Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Nemesis94
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 led 2009 19:29

C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#1 Příspěvek od Nemesis94 »

Tohle detekoval Eset Smart Security 4.
a.exe b.exe c.exe + sshnas.dll

30.12.2009 12:25:16 C:\Windows\SysWOW64\sshnas.dll
30.12.2009 12:25:37 C:\Windows\system32\sshnas.dll

C:\Windows\SysWOW64\sshnas.dll - a variant of Win32/Kryptik.BOJ trojan
C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.BOJ trojan

k těmto soubroum patřily a.exe + b.exe + c.exe které jsem už smazal v Esetu a ted nemuzu najit log ale byli taky Win32/Kryptik.BOJ trojan..
Vše testováno na VIRUSTOTAL vše minimálne 10/40 pozitivní na Malware nebo Trojan ... msa.exe čistej ale četl jsem problemý o sshnas.dll a ve většině případech msa.exe byl infokován

Počítač se mi zdá trochu pomalejší při hraní GTA IV je rozdil vidět hodně ...

HW konfigurace:
Intel Core 2 Duo E4500
Nvidia GeForce 275GTX
2x 2GB Kingoston HyperX 1066Mhz
320GB Sata.. ??
Motherboard Gigabyte P43-ES3G

OS Windows 7 64bit + všechny aktualizace... Instalován před 1 týdnem xD
Ochrana Eset Smart Security 4 + všechny updaty
Dalši software:
TuneUp Utilities 2010 trial
GameBooster 1.30
EasyTune 6 ( Gigabyte motherboard utility )

RSIT ( Spustit v režimu Win XP SP2 ) fungoval

Logfile of random's system information tool 1.06 (written by random/random)
Run by Robin at 2009-12-30 12:46:53
Microsoft Windows 7 Ultimate Service Pack 2
System drive C: has 20 GB (41%) free of 50 GB
Total RAM: 4094 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:46:57, on 30.12.2009
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\msa.exe
C:\Program Files (x86)\Edimax\Common\RaUI.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLiteShellHlp.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Users\Robin\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\Robin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: flashget2 urlcatch - {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} - C:\Program Files (x86)\FlashGet Network\FlashGet universal\ComDlls\bhoCATCH.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AppVodBurner] C:\Program Files (x86)\VodBurner\vodburner.exe
O4 - HKCU\..\Run: [LosAlamos] rundll32.exe C:\Windows\system32\sshnas.dll,AddConsoleAliasAW
O4 - HKCU\..\Run: [PUT2VIDQLG] C:\Users\Robin\AppData\Local\Temp\c.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Wireless Utility.lnk = C:\Program Files (x86)\Edimax\Common\RaUI.exe
O8 - Extra context menu item: &Download All by FlashGet - C:\Program Files (x86)\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
O8 - Extra context menu item: &Download by FlashGet - C:\Program Files (x86)\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files (x86)\Edimax\Common\RaRegistry.exe
O23 - Service: Ralink Registry Writer 64 (RalinkRegistryWriter64) - Ralink Technology, Corp. - C:\Program Files (x86)\Edimax\Common\RaRegistry64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10328 bytes

