[ Príspevkov: 19 ] 
AutorSpráva
Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 14.11.09
Prihlásený: 25.12.15
Príspevky: 292
Témy: 66 | 66
Bydlisko: Bratislava
NapísalOffline : 28.11.2012 15:07 | cmdhost.exe Critical system services

Ahojte, neviete mi niekto poradiť že čo je toto?:
cmdhost.exe Critical system services

Začal mi strašne sekať PC a tak som ho reštartoval. Odvtedy sa mi tam spúšťa táto vec a zaťažuje procesor tak, že PC seká ako predtým. Pravdepodobne sa to spustilo aj keď som PC reštartoval ale nemám tušenia ako sa toho zbaviť. Žeby nejaký vírus? Alebo čo to robí že to tak zaťažuje CPU?


Offline

Čestný člen
Čestný člen
cmdhost.exe Critical system services

Registrovaný: 08.01.09
Príspevky: 27973
Témy: 149 | 149
Bydlisko: Sládkovičovo
Vek: 37
NapísalOffline : 28.11.2012 15:21 | cmdhost.exe Critical system services

co som vycital mal by to byt malware, prebehni cele pc nejakym antimalwarom


_________________
book: HP Probook 470 G0, cpu: i5-3230M, gpu: intel HD 4000 + amd HD 8750m, ram: 8GB ddr3, ssd samsung 850 evo 250GB + ssd crucial m4 128GB, os: Win 10 Pro 64bit
Fén: Samsung Galaxy S7 black 32GB
Car: Ford S-Max 1.8 TDCi @ 160 PS
poradenstvo cez SS neposkytujem, lebo uz ma ubijate s tolkymi SS, nechajte to na forum, dakujem za pochopenie
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 14.09.16
Príspevky: 618
Témy: 2 | 2

vlož log z rsit http://en.kioskea.net/download/download-11416-rsit


Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 14.11.09
Prihlásený: 25.12.15
Príspevky: 292
Témy: 66 | 66
Bydlisko: Bratislava
Napísal autor témyOffline : 28.11.2012 19:13 | cmdhost.exe Critical system services

Už som to prebehol aj animalwareom a nič nenašiel. Teraz som si všimol že sa mi v dokumentoch vytvoril nový priečinok s názvom windows a toto obsahuje:

cmdhost.exe Critical system services

Naozaj by ma zaujímalo že čo to je, či je to nejaká divný aktualizácia windowsu alebo čo... Lebo sa mi aj z ničoho nič otvorilo cmd a začalo sa tam niečo diať, keď sa to otvorí znovu tak to odfotím ale fakt mi nejde do hlavy že čo to je....


Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 14.11.09
Prihlásený: 25.12.15
Príspevky: 292
Témy: 66 | 66
Bydlisko: Bratislava
Napísal autor témyOffline : 28.11.2012 19:18 | cmdhost.exe Critical system services

Tu to je, toto sa spustí:
cmdhost.exe Critical system services

Keď ten priečinok vymažem tak sa súbory po reštartovaní PC zas vytvoria... Vyzerá to fakt ako nejaké svinstvo...


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 14.09.16
Príspevky: 618
Témy: 2 | 2

prečo nepostupujes podla inštrukci vlož log z rsit


Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 14.11.09
Prihlásený: 25.12.15
Príspevky: 292
Témy: 66 | 66
Bydlisko: Bratislava
Napísal autor témyOffline : 28.11.2012 19:38 | cmdhost.exe Critical system services

Kód:
Logfile of random's system information tool 1.09 (written by random/random)
Run by A at 2012-11-28 19:31:09
Microsoft Windows 7 Professional  Service Pack 1
System drive C: has 9 GB (8%) free of 114 GB
Total RAM: 8189 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:31:12, on 28. 11. 2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe
C:\Program Files (x86)\Common Files\Intel\Schedule2\schedhlp.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Users\A\AppData\Roaming\CMDPrompt0.exe
C:\Users\A\AppData\Roaming\CMDHost0.exe
C:\Users\A\AppData\Roaming\HostServices6.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
C:\Program Files (x86)\GIGABYTE\U7300 Utilities\CONRCtl.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Lock Folder XP\LFService.exe
C:\Program Files (x86)\Intel\DataMigrationSoftware\DataMigrationSoftwareMonitor.exe
C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
C:\Program Files (x86)\Razer\Lachesis\OSD.exe
C:\Users\A\Documents\Windows\cmdhost.exe
C:\Program Files (x86)\Razer\Lachesis\razertra.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Razer\Lachesis\razerofa.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ismagent.exe
C:\Users\A\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\A\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\A\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\A\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\A\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 6\DelayLoad.exe
A:\preberanie\RSIT.exe
C:\Program Files (x86)\trend micro\A.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 210.107.100.251:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [openvpn-gui] "C:\Program Files (x86)\OpenVPN\bin\openvpn-gui.exe" --connect 2ceeaab277c99299d65406fa86212364.ovpn
O4 - HKLM\..\Run: [nvch] rundll32.exe rchnewver.dll,go
O4 - HKLM\..\Run: [LFService] C:\Program Files (x86)\Lock Folder XP\LFService.exe -start
O4 - HKLM\..\Run: [DataMigrationSoftwareMonitor.exe] C:\Program Files (x86)\Intel\DataMigrationSoftware\DataMigrationSoftwareMonitor.exe
O4 - HKLM\..\Run: [Lachesis] C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\A\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [NetLimiter] C:\Program Files\NetLimiter 3\NLClientApp.exe /tray
O4 - HKCU\..\Run: [SRSHDAudioLab] "C:\Program Files\SRS Labs\SRS Audio Essentials\AudioEssentials.exe" auto
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Windows Explorer] C:\Users\A\msdata\iexplorer.exe
O4 - HKCU\..\Run: [CMDPrompt] "C:\Users\A\AppData\Roaming\CMDPrompt0.exe"
O4 - HKCU\..\Run: [CMDHost] "C:\Users\A\AppData\Roaming\CMDHost0.exe"
O4 - HKCU\..\Run: [HostServices] "C:\Users\A\AppData\Roaming\HostServices6.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 6] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-964474455-2076792620-3933016070-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-964474455-2076792620-3933016070-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: Facebook Messenger.lnk = A\AppData\Local\Facebook\Messenger\2.1.4651.0\FacebookMessenger.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Remote Control.lnk = C:\Program Files (x86)\GIGABYTE\U7300 Utilities\CONRCtl.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: Intel Scheduler2 Service (IntSch2Svc) - Intel - C:\Program Files (x86)\Common Files\Intel\Schedule2\schedul2.exe
O23 - Service: Media Center Support Service (Jasmio.MediaCenter.Service) - Unknown owner - C:\Program Files\Jasmio\Media Center Support Service\Jasmio.MediaCenter.Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NetLimiter 3 Service (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 3\nlsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
O23 - Service: Overwolf Updater Service (OverwolfUpdaterService) - Overwolf Ltd - C:\Program Files (x86)\Overwolf\\OverwolfUpdater.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD SmartWare Drive Manager Service (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 17596 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-964474455-2076792620-3933016070-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-964474455-2076792620-3933016070-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-964474455-2076792620-3933016070-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-964474455-2076792620-3933016070-1000UA.job
C:\Windows\tasks\HP Photo Creations Communicator.job
C:\Windows\tasks\Intel_C_CVMP222605RW120BGN.job

=========Mozilla firefox=========

ProfilePath - C:\Users\A\AppData\Roaming\Mozilla\Firefox\Profiles\3g1txz55.default

prefs.js - "browser.startup.homepage" -  "http://cz.ikariam.com/"

"smartwebprinting@hp.com"=C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn.me/esnsonar,version=0.70.0]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.104.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.116.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\1.116.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.122.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.138.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=1.96.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\1.96.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=2.1.2]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00]
"Description"=Plug-in to check PlayStation(R)Network Downloader.
"Path"=C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\Sony\Media Go\npmediago.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
adtoolbar@firefox.sk
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
vyhladavanie.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\A\AppData\Roaming\Mozilla\Firefox\Profiles\3g1txz55.default\extensions\
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02 4119744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll [2012-06-11 1307728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-09-27 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f999a48b-1950-4d81-9971-79018f807b4b}]
FreeOnlineRadioPlayerRecorder Toolbar - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{f999a48b-1950-4d81-9971-79018f807b4b} - FreeOnlineRadioPlayerRecorder Toolbar - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll [2011-01-17 175912]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll [2012-06-11 1307728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
""= []
"openvpn-gui"=C:\Program Files (x86)\OpenVPN\bin\openvpn-gui.exe --connect 2ceeaab277c99299d65406fa86212364.ovpn []
"nvch"=rchnewver.dll,go []
"LFService"=C:\Program Files (x86)\Lock Folder XP\LFService.exe [2012-03-31 61280]
"DataMigrationSoftwareMonitor.exe"=C:\Program Files (x86)\Intel\DataMigrationSoftware\DataMigrationSoftwareMonitor.exe [2010-11-01 2605224]
"Lachesis"=C:\Program Files (x86)\Razer\Lachesis\razerhid.exe [2009-11-10 248320]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\A\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-19 136176]
"NetLimiter"=C:\Program Files\NetLimiter 3\NLClientApp.exe [2011-03-21 2910208]
"SRSHDAudioLab"=C:\Program Files\SRS Labs\SRS Audio Essentials\AudioEssentials.exe auto []
"AdobeBridge"= []
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-07-13 17418928]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2012-11-08 16070136]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]
"Windows Explorer"=C:\Users\A\msdata\iexplorer.exe [2012-11-23 56832]
"CMDPrompt"=C:\Users\A\AppData\Roaming\CMDPrompt0.exe [2012-11-28 211456]
"CMDHost"=C:\Users\A\AppData\Roaming\CMDHost0.exe [2012-11-28 215040]
"HostServices"=C:\Users\A\AppData\Roaming\HostServices6.exe [2012-11-28 202240]
"Advanced SystemCare 6"=C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe [2012-09-24 490880]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
Remote Control.lnk - C:\Program Files (x86)\GIGABYTE\U7300 Utilities\CONRCtl.exe

C:\Users\A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Facebook Messenger.lnk - C:\Users\A\AppData\Local\Facebook\Messenger\2.1.4651.0\FacebookMessenger.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=3

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"vidc.mp4e"=MPEG4Evfw.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 month======

2012-11-28 19:18:28 ----D---- C:\rsit
2012-11-28 19:18:28 ----D---- C:\Program Files (x86)\trend micro
2012-11-28 19:00:54 ----D---- C:\ProgramData\IObit
2012-11-28 19:00:08 ----D---- C:\Users\A\AppData\Roaming\IObit
2012-11-28 19:00:06 ----D---- C:\Program Files (x86)\IObit
2012-11-28 18:13:59 ----RASH---- C:\Users\A\AppData\Roaming\HostServices6.exe
2012-11-28 13:32:25 ----RASH---- C:\Users\A\AppData\Roaming\CMDHost0.exe
2012-11-28 13:02:21 ----RASH---- C:\Users\A\AppData\Roaming\CMDPrompt0.exe
2012-11-25 21:28:49 ----D---- C:\Windows\rescache
2012-11-24 13:52:30 ----A---- C:\Users\A\AppData\Roaming\pcouffin.sys
2012-11-24 13:52:29 ----D---- C:\Users\A\AppData\Roaming\Vso
2012-11-24 13:52:28 ----A---- C:\Windows\SysWOW64\wvc1dmod.dll
2012-11-24 13:52:28 ----A---- C:\Windows\SysWOW64\vp7vfw.dll
2012-11-24 13:52:25 ----D---- C:\ProgramData\VSO
2012-11-24 13:52:25 ----D---- C:\Program Files (x86)\VSO
2012-11-23 19:18:16 ----D---- C:\Users\A\AppData\Roaming\Theta
2012-11-23 18:41:32 ----D---- C:\Program Files (x86)\NFO Reader
2012-11-19 21:00:00 ----RA---- C:\Windows\SysWOW64\pbsvc.exe
2012-11-19 16:56:11 ----D---- C:\ProgramData\Razer
2012-11-19 16:56:00 ----D---- C:\Users\A\AppData\Roaming\InstallShield
2012-11-18 16:35:40 ----D---- C:\ProgramData\Mozilla
2012-11-18 16:35:40 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-11-16 13:17:40 ----RD---- C:\Hudba
2012-11-15 16:13:06 ----A---- C:\Windows\SysWOW64\vbscript.dll
2012-11-15 16:13:06 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2012-11-15 16:13:06 ----A---- C:\Windows\SysWOW64\ieui.dll
2012-11-15 16:13:05 ----A---- C:\Windows\SysWOW64\url.dll
2012-11-15 16:13:05 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2012-11-15 16:13:04 ----A---- C:\Windows\SysWOW64\urlmon.dll
2012-11-15 16:13:03 ----A---- C:\Windows\SysWOW64\wininet.dll
2012-11-15 16:13:03 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2012-11-15 16:13:02 ----A---- C:\Windows\SysWOW64\jscript9.dll
2012-11-15 16:13:02 ----A---- C:\Windows\SysWOW64\jscript.dll
2012-11-15 16:13:01 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2012-11-15 16:13:01 ----A---- C:\Windows\SysWOW64\iertutil.dll
2012-11-15 16:12:58 ----A---- C:\Windows\SysWOW64\mshtml.dll
2012-11-15 16:12:54 ----A---- C:\Windows\SysWOW64\ieframe.dll
2012-11-15 15:57:12 ----A---- C:\Windows\SysWOW64\dhcpcsvc6.dll
2012-11-15 15:57:12 ----A---- C:\Windows\SysWOW64\dhcpcore6.dll
2012-11-15 15:57:09 ----A---- C:\Windows\SysWOW64\nlaapi.dll
2012-11-15 15:57:09 ----A---- C:\Windows\SysWOW64\netevent.dll
2012-11-15 15:57:09 ----A---- C:\Windows\SysWOW64\netcorehc.dll
2012-11-15 15:57:09 ----A---- C:\Windows\SysWOW64\ncsi.dll
2012-11-15 15:56:56 ----A---- C:\Windows\SysWOW64\synceng.dll
2012-11-15 15:03:41 ----D---- C:\ProgramData\Intel(R) Update Manager
2012-11-15 15:03:16 ----D---- C:\Intel

