
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kontrola logu-test antiviru
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Kontrola logu-test antiviru
Dobrý den,
když chci spustit v antiviru (MSE) kontrolu počítače, tak se mi zasekne asi po půl minutě u souboru powercfg.exe , poté už musím vypnout počítač natvrdo. Jinak bych řekl že počítač jede normálně. Přikládám log z RSIT.
Logfile of random's system information tool 1.09 (written by random/random)
Run by ASUS at 2011-08-27 10:54:59
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 81 GB (68%) free of 119 GB
Total RAM: 3838 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:55:03, on 27.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
C:\Program Files\trend micro\ASUS.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - Global Startup: FancyStart daemon.lnk = ?
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11073 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe" -switch-3be2f036c43042cdb03588591c9325c3
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\SysWOW64\svchost.exe -k Akamai
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
taskeng.exe {32A4BFB4-FB7B-4AC0-94EC-CD298997175E}
taskeng.exe {CEF538E9-B905-4687-AC62-0E2620536C77}
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe"
taskeng.exe {3DA75EC2-03AD-4491-B031-BAC2A541E8D3}
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
WLIDSvcM.exe 1780
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
ATKOSD.exe
WDC.exe
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Prefetch/ContentPrefetchPrerender1/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_enabled/SpdyImpact/npn_with_spdy/ --disable-client-side-phishing-detection --channel=4680.05759580.828958467 /prefetch:3
C:\Windows\system32\rundll32.exe "C:\PROGRA~2\Google\Chrome\APPLIC~1\130782~1.215\gcswf32.dll",BrokerMain browser=chrome
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Google\Chrome\Application\13.0.782.215\gcswf32.dll" --lang=cs --channel=4680.04E521C0.1741304682 --flash-broker=2692 /prefetch:4
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
taskhost.exe $(Arg0)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\system32\sppsvc.exe
"C:\Users\ASUS\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-03-04 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2011-03-04 318960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-28 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-03-04 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2011-03-04 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2011-03-04 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar BHO - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-14 609544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-07-14 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-03-04 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-03-04 256112]
{8dcb7100-df86-4384-8842-8fa844297b3f} - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-14 609544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [2010-03-16 1754448]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-06-10 649608]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2011-07-22 3077528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2011-03-04 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-03 103720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-13 10144288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console 3]
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2010-09-24 1601536]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS Premium Sound.lnk]
C:\Windows\INSTAL~1\{E5CF6~1\NEBEA7~1.EXE [2011-03-04 156952]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"Nuance PDF Reader-reminder"=C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [2008-11-03 328992]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-11 439568]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-09-22 98304]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-10-08 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-07-19 421736]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.3.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-08-24 19:07:46 ----A---- C:\Windows\system32\tzres.dll
2011-08-24 19:07:45 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-08-20 18:26:36 ----D---- C:\Program Files (x86)\Registry Genius
2011-08-20 17:12:56 ----A---- C:\Windows\system32\aswBoot.exe
2011-08-20 17:12:37 ----D---- C:\ProgramData\AVAST Software
2011-08-20 17:12:37 ----D---- C:\Program Files\AVAST Software
2011-08-20 16:51:47 ----D---- C:\Users\ASUS\AppData\Roaming\ChessBase
2011-08-18 09:03:41 ----D---- C:\Program Files\trend micro
2011-08-18 09:03:40 ----D---- C:\rsit
2011-08-16 12:01:55 ----D---- C:\Users\ASUS\AppData\Roaming\Apple Computer
2011-08-16 12:01:22 ----A---- C:\Windows\SYSWOW64\GEARAspi.dll
2011-08-16 12:01:22 ----A---- C:\Windows\system32\GEARAspi64.dll
2011-08-16 12:01:22 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2011-08-16 12:00:56 ----D---- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-08-16 12:00:56 ----D---- C:\Program Files\iTunes
2011-08-16 12:00:56 ----D---- C:\Program Files\iPod
2011-08-16 12:00:56 ----D---- C:\Program Files (x86)\iTunes
2011-08-16 12:00:23 ----D---- C:\ProgramData\Apple Computer
2011-08-16 12:00:23 ----D---- C:\Program Files (x86)\QuickTime
2011-08-16 12:00:13 ----D---- C:\Program Files (x86)\Apple Software Update
2011-08-16 12:00:05 ----D---- C:\Program Files\Common Files\Apple
2011-08-16 11:59:52 ----D---- C:\Program Files\Bonjour
2011-08-16 11:59:52 ----D---- C:\Program Files (x86)\Bonjour
2011-08-16 11:59:45 ----D---- C:\ProgramData\Apple
2011-08-12 08:55:37 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-12 08:55:36 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-08-12 08:55:35 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-08-12 08:55:35 ----A---- C:\Windows\system32\iertutil.dll
2011-08-12 08:55:34 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-08-12 08:55:34 ----A---- C:\Windows\system32\ieui.dll
2011-08-12 08:55:33 ----A---- C:\Windows\SYSWOW64\url.dll
2011-08-12 08:55:33 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-08-12 08:55:33 ----A---- C:\Windows\system32\url.dll
2011-08-12 08:55:33 ----A---- C:\Windows\system32\jscript9.dll
2011-08-12 08:55:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-08-12 08:55:32 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-08-12 08:55:32 ----A---- C:\Windows\system32\urlmon.dll
2011-08-12 08:55:32 ----A---- C:\Windows\system32\jscript.dll
2011-08-12 08:55:31 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-08-12 08:55:31 ----A---- C:\Windows\system32\wininet.dll
2011-08-12 08:55:31 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-12 08:55:30 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-08-12 08:55:29 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-08-12 08:55:26 ----A---- C:\Windows\system32\mshtml.dll
2011-08-12 08:55:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-08-12 08:55:25 ----A---- C:\Windows\system32\ieframe.dll
2011-08-11 18:07:46 ----D---- C:\Riot Games
2011-08-11 15:09:24 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-08-11 15:09:24 ----A---- C:\Windows\system32\xmllite.dll
2011-08-11 15:09:23 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-11 15:09:23 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-11 15:09:22 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-08-11 15:09:22 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-08-11 15:09:22 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-08-11 15:09:22 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-11 15:09:22 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-11 15:09:21 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-08-11 15:09:21 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-08-11 15:09:17 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-11 15:09:08 ----A---- C:\Windows\system32\wow64.dll
2011-08-11 15:09:08 ----A---- C:\Windows\system32\winsrv.dll
2011-08-11 15:09:08 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-11 15:09:08 ----A---- C:\Windows\system32\kernel32.dll
2011-08-11 15:09:08 ----A---- C:\Windows\system32\conhost.exe
2011-08-11 15:09:07 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-08-11 15:09:07 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-08-11 15:09:07 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-08-11 15:09:07 ----A---- C:\Windows\system32\wow64win.dll
2011-08-11 15:09:07 ----A---- C:\Windows\system32\wow64cpu.dll
2011-08-11 15:09:07 ----A---- C:\Windows\system32\ntvdm64.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 15:09:06 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-08-11 15:09:06 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 15:09:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 15:09:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-08-11 15:09:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-11 15:09:01 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-08-11 15:09:00 ----A---- C:\Windows\SYSWOW64\user.exe
2011-08-11 15:08:58 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-11 15:08:54 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-08-11 15:08:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-11 15:08:52 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-08-03 16:20:30 ----D---- C:\Program Files (x86)\Microsoft WSE
2011-08-03 15:59:59 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-08-03 15:59:51 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-08-03 15:57:59 ----D---- C:\Users\ASUS\AppData\Roaming\DAEMON Tools Lite
2011-08-03 15:57:59 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-08-03 15:56:20 ----D---- C:\Users\ASUS\AppData\Roaming\WinRAR
2011-08-03 15:55:52 ----D---- C:\Program Files (x86)\WinRAR
2011-08-03 13:52:31 ----D---- C:\Windows\pss
2011-08-03 11:46:48 ----D---- C:\ProgramData\VirtualizedApplications
2011-08-03 09:36:29 ----D---- C:\Users\ASUS\AppData\Roaming\SoftGrid Client
2011-08-03 09:35:35 ----D---- C:\Program Files\Microsoft Office
2011-08-03 09:35:34 ----D---- C:\Program Files (x86)\Microsoft Application Virtualization Client
2011-08-03 09:35:21 ----D---- C:\Users\ASUS\AppData\Roaming\TP
2011-08-02 22:50:09 ----D---- C:\Program Files (x86)\NetBeans 7.0
2011-08-02 22:13:50 ----D---- C:\Users\ASUS\AppData\Roaming\FLEXnet
2011-08-02 22:13:48 ----D---- C:\Users\ASUS\AppData\Roaming\Nuance
2011-08-02 22:13:40 ----D---- C:\Users\ASUS\AppData\Roaming\Zeon
2011-08-02 19:06:24 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-08-02 19:06:24 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-08-02 19:06:24 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-08-02 19:06:24 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-08-02 19:06:23 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-08-02 19:06:23 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-08-02 19:06:23 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-08-02 19:06:23 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-08-02 19:06:22 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-08-02 19:06:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-08-02 19:06:22 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-08-02 19:06:22 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-08-02 19:06:21 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-08-02 19:06:21 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-08-02 19:06:20 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-08-02 19:06:20 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-08-02 19:06:20 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-08-02 19:06:20 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-08-02 19:06:19 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-08-02 19:06:19 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-08-02 19:06:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-08-02 19:06:19 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-08-02 19:06:19 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-08-02 19:06:19 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-08-02 19:06:18 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-08-02 19:06:18 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-08-02 19:06:17 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-08-02 19:06:17 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-08-02 19:06:16 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-08-02 19:06:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-08-02 19:06:16 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-08-02 19:06:16 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-08-02 19:06:15 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-08-02 19:06:15 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-08-02 19:06:15 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-08-02 19:06:15 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-08-02 19:06:14 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-08-02 19:06:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-08-02 19:06:14 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-08-02 19:06:14 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-08-02 19:06:13 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-08-02 19:06:13 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-08-02 19:06:13 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-08-02 19:06:13 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-08-02 19:06:13 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-08-02 19:06:13 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-08-02 19:06:12 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-08-02 19:06:12 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-08-02 19:06:12 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-08-02 19:06:12 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-08-02 19:06:11 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-08-02 19:06:11 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-08-02 19:06:11 ----A---- C:\Windows\system32\xinput1_3.dll