======Scheduled tasks folder======

C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F364306-AA45-47B5-9F9D-39A8B94E7EF1}]
FG2CatchUrl - C:\Program Files (x86)\FlashGet Network\FlashGet universal\ComDlls\bhoCATCH.dll [2008-08-19 104016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2009-10-09 25623336]
"AppVodBurner"=C:\Program Files (x86)\VodBurner\vodburner.exe [2009-12-29 5161984]
"LosAlamos"=C:\Windows\system32\sshnas.dll,AddConsoleAliasAW []
"PUT2VIDQLG"=C:\Users\Robin\AppData\Local\Temp\c.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Wireless Utility.lnk - C:\Program Files (x86)\Edimax\Common\RaUI.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2fef091e-f1b3-11de-87c6-00241d788114}]
shell\AutoRun\command - G:\AutoRunCD.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-12-30 12:42:24 ----D---- C:\rsit
2009-12-30 12:42:24 ----D---- C:\Program Files (x86)\trend micro
2009-12-30 11:41:04 ----D---- C:\Users\Robin\AppData\Roaming\ESET
2009-12-30 11:40:21 ----D---- C:\ProgramData\ESET
2009-12-30 09:58:34 ----D---- C:\ProgramData\Codemasters
2009-12-30 00:25:58 ----D---- C:\Program Files (x86)\Wolfenstein - Enemy Territory
2009-12-29 22:21:33 ----A---- C:\Windows\system32\wnaspi32.dll
2009-12-29 22:07:39 ----A---- C:\Windows\msa.exe
2009-12-29 21:54:08 ----D---- C:\ProgramData\Paragon
2009-12-29 21:33:21 ----D---- C:\Program Files (x86)\Common Files\Acronis
2009-12-29 21:33:21 ----D---- C:\Program Files (x86)\Acronis
2009-12-29 15:45:49 ----SD---- C:\Program Files (x86)\HLSW
2009-12-29 15:45:49 ----D---- C:\Users\Robin\AppData\Roaming\HLSW
2009-12-29 15:18:37 ----D---- C:\Program Files (x86)\VodBurner
2009-12-29 13:04:37 ----D---- C:\Program Files (x86)\Windows Live SkyDrive
2009-12-29 13:04:24 ----D---- C:\Program Files (x86)\Windows Live
2009-12-29 13:03:58 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2009-12-28 23:17:41 ----D---- C:\Windows\WindowsMobile
2009-12-28 23:17:40 ----SHD---- C:\Config.Msi
2009-12-28 02:32:15 ----D---- C:\Program Files (x86)\GIGABYTE
2009-12-28 02:32:15 ----D---- C:\Program Files (x86)\AMD
2009-12-28 00:34:26 ----HDC---- C:\ProgramData\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2009-12-28 00:28:16 ----D---- C:\ProgramData\Electronic Arts
2009-12-27 16:27:23 ----D---- C:\Users\Robin\AppData\Roaming\Mozilla
2009-12-27 16:27:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
2009-12-26 23:26:42 ----A---- C:\Windows\system32\PnkBstrB.exe
2009-12-26 23:26:38 ----A---- C:\Windows\system32\PnkBstrA.exe
2009-12-26 23:26:38 ----A---- C:\Windows\system32\pbsvc.exe
2009-12-26 20:41:44 ----A---- C:\Windows\system32\mkl_vml_p4.dll
2009-12-26 20:41:44 ----A---- C:\Windows\system32\mkl_vml_p3.dll
2009-12-26 20:41:43 ----A---- C:\Windows\system32\mkl_vml_def.dll
2009-12-26 20:41:43 ----A---- C:\Windows\system32\mkl_p4.dll
2009-12-26 20:41:43 ----A---- C:\Windows\system32\mkl_p3.dll
2009-12-26 20:41:43 ----A---- C:\Windows\system32\mkl_lapack64.dll
2009-12-26 20:41:42 ----A---- C:\Windows\system32\rapture3d_oal.dll
2009-12-26 20:41:42 ----A---- C:\Windows\system32\mkl_lapack32.dll
2009-12-26 20:41:42 ----A---- C:\Windows\system32\mkl_def.dll
2009-12-26 20:41:42 ----A---- C:\Windows\system32\libguide40.dll
2009-12-26 20:41:40 ----D---- C:\Program Files (x86)\BRS
2009-12-26 20:41:26 ----RA---- C:\Windows\system32\tmp9668.tmp
2009-12-26 20:41:26 ----D---- C:\Program Files (x86)\OpenAL
2009-12-26 20:41:26 ----A---- C:\Windows\system32\wrap_oal.dll
2009-12-26 20:41:26 ----A---- C:\Windows\system32\OpenAL32.dll
2009-12-26 20:39:45 ----RA---- C:\Windows\system32\tmp9667.tmp
2009-12-26 20:20:49 ----D---- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2009-12-26 20:19:56 ----D---- C:\ProgramData\Blizzard
2009-12-26 18:55:07 ----D---- C:\Users\Robin\AppData\Roaming\skypePM
2009-12-26 18:22:43 ----D---- C:\Users\Robin\AppData\Roaming\Skype
2009-12-26 18:19:10 ----D---- C:\Program Files (x86)\Common Files\Skype
2009-12-26 18:19:09 ----RD---- C:\Program Files (x86)\Skype
2009-12-26 18:19:04 ----D---- C:\ProgramData\Skype
2009-12-26 18:18:27 ----D---- C:\Users\Robin\AppData\Roaming\TeamViewer
2009-12-26 18:17:31 ----D---- C:\Program Files (x86)\TeamViewer
2009-12-26 02:59:52 ----D---- C:\Windows\Panther
2009-12-26 02:59:40 ----RASH---- C:\BOOTSECT.BAK
2009-12-26 02:59:38 ----SHD---- C:\Boot
2009-12-26 02:22:38 ----RHD---- C:\Users\Robin\AppData\Roaming\SecuROM
2009-12-26 02:16:28 ----D---- C:\Program Files (x86)\Common Files\Windows Live
2009-12-26 02:15:46 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2009-12-26 02:15:13 ----D---- C:\Program Files (x86)\Microsoft
2009-12-26 02:03:27 ----A---- C:\Windows\system32\uxtuneup.dll
2009-12-26 02:03:27 ----A---- C:\Windows\system32\authuitu.dll
2009-12-26 02:03:15 ----D---- C:\Users\Robin\AppData\Roaming\TuneUp Software
2009-12-26 02:03:07 ----D---- C:\Program Files (x86)\TuneUp Utilities 2010
2009-12-26 02:02:41 ----D---- C:\ProgramData\TuneUp Software
2009-12-26 02:02:36 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-26 02:01:22 ----D---- C:\Program Files (x86)\IObit
2009-12-26 01:53:42 ----A---- C:\Windows\system32\gdiplus.dll
2009-12-26 01:46:00 ----D---- C:\Users\Robin\AppData\Roaming\BITS
2009-12-26 01:45:50 ----A---- C:\Windows\system32\CmdLineExt_x64.dll
2009-12-26 01:44:59 ----D---- C:\profiles
2009-12-26 01:44:37 ----D---- C:\Program Files (x86)\FlashGet Network
2009-12-26 01:29:23 ----D---- C:\ProgramData\FLEXnet
2009-12-26 01:19:45 ----D---- C:\Windows\system32\xlive
2009-12-26 01:19:44 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2009-12-26 01:09:12 ----D---- C:\ProgramData\Adobe
2009-12-26 01:08:52 ----D---- C:\Program Files (x86)\Bonjour
2009-12-26 01:06:47 ----D---- C:\Windows\system32\spool
2009-12-26 01:05:27 ----D---- C:\Program Files (x86)\Adobe
2009-12-26 01:05:06 ----D---- C:\Program Files (x86)\Common Files\Macrovision Shared
2009-12-26 01:04:34 ----D---- C:\Program Files (x86)\Common Files\Adobe
2009-12-26 00:54:30 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2009-12-26 00:54:03 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2009-12-26 00:53:58 ----D---- C:\Users\Robin\AppData\Roaming\DAEMON Tools Lite
2009-12-26 00:50:46 ----D---- C:\Program Files (x86)\SpeedFan
2009-12-26 00:49:44 ----D---- C:\ProgramData\DAEMON Tools Lite
2009-12-26 00:44:50 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2009-12-26 00:44:11 ----D---- C:\Windows\system32\AGEIA
2009-12-26 00:44:11 ----D---- C:\Program Files (x86)\AGEIA Technologies
2009-12-26 00:44:01 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2009-12-26 00:43:10 ----A---- C:\Windows\system32\OpenCL.dll
2009-12-26 00:43:09 ----A---- C:\Windows\system32\nvwgf2um.dll
2009-12-26 00:43:07 ----A---- C:\Windows\system32\nvoglv32.dll
2009-12-26 00:43:07 ----A---- C:\Windows\system32\nvencodemft.dll
2009-12-26 00:43:07 ----A---- C:\Windows\system32\nvdecodemft.dll
2009-12-26 00:43:05 ----A---- C:\Windows\system32\nvd3dum.dll
2009-12-26 00:43:05 ----A---- C:\Windows\system32\nvcuvid.dll
2009-12-26 00:43:04 ----A---- C:\Windows\system32\nvcuvenc.dll
2009-12-26 00:43:04 ----A---- C:\Windows\system32\nvcuda.dll
2009-12-26 00:43:04 ----A---- C:\Windows\system32\nvcompiler.dll
2009-12-26 00:43:02 ----A---- C:\Windows\system32\nvapi.dll
2009-12-26 00:43:00 ----D---- C:\NVIDIA
2009-12-26 00:27:00 ----A---- C:\Windows\system32\XAudio2_5.dll
2009-12-26 00:26:59 ----A---- C:\Windows\system32\xactengine3_5.dll
2009-12-26 00:26:59 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2009-12-26 00:26:58 ----A---- C:\Windows\system32\d3dx11_42.dll
2009-12-26 00:26:58 ----A---- C:\Windows\system32\d3dx10_42.dll
2009-12-26 00:26:58 ----A---- C:\Windows\system32\d3dcsx_42.dll
2009-12-26 00:26:57 ----A---- C:\Windows\system32\D3DX9_42.dll
2009-12-26 00:26:56 ----A---- C:\Windows\system32\D3DX9_41.dll
2009-12-26 00:26:56 ----A---- C:\Windows\system32\d3dx10_41.dll
2009-12-26 00:26:56 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2009-12-26 00:26:54 ----A---- C:\Windows\system32\XAudio2_4.dll
2009-12-26 00:26:54 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2009-12-26 00:26:54 ----A---- C:\Windows\system32\xactengine3_4.dll
2009-12-26 00:26:53 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2009-12-26 00:26:53 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-12-26 00:26:53 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-12-26 00:26:50 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-12-26 00:26:50 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-12-26 00:26:50 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-12-26 00:26:49 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-12-26 00:26:49 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-12-26 00:26:48 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-12-26 00:26:48 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-12-26 00:26:48 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-12-26 00:26:47 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-12-26 00:26:47 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-12-26 00:26:46 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-12-26 00:26:46 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-12-26 00:26:46 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-12-26 00:26:45 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-12-26 00:26:45 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-12-26 00:26:45 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-12-26 00:26:45 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-12-26 00:26:44 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-12-26 00:26:43 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-12-26 00:26:42 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-12-26 00:26:42 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-12-26 00:26:41 ----D---- C:\Users\Robin\AppData\Roaming\WinRAR
2009-12-26 00:26:41 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-12-26 00:26:41 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-12-26 00:26:40 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-12-26 00:26:40 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-12-26 00:26:38 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-12-26 00:26:38 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-12-26 00:26:34 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-12-26 00:26:33 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-12-26 00:26:33 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-12-26 00:26:33 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-12-26 00:26:32 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-12-26 00:26:32 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-12-26 00:26:32 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-12-26 00:26:32 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-12-26 00:26:31 ----A---- C:\Windows\system32\xinput1_3.dll
2009-12-26 00:26:31 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-12-26 00:26:28 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-12-26 00:26:27 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-12-26 00:26:27 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-12-26 00:26:27 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-12-26 00:26:26 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-12-26 00:26:25 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-12-26 00:26:25 ----A---- C:\Windows\system32\d3dx10.dll
2009-12-26 00:26:15 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-12-26 00:26:14 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-12-26 00:26:14 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-12-26 00:26:14 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-12-26 00:26:10 ----A---- C:\Windows\system32\xinput1_2.dll
2009-12-26 00:26:10 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-12-26 00:26:10 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-12-26 00:26:09 ----A---- C:\Windows\system32\xinput1_1.dll
2009-12-26 00:26:08 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-12-26 00:26:01 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-12-26 00:26:00 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-12-26 00:26:00 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-12-26 00:25:59 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-12-26 00:25:59 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-12-26 00:25:58 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-12-26 00:25:58 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-12-26 00:25:57 ----D---- C:\Program Files (x86)\WinRAR
2009-12-26 00:25:57 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-12-26 00:25:56 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-12-26 00:05:14 ----D---- C:\Program Files (x86)\Intel
2009-12-26 00:05:14 ----A---- C:\Windows\system32\CSVer.dll
2009-12-26 00:05:07 ----D---- C:\Intel
2009-12-26 00:04:47 ----A---- C:\Windows\system32\CmdRtr.DLL
2009-12-26 00:04:47 ----A---- C:\Windows\system32\APOMngr.DLL
2009-12-26 00:04:37 ----D---- C:\Windows\system32\RTCOM
2009-12-26 00:04:26 ----A---- C:\Windows\system32\MBAPO32.dll
2009-12-26 00:04:25 ----D---- C:\Program Files (x86)\Realtek
2009-12-26 00:04:24 ----HD---- C:\Program Files (x86)\Temp
2009-12-26 00:04:24 ----A---- C:\Windows\RtlExUpd.dll
2009-12-26 00:04:21 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2009-12-26 00:01:45 ----D---- C:\Program Files (x86)\Microsoft Works
2009-12-26 00:01:32 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2009-12-26 00:01:32 ----D---- C:\Program Files (x86)\Common Files\DESIGNER
2009-12-26 00:01:14 ----D---- C:\Windows\PCHEALTH
2009-12-26 00:01:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2009-12-25 23:59:38 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2009-12-25 23:59:10 ----D---- C:\ProgramData\Microsoft Help
2009-12-25 23:59:10 ----D---- C:\Program Files (x86)\Microsoft Office
2009-12-25 23:58:18 ----RHD---- C:\MSOCache
2009-12-25 23:50:33 ----A---- C:\Windows\system32\MSVCR71.dll
2009-12-25 23:50:33 ----A---- C:\Windows\system32\MSVCP71.dll
2009-12-25 23:50:33 ----A---- C:\Windows\system32\MFC71.dll
2009-12-25 23:48:55 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-12-25 23:48:11 ----D---- C:\Users\Robin\AppData\Roaming\Macromedia
2009-12-25 23:48:11 ----D---- C:\Users\Robin\AppData\Roaming\Adobe
2009-12-25 23:48:09 ----D---- C:\Windows\system32\Macromed
2009-12-25 23:45:52 ----D---- C:\Users\Robin\AppData\Roaming\SoundSpectrum
2009-12-25 23:44:57 ----D---- C:\Program Files (x86)\SoundSpectrum
2009-12-25 23:43:31 ----D---- C:\ProgramData\NVIDIA
2009-12-25 23:25:30 ----A---- C:\Windows\system32\tzres.dll
2009-12-25 23:25:21 ----A---- C:\Windows\system32\msv1_0.dll
2009-12-25 23:10:27 ----A---- C:\Windows\system32\wmp.dll
2009-12-25 23:10:26 ----A---- C:\Windows\system32\t2embed.dll
2009-12-25 23:10:26 ----A---- C:\Windows\system32\fontsub.dll
2009-12-25 23:10:26 ----A---- C:\Windows\system32\explorer.exe
2009-12-25 23:10:26 ----A---- C:\Windows\system32\CertEnroll.dll
2009-12-25 23:10:26 ----A---- C:\Windows\system32\atmfd.dll
2009-12-25 23:10:26 ----A---- C:\Windows\explorer.exe
2009-12-25 23:10:25 ----A---- C:\Windows\system32\wmploc.DLL
2009-12-25 23:10:09 ----A---- C:\Windows\system32\msasn1.dll
2009-12-25 23:10:08 ----A---- C:\Windows\system32\mshtml.dll
2009-12-25 23:10:07 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-12-25 22:56:12 ----D---- C:\ProgramData\Ralink
2009-12-25 22:55:59 ----D---- C:\ProgramData\Edimax Driver
2009-12-25 22:55:53 ----D---- C:\Program Files (x86)\Cisco
2009-12-25 22:55:50 ----SHD---- C:\Windows\Installer
2009-12-25 22:55:49 ----A---- C:\Windows\system32\RAIHV.dll
2009-12-25 22:55:49 ----A---- C:\Windows\system32\RAEXTUI.dll
2009-12-25 22:55:49 ----A---- C:\Windows\system32\RaCertMgr.dll
2009-12-25 22:55:48 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2009-12-25 22:55:48 ----D---- C:\Program Files (x86)\Edimax
2009-12-25 22:55:23 ----D---- C:\Users\Robin\AppData\Roaming\InstallShield
2009-12-25 22:24:30 ----D---- C:\Users\Robin\AppData\Roaming\Identities
2009-12-25 22:24:03 ----SD---- C:\Users\Robin\AppData\Roaming\Microsoft
2009-12-25 22:24:03 ----D---- C:\Users\Robin\AppData\Roaming\Media Center Programs
2009-12-25 22:21:39 ----SHD---- C:\Recovery
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Šablony
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Plocha
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Oblíbené položky
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Nabídka Start
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Dokumenty
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Data aplikací
2009-12-25 18:03:48 ----D---- C:\Windows\SoftwareDistribution
2009-12-25 18:01:06 ----D---- C:\Windows\Prefetch
2009-12-25 18:00:50 ----SHD---- C:\System Volume Information
2009-12-04 01:19:32 ----A---- C:\Windows\system32\qtp-mt334.dll
2009-12-04 01:16:42 ----A---- C:\Windows\system32\prgiso.dll

