HJT log - prosím o kontrolu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 09 čer 2012 11:39

OTL log je moc dlouhý dam ho sem na dvě části.

Reklama
Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 09 čer 2012 11:42

OTL logfile created on: 9.6.2012 11:22:54 - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Documents and Settings\Administrator\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

767,49 Mb Total Physical Memory | 515,56 Mb Available Physical Memory | 67,17% Memory free
1,83 Gb Paging File | 1,61 Gb Available in Paging File | 87,93% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 40,16 Gb Total Space | 26,03 Gb Free Space | 64,82% Space Free | Partition Type: NTFS
Drive D: | 68,65 Gb Total Space | 40,39 Gb Free Space | 58,83% Space Free | Partition Type: NTFS

Computer Name: KOMP | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Plocha\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\WinRAR\rarlng.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (SoundMAX Agent Service (default)) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (aswMBR) -- C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (dtsoftbus01) -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (MouseCap) -- C:\WINDOWS\system32\drivers\MouseCap.sys ()
DRV - (Moufiltr) -- C:\WINDOWS\system32\drivers\Moufiltr.sys (Windows (R) 2000 DDK provider)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (viaagp1) -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={FDE87C9F-F409-496C-8F1E-586431DC5A72}&mid=9dc44eaee74447d0b416d147e0890252-bbb3d8d61ef6b68186f44149e3aba39e4a3bf32e&lang=en&ds=yu012&pr=sa&d=2012-06-08 09:42:06&v=11.1.0.7&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



O1 HOSTS File: ([2012.06.08 22:07:26 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microso ... 9151085984 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CAF20E15-0876-40DD-A8F5-1CFE53ADC7F8}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Proces mezipaměti kategorií součástí - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012.06.09 11:16:59 | 002,127,960 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Administrator\Plocha\TDSSKiller.exe
[2012.06.09 11:16:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2012.06.09 11:15:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.06.09 11:15:09 | 000,214,408 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012.06.09 11:15:09 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012.06.09 11:15:09 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012.06.09 11:07:54 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Plocha\OTL.exe
[2012.06.09 11:07:48 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Administrator\Plocha\aswMBR.exe
[2012.06.09 11:07:24 | 000,892,328 | ---- | C] (Oracle Corporation) -- C:\Documents and Settings\Administrator\Plocha\jre-7-windows-i586-iftw.exe
[2012.06.09 10:40:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Activision
[2012.06.09 10:31:15 | 000,000,000 | ---D | C] -- C:\Program Files\Activision
[2012.06.09 09:50:32 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2012.06.09 09:50:32 | 000,017,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2012.06.08 23:49:36 | 000,363,892 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\ISUN16.EXE
[2012.06.08 23:49:36 | 000,026,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\CTL3D.DLL
[2012.06.08 23:49:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Plocha\km400_window_035
[2012.06.08 23:49:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\WINDOWS
[2012.06.08 23:19:13 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2012.06.08 23:19:02 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012.06.08 23:18:15 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.06.08 23:18:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
[2012.06.08 23:18:01 | 003,862,112 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Administrator\Plocha\ccsetup319.exe
[2012.06.08 22:06:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012.06.08 20:13:53 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012.06.08 20:12:02 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Nástroje pro správu
[2012.06.08 17:53:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Dokumenty\Downloads
[2012.06.08 15:50:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
[2012.06.08 15:50:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2012.06.08 15:49:34 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\Plocha\mbam-setup-1.61.0.1400.exe
[2012.06.08 12:26:53 | 000,000,000 | ---D | C] -- C:\124d32e6a5ef0990e097eb
[2012.06.08 12:26:49 | 000,000,000 | ---D | C] -- C:\ee1572b52872e712f5255e109dbf9c
[2012.06.08 12:02:15 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\IECompatCache
[2012.06.08 10:13:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\SpeedFan
[2012.06.08 10:13:05 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2012.06.08 09:40:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2012.06.08 09:40:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\HijackThis
[2012.06.08 09:40:53 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2012.06.08 09:06:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\NVIDIA
[2012.06.08 08:31:52 | 000,000,000 | ---D | C] -- C:\Program Files\Valve
[2012.06.08 08:31:11 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2012.06.08 08:30:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
[2012.06.08 08:30:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\DAEMON Tools Lite
[2012.06.08 08:30:06 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2012.06.08 08:29:50 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2012.06.08 08:29:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\DAEMON Tools Lite
[2012.06.08 08:28:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2012.06.08 08:17:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012.06.08 08:03:02 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2012.06.08 08:01:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012.06.08 08:00:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\PrivacIE
[2012.06.08 08:00:26 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\IETldCache
[2012.06.08 07:44:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012.06.08 07:44:09 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2012.06.08 07:42:03 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012.06.08 07:16:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie7updates
[2012.06.08 07:06:21 | 000,226,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip6.sys
[2012.06.08 07:06:20 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mswsock.dll
[2012.06.08 07:05:21 | 000,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
[2012.06.08 07:04:48 | 000,457,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2012.06.08 07:03:57 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2012.06.08 07:03:49 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2012.06.08 07:03:03 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fontsub.dll
[2012.06.08 07:03:02 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\t2embed.dll
[2012.06.08 07:01:04 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mup.sys
[2012.06.08 07:00:43 | 001,447,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll
[2012.06.08 07:00:43 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml3.dll
[2012.06.08 07:00:24 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browserchoice.exe
[2012.06.08 06:59:23 | 003,558,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
[2012.06.08 06:57:11 | 002,150,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2012.06.08 06:57:10 | 002,194,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2012.06.08 06:57:09 | 002,028,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2012.06.08 06:56:45 | 000,139,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpwd.sys
[2012.06.08 06:56:14 | 000,010,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndistapi.sys
[2012.06.08 06:55:08 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2012.06.08 06:55:05 | 000,590,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2012.06.08 06:53:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
[2012.06.08 06:53:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2012.06.08 06:50:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2012.06.08 06:46:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012.06.08 06:42:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\TS3Client
[2012.06.08 06:42:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\TeamSpeak 3 Client
[2012.06.08 06:42:26 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2012.06.07 21:42:17 | 000,010,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gameenum.sys
[2012.06.07 21:41:49 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usbui.dll
[2012.06.07 21:40:54 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Dokumenty\Hudba
[2012.06.07 21:40:33 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2012.06.07 21:40:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2012.06.07 21:40:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2012.06.07 21:40:29 | 000,000,000 | R--D | C] -- C:\Program Files
[2012.06.07 21:40:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2012.06.07 21:40:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2012.06.07 21:40:25 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuq.dll
[2012.06.07 21:40:25 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuf.dll
[2012.06.07 21:40:25 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdazel.dll
[2012.06.07 21:40:24 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbduzb.dll
[2012.06.07 21:40:24 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtat.dll
[2012.06.07 21:40:24 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmon.dll
[2012.06.07 21:40:24 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkyr.dll
[2012.06.07 21:40:24 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdaze.dll
[2012.06.07 21:40:23 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycc.dll
[2012.06.07 21:40:23 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdur.dll
[2012.06.07 21:40:23 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru1.dll
[2012.06.07 21:40:23 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru.dll
[2012.06.07 21:40:23 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkaz.dll
[2012.06.07 21:40:23 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbu.dll
[2012.06.07 21:40:23 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdblr.dll
[2012.06.07 21:40:22 | 000,008,192 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhept.dll
[2012.06.07 21:40:22 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela3.dll
[2012.06.07 21:40:22 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela2.dll
[2012.06.07 21:40:22 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdgkl.dll
[2012.06.07 21:40:22 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe319.dll
[2012.06.07 21:40:22 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe220.dll
[2012.06.07 21:40:22 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe.dll
[2012.06.07 21:40:20 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv1.dll
[2012.06.07 21:40:20 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv.dll
[2012.06.07 21:40:20 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdest.dll
[2012.06.07 21:40:20 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt1.dll
[2012.06.07 21:40:20 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt.dll
[2012.06.07 21:40:14 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycl.dll
[2012.06.07 21:40:14 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl1.dll
[2012.06.07 21:40:14 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl.dll
[2012.06.07 21:40:14 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl.dll
[2012.06.07 21:40:14 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu.dll
[2012.06.07 21:40:14 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcr.dll
[2012.06.07 21:40:14 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\KBDAL.DLL
[2012.06.07 21:40:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdro.dll
[2012.06.07 21:40:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl1.dll
[2012.06.07 21:40:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu1.dll
[2012.06.07 21:40:12 | 000,176,157 | ---- | C] (Digi International, Inc.) -- C:\WINDOWS\System32\dgrpsetu.dll
[2012.06.07 21:40:12 | 000,103,424 | ---- | C] (Equinox Systems Inc.) -- C:\WINDOWS\System32\EqnClass.Dll
[2012.06.07 21:40:12 | 000,085,020 | ---- | C] (Digi International) -- C:\WINDOWS\System32\dgsetup.dll
[2012.06.07 21:40:12 | 000,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\spxcoins.dll
[2012.06.07 21:40:12 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll
[2012.06.07 21:40:11 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLECLI.DLL
[2012.06.07 21:40:11 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLESVR.DLL
[2012.06.07 21:40:11 | 000,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TAPI.DLL
[2012.06.07 21:40:11 | 000,013,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WFWNET.DRV
[2012.06.07 21:40:11 | 000,009,291 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VER.DLL
[2012.06.07 21:40:11 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SHELL.DLL
[2012.06.07 21:40:11 | 000,004,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TIMER.DRV
[2012.06.07 21:40:11 | 000,003,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SYSTEM.DRV
[2012.06.07 21:40:11 | 000,002,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VGA.DRV
[2012.06.07 21:40:11 | 000,001,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SOUND.DRV
[2012.06.07 21:40:10 | 000,127,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MSVIDEO.DLL
[2012.06.07 21:40:10 | 000,109,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVIFILE.DLL
[2012.06.07 21:40:10 | 000,073,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIAVI.DRV
[2012.06.07 21:40:10 | 000,070,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVICAP.DLL
[2012.06.07 21:40:10 | 000,033,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\COMMDLG.DLL
[2012.06.07 21:40:10 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIWAVE.DRV
[2012.06.07 21:40:10 | 000,025,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCISEQ.DRV
[2012.06.07 21:40:10 | 000,009,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\LZEXPAND.DLL
[2012.06.07 21:40:10 | 000,002,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MOUSE.DRV
[2012.06.07 21:40:10 | 000,002,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\KEYBOARD.DRV
[2012.06.07 21:40:10 | 000,001,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMTASK.TSK
[2012.06.07 21:40:09 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE
[2012.06.07 21:40:09 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batt.dll
[2012.06.07 21:40:08 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WINSPOOL.DRV
[2012.06.07 21:40:08 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storprop.dll
[2012.06.07 21:40:08 | 000,069,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMSYSTEM.DLL
[2012.06.07 21:39:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
[2012.06.07 21:39:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Nabídka Start
[2012.06.07 21:39:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Dokumenty
[2012.06.07 21:39:59 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Šablony
[2012.06.07 21:39:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Plocha
[2012.06.07 21:39:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Oblíbené položky
[2012.06.07 21:39:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2012.06.07 21:39:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2012.06.07 21:39:38 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Data aplikací\Microsoft
[2012.06.07 21:39:38 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Data aplikací
[2012.06.07 21:39:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2012.06.07 21:36:16 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012.06.07 21:35:26 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2012.06.07 21:35:26 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2012.06.07 21:35:26 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2012.06.07 21:35:26 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2012.06.07 21:35:26 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Offline Web Pages
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Network Diagnostic
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\L2Schemas
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cs-cz
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cs

Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 09 čer 2012 11:43

[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1029
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2012.06.07 21:35:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2012.06.07 21:24:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\A4TECH
[2012.06.07 21:24:39 | 000,000,000 | ---D | C] -- C:\Program Files\A4TECH
[2012.06.07 21:23:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\A4TECH Software
[2012.06.07 21:23:39 | 000,000,000 | ---D | C] -- C:\Program Files\OSCAR Editor X7
[2012.06.07 21:23:16 | 000,000,000 | ---D | C] -- C:\Program Files\OscarX7
[2012.06.07 21:10:01 | 000,419,488 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012.06.07 21:10:01 | 000,070,304 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.06.07 20:53:41 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_4.dll
[2012.06.07 20:53:41 | 000,068,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_3.dll
[2012.06.07 20:53:41 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_1.dll
[2012.06.07 20:53:40 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_31.dll
[2012.06.07 20:53:40 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_3.dll
[2012.06.07 20:53:40 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_2.dll
[2012.06.07 20:53:40 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_2.dll
[2012.06.07 20:53:40 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_1.dll
[2012.06.07 20:53:39 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_1.dll
[2012.06.07 20:53:34 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll
[2012.06.07 20:53:33 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_29.dll
[2012.06.07 20:53:33 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_28.dll
[2012.06.07 20:53:33 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_0.dll
[2012.06.07 20:53:33 | 000,061,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput9_1_0.dll
[2012.06.07 20:53:33 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_0.dll
[2012.06.07 20:53:32 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_25.dll
[2012.06.07 20:53:32 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_27.dll
[2012.06.07 20:53:32 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_26.dll
[2012.06.07 20:53:29 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_24.dll
[2012.06.07 20:43:29 | 000,146,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\portcls.sys
[2012.06.07 20:43:29 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
[2012.06.07 20:43:29 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll
[2012.06.07 20:43:28 | 000,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys
[2012.06.07 20:43:26 | 001,285,632 | ---- | C] (Analog Devices) -- C:\WINDOWS\System32\SMMedia.dll
[2012.06.07 20:43:26 | 000,978,944 | ---- | C] (Analog Devices, Inc.) -- C:\WINDOWS\SynthCoreA.Dll
[2012.06.07 20:43:26 | 000,380,928 | ---- | C] (Analog Devices, Inc.) -- C:\WINDOWS\SynCor.exe
[2012.06.07 20:43:26 | 000,030,208 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\wdmioctl.dll
[2012.06.07 20:43:26 | 000,003,744 | ---- | C] (Analog Devices, Inc.) -- C:\WINDOWS\System32\drivers\smsens.sys
[2012.06.07 20:43:25 | 000,991,232 | ---- | C] (Sensaura) -- C:\WINDOWS\System32\virtear.dll
[2012.06.07 20:43:25 | 000,765,952 | ---- | C] (Sensaura Ltd) -- C:\WINDOWS\System\crlds3d.dll
[2012.06.07 20:43:25 | 000,720,896 | ---- | C] (Sensaura Ltd) -- C:\WINDOWS\System32\Audio3d.dll
[2012.06.07 20:43:25 | 000,720,896 | ---- | C] (Sensaura Ltd) -- C:\WINDOWS\System32\a3d.dll
[2012.06.07 20:43:25 | 000,049,152 | ---- | C] (SoundMAX) -- C:\WINDOWS\System32\S11thk32.dll
[2012.06.07 20:43:25 | 000,049,152 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\DSndUp.exe
[2012.06.07 20:43:25 | 000,045,056 | ---- | C] (Analog Devices, Inc.) -- C:\WINDOWS\System32\SynthCore11Resources.dll
[2012.06.07 20:43:25 | 000,045,056 | ---- | C] (adi) -- C:\WINDOWS\System32\CleanUp.exe
[2012.06.07 20:43:25 | 000,040,820 | ---- | C] (SoundMAX) -- C:\WINDOWS\System32\Syncor11.dll
[2012.06.07 20:43:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\VirtualEar
[2012.06.07 20:43:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\SoundMAX
[2012.06.07 20:43:25 | 000,000,000 | ---D | C] -- C:\Program Files\Analog Devices
[2012.06.07 20:43:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2012.06.07 20:42:54 | 000,000,000 | ---D | C] -- C:\Program Files\S3
[2012.06.07 20:42:16 | 000,026,880 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\drivers\VIAAGP1.SYS
[2012.06.07 20:42:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2012.06.07 20:41:53 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2012.06.07 20:37:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Adobe
[2012.06.07 20:37:43 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012.06.07 20:37:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2012.06.07 20:37:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Macromedia
[2012.06.07 20:37:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Adobe
[2012.06.07 20:37:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Adobe
[2012.06.07 20:36:25 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012.06.07 20:36:23 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2012.06.07 20:35:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Total Commander
[2012.06.07 20:35:28 | 000,000,000 | ---D | C] -- C:\Program Files\totalcmd
[2012.06.07 20:35:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\GHISLER
[2012.06.07 20:35:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\WinRAR
[2012.06.07 20:35:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\WinRAR
[2012.06.07 20:35:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\WinRAR
[2012.06.07 20:34:56 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2012.06.07 20:34:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Sun
[2012.06.07 20:34:32 | 000,544,656 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2012.06.07 20:34:32 | 000,128,000 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012.06.07 20:34:21 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.06.07 20:33:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Sun
[2012.06.07 20:29:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Media Player Classic
[2012.06.07 20:29:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\MPC-HC
[2012.06.07 20:29:21 | 000,000,000 | ---D | C] -- C:\Program Files\MPC-HC
[2012.06.07 20:29:02 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Dokumenty\Filmy
[2012.06.07 20:23:25 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2012.06.07 20:23:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2012.06.07 20:23:18 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2012.06.07 20:23:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2012.06.07 20:22:57 | 000,014,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg2.dll
[2012.06.07 20:22:23 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2012.06.07 20:22:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2012.06.07 20:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Opera
[2012.06.07 20:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Opera
[2012.06.07 20:04:43 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2012.06.07 20:01:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\NVIDIA
[2012.06.07 20:01:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
[2012.06.07 20:01:46 | 000,143,680 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcolor.exe
[2012.06.07 20:01:45 | 015,504,192 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcpl.dll
[2012.06.07 20:01:44 | 000,108,352 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmctray.dll
[2012.06.07 20:01:44 | 000,054,272 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwddi.dll
[2012.06.07 20:01:25 | 000,065,536 | ---- | C] (Khronos Group) -- C:\WINDOWS\System32\OpenCL.dll
[2012.06.07 20:01:04 | 018,771,968 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvoglnt.dll
[2012.06.07 20:01:04 | 006,012,928 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcuda.dll
[2012.06.07 20:01:04 | 002,530,624 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcuvid.dll
[2012.06.07 20:01:04 | 002,445,120 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcuvenc.dll
[2012.06.07 20:01:04 | 001,000,768 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvdispco32.dll
[2012.06.07 20:01:04 | 000,883,008 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvgenco32.dll
[2012.06.07 20:01:02 | 017,543,168 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcompiler.dll
[2012.06.07 20:01:02 | 004,373,248 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nv4_disp.dll
[2012.06.07 20:01:02 | 002,359,808 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvapi.dll
[2012.06.07 20:00:49 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2012.06.07 20:00:29 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2012.06.07 19:58:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Data aplikací\Identities
[2012.06.07 19:58:09 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Dokumenty\Obrázky
[2012.06.07 19:58:09 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Dokumenty\Hudba
[2012.06.07 19:58:09 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2012.06.07 19:58:04 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft
[2012.06.07 19:58:04 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
[2012.06.07 19:58:04 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\SendTo
[2012.06.07 19:58:04 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Data aplikací
[2012.06.07 19:58:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Příslušenství
[2012.06.07 19:58:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
[2012.06.07 19:58:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Oblíbené položky
[2012.06.07 19:58:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Nabídka Start
[2012.06.07 19:58:04 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Dokumenty
[2012.06.07 19:58:04 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\Cookies
[2012.06.07 19:58:04 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Šablony
[2012.06.07 19:58:04 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Okolní tiskárny
[2012.06.07 19:58:04 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Okolní síť
[2012.06.07 19:58:04 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator\Local Settings
[2012.06.07 19:58:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Plocha
[2012.06.07 19:57:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2012.06.07 19:57:47 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2012.06.07 19:57:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012.06.07 19:57:45 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2012.06.07 19:57:45 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2012.06.07 19:57:41 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2012.06.07 19:57:41 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2012.06.07 19:51:52 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logui.ocx
[2012.06.07 19:51:51 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isatq.dll
[2012.06.07 19:51:51 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetsloc.dll
[2012.06.07 19:51:51 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infoadmn.dll
[2012.06.07 19:51:51 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.exe
[2012.06.07 19:51:50 | 000,834,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.dll
[2012.06.07 19:51:50 | 000,171,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisui.dll
[2012.06.07 19:51:50 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrtl.dll
[2012.06.07 19:51:50 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisext51.dll
[2012.06.07 19:51:50 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iismap.dll
[2012.06.07 19:51:50 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstas.exe
[2012.06.07 19:51:50 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisreset.exe
[2012.06.07 19:51:50 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstap.dll
[2012.06.07 19:51:49 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2012.06.07 19:51:49 | 000,020,538 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpremadm.exe
[2012.06.07 19:51:49 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpsapi2.dll
[2012.06.07 19:51:48 | 000,876,653 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awel.dll
[2012.06.07 19:51:48 | 000,598,071 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmc.dll
[2012.06.07 19:51:48 | 000,188,494 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpcount.exe
[2012.06.07 19:51:48 | 000,109,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98swin.exe
[2012.06.07 19:51:48 | 000,049,212 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2012.06.07 19:51:48 | 000,032,826 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avss.dll
[2012.06.07 19:51:48 | 000,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpexedll.dll
[2012.06.07 19:51:48 | 000,014,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2012.06.07 19:51:47 | 000,184,435 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2012.06.07 19:51:47 | 000,147,513 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4apws.dll
[2012.06.07 19:51:47 | 000,102,509 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2012.06.07 19:51:47 | 000,082,035 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2012.06.07 19:51:47 | 000,049,210 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4areg.dll
[2012.06.07 19:51:47 | 000,041,020 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2012.06.07 19:51:46 | 000,278,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certwiz.ocx
[2012.06.07 19:51:46 | 000,188,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2012.06.07 19:51:46 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certmap.ocx
[2012.06.07 19:51:46 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cnfgprts.ocx
[2012.06.07 19:51:46 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\coadmin.dll
[2012.06.07 19:51:45 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adsiis51.dll
[2012.06.07 19:51:45 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admwprox.dll
[2012.06.07 19:51:45 | 000,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.dll
[2012.06.07 19:51:45 | 000,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.exe
[2012.06.07 19:51:44 | 000,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.exe
[2012.06.07 19:51:42 | 000,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.dll
[2012.06.07 19:51:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2012.06.07 19:51:40 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2012.06.07 19:51:40 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2012.06.07 19:51:21 | 000,026,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe
[2012.06.07 19:51:14 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2012.06.07 19:50:32 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\imapi2fs.dll
[2012.06.07 19:50:32 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imapi2fs.dll
[2012.06.07 19:50:32 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\imapi2.dll
[2012.06.07 19:50:32 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imapi2.dll
[2012.06.07 19:50:32 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdrom.sys