2011-08-02 19:06:11 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-08-02 19:06:10 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-08-02 19:06:10 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-08-02 19:06:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-08-02 19:06:10 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-08-02 19:06:10 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-08-02 19:06:10 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-08-02 19:06:09 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-08-02 19:06:09 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-08-02 19:06:08 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-08-02 19:06:08 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-08-02 19:06:07 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-08-02 19:06:07 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-08-02 19:06:07 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-08-02 19:06:07 ----A---- C:\Windows\system32\d3dx10.dll
2011-08-02 19:06:05 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-08-02 19:06:05 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-08-02 19:06:05 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-08-02 19:06:05 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-08-02 19:06:04 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-08-02 19:06:04 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-08-02 19:06:04 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-08-02 19:06:04 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-08-02 19:06:03 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-08-02 19:06:03 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-08-02 19:06:03 ----A---- C:\Windows\system32\xinput1_2.dll
2011-08-02 19:06:03 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-08-02 19:06:02 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-08-02 19:06:02 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-08-02 19:06:02 ----A---- C:\Windows\system32\xinput1_1.dll
2011-08-02 19:06:02 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-08-02 19:05:57 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-08-02 19:05:57 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-08-02 19:05:55 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-08-02 19:05:55 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-08-02 19:05:55 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-08-02 19:05:55 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-08-02 19:05:55 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-08-02 19:05:55 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-08-02 19:05:54 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-08-02 19:05:54 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-08-02 19:05:54 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-08-02 19:05:54 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-08-02 19:05:53 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-08-02 19:05:53 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-08-02 19:05:52 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-08-02 19:05:51 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-08-02 19:05:51 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-08-02 19:00:54 ----D---- C:\Program Files (x86)\Zrychleni Pocitace
2011-08-02 18:39:36 ----RA---- C:\Windows\SYSWOW64\vp6vfw.dll
2011-08-01 21:23:24 ----D---- C:\Users\ASUS\AppData\Roaming\.minecraft
2011-08-01 20:57:41 ----D---- C:\Program Files (x86)\PokerStars
======List of files/folders modified in the last 1 month======
2011-08-27 10:54:48 ----D---- C:\Windows\Temp
2011-08-27 10:52:21 ----D---- C:\Windows\system32\Tasks
2011-08-27 10:48:12 ----D---- C:\ProgramData\PMB Files
2011-08-26 23:03:12 ----D---- C:\Windows\system32\config
2011-08-26 19:48:56 ----D---- C:\Windows\Microsoft.NET
2011-08-26 08:55:31 ----D---- C:\Windows
2011-08-24 21:13:39 ----D---- C:\Windows\winsxs
2011-08-24 21:13:35 ----D---- C:\Windows\SYSWOW64\en-US
2011-08-24 21:13:35 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-08-24 21:13:35 ----D---- C:\Windows\SysWOW64
2011-08-24 21:13:35 ----D---- C:\Windows\system32\en-US
2011-08-24 21:13:35 ----D---- C:\Windows\system32\cs-CZ
2011-08-24 21:13:35 ----D---- C:\Windows\System32
2011-08-24 19:04:19 ----D---- C:\Windows\system32\catroot
2011-08-24 19:04:18 ----D---- C:\Windows\system32\catroot2
2011-08-20 18:26:36 ----RD---- C:\Program Files (x86)
2011-08-20 17:24:26 ----D---- C:\Windows\system32\drivers
2011-08-20 17:20:06 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-08-20 17:19:07 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-08-20 17:12:54 ----SHD---- C:\Windows\Installer
2011-08-20 17:12:54 ----SHD---- C:\Config.Msi
2011-08-20 17:12:37 ----RD---- C:\Program Files
2011-08-20 17:12:37 ----HD---- C:\ProgramData
2011-08-20 17:03:19 ----D---- C:\Windows\SoftwareDistribution
2011-08-20 16:51:47 ----RSD---- C:\Windows\Fonts
2011-08-20 16:51:47 ----A---- C:\Windows\win.ini
2011-08-20 14:59:57 ----D---- C:\Windows\system32\NDF
2011-08-19 13:28:59 ----D---- C:\Windows\system32\drivers\UMDF
2011-08-17 13:28:11 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-08-16 12:01:22 ----DC---- C:\Windows\system32\DRVSTORE
2011-08-16 12:00:40 ----D---- C:\Program Files (x86)\Internet Explorer
2011-08-16 12:00:10 ----D---- C:\Windows\system32\DriverStore
2011-08-16 12:00:09 ----D---- C:\Windows\inf
2011-08-16 12:00:05 ----D---- C:\Program Files\Common Files
2011-08-16 11:59:45 ----D---- C:\Program Files (x86)\Common Files
2011-08-13 12:11:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-12 21:51:12 ----RSD---- C:\Windows\assembly
2011-08-12 09:17:08 ----D---- C:\Windows\SYSWOW64\migration
2011-08-12 09:17:08 ----D---- C:\Windows\system32\migration
2011-08-12 09:17:08 ----D---- C:\Windows\AppPatch
2011-08-12 09:17:07 ----D---- C:\Program Files\Internet Explorer
2011-08-12 09:16:08 ----D---- C:\Windows\Logs
2011-08-12 09:16:08 ----D---- C:\Windows\debug
2011-08-12 09:02:57 ----A---- C:\Windows\system32\MRT.exe
2011-08-12 08:50:46 ----D---- C:\ProgramData\Partner
2011-08-09 15:08:51 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-09 12:22:42 ----D---- C:\Windows\rescache
2011-08-09 12:21:34 ----D---- C:\Program Files\Windows Sidebar
2011-08-09 12:21:34 ----D---- C:\Program Files\Windows Media Player
2011-08-09 12:21:34 ----D---- C:\Program Files\Windows Mail
2011-08-09 12:21:34 ----D---- C:\Program Files\Windows Journal
2011-08-09 12:21:34 ----D---- C:\Program Files\Common Files\System
2011-08-09 12:21:33 ----D---- C:\Windows\SYSWOW64\sr-Latn-CS
2011-08-09 12:21:33 ----D---- C:\Windows\servicing
2011-08-09 12:21:33 ----D---- C:\Windows\ehome
2011-08-09 12:21:33 ----D---- C:\Program Files\Windows Defender
2011-08-09 12:21:33 ----D---- C:\Program Files (x86)\Windows Media Player
2011-08-09 12:21:33 ----D---- C:\Program Files (x86)\Windows Defender
2011-08-09 12:21:26 ----D---- C:\Windows\sr-Latn-CS
2011-08-09 12:21:25 ----D---- C:\Windows\system32\sr-Latn-CS
2011-08-09 12:21:25 ----D---- C:\Windows\system32\migwiz
2011-08-09 12:19:34 ----D---- C:\Program Files\Windows Photo Viewer
2011-08-09 12:19:34 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-08-09 12:19:34 ----D---- C:\Program Files (x86)\Windows Mail
2011-08-09 12:19:33 ----D---- C:\Windows\SYSWOW64\sl-SI
2011-08-09 12:19:33 ----D---- C:\Windows\SYSWOW64\migwiz
2011-08-09 12:19:33 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-08-09 12:19:26 ----D---- C:\Windows\SYSWOW64\WCN
2011-08-09 12:19:26 ----D---- C:\Windows\system32\sysprep
2011-08-09 12:19:26 ----D---- C:\Windows\system32\sl-SI
2011-08-09 12:19:26 ----D---- C:\Windows\system32\oobe
2011-08-09 12:19:21 ----D---- C:\Windows\system32\WCN
2011-08-09 12:17:27 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-08-09 12:17:22 ----D---- C:\Windows\system32\sk-SK
2011-08-09 12:15:15 ----D---- C:\Windows\SYSWOW64\ro-RO
2011-08-09 12:15:10 ----D---- C:\Windows\system32\ro-RO
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\XPSViewer
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\winrm
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\slmgr
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\pl-PL
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\MUI
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\DriverStore
2011-08-09 12:12:08 ----D---- C:\Windows\SYSWOW64\Printing_Admin_Scripts
2011-08-09 12:12:08 ----D---- C:\Windows\IME
2011-08-09 12:12:07 ----D---- C:\Windows\system32\winrm
2011-08-09 12:12:07 ----D---- C:\Windows\system32\slmgr
2011-08-09 12:12:05 ----D---- C:\Windows\system32\MUI
2011-08-09 12:12:01 ----D---- C:\Windows\system32\pl-PL
2011-08-09 12:11:46 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2011-08-09 12:08:44 ----D---- C:\Windows\SYSWOW64\hu-HU
2011-08-09 12:08:44 ----D---- C:\Windows\SYSWOW64\Dism
2011-08-09 12:08:33 ----D---- C:\Windows\SYSWOW64\com
2011-08-09 12:08:32 ----D---- C:\Windows\system32\Boot
2011-08-09 12:08:31 ----D---- C:\Windows\system32\Dism
2011-08-09 12:08:27 ----D---- C:\Windows\system32\hu-HU
2011-08-09 12:08:14 ----D---- C:\Windows\system32\com
2011-08-09 12:05:53 ----D---- C:\Windows\SYSWOW64\lv-LV
2011-08-09 12:05:48 ----D---- C:\Windows\system32\lv-LV
2011-08-09 12:03:35 ----D---- C:\Windows\SYSWOW64\lt-LT
2011-08-09 12:03:32 ----D---- C:\Windows\system32\lt-LT
2011-08-09 12:01:21 ----D---- C:\Windows\SYSWOW64\hr-HR
2011-08-09 12:01:17 ----D---- C:\Windows\system32\hr-HR
2011-08-09 11:59:02 ----D---- C:\Windows\SYSWOW64\et-EE
2011-08-09 11:58:54 ----D---- C:\Windows\system32\et-EE
2011-08-09 11:56:27 ----D---- C:\Windows\SYSWOW64\bg-BG
2011-08-09 11:56:19 ----D---- C:\Windows\system32\bg-BG
2011-08-09 11:28:00 ----D---- C:\Windows\Prefetch
2011-08-03 16:20:31 ----SD---- C:\Users\ASUS\AppData\Roaming\Microsoft
2011-08-03 13:53:51 ----AD---- C:\ProgramData\Temp
2011-08-03 13:48:01 ----D---- C:\Program Files (x86)\Java
2011-08-03 11:14:03 ----D---- C:\totalcmd
2011-08-03 09:36:16 ----SD---- C:\ProgramData\Microsoft
2011-08-03 09:35:49 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-08-03 09:35:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-08-03 09:35:36 ----D---- C:\Program Files (x86)\Microsoft Office
2011-08-02 22:13:48 ----D---- C:\ProgramData\Nuance
2011-08-02 16:54:50 ----D---- C:\Windows\system32\wdi
2011-08-02 14:59:19 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-08-02 13:24:15 ----D---- C:\Program Files\Microsoft Security Client
2011-08-02 12:57:04 ----D---- C:\Program Files (x86)\Microsoft Security Client
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 lullaby;lullaby; C:\Windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-09-22 7883264]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-09-22 285696]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-03-02 1594368]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-04-08 124944]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-03 270912]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-09-08 129024]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-04-13 2345760]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2009-08-18 143472]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits); C:\Windows\system32\DRIVERS\JME.sys [2010-10-12 131552]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-09-24 116752]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 GPU-Z;GPU-Z; \??\C:\Users\ASUS\AppData\Local\Temp\GPU-Z.sys []
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2010-09-30 377264]
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-09-22 203264]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-05-25 37664]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2011-07-12 387944]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-07-24 75136]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-07-28 249136]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-22 2286976]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-07-19 934760]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-03-04 182768]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-07-21 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
když chci spustit v antiviru (MSE) kontrolu počítače, tak se mi zasekne asi po půl minutě u souboru powercfg.exe , poté už musím vypnout počítač natvrdo. Jinak bych řekl že počítač jede normálně. Přikládám log z RSIT.