======List of files/folders modified in the last 1 months======

2009-12-30 12:46:55 ----D---- C:\Windows\Temp
2009-12-30 12:46:12 ----RD---- C:\Program Files (x86)
2009-12-30 12:41:02 ----D---- C:\Windows\winsxs
2009-12-30 12:25:36 ----D---- C:\Windows\SysWOW64
2009-12-30 12:07:54 ----D---- C:\Windows\inf
2009-12-30 12:07:30 ----RD---- C:\Program Files
2009-12-30 12:04:49 ----D---- C:\Windows\Tasks
2009-12-30 11:40:21 ----HD---- C:\ProgramData
2009-12-30 11:38:55 ----D---- C:\Windows\System32
2009-12-29 22:21:33 ----D---- C:\Windows\system32\drivers
2009-12-29 22:21:33 ----D---- C:\Windows
2009-12-29 21:33:21 ----D---- C:\Program Files (x86)\Common Files
2009-12-29 13:03:58 ----RSD---- C:\Windows\assembly
2009-12-29 12:55:56 ----RD---- C:\Users
2009-12-29 12:45:32 ----SHD---- C:\$Recycle.Bin
2009-12-27 16:28:56 ----D---- C:\Windows\LiveKernelReports
2009-12-27 12:45:49 ----D---- C:\Windows\rescache
2009-12-27 12:34:08 ----D---- C:\Windows\Logs
2009-12-26 10:00:10 ----D---- C:\Windows\Microsoft.NET
2009-12-26 02:16:01 ----SD---- C:\ProgramData\Microsoft
2009-12-26 02:15:26 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2009-12-26 01:32:29 ----RSD---- C:\Windows\Fonts
2009-12-26 01:29:15 ----D---- C:\Program Files (x86)\Common Files\System
2009-12-26 01:29:15 ----A---- C:\Windows\win.ini
2009-12-26 00:01:39 ----D---- C:\Program Files (x86)\MSBuild
2009-12-26 00:01:30 ----D---- C:\Windows\ShellNew
2009-12-25 23:48:10 ----D---- C:\Windows\Downloaded Program Files
2009-12-25 23:43:28 ----D---- C:\Windows\Help
2009-12-25 23:29:05 ----D---- C:\Windows\system32\sk-SK
2009-12-25 23:29:05 ----D---- C:\Windows\system32\en-US
2009-12-25 23:29:05 ----D---- C:\Windows\system32\cs-CZ
2009-12-25 23:29:05 ----D---- C:\Windows\ehome
2009-12-25 23:29:05 ----D---- C:\Program Files (x86)\Windows Media Player
2009-12-25 23:29:04 ----D---- C:\Program Files (x86)\Internet Explorer
2009-12-25 23:24:45 ----D---- C:\Windows\debug
2009-12-25 23:24:25 ----D---- C:\Windows\AppPatch
2009-12-25 22:22:45 ----D---- C:\Windows\Setup
2009-12-25 18:01:36 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 blbdrive;blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 DfsC;@%systemroot%\system32\drivers\dfsc.sys,-101; C:\Windows\System32\Drivers\dfsc.sys []
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\Windows\system32\drivers\nsiproxy.sys []
R1 RDPENCDD;@%systemroot%\system32\drivers\RDPENCDD.sys,-101; C:\Windows\system32\drivers\rdpencdd.sys []
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys []
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\Windows\system32\DRIVERS\tdx.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\Windows\system32\DRIVERS\wanarp.sys []
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver; C:\Windows\system32\DRIVERS\lltdio.sys []
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\Windows\system32\drivers\luafv.sys []
R2 PEAUTH;PEAUTH; C:\Windows\system32\drivers\peauth.sys []
R2 rspndr;Link-Layer Topology Discovery Responder; C:\Windows\system32\DRIVERS\rspndr.sys []
R2 tcpipreg;TCP/IP Registry Compatibility; C:\Windows\System32\drivers\tcpipreg.sys []
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\Windows\system32\DRIVERS\bowser.sys []
R3 CompositeBus;Ovladač rozpoznávacího modulu složené sběrnice; C:\Windows\system32\DRIVERS\CompositeBus.sys []
R3 DXGKrnl;LDDM Graphics Subsystem; C:\Windows\System32\drivers\dxgkrnl.sys []
R3 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys []
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys []
R3 HDAudBus;Ovladač sběrnice Microsoft UAA pro zvuk High Definition Audio; C:\Windows\system32\DRIVERS\HDAudBus.sys []
R3 HidUsb;Ovladač třídy standardu HID Microsoft; C:\Windows\system32\DRIVERS\hidusb.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 intelppm;Ovladač procesoru Intel; C:\Windows\system32\DRIVERS\intelppm.sys []
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys []
R3 monitor;Služba ovladače funkce třídy monitorů Microsoft; C:\Windows\system32\DRIVERS\monitor.sys []
R3 mouhid;Ovladač myši standardu HID; C:\Windows\system32\DRIVERS\mouhid.sys []
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\Windows\System32\drivers\mpsdrv.sys []
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\Windows\system32\DRIVERS\mrxsmb10.sys []
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\Windows\system32\DRIVERS\mrxsmb20.sys []
R3 NativeWifiP;NativeWiFi Filter; C:\Windows\system32\DRIVERS\nwifi.sys []
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys []
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys []
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\Windows\system32\DRIVERS\rassstp.sys []
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys []
R3 rt61x64;RT61 Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr6164.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\Windows\System32\DRIVERS\srv2.sys []
R3 srvnet;srvnet; C:\Windows\System32\DRIVERS\srvnet.sys []
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver; C:\Windows\system32\DRIVERS\tunnel.sys []
R3 umbus;Ovladač sběrnice UMBus Enumerator; C:\Windows\system32\DRIVERS\umbus.sys []
R3 usbehci;Ovladač miniportu vylepšeného hostitelského řadiče Microsoft USB 2.0; C:\Windows\system32\DRIVERS\usbehci.sys []
R3 usbhub;Ovladač standardního rozbočovače USB; C:\Windows\system32\DRIVERS\usbhub.sys []
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\Windows\system32\DRIVERS\USBSTOR.SYS []
R3 usbuhci;Ovladač miniportu univerzálního hostitelského řadiče Microsoft USB; C:\Windows\system32\DRIVERS\usbuhci.sys []
R3 vwifibus;Ovladač sběrnice Virtual WiFi; C:\Windows\system32\DRIVERS\vwifibus.sys []
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys []
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys []
S3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys []
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys []
S3 adp94xx;adp94xx; C:\Windows\system32\DRIVERS\adp94xx.sys []
S3 adpahci;adpahci; C:\Windows\system32\DRIVERS\adpahci.sys []
S3 adpu320;adpu320; C:\Windows\system32\DRIVERS\adpu320.sys []
S3 agp440;Intel AGP Bus Filter; C:\Windows\system32\DRIVERS\agp440.sys []
S3 amdide;amdide; C:\Windows\system32\DRIVERS\amdide.sys []
S3 AmdK8;AMD K8 Processor Driver; C:\Windows\system32\DRIVERS\amdk8.sys []
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys []
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys []
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys []
S3 amef7omo;amef7omo; C:\Windows\system32\drivers\amef7omo.sys []
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys [2009-02-23 14904]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys []
S3 arc;arc; C:\Windows\system32\DRIVERS\arc.sys []
S3 arcsas;arcsas; C:\Windows\system32\DRIVERS\arcsas.sys []
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbda.sys []
S3 b57nd60a;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60a.sys []
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver; C:\Windows\system32\DRIVERS\BrFiltLo.sys []
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver; C:\Windows\system32\DRIVERS\BrFiltUp.sys []
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM); C:\Windows\System32\Drivers\Brserid.sys []
S3 BrSerWdm;Brother WDM Serial driver; C:\Windows\System32\Drivers\BrSerWdm.sys []
S3 BrUsbMdm;Brother MFC USB Fax Only Modem; C:\Windows\System32\Drivers\BrUsbMdm.sys []
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\Windows\System32\Drivers\BrUsbSer.sys []
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\Windows\system32\DRIVERS\bthmodem.sys []
S3 circlass;Consumer IR Devices; C:\Windows\system32\DRIVERS\circlass.sys []
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys []
S3 Compbatt;Compbatt; C:\Windows\system32\DRIVERS\compbatt.sys []
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbda.sys []
S3 elxstor;elxstor; C:\Windows\system32\DRIVERS\elxstor.sys []
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2009-12-28 25640]
S3 exfat;exFAT File System Driver; C:\Windows\system32\drivers\exfat.sys []
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\Windows\system32\drivers\filetrace.sys []
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys []
S3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\Windows\system32\DRIVERS\gagp30kx.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-12-28 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2009-12-28 30528]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys []
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys []
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys []
S3 HidBth;Microsoft Bluetooth HID Miniport; C:\Windows\system32\DRIVERS\hidbth.sys []
S3 HidIr;Microsoft Infrared HID Driver; C:\Windows\system32\DRIVERS\hidir.sys []
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys []
S3 iaStorV;iaStorV; C:\Windows\system32\DRIVERS\iaStorV.sys []
S3 iirsp;iirsp; C:\Windows\system32\DRIVERS\iirsp.sys []
S3 intelide;intelide; C:\Windows\system32\DRIVERS\intelide.sys []
S3 IPMIDRV;IPMIDRV; C:\Windows\system32\DRIVERS\IPMIDrv.sys []
S3 isapnp;isapnp; C:\Windows\system32\DRIVERS\isapnp.sys []
S3 iScsiPrt;iScsiPort Driver; C:\Windows\system32\DRIVERS\msiscsi.sys []
S3 kbdhid;Keyboard HID Driver; C:\Windows\system32\DRIVERS\kbdhid.sys []
S3 LSI_FC;LSI_FC; C:\Windows\system32\DRIVERS\lsi_fc.sys []
S3 LSI_SAS;LSI_SAS; C:\Windows\system32\DRIVERS\lsi_sas.sys []
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys []
S3 LSI_SCSI;LSI_SCSI; C:\Windows\system32\DRIVERS\lsi_scsi.sys []
S3 megasas;megasas; C:\Windows\system32\DRIVERS\megasas.sys []
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys []
S3 mpio;mpio; C:\Windows\system32\DRIVERS\mpio.sys []
S3 msdsm;msdsm; C:\Windows\system32\DRIVERS\msdsm.sys []
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys []
S3 MsRPC;MsRPC; C:\Windows\system32\drivers\MsRPC.sys []
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys []
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys []
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys []
S3 nfrd960;nfrd960; C:\Windows\system32\DRIVERS\nfrd960.sys []
S3 nv_agp;NVIDIA nForce AGP Bus Filter; C:\Windows\system32\DRIVERS\nv_agp.sys []
S3 nvraid;nvraid; C:\Windows\system32\DRIVERS\nvraid.sys []
S3 nvstor;nvstor; C:\Windows\system32\DRIVERS\nvstor.sys []
S3 ohci1394;1394 OHCI Compliant Host Controller (Legacy); C:\Windows\system32\DRIVERS\ohci1394.sys []
S3 ql2300;ql2300; C:\Windows\system32\DRIVERS\ql2300.sys []
S3 ql40xx;ql40xx; C:\Windows\system32\DRIVERS\ql40xx.sys []
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\Windows\system32\drivers\qwavedrv.sys []
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys []
S3 sbp2port;sbp2port; C:\Windows\system32\DRIVERS\sbp2port.sys []
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys []
S3 sermouse;Serial Mouse Driver; C:\Windows\system32\DRIVERS\sermouse.sys []
S3 sffdisk;SFF Storage Class Driver; C:\Windows\system32\DRIVERS\sffdisk.sys []
S3 sffp_mmc;SFF Storage Protocol Driver for MMC; C:\Windows\system32\DRIVERS\sffp_mmc.sys []
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\Windows\system32\DRIVERS\sffp_sd.sys []
S3 SiSRaid2;SiSRaid2; C:\Windows\system32\DRIVERS\SiSRaid2.sys []
S3 SiSRaid4;SiSRaid4; C:\Windows\system32\DRIVERS\sisraid4.sys []
S3 Smb;@%SystemRoot%\system32\tcpipcfg.dll,-50005; C:\Windows\system32\DRIVERS\smb.sys []
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys []
S3 TCPIP6;Microsoft IPv6 Protocol Driver; C:\Windows\system32\DRIVERS\tcpip.sys []
S3 tssecsrv;@%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101; C:\Windows\System32\DRIVERS\tssecsrv.sys []
S3 uagp35;Microsoft AGPv3.5 Filter; C:\Windows\system32\DRIVERS\uagp35.sys []
S3 uliagpkx;Uli AGP Bus Filter; C:\Windows\system32\DRIVERS\uliagpkx.sys []
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\Windows\system32\DRIVERS\usbccgp.sys []
S3 usbcir;eHome Infrared Receiver (USBCIR); C:\Windows\system32\DRIVERS\usbcir.sys []
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbohci.sys []
S3 usbprint;Microsoft USB PRINTER Class; C:\Windows\system32\DRIVERS\usbprint.sys []
S3 vga;vga; C:\Windows\system32\DRIVERS\vgapnp.sys []
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys []
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys []
S3 vsmraid;vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys []
S3 WacomPen;Wacom Serial Pen HID Driver; C:\Windows\system32\DRIVERS\wacompen.sys []
S3 Wd;Wd; C:\Windows\system32\DRIVERS\wd.sys []
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys []
S4 crcdisk;Crcdisk Filter Driver; C:\Windows\system32\DRIVERS\crcdisk.sys []
S4 ws2ifsl;@%systemroot%\System32\drivers\ws2ifsl.sys,-1000; C:\Windows\system32\drivers\ws2ifsl.sys []
Naposledy upravil(a) Nemesis94 dne 30 pro 2009 13:32, celkem upraveno 2 x.