======List of files/folders modified in the last 1 month======

2012-11-28 19:31:11 ----D---- C:\Windows\Temp
2012-11-28 19:27:18 ----D---- C:\Users\A\AppData\Roaming\Skype
2012-11-28 19:25:39 ----D---- C:\ProgramData\NVIDIA
2012-11-28 19:21:06 ----HD---- C:\Config.Msi
2012-11-28 19:18:28 ----RD---- C:\Program Files (x86)
2012-11-28 19:00:54 ----HD---- C:\ProgramData
2012-11-28 18:16:35 ----D---- C:\Windows\System32
2012-11-28 18:16:34 ----D---- C:\Windows\inf
2012-11-28 17:21:02 ----SHD---- C:\Windows\Installer
2012-11-28 15:10:52 ----D---- C:\Users\A\AppData\Roaming\vlc
2012-11-28 14:07:25 ----D---- C:\Windows\winsxs
2012-11-28 14:07:25 ----D---- C:\Windows\AppPatch
2012-11-28 14:03:38 ----D---- C:\Program Files (x86)\SpeedFan
2012-11-25 21:28:49 ----D---- C:\Windows
2012-11-24 13:52:34 ----D---- C:\Users\A\AppData\Roaming\NVIDIA
2012-11-24 13:52:28 ----D---- C:\Windows\SysWOW64
2012-11-23 19:34:08 ----A---- C:\Windows\SysWOW64\PnkBstrB.exe
2012-11-23 19:20:13 ----A---- C:\Windows\SysWOW64\PnkBstrA.exe
2012-11-23 18:40:37 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-11-23 18:39:39 ----RSD---- C:\Windows\assembly
2012-11-22 10:57:59 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2012-11-20 14:24:52 ----D---- C:\Users\A\AppData\Roaming\Razer
2012-11-18 16:35:40 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-11-18 12:19:02 ----D---- C:\Users\A\AppData\Roaming\TS3Client
2012-11-18 01:05:53 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-11-16 16:15:53 ----D---- C:\Windows\Microsoft.NET
2012-11-15 19:01:13 ----D---- C:\Windows\SysWOW64\migration
2012-11-15 19:01:13 ----D---- C:\Windows\SysWOW64\en-US
2012-11-15 19:01:13 ----D---- C:\Windows\PolicyDefinitions
2012-11-15 19:01:13 ----D---- C:\Program Files (x86)\Internet Explorer
2012-11-15 19:01:12 ----RSD---- C:\Windows\Fonts
2012-11-15 16:15:36 ----D---- C:\ProgramData\Microsoft Help
2012-11-15 15:03:42 ----D---- C:\Program Files (x86)\Intel
2012-11-14 19:24:16 ----D---- C:\ProgramData\boost_interprocess
2012-11-05 19:12:34 ----D---- C:\ProgramData\Origin
2012-11-05 19:12:17 ----HD---- C:\Program Files (x86)\Common Files\EAInstaller
2012-11-01 15:51:27 ----D---- C:\ProgramData\Skype
2012-11-01 12:05:01 ----D---- C:\Users\A\AppData\Roaming\Mozilla

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 LFSys;LFSys; C:\Windows\SysWOW64\drivers\LFSys64.sys [2012-03-31 93024]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys []
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2011-03-18 29592]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys []
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 nltdi;nltdi; \??\C:\Program Files\NetLimiter 3\nltdi.sys [2011-03-21 88200]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys []
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys []
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys []
R2 RtNdPt60;Realtek NDIS Protocol Driver; C:\Windows\system32\DRIVERS\RtNdPt60.sys []
R3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys []
R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys []
R3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys []
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys []
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys []
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys []
R3 FileMonitor;FileMonitor; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2011-04-27 20336]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys []
R3 NLNdisMP;NLNdisMP; C:\Windows\system32\DRIVERS\nlndis.sys []
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys []
R3 RDPDISPM;RDPDISPM; C:\Windows\system32\DRIVERS\rdpdispm.sys []
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
R3 RegFilter;RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2011-03-23 33184]
R3 RTL2832UBDA;REALTEK 2832U BDA Driver; C:\Windows\system32\drivers\RTL2832UBDA.sys []
R3 RTL2832UUSB;REALTEK 2832U USB Driver; C:\Windows\System32\Drivers\RTL2832UUSB.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys []
R3 UrlFilter;UrlFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2011-03-23 21328]
R3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys []
R3 VaneFltr;Lachesis Mouse Driver; C:\Windows\system32\drivers\Lachesis.sys []
R3 vpcbus;Virtual PC Host Bus Service; C:\Windows\system32\DRIVERS\vpchbus.sys []
R3 vpcusb;USB Virtualization Connector Service; C:\Windows\system32\DRIVERS\vpcusb.sys []
S3 1394hub;1394 Enabled Hub; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys []
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys []
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys []
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys []
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys []
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys []
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys []
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys []
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys []
S3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista; C:\Windows\system32\DRIVERS\netr28ux.sys []
S3 NLNdisPT;NetLimiter Ndis Protocol Service; C:\Windows\system32\DRIVERS\nlndis.sys []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys []
S3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0); C:\Windows\system32\DRIVERS\RtTeam60.sys []
S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2); C:\Windows\system32\DRIVERS\RtVlan60.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 SRS_AE_Service;SRS Audio Essentials; C:\Windows\system32\drivers\SRS_AE_amd64.sys []
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys []
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys []
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0); C:\Windows\system32\DRIVERS\RtTeam60.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 uisp;Freescale USB JW32 driver; C:\Windows\System32\Drivers\usbicp.sys [2005-12-21 14592]
S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\drivers\usb8023x.sys []
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys []
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [2012-10-31 464256]
R2 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe [2012-06-11 193616]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-03-02 844328]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-11-16 735960]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 IMFservice;IMF Service; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2011-06-01 821080]
R2 IntSch2Svc;Intel Scheduler2 Service; C:\Program Files (x86)\Common Files\Intel\Schedule2\schedul2.exe [2010-11-01 1164704]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nlsvc;NetLimiter 3 Service; C:\Program Files\NetLimiter 3\nlsvc.exe [2011-03-21 1845248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe []
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-10 1258856]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-04-13 624856]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-11-23 76888]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
R2 WDDMService;WD SmartWare Drive Manager Service; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-10-14 116224]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-06 136176]
S2 Jasmio.MediaCenter.Service;Media Center Support Service; C:\Program Files\Jasmio\Media Center Support Service\Jasmio.MediaCenter.Service.exe [2009-11-10 73144]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [2012-06-11 240208]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-11-16 23296]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-06 136176]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-11-18 129976]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 OpenVPNService;OpenVPN Service; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [2010-12-01 36352]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 OverwolfUpdaterService;Overwolf Updater Service; C:\Program Files (x86)\Overwolf\\OverwolfUpdater.exe [2011-09-18 16616]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []

-----------------EOF-----------------


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 14.09.16
Príspevky: 618
Témy: 2 | 2

skontroluj vo virustotale https://www.virustotal.com/
C:\Users\A\Documents\Windows\cmdhost.exe
C:\Users\A\AppData\Roaming\CMDPrompt0.exe
C:\Users\A\AppData\Roaming\CMDHost0.exe
Stiahni si combofix http://www.bleepingcomputer.com/download/combofix/
spusť daj skenovať pošli log ktorý ty vybehne budeš ho mať na C:combofix.txt


Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 15.08.11
Prihlásený: 04.09.17
Príspevky: 279
Témy: 46 | 46
Bydlisko: Rabča

Zdravim,
Mam ten isty problem,log sa nezmestyl do textu tu je download link
Kód:
http://download.hellshare.sk/log-txt/10208154/


_________________
CPU:Intel Core i5 2500K 4,2GHz GPU:MSI GTX 960 4GB RAM:CORSAIR 4GB KIT DDR3 1600MHz CL9 Blue PSU:CORSAIR CX600 V2 MB:P8P67-M PRO B3 Revison Case:CoolerMaster Elite 430 Black Edition Phone:iPhone 6s Plus 128 GB Notebook:Asus GL502VM-FY182T
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 14.09.16
Príspevky: 618
Témy: 2 | 2

vlož to na ulož to to je platenne


Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 14.11.09
Prihlásený: 25.12.15
Príspevky: 292
Témy: 66 | 66
Bydlisko: Bratislava
Napísal autor témyOffline : 30.11.2012 17:40 | cmdhost.exe Critical system services

U mňa to nakoniec vyriešil ten combofix. Ten to vymazal a už je po probléme. Síce so sebou vzal ešte čosi ale zjavne to nebolo dôležité lebo mi to zatiaľ nechýba :-D. Takže ďakujem za rady :-).


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 14.09.16
Príspevky: 618
Témy: 2 | 2

prečo si nedal sem log je potreba analyzovať.


Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 15.08.11
Prihlásený: 04.09.17
Príspevky: 279
Témy: 46 | 46
Bydlisko: Rabča

Log prva polovyca
Kód:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Stano at 2012-11-30 16:15:09
Microsoft Windows 7 Professional  Service Pack 1
System drive C: has 21 GB (21%) free of 100 GB
Total RAM: 4077 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:15:15, on 30. 11. 2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal

Running processes:
E:\Programy\Speed Bit\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Users\Stano\AppData\Roaming\CMDHost0.exe
E:\Programy\Opera\opera.exe
C:\Users\Stano\msdata\cmdhost_w1c_9291.exe
E:\Programy\MSI Afterburner\MSIAfterburner.exe
C:\Users\Stano\msdata\nethost_w2c_5420.exe
C:\Users\Stano\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\Stano.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: BitAccelerator - {CAC42510-9B41-42c1-9DCD-7282A2D07C61} - C:\Program Files (x86)\BitAccelerator\BitAccelerator.dll
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpeedBitVideoAccelerator] "E:\Programy\Speed Bit\SpeedBit Video Accelerator\VideoAccelerator.exe" /startup
O4 - HKCU\..\Run: [Windows Explorer] C:\Users\Stano\msdata\iexplorer.exe
O4 - HKCU\..\Run: [CMDHost] "C:\Users\Stano\AppData\Roaming\CMDHost0.exe"
O4 - HKCU\..\Run: [Nethosts] "C:\Users\Stano\AppData\Roaming\Nethosts2.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3005263881-1616786168-1793016659-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3005263881-1616786168-1793016659-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: e:\programy\speed bit\speedbit video accelerator\sblsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Programy\nero\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - E:\Programy\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VideoAcceleratorService - SpeedBit Ltd. - E:\Programy\SPEEDB~1\SPEEDB~1\VideoAcceleratorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8739 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - E:\Programy\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CAC42510-9B41-42c1-9DCD-7282A2D07C61}]
BitAcceleratorBHO Class - C:\Program Files (x86)\BitAccelerator\BitAccelerator.dll [2012-10-30 92160]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"SpeedBitVideoAccelerator"=E:\Programy\Speed Bit\SpeedBit Video Accelerator\VideoAccelerator.exe [2012-11-23 2098376]
"Windows Explorer"=C:\Users\Stano\msdata\iexplorer.exe [2012-11-28 56832]
"CMDHost"=C:\Users\Stano\AppData\Roaming\CMDHost0.exe [2012-11-29 215040]
"Nethosts"=C:\Users\Stano\AppData\Roaming\Nethosts2.exe [2012-11-30 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"msacm.vorbis"=vorbis.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-11-30 16:15:09 ----D---- C:\rsit
2012-11-30 16:15:09 ----D---- C:\Program Files (x86)\trend micro
2012-11-30 15:43:31 ----RASH---- C:\Users\Stano\AppData\Roaming\Nethosts2.exe
2012-11-29 15:39:45 ----D---- C:\Program Files (x86)\Counter Strike Source
2012-11-29 15:36:27 ----D---- C:\Windows\pss
2012-11-29 14:40:53 ----A---- C:\Windows\SysWOW64\OpenCL.dll
2012-11-29 14:40:53 ----A---- C:\Windows\SysWOW64\nvwgf2um.dll
2012-11-29 14:40:53 ----A---- C:\Windows\SysWOW64\nvoglv32.dll
2012-11-29 14:40:53 ----A---- C:\Windows\SysWOW64\nvd3dum.dll
2012-11-29 14:40:53 ----A---- C:\Windows\SysWOW64\nvcuvid.dll
2012-11-29 14:40:53 ----A---- C:\Windows\SysWOW64\nvcuvenc.dll
2012-11-29 14:40:53 ----A---- C:\Windows\SysWOW64\nvcompiler.dll
2012-11-29 14:27:26 ----RASH---- C:\Users\Stano\AppData\Roaming\CMDHost0.exe
2012-11-28 21:04:12 ----D---- C:\Program Files (x86)\BitAccelerator
2012-11-28 21:03:33 ----D---- C:\Users\Stano\AppData\Roaming\NVIDIA
2012-11-28 21:02:26 ----D---- C:\ProgramData\OpenBitCoin
2012-11-28 21:02:26 ----D---- C:\Program Files (x86)\OpenBitCoin
2012-11-28 19:05:35 ----RASH---- C:\Users\Stano\AppData\Roaming\HostServices6.exe
2012-11-28 18:41:32 ----D---- C:\Users\Stano\AppData\Roaming\Theta
2012-11-28 15:50:44 ----A---- C:\Windows\SysWOW64\winver.exe
2012-11-28 15:50:44 ----A---- C:\Windows\SysWOW64\user32.dll
2012-11-28 15:50:44 ----A---- C:\Windows\SysWOW64\systemcpl.dll
2012-11-28 15:50:44 ----A---- C:\Windows\SysWOW64\sppcomapi.dll
2012-11-28 15:50:44 ----A---- C:\Windows\SysWOW64\slmgr.vbs
2012-11-28 14:42:06 ----D---- C:\Windows\Minidump
2012-11-27 19:25:22 ----D---- C:\Program Files (x86)\MSXML 4.0
2012-11-27 12:28:05 ----A---- C:\Windows\SysWOW64\dhcpcsvc6.dll
2012-11-27 12:28:05 ----A---- C:\Windows\SysWOW64\dhcpcore6.dll
2012-11-27 12:28:02 ----A---- C:\Windows\SysWOW64\ncsi.dll
2012-11-27 12:28:01 ----A---- C:\Windows\SysWOW64\nlaapi.dll
2012-11-27 12:28:01 ----A---- C:\Windows\SysWOW64\netevent.dll
2012-11-27 12:28:01 ----A---- C:\Windows\SysWOW64\netcorehc.dll
2012-11-26 18:36:02 ----D---- C:\Program Files (x86)\Common Files\Steam
2012-11-26 17:15:08 ----D---- C:\Program Files (x86)\Microsoft
2012-11-26 17:14:14 ----D---- C:\Program Files (x86)\Windows Live SkyDrive
2012-11-26 17:13:04 ----D---- C:\Program Files (x86)\Windows Live
2012-11-26 17:12:00 ----D---- C:\Windows\PCHEALTH
2012-11-26 17:09:37 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-11-26 17:08:00 ----D---- C:\Program Files (x86)\Common Files\Windows Live
2012-11-25 18:50:27 ----D---- C:\Users\Stano\AppData\Roaming\Nero
2012-11-25 18:36:40 ----A---- C:\Windows\Irremote.ini
2012-11-25 18:35:30 ----D---- C:\ProgramData\Nero
2012-11-25 18:35:30 ----D---- C:\Program Files (x86)\Common Files\Nero
2012-11-25 17:34:50 ----D---- C:\Program Files (x86)\Common Files\Skype
2012-11-25 15:06:22 ----D---- C:\Program Files (x86)\SpeedFan
2012-11-25 14:17:46 ----A---- C:\Windows\SysWOW64\dfshim.dll
2012-11-25 14:17:41 ----A---- C:\Windows\SysWOW64\mstscax.dll
2012-11-25 14:17:40 ----A---- C:\Windows\SysWOW64\mfc40u.dll
2012-11-25 14:17:40 ----A---- C:\Windows\SysWOW64\mfc40.dll
2012-11-25 14:17:40 ----A---- C:\Windows\SysWOW64\d3d10warp.dll
2012-11-25 14:17:39 ----A---- C:\Windows\SysWOW64\pmcsnap.dll
2012-11-25 14:17:36 ----A---- C:\Windows\SysWOW64\secproc_isv.dll
2012-11-25 14:17:36 ----A---- C:\Windows\SysWOW64\d2d1.dll
2012-11-25 14:17:35 ----A---- C:\Windows\SysWOW64\secproc.dll
2012-11-25 14:17:35 ----A---- C:\Windows\SysWOW64\RMActivate_isv.exe
2012-11-25 14:17:34 ----A---- C:\Windows\SysWOW64\RMActivate.exe
2012-11-25 14:17:34 ----A---- C:\Windows\SysWOW64\PushPrinterConnections.exe
2012-11-25 14:17:34 ----A---- C:\Windows\SysWOW64\ppcsnap.dll
2012-11-25 14:17:33 ----A---- C:\Windows\SysWOW64\mscoree.dll
2012-11-25 14:17:32 ----A---- C:\Windows\SysWOW64\mf.dll
2012-11-25 14:17:31 ----A---- C:\Windows\SysWOW64\CertEnroll.dll
2012-11-25 14:17:30 ----A---- C:\Windows\SysWOW64\wmp.dll
2012-11-25 14:17:29 ----A---- C:\Windows\SysWOW64\PresentationHostProxy.dll
2012-11-25 14:17:29 ----A---- C:\Windows\SysWOW64\PresentationHost.exe
2012-11-25 14:17:27 ----A---- C:\Windows\SysWOW64\RacEngn.dll
2012-11-25 14:17:27 ----A---- C:\Windows\SysWOW64\AuthFWSnapin.dll
2012-11-25 14:17:25 ----A---- C:\Windows\SysWOW64\ole32.dll
2012-11-25 14:17:25 ----A---- C:\Windows\SysWOW64\ExplorerFrame.dll
2012-11-25 14:17:24 ----A---- C:\Windows\SysWOW64\vssapi.dll
2012-11-25 14:17:23 ----A---- C:\Windows\SysWOW64\taskschd.dll
2012-11-25 14:17:23 ----A---- C:\Windows\SysWOW64\SearchFolder.dll
2012-11-25 14:17:23 ----A---- C:\Windows\SysWOW64\d3d9.dll
2012-11-25 14:17:22 ----A---- C:\Windows\SysWOW64\mstsc.exe
2012-11-25 14:17:21 ----A---- C:\Windows\SysWOW64\wer.dll
2012-11-25 14:17:21 ----A---- C:\Windows\SysWOW64\certcli.dll
2012-11-25 14:17:20 ----A---- C:\Windows\SysWOW64\tcpmonui.dll
2012-11-25 14:17:20 ----A---- C:\Windows\SysWOW64\odbc32.dll
2012-11-25 14:17:20 ----A---- C:\Windows\SysWOW64\dwmcore.dll
2012-11-25 14:17:19 ----A---- C:\Windows\SysWOW64\TSWorkspace.dll
2012-11-25 14:17:19 ----A---- C:\Windows\SysWOW64\tsmf.dll
2012-11-25 14:17:19 ----A---- C:\Windows\SysWOW64\dot3api.dll
2012-11-25 14:17:18 ----A---- C:\Windows\SysWOW64\winhttp.dll
2012-11-25 14:17:18 ----A---- C:\Windows\SysWOW64\setupapi.dll
2012-11-25 14:17:18 ----A---- C:\Windows\SysWOW64\MSVidCtl.dll
2012-11-25 14:17:18 ----A---- C:\Windows\SysWOW64\dbgeng.dll
2012-11-25 14:17:18 ----A---- C:\Windows\SysWOW64\apphelp.dll
2012-11-25 14:17:17 ----A---- C:\Windows\SysWOW64\WMVDECOD.DLL
2012-11-25 14:17:17 ----A---- C:\Windows\SysWOW64\WindowsCodecs.dll
2012-11-25 14:17:17 ----A---- C:\Windows\SysWOW64\netlogon.dll
2012-11-25 14:17:17 ----A---- C:\Windows\SysWOW64\netcfgx.dll
2012-11-25 14:17:17 ----A---- C:\Windows\SysWOW64\d3d11.dll
2012-11-25 14:17:16 ----A---- C:\Windows\SysWOW64\WsmSvc.dll
2012-11-25 14:17:16 ----A---- C:\Windows\SysWOW64\upnp.dll
2012-11-25 14:17:16 ----A---- C:\Windows\SysWOW64\Query.dll
2012-11-25 14:17:16 ----A---- C:\Windows\SysWOW64\mmcndmgr.dll
2012-11-25 14:17:16 ----A---- C:\Windows\SysWOW64\gpprefcl.dll
2012-11-25 14:17:16 ----A---- C:\Windows\SysWOW64\DShowRdpFilter.dll
2012-11-25 14:17:16 ----A---- C:\Windows\SysWOW64\advapi32.dll
2012-11-25 14:17:15 ----A---- C:\Windows\SysWOW64\netfxperf.dll
2012-11-25 14:17:15 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2012-11-25 14:17:15 ----A---- C:\Windows\SysWOW64\msdrm.dll
2012-11-25 14:17:15 ----A---- C:\Windows\SysWOW64\imapi2fs.dll
2012-11-25 14:17:15 ----A---- C:\Windows\SysWOW64\authui.dll
2012-11-25 14:17:14 ----A---- C:\Windows\SysWOW64\usp10.dll
2012-11-25 14:17:14 ----A---- C:\Windows\SysWOW64\shlwapi.dll
2012-11-25 14:17:14 ----A---- C:\Windows\SysWOW64\SessEnv.dll
2012-11-25 14:17:14 ----A---- C:\Windows\SysWOW64\PortableDeviceApi.dll
2012-11-25 14:17:13 ----A---- C:\Windows\SysWOW64\mcbuilder.exe
2012-11-25 14:17:13 ----A---- C:\Windows\SysWOW64\certmgr.dll
2012-11-25 14:17:12 ----A---- C:\Windows\SysWOW64\xpsservices.dll
2012-11-25 14:17:12 ----A---- C:\Windows\SysWOW64\WebClnt.dll
2012-11-25 14:17:12 ----A---- C:\Windows\SysWOW64\userenv.dll
2012-11-25 14:17:12 ----A---- C:\Windows\SysWOW64\drvstore.dll
2012-11-25 14:17:11 ----A---- C:\Windows\SysWOW64\comdlg32.dll
2012-11-25 14:17:10 ----A---- C:\Windows\SysWOW64\cmd.exe
2012-11-25 14:17:07 ----A---- C:\Windows\SysWOW64\Wldap32.dll
2012-11-25 14:17:07 ----A---- C:\Windows\SysWOW64\propsys.dll
2012-11-25 14:17:07 ----A---- C:\Windows\SysWOW64\mfds.dll
2012-11-25 14:17:07 ----A---- C:\Windows\SysWOW64\framedynos.dll
2012-11-25 14:17:06 ----A---- C:\Windows\SysWOW64\rdpendp.dll
2012-11-25 14:17:05 ----A---- C:\Windows\SysWOW64\azroles.dll
2012-11-25 14:17:05 ----A---- C:\Windows\SysWOW64\appmgr.dll
2012-11-25 14:17:03 ----A---- C:\Windows\SysWOW64\themeui.dll
2012-11-25 14:17:02 ----A---- C:\Windows\SysWOW64\taskeng.exe
2012-11-25 14:17:02 ----A---- C:\Windows\SysWOW64\spp.dll
2012-11-25 14:17:02 ----A---- C:\Windows\SysWOW64\mswsock.dll
2012-11-25 14:17:02 ----A---- C:\Windows\SysWOW64\dhcpcore.dll
2012-11-25 14:17:02 ----A---- C:\Windows\SysWOW64\credui.dll
2012-11-25 14:17:00 ----A---- C:\Windows\SysWOW64\mfreadwrite.dll
2012-11-25 14:17:00 ----A---- C:\Windows\SysWOW64\basecsp.dll
2012-11-25 14:16:59 ----A---- C:\Windows\SysWOW64\dxgi.dll
2012-11-25 14:16:58 ----A---- C:\Windows\SysWOW64\dbghelp.dll
2012-11-25 14:16:57 ----A---- C:\Windows\SysWOW64\NaturalLanguage6.dll
2012-11-25 14:16:56 ----A---- C:\Windows\SysWOW64\taskcomp.dll
2012-11-25 14:16:56 ----A---- C:\Windows\SysWOW64\evr.dll
2012-11-25 14:16:55 ----A---- C:\Windows\SysWOW64\WinSATAPI.dll
2012-11-25 14:16:55 ----A---- C:\Windows\SysWOW64\calc.exe
2012-11-25 14:16:54 ----A---- C:\Windows\SysWOW64\sqlsrv32.dll
2012-11-25 14:16:53 ----A---- C:\Windows\SysWOW64\UIRibbon.dll
2012-11-25 14:16:52 ----A---- C:\Windows\SysWOW64\ws2_32.dll
2012-11-25 14:16:52 ----A---- C:\Windows\SysWOW64\sxs.dll
2012-11-25 14:16:52 ----A---- C:\Windows\SysWOW64\stobject.dll
2012-11-25 14:16:52 ----A---- C:\Windows\SysWOW64\netshell.dll
2012-11-25 14:16:51 ----A---- C:\Windows\SysWOW64\gdi32.dll
2012-11-25 14:16:51 ----A---- C:\Windows\SysWOW64\comctl32.dll
2012-11-25 14:16:50 ----A---- C:\Windows\SysWOW64\prncache.dll
2012-11-25 14:16:50 ----A---- C:\Windows\SysWOW64\printui.dll
2012-11-25 14:16:49 ----A---- C:\Windows\SysWOW64\WSDApi.dll
2012-11-25 14:16:49 ----A---- C:\Windows\SysWOW64\wmpeffects.dll
2012-11-25 14:16:49 ----A---- C:\Windows\SysWOW64\rpchttp.dll
2012-11-25 14:16:49 ----A---- C:\Windows\SysWOW64\net1.exe
2012-11-25 14:16:48 ----A---- C:\Windows\SysWOW64\scansetting.dll
2012-11-25 14:16:46 ----A---- C:\Windows\SysWOW64\MMDevAPI.dll
2012-11-25 14:16:46 ----A---- C:\Windows\SysWOW64\davclnt.dll
2012-11-25 14:16:45 ----A---- C:\Windows\SysWOW64\WMVCORE.DLL
2012-11-25 14:16:45 ----A---- C:\Windows\SysWOW64\wlangpui.dll
2012-11-25 14:16:45 ----A---- C:\Windows\SysWOW64\aaclient.dll
2012-11-25 14:16:44 ----A---- C:\Windows\SysWOW64\wpdshext.dll
2012-11-25 14:16:44 ----A---- C:\Windows\SysWOW64\webservices.dll
2012-11-25 14:16:44 ----A---- C:\Windows\SysWOW64\t2embed.dll
2012-11-25 14:16:44 ----A---- C:\Windows\SysWOW64\scrptadm.dll
2012-11-25 14:16:44 ----A---- C:\Windows\SysWOW64\QSHVHOST.DLL
2012-11-25 14:16:44 ----A---- C:\Windows\SysWOW64\pnidui.dll
2012-11-25 14:16:43 ----A---- C:\Windows\SysWOW64\SyncCenter.dll
2012-11-25 14:16:43 ----A---- C:\Windows\SysWOW64\netdiagfx.dll
2012-11-25 14:16:43 ----A---- C:\Windows\SysWOW64\fde.dll
2012-11-25 14:16:41 ----A---- C:\Windows\SysWOW64\wuapi.dll
2012-11-25 14:16:41 ----A---- C:\Windows\SysWOW64\wscapi.dll
2012-11-25 14:16:40 ----A---- C:\Windows\SysWOW64\WinSCard.dll
2012-11-25 14:16:40 ----A---- C:\Windows\SysWOW64\pla.dll
2012-11-25 14:16:40 ----A---- C:\Windows\SysWOW64\msasn1.dll
2012-11-25 14:16:40 ----A---- C:\Windows\SysWOW64\cscobj.dll
2012-11-25 14:16:39 ----A---- C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2012-11-25 14:16:38 ----A---- C:\Windows\SysWOW64\winsta.dll
2012-11-25 14:16:38 ----A---- C:\Windows\SysWOW64\imapi2.dll
2012-11-25 14:16:37 ----A---- C:\Windows\SysWOW64\gameux.dll
2012-11-25 14:16:37 ----A---- C:\Windows\SysWOW64\DXPTaskRingtone.dll
2012-11-25 14:16:36 ----A---- C:\Windows\SysWOW64\WMPEncEn.dll
2012-11-25 14:16:36 ----A---- C:\Windows\SysWOW64\shsvcs.dll
2012-11-25 14:16:36 ----A---- C:\Windows\SysWOW64\onex.dll
2012-11-25 14:16:35 ----A---- C:\Windows\SysWOW64\winmm.dll
2012-11-25 14:16:35 ----A---- C:\Windows\SysWOW64\netiohlp.dll
2012-11-25 14:16:35 ----A---- C:\Windows\SysWOW64\hbaapi.dll
2012-11-25 14:16:35 ----A---- C:\Windows\SysWOW64\autochk.exe
2012-11-25 14:16:35 ----A---- C:\Windows\SysWOW64\autofmt.exe
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\thumbcache.dll
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\samcli.dll
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\regapi.dll
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\proquota.exe