Logfile of random's system information tool 1.09 (written by random/random)
Run by ASUS at 2011-08-27 10:54:59
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 81 GB (68%) free of 119 GB
Total RAM: 3838 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:55:03, on 27.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
C:\Program Files\trend micro\ASUS.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - Global Startup: FancyStart daemon.lnk = ?
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11073 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe" -switch-3be2f036c43042cdb03588591c9325c3
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\SysWOW64\svchost.exe -k Akamai
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
taskeng.exe {32A4BFB4-FB7B-4AC0-94EC-CD298997175E}
taskeng.exe {CEF538E9-B905-4687-AC62-0E2620536C77}
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe"
taskeng.exe {3DA75EC2-03AD-4491-B031-BAC2A541E8D3}
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
WLIDSvcM.exe 1780
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
ATKOSD.exe
WDC.exe
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Prefetch/ContentPrefetchPrerender1/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_enabled/SpdyImpact/npn_with_spdy/ --disable-client-side-phishing-detection --channel=4680.05759580.828958467 /prefetch:3
C:\Windows\system32\rundll32.exe "C:\PROGRA~2\Google\Chrome\APPLIC~1\130782~1.215\gcswf32.dll",BrokerMain browser=chrome
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Google\Chrome\Application\13.0.782.215\gcswf32.dll" --lang=cs --channel=4680.04E521C0.1741304682 --flash-broker=2692 /prefetch:4
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
taskhost.exe $(Arg0)
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\system32\sppsvc.exe
"C:\Users\ASUS\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-03-04 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2011-03-04 318960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-28 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-03-04 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2011-03-04 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2011-03-04 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar BHO - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-14 609544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-07-14 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-03-04 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-03-04 256112]
{8dcb7100-df86-4384-8842-8fa844297b3f} - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-14 609544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [2010-03-16 1754448]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-06-10 649608]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2011-07-22 3077528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2011-03-04 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-03 103720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-13 10144288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console 3]
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2010-09-24 1601536]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS Premium Sound.lnk]
C:\Windows\INSTAL~1\{E5CF6~1\NEBEA7~1.EXE [2011-03-04 156952]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"Nuance PDF Reader-reminder"=C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [2008-11-03 328992]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-11 439568]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-09-22 98304]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-10-08 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-07-19 421736]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.3.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-08-24 19:07:46 ----A---- C:\Windows\system32\tzres.dll
2011-08-24 19:07:45 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-08-20 18:26:36 ----D---- C:\Program Files (x86)\Registry Genius
2011-08-20 17:12:56 ----A---- C:\Windows\system32\aswBoot.exe
2011-08-20 17:12:37 ----D---- C:\ProgramData\AVAST Software
2011-08-20 17:12:37 ----D---- C:\Program Files\AVAST Software
2011-08-20 16:51:47 ----D---- C:\Users\ASUS\AppData\Roaming\ChessBase
2011-08-18 09:03:41 ----D---- C:\Program Files\trend micro
2011-08-18 09:03:40 ----D---- C:\rsit
2011-08-16 12:01:55 ----D---- C:\Users\ASUS\AppData\Roaming\Apple Computer
2011-08-16 12:01:22 ----A---- C:\Windows\SYSWOW64\GEARAspi.dll
2011-08-16 12:01:22 ----A---- C:\Windows\system32\GEARAspi64.dll
2011-08-16 12:01:22 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2011-08-16 12:00:56 ----D---- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-08-16 12:00:56 ----D---- C:\Program Files\iTunes
2011-08-16 12:00:56 ----D---- C:\Program Files\iPod
2011-08-16 12:00:56 ----D---- C:\Program Files (x86)\iTunes
2011-08-16 12:00:23 ----D---- C:\ProgramData\Apple Computer
2011-08-16 12:00:23 ----D---- C:\Program Files (x86)\QuickTime
2011-08-16 12:00:13 ----D---- C:\Program Files (x86)\Apple Software Update
2011-08-16 12:00:05 ----D---- C:\Program Files\Common Files\Apple
2011-08-16 11:59:52 ----D---- C:\Program Files\Bonjour
2011-08-16 11:59:52 ----D---- C:\Program Files (x86)\Bonjour
2011-08-16 11:59:45 ----D---- C:\ProgramData\Apple
2011-08-12 08:55:37 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-12 08:55:36 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-08-12 08:55:35 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-08-12 08:55:35 ----A---- C:\Windows\system32\iertutil.dll
2011-08-12 08:55:34 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-08-12 08:55:34 ----A---- C:\Windows\system32\ieui.dll
2011-08-12 08:55:33 ----A---- C:\Windows\SYSWOW64\url.dll
2011-08-12 08:55:33 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-08-12 08:55:33 ----A---- C:\Windows\system32\url.dll
2011-08-12 08:55:33 ----A---- C:\Windows\system32\jscript9.dll
2011-08-12 08:55:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-08-12 08:55:32 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-08-12 08:55:32 ----A---- C:\Windows\system32\urlmon.dll
2011-08-12 08:55:32 ----A---- C:\Windows\system32\jscript.dll
2011-08-12 08:55:31 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-08-12 08:55:31 ----A---- C:\Windows\system32\wininet.dll
2011-08-12 08:55:31 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-12 08:55:30 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-08-12 08:55:29 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-08-12 08:55:26 ----A---- C:\Windows\system32\mshtml.dll
2011-08-12 08:55:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-08-12 08:55:25 ----A---- C:\Windows\system32\ieframe.dll
2011-08-11 18:07:46 ----D---- C:\Riot Games
2011-08-11 15:09:24 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-08-11 15:09:24 ----A---- C:\Windows\system32\xmllite.dll
2011-08-11 15:09:23 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-11 15:09:23 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-11 15:09:22 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-08-11 15:09:22 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-08-11 15:09:22 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-08-11 15:09:22 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-11 15:09:22 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-11 15:09:21 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-08-11 15:09:21 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-08-11 15:09:17 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-11 15:09:08 ----A---- C:\Windows\system32\wow64.dll
2011-08-11 15:09:08 ----A---- C:\Windows\system32\winsrv.dll
2011-08-11 15:09:08 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-11 15:09:08 ----A---- C:\Windows\system32\kernel32.dll
2011-08-11 15:09:08 ----A---- C:\Windows\system32\conhost.exe
2011-08-11 15:09:07 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-08-11 15:09:07 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-08-11 15:09:07 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-08-11 15:09:07 ----A---- C:\Windows\system32\wow64win.dll
2011-08-11 15:09:07 ----A---- C:\Windows\system32\wow64cpu.dll
2011-08-11 15:09:07 ----A---- C:\Windows\system32\ntvdm64.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 15:09:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 15:09:06 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-08-11 15:09:06 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 15:09:05 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 15:09:04 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 15:09:03 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 15:09:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 15:09:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-08-11 15:09:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 15:09:01 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-11 15:09:01 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-08-11 15:09:00 ----A---- C:\Windows\SYSWOW64\user.exe
2011-08-11 15:08:58 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-11 15:08:54 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-08-11 15:08:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-11 15:08:52 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-08-03 16:20:30 ----D---- C:\Program Files (x86)\Microsoft WSE
2011-08-03 15:59:59 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-08-03 15:59:51 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-08-03 15:57:59 ----D---- C:\Users\ASUS\AppData\Roaming\DAEMON Tools Lite
2011-08-03 15:57:59 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-08-03 15:56:20 ----D---- C:\Users\ASUS\AppData\Roaming\WinRAR
2011-08-03 15:55:52 ----D---- C:\Program Files (x86)\WinRAR
2011-08-03 13:52:31 ----D---- C:\Windows\pss
2011-08-03 11:46:48 ----D---- C:\ProgramData\VirtualizedApplications
2011-08-03 09:36:29 ----D---- C:\Users\ASUS\AppData\Roaming\SoftGrid Client
2011-08-03 09:35:35 ----D---- C:\Program Files\Microsoft Office
2011-08-03 09:35:34 ----D---- C:\Program Files (x86)\Microsoft Application Virtualization Client
2011-08-03 09:35:21 ----D---- C:\Users\ASUS\AppData\Roaming\TP
2011-08-02 22:50:09 ----D---- C:\Program Files (x86)\NetBeans 7.0
2011-08-02 22:13:50 ----D---- C:\Users\ASUS\AppData\Roaming\FLEXnet
2011-08-02 22:13:48 ----D---- C:\Users\ASUS\AppData\Roaming\Nuance
2011-08-02 22:13:40 ----D---- C:\Users\ASUS\AppData\Roaming\Zeon
2011-08-02 19:06:24 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-08-02 19:06:24 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-08-02 19:06:24 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-08-02 19:06:24 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-08-02 19:06:23 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-08-02 19:06:23 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-08-02 19:06:23 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-08-02 19:06:23 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-08-02 19:06:22 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-08-02 19:06:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-08-02 19:06:22 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-08-02 19:06:22 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-08-02 19:06:21 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-08-02 19:06:21 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-08-02 19:06:20 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-08-02 19:06:20 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-08-02 19:06:20 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-08-02 19:06:20 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-08-02 19:06:19 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-08-02 19:06:19 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-08-02 19:06:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-08-02 19:06:19 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-08-02 19:06:19 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-08-02 19:06:19 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-08-02 19:06:18 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-08-02 19:06:18 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-08-02 19:06:17 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-08-02 19:06:17 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-08-02 19:06:16 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-08-02 19:06:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-08-02 19:06:16 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-08-02 19:06:16 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-08-02 19:06:15 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-08-02 19:06:15 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-08-02 19:06:15 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-08-02 19:06:15 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-08-02 19:06:14 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-08-02 19:06:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-08-02 19:06:14 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-08-02 19:06:14 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-08-02 19:06:13 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-08-02 19:06:13 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-08-02 19:06:13 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-08-02 19:06:13 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-08-02 19:06:13 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-08-02 19:06:13 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-08-02 19:06:12 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-08-02 19:06:12 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-08-02 19:06:12 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-08-02 19:06:12 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-08-02 19:06:11 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-08-02 19:06:11 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-08-02 19:06:11 ----A---- C:\Windows\system32\xinput1_3.dll