Nemesis94
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 led 2009 19:29

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#2 Příspěvek od Nemesis94 »

ZBYTEK LOGU

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AudioEndpointBuilder;@%SystemRoot%\system32\audiosrv.dll,-204; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-11-16 735960]
R2 gpsvc;@gpapi.dll,-112; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe []
R2 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2009-12-26 66872]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RalinkRegistryWriter;Ralink Registry Writer; C:\Program Files (x86)\Edimax\Common\RaRegistry.exe [2009-10-06 185632]
R2 RalinkRegistryWriter64;Ralink Registry Writer 64; C:\Program Files (x86)\Edimax\Common\RaRegistry64.exe [2009-10-06 212256]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2009-12-08 185640]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-18 1394504]
R2 UxSms;@%SystemRoot%\system32\dwm.exe,-2000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 WinDefend;@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 2297216]
R2 WSearch;@%systemroot%\system32\SearchIndexer.exe,-103; C:\Windows\system32\SearchIndexer.exe [2009-07-14 428032]
R2 wudfsvc;@%SystemRoot%\system32\wudfsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 KeyIso;@keyiso.dll,-100; C:\Windows\system32\lsass.exe []
R3 netprofm;@%SystemRoot%\system32\netprofm.dll,-202; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\Windows\servicing\TrustedInstaller.exe [2009-07-14 194048]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WMPNetworkSvc;@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101; C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe []
R3 WPDBusEnum;@%SystemRoot%\system32\wpdbusenum.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service; C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2007-03-14 2233400]
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe []
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 clr_optimization_v2.0.50727_32;Microsoft .NET Framework NGEN v2.0.50727_X86; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2009-06-10 66384]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-06-10 89920]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe []
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\Windows\ehome\ehRecvr.exe [2009-07-14 696832]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\Windows\ehome\ehsched.exe [2009-07-14 127488]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-11-16 23296]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe []
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-26 654848]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2009-06-10 42840]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe [2009-06-10 856384]
S3 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 IPBusEnum;@%systemroot%\system32\IPBusEnum.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 KtmRm;@comres.dll,-2946; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2009-07-14 20992]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\Windows\System32\snmptrap.exe []
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TBS;@%SystemRoot%\system32\tbssvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TuneUp.Defrag;@C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [2009-12-26 607048]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\Windows\system32\UI0Detect.exe []
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe []
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\Windows\System32\vds.exe []
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe []
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WPCSvc;@%SystemRoot%\system32\wpcsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2009-06-10 116560]

-----------------EOF-----------------


Podezření na soubory a.exe - c.exe - b.exe - msa.exe - sshnas.dll

c.exe je občas v spuštěných procesech tak ho killnu.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#3 Příspěvek od motji »

Dobrý večer :)

:arrow:Stáhněte OTM http://oldtimer.geekstogo.com/OTM.exe
Stáhněte na plochu Otm, 2krát klikněte na Otm,spustí se program,
Do levého okna "Paste Instructions for Items to be Moved" pod žlutou čáru zkopírujete skript

Kód: Vybrat vše

:processes
explorer.exe
 
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Windows\SysWOW64\sshnas.dll
C:\Windows\system32\sshnas.dll
C:\Users\Robin\AppData\Local\Temp\c.exe
C:\Users\Robin\AppData\Local\Temp\a.exe
C:\Users\Robin\AppData\Local\Temp\b.exe
C:\Windows\msa.exe
C:\Windows\msb.exe
C:\Windows\system32\tmp9667.tmp
C:\Windows\system32\tmp9668.tmp

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LosAlamos"=-
"PUT2VIDQLG"=-

:commands
[emptytemp]
[Reboot]
-klikněte na červené tlačítko Moveit!
-sem vložte obsah zeleného okénka
-Pokud se bude chtít restartovat pc, dejte YES,log pak najdete C:\_OTM\MovedFiles. Log vložte sem

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Nemesis94
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 led 2009 19:29

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#4 Příspěvek od Nemesis94 »

Při testování Eset Smart Security nahlásil:
31.12.2009 4:14:24
Real-time file system protection
file
C:\_OTM\MovedFiles\12312009_041316\C_WINDOWS\msa.exe
a variant of Win32/Kryptik.BKE trojan
cleaned by deleting - quarantined
Robin-PC\Robin
Event occurred on a file modified by the application: C:\Users\Robin\Desktop\OTM.exe.