[2012.06.07 19:50:22 | 002,000,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2012.06.07 19:50:22 | 001,282,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2012.06.07 19:50:22 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2012.06.07 19:50:22 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2012.06.07 19:50:22 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2012.06.07 19:50:22 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieaksie.dll
[2012.06.07 19:50:22 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
[2012.06.07 19:50:22 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msrating.dll
[2012.06.07 19:50:22 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieakui.dll
[2012.06.07 19:50:22 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieakeng.dll
[2012.06.07 19:50:22 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
[2012.06.07 19:50:22 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iernonce.dll
[2012.06.07 19:50:22 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2012.06.07 19:50:21 | 003,698,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2012.06.07 19:50:21 | 000,916,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
[2012.06.07 19:50:21 | 000,638,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iexplore.exe
[2012.06.07 19:50:21 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2012.06.07 19:50:21 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2012.06.07 19:50:21 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtrans.dll
[2012.06.07 19:50:21 | 000,174,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2012.06.07 19:50:21 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
[2012.06.07 19:50:21 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pngfilt.dll
[2012.06.07 19:50:21 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieudinit.exe
[2012.06.07 19:50:20 | 001,212,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
[2012.06.07 19:50:20 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\webcheck.dll
[2012.06.07 19:50:20 | 000,133,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\extmgr.dll
[2012.06.07 19:50:20 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advpack.dll
[2012.06.07 19:50:19 | 011,082,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2012.06.07 19:50:19 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2012.06.07 19:50:19 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icardie.dll
[2012.06.07 19:50:12 | 000,017,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2012.06.07 19:50:11 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2012.06.07 19:50:10 | 000,759,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\VGX.dll
[2012.06.07 19:49:36 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mapi32.dll
[2012.06.07 19:48:51 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2012.06.07 19:48:33 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012.06.07 19:48:28 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2012.06.07 19:48:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2012.06.07 19:48:04 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\atrace.dll
[2012.06.07 19:47:54 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmevtmsg.dll
[2012.06.07 19:47:53 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\acctres.dll
[2012.06.07 19:47:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2012.06.07 19:47:50 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icfgnt5.dll
[2012.06.07 19:47:50 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2012.06.07 19:47:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2012.06.07 19:47:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2012.06.07 19:47:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2012.06.07 19:47:42 | 000,327,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll
[2012.06.07 19:47:42 | 000,183,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng1.dll
[2012.06.07 19:47:42 | 000,035,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups.dll
[2012.06.07 19:47:41 | 000,575,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll
[2012.06.07 19:47:41 | 000,166,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauclt1.exe
[2012.06.07 19:47:41 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qmgrprxy.dll
[2012.06.07 19:47:41 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx2.dll
[2012.06.07 19:47:41 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bitsprx4.dll
[2012.06.07 19:47:41 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx4.dll
[2012.06.07 19:47:41 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx3.dll
[2012.06.07 19:47:38 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2012.06.07 19:47:20 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrslv.dll
[2012.06.07 19:47:20 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrcdlg.dll
[2012.06.07 19:47:20 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\racpldlg.dll
[2012.06.07 19:47:20 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrdm.dll
[2012.06.07 19:47:17 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltMc.exe
[2012.06.07 19:47:16 | 000,240,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srrstr.dll
[2012.06.07 19:47:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2012.06.07 19:47:15 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ils.dll
[2012.06.07 19:47:15 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msconf.dll
[2012.06.07 19:47:15 | 000,034,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mnmdd.dll
[2012.06.07 19:47:15 | 000,032,768 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\isrdbg32.dll
[2012.06.07 19:47:15 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmmkcert.dll
[2012.06.07 19:47:12 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoeacct.dll
[2012.06.07 19:47:12 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoert2.dll
[2012.06.07 19:47:12 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2012.06.07 19:47:11 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetres.dll
[2012.06.07 19:47:09 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstinit.exe
[2012.06.07 19:47:09 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2012.06.07 19:47:08 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcfg.dll
[2012.06.07 19:47:08 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\isign32.dll
[2012.06.07 19:47:08 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwdial.dll
[2012.06.07 19:47:08 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwphbk.dll
[2012.06.07 19:47:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2012.06.07 19:46:58 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2012.06.07 19:46:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Dokumenty\Obrázky
[2012.06.07 19:46:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Hry
[2012.06.07 19:46:10 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2012.06.07 19:46:03 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Nástroje pro správu
[2012.06.07 19:46:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2012.06.07 19:45:41 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2012.06.07 19:45:40 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2012.06.07 19:45:39 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2012.06.07 19:45:35 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\write.exe
[2012.06.07 19:45:35 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2012.06.07 19:45:27 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndvol32.exe
[2012.06.07 19:45:27 | 000,044,544 | ---- | C] (Hilgraeve, Inc.) -- C:\WINDOWS\System32\hticons.dll
[2012.06.07 19:45:26 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avtapi.dll
[2012.06.07 19:45:26 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avwav.dll
[2012.06.07 19:45:26 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winchat.exe
[2012.06.07 19:45:26 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avmeter.dll
[2012.06.07 19:45:19 | 000,670,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\getuname.dll
[2012.06.07 19:45:19 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\calc.exe
[2012.06.07 19:45:19 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\charmap.exe
[2012.06.07 19:45:18 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mshearts.exe
[2012.06.07 19:45:18 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winmine.exe
[2012.06.07 19:45:18 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sol.exe
[2012.06.07 19:45:18 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\freecell.exe
[2012.06.07 19:45:18 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\reset.exe
[2012.06.07 19:45:17 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\regini.exe
[2012.06.07 19:45:17 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qwinsta.exe
[2012.06.07 19:45:17 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msg.exe
[2012.06.07 19:45:17 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qappsrv.exe
[2012.06.07 19:45:17 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsshutdn.exe
[2012.06.07 19:45:17 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tskill.exe
[2012.06.07 19:45:17 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwinsta.exe
[2012.06.07 19:45:17 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscon.exe
[2012.06.07 19:45:17 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shadow.exe
[2012.06.07 19:45:17 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\logoff.exe
[2012.06.07 19:45:17 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsdiscon.exe
[2012.06.07 19:45:17 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpcfgex.dll
[2012.06.07 19:45:16 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cdmodem.dll
[2012.06.07 19:45:09 | 000,351,232 | ---- | C] (Hilgraeve, Inc.) -- C:\WINDOWS\System32\hypertrm.dll
[2012.06.07 19:45:09 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\accwiz.exe
[2012.06.07 19:45:09 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndrec32.exe
[2012.06.07 19:45:09 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mplay32.exe
[2012.06.07 19:45:09 | 000,070,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\access.cpl
[2012.06.07 19:45:08 | 000,538,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spider.exe
[2012.06.07 19:45:08 | 000,343,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mspaint.exe
[2012.06.07 19:45:08 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clipbrd.exe
[2012.06.07 19:45:08 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2012.06.07 19:45:07 | 000,290,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rhttpaa.dll
[2012.06.07 19:45:07 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscfgwmi.dll
[2012.06.07 19:45:07 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsgqec.dll
[2012.06.07 19:45:06 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aaclient.dll
[2012.06.07 19:45:06 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aaclient.dll
[2012.06.07 19:45:05 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdchost.dll
[2012.06.07 19:45:05 | 000,087,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpwsx.dll
[2012.06.07 19:45:05 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdshost.exe
[2012.06.07 19:45:05 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpclip.exe
[2012.06.07 19:45:05 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qprocess.exe
[2012.06.07 19:45:05 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpsnd.dll
[2012.06.07 19:45:05 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdsaddin.exe
[2012.06.07 19:45:04 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtctm.dll
[2012.06.07 19:45:04 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcprx.dll
[2012.06.07 19:45:04 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcuiu.dll
[2012.06.07 19:45:04 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cfgbkend.dll
[2012.06.07 19:45:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2012.06.07 19:45:03 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtclog.dll
[2012.06.07 19:45:03 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xolehlp.dll
[2012.06.07 19:45:02 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comrepl.dll
[2012.06.07 19:45:02 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stclient.dll
[2012.06.07 19:45:02 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxlegih.dll
[2012.06.07 19:45:02 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxdm.dll
[2012.06.07 19:45:02 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comaddin.dll
[2012.06.07 19:45:02 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dcomcnfg.exe
[2012.06.07 19:45:02 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxex.dll
[2012.06.07 19:45:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2012.06.07 19:45:01 | 000,539,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comuid.dll
[2012.06.07 19:45:01 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clbcatex.dll
[2012.06.07 19:45:01 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrvps.dll
[2012.06.07 19:45:00 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsnap.dll
[2012.06.07 19:44:55 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\licwmi.dll
[2012.06.07 19:44:55 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\servdeps.dll
[2012.06.07 19:44:55 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmfutil.dll
[2012.06.07 19:44:54 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmprops.dll
[2012.06.07 19:44:49 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Dokumenty\Filmy
[2012.06.07 19:44:01 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Příslušenství
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012.06.09 11:22:51 | 000,432,356 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.06.09 11:22:51 | 000,428,744 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2012.06.09 11:22:51 | 000,077,850 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2012.06.09 11:22:51 | 000,067,312 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.06.09 11:20:51 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\MBR.dat
[2012.06.09 11:18:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.06.09 11:14:47 | 000,544,656 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2012.06.09 11:14:47 | 000,214,408 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012.06.09 11:14:47 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012.06.09 11:14:47 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012.06.09 11:14:47 | 000,128,000 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012.06.09 11:09:29 | 000,892,328 | ---- | M] (Oracle Corporation) -- C:\Documents and Settings\Administrator\Plocha\jre-7-windows-i586-iftw.exe
[2012.06.09 11:08:35 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.06.09 11:08:34 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Administrator\Plocha\aswMBR.exe
[2012.06.09 11:08:32 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Plocha\OTL.exe
[2012.06.09 11:08:25 | 002,745,121 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\Blink-182---First-Date.mp3
[2012.06.09 11:07:19 | 002,108,959 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\tdsskiller.zip
[2012.06.09 10:58:37 | 000,000,366 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2012.06.09 10:40:38 | 000,001,563 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Call of Duty(R) 2 Singleplayer.lnk
[2012.06.09 10:40:38 | 000,001,563 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Call of Duty(R) 2 Multiplayer.lnk
[2012.06.09 10:40:37 | 000,000,287 | ---- | M] () -- C:\WINDOWS\game.ini
[2012.06.09 10:31:26 | 094,318,732 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\2003-Blink-182-Blink-182.rar