2011-08-02 19:06:11 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-08-02 19:06:10 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-08-02 19:06:10 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-08-02 19:06:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-08-02 19:06:10 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-08-02 19:06:10 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-08-02 19:06:10 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-08-02 19:06:09 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-08-02 19:06:09 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-08-02 19:06:08 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-08-02 19:06:08 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-08-02 19:06:07 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-08-02 19:06:07 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-08-02 19:06:07 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-08-02 19:06:07 ----A---- C:\Windows\system32\d3dx10.dll
2011-08-02 19:06:05 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-08-02 19:06:05 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-08-02 19:06:05 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-08-02 19:06:05 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-08-02 19:06:04 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-08-02 19:06:04 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-08-02 19:06:04 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-08-02 19:06:04 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-08-02 19:06:03 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-08-02 19:06:03 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-08-02 19:06:03 ----A---- C:\Windows\system32\xinput1_2.dll
2011-08-02 19:06:03 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-08-02 19:06:02 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-08-02 19:06:02 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-08-02 19:06:02 ----A---- C:\Windows\system32\xinput1_1.dll
2011-08-02 19:06:02 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-08-02 19:05:57 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-08-02 19:05:57 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-08-02 19:05:55 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-08-02 19:05:55 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-08-02 19:05:55 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-08-02 19:05:55 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-08-02 19:05:55 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-08-02 19:05:55 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-08-02 19:05:54 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-08-02 19:05:54 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-08-02 19:05:54 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-08-02 19:05:54 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-08-02 19:05:53 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-08-02 19:05:53 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-08-02 19:05:52 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-08-02 19:05:51 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-08-02 19:05:51 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-08-02 19:00:54 ----D---- C:\Program Files (x86)\Zrychleni Pocitace
2011-08-02 18:39:36 ----RA---- C:\Windows\SYSWOW64\vp6vfw.dll
2011-08-01 21:23:24 ----D---- C:\Users\ASUS\AppData\Roaming\.minecraft
2011-08-01 20:57:41 ----D---- C:\Program Files (x86)\PokerStars
======List of files/folders modified in the last 1 month======
2011-08-27 10:54:48 ----D---- C:\Windows\Temp
2011-08-27 10:52:21 ----D---- C:\Windows\system32\Tasks
2011-08-27 10:48:12 ----D---- C:\ProgramData\PMB Files
2011-08-26 23:03:12 ----D---- C:\Windows\system32\config
2011-08-26 19:48:56 ----D---- C:\Windows\Microsoft.NET
2011-08-26 08:55:31 ----D---- C:\Windows
2011-08-24 21:13:39 ----D---- C:\Windows\winsxs
2011-08-24 21:13:35 ----D---- C:\Windows\SYSWOW64\en-US
2011-08-24 21:13:35 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-08-24 21:13:35 ----D---- C:\Windows\SysWOW64
2011-08-24 21:13:35 ----D---- C:\Windows\system32\en-US
2011-08-24 21:13:35 ----D---- C:\Windows\system32\cs-CZ
2011-08-24 21:13:35 ----D---- C:\Windows\System32
2011-08-24 19:04:19 ----D---- C:\Windows\system32\catroot
2011-08-24 19:04:18 ----D---- C:\Windows\system32\catroot2
2011-08-20 18:26:36 ----RD---- C:\Program Files (x86)
2011-08-20 17:24:26 ----D---- C:\Windows\system32\drivers
2011-08-20 17:20:06 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-08-20 17:19:07 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-08-20 17:12:54 ----SHD---- C:\Windows\Installer
2011-08-20 17:12:54 ----SHD---- C:\Config.Msi
2011-08-20 17:12:37 ----RD---- C:\Program Files
2011-08-20 17:12:37 ----HD---- C:\ProgramData
2011-08-20 17:03:19 ----D---- C:\Windows\SoftwareDistribution
2011-08-20 16:51:47 ----RSD---- C:\Windows\Fonts
2011-08-20 16:51:47 ----A---- C:\Windows\win.ini
2011-08-20 14:59:57 ----D---- C:\Windows\system32\NDF
2011-08-19 13:28:59 ----D---- C:\Windows\system32\drivers\UMDF
2011-08-17 13:28:11 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-08-16 12:01:22 ----DC---- C:\Windows\system32\DRVSTORE
2011-08-16 12:00:40 ----D---- C:\Program Files (x86)\Internet Explorer
2011-08-16 12:00:10 ----D---- C:\Windows\system32\DriverStore
2011-08-16 12:00:09 ----D---- C:\Windows\inf
2011-08-16 12:00:05 ----D---- C:\Program Files\Common Files
2011-08-16 11:59:45 ----D---- C:\Program Files (x86)\Common Files
2011-08-13 12:11:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-12 21:51:12 ----RSD---- C:\Windows\assembly
2011-08-12 09:17:08 ----D---- C:\Windows\SYSWOW64\migration
2011-08-12 09:17:08 ----D---- C:\Windows\system32\migration
2011-08-12 09:17:08 ----D---- C:\Windows\AppPatch
2011-08-12 09:17:07 ----D---- C:\Program Files\Internet Explorer
2011-08-12 09:16:08 ----D---- C:\Windows\Logs
2011-08-12 09:16:08 ----D---- C:\Windows\debug
2011-08-12 09:02:57 ----A---- C:\Windows\system32\MRT.exe
2011-08-12 08:50:46 ----D---- C:\ProgramData\Partner
2011-08-09 15:08:51 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-09 12:22:42 ----D---- C:\Windows\rescache
2011-08-09 12:21:34 ----D---- C:\Program Files\Windows Sidebar
2011-08-09 12:21:34 ----D---- C:\Program Files\Windows Media Player
2011-08-09 12:21:34 ----D---- C:\Program Files\Windows Mail
2011-08-09 12:21:34 ----D---- C:\Program Files\Windows Journal
2011-08-09 12:21:34 ----D---- C:\Program Files\Common Files\System
2011-08-09 12:21:33 ----D---- C:\Windows\SYSWOW64\sr-Latn-CS
2011-08-09 12:21:33 ----D---- C:\Windows\servicing
2011-08-09 12:21:33 ----D---- C:\Windows\ehome
2011-08-09 12:21:33 ----D---- C:\Program Files\Windows Defender
2011-08-09 12:21:33 ----D---- C:\Program Files (x86)\Windows Media Player
2011-08-09 12:21:33 ----D---- C:\Program Files (x86)\Windows Defender
2011-08-09 12:21:26 ----D---- C:\Windows\sr-Latn-CS
2011-08-09 12:21:25 ----D---- C:\Windows\system32\sr-Latn-CS
2011-08-09 12:21:25 ----D---- C:\Windows\system32\migwiz
2011-08-09 12:19:34 ----D---- C:\Program Files\Windows Photo Viewer
2011-08-09 12:19:34 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-08-09 12:19:34 ----D---- C:\Program Files (x86)\Windows Mail
2011-08-09 12:19:33 ----D---- C:\Windows\SYSWOW64\sl-SI
2011-08-09 12:19:33 ----D---- C:\Windows\SYSWOW64\migwiz
2011-08-09 12:19:33 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-08-09 12:19:26 ----D---- C:\Windows\SYSWOW64\WCN
2011-08-09 12:19:26 ----D---- C:\Windows\system32\sysprep
2011-08-09 12:19:26 ----D---- C:\Windows\system32\sl-SI
2011-08-09 12:19:26 ----D---- C:\Windows\system32\oobe
2011-08-09 12:19:21 ----D---- C:\Windows\system32\WCN
2011-08-09 12:17:27 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-08-09 12:17:22 ----D---- C:\Windows\system32\sk-SK
2011-08-09 12:15:15 ----D---- C:\Windows\SYSWOW64\ro-RO
2011-08-09 12:15:10 ----D---- C:\Windows\system32\ro-RO
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\XPSViewer
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\winrm
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\slmgr
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\pl-PL
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\MUI
2011-08-09 12:12:22 ----D---- C:\Windows\SYSWOW64\DriverStore
2011-08-09 12:12:08 ----D---- C:\Windows\SYSWOW64\Printing_Admin_Scripts
2011-08-09 12:12:08 ----D---- C:\Windows\IME
2011-08-09 12:12:07 ----D---- C:\Windows\system32\winrm
2011-08-09 12:12:07 ----D---- C:\Windows\system32\slmgr
2011-08-09 12:12:05 ----D---- C:\Windows\system32\MUI
2011-08-09 12:12:01 ----D---- C:\Windows\system32\pl-PL
2011-08-09 12:11:46 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2011-08-09 12:08:44 ----D---- C:\Windows\SYSWOW64\hu-HU
2011-08-09 12:08:44 ----D---- C:\Windows\SYSWOW64\Dism
2011-08-09 12:08:33 ----D---- C:\Windows\SYSWOW64\com
2011-08-09 12:08:32 ----D---- C:\Windows\system32\Boot
2011-08-09 12:08:31 ----D---- C:\Windows\system32\Dism
2011-08-09 12:08:27 ----D---- C:\Windows\system32\hu-HU
2011-08-09 12:08:14 ----D---- C:\Windows\system32\com
2011-08-09 12:05:53 ----D---- C:\Windows\SYSWOW64\lv-LV
2011-08-09 12:05:48 ----D---- C:\Windows\system32\lv-LV
2011-08-09 12:03:35 ----D---- C:\Windows\SYSWOW64\lt-LT
2011-08-09 12:03:32 ----D---- C:\Windows\system32\lt-LT
2011-08-09 12:01:21 ----D---- C:\Windows\SYSWOW64\hr-HR
2011-08-09 12:01:17 ----D---- C:\Windows\system32\hr-HR
2011-08-09 11:59:02 ----D---- C:\Windows\SYSWOW64\et-EE
2011-08-09 11:58:54 ----D---- C:\Windows\system32\et-EE
2011-08-09 11:56:27 ----D---- C:\Windows\SYSWOW64\bg-BG
2011-08-09 11:56:19 ----D---- C:\Windows\system32\bg-BG
2011-08-09 11:28:00 ----D---- C:\Windows\Prefetch
2011-08-03 16:20:31 ----SD---- C:\Users\ASUS\AppData\Roaming\Microsoft
2011-08-03 13:53:51 ----AD---- C:\ProgramData\Temp
2011-08-03 13:48:01 ----D---- C:\Program Files (x86)\Java
2011-08-03 11:14:03 ----D---- C:\totalcmd
2011-08-03 09:36:16 ----SD---- C:\ProgramData\Microsoft
2011-08-03 09:35:49 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-08-03 09:35:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-08-03 09:35:36 ----D---- C:\Program Files (x86)\Microsoft Office
2011-08-02 22:13:48 ----D---- C:\ProgramData\Nuance
2011-08-02 16:54:50 ----D---- C:\Windows\system32\wdi
2011-08-02 14:59:19 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-08-02 13:24:15 ----D---- C:\Program Files\Microsoft Security Client
2011-08-02 12:57:04 ----D---- C:\Program Files (x86)\Microsoft Security Client
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 lullaby;lullaby; C:\Windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-09-22 7883264]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-09-22 285696]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-03-02 1594368]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-04-08 124944]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-03 270912]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-09-08 129024]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-04-13 2345760]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2009-08-18 143472]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits); C:\Windows\system32\DRIVERS\JME.sys [2010-10-12 131552]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-09-24 116752]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 GPU-Z;GPU-Z; \??\C:\Users\ASUS\AppData\Local\Temp\GPU-Z.sys []
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2010-09-30 377264]
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-09-22 203264]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-05-25 37664]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2011-07-12 387944]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-07-24 75136]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-07-28 249136]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-22 2286976]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-07-19 934760]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-03-04 182768]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-07-21 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Re: Kontrola logu-test antiviru
Zdravím, tohle fixni v HJT :
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
HJT najdeš zde :
C:\Program Files\trend micro\ASUS.exe
Fix znamená že spustíš HJT
jako admin
v okně které se ti otevře klikneš na Do a system scan only
v dalším okně najdeš řádky které jsem ti vypsal,
vedle nich je čtvereček do kterého uděláš zatržítko,
pak klikneš na Fix checked které je vlevo dole,
program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.
Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :
Google Update Service (gupdate)
Služba Google Update (gupdatem)
Google Software Updater
klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Pak použij Mbam z mého podpisu a dej mi sem z něj log, předem nic nemazat !!!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
HJT najdeš zde :
C:\Program Files\trend micro\ASUS.exe
Fix znamená že spustíš HJT

v okně které se ti otevře klikneš na Do a system scan only
v dalším okně najdeš řádky které jsem ti vypsal,
vedle nich je čtvereček do kterého uděláš zatržítko,
pak klikneš na Fix checked které je vlevo dole,
program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.
Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :
Google Update Service (gupdate)
Služba Google Update (gupdatem)
Google Software Updater
klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Pak použij Mbam z mého podpisu a dej mi sem z něj log, předem nic nemazat !!!
Re: Kontrola logu-test antiviru
Malý problém ten HJT musím asi stáhnout protože ten v počítači nemám na té adrese C:/Program Files/trend micro/Asus.exe
Nebo je někde jinde?
Nebo je někde jinde?
Re: Kontrola logu-test antiviru
Tak ten HJT tam opravdu byl, jsem asi slepý. Vše jsem provedl až na MBAM u něhož se mi počítač zasekne i bez kontroly (jednou jsem ho už používal a hlásilo že databáze je zastaralá víc jak 51 dní) ...takže jsem ho musel odinstalovat v nouzovém režimu.
Takže bych řekl že všechny skeny počítače ho zamrazí.
Takže bych řekl že všechny skeny počítače ho zamrazí.
Re: Kontrola logu-test antiviru
Nyní použijeme větší kalibr tak že pozorně čti, protože tenhle softík netoleruje chyby.
Kdyby byl problém se spuštěním v Normálním proveď to v Nouzovém.
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Kdyby byl problém se spuštěním v Normálním proveď to v Nouzovém.
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Re: Kontrola logu-test antiviru
Provedl jsem, ale po dokončení Combofixu mi nejdou spustit aplikace všeho druhu ani internet ani textové soubory, atd.
Citace: Pokus použit neplatnou operaci na klíč registru, který je označen pro odstranění.
Log jsem přetáhnul přes flashku na jiný počítač
ComboFix 11-08-27.01 - ASUS 28.08.2011 9:51.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3838.2601 [GMT 2:00]
Spuštěný z: c:\users\ASUS\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
c:\programdata\FullRemove.exe
c:\windows\isRS-000.tmp
c:\windows\pl
c:\windows\pl\WLXPGSS.SCR.mui
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-28 )))))))))))))))))))))))))))))))
.
.
2011-08-28 08:03 . 2011-08-28 08:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-27 09:02 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{434A7ED5-CFA2-48E3-ADA6-DECE3B7951BB}\mpengine.dll
2011-08-24 17:07 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 17:07 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-20 16:26 . 2011-08-20 16:36 -------- d-----w- c:\program files (x86)\Registry Genius
2011-08-20 15:12 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-08-20 15:12 . 2011-08-20 15:24 -------- d-----w- c:\programdata\AVAST Software
2011-08-20 15:12 . 2011-08-20 15:12 -------- d-----w- c:\program files\AVAST Software
2011-08-20 14:51 . 2011-08-20 14:57 -------- d-----w- c:\users\ASUS\AppData\Roaming\ChessBase
2011-08-20 12:59 . 2011-08-20 12:59 -------- d-----w- c:\users\ASUS\AppData\Local\Diagnostics
2011-08-18 07:03 . 2011-08-27 17:45 -------- d-----w- c:\program files\trend micro
2011-08-18 07:03 . 2011-08-18 07:03 -------- d-----w- C:\rsit
2011-08-18 06:49 . 2011-08-18 06:49 0 ---ha-w- c:\users\ASUS\AppData\Local\BITD622.tmp
2011-08-16 10:01 . 2011-08-16 10:02 -------- d-----w- c:\users\ASUS\AppData\Roaming\Apple Computer
2011-08-16 10:01 . 2011-08-16 10:01 -------- d-----w- c:\users\ASUS\AppData\Local\Apple Computer
2011-08-16 10:01 . 2009-05-18 11:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-08-16 10:01 . 2008-04-17 10:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
2011-08-16 10:01 . 2008-04-17 10:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\program files\Bonjour
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\program files (x86)\Bonjour
2011-08-16 09:59 . 2011-08-16 10:00 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\programdata\Apple
2011-08-11 20:47 . 2011-07-21 13:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-08-11 20:47 . 2011-07-21 13:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC9EAC14-248E-4A65-A672-23683BF4F080}\gapaengine.dll
2011-08-11 16:07 . 2011-08-11 16:07 -------- d-----w- C:\Riot Games
2011-08-11 13:08 . 2011-06-21 06:34 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-11 13:08 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-08-11 13:08 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-11 13:08 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-08-09 12:50 . 2011-08-09 12:50 0 ---ha-w- c:\users\ASUS\AppData\Local\BITF353.tmp
2011-08-09 08:35 . 2011-08-28 08:04 -------- d-----w- c:\program files (x86)\Common Files\Akamai
2011-08-08 07:56 . 2011-08-08 07:57 -------- d-----w- c:\users\ASUS\.nbi
2011-08-03 14:20 . 2011-08-03 14:20 -------- d-----w- c:\program files (x86)\Microsoft WSE
2011-08-03 13:59 . 2011-08-03 13:59 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-03 13:59 . 2011-08-03 13:59 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-03 13:57 . 2011-08-05 07:11 -------- d-----w- c:\users\ASUS\AppData\Roaming\DAEMON Tools Lite
2011-08-03 13:57 . 2011-08-03 13:58 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-03 10:03 . 2011-08-26 20:57 -------- d-----w- c:\users\ASUS\riotsGamesLogs
2011-08-03 09:46 . 2011-08-09 06:56 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-03 07:36 . 2011-08-11 20:47 -------- d-----w- c:\users\ASUS\AppData\Roaming\SoftGrid Client
2011-08-03 07:36 . 2011-08-03 07:36 -------- d-----w- c:\users\ASUS\AppData\Local\SoftGrid Client
2011-08-03 07:35 . 2011-08-03 07:35 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-08-03 07:35 . 2011-08-03 07:36 -------- d-----w- c:\users\ASUS\AppData\Roaming\TP
2011-08-02 20:50 . 2011-08-02 20:53 -------- d-----w- c:\program files (x86)\NetBeans 7.0
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\FLEXnet
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\Nuance
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\Zeon
2011-08-02 17:00 . 2011-08-02 17:08 -------- d-----w- c:\program files (x86)\Zrychleni Pocitace
2011-08-02 16:39 . 2004-08-18 08:34 442368 ----a-r- c:\windows\SysWow64\vp6vfw.dll
2011-08-02 10:56 . 2011-07-12 19:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-08-01 19:23 . 2011-08-01 19:23 -------- d-----w- c:\users\ASUS\AppData\Roaming\.minecraft
2011-08-01 18:58 . 2011-08-01 18:58 -------- d-----w- c:\users\ASUS\AppData\Local\PokerStars
2011-08-01 18:57 . 2011-08-01 18:58 -------- d-----w- c:\program files (x86)\PokerStars
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 04:10 . 2011-07-23 14:55 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-02 12:59 . 2011-07-24 13:53 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-08-02 12:59 . 2011-07-24 07:54 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-24 07:54 . 2011-07-24 07:54 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-07-22 07:59 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-07-22 07:59 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-21 11:12 . 2011-07-21 11:12 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-07-21 11:12 . 2011-07-21 11:12 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-07-21 11:12 . 2011-07-21 11:12 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-07-21 11:12 . 2011-07-21 11:12 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-07-21 11:12 . 2011-07-21 11:12 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-07-21 11:12 . 2011-07-21 11:12 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-07-21 11:12 . 2011-07-21 11:12 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-07-21 11:12 . 2011-07-21 11:12 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-07-21 11:12 . 2011-07-21 11:12 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-07-21 11:12 . 2011-07-21 11:12 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-07-21 11:12 . 2011-07-21 11:12 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-07-21 11:12 . 2011-07-21 11:12 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-07-21 11:12 . 2011-07-21 11:12 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-07-21 11:12 . 2011-07-21 11:12 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-07-21 11:12 . 2011-07-21 11:12 222208 ----a-w- c:\windows\system32\msls31.dll
2011-07-21 11:12 . 2011-07-21 11:12 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-07-21 11:12 . 2011-07-21 11:12 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-07-21 11:12 . 2011-07-21 11:12 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-07-21 11:12 . 2011-07-21 11:12 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-07-21 11:12 . 2011-07-21 11:12 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-07-21 11:12 . 2011-07-21 11:12 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-07-21 11:12 . 2011-07-21 11:12 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-07-21 11:12 . 2011-07-21 11:12 12288 ----a-w- c:\windows\system32\mshta.exe
2011-07-21 11:12 . 2011-07-21 11:12 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-07-21 11:12 . 2011-07-21 11:12 114176 ----a-w- c:\windows\system32\admparse.dll
2011-07-21 11:12 . 2011-07-21 11:12 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-07-21 11:12 . 2011-07-21 11:12 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-07-21 11:12 . 2011-07-21 11:12 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-07-21 11:12 . 2011-07-21 11:12 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-07-21 11:12 . 2011-07-21 11:12 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-07-21 11:12 . 2011-07-21 11:12 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-07-21 11:12 . 2011-07-21 11:12 448512 ----a-w- c:\windows\system32\html.iec
2011-07-21 11:12 . 2011-07-21 11:12 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-07-21 11:12 . 2011-07-21 11:12 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-07-21 11:12 . 2011-07-21 11:12 160256 ----a-w- c:\windows\system32\wextract.exe
2011-07-21 11:12 . 2011-07-21 11:12 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-07-21 08:21 . 2010-06-24 19:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-16 04:26 . 2011-08-11 13:09 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-06 17:52 . 2011-07-25 12:02 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-11 03:07 . 2011-07-21 08:46 3137536 ----a-w- c:\windows\system32\win32k.sys
2009-04-08 18:31 . 2009-04-08 18:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 05:45 . 2008-08-12 05:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-3-4 548528]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-3-4 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
R3 GPU-Z;GPU-Z;c:\users\ASUS\AppData\Local\Temp\GPU-Z.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 20:24]
.
2011-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 20:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.254
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_2da1ebd.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_2da1ebd.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\SmartLogon\smartlogon.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeck.exe
.
**************************************************************************
.
Celkový čas: 2011-08-28 10:10:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-28 08:10
.
Před spuštěním: Volných bajtů: 85 425 111 040
Po spuštění: Volných bajtů: 85 262 049 280
.
- - End Of File - - 52958C0C2ED1BE3086CC282A48553372
Citace: Pokus použit neplatnou operaci na klíč registru, který je označen pro odstranění.
Log jsem přetáhnul přes flashku na jiný počítač
ComboFix 11-08-27.01 - ASUS 28.08.2011 9:51.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3838.2601 [GMT 2:00]
Spuštěný z: c:\users\ASUS\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
c:\programdata\FullRemove.exe
c:\windows\isRS-000.tmp
c:\windows\pl
c:\windows\pl\WLXPGSS.SCR.mui
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-28 )))))))))))))))))))))))))))))))
.