All processes killed
Error: Unable to interpret <Dobrý večer :)> in the current context!
Error: Unable to interpret <:arrow:Stáhněte OTM http://oldtimer.geekstogo.com/OTM.exe> in the current context!
Error: Unable to interpret <Stáhněte na plochu Otm, 2krát klikněte na Otm,spustí se program,> in the current context!
Error: Unable to interpret <Do levého okna "Paste Instructions for Items to be Moved" pod žlutou čáru zkopírujete skript> in the current context!
Error: Unable to interpret <Kód:> in the current context!
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp folder moved successfully.
C:\WINDOWS\Installer\MSI6DC3.tmp moved successfully.
C:\WINDOWS\Installer\MSID724.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\AuthCabs\7971f918-a847-4430-9279-4a52d1efe18d\wltF3F3.tmp moved successfully.
C:\WINDOWS\System32\tmp9667.tmp moved successfully.
C:\WINDOWS\System32\tmp9668.tmp moved successfully.
C:\WINDOWS\Temp\DMIBE7D.tmp moved successfully.
C:\WINDOWS\Temp\DMID029.tmp moved successfully.
C:\WINDOWS\Temp\TS_AB8B.tmp moved successfully.
C:\WINDOWS\Temp\TS_B194.tmp moved successfully.
C:\WINDOWS\Temp\TS_B405.tmp moved successfully.
C:\WINDOWS\Temp\TS_BBE3.tmp moved successfully.
C:\WINDOWS\Temp\TS_BDE6.tmp moved successfully.
C:\WINDOWS\Temp\TS_BF9C.tmp moved successfully.
C:\WINDOWS\Temp\TS_CD92.tmp moved successfully.
C:\WINDOWS\Temp\TS_DCDE.tmp moved successfully.
C:\WINDOWS\Temp\TS_E5E4.tmp moved successfully.
File/Folder C:\Windows\SysWOW64\sshnas.dll not found.
File/Folder C:\Windows\system32\sshnas.dll not found.
File/Folder C:\Users\Robin\AppData\Local\Temp\c.exe not found.
File/Folder C:\Users\Robin\AppData\Local\Temp\a.exe not found.
File/Folder C:\Users\Robin\AppData\Local\Temp\b.exe not found.
C:\Windows\msa.exe moved successfully.
File/Folder C:\Windows\msb.exe not found.
File/Folder C:\Windows\system32\tmp9667.tmp not found.
File/Folder C:\Windows\system32\tmp9668.tmp not found.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LosAlamos deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\PUT2VIDQLG deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Robin
->Temp folder emptied: 14413459 bytes
->Temporary Internet Files folder emptied: 77463073 bytes
->FireFox cache emptied: 35895560 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
Windows Temp folder emptied: 3863561 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50507 bytes
RecycleBin emptied: 66504095 bytes

Total Files Cleaned = 189,00 mb

Error: Unable to interpret <:arrow: Stahněte MBAM z mého podpisu> in the current context!
Error: Unable to interpret <-Nainstalujte,dejte úplný sken> in the current context!
Error: Unable to interpret <NIC NEMAZAT :!:> in the current context!
Error: Unable to interpret <-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.> in the current context!
Error: Unable to interpret <-Log zkopírujte sem.> in the current context!
Error: Unable to interpret <_________________> in the current context!
Error: Unable to interpret <RSIT - - CCLEANER - - SAS - - MBAM - - SVI - - StartUpLite - - GMER - - RootRepeal - - DrWeb CureIt - - AVPTool> in the current context!
Error: Unable to interpret <Obrázek Nepoužívejte COMBOFIX bez doporučení rádce! Při špatné manipulaci může dojít k poškození systému !Obrázek> in the current context!
Error: Unable to interpret <-----------------------------------------Chcete podpořit naše forum? Informace zde Obrázek---------------------------------------> in the current context!
Error: Unable to interpret <Omlouvám se ale přes vánoce tu budu nepravidelně> in the current context!

OTM by OldTimer - Version 3.1.4.0 log created on 12312009_041316

Files moved on Reboot...
C:\Users\Robin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Robin\AppData\Local\Mozilla\Firefox\Profiles\835hr3ew.default\Cache\_CACHE_001_ moved successfully.
C:\Users\Robin\AppData\Local\Mozilla\Firefox\Profiles\835hr3ew.default\Cache\_CACHE_002_ moved successfully.
C:\Users\Robin\AppData\Local\Mozilla\Firefox\Profiles\835hr3ew.default\Cache\_CACHE_003_ moved successfully.
C:\Users\Robin\AppData\Local\Mozilla\Firefox\Profiles\835hr3ew.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\Robin\AppData\Local\Mozilla\Firefox\Profiles\835hr3ew.default\urlclassifier3.sqlite moved successfully.
C:\Users\Robin\AppData\Local\Mozilla\Firefox\Profiles\835hr3ew.default\XUL.mfl moved successfully.

Registry entries deleted on Reboot...

MBAM :

Malwarebytes' Anti-Malware 1.43
Verze databáze: 3460
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

31.12.2009 4:28:42
mbam-log-2009-12-31 (04-28-35).txt

Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 95976
Uplynulý čas: 3 minute(s), 16 second(s)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 4
Infikované hodnoty registru: 0
Infikované datové položky registru: 1
Infikované adresáře: 0
Infikované soubory: 2

Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované klíče registru:
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\PUT2VIDQLG (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\B1RQJ7YJ0U (Trojan.FakeAlert) -> No action taken.

Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované datové položky registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.

Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)

Infikované soubory:
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> No action taken.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> No action taken.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#5 Příspěvek od motji »

:shock: Skript je ten zelený text v bálém rámečku, Vy jste tam toho zkopíroval trochu víc včetně podpisu :D .

Co našel mbam, smažte a poprosím o nový log ze Rsitu.
Jak to vypadá s počítačem? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#6 Příspěvek od motji »

Jak to tu vypadá? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Nemesis94
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 led 2009 19:29

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#7 Příspěvek od Nemesis94 »

Omlouvám se nebyl jsem doma u PC

RSIT

Logfile of random's system information tool 1.06 (written by random/random)
Run by Robin at 2010-01-03 14:17:32
Microsoft Windows 7 Ultimate Service Pack 2
System drive C: has 8 GB (15%) free of 50 GB
Total RAM: 4094 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:36, on 3.1.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Edimax\Common\RaUI.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Robin\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\Robin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "D:\Hry\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Wireless Utility.lnk = C:\Program Files (x86)\Edimax\Common\RaUI.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files (x86)\Edimax\Common\RaRegistry.exe
O23 - Service: Ralink Registry Writer 64 (RalinkRegistryWriter64) - Ralink Technology, Corp. - C:\Program Files (x86)\Edimax\Common\RaRegistry64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10221 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2009-10-09 25623336]
"Steam"=D:\Hry\Steam\Steam.exe [2009-12-30 1217808]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-05-16 153136]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Wireless Utility.lnk - C:\Program Files (x86)\Edimax\Common\RaUI.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"ForceActiveDesktopOn"=
"NoActiveDesktopChanges"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2fef091e-f1b3-11de-87c6-00241d788114}]
shell\AutoRun\command - G:\AutoRunCD.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

Nemesis94
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 led 2009 19:29

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#8 Příspěvek od Nemesis94 »