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\msutb.dll
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\msinfo32.exe
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\mimefilt.dll
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\IPHLPAPI.DLL
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\autoconv.exe
2012-11-25 14:16:34 ----A---- C:\Windows\SysWOW64\AudioSes.dll
2012-11-25 14:16:33 ----A---- C:\Windows\SysWOW64\tcpipcfg.dll
2012-11-25 14:16:33 ----A---- C:\Windows\SysWOW64\srchadmin.dll
2012-11-25 14:16:33 ----A---- C:\Windows\SysWOW64\schtasks.exe
2012-11-25 14:16:33 ----A---- C:\Windows\SysWOW64\powercpl.dll
2012-11-25 14:16:33 ----A---- C:\Windows\SysWOW64\ipsmsnap.dll
2012-11-25 14:16:33 ----A---- C:\Windows\SysWOW64\eapphost.dll
2012-11-25 14:16:32 ----A---- C:\Windows\SysWOW64\wcncsvc.dll
2012-11-25 14:16:32 ----A---- C:\Windows\SysWOW64\QAGENT.DLL
2012-11-25 14:16:32 ----A---- C:\Windows\SysWOW64\msihnd.dll
2012-11-25 14:16:32 ----A---- C:\Windows\SysWOW64\mscorier.dll
2012-11-25 14:16:32 ----A---- C:\Windows\SysWOW64\framedyn.dll
2012-11-25 14:16:32 ----A---- C:\Windows\SysWOW64\AuxiliaryDisplayCpl.dll
2012-11-25 14:16:31 ----A---- C:\Windows\SysWOW64\wdc.dll
2012-11-25 14:16:31 ----A---- C:\Windows\SysWOW64\netid.dll
2012-11-25 14:16:31 ----A---- C:\Windows\SysWOW64\actxprxy.dll
2012-11-25 14:16:30 ----A---- C:\Windows\SysWOW64\StructuredQuery.dll
2012-11-25 14:16:30 ----A---- C:\Windows\SysWOW64\scesrv.dll
2012-11-25 14:16:29 ----A---- C:\Windows\SysWOW64\wlanpref.dll
2012-11-25 14:16:29 ----A---- C:\Windows\SysWOW64\Vault.dll
2012-11-25 14:16:29 ----A---- C:\Windows\SysWOW64\untfs.dll
2012-11-25 14:16:29 ----A---- C:\Windows\SysWOW64\rastls.dll
2012-11-25 14:16:29 ----A---- C:\Windows\SysWOW64\nci.dll
2012-11-25 14:16:28 ----A---- C:\Windows\SysWOW64\WMNetMgr.dll
2012-11-25 14:16:28 ----A---- C:\Windows\SysWOW64\RpcRtRemote.dll
2012-11-25 14:16:28 ----A---- C:\Windows\SysWOW64\Robocopy.exe
2012-11-25 14:16:25 ----A---- C:\Windows\SysWOW64\DxpTaskSync.dll
2012-11-25 14:16:24 ----A---- C:\Windows\SysWOW64\taskmgr.exe
2012-11-25 14:16:24 ----A---- C:\Windows\SysWOW64\Display.dll
2012-11-25 14:16:23 ----A---- C:\Windows\SysWOW64\mtxclu.dll
2012-11-25 14:16:22 ----A---- C:\Windows\SysWOW64\XpsRasterService.dll
2012-11-25 14:16:22 ----A---- C:\Windows\SysWOW64\userinit.exe
2012-11-25 14:16:22 ----A---- C:\Windows\SysWOW64\termmgr.dll
2012-11-25 14:16:22 ----A---- C:\Windows\SysWOW64\puiobj.dll
2012-11-25 14:16:22 ----A---- C:\Windows\SysWOW64\eudcedit.exe
2012-11-25 14:16:21 ----A---- C:\Windows\SysWOW64\wiadefui.dll
2012-11-25 14:16:21 ----A---- C:\Windows\SysWOW64\shsetup.dll
2012-11-25 14:16:21 ----A---- C:\Windows\SysWOW64\rasppp.dll
2012-11-25 14:16:21 ----A---- C:\Windows\SysWOW64\logoncli.dll
2012-11-25 14:16:21 ----A---- C:\Windows\SysWOW64\cabview.dll
2012-11-25 14:16:20 ----A---- C:\Windows\SysWOW64\FirewallControlPanel.dll
2012-11-25 14:16:19 ----A---- C:\Windows\SysWOW64\themecpl.dll
2012-11-25 14:16:19 ----A---- C:\Windows\SysWOW64\SensorsCpl.dll
2012-11-25 14:16:19 ----A---- C:\Windows\SysWOW64\PhotoScreensaver.scr
2012-11-25 14:16:19 ----A---- C:\Windows\SysWOW64\hgcpl.dll
2012-11-25 14:16:19 ----A---- C:\Windows\SysWOW64\FWPUCLNT.DLL
2012-11-25 14:16:19 ----A---- C:\Windows\SysWOW64\dnscmmc.dll
2012-11-25 14:16:18 ----A---- C:\Windows\SysWOW64\tapisrv.dll
2012-11-25 14:16:18 ----A---- C:\Windows\SysWOW64\scecli.dll
2012-11-25 14:16:18 ----A---- C:\Windows\SysWOW64\mscories.dll
2012-11-25 14:16:18 ----A---- C:\Windows\SysWOW64\fontext.dll
2012-11-25 14:16:17 ----A---- C:\Windows\SysWOW64\wlanui.dll
2012-11-25 14:16:17 ----A---- C:\Windows\SysWOW64\usercpl.dll
2012-11-25 14:16:17 ----A---- C:\Windows\SysWOW64\SndVolSSO.dll
2012-11-25 14:16:17 ----A---- C:\Windows\SysWOW64\PerfCenterCPL.dll
2012-11-25 14:16:17 ----A---- C:\Windows\SysWOW64\mscms.dll
2012-11-25 14:16:17 ----A---- C:\Windows\SysWOW64\mprddm.dll
2012-11-25 14:16:17 ----A---- C:\Windows\SysWOW64\localsec.dll
2012-11-25 14:16:17 ----A---- C:\Windows\SysWOW64\iasacct.dll
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\w32tm.exe
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\VAN.dll
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\spwizeng.dll
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\SndVol.exe
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\qedit.dll
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\prntvpt.dll
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\netcenter.dll
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\batmeter.dll
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\azroleui.dll
2012-11-25 14:16:16 ----A---- C:\Windows\SysWOW64\accessibilitycpl.dll
2012-11-25 14:16:15 ----A---- C:\Windows\SysWOW64\zipfldr.dll
2012-11-25 14:16:15 ----A---- C:\Windows\SysWOW64\networkmap.dll
2012-11-25 14:16:15 ----A---- C:\Windows\SysWOW64\netjoin.dll
2012-11-25 14:16:15 ----A---- C:\Windows\SysWOW64\MSAC3ENC.DLL
2012-11-25 14:16:15 ----A---- C:\Windows\SysWOW64\fdeploy.dll
2012-11-25 14:16:15 ----A---- C:\Windows\SysWOW64\Faultrep.dll
2012-11-25 14:16:15 ----A---- C:\Windows\SysWOW64\cryptui.dll
2012-11-25 14:16:15 ----A---- C:\Windows\SysWOW64\adsldp.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\wusa.exe
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\sud.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\prnfldr.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\photowiz.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\OnLineIDCpl.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\msieftp.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\MediaMetadataHandler.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\MCEWMDRMNDBootstrap.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\iasrad.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\credssp.dll
2012-11-25 14:16:14 ----A---- C:\Windows\SysWOW64\ActionCenter.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\syncui.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\sisbkup.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\shwebsvc.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\iprtrmgr.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\ifsutil.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\ftp.exe
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\efscore.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\dot3cfg.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\defaultlocationcpl.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\autoplay.dll
2012-11-25 14:16:13 ----A---- C:\Windows\SysWOW64\ActionCenterCPL.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\wmpmde.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\sethc.exe
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\rtutils.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\riched20.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\OobeFldr.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\ntprint.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\ntlanman.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\nshwfp.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\dskquoui.dll
2012-11-25 14:16:12 ----A---- C:\Windows\SysWOW64\DeviceCenter.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\wmpsrcwp.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\wavemsp.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\ReAgent.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\nshipsec.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\netplwiz.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\NAPHLPR.DLL
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\msftedit.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\migisol.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\isoburn.exe
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\httpapi.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\fms.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\dpx.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\blackbox.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\asycfilt.dll
2012-11-25 14:16:11 ----A---- C:\Windows\SysWOW64\activeds.dll
2012-11-25 14:16:10 ----A---- C:\Windows\twain_32.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\wvc.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\wuwebv.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\wtsapi32.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\wlanmsm.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\wimgapi.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\tzutil.exe
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\twext.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\shdocvw.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\setupugc.exe
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\qcap.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\qasf.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\provsvc.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\PkgMgr.exe
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\ocsetup.exe
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\mstask.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\dsuiext.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\dot3ui.dll
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\dfrgui.exe
2012-11-25 14:16:10 ----A---- C:\Windows\SysWOW64\AdmTmpl.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\WPDShServiceObj.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\wmdrmsdk.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\wimserv.exe
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\uxlib.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\ssText3d.scr
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\slwga.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\rpcrt4.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\rdpencom.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\nslookup.exe
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\msvfw32.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\msscp.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\mciavi32.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\diskraid.exe
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\DevicePairingFolder.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\clusapi.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\audiodev.dll
2012-11-25 14:16:09 ----A---- C:\Windows\SysWOW64\acppage.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\wpdwcn.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\wmpdxm.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\vpnikeapi.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\vdsbas.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\UserAccountControlSettings.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\runonce.exe
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\remotepg.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\raschap.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\QUTIL.DLL
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\perfmon.exe
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\onexui.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\olepro32.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\ocsetapi.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\networkexplorer.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\NAPCRYPT.DLL
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\msvidc32.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\logagent.exe
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\iTVData.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\input.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\dxdiagn.dll
2012-11-25 14:16:08 ----A---- C:\Windows\SysWOW64\drmmgrtn.dll
2012-11-25 14:16:08 ----A---- C:\Windows\bfsvc.exe
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\wudriver.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\WPDSp.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\wmpshell.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\wmdrmdev.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\unimdmat.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\tsgqec.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\srvcli.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\sqlcese30.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\shacct.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\Ribbons.scr
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\rdpd3d.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\QSVRMGMT.DLL
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\PortableDeviceSyncProvider.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\PortableDeviceStatus.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\pdh.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\OpcServices.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\olethk32.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\ncryptui.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\Mystify.scr
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\msiexec.exe
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\mprapi.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\MFPlay.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\lsmproxy.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\logman.exe
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\iscsium.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\eapp3hst.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\cscapi.dll
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\Bubbles.scr
2012-11-25 14:16:07 ----A---- C:\Windows\SysWOW64\bitsadmin.exe
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\WMPhoto.dll
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\WMADMOD.DLL
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\wiavideo.dll
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\utildll.dll
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\takeown.exe
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\mapistub.dll