.
2011-08-28 08:03 . 2011-08-28 08:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-27 09:02 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{434A7ED5-CFA2-48E3-ADA6-DECE3B7951BB}\mpengine.dll
2011-08-24 17:07 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 17:07 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-20 16:26 . 2011-08-20 16:36 -------- d-----w- c:\program files (x86)\Registry Genius
2011-08-20 15:12 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-08-20 15:12 . 2011-08-20 15:24 -------- d-----w- c:\programdata\AVAST Software
2011-08-20 15:12 . 2011-08-20 15:12 -------- d-----w- c:\program files\AVAST Software
2011-08-20 14:51 . 2011-08-20 14:57 -------- d-----w- c:\users\ASUS\AppData\Roaming\ChessBase
2011-08-20 12:59 . 2011-08-20 12:59 -------- d-----w- c:\users\ASUS\AppData\Local\Diagnostics
2011-08-18 07:03 . 2011-08-27 17:45 -------- d-----w- c:\program files\trend micro
2011-08-18 07:03 . 2011-08-18 07:03 -------- d-----w- C:\rsit
2011-08-18 06:49 . 2011-08-18 06:49 0 ---ha-w- c:\users\ASUS\AppData\Local\BITD622.tmp
2011-08-16 10:01 . 2011-08-16 10:02 -------- d-----w- c:\users\ASUS\AppData\Roaming\Apple Computer
2011-08-16 10:01 . 2011-08-16 10:01 -------- d-----w- c:\users\ASUS\AppData\Local\Apple Computer
2011-08-16 10:01 . 2009-05-18 11:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-08-16 10:01 . 2008-04-17 10:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
2011-08-16 10:01 . 2008-04-17 10:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\program files\Bonjour
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\program files (x86)\Bonjour
2011-08-16 09:59 . 2011-08-16 10:00 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\programdata\Apple
2011-08-11 20:47 . 2011-07-21 13:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-08-11 20:47 . 2011-07-21 13:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC9EAC14-248E-4A65-A672-23683BF4F080}\gapaengine.dll
2011-08-11 16:07 . 2011-08-11 16:07 -------- d-----w- C:\Riot Games
2011-08-11 13:08 . 2011-06-21 06:34 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-11 13:08 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-08-11 13:08 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-11 13:08 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-08-09 12:50 . 2011-08-09 12:50 0 ---ha-w- c:\users\ASUS\AppData\Local\BITF353.tmp
2011-08-09 08:35 . 2011-08-28 08:04 -------- d-----w- c:\program files (x86)\Common Files\Akamai
2011-08-08 07:56 . 2011-08-08 07:57 -------- d-----w- c:\users\ASUS\.nbi
2011-08-03 14:20 . 2011-08-03 14:20 -------- d-----w- c:\program files (x86)\Microsoft WSE
2011-08-03 13:59 . 2011-08-03 13:59 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-03 13:59 . 2011-08-03 13:59 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-03 13:57 . 2011-08-05 07:11 -------- d-----w- c:\users\ASUS\AppData\Roaming\DAEMON Tools Lite
2011-08-03 13:57 . 2011-08-03 13:58 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-03 10:03 . 2011-08-26 20:57 -------- d-----w- c:\users\ASUS\riotsGamesLogs
2011-08-03 09:46 . 2011-08-09 06:56 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-03 07:36 . 2011-08-11 20:47 -------- d-----w- c:\users\ASUS\AppData\Roaming\SoftGrid Client
2011-08-03 07:36 . 2011-08-03 07:36 -------- d-----w- c:\users\ASUS\AppData\Local\SoftGrid Client
2011-08-03 07:35 . 2011-08-03 07:35 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-08-03 07:35 . 2011-08-03 07:36 -------- d-----w- c:\users\ASUS\AppData\Roaming\TP
2011-08-02 20:50 . 2011-08-02 20:53 -------- d-----w- c:\program files (x86)\NetBeans 7.0
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\FLEXnet
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\Nuance
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\Zeon
2011-08-02 17:00 . 2011-08-02 17:08 -------- d-----w- c:\program files (x86)\Zrychleni Pocitace
2011-08-02 16:39 . 2004-08-18 08:34 442368 ----a-r- c:\windows\SysWow64\vp6vfw.dll
2011-08-02 10:56 . 2011-07-12 19:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-08-01 19:23 . 2011-08-01 19:23 -------- d-----w- c:\users\ASUS\AppData\Roaming\.minecraft
2011-08-01 18:58 . 2011-08-01 18:58 -------- d-----w- c:\users\ASUS\AppData\Local\PokerStars
2011-08-01 18:57 . 2011-08-01 18:58 -------- d-----w- c:\program files (x86)\PokerStars
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 04:10 . 2011-07-23 14:55 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-02 12:59 . 2011-07-24 13:53 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-08-02 12:59 . 2011-07-24 07:54 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-24 07:54 . 2011-07-24 07:54 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-07-22 07:59 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-07-22 07:59 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-21 11:12 . 2011-07-21 11:12 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-07-21 11:12 . 2011-07-21 11:12 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-07-21 11:12 . 2011-07-21 11:12 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-07-21 11:12 . 2011-07-21 11:12 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-07-21 11:12 . 2011-07-21 11:12 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-07-21 11:12 . 2011-07-21 11:12 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-07-21 11:12 . 2011-07-21 11:12 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-07-21 11:12 . 2011-07-21 11:12 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-07-21 11:12 . 2011-07-21 11:12 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-07-21 11:12 . 2011-07-21 11:12 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-07-21 11:12 . 2011-07-21 11:12 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-07-21 11:12 . 2011-07-21 11:12 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-07-21 11:12 . 2011-07-21 11:12 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-07-21 11:12 . 2011-07-21 11:12 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-07-21 11:12 . 2011-07-21 11:12 222208 ----a-w- c:\windows\system32\msls31.dll
2011-07-21 11:12 . 2011-07-21 11:12 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-07-21 11:12 . 2011-07-21 11:12 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-07-21 11:12 . 2011-07-21 11:12 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-07-21 11:12 . 2011-07-21 11:12 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-07-21 11:12 . 2011-07-21 11:12 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-07-21 11:12 . 2011-07-21 11:12 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-07-21 11:12 . 2011-07-21 11:12 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-07-21 11:12 . 2011-07-21 11:12 12288 ----a-w- c:\windows\system32\mshta.exe
2011-07-21 11:12 . 2011-07-21 11:12 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-07-21 11:12 . 2011-07-21 11:12 114176 ----a-w- c:\windows\system32\admparse.dll
2011-07-21 11:12 . 2011-07-21 11:12 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-07-21 11:12 . 2011-07-21 11:12 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-07-21 11:12 . 2011-07-21 11:12 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-07-21 11:12 . 2011-07-21 11:12 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-07-21 11:12 . 2011-07-21 11:12 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-07-21 11:12 . 2011-07-21 11:12 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-07-21 11:12 . 2011-07-21 11:12 448512 ----a-w- c:\windows\system32\html.iec
2011-07-21 11:12 . 2011-07-21 11:12 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-07-21 11:12 . 2011-07-21 11:12 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-07-21 11:12 . 2011-07-21 11:12 160256 ----a-w- c:\windows\system32\wextract.exe
2011-07-21 11:12 . 2011-07-21 11:12 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-07-21 08:21 . 2010-06-24 19:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-16 04:26 . 2011-08-11 13:09 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-06 17:52 . 2011-07-25 12:02 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-11 03:07 . 2011-07-21 08:46 3137536 ----a-w- c:\windows\system32\win32k.sys
2009-04-08 18:31 . 2009-04-08 18:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 05:45 . 2008-08-12 05:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-3-4 548528]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-3-4 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
R3 GPU-Z;GPU-Z;c:\users\ASUS\AppData\Local\Temp\GPU-Z.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 20:24]
.
2011-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 20:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.254
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_2da1ebd.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_2da1ebd.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\SmartLogon\smartlogon.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeck.exe
.
**************************************************************************
.
Celkový čas: 2011-08-28 10:10:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-28 08:10
.
Před spuštěním: Volných bajtů: 85 425 111 040
Po spuštění: Volných bajtů: 85 262 049 280
.
- - End Of File - - 52958C0C2ED1BE3086CC282A48553372
Re: Kontrola logu-test antiviru
Po restartu aplikace fungují, u antiviru stále stejný problém.
Re: Kontrola logu-test antiviru
Antivir pořešíme až budou pryč všichni šmejdi.