======List of files/folders created in the last 1 months======

2010-01-02 17:03:30 ----D---- C:\Users\Robin\AppData\Roaming\Nero
2010-01-02 16:53:26 ----D---- C:\Users\Robin\AppData\Roaming\Ahead
2010-01-02 16:53:11 ----D---- C:\ProgramData\Ahead
2010-01-02 16:51:49 ----D---- C:\Program Files (x86)\Nero
2010-01-02 16:51:49 ----D---- C:\Program Files (x86)\Common Files\Ahead
2010-01-02 13:46:17 ----D---- C:\ProgramData\Nero
2010-01-02 13:08:22 ----RASHD---- C:\System
2010-01-02 03:42:48 ----D---- C:\Program Files (x86)\uTorrent
2010-01-02 03:41:21 ----D---- C:\Users\Robin\AppData\Roaming\uTorrent
2009-12-31 04:21:47 ----D---- C:\Users\Robin\AppData\Roaming\Malwarebytes
2009-12-31 04:21:40 ----D---- C:\ProgramData\Malwarebytes
2009-12-31 04:21:39 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2009-12-31 04:13:16 ----D---- C:\_OTM
2009-12-30 15:04:10 ----D---- C:\Users\Robin\AppData\Roaming\SoundSpectrum
2009-12-30 14:59:09 ----D---- C:\Program Files (x86)\SoundSpectrum
2009-12-30 13:03:21 ----D---- C:\Program Files (x86)\Common Files\Steam
2009-12-30 12:42:24 ----D---- C:\rsit
2009-12-30 12:42:24 ----D---- C:\Program Files (x86)\trend micro
2009-12-30 11:41:04 ----D---- C:\Users\Robin\AppData\Roaming\ESET
2009-12-30 11:40:21 ----D---- C:\ProgramData\ESET
2009-12-30 09:58:34 ----D---- C:\ProgramData\Codemasters
2009-12-30 00:25:58 ----D---- C:\Program Files (x86)\Wolfenstein - Enemy Territory
2009-12-29 22:21:33 ----A---- C:\Windows\system32\wnaspi32.dll
2009-12-29 21:54:08 ----D---- C:\ProgramData\Paragon
2009-12-29 15:45:49 ----SD---- C:\Program Files (x86)\HLSW
2009-12-29 15:45:49 ----D---- C:\Users\Robin\AppData\Roaming\HLSW
2009-12-29 15:18:37 ----D---- C:\Program Files (x86)\VodBurner
2009-12-29 13:04:37 ----D---- C:\Program Files (x86)\Windows Live SkyDrive
2009-12-29 13:04:24 ----D---- C:\Program Files (x86)\Windows Live
2009-12-29 13:03:58 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2009-12-28 23:17:41 ----D---- C:\Windows\WindowsMobile
2009-12-28 23:17:40 ----SHD---- C:\Config.Msi
2009-12-28 02:32:15 ----D---- C:\Program Files (x86)\GIGABYTE
2009-12-28 02:32:15 ----D---- C:\Program Files (x86)\AMD
2009-12-28 00:34:26 ----HDC---- C:\ProgramData\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2009-12-28 00:28:16 ----D---- C:\ProgramData\Electronic Arts
2009-12-27 16:27:23 ----D---- C:\Users\Robin\AppData\Roaming\Mozilla
2009-12-27 16:27:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
2009-12-26 23:26:42 ----A---- C:\Windows\system32\PnkBstrB.exe
2009-12-26 23:26:38 ----A---- C:\Windows\system32\PnkBstrA.exe
2009-12-26 23:26:38 ----A---- C:\Windows\system32\pbsvc.exe
2009-12-26 20:41:44 ----A---- C:\Windows\system32\mkl_vml_p4.dll
2009-12-26 20:41:44 ----A---- C:\Windows\system32\mkl_vml_p3.dll
2009-12-26 20:41:43 ----A---- C:\Windows\system32\mkl_vml_def.dll
2009-12-26 20:41:43 ----A---- C:\Windows\system32\mkl_p4.dll
2009-12-26 20:41:43 ----A---- C:\Windows\system32\mkl_p3.dll
2009-12-26 20:41:43 ----A---- C:\Windows\system32\mkl_lapack64.dll
2009-12-26 20:41:42 ----A---- C:\Windows\system32\rapture3d_oal.dll
2009-12-26 20:41:42 ----A---- C:\Windows\system32\mkl_lapack32.dll
2009-12-26 20:41:42 ----A---- C:\Windows\system32\mkl_def.dll
2009-12-26 20:41:42 ----A---- C:\Windows\system32\libguide40.dll
2009-12-26 20:41:40 ----D---- C:\Program Files (x86)\BRS
2009-12-26 20:41:26 ----D---- C:\Program Files (x86)\OpenAL
2009-12-26 20:41:26 ----A---- C:\Windows\system32\wrap_oal.dll
2009-12-26 20:41:26 ----A---- C:\Windows\system32\OpenAL32.dll
2009-12-26 20:20:49 ----D---- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2009-12-26 20:19:56 ----D---- C:\ProgramData\Blizzard
2009-12-26 18:55:07 ----D---- C:\Users\Robin\AppData\Roaming\skypePM
2009-12-26 18:22:43 ----D---- C:\Users\Robin\AppData\Roaming\Skype
2009-12-26 18:19:10 ----D---- C:\Program Files (x86)\Common Files\Skype
2009-12-26 18:19:09 ----RD---- C:\Program Files (x86)\Skype
2009-12-26 18:19:04 ----D---- C:\ProgramData\Skype
2009-12-26 18:18:27 ----D---- C:\Users\Robin\AppData\Roaming\TeamViewer
2009-12-26 18:17:31 ----D---- C:\Program Files (x86)\TeamViewer
2009-12-26 02:59:52 ----D---- C:\Windows\Panther
2009-12-26 02:59:40 ----RASH---- C:\BOOTSECT.BAK
2009-12-26 02:59:38 ----SHD---- C:\Boot
2009-12-26 02:22:38 ----RHD---- C:\Users\Robin\AppData\Roaming\SecuROM
2009-12-26 02:16:28 ----D---- C:\Program Files (x86)\Common Files\Windows Live
2009-12-26 02:15:46 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2009-12-26 02:15:13 ----D---- C:\Program Files (x86)\Microsoft
2009-12-26 02:03:27 ----A---- C:\Windows\system32\uxtuneup.dll
2009-12-26 02:03:27 ----A---- C:\Windows\system32\authuitu.dll
2009-12-26 02:03:15 ----D---- C:\Users\Robin\AppData\Roaming\TuneUp Software
2009-12-26 02:03:07 ----D---- C:\Program Files (x86)\TuneUp Utilities 2010
2009-12-26 02:02:41 ----D---- C:\ProgramData\TuneUp Software
2009-12-26 02:02:36 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-26 02:01:22 ----D---- C:\Program Files (x86)\IObit
2009-12-26 01:53:42 ----A---- C:\Windows\system32\gdiplus.dll
2009-12-26 01:46:00 ----D---- C:\Users\Robin\AppData\Roaming\BITS
2009-12-26 01:45:50 ----A---- C:\Windows\system32\CmdLineExt_x64.dll
2009-12-26 01:44:59 ----D---- C:\profiles
2009-12-26 01:44:37 ----D---- C:\Program Files (x86)\FlashGet Network
2009-12-26 01:29:23 ----D---- C:\ProgramData\FLEXnet
2009-12-26 01:19:45 ----D---- C:\Windows\system32\xlive
2009-12-26 01:19:44 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2009-12-26 01:09:12 ----D---- C:\ProgramData\Adobe
2009-12-26 01:08:52 ----D---- C:\Program Files (x86)\Bonjour
2009-12-26 01:06:47 ----D---- C:\Windows\system32\spool
2009-12-26 01:05:27 ----D---- C:\Program Files (x86)\Adobe
2009-12-26 01:05:06 ----D---- C:\Program Files (x86)\Common Files\Macrovision Shared
2009-12-26 01:04:34 ----D---- C:\Program Files (x86)\Common Files\Adobe
2009-12-26 00:54:30 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2009-12-26 00:54:03 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2009-12-26 00:53:58 ----D---- C:\Users\Robin\AppData\Roaming\DAEMON Tools Lite
2009-12-26 00:50:46 ----D---- C:\Program Files (x86)\SpeedFan
2009-12-26 00:49:44 ----D---- C:\ProgramData\DAEMON Tools Lite
2009-12-26 00:44:50 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2009-12-26 00:44:11 ----D---- C:\Windows\system32\AGEIA
2009-12-26 00:44:11 ----D---- C:\Program Files (x86)\AGEIA Technologies
2009-12-26 00:44:01 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2009-12-26 00:43:10 ----A---- C:\Windows\system32\OpenCL.dll
2009-12-26 00:43:09 ----A---- C:\Windows\system32\nvwgf2um.dll
2009-12-26 00:43:07 ----A---- C:\Windows\system32\nvoglv32.dll
2009-12-26 00:43:07 ----A---- C:\Windows\system32\nvencodemft.dll
2009-12-26 00:43:07 ----A---- C:\Windows\system32\nvdecodemft.dll
2009-12-26 00:43:05 ----A---- C:\Windows\system32\nvd3dum.dll
2009-12-26 00:43:05 ----A---- C:\Windows\system32\nvcuvid.dll
2009-12-26 00:43:04 ----A---- C:\Windows\system32\nvcuvenc.dll
2009-12-26 00:43:04 ----A---- C:\Windows\system32\nvcuda.dll
2009-12-26 00:43:04 ----A---- C:\Windows\system32\nvcompiler.dll
2009-12-26 00:43:02 ----A---- C:\Windows\system32\nvapi.dll
2009-12-26 00:43:00 ----D---- C:\NVIDIA
2009-12-26 00:27:00 ----A---- C:\Windows\system32\XAudio2_5.dll
2009-12-26 00:26:59 ----A---- C:\Windows\system32\xactengine3_5.dll
2009-12-26 00:26:59 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2009-12-26 00:26:58 ----A---- C:\Windows\system32\d3dx11_42.dll
2009-12-26 00:26:58 ----A---- C:\Windows\system32\d3dx10_42.dll
2009-12-26 00:26:58 ----A---- C:\Windows\system32\d3dcsx_42.dll
2009-12-26 00:26:57 ----A---- C:\Windows\system32\D3DX9_42.dll
2009-12-26 00:26:56 ----A---- C:\Windows\system32\D3DX9_41.dll
2009-12-26 00:26:56 ----A---- C:\Windows\system32\d3dx10_41.dll
2009-12-26 00:26:56 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2009-12-26 00:26:54 ----A---- C:\Windows\system32\XAudio2_4.dll
2009-12-26 00:26:54 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2009-12-26 00:26:54 ----A---- C:\Windows\system32\xactengine3_4.dll
