.0093 0712 TapiSrv - ok
10:54:32.0109 0712 [ 93EA8D04EC73A85DB02EB8805988F733 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:54:32.0109 0712 Tcpip - ok
10:54:32.0140 0712 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
10:54:32.0140 0712 TDPIPE - ok
10:54:32.0156 0712 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
10:54:32.0156 0712 TDTCP - ok
10:54:32.0187 0712 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
10:54:32.0187 0712 TermDD - ok
10:54:32.0203 0712 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E ] TermService C:\WINDOWS\System32\termsrv.dll
10:54:32.0234 0712 TermService - ok
10:54:32.0250 0712 [ B927443008910B412BEC72FC41C1BAD0 ] Themes C:\WINDOWS\System32\shsvcs.dll
10:54:32.0250 0712 Themes - ok
10:54:32.0265 0712 TosIde - ok
10:54:32.0281 0712 [ 38853304CCB938D30E0C4CDE8D2C2A8A ] TrkWks C:\WINDOWS\system32\trkwks.dll
10:54:32.0281 0712 TrkWks - ok
10:54:32.0312 0712 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
10:54:32.0328 0712 Udfs - ok
10:54:32.0328 0712 ultra - ok
10:54:32.0359 0712 [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe
10:54:32.0359 0712 UMWdf - ok
10:54:32.0390 0712 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
10:54:32.0390 0712 Update - ok
10:54:32.0421 0712 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E ] upnphost C:\WINDOWS\System32\upnphost.dll
10:54:32.0437 0712 upnphost - ok
10:54:32.0453 0712 [ 20A0F6A11959E92908717D09E87D670D ] UPS C:\WINDOWS\System32\ups.exe
10:54:32.0453 0712 UPS - ok
10:54:32.0484 0712 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys
10:54:32.0484 0712 usbaudio - ok
10:54:32.0500 0712 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:54:32.0515 0712 usbccgp - ok
10:54:32.0531 0712 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:54:32.0531 0712 usbehci - ok
10:54:32.0562 0712 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:54:32.0562 0712 usbhub - ok
10:54:32.0578 0712 [ 0DAECCE65366EA32B162F85F07C6753B ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys
10:54:32.0593 0712 usbohci - ok
10:54:32.0609 0712 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:54:32.0625 0712 usbscan - ok
10:54:32.0640 0712 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:54:32.0656 0712 USBSTOR - ok
10:54:32.0687 0712 [ 63BBFCA7F390F4C49ED4B96BFB1633E0 ] usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys
10:54:32.0687 0712 usbvideo - ok
10:54:32.0718 0712 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
10:54:32.0718 0712 VgaSave - ok
10:54:32.0734 0712 ViaIde - ok
10:54:32.0734 0712 [ 28A4B296B47782173C346E376CB374D1 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
10:54:32.0750 0712 VolSnap - ok
10:54:32.0765 0712 [ D6BA1A63D9E00933F1CD2A885573AFB2 ] VSS C:\WINDOWS\System32\vssvc.exe
10:54:32.0765 0712 VSS - ok
10:54:32.0781 0712 [ FA4E1CDBA256787F2149F4AAD07BC91F ] W32Time C:\WINDOWS\system32\w32time.dll
10:54:32.0828 0712 W32Time - ok
10:54:32.0859 0712 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:54:32.0859 0712 Wanarp - ok
10:54:32.0875 0712 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
10:54:32.0890 0712 wdmaud - ok
10:54:32.0906 0712 [ 47AE51048A82DFA1CD6B51D369F7E169 ] WebClient C:\WINDOWS\System32\webclnt.dll
10:54:32.0906 0712 WebClient - ok
10:54:32.0968 0712 [ E488332126E3B1182D2B8A0C35408EC6 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
10:54:32.0968 0712 winmgmt - ok
10:54:33.0015 0712 [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
10:54:33.0015 0712 WmdmPmSN - ok
10:54:33.0062 0712 [ 23F6F03272F7E5679F1F050AED5ACEE6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
10:54:33.0062 0712 WmiApSrv - ok
10:54:33.0125 0712 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
10:54:33.0156 0712 WPFFontCache_v0400 - ok
10:54:33.0203 0712 [ 4C86D5FAF78194995AF9CC1075F65DD3 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
10:54:33.0203 0712 wscsvc - ok
10:54:33.0234 0712 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:54:33.0234 0712 WSTCODEC - ok
10:54:33.0250 0712 [ C1364564800EE9784192145324A23308 ] wuauserv C:\WINDOWS\system32\wuauserv.dll
10:54:33.0265 0712 wuauserv - ok
10:54:33.0312 0712 [ A27D4BA7264C0BF52F32D10405BEA1D4 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
10:54:33.0343 0712 WZCSVC - ok
10:54:33.0359 0712 [ EAA4BB9EDB3FB10CF8979FE65E63658F ] xmlprov C:\WINDOWS\System32\xmlprov.dll
10:54:33.0375 0712 xmlprov - ok
10:54:33.0406 0712 ================ Scan global ===============================
10:54:33.0421 0712 [ F36278E42C8C5DF03CE17DAC8231C91C ] C:\WINDOWS\system32\basesrv.dll
10:54:33.0453 0712 [ 77A41C497ADB0C96D1E8DF6F71D843C0 ] C:\WINDOWS\system32\winsrv.dll
10:54:33.0468 0712 [ 77A41C497ADB0C96D1E8DF6F71D843C0 ] C:\WINDOWS\system32\winsrv.dll
10:54:33.0500 0712 [ F0D2AE69035092BF22DAD6B50FAB85C2 ] C:\WINDOWS\system32\services.exe
10:54:33.0500 0712 [Global] - ok
10:54:33.0515 0712 ================ Scan MBR ==================================
10:54:33.0531 0712 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
10:54:33.0671 0712 \Device\Harddisk0\DR0 - ok
10:54:33.0687 0712 [ EA9EA666E81195AEACDD2BFE6FD523F3 ] \Device\Harddisk1\DR4
10:54:35.0453 0712 \Device\Harddisk1\DR4 - ok
10:54:35.0453 0712 ================ Scan VBR ==================================
10:54:35.0453 0712 [ 2CDB0A6132464025B509421F46CE98DD ] \Device\Harddisk0\DR0\Partition1
10:54:35.0453 0712 \Device\Harddisk0\DR0\Partition1 - ok
10:54:35.0484 0712 [ 9FA98E7B9D05A016C67ABFAFE4A93A8E ] \Device\Harddisk0\DR0\Partition2
10:54:35.0484 0712 \Device\Harddisk0\DR0\Partition2 - ok
10:54:35.0500 0712 [ EF8CC973348AD6396FD271B5FAA0E9E0 ] \Device\Harddisk0\DR0\Partition3
10:54:35.0500 0712 \Device\Harddisk0\DR0\Partition3 - ok
10:54:35.0515 0712 ============================================================
10:54:35.0515 0712 Scan finished
10:54:35.0515 0712 ============================================================
10:54:35.0531 0212 Detected object count: 0
10:54:35.0531 0212 Actual detected object count: 0
10:54:45.0984 2596 Deinitialize success