Pokud jsi tak ještě neučinil, přesuň Combofix na plochu
otevři si Poznámkový blok
do něj zkopíruj skript z následujícího okna:
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,
po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,
v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
Pokud jsi tak ještě neučinil, přesuň Combofix na plochu
otevři si Poznámkový blok
do něj zkopíruj skript z následujícího okna:
Kód: Vybrat vše
File::
c:\users\ASUS\AppData\Local\BITD622.tmp
c:\users\ASUS\AppData\Local\BITF353.tmp
Folder::
c:\users\ASUS\AppData\Local\BITD622.tmp
c:\users\ASUS\AppData\Local\BITF353.tmp
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,
v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
Re: Kontrola logu-test antiviru
Provedl jsem, přikládám log
ComboFix 11-08-27.01 - ASUS 29.08.2011 8:38.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3838.2544 [GMT 2:00]
Spuštěný z: c:\users\ASUS\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\ASUS\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\users\ASUS\AppData\Local\BITD622.tmp"
"c:\users\ASUS\AppData\Local\BITF353.tmp"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\ASUS\AppData\Local\BITD622.tmp
c:\users\ASUS\AppData\Local\BITF353.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 06:45 . 2011-08-29 06:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-28 09:06 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3D5E7F9E-2AD1-4F43-B3A3-072B59E86DF3}\mpengine.dll
2011-08-24 17:07 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 17:07 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-20 16:26 . 2011-08-20 16:36 -------- d-----w- c:\program files (x86)\Registry Genius
2011-08-20 15:12 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-08-20 15:12 . 2011-08-20 15:24 -------- d-----w- c:\programdata\AVAST Software
2011-08-20 15:12 . 2011-08-20 15:12 -------- d-----w- c:\program files\AVAST Software
2011-08-20 14:51 . 2011-08-20 14:57 -------- d-----w- c:\users\ASUS\AppData\Roaming\ChessBase
2011-08-20 12:59 . 2011-08-20 12:59 -------- d-----w- c:\users\ASUS\AppData\Local\Diagnostics
2011-08-18 07:03 . 2011-08-27 17:45 -------- d-----w- c:\program files\trend micro
2011-08-18 07:03 . 2011-08-18 07:03 -------- d-----w- C:\rsit
2011-08-16 10:01 . 2011-08-16 10:02 -------- d-----w- c:\users\ASUS\AppData\Roaming\Apple Computer
2011-08-16 10:01 . 2011-08-16 10:01 -------- d-----w- c:\users\ASUS\AppData\Local\Apple Computer
2011-08-16 10:01 . 2009-05-18 11:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-08-16 10:01 . 2008-04-17 10:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
2011-08-16 10:01 . 2008-04-17 10:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\program files\Bonjour
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\program files (x86)\Bonjour
2011-08-16 09:59 . 2011-08-16 10:00 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\programdata\Apple
2011-08-11 20:47 . 2011-07-21 13:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-08-11 20:47 . 2011-07-21 13:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC9EAC14-248E-4A65-A672-23683BF4F080}\gapaengine.dll
2011-08-11 13:08 . 2011-06-21 06:34 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-11 13:08 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-08-11 13:08 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-11 13:08 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-08-09 08:35 . 2011-08-29 06:46 -------- d-----w- c:\program files (x86)\Common Files\Akamai
2011-08-08 07:56 . 2011-08-08 07:57 -------- d-----w- c:\users\ASUS\.nbi
2011-08-03 14:20 . 2011-08-03 14:20 -------- d-----w- c:\program files (x86)\Microsoft WSE
2011-08-03 13:59 . 2011-08-03 13:59 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-03 13:59 . 2011-08-03 13:59 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-03 13:57 . 2011-08-05 07:11 -------- d-----w- c:\users\ASUS\AppData\Roaming\DAEMON Tools Lite
2011-08-03 13:57 . 2011-08-03 13:58 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-03 10:03 . 2011-08-28 15:53 -------- d-----w- c:\users\ASUS\riotsGamesLogs
2011-08-03 09:46 . 2011-08-09 06:56 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-03 07:36 . 2011-08-11 20:47 -------- d-----w- c:\users\ASUS\AppData\Roaming\SoftGrid Client
2011-08-03 07:36 . 2011-08-03 07:36 -------- d-----w- c:\users\ASUS\AppData\Local\SoftGrid Client
2011-08-03 07:35 . 2011-08-03 07:35 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-08-03 07:35 . 2011-08-03 07:36 -------- d-----w- c:\users\ASUS\AppData\Roaming\TP
2011-08-02 20:50 . 2011-08-02 20:53 -------- d-----w- c:\program files (x86)\NetBeans 7.0
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\FLEXnet
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\Nuance
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\Zeon
2011-08-02 17:00 . 2011-08-02 17:08 -------- d-----w- c:\program files (x86)\Zrychleni Pocitace
2011-08-02 16:39 . 2004-08-18 08:34 442368 ----a-r- c:\windows\SysWow64\vp6vfw.dll
2011-08-02 10:56 . 2011-07-12 19:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-08-01 19:23 . 2011-08-01 19:23 -------- d-----w- c:\users\ASUS\AppData\Roaming\.minecraft
2011-08-01 18:58 . 2011-08-01 18:58 -------- d-----w- c:\users\ASUS\AppData\Local\PokerStars
2011-08-01 18:57 . 2011-08-01 18:58 -------- d-----w- c:\program files (x86)\PokerStars
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 04:10 . 2011-07-23 14:55 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-02 12:59 . 2011-07-24 13:53 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-08-02 12:59 . 2011-07-24 07:54 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-24 07:54 . 2011-07-24 07:54 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-07-22 07:59 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-07-22 07:59 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-21 11:12 . 2011-07-21 11:12 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-07-21 11:12 . 2011-07-21 11:12 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-07-21 11:12 . 2011-07-21 11:12 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-07-21 11:12 . 2011-07-21 11:12 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-07-21 11:12 . 2011-07-21 11:12 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-07-21 11:12 . 2011-07-21 11:12 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-07-21 11:12 . 2011-07-21 11:12 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-07-21 11:12 . 2011-07-21 11:12 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-07-21 11:12 . 2011-07-21 11:12 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-07-21 11:12 . 2011-07-21 11:12 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-07-21 11:12 . 2011-07-21 11:12 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-07-21 11:12 . 2011-07-21 11:12 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-07-21 11:12 . 2011-07-21 11:12 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-07-21 11:12 . 2011-07-21 11:12 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-07-21 11:12 . 2011-07-21 11:12 222208 ----a-w- c:\windows\system32\msls31.dll
2011-07-21 11:12 . 2011-07-21 11:12 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-07-21 11:12 . 2011-07-21 11:12 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-07-21 11:12 . 2011-07-21 11:12 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-07-21 11:12 . 2011-07-21 11:12 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-07-21 11:12 . 2011-07-21 11:12 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-07-21 11:12 . 2011-07-21 11:12 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-07-21 11:12 . 2011-07-21 11:12 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-07-21 11:12 . 2011-07-21 11:12 12288 ----a-w- c:\windows\system32\mshta.exe
2011-07-21 11:12 . 2011-07-21 11:12 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-07-21 11:12 . 2011-07-21 11:12 114176 ----a-w- c:\windows\system32\admparse.dll
2011-07-21 11:12 . 2011-07-21 11:12 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-07-21 11:12 . 2011-07-21 11:12 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-07-21 11:12 . 2011-07-21 11:12 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-07-21 11:12 . 2011-07-21 11:12 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-07-21 11:12 . 2011-07-21 11:12 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-07-21 11:12 . 2011-07-21 11:12 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-07-21 11:12 . 2011-07-21 11:12 448512 ----a-w- c:\windows\system32\html.iec
2011-07-21 11:12 . 2011-07-21 11:12 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-07-21 11:12 . 2011-07-21 11:12 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-07-21 11:12 . 2011-07-21 11:12 160256 ----a-w- c:\windows\system32\wextract.exe
2011-07-21 11:12 . 2011-07-21 11:12 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-07-21 08:21 . 2010-06-24 19:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-16 04:26 . 2011-08-11 13:09 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-06 17:52 . 2011-07-25 12:02 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-11 03:07 . 2011-07-21 08:46 3137536 ----a-w- c:\windows\system32\win32k.sys
2009-04-08 18:31 . 2009-04-08 18:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 05:45 . 2008-08-12 05:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-28_08.05.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-29 06:45 . 2011-08-29 06:45 13306 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-08-28 08:03 . 2011-08-28 08:03 13306 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2011-03-04 20:50 . 2011-08-28 08:37 38600 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-08-28 07:45 30904 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-08-29 06:31 30904 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:46 . 2011-08-28 09:06 94640 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-07-21 08:22 . 2011-08-29 06:31 7846 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2704008240-1525999651-1536097993-1000_UserData.bin
+ 2011-08-29 06:45 . 2011-08-29 06:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-28 08:04 . 2011-08-28 08:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-29 06:45 . 2011-08-29 06:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-28 08:04 . 2011-08-28 08:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-21 10:58 . 2011-08-28 15:01 239074 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 02:36 . 2011-08-13 10:11 629964 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-08-28 08:14 629964 c:\windows\system32\perfh009.dat
- 2009-08-03 20:00 . 2011-08-13 10:11 645248 c:\windows\system32\perfh005.dat
+ 2009-08-03 20:00 . 2011-08-28 08:14 645248 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2011-08-28 08:14 111326 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-08-13 10:11 111326 c:\windows\system32\perfc009.dat
- 2009-08-03 20:00 . 2011-08-13 10:11 126852 c:\windows\system32\perfc005.dat
+ 2009-08-03 20:00 . 2011-08-28 08:14 126852 c:\windows\system32\perfc005.dat
- 2011-03-04 05:09 . 2011-08-28 08:03 980984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-03-04 05:09 . 2011-08-29 06:45 980984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 05:01 . 2011-08-29 06:45 289108 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-08-28 08:03 289108 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-3-4 548528]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-3-4 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
R3 GPU-Z;GPU-Z;c:\users\ASUS\AppData\Local\Temp\GPU-Z.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 20:24]
.
2011-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 20:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"ETDWare"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_2da1ebd.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_2da1ebd.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\SmartLogon\smartlogon.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeck.exe
.
**************************************************************************
.
Celkový čas: 2011-08-29 08:51:36 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-29 06:51
ComboFix2.txt 2011-08-28 08:10
.
Před spuštěním: Volných bajtů: 88 719 339 520
Po spuštění: Volných bajtů: 88 658 919 424
.
- - End Of File - - C8CA237FC56043E0BCF460FB675127F9
ComboFix 11-08-27.01 - ASUS 29.08.2011 8:38.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3838.2544 [GMT 2:00]
Spuštěný z: c:\users\ASUS\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\ASUS\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\users\ASUS\AppData\Local\BITD622.tmp"
"c:\users\ASUS\AppData\Local\BITF353.tmp"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\ASUS\AppData\Local\BITD622.tmp
c:\users\ASUS\AppData\Local\BITF353.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 06:45 . 2011-08-29 06:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-28 09:06 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3D5E7F9E-2AD1-4F43-B3A3-072B59E86DF3}\mpengine.dll
2011-08-24 17:07 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 17:07 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-20 16:26 . 2011-08-20 16:36 -------- d-----w- c:\program files (x86)\Registry Genius
2011-08-20 15:12 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-08-20 15:12 . 2011-08-20 15:24 -------- d-----w- c:\programdata\AVAST Software
2011-08-20 15:12 . 2011-08-20 15:12 -------- d-----w- c:\program files\AVAST Software
2011-08-20 14:51 . 2011-08-20 14:57 -------- d-----w- c:\users\ASUS\AppData\Roaming\ChessBase
2011-08-20 12:59 . 2011-08-20 12:59 -------- d-----w- c:\users\ASUS\AppData\Local\Diagnostics
2011-08-18 07:03 . 2011-08-27 17:45 -------- d-----w- c:\program files\trend micro
2011-08-18 07:03 . 2011-08-18 07:03 -------- d-----w- C:\rsit
2011-08-16 10:01 . 2011-08-16 10:02 -------- d-----w- c:\users\ASUS\AppData\Roaming\Apple Computer
2011-08-16 10:01 . 2011-08-16 10:01 -------- d-----w- c:\users\ASUS\AppData\Local\Apple Computer
2011-08-16 10:01 . 2009-05-18 11:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-08-16 10:01 . 2008-04-17 10:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
2011-08-16 10:01 . 2008-04-17 10:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\program files\Bonjour
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\program files (x86)\Bonjour
2011-08-16 09:59 . 2011-08-16 10:00 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-08-16 09:59 . 2011-08-16 09:59 -------- d-----w- c:\programdata\Apple
2011-08-11 20:47 . 2011-07-21 13:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-08-11 20:47 . 2011-07-21 13:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC9EAC14-248E-4A65-A672-23683BF4F080}\gapaengine.dll
2011-08-11 13:08 . 2011-06-21 06:34 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-11 13:08 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-08-11 13:08 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-11 13:08 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-08-09 08:35 . 2011-08-29 06:46 -------- d-----w- c:\program files (x86)\Common Files\Akamai
2011-08-08 07:56 . 2011-08-08 07:57 -------- d-----w- c:\users\ASUS\.nbi
2011-08-03 14:20 . 2011-08-03 14:20 -------- d-----w- c:\program files (x86)\Microsoft WSE
2011-08-03 13:59 . 2011-08-03 13:59 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-03 13:59 . 2011-08-03 13:59 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-03 13:57 . 2011-08-05 07:11 -------- d-----w- c:\users\ASUS\AppData\Roaming\DAEMON Tools Lite
2011-08-03 13:57 . 2011-08-03 13:58 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-03 10:03 . 2011-08-28 15:53 -------- d-----w- c:\users\ASUS\riotsGamesLogs
2011-08-03 09:46 . 2011-08-09 06:56 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-03 07:36 . 2011-08-11 20:47 -------- d-----w- c:\users\ASUS\AppData\Roaming\SoftGrid Client
2011-08-03 07:36 . 2011-08-03 07:36 -------- d-----w- c:\users\ASUS\AppData\Local\SoftGrid Client
2011-08-03 07:35 . 2011-08-03 07:35 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2011-08-03 07:35 . 2011-08-03 07:36 -------- d-----w- c:\users\ASUS\AppData\Roaming\TP
2011-08-02 20:50 . 2011-08-02 20:53 -------- d-----w- c:\program files (x86)\NetBeans 7.0
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\FLEXnet
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\Nuance
2011-08-02 20:13 . 2011-08-02 20:13 -------- d-----w- c:\users\ASUS\AppData\Roaming\Zeon
2011-08-02 17:00 . 2011-08-02 17:08 -------- d-----w- c:\program files (x86)\Zrychleni Pocitace
2011-08-02 16:39 . 2004-08-18 08:34 442368 ----a-r- c:\windows\SysWow64\vp6vfw.dll
2011-08-02 10:56 . 2011-07-12 19:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-08-01 19:23 . 2011-08-01 19:23 -------- d-----w- c:\users\ASUS\AppData\Roaming\.minecraft
2011-08-01 18:58 . 2011-08-01 18:58 -------- d-----w- c:\users\ASUS\AppData\Local\PokerStars
2011-08-01 18:57 . 2011-08-01 18:58 -------- d-----w- c:\program files (x86)\PokerStars
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 04:10 . 2011-07-23 14:55 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-02 12:59 . 2011-07-24 13:53 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-08-02 12:59 . 2011-07-24 07:54 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-24 07:54 . 2011-07-24 07:54 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-07-22 07:59 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-07-22 07:59 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-21 11:12 . 2011-07-21 11:12 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-07-21 11:12 . 2011-07-21 11:12 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-07-21 11:12 . 2011-07-21 11:12 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-07-21 11:12 . 2011-07-21 11:12 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-07-21 11:12 . 2011-07-21 11:12 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-07-21 11:12 . 2011-07-21 11:12 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-07-21 11:12 . 2011-07-21 11:12 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-07-21 11:12 . 2011-07-21 11:12 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-07-21 11:12 . 2011-07-21 11:12 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-07-21 11:12 . 2011-07-21 11:12 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-07-21 11:12 . 2011-07-21 11:12 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-07-21 11:12 . 2011-07-21 11:12 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-07-21 11:12 . 2011-07-21 11:12 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-07-21 11:12 . 2011-07-21 11:12 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-07-21 11:12 . 2011-07-21 11:12 222208 ----a-w- c:\windows\system32\msls31.dll
2011-07-21 11:12 . 2011-07-21 11:12 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-07-21 11:12 . 2011-07-21 11:12 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-07-21 11:12 . 2011-07-21 11:12 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-07-21 11:12 . 2011-07-21 11:12 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-07-21 11:12 . 2011-07-21 11:12 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-07-21 11:12 . 2011-07-21 11:12 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-07-21 11:12 . 2011-07-21 11:12 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-07-21 11:12 . 2011-07-21 11:12 12288 ----a-w- c:\windows\system32\mshta.exe
2011-07-21 11:12 . 2011-07-21 11:12 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-07-21 11:12 . 2011-07-21 11:12 114176 ----a-w- c:\windows\system32\admparse.dll
2011-07-21 11:12 . 2011-07-21 11:12 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-07-21 11:12 . 2011-07-21 11:12 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-07-21 11:12 . 2011-07-21 11:12 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-07-21 11:12 . 2011-07-21 11:12 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-07-21 11:12 . 2011-07-21 11:12 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-07-21 11:12 . 2011-07-21 11:12 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-07-21 11:12 . 2011-07-21 11:12 448512 ----a-w- c:\windows\system32\html.iec
2011-07-21 11:12 . 2011-07-21 11:12 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-07-21 11:12 . 2011-07-21 11:12 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-07-21 11:12 . 2011-07-21 11:12 160256 ----a-w- c:\windows\system32\wextract.exe
2011-07-21 11:12 . 2011-07-21 11:12 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-07-21 08:21 . 2010-06-24 19:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-16 04:26 . 2011-08-11 13:09 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-06 17:52 . 2011-07-25 12:02 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-11 03:07 . 2011-07-21 08:46 3137536 ----a-w- c:\windows\system32\win32k.sys
2009-04-08 18:31 . 2009-04-08 18:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 05:45 . 2008-08-12 05:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-28_08.05.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-29 06:45 . 2011-08-29 06:45 13306 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-08-28 08:03 . 2011-08-28 08:03 13306 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2011-03-04 20:50 . 2011-08-28 08:37 38600 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-08-28 07:45 30904 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-08-29 06:31 30904 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:46 . 2011-08-28 09:06 94640 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-07-21 08:22 . 2011-08-29 06:31 7846 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2704008240-1525999651-1536097993-1000_UserData.bin
+ 2011-08-29 06:45 . 2011-08-29 06:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-28 08:04 . 2011-08-28 08:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-29 06:45 . 2011-08-29 06:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-28 08:04 . 2011-08-28 08:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-21 10:58 . 2011-08-28 15:01 239074 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 02:36 . 2011-08-13 10:11 629964 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-08-28 08:14 629964 c:\windows\system32\perfh009.dat
- 2009-08-03 20:00 . 2011-08-13 10:11 645248 c:\windows\system32\perfh005.dat
+ 2009-08-03 20:00 . 2011-08-28 08:14 645248 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2011-08-28 08:14 111326 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-08-13 10:11 111326 c:\windows\system32\perfc009.dat
- 2009-08-03 20:00 . 2011-08-13 10:11 126852 c:\windows\system32\perfc005.dat
+ 2009-08-03 20:00 . 2011-08-28 08:14 126852 c:\windows\system32\perfc005.dat
- 2011-03-04 05:09 . 2011-08-28 08:03 980984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-03-04 05:09 . 2011-08-29 06:45 980984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-07-14 05:01 . 2011-08-29 06:45 289108 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-08-28 08:03 289108 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-3-4 548528]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-3-4 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
R3 GPU-Z;GPU-Z;c:\users\ASUS\AppData\Local\Temp\GPU-Z.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 135664]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 20:24]
.
2011-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-04 20:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"ETDWare"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_2da1ebd.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_2da1ebd.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\SmartLogon\smartlogon.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeck.exe
.
**************************************************************************
.
Celkový čas: 2011-08-29 08:51:36 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-29 06:51
ComboFix2.txt 2011-08-28 08:10
.
Před spuštěním: Volných bajtů: 88 719 339 520
Po spuštění: Volných bajtů: 88 658 919 424
.
- - End Of File - - C8CA237FC56043E0BCF460FB675127F9
Re: Kontrola logu-test antiviru
Přes Start >> Spustit zkopíruj do okna:
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.
Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.
Nepořádek je pryč a nyní se mrkneme na ten antivir.
Pořád se sekne u toho powercfg.exe ?
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.
Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.
Nepořádek je pryč a nyní se mrkneme na ten antivir.
Pořád se sekne u toho powercfg.exe ?
Re: Kontrola logu-test antiviru
Stále to stejné
Re: Kontrola logu-test antiviru
Stáhni SystemLook
spusť aplikaci a do otevřeného okna zkopíruj :
pak klik na Look aplikace vytvoří SystemLook.txt jeho obsah mi sem zkopíruj.
spusť aplikaci a do otevřeného okna zkopíruj :
Kód: Vybrat vše
:filefind
powercfg.exe
Re: Kontrola logu-test antiviru
SystemLook 30.07.11 by jpshortstuff
Log created at 10:02 on 31/08/2011 by ASUS
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.
========== filefind ==========
Searching for "powercfg.exe"
C:\Windows\System32\powercfg.exe --a---- 59392 bytes [23:16 13/07/2009] [01:14 14/07/2009] 98E7E971AB21A6EDD2323C0FB37B9A0F
C:\Windows\SysWOW64\powercfg.exe --a---- 59392 bytes [23:16 13/07/2009] [01:14 14/07/2009] 98E7E971AB21A6EDD2323C0FB37B9A0F
C:\Windows\winsxs\amd64_microsoft-windows-p..nfiguration-cmdline_31bf3856ad364e35_6.1.7600.16385_none_6550a9de9a702b0f\powercfg.exe --a---- 71168 bytes [23:27 13/07/2009] [01:39 14/07/2009] F779EE89CD1F679C91AB8848C978F086
C:\Windows\winsxs\x86_microsoft-windows-p..nfiguration-cmdline_31bf3856ad364e35_6.1.7600.16385_none_09320e5ae212b9d9\powercfg.exe --a---- 59392 bytes [23:16 13/07/2009] [01:14 14/07/2009] 98E7E971AB21A6EDD2323C0FB37B9A0F
-= EOF =
Log created at 10:02 on 31/08/2011 by ASUS
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.
========== filefind ==========
Searching for "powercfg.exe"
C:\Windows\System32\powercfg.exe --a---- 59392 bytes [23:16 13/07/2009] [01:14 14/07/2009] 98E7E971AB21A6EDD2323C0FB37B9A0F
C:\Windows\SysWOW64\powercfg.exe --a---- 59392 bytes [23:16 13/07/2009] [01:14 14/07/2009] 98E7E971AB21A6EDD2323C0FB37B9A0F
C:\Windows\winsxs\amd64_microsoft-windows-p..nfiguration-cmdline_31bf3856ad364e35_6.1.7600.16385_none_6550a9de9a702b0f\powercfg.exe --a---- 71168 bytes [23:27 13/07/2009] [01:39 14/07/2009] F779EE89CD1F679C91AB8848C978F086
C:\Windows\winsxs\x86_microsoft-windows-p..nfiguration-cmdline_31bf3856ad364e35_6.1.7600.16385_none_09320e5ae212b9d9\powercfg.exe --a---- 59392 bytes [23:16 13/07/2009] [01:14 14/07/2009] 98E7E971AB21A6EDD2323C0FB37B9A0F
-= EOF =
Re: Kontrola logu-test antiviru
Tyhle dva soubory :
C:\Windows\System32\powercfg.exe
C:\Windows\SysWOW64\powercfg.exe
postupně otestuj na VIRUSTOTAL
(po načtení stránky klikni na tlačítko Procházet, najdi cestu k výše zmíněnému souboru a klikni na tlačítko Odeslat soubor
trvá to okolo deseti minut pak mi sem zkopíruj link, to je ten řádek nahoře v prohlížeči)
Pokud ti to napíše že soubor již byl testován nech otestovat znovu.
C:\Windows\System32\powercfg.exe
C:\Windows\SysWOW64\powercfg.exe
postupně otestuj na VIRUSTOTAL
(po načtení stránky klikni na tlačítko Procházet, najdi cestu k výše zmíněnému souboru a klikni na tlačítko Odeslat soubor
trvá to okolo deseti minut pak mi sem zkopíruj link, to je ten řádek nahoře v prohlížeči)
Pokud ti to napíše že soubor již byl testován nech otestovat znovu.