2009-12-26 00:26:53 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2009-12-26 00:26:53 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-12-26 00:26:53 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-12-26 00:26:50 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-12-26 00:26:50 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-12-26 00:26:50 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-12-26 00:26:49 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-12-26 00:26:49 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-12-26 00:26:48 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-12-26 00:26:48 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-12-26 00:26:48 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-12-26 00:26:47 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-12-26 00:26:47 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-12-26 00:26:46 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-12-26 00:26:46 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-12-26 00:26:46 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-12-26 00:26:45 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-12-26 00:26:45 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-12-26 00:26:45 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-12-26 00:26:45 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-12-26 00:26:44 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-12-26 00:26:43 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-12-26 00:26:42 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-12-26 00:26:42 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-12-26 00:26:41 ----D---- C:\Users\Robin\AppData\Roaming\WinRAR
2009-12-26 00:26:41 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-12-26 00:26:41 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-12-26 00:26:40 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-12-26 00:26:40 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-12-26 00:26:38 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-12-26 00:26:38 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-12-26 00:26:34 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-12-26 00:26:33 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-12-26 00:26:33 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-12-26 00:26:33 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-12-26 00:26:32 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-12-26 00:26:32 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-12-26 00:26:32 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-12-26 00:26:32 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-12-26 00:26:31 ----A---- C:\Windows\system32\xinput1_3.dll
2009-12-26 00:26:31 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-12-26 00:26:28 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-12-26 00:26:27 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-12-26 00:26:27 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-12-26 00:26:27 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-12-26 00:26:26 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-12-26 00:26:25 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-12-26 00:26:25 ----A---- C:\Windows\system32\d3dx10.dll
2009-12-26 00:26:15 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-12-26 00:26:14 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-12-26 00:26:14 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-12-26 00:26:14 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-12-26 00:26:10 ----A---- C:\Windows\system32\xinput1_2.dll
2009-12-26 00:26:10 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-12-26 00:26:10 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-12-26 00:26:09 ----A---- C:\Windows\system32\xinput1_1.dll
2009-12-26 00:26:08 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-12-26 00:26:01 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-12-26 00:26:00 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-12-26 00:26:00 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-12-26 00:25:59 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-12-26 00:25:59 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-12-26 00:25:58 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-12-26 00:25:58 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-12-26 00:25:57 ----D---- C:\Program Files (x86)\WinRAR
2009-12-26 00:25:57 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-12-26 00:25:56 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-12-26 00:05:14 ----D---- C:\Program Files (x86)\Intel
2009-12-26 00:05:14 ----A---- C:\Windows\system32\CSVer.dll
2009-12-26 00:05:07 ----D---- C:\Intel
2009-12-26 00:04:47 ----A---- C:\Windows\system32\CmdRtr.DLL
2009-12-26 00:04:47 ----A---- C:\Windows\system32\APOMngr.DLL
2009-12-26 00:04:37 ----D---- C:\Windows\system32\RTCOM
2009-12-26 00:04:26 ----A---- C:\Windows\system32\MBAPO32.dll
2009-12-26 00:04:25 ----D---- C:\Program Files (x86)\Realtek
2009-12-26 00:04:24 ----HD---- C:\Program Files (x86)\Temp
2009-12-26 00:04:24 ----A---- C:\Windows\RtlExUpd.dll
2009-12-26 00:04:21 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2009-12-26 00:01:45 ----D---- C:\Program Files (x86)\Microsoft Works
2009-12-26 00:01:32 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2009-12-26 00:01:32 ----D---- C:\Program Files (x86)\Common Files\DESIGNER
2009-12-26 00:01:14 ----D---- C:\Windows\PCHEALTH
2009-12-26 00:01:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2009-12-25 23:59:38 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2009-12-25 23:59:10 ----D---- C:\ProgramData\Microsoft Help
2009-12-25 23:59:10 ----D---- C:\Program Files (x86)\Microsoft Office
2009-12-25 23:58:18 ----RHD---- C:\MSOCache
2009-12-25 23:50:33 ----A---- C:\Windows\system32\MSVCR71.dll
2009-12-25 23:50:33 ----A---- C:\Windows\system32\MSVCP71.dll
2009-12-25 23:50:33 ----A---- C:\Windows\system32\MFC71.dll
2009-12-25 23:48:55 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-12-25 23:48:11 ----D---- C:\Users\Robin\AppData\Roaming\Macromedia
2009-12-25 23:48:11 ----D---- C:\Users\Robin\AppData\Roaming\Adobe
2009-12-25 23:48:09 ----D---- C:\Windows\system32\Macromed
2009-12-25 23:43:31 ----D---- C:\ProgramData\NVIDIA
2009-12-25 23:25:30 ----A---- C:\Windows\system32\tzres.dll
2009-12-25 23:25:21 ----A---- C:\Windows\system32\msv1_0.dll
2009-12-25 23:10:27 ----A---- C:\Windows\system32\wmp.dll
2009-12-25 23:10:26 ----A---- C:\Windows\system32\t2embed.dll
2009-12-25 23:10:26 ----A---- C:\Windows\system32\fontsub.dll
2009-12-25 23:10:26 ----A---- C:\Windows\system32\explorer.exe
2009-12-25 23:10:26 ----A---- C:\Windows\system32\CertEnroll.dll
2009-12-25 23:10:26 ----A---- C:\Windows\system32\atmfd.dll
2009-12-25 23:10:26 ----A---- C:\Windows\explorer.exe
2009-12-25 23:10:25 ----A---- C:\Windows\system32\wmploc.DLL
2009-12-25 23:10:09 ----A---- C:\Windows\system32\msasn1.dll
2009-12-25 23:10:08 ----A---- C:\Windows\system32\mshtml.dll
2009-12-25 23:10:07 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-12-25 22:56:12 ----D---- C:\ProgramData\Ralink
2009-12-25 22:55:59 ----D---- C:\ProgramData\Edimax Driver
2009-12-25 22:55:53 ----D---- C:\Program Files (x86)\Cisco
2009-12-25 22:55:50 ----SHD---- C:\Windows\Installer
2009-12-25 22:55:49 ----A---- C:\Windows\system32\RAIHV.dll
2009-12-25 22:55:49 ----A---- C:\Windows\system32\RAEXTUI.dll
2009-12-25 22:55:49 ----A---- C:\Windows\system32\RaCertMgr.dll
2009-12-25 22:55:48 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2009-12-25 22:55:48 ----D---- C:\Program Files (x86)\Edimax
2009-12-25 22:55:23 ----D---- C:\Users\Robin\AppData\Roaming\InstallShield
2009-12-25 22:24:30 ----D---- C:\Users\Robin\AppData\Roaming\Identities
2009-12-25 22:24:03 ----SD---- C:\Users\Robin\AppData\Roaming\Microsoft
2009-12-25 22:24:03 ----D---- C:\Users\Robin\AppData\Roaming\Media Center Programs
2009-12-25 22:21:39 ----SHD---- C:\Recovery
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Šablony
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Plocha
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Oblíbené položky
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Nabídka Start
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Dokumenty
2009-12-25 22:21:39 ----SHD---- C:\ProgramData\Data aplikací
2009-12-25 18:03:48 ----D---- C:\Windows\SoftwareDistribution
2009-12-25 18:01:06 ----D---- C:\Windows\Prefetch
2009-12-25 18:00:50 ----SHD---- C:\System Volume Information
2009-12-04 01:19:32 ----A---- C:\Windows\system32\qtp-mt334.dll
2009-12-04 01:16:42 ----A---- C:\Windows\system32\prgiso.dll