[2012.06.09 09:59:20 | 000,000,396 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012.06.08 23:48:53 | 012,089,946 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\km400_window_035.zip
[2012.06.08 23:43:46 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.06.08 23:26:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2012.06.08 23:19:57 | 000,020,736 | ---- | M] () -- C:\Documents and Settings\Administrator\Dokumenty\cc_20120608_231952.reg
[2012.06.08 23:18:15 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2012.06.08 23:18:05 | 003,862,112 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Administrator\Plocha\ccsetup319.exe
[2012.06.08 22:07:26 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012.06.08 21:09:45 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012.06.08 17:54:06 | 000,004,608 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.08 17:53:15 | 000,029,233 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\[CzT]call_of_duty_2_cz.torrent
[2012.06.08 15:50:02 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\Plocha\mbam-setup-1.61.0.1400.exe
[2012.06.08 12:32:55 | 007,653,010 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\hfps_103.zip
[2012.06.08 10:13:09 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\SpeedFan.lnk
[2012.06.08 10:13:05 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2012.06.08 09:40:55 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\HijackThis.lnk
[2012.06.08 08:31:52 | 000,001,375 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Counter-Strike 1.6.lnk
[2012.06.08 08:31:15 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\µTorrent.lnk
[2012.06.08 08:30:25 | 000,001,613 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\DAEMON Tools Lite.lnk
[2012.06.08 08:30:07 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2012.06.08 08:17:48 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2012.06.08 08:02:03 | 000,001,912 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012.06.08 08:00:14 | 000,096,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.06.08 06:47:07 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader X.lnk
[2012.06.08 06:42:32 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\TeamSpeak 3 Client.lnk
[2012.06.07 21:40:38 | 000,004,444 | ---- | M] () -- C:\WINDOWS\System32\pid.PNF
[2012.06.07 21:30:19 | 000,002,643 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\A4tech USB Mouse Quality Test Program.lnk
[2012.06.07 21:23:43 | 000,001,954 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\X7 Oscar Editor.lnk
[2012.06.07 21:10:01 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012.06.07 21:10:01 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.06.07 20:49:48 | 001,074,972 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2012.06.07 20:49:48 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2012.06.07 20:49:44 | 001,074,972 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2012.06.07 20:35:30 | 000,000,708 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\Total Commander.lnk
[2012.06.07 20:29:23 | 000,001,548 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\MPC-HC.lnk
[2012.06.07 20:04:47 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Nefunkční.lnk
[2012.06.07 20:01:17 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvdrswr.lk
[2012.06.07 19:57:45 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2012.06.07 19:52:41 | 000,001,369 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2012.06.07 19:49:54 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.06.07 19:49:54 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2012.06.07 19:49:54 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2012.06.07 19:49:54 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2012.06.07 19:49:47 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012.06.07 19:49:47 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012.06.07 19:49:46 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2012.06.07 19:49:36 | 000,004,249 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2012.06.07 19:46:20 | 000,021,812 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012.05.31 15:22:06 | 000,602,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[2012.05.31 14:23:29 | 000,000,576 | ---- | M] () -- C:\Documents and Settings\Administrator\Plocha\Zástupce - Wow.lnk
[2012.05.26 12:36:44 | 000,178,176 | ---- | M] () -- C:\WINDOWS\System32\unrar.dll
[2012.05.21 16:40:50 | 002,127,960 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Administrator\Plocha\TDSSKiller.exe
[2012.05.15 12:18:00 | 018,771,968 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvoglnt.dll
[2012.05.15 12:18:00 | 017,543,168 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcompiler.dll
[2012.05.15 12:18:00 | 006,012,928 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcuda.dll
[2012.05.15 12:18:00 | 004,373,248 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nv4_disp.dll
[2012.05.15 12:18:00 | 002,807,708 | ---- | M] () -- C:\WINDOWS\System32\nvdata.data
[2012.05.15 12:18:00 | 002,530,624 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcuvid.dll
[2012.05.15 12:18:00 | 002,445,120 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcuvenc.dll
[2012.05.15 12:18:00 | 002,359,808 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvapi.dll
[2012.05.15 12:18:00 | 001,000,768 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvdispco32.dll
[2012.05.15 12:18:00 | 000,883,008 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvgenco32.dll
[2012.05.15 12:18:00 | 000,065,536 | ---- | M] (Khronos Group) -- C:\WINDOWS\System32\OpenCL.dll
[2012.05.15 12:18:00 | 000,010,264 | ---- | M] () -- C:\WINDOWS\System32\nvinfo.pb
[2012.05.15 11:40:26 | 000,054,272 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvwddi.dll
[2012.05.15 11:40:02 | 015,504,192 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcpl.dll
[2012.05.15 11:40:02 | 000,143,680 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcolor.exe
[2012.05.15 11:40:01 | 000,108,352 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvmctray.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.06.09 11:20:51 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\MBR.dat
[2012.06.09 11:06:55 | 002,108,959 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\tdsskiller.zip
[2012.06.09 10:40:38 | 000,001,563 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Call of Duty(R) 2 Singleplayer.lnk
[2012.06.09 10:40:38 | 000,001,563 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Call of Duty(R) 2 Multiplayer.lnk
[2012.06.09 10:40:37 | 000,000,287 | ---- | C] () -- C:\WINDOWS\game.ini
[2012.06.09 10:34:04 | 002,745,121 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\Blink-182---First-Date.mp3
[2012.06.09 10:30:33 | 094,318,732 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\2003-Blink-182-Blink-182.rar
[2012.06.08 23:48:15 | 012,089,946 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\km400_window_035.zip
[2012.06.08 23:19:54 | 000,020,736 | ---- | C] () -- C:\Documents and Settings\Administrator\Dokumenty\cc_20120608_231952.reg
[2012.06.08 23:18:15 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2012.06.08 20:13:58 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012.06.08 20:13:55 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2012.06.08 17:54:00 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.08 17:53:11 | 000,029,233 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\[CzT]call_of_duty_2_cz.torrent
[2012.06.08 14:35:35 | 000,000,576 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\Zástupce - Wow.lnk
[2012.06.08 12:32:50 | 007,653,010 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\hfps_103.zip
[2012.06.08 10:13:09 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\SpeedFan.lnk
[2012.06.08 10:13:04 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2012.06.08 09:40:55 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\HijackThis.lnk
[2012.06.08 08:31:52 | 000,001,375 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Counter-Strike 1.6.lnk
[2012.06.08 08:31:15 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\µTorrent.lnk
[2012.06.08 08:30:25 | 000,001,613 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\DAEMON Tools Lite.lnk
[2012.06.08 08:11:57 | 000,000,396 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012.06.08 08:11:57 | 000,000,366 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2012.06.08 08:01:58 | 000,001,698 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft Security Essentials.lnk
[2012.06.08 07:17:13 | 000,001,912 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012.06.08 06:55:57 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.06.08 06:55:57 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012.06.08 06:47:07 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Adobe Reader X.lnk
[2012.06.08 06:47:07 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader X.lnk
[2012.06.08 06:42:32 | 000,000,837 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\TeamSpeak 3 Client.lnk
[2012.06.07 21:40:38 | 000,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF
[2012.06.07 21:40:32 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012.06.07 21:40:09 | 000,001,592 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2012.06.07 21:39:57 | 000,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2012.06.07 21:39:57 | 000,105,628 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2012.06.07 21:39:57 | 000,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2012.06.07 21:39:57 | 000,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2012.06.07 21:39:57 | 000,008,599 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2012.06.07 21:39:57 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2012.06.07 21:39:56 | 002,033,597 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2012.06.07 21:39:56 | 001,246,067 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2012.06.07 21:39:56 | 000,809,394 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2012.06.07 21:39:56 | 000,399,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2012.06.07 21:39:56 | 000,037,509 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2012.06.07 21:39:56 | 000,033,765 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2012.06.07 21:39:56 | 000,016,825 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2012.06.07 21:39:56 | 000,013,497 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2012.06.07 21:39:56 | 000,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2012.06.07 21:39:56 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2012.06.07 21:39:55 | 000,631,112 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2012.06.07 21:39:13 | 000,096,664 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.06.07 21:38:33 | 000,000,327 | RHS- | C] () -- C:\boot.ini
[2012.06.07 21:38:29 | 000,001,369 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2012.06.07 21:35:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MEMORY.DMP
[2012.06.07 21:24:53 | 000,000,905 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\MouseCaptureMonitor.lnk
[2012.06.07 21:24:40 | 000,002,643 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\A4tech USB Mouse Quality Test Program.lnk
[2012.06.07 21:23:43 | 000,001,954 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\X7 Oscar Editor.lnk
[2012.06.07 21:10:02 | 000,000,914 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.06.07 20:35:30 | 000,000,708 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\Total Commander.lnk
[2012.06.07 20:35:28 | 000,000,545 | ---- | C] () -- C:\WINDOWS\UC.PIF
[2012.06.07 20:35:28 | 000,000,545 | ---- | C] () -- C:\WINDOWS\RAR.PIF
[2012.06.07 20:35:28 | 000,000,545 | ---- | C] () -- C:\WINDOWS\NOCLOSE.PIF
[2012.06.07 20:35:28 | 000,000,545 | ---- | C] () -- C:\WINDOWS\LHA.PIF
[2012.06.07 20:35:28 | 000,000,545 | ---- | C] () -- C:\WINDOWS\ARJ.PIF
[2012.06.07 20:29:23 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2012.06.07 20:29:23 | 000,001,548 | ---- | C] () -- C:\Documents and Settings\Administrator\Plocha\MPC-HC.lnk
[2012.06.07 20:23:47 | 000,064,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2012.06.07 20:04:47 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2012.06.07 20:04:47 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Nefunkční.lnk
[2012.06.07 20:01:17 | 001,074,972 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2012.06.07 20:01:17 | 001,074,972 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2012.06.07 20:01:17 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2012.06.07 20:01:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvdrswr.lk
[2012.06.07 20:01:04 | 002,807,708 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2012.06.07 20:01:04 | 000,010,264 | ---- | C] () -- C:\WINDOWS\System32\nvinfo.pb
[2012.06.07 19:58:33 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Internet Explorer.lnk
[2012.06.07 19:58:14 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Outlook Express.lnk
[2012.06.07 19:58:04 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Vzdálená pomoc.lnk
[2012.06.07 19:58:04 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\Administrator\Nabídka Start\Programy\Windows Media Player.lnk
[2012.06.07 19:57:45 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2012.06.07 19:52:34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012.06.07 19:49:54 | 000,002,504 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.06.07 19:49:54 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2012.06.07 19:49:54 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2012.06.07 19:49:54 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2012.06.07 19:49:47 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2012.06.07 19:49:47 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2012.06.07 19:49:46 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2012.06.07 19:48:32 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Windows Movie Maker.lnk
[2012.06.07 19:48:01 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2012.06.07 19:48:01 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2012.06.07 19:46:22 | 000,000,615 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Windows Messenger.lnk
[2012.06.07 19:46:20 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012.06.07 19:45:21 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prérijní vítr.bmp
[2012.06.07 19:45:21 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Omítka Santa Fe.bmp
[2012.06.07 19:45:21 | 000,026,680 | ---- | C] () -- C:\WINDOWS\Řeka Sumida.bmp
[2012.06.07 19:45:21 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Zelený kámen.bmp
[2012.06.07 19:45:21 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rododendron.bmp
[2012.06.07 19:45:21 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Na rybách.bmp
[2012.06.07 19:45:21 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2012.06.07 19:45:20 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Mýdlové bubliny.bmp
[2012.06.07 19:45:20 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Zrnko kávy.bmp
[2012.06.07 19:45:20 | 000,016,730 | ---- | C] () -- C:\WINDOWS\Textura peří.bmp
[2012.06.07 19:45:20 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Modrá krajka 16.bmp
[2012.06.07 19:45:17 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2012.06.07 19:45:17 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2012.06.07 19:45:16 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2012.06.07 19:45:10 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc

========== LOP Check ==========

[2012.06.08 08:29:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\DAEMON Tools Lite
[2012.06.07 20:35:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\GHISLER
[2012.06.07 20:04:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\Opera
[2012.06.08 06:43:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\TS3Client
[2012.06.08 23:19:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
[2012.06.08 09:40:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2012.06.08 08:29:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2012.06.09 10:58:37 | 000,000,366 | -H-- | M] () -- C:\WINDOWS\Tasks\MpIdleTask.job

========== Purity Check ==========



< End of report >

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod jaro3 » 10 čer 2012 10:51

Ještě ten TDSSKiller , script OTL dodám.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 10 čer 2012 11:03

11:17:02.0609 3308 TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:16
11:17:02.0703 3308 ============================================================
11:17:02.0703 3308 Current date / time: 2012/06/09 11:17:02.0703
11:17:02.0703 3308 SystemInfo:
11:17:02.0703 3308
11:17:02.0703 3308 OS Version: 5.1.2600 ServicePack: 3.0
11:17:02.0703 3308 Product type: Workstation
11:17:02.0703 3308 ComputerName: KOMP
11:17:02.0703 3308 UserName: Administrator
11:17:02.0703 3308 Windows directory: C:\WINDOWS
11:17:02.0703 3308 System windows directory: C:\WINDOWS
11:17:02.0703 3308 Processor architecture: Intel x86
11:17:02.0703 3308 Number of processors: 1
11:17:02.0703 3308 Page size: 0x1000
11:17:02.0703 3308 Boot type: Normal boot
11:17:02.0703 3308 ============================================================
11:17:04.0046 3308 Drive \Device\Harddisk0\DR0 - Size: 0x1B34367A00 (108.82 Gb), SectorSize: 0x200, Cylinders: 0x377D, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
11:17:04.0046 3308 ============================================================
11:17:04.0046 3308 \Device\Harddisk0\DR0:
11:17:04.0046 3308 MBR partitions:
11:17:04.0046 3308 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x504FBBB
11:17:04.0062 3308 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x504FC39, BlocksNum 0x894E043
11:17:04.0062 3308 ============================================================
11:17:04.0109 3308 D: <-> \Device\Harddisk0\DR0\Partition1
11:17:04.0125 3308 C: <-> \Device\Harddisk0\DR0\Partition0
11:17:04.0125 3308 ============================================================
11:17:04.0125 3308 Initialize success
11:17:04.0125 3308 ============================================================
11:17:05.0953 3372 ============================================================
11:17:05.0953 3372 Scan started
11:17:05.0953 3372 Mode: Manual;
11:17:05.0953 3372 ============================================================
11:17:06.0703 3372 Abiosdsk - ok
11:17:06.0750 3372 abp480n5 - ok
11:17:06.0812 3372 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:17:06.0828 3372 ACPI - ok
11:17:06.0875 3372 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
11:17:06.0875 3372 ACPIEC - ok
11:17:07.0000 3372 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
11:17:07.0015 3372 AdobeFlashPlayerUpdateSvc - ok
11:17:07.0046 3372 adpu160m - ok
11:17:07.0109 3372 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
11:17:07.0109 3372 aeaudio - ok
11:17:07.0171 3372 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
11:17:07.0187 3372 aec - ok
11:17:07.0265 3372 AFD (f6b7b1ecd7b41736bdb6ff4b092bcb79) C:\WINDOWS\System32\drivers\afd.sys
11:17:07.0281 3372 AFD - ok
11:17:07.0312 3372 Aha154x - ok
11:17:07.0359 3372 aic78u2 - ok
11:17:07.0390 3372 aic78xx - ok
11:17:07.0453 3372 Alerter (e0a6fa244b8624d78fe5ff6f56a33bae) C:\WINDOWS\system32\alrsvc.dll
11:17:07.0453 3372 Alerter - ok
11:17:07.0500 3372 ALG (88842de939a827577bf24243699ac80a) C:\WINDOWS\System32\alg.exe
11:17:07.0515 3372 ALG - ok
11:17:07.0546 3372 AliIde - ok
11:17:07.0593 3372 AmdK7 (3980814f8027d27ea003e2e3d9d4f604) C:\WINDOWS\system32\DRIVERS\amdk7.sys
11:17:07.0593 3372 AmdK7 - ok
11:17:07.0640 3372 amsint - ok
11:17:07.0687 3372 AppMgmt (6b8e7a90e576d4fe308f97c69060a171) C:\WINDOWS\System32\appmgmts.dll
11:17:07.0703 3372 AppMgmt - ok
11:17:07.0750 3372 asc - ok
11:17:07.0796 3372 asc3350p - ok
11:17:07.0843 3372 asc3550 - ok
11:17:07.0984 3372 aspnet_state (4eabf511b1af176a971c3271e48fa3a8) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
11:17:08.0000 3372 aspnet_state - ok
11:17:08.0078 3372 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:17:08.0078 3372 AsyncMac - ok
11:17:08.0125 3372 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
11:17:08.0125 3372 atapi - ok
11:17:08.0171 3372 Atdisk - ok
11:17:08.0218 3372 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:17:08.0234 3372 Atmarpc - ok
11:17:08.0281 3372 AudioSrv (de31b88962a8645dba5a37b993e7b0f1) C:\WINDOWS\System32\audiosrv.dll
11:17:08.0281 3372 AudioSrv - ok
11:17:08.0328 3372 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
11:17:08.0328 3372 audstub - ok
11:17:08.0375 3372 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
11:17:08.0375 3372 Beep - ok
11:17:08.0437 3372 BITS (19395d092fd85ddc2d9c7729cf5a2ac8) C:\WINDOWS\system32\qmgr.dll
11:17:08.0453 3372 BITS - ok
11:17:08.0500 3372 Browser (249276d3ef1e74b992299cb96099e4d7) C:\WINDOWS\System32\browser.dll
11:17:08.0515 3372 Browser - ok
11:17:08.0578 3372 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
11:17:08.0578 3372 cbidf2k - ok
11:17:08.0625 3372 cd20xrnt - ok
11:17:08.0671 3372 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
11:17:08.0671 3372 Cdaudio - ok
11:17:08.0937 3372 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
11:17:08.0953 3372 Cdfs - ok
11:17:09.0000 3372 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:17:09.0015 3372 Cdrom - ok
11:17:09.0078 3372 Changer - ok
11:17:09.0125 3372 CiSvc (e390dc1d7c461d7d56ec53402f329928) C:\WINDOWS\system32\cisvc.exe
11:17:09.0125 3372 CiSvc - ok
11:17:09.0171 3372 ClipSrv (064507a8dfa8c5c7e2ffddd3e6f424fa) C:\WINDOWS\system32\clipsrv.exe
11:17:09.0171 3372 ClipSrv - ok
11:17:09.0203 3372 clr_optimization_v2.0.50727_32 (234b1bc2796483e1f5c3f26649fb3388) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:17:09.0234 3372 clr_optimization_v2.0.50727_32 - ok
11:17:09.0281 3372 CmdIde - ok
11:17:09.0328 3372 COMSysApp - ok
11:17:09.0406 3372 Cpqarray - ok
11:17:09.0468 3372 CryptSvc (f3ab0933cbd166d271992f411c27ccaf) C:\WINDOWS\System32\cryptsvc.dll
11:17:09.0484 3372 CryptSvc - ok
11:17:09.0515 3372 dac2w2k - ok
11:17:09.0578 3372 dac960nt - ok
11:17:09.0640 3372 DcomLaunch (be27674d1cbc3214aec84b4336a38bbf) C:\WINDOWS\system32\rpcss.dll
11:17:09.0656 3372 DcomLaunch - ok
11:17:09.0718 3372 Dhcp (8c9a53e285ac5e6704844d0459ec85be) C:\WINDOWS\System32\dhcpcsvc.dll
11:17:09.0734 3372 Dhcp - ok
11:17:09.0765 3372 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
11:17:09.0765 3372 Disk - ok
11:17:09.0828 3372 dmadmin - ok
11:17:09.0906 3372 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
11:17:09.0937 3372 dmboot - ok
11:17:09.0984 3372 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
11:17:10.0000 3372 dmio - ok
11:17:10.0046 3372 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
11:17:10.0078 3372 dmload - ok
11:17:10.0109 3372 dmserver (2bfefe9e865655a76982f050450b9591) C:\WINDOWS\System32\dmserver.dll
11:17:10.0109 3372 dmserver - ok
11:17:10.0171 3372 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
11:17:10.0187 3372 DMusic - ok
11:17:10.0250 3372 Dnscache (adb285644a95431ccedc7c706090936d) C:\WINDOWS\System32\dnsrslvr.dll
11:17:10.0250 3372 Dnscache - ok
11:17:10.0296 3372 Dot3svc (4a3e2bd20157a0946751229e92eb8621) C:\WINDOWS\System32\dot3svc.dll
11:17:10.0312 3372 Dot3svc - ok
11:17:10.0343 3372 dpti2o - ok
11:17:10.0359 3372 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
11:17:10.0359 3372 drmkaud - ok
11:17:10.0437 3372 dtsoftbus01 (687af6bb383885ff6a64071b189a7f3e) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
11:17:10.0468 3372 dtsoftbus01 - ok
11:17:10.0531 3372 EapHost (0887d9c2be8d940778cad1e3b85f2a41) C:\WINDOWS\System32\eapsvc.dll
11:17:10.0531 3372 EapHost - ok
11:17:10.0562 3372 ERSvc (a2a4912798f2be706abadd3d30800d16) C:\WINDOWS\System32\ersvc.dll
11:17:10.0562 3372 ERSvc - ok
11:17:10.0656 3372 Eventlog (9ef697af07bb8dd82c3b02ca953a95b7) C:\WINDOWS\system32\services.exe
11:17:10.0671 3372 Eventlog - ok
11:17:10.0718 3372 EventSystem (be68ea4457e2e5717231cf91be5448e0) C:\WINDOWS\system32\es.dll
11:17:10.0718 3372 EventSystem - ok
11:17:10.0781 3372 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
11:17:10.0796 3372 Fastfat - ok
11:17:10.0875 3372 FastUserSwitchingCompatibility (54a6bf743e0517528a5064ceaeb40ea7) C:\WINDOWS\System32\shsvcs.dll
11:17:10.0890 3372 FastUserSwitchingCompatibility - ok
11:17:10.0937 3372 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
11:17:10.0937 3372 Fdc - ok
11:17:10.0968 3372 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys
11:17:10.0968 3372 FETNDIS - ok
11:17:11.0015 3372 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
11:17:11.0015 3372 Fips - ok
11:17:11.0062 3372 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
11:17:11.0062 3372 Flpydisk - ok
11:17:11.0109 3372 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
11:17:11.0140 3372 FltMgr - ok
11:17:11.0250 3372 FontCache3.0.0.0 (993883524aa9cf1c90e1545411a9ac9c) C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:17:11.0250 3372 FontCache3.0.0.0 - ok
11:17:11.0296 3372 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:17:11.0296 3372 Fs_Rec - ok
11:17:11.0343 3372 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:17:11.0359 3372 Ftdisk - ok
11:17:11.0406 3372 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
11:17:11.0406 3372 gameenum - ok
11:17:11.0453 3372 giveio (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys
11:17:11.0468 3372 giveio - ok
11:17:11.0515 3372 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:17:11.0515 3372 Gpc - ok
11:17:11.0578 3372 helpsvc (fcfe31fb75f8a6295b6b0af87a626282) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
11:17:11.0578 3372 helpsvc - ok
11:17:11.0640 3372 HidServ (00e25ee90166b3e1be6e74aebf858306) C:\WINDOWS\System32\hidserv.dll
11:17:11.0640 3372 HidServ - ok
11:17:11.0718 3372 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
11:17:11.0718 3372 hidusb - ok
11:17:11.0781 3372 hkmsvc (7a6b320928f86bc851530d63c82965d9) C:\WINDOWS\System32\kmsvc.dll
11:17:11.0796 3372 hkmsvc - ok
11:17:11.0828 3372 hpn - ok
11:17:11.0906 3372 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
11:17:11.0937 3372 HTTP - ok
11:17:11.0984 3372 HTTPFilter (58fe2f2da3bc5573f4a35b3760d3125f) C:\WINDOWS\System32\w3ssl.dll
11:17:11.0984 3372 HTTPFilter - ok
11:17:12.0031 3372 i2omgmt - ok
11:17:12.0062 3372 i2omp - ok
11:17:12.0125 3372 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:17:12.0125 3372 i8042prt - ok
11:17:12.0250 3372 idsvc (e7cc3aeaed9893a88876744cd439f76c) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:17:12.0281 3372 idsvc - ok
11:17:12.0328 3372 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
11:17:12.0328 3372 Imapi - ok
11:17:12.0390 3372 ImapiService (f7b93aafad33b2320954c17e26c8d361) C:\WINDOWS\system32\imapi.exe
11:17:12.0390 3372 ImapiService - ok
11:17:12.0468 3372 ini910u - ok
11:17:12.0531 3372 IntelIde - ok
11:17:12.0578 3372 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
11:17:12.0578 3372 Ip6Fw - ok
11:17:12.0640 3372 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:17:12.0640 3372 IpFilterDriver - ok
11:17:12.0671 3372 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:17:12.0671 3372 IpInIp - ok
11:17:12.0734 3372 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:17:12.0734 3372 IpNat - ok
11:17:12.0796 3372 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:17:12.0812 3372 IPSec - ok
11:17:12.0875 3372 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
11:17:12.0875 3372 IRENUM - ok
11:17:12.0953 3372 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:17:12.0968 3372 isapnp - ok
11:17:13.0109 3372 JavaQuickStarterService (a1509ba3a5fdc5366146e92b3d130eb5) C:\Program Files\Java\jre7\bin\jqs.exe
11:17:13.0109 3372 JavaQuickStarterService - ok
11:17:13.0171 3372 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:17:13.0171 3372 Kbdclass - ok
11:17:13.0218 3372 kbdhid (86c8f23616c6c6e5b2776901c17b945b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
11:17:13.0234 3372 kbdhid - ok
11:17:13.0281 3372 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
11:17:13.0296 3372 kmixer - ok
11:17:13.0359 3372 KSecDD (c6ebf1d6ad71df30db49b8d3287e1368) C:\WINDOWS\system32\drivers\KSecDD.sys
11:17:13.0375 3372 KSecDD - ok
11:17:13.0421 3372 LanmanServer (21920ac69594ab021237054fa728fe46) C:\WINDOWS\System32\srvsvc.dll
11:17:13.0437 3372 LanmanServer - ok
11:17:13.0515 3372 lanmanworkstation (9a2e7ee3989aac0079e9d23555545d52) C:\WINDOWS\System32\wkssvc.dll
11:17:13.0531 3372 lanmanworkstation - ok
11:17:13.0562 3372 lbrtfdc - ok
11:17:13.0671 3372 LmHosts (0ab159f536e3e8f7f07113702a07cca5) C:\WINDOWS\System32\lmhsvc.dll
11:17:13.0671 3372 LmHosts - ok
11:17:13.0718 3372 Messenger (221cd1c815b8a6b79389c3f5d1018de8) C:\WINDOWS\System32\msgsvc.dll
11:17:13.0750 3372 Messenger - ok
11:17:13.0796 3372 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
11:17:13.0796 3372 mnmdd - ok
11:17:13.0859 3372 mnmsrvc (9a57d046f88f4b69751b11fd40088a61) C:\WINDOWS\system32\mnmsrvc.exe
11:17:13.0859 3372 mnmsrvc - ok
11:17:13.0906 3372 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
11:17:13.0906 3372 Modem - ok
11:17:13.0953 3372 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:17:13.0953 3372 Mouclass - ok
11:17:14.0031 3372 Moufiltr (956bd3a1db91f7e2b9153ee7600d5648) C:\WINDOWS\system32\DRIVERS\Moufiltr.sys
11:17:14.0031 3372 Moufiltr - ok
11:17:14.0078 3372 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
11:17:14.0078 3372 mouhid - ok
11:17:14.0125 3372 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
11:17:14.0125 3372 MountMgr - ok
11:17:14.0187 3372 MouseCap (d0ac7ac40fff21056b1a3401361958ca) C:\WINDOWS\system32\Drivers\MouseCap.sys
11:17:14.0187 3372 MouseCap - ok
11:17:14.0265 3372 MpFilter (d993bea500e7382dc4e760bf4f35efcb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
11:17:14.0265 3372 MpFilter - ok
11:17:14.0312 3372 mraid35x - ok
11:17:14.0359 3372 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:17:14.0375 3372 MRxDAV - ok
11:17:14.0437 3372 MRxSmb (fb2fccc70f7174c7bf64f48e96d3adf4) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:17:14.0468 3372 MRxSmb - ok
11:17:14.0515 3372 MSDTC (6db4d1521caba9a5ffab54ade0ae867d) C:\WINDOWS\system32\msdtc.exe
11:17:14.0515 3372 MSDTC - ok
11:17:14.0578 3372 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
11:17:14.0578 3372 Msfs - ok
11:17:14.0609 3372 MSIServer - ok
11:17:14.0687 3372 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:17:14.0687 3372 MSKSSRV - ok
11:17:14.0781 3372 MsMpSvc (24516bf4e12a46cb67302e2cdcb8cddf) c:\Program Files\Microsoft Security Client\MsMpEng.exe
11:17:14.0781 3372 MsMpSvc - ok
11:17:14.0828 3372 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:17:14.0828 3372 MSPCLOCK - ok
11:17:14.0859 3372 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
11:17:14.0859 3372 MSPQM - ok
11:17:14.0906 3372 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:17:14.0906 3372 mssmbios - ok
11:17:14.0937 3372 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
11:17:14.0953 3372 Mup - ok
11:17:15.0015 3372 napagent (6ea362e9db03d44f6b996f4d8be237e9) C:\WINDOWS\System32\qagentrt.dll
11:17:15.0031 3372 napagent - ok
11:17:15.0093 3372 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
11:17:15.0109 3372 NDIS - ok
11:17:15.0156 3372 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:17:15.0171 3372 NdisTapi - ok
11:17:15.0187 3372 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:17:15.0203 3372 Ndisuio - ok
11:17:15.0250 3372 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:17:15.0265 3372 NdisWan - ok
11:17:15.0328 3372 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
11:17:15.0328 3372 NDProxy - ok
11:17:15.0375 3372 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
11:17:15.0375 3372 NetBIOS - ok
11:17:15.0437 3372 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
11:17:15.0453 3372 NetBT - ok
11:17:15.0500 3372 NetDDE (933de774986ec85e48210c44ab431de6) C:\WINDOWS\system32\netdde.exe
11:17:15.0500 3372 NetDDE - ok
11:17:15.0546 3372 NetDDEdsdm (933de774986ec85e48210c44ab431de6) C:\WINDOWS\system32\netdde.exe
11:17:15.0546 3372 NetDDEdsdm - ok
11:17:15.0609 3372 Netlogon (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
11:17:15.0609 3372 Netlogon - ok
11:17:15.0671 3372 Netman (72e1e9e2977be08bdeedb6d8fd9d4d40) C:\WINDOWS\System32\netman.dll
11:17:15.0687 3372 Netman - ok
11:17:15.0796 3372 NetTcpPortSharing (f9102685f97f9ba85f4a70afcf722cfe) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:17:15.0812 3372 NetTcpPortSharing - ok
11:17:15.0890 3372 Nla (b6cec406351ea5ef131416d5f52d006f) C:\WINDOWS\System32\mswsock.dll
11:17:15.0890 3372 Nla - ok
11:17:15.0937 3372 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
11:17:15.0937 3372 Npfs - ok
11:17:16.0000 3372 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
11:17:16.0031 3372 Ntfs - ok
11:17:16.0062 3372 NtLmSsp (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
11:17:16.0062 3372 NtLmSsp - ok
11:17:16.0140 3372 NtmsSvc (023dd70573d644f3d9c8b1258a7bfd08) C:\WINDOWS\system32\ntmssvc.dll
11:17:16.0156 3372 NtmsSvc - ok
11:17:16.0218 3372 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
11:17:16.0218 3372 Null - ok
11:17:16.0953 3372 nv (7b5a17bd54bb9142843dbe99a1caaed8) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
11:17:17.0359 3372 nv - ok
11:17:17.0546 3372 NVSvc (5150b108ea88831e1c599603d8b89621) C:\WINDOWS\system32\nvsvc32.exe
11:17:17.0562 3372 NVSvc - ok
11:17:17.0734 3372 nvUpdatusService (83e8ab7bb3c8956c53fec071c94f0bbb) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
11:17:17.0765 3372 nvUpdatusService - ok
11:17:17.0828 3372 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:17:17.0828 3372 NwlnkFlt - ok
11:17:17.0859 3372 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:17:17.0859 3372 NwlnkFwd - ok
11:17:17.0937 3372 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
11:17:17.0953 3372 Parport - ok
11:17:18.0015 3372 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
11:17:18.0015 3372 PartMgr - ok
11:17:18.0062 3372 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
11:17:18.0062 3372 ParVdm - ok
11:17:18.0125 3372 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
11:17:18.0140 3372 PCI - ok
11:17:18.0171 3372 PCIDump - ok
11:17:18.0234 3372 PCIIde - ok
11:17:18.0281 3372 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
11:17:18.0296 3372 Pcmcia - ok
11:17:18.0328 3372 PDCOMP - ok
11:17:18.0375 3372 PDFRAME - ok
11:17:18.0406 3372 PDRELI - ok
11:17:18.0453 3372 PDRFRAME - ok
11:17:18.0500 3372 perc2 - ok
11:17:18.0546 3372 perc2hib - ok
11:17:18.0687 3372 PlugPlay (9ef697af07bb8dd82c3b02ca953a95b7) C:\WINDOWS\system32\services.exe
11:17:18.0687 3372 PlugPlay - ok
11:17:18.0734 3372 PolicyAgent (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
11:17:18.0734 3372 PolicyAgent - ok
11:17:18.0796 3372 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:17:18.0812 3372 PptpMiniport - ok
11:17:18.0828 3372 ProtectedStorage (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
11:17:18.0828 3372 ProtectedStorage - ok
11:17:18.0875 3372 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
11:17:18.0890 3372 PSched - ok
11:17:18.0890 3372 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:17:18.0890 3372 Ptilink - ok
11:17:18.0937 3372 ql1080 - ok
11:17:18.0968 3372 Ql10wnt - ok
11:17:19.0015 3372 ql12160 - ok
11:17:19.0031 3372 ql1240 - ok
11:17:19.0062 3372 ql1280 - ok
11:17:19.0109 3372 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:17:19.0109 3372 RasAcd - ok
11:17:19.0171 3372 RasAuto (2b5e44ea009f2f374b980e1e9a70635d) C:\WINDOWS\System32\rasauto.dll
11:17:19.0187 3372 RasAuto - ok
11:17:19.0218 3372 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:17:19.0250 3372 Rasl2tp - ok
11:17:19.0312 3372 RasMan (d57554c664b64604bd1ee13ea2c07e77) C:\WINDOWS\System32\rasmans.dll
11:17:19.0312 3372 RasMan - ok
11:17:19.0359 3372 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:17:19.0359 3372 RasPppoe - ok
11:17:19.0406 3372 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
11:17:19.0406 3372 Raspti - ok
11:17:19.0468 3372 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:17:19.0468 3372 Rdbss - ok
11:17:19.0531 3372 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:17:19.0546 3372 RDPCDD - ok
11:17:19.0625 3372 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
11:17:19.0640 3372 rdpdr - ok
11:17:19.0718 3372 RDPWD (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
11:17:19.0734 3372 RDPWD - ok
11:17:19.0828 3372 RDSessMgr (c0d9d9711cb74ee9bc66353d8cbdab0e) C:\WINDOWS\system32\sessmgr.exe
11:17:19.0828 3372 RDSessMgr - ok
11:17:19.0890 3372 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
11:17:19.0906 3372 redbook - ok
11:17:19.0968 3372 RemoteAccess (127c26b5371651043450e52542099aba) C:\WINDOWS\System32\mprdim.dll
11:17:19.0984 3372 RemoteAccess - ok
11:17:20.0046 3372 RemoteRegistry (8f31505484a190d5b22274708799f4ec) C:\WINDOWS\system32\regsvc.dll
11:17:20.0062 3372 RemoteRegistry - ok
11:17:20.0125 3372 RpcLocator (718b3bdc0bc3c2f7d065a53d26202af9) C:\WINDOWS\system32\locator.exe
11:17:20.0140 3372 RpcLocator - ok
11:17:20.0203 3372 RpcSs (be27674d1cbc3214aec84b4336a38bbf) C:\WINDOWS\System32\rpcss.dll
11:17:20.0203 3372 RpcSs - ok
11:17:20.0281 3372 RSVP (09ab2e71e58b078038e3bfdba7ffc984) C:\WINDOWS\system32\rsvp.exe
11:17:20.0296 3372 RSVP - ok
11:17:20.0343 3372 SamSs (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
11:17:20.0343 3372 SamSs - ok
11:17:20.0406 3372 SCardSvr (410046e401eb11e1e6749e9deea41d4a) C:\WINDOWS\System32\SCardSvr.exe
11:17:20.0421 3372 SCardSvr - ok
11:17:20.0484 3372 Schedule (3ff232a7731621b8902d81d42418c93c) C:\WINDOWS\system32\schedsvc.dll
11:17:20.0500 3372 Schedule - ok
11:17:20.0578 3372 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:17:20.0578 3372 Secdrv - ok
11:17:20.0625 3372 seclogon (477e2c3cc5e4a0d635bcb0ea8dcac3c6) C:\WINDOWS\System32\seclogon.dll
11:17:20.0625 3372 seclogon - ok
11:17:20.0671 3372 SENS (a530b75c10c23c9ab28fdb6ce719e21f) C:\WINDOWS\system32\sens.dll
11:17:20.0671 3372 SENS - ok
11:17:20.0734 3372 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
11:17:20.0734 3372 serenum - ok
11:17:20.0828 3372 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
11:17:20.0843 3372 Serial - ok
11:17:20.0937 3372 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
11:17:20.0937 3372 Sfloppy - ok
11:17:21.0015 3372 SharedAccess (19c016c79db4d1a840b9d5a20d7eca54) C:\WINDOWS\System32\ipnathlp.dll
11:17:21.0046 3372 SharedAccess - ok
11:17:21.0125 3372 ShellHWDetection (54a6bf743e0517528a5064ceaeb40ea7) C:\WINDOWS\System32\shsvcs.dll
11:17:21.0125 3372 ShellHWDetection - ok
11:17:21.0171 3372 Simbad - ok
11:17:21.0281 3372 smwdm (1d381a07361e4d6a8be95026b3eba47a) C:\WINDOWS\system32\drivers\smwdm.sys
11:17:21.0296 3372 smwdm - ok
11:17:21.0375 3372 SoundMAX Agent Service (default) (3978f082274f723ad5a0a8058c2417dd) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
11:17:21.0375 3372 SoundMAX Agent Service (default) - ok
11:17:21.0406 3372 Sparrow - ok
11:17:21.0468 3372 speedfan (d703f972d23867dfd4ee9a9ef9cb767e) C:\WINDOWS\system32\speedfan.sys
11:17:21.0468 3372 speedfan - ok
11:17:21.0531 3372 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
11:17:21.0531 3372 splitter - ok
11:17:21.0609 3372 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
11:17:21.0625 3372 Spooler - ok
11:17:21.0687 3372 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
11:17:21.0703 3372 sr - ok
11:17:21.0750 3372 srservice (35b91147124f64ac8081a2edb9ea4dee) C:\WINDOWS\system32\srsvc.dll
11:17:21.0765 3372 srservice - ok
11:17:21.0843 3372 Srv (9b390283569ea58d43d2586032b892f5) C:\WINDOWS\system32\DRIVERS\srv.sys
11:17:21.0843 3372 Srv - ok
11:17:21.0890 3372 SSDPSRV (becd5271dc4e3b7c3d035f790fcbc1e5) C:\WINDOWS\System32\ssdpsrv.dll
11:17:21.0906 3372 SSDPSRV - ok
11:17:22.0000 3372 stisvc (c1cdd9275f6a115bb0ae1d55d8d27ba6) C:\WINDOWS\system32\wiaservc.dll
11:17:22.0000 3372 stisvc - ok
11:17:22.0062 3372 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
11:17:22.0062 3372 swenum - ok
11:17:22.0109 3372 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
11:17:22.0125 3372 swmidi - ok
11:17:22.0156 3372 SwPrv - ok
11:17:22.0187 3372 symc810 - ok
11:17:22.0234 3372 symc8xx - ok
11:17:22.0265 3372 sym_hi - ok
11:17:22.0312 3372 sym_u3 - ok
11:17:22.0359 3372 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
11:17:22.0375 3372 sysaudio - ok
11:17:22.0437 3372 SysmonLog (ce06f01b88ace199a1bf460cac29c110) C:\WINDOWS\system32\smlogsvc.exe
11:17:22.0437 3372 SysmonLog - ok
11:17:22.0500 3372 TapiSrv (c2546cd7a398476f9df5614b2ae160e8) C:\WINDOWS\System32\tapisrv.dll
11:17:22.0515 3372 TapiSrv - ok
11:17:22.0593 3372 Tcpip (ad978a1b783b5719720cff204b666c8e) C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:17:22.0609 3372 Tcpip - ok
11:17:22.0656 3372 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
11:17:22.0656 3372 TDPIPE - ok
11:17:22.0718 3372 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
11:17:22.0734 3372 TDTCP - ok
11:17:22.0781 3372 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
11:17:22.0781 3372 TermDD - ok
11:17:22.0828 3372 TermService (a75dd6fc3dbee4fff5ebc9f2c28bb66e) C:\WINDOWS\System32\termsrv.dll
11:17:22.0843 3372 TermService - ok
11:17:22.0906 3372 Themes (54a6bf743e0517528a5064ceaeb40ea7) C:\WINDOWS\System32\shsvcs.dll
11:17:22.0906 3372 Themes - ok
11:17:22.0984 3372 TlntSvr (cd0cc7b167d78043a41c98d4921efb54) C:\WINDOWS\system32\tlntsvr.exe
11:17:23.0000 3372 TlntSvr - ok
11:17:23.0031 3372 TosIde - ok
11:17:23.0093 3372 TrkWks (38853304ccb938d30e0c4cde8d2c2a8a) C:\WINDOWS\system32\trkwks.dll
11:17:23.0109 3372 TrkWks - ok
11:17:23.0171 3372 uagp35 (d85938f272d1bcf3db3a31fc0a048928) C:\WINDOWS\system32\DRIVERS\uagp35.sys
11:17:23.0171 3372 uagp35 - ok
11:17:23.0250 3372 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
11:17:23.0265 3372 Udfs - ok
11:17:23.0296 3372 ultra - ok
11:17:23.0375 3372 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
11:17:23.0390 3372 Update - ok
11:17:23.0484 3372 upnphost (651bd90dcee5b7bdc74a2eb7c9266f9e) C:\WINDOWS\System32\upnphost.dll
11:17:23.0500 3372 upnphost - ok
11:17:23.0546 3372 UPS (20a0f6a11959e92908717d09e87d670d) C:\WINDOWS\System32\ups.exe
11:17:23.0562 3372 UPS - ok
11:17:23.0625 3372 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
11:17:23.0625 3372 usbccgp - ok
11:17:23.0671 3372 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:17:23.0671 3372 usbehci - ok
11:17:23.0734 3372 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:17:23.0750 3372 usbhub - ok
11:17:23.0796 3372 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
11:17:23.0796 3372 usbuhci - ok
11:17:23.0828 3372 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
11:17:23.0828 3372 VgaSave - ok
11:17:23.0875 3372 viaagp1 (0e3e3fae3a0a58b8d936a8e841a17d16) C:\WINDOWS\system32\DRIVERS\viaagp1.sys
11:17:23.0875 3372 viaagp1 - ok
11:17:23.0890 3372 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
11:17:23.0906 3372 ViaIde - ok
11:17:23.0937 3372 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
11:17:23.0953 3372 VolSnap - ok
11:17:24.0000 3372 VSS (d6ba1a63d9e00933f1cd2a885573afb2) C:\WINDOWS\System32\vssvc.exe
11:17:24.0015 3372 VSS - ok
11:17:24.0078 3372 W32Time (298c47e71f7da78d264f88c9f5a27f15) C:\WINDOWS\system32\w32time.dll
11:17:24.0093 3372 W32Time - ok
11:17:24.0140 3372 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:17:24.0156 3372 Wanarp - ok
11:17:24.0187 3372 WDICA - ok
11:17:24.0250 3372 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
11:17:24.0265 3372 wdmaud - ok
11:17:24.0312 3372 WebClient (47ae51048a82dfa1cd6b51d369f7e169) C:\WINDOWS\System32\webclnt.dll
11:17:24.0328 3372 WebClient - ok
11:17:24.0453 3372 winmgmt (e488332126e3b1182d2b8a0c35408ec6) C:\WINDOWS\system32\wbem\WMIsvc.dll
11:17:24.0468 3372 winmgmt - ok
11:17:24.0531 3372 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\mspmsnsv.dll
11:17:24.0546 3372 WmdmPmSN - ok
11:17:24.0640 3372 Wmi (0171cff34bba8c5977f18c48d8aef8c6) C:\WINDOWS\System32\advapi32.dll
11:17:24.0656 3372 Wmi - ok
11:17:24.0734 3372 WmiApSrv (23f6f03272f7e5679f1f050aed5acee6) C:\WINDOWS\system32\wbem\wmiapsrv.exe
11:17:24.0750 3372 WmiApSrv - ok
11:17:24.0875 3372 WMPNetworkSvc (3739866d20abd42f26a7b85f9e2560af) C:\Program Files\Windows Media Player\WMPNetwk.exe
11:17:24.0906 3372 WMPNetworkSvc - ok
11:17:24.0968 3372 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
11:17:24.0968 3372 WS2IFSL - ok
11:17:25.0015 3372 wscsvc (4c86d5faf78194995af9cc1075f65dd3) C:\WINDOWS\system32\wscsvc.dll
11:17:25.0046 3372 wscsvc - ok
11:17:25.0109 3372 wuauserv (c1364564800ee9784192145324a23308) C:\WINDOWS\system32\wuauserv.dll
11:17:25.0125 3372 wuauserv - ok
11:17:25.0171 3372 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:17:25.0187 3372 WudfPf - ok
11:17:25.0218 3372 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
11:17:25.0234 3372 WudfRd - ok
11:17:25.0281 3372 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
11:17:25.0296 3372 WudfSvc - ok
11:17:25.0375 3372 WZCSVC (a27d4ba7264c0bf52f32d10405bea1d4) C:\WINDOWS\System32\wzcsvc.dll
11:17:25.0390 3372 WZCSVC - ok
11:17:25.0453 3372 xmlprov (eaa4bb9edb3fb10cf8979fe65e63658f) C:\WINDOWS\System32\xmlprov.dll
11:17:25.0468 3372 xmlprov - ok
11:17:25.0515 3372 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
11:17:25.0953 3372 \Device\Harddisk0\DR0 - ok
11:17:25.0984 3372 Boot (0x1200) (8ca4bc6f38dac93f21aadeb8ddb78e05) \Device\Harddisk0\DR0\Partition0
11:17:25.0984 3372 \Device\Harddisk0\DR0\Partition0 - ok
11:17:26.0015 3372 Boot (0x1200) (cb93008e765c1248977d2d2eaf08a2c8) \Device\Harddisk0\DR0\Partition1
11:17:26.0015 3372 \Device\Harddisk0\DR0\Partition1 - ok
11:17:26.0031 3372 ============================================================
11:17:26.0031 3372 Scan finished
11:17:26.0031 3372 ============================================================
11:17:26.0078 3284 Detected object count: 0
11:17:26.0078 3284 Actual detected object count: 0
11:17:34.0515 3412 Deinitialize success

Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 10 čer 2012 21:53

Chtěl bych dodat , že tento pc jsem dostal není to zrovna nejlepší pc , ale je to lepší než to co jsem měl předtím a když jsem ho dostal zapl tak tam jela Mozzila uplně v pořádku potom sem to ten den ještě přeinstaloval a od té doby mi to dělá takovéhle chyby.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod jaro3 » 10 čer 2012 23:55

Si přeinstalovával windows , i když to předtím šlo? Proč?

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (aswMBR) -- C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\aswMBR.sys File not found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={FDE87C9F-F409-496C-8F1E-586431DC5A72}&mid=9dc44eaee74447d0b416d147e0890252-bbb3d8d61ef6b68186f44149e3aba39e4a3bf32e&lang=en&ds=yu012&pr=sa&d=2012-06-08 09:42:06&v=11.1.0.7&sap=dsp&q={searchTerms}
O1 HOSTS File: ([2012.06.08 22:07:26 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O18 - Protocol\Handler\msdaipp - No CLSID value found

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\WINDOWS\System32\CleanUp.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
C:\Documents and Settings\Administrator\Plocha\aswMBR.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Documents and Settings\Administrator\Plocha\TDSSKiller.exe
ipconfig /flushdns /c

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" =-

:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

********************************************************************************************************************************************
Spousta chyb:
Error - 8.6.2012 1:48:08 | Computer Name = KOMP | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF66 Description:. 0x8004FF66.
Error - 9.6.2012 4:27:53 | Computer Name = KOMP | Source = MsiInstaller | ID = 11704
Description = Product: ISScript -- Error 1704.An installation for Microsoft .NET
Framework 2.0 Service Pack 2 is currently suspended. You must undo the changes
made by that installation to continue. Do you want to undo those changes?

Microsoft .NET
Framework:
Vyzkoušet toto:
Stáhni .Net Cleanup Utility z tohoto odkazu:
http://cid-27e6a35d1a492af7.skydrive.li ... p_tool.zip
kliknout na tlačítko: Download; nebo obrázek složky.
Použij Cleanup Tool a odinstaluj .Net Framework 1.0, 1.1, 2.0. 3.0 a 3.5 ( cleanup tool Ti nedovolí odinstalovat .NET Framework 2.0 na Vistě a výš protože to je součástí systému.)
Restartuj počítač
Stáhni následující komponenty

.Net Framework 3.5 SP1 (toto nainstaluje zaroven.Net Framework 2.0 SP2 a 3.0 SP2)
.Net Framework 1.1
.Net Framework 1.1 SP1
.Net Framework 3.5 SP1:

http://www.microsoft.com/downloads/deta ... laylang=en

.Net Framework 1.1 :
http://www.microsoft.com/downloads/deta ... 4d1e7cf3a3

.Net Framework 1.1 SP1 :

http://www.microsoft.com/downloads/deta ... laylang=en

Instaluj stažené soubory v tomto pořadí!:

.Net Framework 3.5 SP1
.Net Framework 1.1
.Net Framework 1.1 SP1
********************************************************************************************************************************************
Error - 8.6.2012 16:06:20 | Computer Name = KOMP | Source = PlugPlayManager | ID = 11
Description = Zařízení Root\LEGACY_AIDA64DRIVER\0000 se již v systému nenachází,
přestože nebylo nejdříve připraveno k odebrání.
Zkus tento návod (dole):
http://www.tomshardware.co.uk/forum/148 ... isappeared

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\WINDOWS\System32\pid.PNF

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo:
http://www.virscan.org/

Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 11 čer 2012 06:21

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Service WDICA stopped successfully!
Service WDICA deleted successfully!
File File not found not found.
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
File File not found not found.
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
File File not found not found.
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
File File not found not found.
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
File File not found not found.
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
File File not found not found.
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
File File not found not found.
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
File File not found not found.
Service Changer stopped successfully!
Service Changer deleted successfully!
File File not found not found.
Error: No service named aswMBR was found to stop!
Service\Driver key aswMBR not found.
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\aswMBR.sys File not found not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
127.0.0.1 localhost removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.
File Protocol\Handler\msdaipp - No CLSID value found not found.
========== FILES ==========
C:\WINDOWS\System32\CONFIG.TMP moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
c:\windows\Tasks\Adobe Flash Player Updater.job moved successfully.
c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job moved successfully.
c:\windows\Tasks\MpIdleTask.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
C:\WINDOWS\System32\CleanUp.exe moved successfully.
File\Folder [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] not found.
File\Folder [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] not found.
C:\Documents and Settings\Administrator\Plocha\aswMBR.exe moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Documents and Settings\Administrator\Plocha\TDSSKiller.exe moved successfully.
< ipconfig /flushdns /c >
Konfigurace protokolu IP systému Windows
Mezipaměť překládání DNS byla úspěšně vyprázdněna.
C:\Documents and Settings\Administrator\Plocha\cmd.bat deleted successfully.
C:\Documents and Settings\Administrator\Plocha\cmd.txt deleted successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 45299160 bytes
->Temporary Internet Files folder emptied: 51514004 bytes
->Java cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 57246 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56466 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 40878 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 23709647 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 85407070 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 197,00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: UpdatusUser

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.48.0 log created on 06112012_061714

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 11 čer 2012 14:52

https://www.virustotal.com/file/faefe0a ... 339418934/

Myslim si , že to nebude virem , tolik antivirů co už mi projelo pc a nikdy nic nenašlo , nechodim ani na žádné nedůvěryhodné stránky takže stím by být problém nebyl, ale radši to udělám podle vás aby se problém vyřešil než abych musel surfovat na nejhorším prohlížeči co snad je..

Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 11 čer 2012 14:54

----------------------------------------------------------------------------
CrystalDiskInfo 4.6.2 (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows XP Professional SP3 [5.1 Build 2600] (x86)
Date : 2012/06/11 14:54:27

-- Controller Map ----------------------------------------------------------
+ Řadič VIA rozhraní IDE ke sběrnici PCI v režimu Bus Master [ATA]
+ Primární kanál IDE (0)
- _NEC DVD_RW ND-4571A
- WDC WD1200JB-00EVA0
- Sekundární kanál IDE (1)

-- Disk List ---------------------------------------------------------------
(1) WDC WD1200JB-00EVA0 : 116.8 GB [0/0/0, pd1]

----------------------------------------------------------------------------
(1) WDC WD1200JB-00EVA0
----------------------------------------------------------------------------
Model : WDC WD1200JB-00EVA0
Firmware : 15.05R15
Serial Number : WD-WMAEK2329561
Disk Size : 116.8 GB (8.4/116.8/116.8)
Buffer Size : 8192 KB
Queue Depth : 1
# of Sectors : 228203325
Rotation Rate : Neznámy údaj
Interface : Parallel ATA
Major Version : ATA/ATAPI-6
Minor Version : ----
Transfer Mode : Ultra DMA/100
Power On Hours : 14345 hod.
Power On Count : 5555 krát
Temparature : 37 C (98 F)
Health Status : Pozor
Features : S.M.A.R.T., AAM, 48bit LBA
APM Level : ----
AAM Level : 80FEh [OFF]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 198 _51 000000000000 Počet chyb čtení
03 146 141 _21 000000000CA1 Čas na roztočení ploten
04 _95 _95 _40 000000001602 Počet spuštění/zastavení
05 199 199 140 000000000001 Počet přemapovaných sektorů
07 100 253 _51 000000000000 Počet chybných hledání
09 _81 _81 __0 000000003809 Hodin v činnosti
0A 100 100 _51 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 _51 000000000000 Počet pokusů o překalibrování
0C _95 _95 __0 0000000015B3 Počet cyklů zapnutí zařízení
C2 113 253 __0 000000000025 Teplota
C4 199 199 __0 000000000001 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000003 Počet podezřelých sektorů
C6 200 200 __0 000000000000 Počet neopravitelných sektorů
C7 200 253 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 200 155 _51 000000000000 Počet chyb při zápisu sektorů

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF 0000 0010 E100 003F 003F 0000 0000 000E
010: 5744 2D57 4D41 454B 3233 3536 3536 3100 0000 0000
020: 0003 4000 004A 3135 2E30 3135 3135 5744 4320 5744
030: 3132 3030 4A42 2D30 3045 3020 3020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0280 0000 0007 3FFF 003F 003F FC10 00FB 0110
060: 1B3D 0D9A 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
080: 007E 0000 346B 7F01 4003 3C01 3C01 4003 203F 0000
090: 0000 0000 0000 603B 80FE 0000 0000 0000 0000 0000
100: 1B3D 0D9A 0000 0000 0000 0000 0000 0000 0000 0000
110: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
120: 0000 0000 0000 0000 0000 0000 0000 0000 0009 0041
130: 0000 0000 0000 0345 0000 0000 0000 0000 0000 0000
140: 0000 0000 0002 0001 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0017
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 8AA5

Uživatelský avatar
bledulka
Level 5
Level 5
Příspěvky: 2242
Registrován: srpen 09
Pohlaví: Žena
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod bledulka » 12 čer 2012 22:33

Něco s diskem bude.

Stáhni http://www.slunecnice.cz/sw/hd-tune/ a udělej poslední zááložku - eror scan.

Pissak
nováček
Příspěvky: 34
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: HJT log - prosím o kontrolu

Příspěvekod Pissak » 13 čer 2012 13:14

HD tune
Přílohy
HDTune_Error_Scan_WDC_WD1200JB-00EVA0.png
HD tune


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 32 hostů