_________________
CPU:Intel Core i5 2500K 4,2GHz GPU:MSI GTX 960 4GB RAM:CORSAIR 4GB KIT DDR3 1600MHz CL9 Blue PSU:CORSAIR CX600 V2 MB:P8P67-M PRO B3 Revison Case:CoolerMaster Elite 430 Black Edition Phone:iPhone 6s Plus 128 GB Notebook:Asus GL502VM-FY182T
Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 15.08.11
Prihlásený: 04.09.17
Príspevky: 279
Témy: 46 | 46
Bydlisko: Rabča

Druha polka
Kód:
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\mapi32.dll
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\fphc.dll
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\dot3msm.dll
2012-11-25 14:16:06 ----A---- C:\Windows\SysWOW64\avifil32.dll
2012-11-25 14:16:05 ----A---- C:\Windows\SysWOW64\iyuv_32.dll
2012-11-25 14:16:04 ----A---- C:\Windows\SysWOW64\WMVSDECD.DLL
2012-11-25 14:16:04 ----A---- C:\Windows\SysWOW64\wmdrmnet.dll
2012-11-25 14:16:04 ----A---- C:\Windows\SysWOW64\qdv.dll
2012-11-25 14:16:04 ----A---- C:\Windows\SysWOW64\msnetobj.dll
2012-11-25 14:16:04 ----A---- C:\Windows\SysWOW64\EhStorAPI.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\wsnmp32.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\WMSPDMOD.DLL
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\vfwwdm32.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\tsbyuv.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\sppinst.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\setupcln.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\QCLIPROV.DLL
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\pdhui.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\MuiUnattend.exe
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\msyuv.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\msrle32.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\cmstp.exe
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\cca.dll
2012-11-25 14:16:03 ----A---- C:\Windows\SysWOW64\AzSqlExt.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\wmpps.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\wkscli.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\syssetup.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\spbcd.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\secproc_ssp_isv.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\secproc_ssp.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\resutils.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\relog.exe
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\rastapi.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\netiougc.exe
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\netbtugc.exe
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\mydocs.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\msorcl32.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\itircl.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\iscsicli.exe
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\iasrecst.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\diskpart.exe
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\CertPolEng.dll
2012-11-25 14:16:02 ----A---- C:\Windows\SysWOW64\amstream.dll
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\wuapp.exe
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\WerFaultSecure.exe
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\tlscsp.dll
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\sppc.dll
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\RMActivate_ssp.exe
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\ReAgentc.exe
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\netutils.dll
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\muifontsetup.dll
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\mobsync.exe
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\mciqtz32.dll
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\iccvid.dll
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\findstr.exe
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\eappgnui.dll
2012-11-25 14:16:01 ----A---- C:\Windows\SysWOW64\cabinet.dll
2012-11-25 14:16:00 ----A---- C:\Windows\SysWOW64\unlodctr.exe
2012-11-25 14:16:00 ----A---- C:\Windows\SysWOW64\spopk.dll
2012-11-25 14:16:00 ----A---- C:\Windows\SysWOW64\shimgvw.dll
2012-11-25 14:16:00 ----A---- C:\Windows\SysWOW64\rdprefdrvapi.dll
2012-11-25 14:16:00 ----A---- C:\Windows\SysWOW64\odbcconf.dll
2012-11-25 14:16:00 ----A---- C:\Windows\SysWOW64\msdmo.dll
2012-11-25 14:16:00 ----A---- C:\Windows\SysWOW64\luainstall.dll
2012-11-25 14:16:00 ----A---- C:\Windows\SysWOW64\inetmib1.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\wups.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\wshbth.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\UIRibbonRes.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\TRAPI.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\schedcli.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\perfts.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\napdsnap.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\imm32.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\elsTrans.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\dsauth.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\cscdll.dll
2012-11-25 14:15:59 ----A---- C:\Windows\SysWOW64\bitsperf.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\wshirda.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\wsdchngr.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\wmploc.DLL
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\sscore.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\spwmp.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\shunimpl.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\shgina.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\riched32.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\KBDTUQ.DLL
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\KBDTUF.DLL
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\KBDSG.DLL
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\kbdlk41a.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\KBDGR1.DLL
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\KBDGKL.DLL
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\dxmasf.dll
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\C_ISCII.DLL
2012-11-25 14:15:58 ----A---- C:\Windows\SysWOW64\browseui.dll
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\spwizres.dll
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\pifmgr.dll
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\nlsbres.dll
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDUS.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDUGHR1.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDTURME.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDTAJIK.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDSF.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDPO.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDNEPR.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDMON.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDMAORI.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDLT1.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDINTEL.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDINTAM.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDINORI.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDINMAR.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDINKAN.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDINHIN.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDINBEN.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDGEO.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDCZ1.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDBULG.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDBLR.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\KBDBASH.DLL
2012-11-25 14:15:57 ----A---- C:\Windows\SysWOW64\dpnaddr.dll
2012-11-25 14:15:54 ----A---- C:\Windows\SysWOW64\wdscore.dll
2012-11-25 14:15:49 ----A---- C:\Windows\SysWOW64\sqmapi.dll
2012-11-25 14:15:48 ----A---- C:\Windows\SysWOW64\printmanagement.msc
2012-11-25 14:15:40 ----A---- C:\Windows\SysWOW64\wbemcomn.dll
2012-11-25 13:43:11 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-11-25 13:43:05 ----A---- C:\Windows\SysWOW64\esent.dll
2012-11-25 13:43:03 ----A---- C:\Windows\SysWOW64\fsutil.exe
2012-11-25 13:41:35 ----D---- C:\ProgramData\Adobe
2012-11-24 20:00:02 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-11-24 19:10:44 ----D---- C:\Users\Stano\AppData\Roaming\iZotope
2012-11-24 19:06:26 ----D---- C:\Program Files (x86)\iZotope
2012-11-24 18:35:00 ----D---- C:\Users\Stano\AppData\Roaming\Apple Computer
2012-11-24 18:34:52 ----D---- C:\ProgramData\Apple Computer
2012-11-24 18:34:12 ----D---- C:\Program Files (x86)\Common Files\Apple
2012-11-24 18:34:04 ----D---- C:\ProgramData\Apple
2012-11-24 18:34:04 ----D---- C:\Program Files (x86)\Apple Software Update
2012-11-24 14:59:37 ----D---- C:\Program Files (x86)\Common Files\VST3
2012-11-24 14:59:36 ----D---- C:\Program Files (x86)\Brainworx Music
2012-11-24 14:38:08 ----D---- C:\Users\Stano\AppData\Roaming\uTorrent
2012-11-24 14:27:33 ----D---- C:\Program Files (x86)\Common Files\Digidesign
2012-11-24 14:27:33 ----A---- C:\Windows\SysWOW64\SYNSOEMU.DLL
2012-11-24 14:06:33 ----D---- C:\Windows\SysWOW64\Wat
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\wininet.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\urlmon.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\msrating.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\msls31.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\msfeedssync.exe
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\jscript9.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\jscript.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\iertutil.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\iepeers.dll
2012-11-24 10:32:54 ----A---- C:\Windows\SysWOW64\IEAdvpack.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\wextract.exe
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\webcheck.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\vbscript.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\url.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\SetIEInstalledDate.exe
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\pngfilt.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\occache.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\mshtmler.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\mshtml.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\mshta.exe
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\licmgr10.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\inseng.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\iexpress.exe
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\ieui.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\iesetup.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\iernonce.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\ieframe.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\ieapfltr.dat
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\ieakeng.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\ie4uinit.exe
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\icardie.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2012-11-24 10:32:53 ----A---- C:\Windows\SysWOW64\admparse.dll
2012-11-24 10:32:52 ----A---- C:\Windows\SysWOW64\imgutil.dll
2012-11-24 10:32:52 ----A---- C:\Windows\SysWOW64\ieakui.dll
2012-11-24 10:32:52 ----A---- C:\Windows\SysWOW64\ieaksie.dll
2012-11-24 10:23:07 ----A---- C:\Windows\SysWOW64\wmi.dll
2012-11-24 10:23:07 ----A---- C:\Windows\SysWOW64\imagehlp.dll
2012-11-24 09:59:30 ----A---- C:\Windows\SysWOW64\xmllite.dll
2012-11-24 09:59:28 ----A---- C:\Windows\SysWOW64\odbctrac.dll
2012-11-24 09:59:28 ----A---- C:\Windows\SysWOW64\odbcjt32.dll
2012-11-24 09:59:28 ----A---- C:\Windows\SysWOW64\odbccu32.dll
2012-11-24 09:59:28 ----A---- C:\Windows\SysWOW64\odbccr32.dll
2012-11-24 09:59:28 ----A---- C:\Windows\SysWOW64\odbccp32.dll
2012-11-24 09:59:21 ----A---- C:\Windows\SysWOW64\DWrite.dll
2012-11-24 09:58:46 ----A---- C:\Windows\SysWOW64\poqexec.exe
2012-11-24 09:58:45 ----A---- C:\Windows\SysWOW64\explorer.exe
2012-11-24 09:58:45 ----A---- C:\Windows\explorer.exe
2012-11-24 09:58:43 ----A---- C:\Windows\SysWOW64\CPFilters.dll
2012-11-24 09:58:42 ----A---- C:\Windows\SysWOW64\sbe.dll
2012-11-24 09:58:10 ----A---- C:\Windows\unvise32.exe
2012-11-24 09:57:12 ----A---- C:\Windows\SysWOW64\quartz.dll
2012-11-24 09:57:11 ----A---- C:\Windows\SysWOW64\qdvd.dll
2012-11-24 09:57:05 ----A---- C:\Windows\SysWOW64\ntshrui.dll
2012-11-24 09:56:51 ----A---- C:\Windows\SysWOW64\tquery.dll
2012-11-24 09:56:51 ----A---- C:\Windows\SysWOW64\SearchProtocolHost.exe
2012-11-24 09:56:51 ----A---- C:\Windows\SysWOW64\SearchIndexer.exe
2012-11-24 09:56:51 ----A---- C:\Windows\SysWOW64\mssrch.dll
2012-11-24 09:56:51 ----A---- C:\Windows\SysWOW64\mssph.dll
2012-11-24 09:56:50 ----A---- C:\Windows\SysWOW64\SearchFilterHost.exe
2012-11-24 09:56:50 ----A---- C:\Windows\SysWOW64\mssvp.dll
2012-11-24 09:56:50 ----A---- C:\Windows\SysWOW64\mssphtb.dll
2012-11-24 09:56:50 ----A---- C:\Windows\SysWOW64\msscntrs.dll
2012-11-24 09:56:27 ----A---- C:\Windows\SysWOW64\webio.dll
2012-11-24 09:55:59 ----A---- C:\Windows\SysWOW64\msxml6.dll
2012-11-24 09:55:59 ----A---- C:\Windows\SysWOW64\msxml3r.dll
2012-11-24 09:55:59 ----A---- C:\Windows\SysWOW64\msxml3.dll
2012-11-24 09:54:40 ----A---- C:\Windows\SysWOW64\XpsGdiConverter.dll
2012-11-24 09:54:21 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2012-11-24 09:54:21 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2012-11-24 09:54:05 ----A---- C:\Windows\SysWOW64\XpsPrint.dll
2012-11-24 09:54:00 ----A---- C:\Windows\SysWOW64\mfc42u.dll
2012-11-24 09:54:00 ----A---- C:\Windows\SysWOW64\mfc42.dll
2012-11-24 09:53:58 ----A---- C:\Windows\SysWOW64\shell32.dll
2012-11-24 09:53:47 ----A---- C:\Windows\SysWOW64\kernel32.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2012-11-24 09:53:46 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2012-11-24 09:53:46 ----A---- C:\Windows\SysWOW64\wow32.dll
2012-11-24 09:53:46 ----A---- C:\Windows\SysWOW64\user.exe
2012-11-24 09:53:46 ----A---- C:\Windows\SysWOW64\setup16.exe
2012-11-24 09:53:46 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2012-11-24 09:53:46 ----A---- C:\Windows\SysWOW64\KernelBase.dll
2012-11-24 09:53:46 ----A---- C:\Windows\SysWOW64\instnm.exe
2012-11-24 09:52:47 ----A---- C:\Windows\SysWOW64\d3d10level9.dll
2012-11-24 09:52:16 ----A---- C:\Windows\SysWOW64\schannel.dll
2012-11-24 09:52:14 ----A---- C:\Windows\SysWOW64\sspicli.dll
2012-11-24 09:52:14 ----A---- C:\Windows\SysWOW64\secur32.dll
2012-11-24 09:52:14 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2012-11-24 09:51:56 ----A---- C:\Windows\SysWOW64\fontsub.dll
2012-11-24 09:51:56 ----A---- C:\Windows\SysWOW64\atmlib.dll
2012-11-24 09:51:56 ----A---- C:\Windows\SysWOW64\atmfd.dll
2012-11-24 09:51:26 ----A---- C:\Windows\SysWOW64\dnsapi.dll
2012-11-24 09:51:25 ----A---- C:\Windows\SysWOW64\dnscacheugc.exe
2012-11-24 09:50:27 ----A---- C:\Windows\SysWOW64\wintrust.dll
2012-11-24 09:50:10 ----A---- C:\Windows\SysWOW64\tzres.dll
2012-11-24 09:49:35 ----A---- C:\Windows\SysWOW64\d3d10_1core.dll
2012-11-24 09:49:35 ----A---- C:\Windows\SysWOW64\d3d10_1.dll
2012-11-24 09:49:30 ----A---- C:\Windows\SysWOW64\psisdecd.dll
2012-11-24 09:49:10 ----A---- C:\Windows\SysWOW64\kerberos.dll
2012-11-24 09:49:05 ----A---- C:\Windows\SysWOW64\msi.dll
2012-11-24 09:48:27 ----A---- C:\Windows\SysWOW64\synceng.dll
2012-11-24 09:47:31 ----A---- C:\Windows\SysWOW64\drvinst.exe
2012-11-24 09:47:31 ----A---- C:\Windows\SysWOW64\devrtl.dll
2012-11-24 09:47:31 ----A---- C:\Windows\SysWOW64\devobj.dll
2012-11-24 09:47:31 ----A---- C:\Windows\SysWOW64\cfgmgr32.dll
2012-11-24 09:47:25 ----A---- C:\Windows\SysWOW64\netapi32.dll
2012-11-24 09:47:25 ----A---- C:\Windows\SysWOW64\browcli.dll
2012-11-24 09:47:08 ----A---- C:\Windows\SysWOW64\prevhost.exe
2012-11-24 09:47:07 ----A---- C:\Windows\SysWOW64\srclient.dll
2012-11-24 09:47:04 ----A---- C:\Windows\SysWOW64\inetcomm.dll
2012-11-24 09:46:59 ----A---- C:\Windows\SysWOW64\msvcrt.dll
2012-11-24 09:46:52 ----A---- C:\Windows\SysWOW64\oleacc.dll
2012-11-24 09:46:51 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2012-11-24 09:46:45 ----A---- C:\Windows\SysWOW64\EncDec.dll
2012-11-24 09:46:27 ----A---- C:\Windows\SysWOW64\cdosys.dll
2012-11-24 09:46:13 ----A---- C:\Windows\SysWOW64\ntdll.dll
2012-11-24 09:46:07 ----A---- C:\Windows\SysWOW64\win32spl.dll
2012-11-24 09:46:07 ----A---- C:\Windows\splwow64.exe
2012-11-24 09:46:01 ----A---- C:\Windows\SysWOW64\cryptsvc.dll
2012-11-24 09:46:01 ----A---- C:\Windows\SysWOW64\cryptnet.dll
2012-11-24 09:46:01 ----A---- C:\Windows\SysWOW64\crypt32.dll
2012-11-24 09:26:53 ----A---- C:\Windows\SysWOW64\packager.dll
2012-11-24 09:23:17 ----A---- C:\Windows\SysWOW64\rdpcore.dll
2012-11-24 09:17:00 ----D---- C:\Users\Stano\AppData\Roaming\Macromedia
2012-11-24 09:16:59 ----D---- C:\Users\Stano\AppData\Roaming\Adobe
2012-11-24 09:15:33 ----D---- C:\Users\Stano\AppData\Roaming\vlc
2012-11-24 09:14:55 ----A---- C:\Windows\SysWOW64\PnkBstrB.exe
2012-11-24 09:14:51 ----A---- C:\Windows\SysWOW64\PnkBstrA.exe
2012-11-24 09:14:38 ----D---- C:\Program Files (x86)\Ubisoft
2012-11-24 09:14:29 ----A---- C:\Windows\SysWOW64\XAudio2_7.dll
2012-11-24 09:14:29 ----A---- C:\Windows\SysWOW64\XAPOFX1_5.dll
2012-11-24 09:14:27 ----A---- C:\Windows\SysWOW64\xactengine3_7.dll
2012-11-24 09:14:27 ----A---- C:\Windows\SysWOW64\d3dcsx_43.dll
2012-11-24 09:14:27 ----A---- C:\Windows\SysWOW64\D3DCompiler_43.dll
2012-11-24 09:14:26 ----A---- C:\Windows\SysWOW64\D3DX9_43.dll
2012-11-24 09:14:26 ----A---- C:\Windows\SysWOW64\d3dx11_43.dll
2012-11-24 09:14:26 ----A---- C:\Windows\SysWOW64\d3dx10_43.dll
2012-11-24 09:14:24 ----A---- C:\Windows\SysWOW64\XAudio2_6.dll
2012-11-24 09:14:24 ----A---- C:\Windows\SysWOW64\XAPOFX1_4.dll
2012-11-24 09:14:21 ----A---- C:\Windows\SysWOW64\xactengine3_6.dll
2012-11-24 09:14:21 ----A---- C:\Windows\SysWOW64\X3DAudio1_7.dll
2012-11-24 09:14:19 ----A---- C:\Windows\SysWOW64\XAudio2_5.dll
2012-11-24 09:14:19 ----A---- C:\Windows\SysWOW64\xactengine3_5.dll
2012-11-24 09:14:19 ----A---- C:\Windows\SysWOW64\d3dcsx_42.dll
2012-11-24 09:14:19 ----A---- C:\Windows\SysWOW64\D3DCompiler_42.dll
2012-11-24 09:14:18 ----A---- C:\Windows\SysWOW64\D3DX9_42.dll
2012-11-24 09:14:18 ----A---- C:\Windows\SysWOW64\d3dx11_42.dll
2012-11-24 09:14:18 ----A---- C:\Windows\SysWOW64\d3dx10_42.dll
2012-11-24 09:14:18 ----A---- C:\Windows\SysWOW64\d3dx10_41.dll
2012-11-24 09:14:18 ----A---- C:\Windows\SysWOW64\D3DCompiler_41.dll
2012-11-24 09:14:17 ----A---- C:\Windows\SysWOW64\XAudio2_4.dll
2012-11-24 09:14:17 ----A---- C:\Windows\SysWOW64\XAPOFX1_3.dll
2012-11-24 09:14:17 ----A---- C:\Windows\SysWOW64\D3DX9_41.dll
2012-11-24 09:14:15 ----A---- C:\Windows\SysWOW64\xactengine3_4.dll
2012-11-24 09:14:15 ----A---- C:\Windows\SysWOW64\X3DAudio1_6.dll
2012-11-24 09:14:15 ----A---- C:\Windows\SysWOW64\d3dx10_40.dll
2012-11-24 09:14:15 ----A---- C:\Windows\SysWOW64\D3DCompiler_40.dll
2012-11-24 09:14:14 ----A---- C:\Windows\SysWOW64\D3DX9_40.dll
2012-11-24 09:14:13 ----A---- C:\Windows\SysWOW64\XAudio2_3.dll
2012-11-24 09:14:13 ----A---- C:\Windows\SysWOW64\XAPOFX1_2.dll
2012-11-24 09:14:13 ----A---- C:\Windows\SysWOW64\xactengine3_3.dll
2012-11-24 09:14:13 ----A---- C:\Windows\SysWOW64\X3DAudio1_5.dll
2012-11-24 09:14:12 ----A---- C:\Windows\SysWOW64\XAudio2_2.dll
2012-11-24 09:14:12 ----A---- C:\Windows\SysWOW64\XAPOFX1_1.dll
2012-11-24 09:14:11 ----A---- C:\Windows\SysWOW64\xactengine3_2.dll
2012-11-24 09:14:11 ----A---- C:\Windows\SysWOW64\D3DX9_39.dll
2012-11-24 09:14:11 ----A---- C:\Windows\SysWOW64\d3dx10_39.dll
2012-11-24 09:14:11 ----A---- C:\Windows\SysWOW64\D3DCompiler_39.dll
2012-11-24 09:14:10 ----A---- C:\Windows\SysWOW64\XAudio2_1.dll
2012-11-24 09:14:10 ----A---- C:\Windows\SysWOW64\XAPOFX1_0.dll
2012-11-24 09:14:09 ----A---- C:\Windows\SysWOW64\xactengine3_1.dll
2012-11-24 09:14:09 ----A---- C:\Windows\SysWOW64\X3DAudio1_4.dll
2012-11-24 09:14:09 ----A---- C:\Windows\SysWOW64\D3DX9_38.dll
2012-11-24 09:14:09 ----A---- C:\Windows\SysWOW64\d3dx10_38.dll
2012-11-24 09:14:09 ----A---- C:\Windows\SysWOW64\D3DCompiler_38.dll
2012-11-24 09:14:07 ----A---- C:\Windows\SysWOW64\XAudio2_0.dll
2012-11-24 09:14:07 ----A---- C:\Windows\SysWOW64\xactengine3_0.dll
2012-11-24 09:14:07 ----A---- C:\Windows\SysWOW64\X3DAudio1_3.dll
2012-11-24 09:14:06 ----A---- C:\Windows\SysWOW64\d3dx10_37.dll
2012-11-24 09:14:06 ----A---- C:\Windows\SysWOW64\D3DCompiler_37.dll
2012-11-24 09:14:05 ----A---- C:\Windows\SysWOW64\xactengine2_10.dll
2012-11-24 09:14:05 ----A---- C:\Windows\SysWOW64\D3DX9_37.dll
2012-11-24 09:14:04 ----A---- C:\Windows\SysWOW64\d3dx10_36.dll
2012-11-24 09:14:04 ----A---- C:\Windows\SysWOW64\D3DCompiler_36.dll
2012-11-24 09:14:03 ----A---- C:\Windows\SysWOW64\xactengine2_9.dll
2012-11-24 09:14:03 ----A---- C:\Windows\SysWOW64\d3dx9_36.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\xinput1_3.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\xactengine2_8.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\X3DAudio1_2.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\d3dx9_35.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\d3dx9_34.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\d3dx10_35.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\d3dx10_34.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\D3DCompiler_35.dll
2012-11-24 09:14:02 ----A---- C:\Windows\SysWOW64\D3DCompiler_34.dll
2012-11-24 09:14:01 ----A---- C:\Windows\SysWOW64\xactengine2_7.dll
2012-11-24 09:14:01 ----A---- C:\Windows\SysWOW64\d3dx9_33.dll
2012-11-24 09:14:01 ----A---- C:\Windows\SysWOW64\d3dx10_33.dll
2012-11-24 09:14:01 ----A---- C:\Windows\SysWOW64\D3DCompiler_33.dll
2012-11-24 09:14:00 ----A---- C:\Windows\SysWOW64\xactengine2_6.dll
2012-11-24 09:14:00 ----A---- C:\Windows\SysWOW64\xactengine2_5.dll
2012-11-24 09:14:00 ----A---- C:\Windows\SysWOW64\d3dx9_32.dll
2012-11-24 09:14:00 ----A---- C:\Windows\SysWOW64\d3dx10.dll
2012-11-24 09:13:59 ----A---- C:\Windows\SysWOW64\xinput1_2.dll
2012-11-24 09:13:59 ----A---- C:\Windows\SysWOW64\xinput1_1.dll
2012-11-24 09:13:59 ----A---- C:\Windows\SysWOW64\xactengine2_4.dll
2012-11-24 09:13:59 ----A---- C:\Windows\SysWOW64\xactengine2_3.dll
2012-11-24 09:13:59 ----A---- C:\Windows\SysWOW64\xactengine2_2.dll
2012-11-24 09:13:59 ----A---- C:\Windows\SysWOW64\x3daudio1_1.dll
2012-11-24 09:13:59 ----A---- C:\Windows\SysWOW64\d3dx9_31.dll
2012-11-24 09:13:58 ----A---- C:\Windows\SysWOW64\xactengine2_1.dll
2012-11-24 09:13:50 ----A---- C:\Windows\SysWOW64\d3dx9_30.dll
2012-11-24 09:13:40 ----A---- C:\Windows\SysWOW64\xactengine2_0.dll
2012-11-24 09:13:40 ----A---- C:\Windows\SysWOW64\x3daudio1_0.dll
2012-11-24 09:13:36 ----A---- C:\Windows\SysWOW64\d3dx9_29.dll
2012-11-24 09:13:35 ----A---- C:\Windows\SysWOW64\d3dx9_28.dll
2012-11-24 09:13:35 ----A---- C:\Windows\SysWOW64\d3dx9_27.dll
2012-11-24 09:13:34 ----A---- C:\Windows\SysWOW64\d3dx9_26.dll
2012-11-24 09:13:33 ----A---- C:\Windows\SysWOW64\d3dx9_25.dll
2012-11-24 09:13:29 ----A---- C:\Windows\SysWOW64\d3dx9_24.dll
2012-11-23 20:21:44 ----A---- C:\Windows\SysWOW64\msvcr71.dll
2012-11-23 20:21:44 ----A---- C:\Windows\SysWOW64\mfc71.dll
2012-11-23 20:21:44 ----A---- C:\Windows\SysWOW64\gdiplus.dll
2012-11-23 20:20:15 ----D---- C:\Program Files (x86)\ASIO4ALL v2
2012-11-23 20:20:08 ----D---- C:\Program Files (x86)\VstPlugins
2012-11-23 20:20:08 ----A---- C:\Windows\SysWOW64\rewire.dll
2012-11-23 20:20:05 ----D---- C:\Program Files (x86)\Image-Line
2012-11-23 20:20:00 ----D---- C:\Users\Stano\AppData\Roaming\WinRAR
2012-11-23 20:19:51 ----D---- C:\Program Files (x86)\Outsim
2012-11-23 20:16:26 ----D---- C:\Windows\SysWOW64\Macromed
2012-11-23 20:16:03 ----D---- C:\Users\Stano\AppData\Roaming\Skype
2012-11-23 20:15:50 ----D---- C:\ProgramData\Skype
2012-11-23 19:51:23 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-11-23 19:51:23 ----D---- C:\Program Files (x86)\Realtek
2012-11-23 19:49:40 ----A---- C:\Windows\Language_trs.ini
2012-11-23 19:44:59 ----D---- C:\Users\Stano\AppData\Roaming\Opera
2012-11-23 19:34:58 ----SHD---- C:\Windows\Installer
2012-11-23 19:34:55 ----D---- C:\ProgramData\NVIDIA
2012-11-23 19:34:54 ----D---- C:\Users\Stano\AppData\Roaming\DAEMON Tools Lite
2012-11-23 19:34:37 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-11-23 19:34:06 ----D---- C:\ProgramData\NVIDIA Corporation
2012-11-23 19:34:04 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-11-23 19:33:36 ----A---- C:\Windows\SysWOW64\nvdecodemft.dll
2012-11-23 19:29:40 ----D---- C:\Users\Stano\AppData\Roaming\Identities
2012-11-23 19:28:28 ----SD---- C:\Users\Stano\AppData\Roaming\Microsoft
2012-11-23 19:28:28 ----D---- C:\Users\Stano\AppData\Roaming\Media Center Programs
2012-11-23 19:28:06 ----SHD---- C:\ProgramData\Šablony
2012-11-23 19:28:06 ----SHD---- C:\ProgramData\Plocha
2012-11-23 19:28:06 ----SHD---- C:\ProgramData\Oblíbené položky
2012-11-23 19:28:06 ----SHD---- C:\ProgramData\Nabídka Start
2012-11-23 19:28:06 ----SHD---- C:\ProgramData\Dokumenty
2012-11-23 19:28:06 ----SHD---- C:\ProgramData\Data aplikací
2012-11-23 19:09:00 ----D---- C:\Windows\SoftwareDistribution
2012-11-23 19:06:26 ----D---- C:\Windows\Prefetch
2012-11-23 19:05:09 ----D---- C:\Windows\Panther
2012-11-23 18:52:35 ----D---- C:\Windows.old
2012-11-03 10:43:44 ----D---- C:\Flashtool

======List of files/folders modified in the last 1 month======

2012-11-30 16:15:12 ----D---- C:\Windows\Temp
2012-11-30 16:15:09 ----RD---- C:\Program Files (x86)
2012-11-30 15:40:53 ----SHD---- C:\System Volume Information
2012-11-30 15:40:34 ----D---- C:\Windows\System32
2012-11-30 15:40:33 ----D---- C:\Windows
2012-11-30 15:40:32 ----SHD---- C:\Config.Msi
2012-11-29 15:28:45 ----D---- C:\Windows\SysWOW64
2012-11-29 14:44:59 ----D---- C:\Windows\inf
2012-11-28 21:02:26 ----HD---- C:\ProgramData
2012-11-28 14:49:28 ----D---- C:\Windows\winsxs
2012-11-28 14:49:20 ----D---- C:\Windows\AppPatch
2012-11-27 17:16:16 ----RSD---- C:\Windows\assembly
2012-11-27 17:16:16 ----D---- C:\Windows\Microsoft.NET
2012-11-27 17:10:30 ----D---- C:\Windows\SysWOW64\cs-CZ
2012-11-27 17:10:29 ----D---- C:\Windows\PolicyDefinitions
2012-11-27 17:10:28 ----D---- C:\Windows\SysWOW64\migration
2012-11-26 18:36:02 ----D---- C:\Program Files (x86)\Common Files
2012-11-26 17:14:27 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2012-11-26 17:07:58 ----SD---- C:\ProgramData\Microsoft
2012-11-26 15:35:25 ----SHD---- C:\Boot
2012-11-26 15:30:58 ----D---- C:\Program Files (x86)\Windows Sidebar
2012-11-26 15:30:58 ----D---- C:\Program Files (x86)\Windows Portable Devices
2012-11-26 15:30:58 ----D---- C:\Program Files (x86)\Windows Media Player
2012-11-26 15:30:58 ----D---- C:\Program Files (x86)\Windows Mail
2012-11-26 15:30:57 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2012-11-26 15:30:57 ----D---- C:\Program Files (x86)\Common Files\System
2012-11-26 15:30:53 ----D---- C:\Windows\servicing
2012-11-26 15:30:53 ----D---- C:\Windows\ehome
2012-11-26 15:30:43 ----D---- C:\Windows\SysWOW64\Setup
2012-11-26 15:30:43 ----D---- C:\Windows\SysWOW64\oobe
2012-11-26 15:30:43 ----D---- C:\Windows\SysWOW64\da-DK
2012-11-26 15:30:43 ----D---- C:\Windows\SysWOW64\cs
2012-11-26 15:30:43 ----D---- C:\Windows\SysWOW64\AdvancedInstallers
2012-11-26 15:30:40 ----D---- C:\Windows\SysWOW64\sppui
2012-11-26 15:30:40 ----D---- C:\Windows\SysWOW64\manifeststore
2012-11-26 15:30:40 ----D---- C:\Windows\SysWOW64\es-ES
2012-11-26 15:30:39 ----D---- C:\Windows\SysWOW64\wbem
2012-11-26 15:30:39 ----D---- C:\Windows\SysWOW64\migwiz
2012-11-26 15:30:39 ----D---- C:\Windows\SysWOW64\Dism
2012-11-26 15:29:28 ----RSD---- C:\Windows\Fonts
2012-11-26 12:33:30 ----A---- C:\Windows\SysWOW64\msclmd.dll
2012-11-26 12:25:24 ----D---- C:\Windows\debug
2012-11-25 18:35:29 ----D---- C:\Windows\Cursors
2012-11-25 13:43:13 ----D---- C:\Windows\Tasks
2012-11-24 20:00:02 ----D---- C:\Windows\SysWOW64\en-US
2012-11-24 17:34:43 ----D---- C:\temp
2012-11-24 14:06:41 ----D---- C:\Program Files (x86)\Internet Explorer
2012-11-24 10:33:47 ----D---- C:\Windows\Logs
2012-11-23 19:34:54 ----RD---- C:\Users
2012-11-23 19:34:24 ----D---- C:\Windows\Help
2012-11-23 19:33:09 ----RD---- C:\Program Files
2012-11-23 19:29:37 ----SHD---- C:\$Recycle.Bin
2012-11-23 19:28:06 ----D---- C:\Recovery
2012-11-23 19:27:55 ----D---- C:\Windows\rescache
2012-11-23 19:06:46 ----D---- C:\Windows\CSC
2012-11-23 19:04:57 ----RASH---- C:\BOOTSECT.BAK
2012-11-23 19:04:36 ----D---- C:\Windows\Setup

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2011-03-18 29592]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys []
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R2 cpuz134;cpuz134; \??\C:\Windows\system32\drivers\cpuz134_x64.sys []
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys []
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys []
R3 RTCore64;RTCore64; \??\E:\Programy\MSI Afterburner\RTCore64.sys [2010-08-31 14648]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
S3 a6imafaz;a6imafaz; C:\Windows\SysWOW64\drivers\a6imafaz.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 WinUSB;Sony sa0102 ADB Interface; C:\Windows\system32\DRIVERS\WinUSB.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; E:\Programy\nero\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe []
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [2006-12-19 81920]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-11-24 75136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R2 VideoAcceleratorService;VideoAcceleratorService; E:\Programy\SPEEDB~1\SPEEDB~1\VideoAcceleratorService.exe [2012-11-23 265928]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 SkypeUpdate;Skype Updater; E:\Programy\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-26 250808]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []

-----------------EOF-----------------


_________________
CPU:Intel Core i5 2500K 4,2GHz GPU:MSI GTX 960 4GB RAM:CORSAIR 4GB KIT DDR3 1600MHz CL9 Blue PSU:CORSAIR CX600 V2 MB:P8P67-M PRO B3 Revison Case:CoolerMaster Elite 430 Black Edition Phone:iPhone 6s Plus 128 GB Notebook:Asus GL502VM-FY182T
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 14.09.16
Príspevky: 618
Témy: 2 | 2

aplikuj combofix http://www.bleepingcomputer.com/download/combofix/ spusť keď skonči pošli log z c:combofix.txt


Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 15.08.11
Prihlásený: 04.09.17
Príspevky: 279
Témy: 46 | 46
Bydlisko: Rabča

Takze aplikoval som to tu je log
Kód:
ComboFix 12-11-30.02 - Stano . 11. 2012  19:14:36.1.4 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1250.421.1029.18.4077.2490 [GMT 1:00]
Running from: c:\users\Stano\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\BitAccelerator
c:\program files (x86)\BitAccelerator\BiTAccelerator.dll
c:\users\Stano\AppData\Roaming\CMDHost0.exe
c:\users\Stano\AppData\Roaming\HostServices6.exe
c:\users\Stano\AppData\Roaming\Nethosts2.exe
c:\users\Stano\AppData\Roaming\tep841
c:\users\Stano\drivers\explorer.exe
c:\users\Stano\msdata
c:\users\Stano\msdata\cmdhost_w1c_5.exe
c:\users\Stano\msdata\cmdhost_w1c_571.exe
c:\users\Stano\msdata\cmdhost_w1c_7207.exe
c:\users\Stano\msdata\cmdhost_w1c_9291.exe
c:\users\Stano\msdata\explorer.exe
c:\users\Stano\msdata\iexplorer.exe
c:\users\Stano\msdata\ltc_w1.exe
c:\users\Stano\msdata\nethost_w2c_5397.exe
c:\users\Stano\msdata\nethost_w2c_5420.exe
c:\windows\msxml4-KB954430-enu.LOG
c:\windows\msxml4-KB973688-enu.LOG
E:\x3xh.exe
.
.
(((((((((((((((((((((((((   Files Created from 2012-10-28 to 2012-11-30  )))))))))))))))))))))))))))))))
.
.
2012-11-30 18:18 . 2012-11-30 18:18   --------   d-----w-   c:\users\Default\AppData\Local\temp
2012-11-30 17:50 . 2012-11-30 17:50   --------   d-----w-   c:\program files (x86)\Common Files\Skype
2012-11-30 17:43 . 2012-11-30 17:50   --------   d-----r-   c:\program files (x86)\Skype
2012-11-30 15:15 . 2012-11-30 15:15   --------   d-----w-   C:\rsit
2012-11-30 15:15 . 2012-11-30 15:15   --------   d-----w-   c:\program files (x86)\trend micro
2012-11-30 14:40 . 2012-11-30 14:40   --------   d-----w-   c:\windows\system32\appmgmt
2012-11-29 14:39 . 2012-11-30 15:32   --------   d-----w-   c:\program files (x86)\Counter Strike Source
2012-11-29 13:40 . 2011-10-15 08:53   68928   ----a-w-   c:\windows\system32\OpenCL.dll
2012-11-29 13:40 . 2011-10-15 08:53   61248   ----a-w-   c:\windows\SysWow64\OpenCL.dll
2012-11-29 13:40 . 2011-10-15 08:53   1454400   ----a-w-   c:\windows\system32\nvgenco64.dll
2012-11-29 13:40 . 2011-07-07 23:21   29288   ----a-w-   c:\windows\system32\nvhdap64.dll
2012-11-29 13:40 . 2011-07-07 23:21   174184   ----a-w-   c:\windows\system32\drivers\nvhda64v.sys
2012-11-29 13:40 . 2011-07-07 23:21   1452648   ----a-w-   c:\windows\system32\nvhdagenco6420102.dll
2012-11-28 20:02 . 2012-11-28 20:03   --------   d-----w-   c:\programdata\OpenBitCoin
2012-11-28 20:02 . 2012-11-28 20:03   --------   d-----w-   c:\program files (x86)\OpenBitCoin
2012-11-28 14:50 . 2012-11-28 14:50   2048   ----a-w-   c:\windows\SysWow64\winver.exe
2012-11-28 14:50 . 2012-11-28 14:50   833024   ----a-w-   c:\windows\SysWow64\user32.dll
2012-11-28 14:50 . 2012-11-28 14:50   410624   ----a-w-   c:\windows\SysWow64\systemcpl.dll
2012-11-28 14:50 . 2012-11-28 14:50   1536   ----a-w-   c:\windows\SysWow64\sppcomapi.dll
2012-11-28 14:50 . 2012-11-28 14:50   113543   ----a-w-   c:\windows\SysWow64\slmgr.vbs
2012-11-27 18:25 . 2012-11-27 18:25   --------   d-----w-   c:\program files (x86)\MSXML 4.0
2012-11-27 11:27 . 2012-08-21 21:01   245760   ----a-w-   c:\windows\system32\OxpsConverter.exe
2012-11-27 11:27 . 2012-11-19 00:01   9125352   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{710D11FA-BF09-4F9B-9ECF-687F3613BDE7}\mpengine.dll
2012-11-26 17:36 . 2012-11-27 16:12   --------   d-----w-   c:\program files (x86)\Common Files\Steam
2012-11-26 16:15 . 2012-11-26 16:15   --------   d-----w-   c:\program files (x86)\Microsoft
2012-11-26 16:14 . 2012-11-26 16:14   --------   d-----w-   c:\program files (x86)\Windows Live SkyDrive
2012-11-26 16:13 . 2012-11-26 16:15   --------   d-----w-   c:\program files (x86)\Windows Live
2012-11-26 16:12 . 2012-11-26 16:12   --------   d-----w-   c:\windows\PCHEALTH
2012-11-26 16:09 . 2012-11-26 16:09   --------   d-----w-   c:\program files (x86)\Microsoft SQL Server Compact Edition
2012-11-26 16:08 . 2012-11-26 16:08   --------   d-----w-   c:\program files (x86)\Common Files\Windows Live
2012-11-26 11:27 . 2012-11-26 11:27   --------   d-----w-   c:\windows\system32\SPReview
2012-11-26 11:26 . 2012-11-26 11:26   --------   d-----w-   c:\windows\system32\EventProviders
2012-11-26 11:25 . 2012-10-29 20:04   66395536   ----a-w-   c:\windows\system32\MRT.exe
2012-11-25 17:35 . 2012-11-25 17:36   --------   d-----w-   c:\program files (x86)\Common Files\Nero
2012-11-25 17:35 . 2012-11-25 17:35   --------   d-----w-   c:\programdata\Nero
2012-11-25 14:06 . 2012-11-25 14:06   --------   d-----w-   c:\program files (x86)\SpeedFan
2012-11-25 13:16 . 2010-11-20 12:18   508416   ----a-w-   c:\windows\SysWow64\dxgi.dll
2012-11-25 13:15 . 2010-11-20 13:27   47104   ----a-w-   c:\windows\system32\wshbth.dll
2012-11-25 13:14 . 2010-11-20 13:27   529408   ----a-w-   c:\windows\system32\wbemcomn.dll
2012-11-25 13:14 . 2010-11-20 13:27   244736   ----a-w-   c:\program files\Windows Portable Devices\sqmapi.dll
2012-11-25 13:14 . 2010-11-20 13:27   244736   ----a-w-   c:\windows\system32\sqmapi.dll
2012-11-24 18:06 . 2012-11-24 18:06   --------   d-----w-   c:\program files (x86)\iZotope
2012-11-24 18:06 . 2012-11-24 18:06   --------   d-----w-   c:\program files\Common Files\VST3
2012-11-24 17:34 . 2012-11-24 17:34   --------   d-----w-   c:\programdata\Apple Computer
2012-11-24 17:34 . 2012-11-24 17:34   --------   d-----w-   c:\program files (x86)\Common Files\Apple
2012-11-24 17:34 . 2012-11-24 17:34   --------   d-----w-   c:\programdata\Apple
2012-11-24 17:34 . 2012-11-24 17:34   --------   d-----w-   c:\program files (x86)\Apple Software Update
2012-11-24 13:59 . 2012-11-24 13:59   --------   d-----w-   c:\program files (x86)\Common Files\VST3
2012-11-24 13:59 . 2012-11-24 13:59   --------   d-----w-   c:\program files (x86)\Brainworx Music
2012-11-24 13:27 . 2012-11-24 13:27   --------   d-----w-   c:\program files (x86)\Common Files\Digidesign
2012-11-24 13:27 . 2009-10-24 20:15   1332224   ----a-w-   c:\windows\SysWow64\SYNSOEMU.DLL
2012-11-24 13:06 . 2012-11-24 13:06   --------   d-----w-   c:\windows\SysWow64\Wat
2012-11-24 13:06 . 2012-11-24 13:06   --------   d-----w-   c:\windows\system32\Wat
2012-11-24 09:43 . 2012-07-26 07:40   2560   ----a-w-   c:\windows\system32\drivers\cs-CZ\wdf01000.sys.mui
2012-11-24 09:43 . 2012-07-26 04:55   785512   ----a-w-   c:\windows\system32\drivers\Wdf01000.sys
2012-11-24 09:43 . 2012-07-26 04:55   54376   ----a-w-   c:\windows\system32\drivers\WdfLdr.sys
2012-11-24 09:43 . 2012-07-26 02:36   9728   ----a-w-   c:\windows\system32\Wdfres.dll
2012-11-24 09:35 . 2010-02-23 08:16   294912   ----a-w-   c:\windows\system32\browserchoice.exe
2012-11-24 09:25 . 2012-07-26 03:08   229888   ----a-w-   c:\windows\system32\WUDFHost.exe
2012-11-24 09:25 . 2012-07-26 03:08   84992   ----a-w-   c:\windows\system32\WUDFSvc.dll
2012-11-24 09:25 . 2012-07-26 03:08   45056   ----a-w-   c:\windows\system32\WUDFCoinstaller.dll
2012-11-24 09:25 . 2012-07-26 03:08   194048   ----a-w-   c:\windows\system32\WUDFPlatform.dll
2012-11-24 09:25 . 2012-07-26 02:26   87040   ----a-w-   c:\windows\system32\drivers\WUDFPf.sys
2012-11-24 09:25 . 2012-07-26 02:26   198656   ----a-w-   c:\windows\system32\drivers\WUDFRd.sys
2012-11-24 09:25 . 2012-07-26 03:08   744448   ----a-w-   c:\windows\system32\WUDFx.dll
2012-11-24 09:23 . 2012-03-01 06:46   23408   ----a-w-   c:\windows\system32\drivers\fs_rec.sys
2012-11-24 09:23 . 2012-03-01 06:33   81408   ----a-w-   c:\windows\system32\imagehlp.dll
2012-11-24 09:23 . 2012-03-01 06:28   5120   ----a-w-   c:\windows\system32\wmi.dll
2012-11-24 09:23 . 2012-03-01 05:33   159232   ----a-w-   c:\windows\SysWow64\imagehlp.dll
2012-11-24 09:23 . 2012-03-01 05:29   5120   ----a-w-   c:\windows\SysWow64\wmi.dll
2012-11-24 08:58 . 2011-04-09 06:58   142336   ----a-w-   c:\windows\system32\poqexec.exe
2012-11-24 08:58 . 2011-04-09 05:56   123904   ----a-w-   c:\windows\SysWow64\poqexec.exe
2012-11-24 08:58 . 2011-02-25 06:19   2871808   ----a-w-   c:\windows\explorer.exe
2012-11-24 08:58 . 2011-02-25 05:30   2616320   ----a-w-   c:\windows\SysWow64\explorer.exe
2012-11-24 08:58 . 2010-12-23 10:42   1118720   ----a-w-   c:\windows\system32\sbe.dll
2012-11-24 08:58 . 2010-12-23 10:42   961024   ----a-w-   c:\windows\system32\CPFilters.dll
2012-11-24 08:58 . 2010-12-23 05:54   642048   ----a-w-   c:\windows\SysWow64\CPFilters.dll
2012-11-24 08:58 . 2010-12-23 10:36   259072   ----a-w-   c:\windows\system32\mpg2splt.ax
2012-11-24 08:58 . 2010-12-23 05:54   850944   ----a-w-   c:\windows\SysWow64\sbe.dll
2012-11-24 08:58 . 2010-12-23 05:50   199680   ----a-w-   c:\windows\SysWow64\mpg2splt.ax
2012-11-24 08:58 . 1999-12-17 09:13   86016   ----a-w-   c:\windows\unvise32.exe
2012-11-24 08:57 . 2011-10-26 05:25   1572864   ----a-w-   c:\windows\system32\quartz.dll
2012-11-24 08:57 . 2011-10-26 04:32   1328128   ----a-w-   c:\windows\SysWow64\quartz.dll
2012-11-24 08:57 . 2011-10-26 05:25   366592   ----a-w-   c:\windows\system32\qdvd.dll
2012-11-24 08:57 . 2011-10-26 04:32   514560   ----a-w-   c:\windows\SysWow64\qdvd.dll
2012-11-24 08:57 . 2012-01-04 10:44   509952   ----a-w-   c:\windows\system32\ntshrui.dll
2012-11-24 08:57 . 2012-01-04 08:58   442880   ----a-w-   c:\windows\SysWow64\ntshrui.dll
2012-11-24 08:55 . 2012-06-06 05:05   1390080   ----a-w-   c:\windows\SysWow64\msxml6.dll
2012-11-24 08:55 . 2012-06-06 05:05   1236992   ----a-w-   c:\windows\SysWow64\msxml3.dll
2012-11-24 08:55 . 2010-06-26 03:55   2048   ----a-w-   c:\windows\system32\msxml3r.dll
2012-11-24 08:55 . 2010-06-26 03:24   2048   ----a-w-   c:\windows\SysWow64\msxml3r.dll
2012-11-24 08:53 . 2012-06-09 05:43   14172672   ----a-w-   c:\windows\system32\shell32.dll
2012-11-24 08:52 . 2012-08-02 17:58   574464   ----a-w-   c:\windows\system32\d3d10level9.dll
2012-11-24 08:51 . 2011-02-19 12:03   46080   ----a-w-   c:\windows\system32\atmlib.dll
2012-11-24 08:50 . 2012-08-24 18:05   220160   ----a-w-   c:\windows\system32\wintrust.dll
2012-11-24 08:50 . 2012-08-24 16:57   172544   ----a-w-   c:\windows\SysWow64\wintrust.dll
2012-11-24 08:50 . 2012-09-14 19:19   2048   ----a-w-   c:\windows\system32\tzres.dll
2012-11-24 08:50 . 2012-09-14 18:28   2048   ----a-w-   c:\windows\SysWow64\tzres.dll
2012-11-24 08:48 . 2012-09-25 22:47   78336   ----a-w-   c:\windows\SysWow64\synceng.dll
2012-11-24 08:48 . 2012-09-25 22:46   95744   ----a-w-   c:\windows\system32\synceng.dll
2012-11-24 08:48 . 2011-02-05 17:10   642944   ----a-w-   c:\windows\system32\winload.efi
2012-11-24 08:48 . 2011-02-05 17:10   20352   ----a-w-   c:\windows\system32\kdusb.dll
2012-11-24 08:48 . 2011-02-05 17:10   19328   ----a-w-   c:\windows\system32\kd1394.dll
2012-11-24 08:48 . 2011-02-05 17:10   17792   ----a-w-   c:\windows\system32\kdcom.dll
2012-11-24 08:48 . 2011-02-05 17:06   605552   ----a-w-   c:\windows\system32\winload.exe
2012-11-24 08:48 . 2011-02-05 17:06   566208   ----a-w-   c:\windows\system32\winresume.efi
2012-11-24 08:48 . 2011-02-05 17:06   518672   ----a-w-   c:\windows\system32\winresume.exe
2012-11-24 08:48 . 2010-11-20 13:27   63488   ----a-w-   c:\windows\system32\setbcdlocale.dll
2012-11-24 08:46 . 2011-12-16 08:46   634880   ----a-w-   c:\windows\system32\msvcrt.dll
2012-11-24 08:30 . 2012-11-24 08:30   163056   ----a-w-   c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10142.bin
2012-11-24 08:26 . 2011-11-19 14:58   77312   ----a-w-   c:\windows\system32\packager.dll
2012-11-24 08:26 . 2011-11-19 14:01   67072   ----a-w-   c:\windows\SysWow64\packager.dll
2012-11-24 08:23 . 2012-02-17 06:38   1031680   ----a-w-   c:\windows\system32\rdpcore.dll
2012-11-24 08:23 . 2012-02-17 05:34   826880   ----a-w-   c:\windows\SysWow64\rdpcore.dll
2012-11-24 08:23 . 2012-02-17 04:57   23552   ----a-w-   c:\windows\system32\drivers\tdtcp.sys
2012-11-24 08:13 . 2007-03-05 11:42   15128   ----a-w-   c:\windows\SysWow64\x3daudio1_1.dll
2012-11-24 08:12 . 2012-06-02 22:19   2428952   ----a-w-   c:\windows\system32\wuaueng.dll
2012-11-24 08:12 . 2012-06-02 22:19   57880   ----a-w-   c:\windows\system32\wuauclt.exe
2012-11-24 08:12 . 2012-06-02 22:19   44056   ----a-w-   c:\windows\system32\wups2.dll
2012-11-24 08:12 . 2012-06-02 22:15   2622464   ----a-w-   c:\windows\system32\wucltux.dll
2012-11-24 08:12 . 2012-06-02 22:19   38424   ----a-w-   c:\windows\system32\wups.dll
2012-11-24 08:12 . 2012-06-02 22:19   701976   ----a-w-   c:\windows\system32\wuapi.dll
2012-11-24 08:12 . 2012-06-02 22:15   99840   ----a-w-   c:\windows\system32\wudriver.dll
2012-11-24 08:12 . 2012-06-02 14:19   186752   ----a-w-   c:\windows\system32\wuwebv.dll
2012-11-24 08:12 . 2012-06-02 14:15   36864   ----a-w-   c:\windows\system32\wuapp.exe
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-26 11:33 . 2009-07-14 02:36   175616   ----a-w-   c:\windows\system32\msclmd.dll
2012-11-26 11:33 . 2009-07-14 02:36   152576   ----a-w-   c:\windows\SysWow64\msclmd.dll
2012-11-24 09:32 . 2012-11-24 09:32   203776   ----a-w-   c:\windows\SysWow64\webcheck.dll
2012-11-24 09:32 . 2012-11-24 09:32   249344   ----a-w-   c:\windows\system32\webcheck.dll
2012-10-16 08:38 . 2012-11-28 13:47   135168   ----a-w-   c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 13:47   350208   ----a-w-   c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 13:47   561664   ----a-w-   c:\windows\apppatch\AcLayers.dll
2012-10-10 20:23 . 2012-10-10 20:23   247144   ----a-w-   c:\windows\system32\nvinitx.dll
2012-10-10 20:23 . 2012-10-10 20:23   1867112   ----a-w-   c:\windows\SysWow64\nvcuvenc.dll
2012-10-10 20:23 . 2012-10-10 20:23   18252136   ----a-w-   c:\windows\system32\nvd3dumx.dll
2012-10-10 20:23 . 2012-10-10 20:23   1482600   ----a-w-   c:\windows\system32\nvdispgenco64.dll
2012-10-10 20:23 . 2012-10-10 20:23   6127464   ----a-w-   c:\windows\SysWow64\nvopencl.dll
2012-10-10 20:23 . 2012-10-10 20:23   2574696   ----a-w-   c:\windows\SysWow64\nvcuvid.dll
2012-10-10 20:23 . 2012-10-10 20:23   25256296   ----a-w-   c:\windows\system32\nvcompiler.dll
2012-10-10 20:23 . 2012-10-10 20:23   831848   ----a-w-   c:\windows\SysWow64\nvumdshim.dll
2012-10-10 20:23 . 2012-10-10 20:23   202600   ----a-w-   c:\windows\SysWow64\nvinit.dll
2012-10-10 20:23 . 2012-10-10 20:23   7414632   ----a-w-   c:\windows\system32\nvopencl.dll
2012-10-10 20:23 . 2012-10-10 20:23   2731880   ----a-w-   c:\windows\system32\nvapi64.dll
2012-10-10 20:23 . 2012-10-10 20:23   973672   ----a-w-   c:\windows\system32\nvumdshimx.dll
2012-10-10 20:23 . 2012-10-10 20:23   14922600   ----a-w-   c:\windows\system32\nvwgf2umx.dll
2012-10-10 20:23 . 2012-10-10 20:23   9146728   ----a-w-   c:\windows\system32\nvcuda.dll
2012-10-10 20:23 . 2012-10-10 20:23   7697768   ----a-w-   c:\windows\SysWow64\nvcuda.dll
2012-10-10 20:23 . 2012-10-10 20:23   2218344   ----a-w-   c:\windows\system32\nvcuvenc.dll
2012-10-10 20:23 . 2012-10-10 20:23   12501352   ----a-w-   c:\windows\SysWow64\nvwgf2um.dll
2012-10-10 20:22 . 2012-10-10 20:22   2428776   ----a-w-   c:\windows\SysWow64\nvapi.dll
2012-10-10 20:22 . 2012-10-10 20:22   26331496   ----a-w-   c:\windows\system32\nvoglv64.dll
2012-10-10 20:22 . 2012-10-10 20:22   15309160   ----a-w-   c:\windows\SysWow64\nvd3dum.dll
2012-10-10 20:22 . 2012-10-10 20:22   2747240   ----a-w-   c:\windows\system32\nvcuvid.dll
2012-10-10 20:22 . 2012-10-10 20:22   19906920   ----a-w-   c:\windows\SysWow64\nvoglv32.dll
2012-10-10 20:22 . 2012-10-10 20:22   13443944   ----a-w-   c:\windows\system32\drivers\nvlddmkm.sys
2012-10-10 20:22 . 2012-10-10 20:22   17559912   ----a-w-   c:\windows\SysWow64\nvcompiler.dll
2012-10-02 12:15 . 2012-10-02 12:15   430952   ----a-w-   c:\windows\SysWow64\nvStreaming.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2010-11-20 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2012-11-28 . 2C9CC9F492CA596B1B9FC1AE5E916356 . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"SpeedBitVideoAccelerator"="e:\programy\Speed Bit\SpeedBit Video Accelerator\VideoAccelerator.exe" [2012-11-23 2098376]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-11-09 17877168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R2 VideoAcceleratorService;VideoAcceleratorService;e:\programy\SPEEDB~1\SPEEDB~1\VideoAcceleratorService.exe [2012-11-23 265928]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-24 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-11-23 834544]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x64.sys [2010-07-09 21480]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 RTCore64;RTCore64;e:\programy\MSI Afterburner\RTCore64.sys [2010-08-31 14648]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - RTCORE64
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-25 17:35]
.
.
--------- X64 Entries -----------
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
LSP: e:\programy\Speed Bit\SpeedBit Video Accelerator\SBLSP.dll
TCP: DhcpNameServer = 192.168.1.10 195.146.132.59 195.146.128.60
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{CAC42510-9B41-42c1-9DCD-7282A2D07C61} - c:\program files (x86)\BitAccelerator\BitAccelerator.dll
Wow6432Node-HKCU-Run-CMDHost - c:\users\Stano\AppData\Roaming\CMDHost0.exe
Wow6432Node-HKCU-Run-Nethosts - c:\users\Stano\AppData\Roaming\Nethosts2.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-11-30  19:20:18
ComboFix-quarantined-files.txt  2012-11-30 18:20
.
Pre-Run: Volných bajtů: 21 026 631 680
Post-Run: Volných bajtů: 27 369 205 760
.
- - End Of File - - 65FA2766471F800B6EDA3E9FFC413753


_________________
CPU:Intel Core i5 2500K 4,2GHz GPU:MSI GTX 960 4GB RAM:CORSAIR 4GB KIT DDR3 1600MHz CL9 Blue PSU:CORSAIR CX600 V2 MB:P8P67-M PRO B3 Revison Case:CoolerMaster Elite 430 Black Edition Phone:iPhone 6s Plus 128 GB Notebook:Asus GL502VM-FY182T
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 14.09.16
Príspevky: 618
Témy: 2 | 2

1.Stiahni si cfscript http://www.ulozto.sk/x8gLn2u/cfscript-txt na plochu pretiahni cez combofix aplikuje sa skript pošli log
2.Stiahni si TDSkiller z http://support.kaspersky.com/downloads/ ... killer.exe daj scan pošli report predom nič nemaž
3.Stiahni si MBAM z http://fileforum.betanews.com/download/ ... 86760019/1 nainštaluj spusť daj plnú kontrolu predom nič nemaž pošli log


Offline

Užívateľ
Užívateľ
cmdhost.exe Critical system services

Registrovaný: 15.08.11
Prihlásený: 04.09.17
Príspevky: 279
Témy: 46 | 46
Bydlisko: Rabča

pocuj ako som aplikoval combofix tak my vymazalo cmdhost.exe a vsetky ostatne subory tohto typu, nemam ziadne problemi s pretazenim systemu,CPU a GPU funguje tak ako ma.
mam aj tak pokracovat podla tvojich instukcii ?


_________________
CPU:Intel Core i5 2500K 4,2GHz GPU:MSI GTX 960 4GB RAM:CORSAIR 4GB KIT DDR3 1600MHz CL9 Blue PSU:CORSAIR CX600 V2 MB:P8P67-M PRO B3 Revison Case:CoolerMaster Elite 430 Black Edition Phone:iPhone 6s Plus 128 GB Notebook:Asus GL502VM-FY182T
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 14.09.16
Príspevky: 618
Témy: 2 | 2

ano maš pokračovať v inštrukciach


 [ Príspevkov: 19 ] 


cmdhost.exe Critical system services



Podobné témy

 Témy  Odpovede  Zobrazenia  Posledný príspevok 
V tomto fóre nie sú ďalšie neprečítané témy.

Problém s Critical System Errors

v Operačné systémy Microsoft

0

217

16.12.2006 22:26

yossarian

V tomto fóre nie sú ďalšie neprečítané témy.

Critical system event Kernel-Power

v Operačné systémy Microsoft

3

142

30.09.2014 16:58

4040

V tomto fóre nie sú ďalšie neprečítané témy.

Proces System.exe zahlcuje CPU

v Operačné systémy Microsoft

0

499

28.03.2007 18:15

AdrenAline

V tomto fóre nie sú ďalšie neprečítané témy.

Error: System nemoze najst csrcs.exe !

v Operačné systémy Microsoft

2

2314

07.10.2008 19:38

mersi

V tomto fóre nie sú ďalšie neprečítané témy.

System nemuze nalezt mmc.exe (Spravca zariadeni)

v Operačné systémy Microsoft

4

406

16.10.2008 23:22

armin.owen

V tomto fóre nie sú ďalšie neprečítané témy.

WIN 8.1 Vytazenie CPU procesom System, thread ntoskrnl.exe

v Operačné systémy Microsoft

0

118

20.04.2015 8:58

wlado93

V tomto fóre nie sú ďalšie neprečítané témy.

Critical error-win7

v Operačné systémy Microsoft

2

206

15.02.2010 8:34

AsuSmaNiaK

V tomto fóre nie sú ďalšie neprečítané témy.

Critical Java 0-day exploit

v Novinky

6

238

03.09.2012 12:56

Xarxes

V tomto fóre nie sú ďalšie neprečítané témy.

Win 10 Critical process died

v Operačné systémy Microsoft

0

134

24.01.2016 22:47

kkoloman

V tomto fóre nie sú ďalšie neprečítané témy.

explorer.exe, dllhost.exe - vyťaženie 100% CPU

v Antivíry a antispywary

3

1420

24.01.2012 15:41

Reverser

V tomto fóre nie sú ďalšie neprečítané témy.

egui.exe a ekern.exe

v Antivíry a antispywary

4

865

24.04.2010 15:32

feldino

V tomto fóre nie sú ďalšie neprečítané témy.

msconfig,services.msc

v Operačné systémy Microsoft

12

522

11.08.2008 23:34

shiro

V tomto fóre nie sú ďalšie neprečítané témy.

amazon web services registracia

v Služby a webstránky

1

123

29.06.2013 16:06

1daemon1

V tomto fóre nie sú ďalšie neprečítané témy.

Najlepsie ONLINE file scanning services

v Sieťové a internetové programy

0

749

17.11.2005 13:29

Pufo Callo

V tomto fóre nie sú ďalšie neprečítané témy.

Host Process for Windows Services

v Operačné systémy Microsoft

0

343

20.06.2008 18:40

allan

V tomto fóre nie sú ďalšie neprečítané témy.

WSUS - windows server update services

v Operačné systémy Microsoft

9

713

04.01.2007 11:03

manazer



© 2005 - 2017 PCforum, edited by JanoF