======List of files/folders modified in the last 1 months======

2010-01-03 14:17:34 ----D---- C:\Windows\Temp
2010-01-03 13:52:11 ----D---- C:\Program Files (x86)\Common Files
2010-01-02 16:53:11 ----HD---- C:\ProgramData
2010-01-02 16:52:50 ----D---- C:\Windows\ehome
2010-01-02 16:52:48 ----D---- C:\Windows
2010-01-02 16:52:13 ----D---- C:\Windows\SysWOW64
2010-01-02 16:51:49 ----RD---- C:\Program Files (x86)
2010-01-02 13:44:07 ----RSD---- C:\Windows\assembly
2010-01-02 13:43:13 ----D---- C:\Windows\inf
2010-01-02 13:41:31 ----RD---- C:\Program Files
2010-01-02 11:56:30 ----D---- C:\Windows\winsxs
2010-01-02 03:06:05 ----D---- C:\Windows\Tasks
2009-12-31 04:34:50 ----D---- C:\Windows\System32
2009-12-31 04:21:43 ----D---- C:\Windows\system32\drivers
2009-12-29 12:55:56 ----RD---- C:\Users
2009-12-29 12:45:32 ----SHD---- C:\$Recycle.Bin
2009-12-27 16:28:56 ----D---- C:\Windows\LiveKernelReports
2009-12-27 12:45:49 ----D---- C:\Windows\rescache
2009-12-27 12:34:08 ----D---- C:\Windows\Logs
2009-12-26 10:00:10 ----D---- C:\Windows\Microsoft.NET
2009-12-26 02:16:01 ----SD---- C:\ProgramData\Microsoft
2009-12-26 02:15:26 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2009-12-26 01:32:29 ----RSD---- C:\Windows\Fonts
2009-12-26 01:29:15 ----D---- C:\Program Files (x86)\Common Files\System
2009-12-26 01:29:15 ----A---- C:\Windows\win.ini
2009-12-26 00:01:39 ----D---- C:\Program Files (x86)\MSBuild
2009-12-26 00:01:30 ----D---- C:\Windows\ShellNew
2009-12-25 23:48:10 ----D---- C:\Windows\Downloaded Program Files
2009-12-25 23:43:28 ----D---- C:\Windows\Help
2009-12-25 23:29:05 ----D---- C:\Windows\system32\sk-SK
2009-12-25 23:29:05 ----D---- C:\Windows\system32\en-US
2009-12-25 23:29:05 ----D---- C:\Windows\system32\cs-CZ
2009-12-25 23:29:05 ----D---- C:\Program Files (x86)\Windows Media Player
2009-12-25 23:29:04 ----D---- C:\Program Files (x86)\Internet Explorer
2009-12-25 23:24:45 ----D---- C:\Windows\debug
2009-12-25 23:24:25 ----D---- C:\Windows\AppPatch
2009-12-25 22:22:45 ----D---- C:\Windows\Setup
2009-12-25 18:01:36 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 blbdrive;blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 DfsC;@%systemroot%\system32\drivers\dfsc.sys,-101; C:\Windows\System32\Drivers\dfsc.sys []
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\Windows\system32\drivers\nsiproxy.sys []
R1 RDPENCDD;@%systemroot%\system32\drivers\RDPENCDD.sys,-101; C:\Windows\system32\drivers\rdpencdd.sys []
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys []
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\Windows\system32\DRIVERS\tdx.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\Windows\system32\DRIVERS\wanarp.sys []
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys []
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver; C:\Windows\system32\DRIVERS\lltdio.sys []
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\Windows\system32\drivers\luafv.sys []
R2 PEAUTH;PEAUTH; C:\Windows\system32\drivers\peauth.sys []
R2 rspndr;Link-Layer Topology Discovery Responder; C:\Windows\system32\DRIVERS\rspndr.sys []
R2 tcpipreg;TCP/IP Registry Compatibility; C:\Windows\System32\drivers\tcpipreg.sys []
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\Windows\system32\DRIVERS\bowser.sys []
R3 CompositeBus;Ovladač rozpoznávacího modulu složené sběrnice; C:\Windows\system32\DRIVERS\CompositeBus.sys []
R3 DXGKrnl;LDDM Graphics Subsystem; C:\Windows\System32\drivers\dxgkrnl.sys []
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys []
R3 HDAudBus;Ovladač sběrnice Microsoft UAA pro zvuk High Definition Audio; C:\Windows\system32\DRIVERS\HDAudBus.sys []
R3 HidUsb;Ovladač třídy standardu HID Microsoft; C:\Windows\system32\DRIVERS\hidusb.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 intelppm;Ovladač procesoru Intel; C:\Windows\system32\DRIVERS\intelppm.sys []
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys []
R3 monitor;Služba ovladače funkce třídy monitorů Microsoft; C:\Windows\system32\DRIVERS\monitor.sys []
R3 mouhid;Ovladač myši standardu HID; C:\Windows\system32\DRIVERS\mouhid.sys []
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\Windows\System32\drivers\mpsdrv.sys []
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\Windows\system32\DRIVERS\mrxsmb10.sys []
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\Windows\system32\DRIVERS\mrxsmb20.sys []
R3 NativeWifiP;NativeWiFi Filter; C:\Windows\system32\DRIVERS\nwifi.sys []
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys []
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys []
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\Windows\system32\DRIVERS\rassstp.sys []
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys []
R3 rt61x64;RT61 Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr6164.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\Windows\System32\DRIVERS\srv2.sys []
R3 srvnet;srvnet; C:\Windows\System32\DRIVERS\srvnet.sys []
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver; C:\Windows\system32\DRIVERS\tunnel.sys []
R3 umbus;Ovladač sběrnice UMBus Enumerator; C:\Windows\system32\DRIVERS\umbus.sys []
R3 usbehci;Ovladač miniportu vylepšeného hostitelského řadiče Microsoft USB 2.0; C:\Windows\system32\DRIVERS\usbehci.sys []
R3 usbhub;Ovladač standardního rozbočovače USB; C:\Windows\system32\DRIVERS\usbhub.sys []
R3 usbuhci;Ovladač miniportu univerzálního hostitelského řadiče Microsoft USB; C:\Windows\system32\DRIVERS\usbuhci.sys []
R3 vwifibus;Ovladač sběrnice Virtual WiFi; C:\Windows\system32\DRIVERS\vwifibus.sys []
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys []
S3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys []
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys []
S3 adp94xx;adp94xx; C:\Windows\system32\DRIVERS\adp94xx.sys []
S3 adpahci;adpahci; C:\Windows\system32\DRIVERS\adpahci.sys []
S3 adpu320;adpu320; C:\Windows\system32\DRIVERS\adpu320.sys []
S3 agp440;Intel AGP Bus Filter; C:\Windows\system32\DRIVERS\agp440.sys []
S3 amdide;amdide; C:\Windows\system32\DRIVERS\amdide.sys []
S3 AmdK8;AMD K8 Processor Driver; C:\Windows\system32\DRIVERS\amdk8.sys []
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys []
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys []
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys []
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys [2009-02-23 14904]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys []
S3 aqwllkt9;aqwllkt9; C:\Windows\system32\drivers\aqwllkt9.sys []
S3 arc;arc; C:\Windows\system32\DRIVERS\arc.sys []
S3 arcsas;arcsas; C:\Windows\system32\DRIVERS\arcsas.sys []
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbda.sys []
S3 b57nd60a;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60a.sys []
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver; C:\Windows\system32\DRIVERS\BrFiltLo.sys []
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver; C:\Windows\system32\DRIVERS\BrFiltUp.sys []
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM); C:\Windows\System32\Drivers\Brserid.sys []
S3 BrSerWdm;Brother WDM Serial driver; C:\Windows\System32\Drivers\BrSerWdm.sys []
S3 BrUsbMdm;Brother MFC USB Fax Only Modem; C:\Windows\System32\Drivers\BrUsbMdm.sys []
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\Windows\System32\Drivers\BrUsbSer.sys []
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\Windows\system32\DRIVERS\bthmodem.sys []
S3 circlass;Consumer IR Devices; C:\Windows\system32\DRIVERS\circlass.sys []
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys []
S3 Compbatt;Compbatt; C:\Windows\system32\DRIVERS\compbatt.sys []
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbda.sys []
S3 elxstor;elxstor; C:\Windows\system32\DRIVERS\elxstor.sys []
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2009-12-28 25640]
S3 exfat;exFAT File System Driver; C:\Windows\system32\drivers\exfat.sys []
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\Windows\system32\drivers\filetrace.sys []
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys []
S3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\Windows\system32\DRIVERS\gagp30kx.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-12-28 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2009-12-28 30528]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys []
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys []
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys []
S3 HidBth;Microsoft Bluetooth HID Miniport; C:\Windows\system32\DRIVERS\hidbth.sys []
S3 HidIr;Microsoft Infrared HID Driver; C:\Windows\system32\DRIVERS\hidir.sys []
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys []
S3 iaStorV;iaStorV; C:\Windows\system32\DRIVERS\iaStorV.sys []
S3 iirsp;iirsp; C:\Windows\system32\DRIVERS\iirsp.sys []
S3 intelide;intelide; C:\Windows\system32\DRIVERS\intelide.sys []
S3 IPMIDRV;IPMIDRV; C:\Windows\system32\DRIVERS\IPMIDrv.sys []
S3 isapnp;isapnp; C:\Windows\system32\DRIVERS\isapnp.sys []
S3 iScsiPrt;iScsiPort Driver; C:\Windows\system32\DRIVERS\msiscsi.sys []
S3 kbdhid;Keyboard HID Driver; C:\Windows\system32\DRIVERS\kbdhid.sys []
S3 LSI_FC;LSI_FC; C:\Windows\system32\DRIVERS\lsi_fc.sys []
S3 LSI_SAS;LSI_SAS; C:\Windows\system32\DRIVERS\lsi_sas.sys []
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys []
S3 LSI_SCSI;LSI_SCSI; C:\Windows\system32\DRIVERS\lsi_scsi.sys []
S3 megasas;megasas; C:\Windows\system32\DRIVERS\megasas.sys []
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys []
S3 mpio;mpio; C:\Windows\system32\DRIVERS\mpio.sys []
S3 msdsm;msdsm; C:\Windows\system32\DRIVERS\msdsm.sys []
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys []
S3 MsRPC;MsRPC; C:\Windows\system32\drivers\MsRPC.sys []
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys []
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys []
S3 Nbdrv;NetBalancer Service; C:\Windows\system32\DRIVERS\nbdrv.sys []
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys []
S3 nfrd960;nfrd960; C:\Windows\system32\DRIVERS\nfrd960.sys []
S3 nv_agp;NVIDIA nForce AGP Bus Filter; C:\Windows\system32\DRIVERS\nv_agp.sys []
S3 nvraid;nvraid; C:\Windows\system32\DRIVERS\nvraid.sys []
S3 nvstor;nvstor; C:\Windows\system32\DRIVERS\nvstor.sys []
S3 ohci1394;1394 OHCI Compliant Host Controller (Legacy); C:\Windows\system32\DRIVERS\ohci1394.sys []
S3 ql2300;ql2300; C:\Windows\system32\DRIVERS\ql2300.sys []
S3 ql40xx;ql40xx; C:\Windows\system32\DRIVERS\ql40xx.sys []
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\Windows\system32\drivers\qwavedrv.sys []
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys []
S3 sbp2port;sbp2port; C:\Windows\system32\DRIVERS\sbp2port.sys []
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys []
S3 sermouse;Serial Mouse Driver; C:\Windows\system32\DRIVERS\sermouse.sys []
S3 sffdisk;SFF Storage Class Driver; C:\Windows\system32\DRIVERS\sffdisk.sys []
S3 sffp_mmc;SFF Storage Protocol Driver for MMC; C:\Windows\system32\DRIVERS\sffp_mmc.sys []
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\Windows\system32\DRIVERS\sffp_sd.sys []
S3 SiSRaid2;SiSRaid2; C:\Windows\system32\DRIVERS\SiSRaid2.sys []
S3 SiSRaid4;SiSRaid4; C:\Windows\system32\DRIVERS\sisraid4.sys []
S3 Smb;@%SystemRoot%\system32\tcpipcfg.dll,-50005; C:\Windows\system32\DRIVERS\smb.sys []
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys []
S3 TCPIP6;Microsoft IPv6 Protocol Driver; C:\Windows\system32\DRIVERS\tcpip.sys []
S3 tssecsrv;@%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101; C:\Windows\System32\DRIVERS\tssecsrv.sys []
S3 uagp35;Microsoft AGPv3.5 Filter; C:\Windows\system32\DRIVERS\uagp35.sys []
S3 uliagpkx;Uli AGP Bus Filter; C:\Windows\system32\DRIVERS\uliagpkx.sys []
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\Windows\system32\DRIVERS\usbccgp.sys []
S3 usbcir;eHome Infrared Receiver (USBCIR); C:\Windows\system32\DRIVERS\usbcir.sys []
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbohci.sys []
S3 usbprint;Microsoft USB PRINTER Class; C:\Windows\system32\DRIVERS\usbprint.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\Windows\system32\DRIVERS\USBSTOR.SYS []
S3 vga;vga; C:\Windows\system32\DRIVERS\vgapnp.sys []
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys []
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys []
S3 vsmraid;vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys []
S3 WacomPen;Wacom Serial Pen HID Driver; C:\Windows\system32\DRIVERS\wacompen.sys []
S3 Wd;Wd; C:\Windows\system32\DRIVERS\wd.sys []
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys []
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys []
S4 crcdisk;Crcdisk Filter Driver; C:\Windows\system32\DRIVERS\crcdisk.sys []
S4 ws2ifsl;@%systemroot%\System32\drivers\ws2ifsl.sys,-1000; C:\Windows\system32\drivers\ws2ifsl.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AudioEndpointBuilder;@%SystemRoot%\system32\audiosrv.dll,-204; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-11-16 735960]
R2 gpsvc;@gpapi.dll,-112; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe []
R2 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2009-12-30 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2010-01-03 214816]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RalinkRegistryWriter;Ralink Registry Writer; C:\Program Files (x86)\Edimax\Common\RaRegistry.exe [2009-10-06 185632]
R2 RalinkRegistryWriter64;Ralink Registry Writer 64; C:\Program Files (x86)\Edimax\Common\RaRegistry64.exe [2009-10-06 212256]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2009-12-08 185640]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-18 1394504]
R2 UxSms;@%SystemRoot%\system32\dwm.exe,-2000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 WinDefend;@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 2297216]
R2 WSearch;@%systemroot%\system32\SearchIndexer.exe,-103; C:\Windows\system32\SearchIndexer.exe [2009-07-14 428032]
R2 wudfsvc;@%SystemRoot%\system32\wudfsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 KeyIso;@keyiso.dll,-100; C:\Windows\system32\lsass.exe []
R3 netprofm;@%SystemRoot%\system32\netprofm.dll,-202; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WMPNetworkSvc;@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101; C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe []
S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service; C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe []
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe []
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 clr_optimization_v2.0.50727_32;Microsoft .NET Framework NGEN v2.0.50727_X86; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2009-06-10 66384]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-06-10 89920]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe []
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\Windows\ehome\ehRecvr.exe [2009-07-14 696832]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\Windows\ehome\ehsched.exe [2009-07-14 127488]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-11-16 23296]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe []
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-26 654848]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2009-06-10 42840]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe [2009-06-10 856384]
S3 IPBusEnum;@%systemroot%\system32\IPBusEnum.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 KtmRm;@comres.dll,-2946; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2009-07-14 20992]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\Windows\System32\snmptrap.exe []
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2009-12-30 321320]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TBS;@%SystemRoot%\system32\tbssvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\Windows\servicing\TrustedInstaller.exe [2009-07-14 194048]
S3 TuneUp.Defrag;@C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [2009-12-26 607048]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\Windows\system32\UI0Detect.exe []
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe []
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\Windows\System32\vds.exe []
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe []
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WPCSvc;@%SystemRoot%\system32\wpcsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WPDBusEnum;@%SystemRoot%\system32\wpdbusenum.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2009-06-10 116560]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#9 Příspěvek od motji »

Ještě odinstalujte Daemon tool toolbar.
Jak to vypadá s počítačem ted? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Nemesis94
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 14 led 2009 19:29

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#10 Příspěvek od Nemesis94 »

Výborný nic nevyskakuje a GTA jde jak má děkuju :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: C:\Windows\system32\sshnas.dll - a variant of Win32/Kryptik.

#11 Příspěvek od motji »

Není zač :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět